Privacy Policy

Last updated: June 2025

This Privacy Policy explains how ("we", "us", "our") collects, uses, stores, shares, and protects personal data in connection with the website stayauditjournal.com (the "Website"), our hotel and casino services, and any related communications or transactions. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable New Zealand privacy legislation including the Privacy Act 2020, and all other applicable data protection laws.

Please read this Privacy Policy carefully before using our Website or services. By accessing our Website or making a reservation, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for your personal data is:

Legal Entity Name
Trading Name / Website Stayauditjournal.com — stayauditjournal.com
Registration Country New Zealand
Company Registration Number Company No. 8539174
GST / VAT Number GST No. 129-583-746
Registered Address
Privacy Email privacy@stayauditjournal.com

As the data controller, determines the purposes and means by which your personal data is processed. We are accountable for ensuring that all processing activities meet the requirements of applicable data protection legislation.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:

Title The Data Protection Officer
Organisation
Postal Address
Email Address privacy@stayauditjournal.com

3. Personal Data We Collect

Depending on how you interact with our Website and services, we may collect and process the following categories of personal data:

3.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth (required for age verification for casino services)
  • Gender (where voluntarily provided)
  • Nationality and passport or national identity document details (required for hotel registration under applicable law)
  • Postal address, billing address, and correspondence address
  • Email address
  • Telephone and mobile phone numbers

3.2 Reservation and Stay Data

  • Booking reference numbers and reservation details
  • Check-in and check-out dates
  • Room type and preferences (bed type, floor, smoking preferences, accessibility requirements)
  • Number of guests and names of accompanying guests
  • Special requests and dietary requirements
  • Loyalty programme membership details
  • Previous stay history and records of services used during your stay

3.3 Financial and Payment Data

  • Credit card and debit card details (card number, expiry date, security code — processed through PCI-DSS compliant payment gateways)
  • Bank account details where applicable
  • Billing history, invoices, and transaction records
  • Deposit and incidental charge information

3.4 Casino and Gaming Data

  • Proof of age and identity documents for mandatory age verification
  • Gaming activity, history, and transaction records as required by applicable gambling regulations
  • Self-exclusion requests and responsible gaming declarations
  • Anti-money laundering (AML) and Know Your Customer (KYC) documentation
  • Source of funds declarations where required by law
  • Winnings and losses records as required by applicable regulations

3.5 Technical and Usage Data

  • Internet Protocol (IP) address
  • Browser type and version
  • Device type, operating system, and device identifiers
  • Time zone setting and geographic location data
  • Pages visited on our Website, time spent on pages, and navigation paths
  • Referring URLs and exit pages
  • Website errors and crash reports

3.6 Cookie and Tracking Data

  • Cookie identifiers and session tokens
  • Analytics data collected via cookies and similar technologies
  • Advertising identifiers and marketing attribution data
  • User preferences stored in cookies

3.7 Communications Data

  • Content of emails, letters, live chat, and other communications sent to or received from us
  • Customer service enquiry records
  • Feedback, reviews, and survey responses
  • Complaints and dispute records

3.8 Marketing and Preferences Data

  • Marketing communication preferences and opt-in/opt-out records
  • Interests and preferences inferred from booking history and service usage
  • Participation in promotional events, competitions, and loyalty programmes

3.9 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR. These include:

  • Health and dietary information: where you voluntarily provide details of allergies, dietary requirements, or accessibility needs to facilitate your stay or dining experience
  • Biometric data: facial recognition data collected via CCTV systems in the casino area where required by law for security and fraud prevention purposes

We process special category data only where we have obtained your explicit consent, where processing is necessary for reasons of substantial public interest under applicable law, or where another lawful basis under Article 9 GDPR applies.

