Privacy Policy
Last updated: June 2025
Welcome to MorvellianroyalHaven. We are committed to protecting your personal data and respecting your privacy in full compliance with applicable data protection legislation, including the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and — where applicable to individuals in the European Economic Area or the United Kingdom — the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use and protect it, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.
Please read this Privacy Policy carefully before using our website located at morvellianroyalhaven.com (the "Website"), making a reservation, visiting our premises, or using any of our services. By interacting with us, you acknowledge that you have read and understood this Policy.
1. Data Controller
The entity responsible for collecting, processing, and safeguarding your personal data is:
| Trading Name | MorvellianroyalHaven |
|---|---|
| Legal / Registered Entity Name | |
| Company Registration Number | 451 814 955 |
| Australian Business Number (ABN) | ABN 33 451 814 955 |
| Registration Country | Australia |
| Registered Address | |
| Website | morvellianroyalhaven.com |
| Privacy Contact Email | privacy@morvellianroyalhaven.com |
References to "we", "us", "our", or "MorvellianroyalHaven" throughout this Policy mean acting as the data controller.
1.1 Data Protection Officer (DPO)
We have designated a Data Protection Officer to oversee compliance with data protection obligations. You may contact our DPO directly on any matter relating to the processing of your personal data or the exercise of your rights:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@morvellianroyalhaven.com |
2. Scope and Application
This Privacy Policy applies to all personal data processed by MorvellianroyalHaven in connection with:
- Visits to and use of the Website, including any bookings, enquiries, or account registrations made online;
- Physical visits to our hotel and casino premises in Canberra, ACT;
- Participation in our loyalty programme, promotions, competitions, or events;
- Casino gaming activities, including the use of electronic gaming machines and table games;
- Correspondence or communications with us by any channel (email, telephone, post, live chat, social media);
- Employment applications and recruitment processes;
- Supplier, vendor, and business partner relationships.
This Policy does not apply to third-party websites, applications, or services that may be linked from our Website. We are not responsible for the privacy practices of those third parties and encourage you to review their respective privacy policies.
3. Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
3.1 Identity and Contact Data
- Full name, title, date of birth, and gender;
- Passport number, driver's licence number, or other government-issued identification number (required for check-in and casino regulatory compliance);
- Nationality and country of residence;
- Postal address, email address, and telephone number(s);
- Emergency contact details (provided voluntarily).
3.2 Reservation and Stay Data
- Booking reference, arrival and departure dates, room type, and special requests;
- Number and ages of guests sharing accommodation;
- Food and beverage preferences, dietary requirements, and accessibility needs;
- Records of services used during your stay (restaurant, spa, parking, concierge, etc.);
- Guest satisfaction survey responses and feedback.
3.3 Financial and Payment Data
- Payment card type, last four digits, expiry date, and billing address;
- Bank account details where direct debit or wire transfer is used;
- Transaction history, invoices, and receipts relating to hotel and casino services;
- Credit checks and financial standing assessments (where applicable and lawfully permitted).
3.4 Casino and Gaming Data
- Player card or loyalty programme membership number;
- Gaming history, wager amounts, wins, losses, and game preferences;
- Self-exclusion records and responsible gambling declarations;
- Mandatory reporting data required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), including threshold transaction reports and suspicious matter reports;
- Know Your Customer (KYC) documentation collected to meet regulatory obligations.
3.5 Technical and Website Usage Data
- IP address, browser type and version, operating system, and device identifiers;
- Pages visited, time spent on pages, links clicked, and referring URL;
- Cookie identifiers and tracking technology data (see Section 10 — Cookies);
- Log files and session data generated during Website use.
3.6 Communications Data
- Content of emails, letters, live chat transcripts, and other correspondence with us;
- Telephone call recordings (where you are informed and consent is obtained or a legitimate interest applies);
- Social media posts, reviews, or messages directed to us on public or private channels.
3.7 Marketing and Preferences Data
- Marketing communication preferences and opt-in/opt-out records;
- Loyalty programme tier, points balance, and redemption history;
- Event attendance records and competition entries.
3.8 CCTV and Security Data
- CCTV footage captured on our premises (hotel public areas, casino floor, car parks, entrances);
- Incident reports, security logs, and access control records.
3.9 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9, including:
- Health data — dietary requirements indicating a medical condition, accessibility needs, or medical emergencies occurring on our premises;
- Biometric data — where used for identity verification in compliance with applicable gaming regulation;
- Data relating to criminal convictions or offences — required for AML/CTF compliance, responsible gambling investigations, or security incident management.
