Privacy Policy
Last updated: June 2025
Welcome to Lavenohotel Insight (hereinafter referred to as "we", "us", or "our"). We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website lavenohotelinsight.com, make a reservation, use our hotel-casino services, or interact with us in any other way.
Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please discontinue use of our website and services.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Trading Name | Lavenohotel Insight |
| Registration Country | New Zealand |
| Company Registration Number | 9482716 |
| VAT / GST Number | NZ 136-428-785 |
| Registered Legal Address | |
| Website | lavenohotelinsight.com |
| Privacy Contact Email | info@lavenohotelinsight.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing matters related to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding your personal data, you may contact our Data Protection Officer directly:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@lavenohotelinsight.com |
3. Personal Data We Collect
We collect various categories of personal data depending on how you interact with us. Personal data means any information relating to an identified or identifiable natural person. The categories of personal data we may collect include:
3.1 Identity and Contact Data
- Full name (first name, last name)
- Date of birth and age verification data
- Gender
- Nationality and country of residence
- Passport, national identity card, or other government-issued identification details
- Email address
- Telephone number(s)
- Postal address (home and/or billing address)
3.2 Reservation and Stay Data
- Booking reference numbers and reservation history
- Check-in and check-out dates
- Room type preferences and special requests
- Number of guests and accompanying persons
- Details of services and amenities used during your stay
- Loyalty programme membership information
- Guest satisfaction surveys and feedback
3.3 Financial and Payment Data
- Credit and debit card details (processed via secure third-party payment processors)
- Bank account information where applicable
- Transaction history and billing records
- Invoices and receipts
- Casino gaming account balance and transaction history
3.4 Casino and Gaming Data
- Casino membership and player account details
- Gaming activity, betting history, and wagering records
- Self-exclusion status and responsible gambling declarations
- Age verification documents and records
- Anti-money laundering (AML) and Know Your Customer (KYC) documentation
- Source of funds declarations where legally required
- Winnings, jackpot records, and prize claims
3.5 Technical and Usage Data
- IP address and device identifiers
- Browser type, version, and language settings
- Operating system and platform
- Pages visited, links clicked, and time spent on pages
- Referring URLs and exit pages
- Session duration and interaction logs
- Cookie identifiers and similar tracking technologies (see our Cookie Policy)
3.6 Communications Data
- Records of correspondence, including emails, letters, and online chat transcripts
- Customer service enquiry records and complaint histories
- Marketing preferences and opt-in/opt-out records
- Social media interactions where you contact us via social platforms
3.7 Special Categories of Personal Data
In certain limited circumstances, we may process special categories of personal data as defined under GDPR Article 9. This may include:
- Health and dietary requirements or accessibility needs (where voluntarily provided for the purpose of tailoring your hotel stay)
- Information relating to problem gambling or self-exclusion linked to health considerations
We only process such sensitive data where we have obtained your explicit consent, or where processing is necessary to fulfil a legal obligation, or where it is necessary to protect your vital interests or those of another person, in accordance with GDPR Article 9(2).
3.8 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia)
- Payment service providers and fraud prevention agencies
- Credit reference and identity verification agencies
- Regulatory bodies for AML and KYC compliance purposes
- Social media platforms when you interact with our pages or use social login features
- Analytics and advertising partners
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so under GDPR Article 6. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay
- Creating and managing your casino membership or player account
- Processing payments for accommodation, dining, and gaming services
- Providing customer support and responding to your service requests
- Administering loyalty programme membership and rewards
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing obligations
- Know Your Customer (KYC) and age verification requirements under gambling legislation
- Tax and accounting obligations including retention of financial records
- Regulatory reporting to gaming authorities and financial regulators
- Compliance with court orders, law enforcement requests, and legal proceedings
- Health and safety obligations during your stay on our premises
4.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where those interests are overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Preventing fraud, cheating, and security incidents at the hotel and casino
- Improving and personalising our services, website, and user experience
- Conducting analytics and business intelligence to develop our offerings
- Sending service-related communications and updates about your booking
- Administering and protecting our business, IT systems, and network security
- Operating and monitoring CCTV systems for premises security and crime prevention
- Handling and resolving complaints and legal claims
- Direct marketing to existing customers regarding similar products and services (subject to your right to opt out at any time)
4.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will always ask for your explicit and freely given consent before processing your data for that specific purpose. This includes:
- Sending promotional marketing communications, newsletters, and special offers via email, SMS, or other channels
- Placing non-essential cookies and tracking technologies on your device
- Processing special category data such as health or dietary information not strictly necessary for contractual purposes
- Sharing your data with selected third-party partners for their marketing purposes
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at info@lavenohotelinsight.com or use the unsubscribe link provided in our marketing communications.