3.10 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies (OTAs) and booking platforms through which you made a reservation (e.g., Booking.com, Expedia, Hotels.com)
  • Travel agents or tour operators acting on your behalf
  • Payment processors and fraud prevention agencies
  • Publicly available sources such as social media profiles (where you have interacted with us on social media)
  • Credit reference agencies and sanctions screening providers
  • Regulatory authorities as required by applicable law

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Hotel Services

  • Processing, confirming, and managing hotel reservations made directly or through third-party booking platforms
  • Facilitating check-in and check-out procedures
  • Providing in-room and on-site services including dining, spa, room service, concierge services, and other amenities
  • Processing payments, issuing invoices, and managing billing disputes
  • Managing your loyalty programme account and administering rewards and benefits
  • Communicating with you before, during, and after your stay (including pre-arrival information, during-stay assistance, and post-stay follow-up)
  • Accommodating special requests, accessibility needs, and dietary requirements

5.2 Casino and Gaming Services

  • Verifying your identity and age before granting access to casino facilities as required by law
  • Conducting AML/KYC checks as required by applicable regulations
  • Recording gaming transactions and activity as required by gaming and regulatory authorities
  • Administering responsible gambling programmes, including processing self-exclusion requests and monitoring for signs of problem gambling
  • Preventing and detecting fraud, cheating, and other irregular activity within the casino
  • Complying with reporting obligations to gaming regulators

5.3 Security and Safety

  • Operating CCTV and video surveillance systems throughout the hotel and casino premises for the safety and security of guests, staff, and assets
  • Conducting investigations into incidents, theft, fraud, or misconduct
  • Enforcing our terms and conditions and house rules
  • Providing information to law enforcement authorities where required or permitted by law

5.4 Marketing and Communications

  • Sending you promotional offers, special packages, newsletters, and other marketing materials where you have consented or where permitted by applicable law
  • Personalising marketing communications based on your preferences, stay history, and interests
  • Conducting customer satisfaction surveys, feedback requests, and market research
  • Managing competitions, promotions, and prize draws
  • Running targeted advertising campaigns on third-party platforms (subject to your consent preferences for cookies and tracking technologies)

5.5 Website and Technology Management

  • Operating, maintaining, and improving our Website and online booking systems
  • Monitoring Website performance, diagnosing technical errors, and ensuring cybersecurity
  • Conducting analytics to understand user behaviour and improve website usability
  • Implementing and managing cookie preferences and consent management

5.6 Legal and Compliance

  • Complying with our legal and regulatory obligations under New Zealand law and applicable international law
  • Maintaining records required by tax, accounting, and financial reporting obligations
  • Responding to regulatory investigations, audits, and requests from authorities
  • Establishing, exercising, or defending legal claims
  • Conducting internal audits and risk assessments

6. Cookies and Similar Tracking Technologies

Our Website uses cookies and similar technologies (such as web beacons, pixel tags, and local storage) to collect technical and usage data. Cookies are small text files placed on your device when you visit our Website.

6.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Website to function properly. They enable basic features such as page navigation, access to secure areas, and the online booking process. These cookies do not require your consent.
  • Functional Cookies: Allow us to remember your preferences and settings (such as language, currency, and login details) to provide a more personalised experience.
  • Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous information about pages visited, time spent on the site, and navigation paths. We use tools such as Google Analytics for this purpose.
  • Marketing and Advertising Cookies: Used to track visitors across websites and display relevant advertisements based on your browsing history and interests. These cookies require your prior consent.

6.2 Managing Your Cookie Preferences

When you first visit our Website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time by clicking the "Cookie Settings" link available in the footer of our Website.

You can also manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. For more information about managing cookies, please visit www.allaboutcookies.org.

7. How We Share Your Personal Data

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients in the circumstances described below:

7.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:

  • Payment processors and banking institutions: to process credit and debit card payments securely
  • Cloud hosting and IT infrastructure providers: to host our Website, reservation systems, and business applications
  • Booking platform and channel management providers: to manage reservations made through OTAs and other distribution channels
  • Email and marketing automation providers: to send transactional and marketing emails
  • Customer relationship management (CRM) system providers
  • Analytics and reporting tools providers (e.g., Google Analytics)
  • CCTV and security system operators
  • AML/KYC compliance and identity verification providers
  • Legal, accounting, and auditing firms

All service providers are contractually obligated to process your personal data only in accordance with our instructions and applicable data protection law, and to implement appropriate technical and organisational security measures.

7.2 Online Travel Agencies and Booking Platforms

If you made your reservation through an online travel agency or booking platform, we may share limited booking-related data with that platform for the purposes of confirming your reservation, managing changes or cancellations, and processing payments.