We process special category data only where a specific legal basis under Article 9(2) GDPR applies, such as your explicit consent, vital interests, or the exercise of legal claims. We apply enhanced safeguards to all such data.
3.10 Data Collected from Third Parties
We may receive personal data about you from third-party sources, including:
- Online travel agents and booking platforms (e.g., Booking.com, Expedia);
- Corporate clients making reservations on behalf of their employees;
- Regulatory and law enforcement authorities;
- Credit reference and fraud prevention agencies;
- Publicly available sources such as corporate registers or social media platforms.
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. Pursuant to Article 6 GDPR, the legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This applies to:
- Processing your hotel reservation, check-in, check-out, and billing;
- Delivering the specific hotel and casino services you have requested;
- Managing your loyalty programme membership and associated benefits;
- Handling complaints or service requests directly related to your booking.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary to comply with a legal obligation to which we are subject under Australian or applicable international law. This includes:
- Verification of identity for check-in under applicable hotel and gaming legislation;
- AML/CTF obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth);
- Responsible gambling obligations under ACT gaming legislation, including the Gaming Machine Act 2004 (ACT);
- Tax reporting and record-keeping obligations under the Income Tax Assessment Act 1997 (Cth) and GST legislation;
- Mandatory disclosure to regulatory authorities (AUSTRAC, ACT Gambling and Racing Commission, etc.);
- Workplace health and safety obligations;
- Responding to lawful requests from law enforcement agencies.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on this basis for:
- Operating and improving our Website, including fraud detection and network security;
- CCTV surveillance on our premises for security and crime prevention purposes;
- Managing and resolving disputes, complaints, and legal claims;
- Conducting anonymised data analytics to enhance guest experience and operational efficiency;
- Sending service-related communications, such as post-stay satisfaction surveys;
- Maintaining accurate business records and ensuring continuity of operations;
- Conducting due diligence on business partners and suppliers.
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) and concluded that our interests are not overridden by your rights. You may request a summary of our LIA by contacting us at the details in Section 12.
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent, we will always ask for it clearly and separately before collecting or using your data for that specific purpose. Consent-based processing includes:
- Sending direct marketing emails, SMS, or push notifications about offers, promotions, and news;
- Placing non-essential cookies and tracking technologies on your device (see Section 10);
- Processing special category data for purposes not otherwise permitted by law.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at privacy@morvellianroyalhaven.com or use the unsubscribe link in any marketing communication.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another person — for example, sharing medical information with emergency services if you suffer a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
Where we carry out tasks in the public interest or in the exercise of official authority — for example, cooperating with government-mandated responsible gambling programmes — we may rely on this legal basis.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Providing Hotel and Hospitality Services
- Processing and confirming reservations, managing check-in and check-out procedures;
- Allocating rooms and fulfilling special requests (accessibility requirements, dietary needs, etc.);
- Providing in-house services including dining, spa, concierge, and valet parking;
- Issuing invoices, processing payments, and managing billing disputes;
- Responding to guest enquiries, complaints, and service requests.
5.2 Casino and Gaming Operations
- Verifying the identity and eligibility of players in accordance with gaming legislation;
- Administering player accounts, loyalty points, and gaming activity records;
- Implementing responsible gambling tools, including voluntary and mandatory self-exclusion programmes;
- Detecting and preventing fraud, cheating, money laundering, and other financial crime;
- Fulfilling mandatory AML/CTF reporting obligations to AUSTRAC and other regulators.
5.3 Marketing and Personalisation
- Sending you direct marketing communications about special offers, packages, events, and news (where you have consented or where permitted by applicable law);
- Personalising your Website experience and tailoring offers based on your preferences and history;
- Administering loyalty programme rewards, competitions, and promotions.
5.4 Security and Safety
- Operating CCTV surveillance systems for the safety of guests, staff, and assets;
- Managing access control to restricted areas of the premises;
- Investigating security incidents, theft, damage, or suspicious activity;
- Cooperating with law enforcement agencies on criminal investigations.
5.5 Legal and Regulatory Compliance
- Meeting obligations imposed by gambling regulators, tax authorities, financial intelligence units, and other government agencies;
- Retaining records as required by law (see Section 8 — Data Retention);
- Defending or pursuing legal claims;
- Conducting internal audits and compliance reviews.
5.6 Business Improvement and Analytics
- Analysing Website usage patterns to improve functionality and user experience;
- Conducting market research and satisfaction surveys;
- Generating aggregated and anonymised statistical reports for internal business planning.