4.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another person, for example, in a medical emergency during your stay at our hotel.
4.6 Public Task (Article 6(1)(e))
Where applicable, we may process personal data in connection with the exercise of official authority vested in us or in performance of a task carried out in the public interest, such as cooperation with regulatory inspections or mandatory reporting obligations under gaming law.
5. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
5.1 Hotel and Accommodation Services
- Processing, confirming, and managing hotel reservations
- Facilitating check-in and check-out procedures
- Arranging room preferences, special requests, and accessibility requirements
- Providing concierge, dining, spa, and other in-hotel services
- Issuing invoices and processing payments for accommodation and ancillary services
5.2 Casino and Gaming Services
- Creating and maintaining your casino player account
- Verifying your identity and age for legal compliance
- Processing gaming transactions, bets, and winnings
- Administering responsible gambling tools including deposit limits and self-exclusion
- Conducting AML and KYC checks as required by law
- Detecting and preventing cheating, fraud, and money laundering
5.3 Customer Relationship and Support
- Responding to your enquiries, requests, and complaints
- Providing customer support via telephone, email, and live chat
- Sending booking confirmations, reminders, and post-stay follow-up communications
- Administering our loyalty and rewards programme
- Conducting guest satisfaction surveys to improve service quality
5.4 Marketing and Communications
- Sending marketing emails, promotional offers, and newsletters where you have provided consent or where we have a legitimate interest to do so
- Personalising marketing content based on your preferences and booking history
- Running prize draws, competitions, and promotional campaigns
- Retargeting advertisements on third-party platforms with your consent
5.5 Security and Fraud Prevention
- Operating CCTV and access control systems across hotel and casino premises
- Monitoring for suspicious gambling activity or potential fraud
- Verifying the identity of persons accessing restricted areas
- Cooperating with law enforcement and regulatory investigations
5.6 Legal and Regulatory Compliance
- Meeting our obligations under applicable gaming, financial, and data protection legislation
- Maintaining required records for tax, audit, and regulatory purposes
- Establishing, exercising, or defending legal claims
5.7 Business Analytics and Improvement
- Analysing website usage and visitor behaviour to improve our online platform
- Conducting internal research to develop new products and services
- Generating anonymised statistical reports for business planning purposes
6. Sharing Your Personal Data
We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients where necessary and lawful:
6.1 Service Providers and Data Processors
We work with trusted third-party companies that process personal data on our behalf and under our instructions as data processors. These include:
- Payment processing and card transaction services
- IT infrastructure, cloud hosting, and cybersecurity providers
- Online booking platforms and reservation management systems
- Email marketing and CRM software providers
- Website analytics and performance monitoring tools
- Identity verification and KYC compliance service providers
- Printing, mailing, and document management services
All processors are bound by data processing agreements requiring them to process personal data only on our documented instructions and to implement appropriate security measures.