7.3 Regulatory and Law Enforcement Authorities

We may disclose your personal data to regulatory authorities, government agencies, law enforcement bodies, or courts where we are required to do so by law or in response to a lawful request. This includes, but is not limited to:

  • The New Zealand Police and other law enforcement agencies
  • The Department of Internal Affairs (DIA) as the gambling regulatory authority in New Zealand
  • The Financial Intelligence Unit (FIU) and other AML authorities
  • Inland Revenue (IRD) for tax compliance purposes
  • Immigration New Zealand for guest registration purposes
  • Any court, tribunal, or arbitration body in connection with legal proceedings

7.4 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction involving , your personal data may be transferred to the relevant third party as part of that transaction. We will ensure that any such transfer is subject to appropriate confidentiality and data protection obligations. We will notify you of any such transfer where required by applicable law.

7.5 Professional Advisors

We may share your personal data with our lawyers, accountants, auditors, and other professional advisors where necessary for them to provide professional services to us, subject to binding confidentiality obligations.

7.6 With Your Consent

We may share your personal data with third parties where you have provided your explicit consent to do so, for example, when enrolling in a third-party loyalty or rewards programme.

8. International Transfers of Personal Data

is based in New Zealand. Some of our service providers and technology partners are located outside New Zealand and the European Economic Area (EEA). When we transfer your personal data to countries that may not provide the same level of data protection as New Zealand or the EEA, we ensure that appropriate safeguards are in place to protect your data.

These safeguards may include:

  • Transfers to countries that have been recognised as providing an adequate level of data protection by the European Commission or the New Zealand Privacy Commissioner
  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our contracts with third-party processors
  • Binding Corporate Rules where applicable
  • Other legally approved transfer mechanisms under applicable data protection law

You may request a copy of the safeguards we have put in place for international transfers by contacting our DPO at privacy@stayauditjournal.com.

9. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, and reporting obligations. The criteria we use to determine retention periods include:

  • The nature and sensitivity of the personal data
  • The purpose for which the data was collected and whether that purpose has been fulfilled
  • Applicable legal and regulatory retention obligations
  • Whether the data is needed to establish, exercise, or defend legal claims
  • Industry best practice and guidance from data protection authorities

9.1 Indicative Retention Periods

Category of Data Indicative Retention Period Legal Basis / Reason
Hotel reservation and stay records 7 years from date of stay Legal obligation (tax and accounting law); legitimate interests (legal claims)
Financial and payment records 7 years from date of transaction Legal obligation (Inland Revenue, Companies Act, financial regulations)
Casino and gaming records 7 years or as required by gambling regulation Legal obligation (Gaming regulations, AML/CTF Act)
AML/KYC identity verification records 5–7 years from end of business relationship Legal obligation (Anti-Money Laundering and Countering Financing of Terrorism Act 2009)
CCTV footage 30–90 days unless required for an investigation Legitimate interests (security); legal obligation where under investigation
Guest correspondence and complaints 3 years from date of communication Legitimate interests (quality assurance, legal claims)
Marketing consent records 3 years from date of last interaction or consent withdrawal Legal obligation (demonstrating compliance with consent obligations)
Website analytics data 26 months (or as configured in analytics tools) Legitimate interests (website performance and improvement)
Cookie consent records 1 year from date of consent Legal obligation (demonstrating compliance)

Where your personal data is no longer required, we will securely delete, destroy, or anonymise it in accordance with our data retention and disposal procedures. Anonymised data (which can no longer identify you) may be retained indefinitely for statistical and analytical purposes.

10. Your Rights Under GDPR and Applicable Data Protection Law

Depending on your location and the applicable data protection law, you have the following rights in relation to your personal data. We will respond to all valid requests within one month of receipt, unless the request is complex or you have made multiple requests, in which case we may extend this period by a further two months (with prior notification to you).

10.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that personal data together with information about how it is processed. This is known as a Subject Access Request (SAR).

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct inaccurate personal data or complete incomplete personal data held about you without undue delay.