6. How We Share Your Personal Data
We do not sell your personal data. We may share your personal data with the following categories of recipients only to the extent necessary and in accordance with applicable law:
6.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions, subject to written data processing agreements:
- Cloud computing and IT infrastructure providers;
- Payment processing and banking services;
- Property Management System (PMS) and casino management system providers;
- Email marketing and CRM platform providers;
- Website analytics and advertising technology providers;
- CCTV system operators and security contractors;
- Printing, mailing, and archiving services;
- Legal, accounting, and auditing advisers.
6.2 Regulatory and Law Enforcement Authorities
We are required by law to share certain personal data with:
- AUSTRAC (Australian Transaction Reports and Analysis Centre) for AML/CTF reporting;
- ACT Gambling and Racing Commission and other gaming regulators;
- The Australian Taxation Office (ATO);
- Australian Federal Police (AFP), Australian Capital Territory Policing (ACTP), and other law enforcement agencies upon lawful request;
- Courts, tribunals, and judicial bodies in connection with legal proceedings.
6.3 Online Travel Agents and Booking Platforms
Where your booking was made through an online travel agent (OTA) or third-party booking platform, we may share limited booking confirmation and communication data with that platform for fulfilment purposes.
6.4 Corporate Clients
Where you are travelling as a guest of a corporate client, we may share relevant stay information (e.g., billing details) with that corporate client in accordance with their agreement with us.
6.5 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant prospective or actual acquirer. We will notify you of any such transfer where required by law.
6.6 International Transfers
Some of our service providers may be located outside Australia or the European Economic Area. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- The recipient country having been deemed to provide an adequate level of protection;
- Binding Corporate Rules (where applicable);
- Your explicit consent (in limited circumstances).
You may request details of specific safeguards applicable to international transfers by contacting our DPO at privacy@morvellianroyalhaven.com.
7. Automated Decision-Making and Profiling
We may use automated processing, including profiling, for the following limited purposes:
- Fraud and AML risk scoring — automated systems may flag unusual payment patterns or gaming activity for human review;
- Responsible gambling monitoring — algorithms may identify patterns consistent with problem gambling behaviour, which are then reviewed by a trained responsible gambling officer;
- Website personalisation — your browsing and booking history may be used to display relevant offers and content.
We do not make solely automated decisions that produce significant legal effects or similarly significant impacts on you without human involvement. Where automated processing is used as a preliminary step, a qualified member of our staff always reviews the outcome before any action is taken. You have the right to object to profiling in certain circumstances — see Section 9 (Your Rights).
8. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected and to comply with our legal, regulatory, and contractual obligations. Our standard retention periods are as follows:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from check-out date | Tax and accounting obligations; limitation periods for contractual claims |
| Payment and financial transaction records | 7 years from date of transaction | Corporations Act 2001 (Cth); Income Tax Assessment Act 1997 (Cth) |
| AML/CTF records (KYC, transaction reports) | 7 years from date of transaction or end of business relationship | Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), s. 106 |
| Casino gaming records and player accounts | 7 years from date of last gaming activity | Gaming Machine Act 2004 (ACT) and associated regulations |
| Self-exclusion records | Duration of exclusion plus 7 years | Gaming regulation; responsible gambling obligations |
| CCTV footage (general areas) | 31 days unless required for an investigation | Legitimate interests (security); proportionality |
| CCTV footage (casino floor) | As required by gaming licence conditions (typically up to 31 days or longer if flagged) | Regulatory requirement under gaming legislation |
| Marketing preferences and consent records | Until withdrawn plus 3 years | Accountability and evidence of consent (GDPR Article 7(1)) |
| Website cookies and analytics data | As per individual cookie lifespan (up to 24 months); see Cookie Policy | Consent; legitimate interests |
| Recruitment and application data (unsuccessful candidates) | 12 months from date of application unless consent given for longer | Legitimate interests; consent |
| Employee records | Duration of employment plus 7 years | Employment legislation; tax obligations |
| Incident and security reports | 7 years from date of incident | Legitimate interests; legal claims limitation periods |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data retention and destruction procedures. Where data is subject to a legal hold (e.g., pending litigation or regulatory investigation), it will be retained for the duration of that hold.
9. Your Rights Under Applicable Data Protection Law
Depending on your location and the applicable legal framework, you may have the following rights with respect to your personal data. We are committed to facilitating the exercise of these rights promptly and transparently.
9.1 Right of Access (Article 15 GDPR / APP 12)
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with information about how it is used, where it comes from, with whom it is shared, and how long it is kept.
9.2 Right to Rectification (Article 16 GDPR / APP 13)
You have the right to request that we correct inaccurate personal data or complete incomplete personal data we hold about you without undue delay.
9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data where: the data is no longer necessary for the purpose for which it was collected; you withdraw consent (where consent was the legal basis); you successfully object to processing; or the data has been unlawfully processed. This right is subject to exemptions, including where retention is required by law or for legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while the accuracy of data is being verified, or where you have objected to processing and we are assessing the merits of that objection.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have it transmitted directly to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object to processing of your personal data where we rely on legitimate interests (Article 6(1)(f)) or where processing is for direct marketing purposes. Where you object to direct marketing, we will cease processing for that purpose immediately. Where you object to processing based on legitimate interests, we will cease unless we can demonstrate compelling legitimate grounds that override your interests.
9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces significant legal or similarly significant effects. As noted in Section 7, we ensure human involvement in all consequential decisions.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, contact us at privacy@morvellianroyalhaven.com or use the unsubscribe mechanism in marketing communications.
9.9 Rights Under the Australian Privacy Act 1988
If you are located in Australia, you also have the right to:
- Access personal information we hold about you (APP 12);
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13);
- Make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Australian Privacy Principles.
9.10 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to:
- Email: privacy@morvellianroyalhaven.com
- Post: The Data Protection Officer, ,
We will respond to your request within 30 days of receipt. This period may be extended by a further two months where the request is complex or numerous requests have been received; we will notify you of any such extension within the initial 30-day period. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive.
9.11 Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data or your rights request, you have the right to lodge a complaint with the relevant supervisory authority:
-
Australia: Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Telephone: 1300 363 992 - European Economic Area: The supervisory authority in your EU member state of habitual residence or place of work.
-
United Kingdom: Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
We would, however, welcome the opportunity to address your concerns directly before you approach a regulator. Please contact our DPO in the first instance.
11. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest (AES-256 or equivalent);
- Role-based access controls and multi-factor authentication for systems containing personal data;
- Regular vulnerability assessments, penetration testing, and security audits;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures compliant with the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act 1988 and GDPR Article 33/34;
- Physical security controls at our premises, including access management and CCTV.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (and you, where required) within the timeframes prescribed by applicable law — generally within 72 hours of becoming aware of the breach under the GDPR, and as soon as practicable under the NDB scheme.
12. Children's Privacy
Our Website and casino services are not directed at children under the age of 18. We do not knowingly collect personal data from individuals under the age of 18. Casino access is restricted to persons aged 18 and over in accordance with the Gaming Machine Act 2004 (ACT) and applicable gambling legislation.
If you are a parent or guardian and believe that a child under 18 has provided us with personal data without your consent, please contact us immediately at privacy@morvellianroyalhaven.com and we will take steps to delete that data promptly.
13. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us using the details below:
| Data Controller | |
|---|---|
| Contact Person | The Data Protection Officer |
| privacy@morvellianroyalhaven.com | |
| Postal Address | |
| Website | morvellianroyalhaven.com |
We aim to acknowledge all privacy-related correspondence within 5 business days and to resolve substantive matters within 30 calendar days, unless greater complexity requires additional time (in which case we will keep you informed).
14. Updates to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in our data processing practices, applicable legislation, regulatory guidance, or business operations. The date of the most recent revision is displayed at the top of this page.
Where changes are material — that is, where they significantly affect your rights or the way we process your personal data — we will notify you by email (if we hold your email address) and/or by placing a prominent notice on our Website prior to the changes taking effect. We encourage you to review this Policy regularly.
Continued use of our Website or services after the effective date of any updated Privacy Policy constitutes your acknowledgement of the revised terms, to the extent permitted by applicable law.
15. Glossary
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person ("data subject"), as defined under GDPR Article 4(1) and the Australian Privacy Act 1988. |
| Processing | Any operation performed on personal data, whether automated or manual, including collection, recording, storage, use, disclosure, erasure, or destruction. |
| Data Controller | The entity that determines the purposes and means of processing personal data — in this case, . |
| Data Processor | A third party that processes personal data on behalf of and under the instructions of a controller. |
| Special Category Data | Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, or data concerning sex life or sexual orientation, as defined in GDPR Article 9. |
| GDPR | General Data Protection Regulation (EU) 2016/679. |
| APP | Australian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988 (Cth). |
| AML/CTF | Anti-Money Laundering and Counter-Terrorism Financing. |
| AUSTRAC | Australian Transaction Reports and Analysis Centre, Australia's financial intelligence agency and AML/CTF regulator. |
| DPO | Data Protection Officer — the individual responsible for overseeing data protection compliance within our organisation. |
| Cookie | A small text file stored on your device by a website you visit, used to remember information about you. |