10.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request the deletion or removal of your personal data where there is no compelling reason for us to continue processing it. This right applies in the following circumstances:

  • The personal data is no longer necessary for the purpose for which it was collected
  • You withdraw consent and there is no other lawful basis for processing
  • You object to the processing and there are no overriding legitimate grounds
  • The personal data has been unlawfully processed
  • The personal data must be erased to comply with a legal obligation

Please note that this right is not absolute and may be overridden by our legal obligations (for example, our obligation to retain financial records for tax purposes).

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, if you contest the accuracy of the data or have objected to processing pending verification of our legitimate grounds.

10.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

10.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests or public task as the legal basis. You also have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, without giving any reason. We will cease processing your data for direct marketing purposes upon receipt of your objection.

10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we do conduct automated decision-making or profiling, we will inform you accordingly and you may request human review of any such decision.

10.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent, please contact us at privacy@stayauditjournal.com or use the opt-out mechanism provided in any marketing communication.

10.9 How to Exercise Your Rights

To exercise any of the rights set out above, please submit a written request to our Data Protection Officer:

We may need to verify your identity before processing your request to ensure we do not disclose personal data to an unauthorised party. We will not charge a fee for handling your request unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to comply (we will notify you of either).

10.10 Right to Lodge a Complaint with a Supervisory Authority

If you are located in the European Union or EEA and you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the relevant supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

If you are located in New Zealand and believe we have breached the Privacy Act 2020, you have the right to make a complaint to the Office of the Privacy Commissioner of New Zealand:

  • Website: www.privacy.org.nz
  • Phone: 0800 803 909
  • Post: PO Box 10094, The Terrace, Wellington 6143, New Zealand

We encourage you to contact us in the first instance before making a formal complaint so that we have the opportunity to address your concerns directly.

11. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Our security measures include:

  • Encryption of personal data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest
  • Access controls and role-based permissions restricting access to personal data on a need-to-know basis
  • Regular security assessments, penetration testing, and vulnerability management
  • Staff training on data protection and cybersecurity awareness
  • Incident response and data breach notification procedures
  • PCI-DSS compliant payment processing systems
  • Regular backups and business continuity measures

Despite our best efforts, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your personal data transmitted to our Website. Any transmission of personal data is at your own risk. Once we receive your personal data, we apply strict security procedures and controls to prevent unauthorised access.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Articles 33 and 34 GDPR.

13. Children's Privacy

Our Website and services are not directed at children under the age of 18. We do not knowingly collect personal data from children under 18. Casino and gaming services are strictly restricted to adults of the minimum legal gambling age as required by applicable New Zealand law. If we become aware that we have inadvertently collected personal data from a child under 18 without appropriate parental consent, we will take steps to delete that data promptly.

If you believe that we may have collected personal data from or about a child, please contact us immediately at privacy@stayauditjournal.com.

14. Responsible Gambling and Data Processing

As a hotel-casino operator, we are required by law and our gaming licence conditions to process certain personal data in connection with responsible gambling obligations. This includes:

  • Recording and honouring voluntary self-exclusion requests from guests who wish to be excluded from casino facilities
  • Maintaining records of self-excluded individuals to prevent them from accessing gaming facilities
  • Monitoring gaming activity to identify patterns that may indicate problem gambling behaviour, as required by regulatory guidelines
  • Training staff to identify and support guests who may be experiencing gambling-related harm

Processing of personal data for responsible gambling purposes is based on our legal obligations under applicable gaming and gambling regulations and, where applicable, the vital interests of the individuals concerned. Self-exclusion records will be retained for the duration specified by applicable gaming regulations.

15. Changes to This Privacy Policy

We review and update this Privacy Policy periodically to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes to this Privacy Policy, we will:

  • Update the "Last updated" date at the top of this Privacy Policy
  • Post the revised Privacy Policy on our Website
  • Where required by law or where changes are significant, notify you directly by email or through a prominent notice on our Website

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after any changes have been posted constitutes your acceptance of the updated Privacy Policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us:

Data Controller
Contact Person The Data Protection Officer
Postal Address
Email Address privacy@stayauditjournal.com
Website www.stayauditjournal.com

We are committed to working with you to resolve any concerns you may have about the way in which we process your personal data. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 10.10 above.