6.2 Regulatory Authorities and Law Enforcement
We may disclose personal data to competent authorities where required by law or regulatory obligation, including:
- Gaming and gambling regulatory bodies in New Zealand
- Financial intelligence units and AML regulatory bodies
- Tax authorities (Inland Revenue Department, New Zealand)
- Police and law enforcement agencies
- Courts and judicial bodies in connection with legal proceedings
6.3 Business Partners
- Travel agents and online booking platforms that facilitate reservations on our behalf
- Co-branded loyalty programme partners where you have enrolled in joint programmes
- Insurance providers in connection with claims relevant to your stay
6.4 Professional Advisers
We may share data with lawyers, accountants, auditors, and other professional advisers where necessary in connection with legal, financial, or regulatory matters, subject to appropriate confidentiality obligations.
6.5 Corporate Transactions
In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, personal data held by us may be transferred to the successor entity. We will notify you before any such transfer takes place if it materially affects your data.
6.6 International Data Transfers
Some of our service providers and partners may be located outside New Zealand and the European Economic Area (EEA). When we transfer personal data internationally, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V, including:
- Transfers to countries with an adequacy decision by the European Commission
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Other appropriate safeguards as permitted under applicable data protection law
You may request a copy of the transfer safeguards we use by contacting us at info@lavenohotelinsight.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The following retention periods apply as a general guide:
| Category of Data | Retention Period | Rationale |
|---|---|---|
| Hotel reservation and stay records | 7 years from date of stay | Legal, tax, and accounting obligations |
| Payment and financial transaction records | 7 years from transaction date | Tax, audit, and regulatory compliance |
| Casino player account data | 7 years from account closure | AML, KYC, and gambling regulatory obligations |
| AML/KYC documentation | 7 years from end of business relationship | Anti-money laundering legislation |
| Customer correspondence and complaints | 3 years from resolution | Legitimate interests and legal claims |
| Marketing preferences and consent records | 3 years from last interaction or withdrawal of consent | Proof of consent and legitimate interests |
| Website usage and analytics data | 26 months from collection | Legitimate interests (website improvement) |
| CCTV footage | 30 days unless required for investigation | Security and crime prevention |
| Self-exclusion records | Duration of exclusion plus 5 years | Responsible gambling obligations |
Where personal data is no longer required, we will securely delete or anonymise it in accordance with our data disposal procedures. In some circumstances, we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such anonymised data without further notice.
8. Your Rights Under GDPR
Under the General Data Protection Regulation and applicable data protection law, you have the following rights in relation to your personal data. We will respond to all legitimate requests within one month of receipt, and will notify you if we need to extend this period.
8.1 Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and, if so, to request a copy of that data (a "Subject Access Request") along with information about how it is processed, the purposes of processing, categories of data, recipients, retention periods, and your applicable rights.
8.2 Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, taking into account the purposes of the processing.
8.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request the deletion of your personal data where one of the following grounds applies: the data is no longer necessary for the purpose for which it was collected; you withdraw consent and there is no other legal basis for processing; you object to processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or the data must be erased to comply with a legal obligation.
Please note that this right is not absolute and may be limited where we are required to retain data for legal, regulatory, or contractual reasons.
8.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, or where you have objected to processing and we are assessing whether our legitimate interests override yours.
8.5 Right to Data Portability (Article 20)
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another data controller where technically feasible.
8.6 Right to Object (Article 21)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as our legal basis. We will cease processing unless we demonstrate compelling legitimate grounds which override your interests, or the processing is for the establishment, exercise, or defence of legal claims.
You have an absolute right to object to processing of your personal data for direct marketing purposes at any time, and we will immediately cease such processing upon receipt of your objection.
8.7 Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we carry out such automated decision-making, we will inform you and provide you with the right to request human review of the decision, to express your point of view, and to contest the decision.
8.8 Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
8.9 How to Exercise Your Rights
To exercise any of the rights described above, please submit your request in writing to:
- Email: info@lavenohotelinsight.com
- Postal Address: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to comply with the request.
8.10 Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with a competent supervisory authority. In New Zealand, the relevant authority is:
- Office of the Privacy Commissioner (OPC)
- Website: privacy.org.nz
- PO Box 10094, Wellington 6143, New Zealand
If you are located in the European Union or the European Economic Area, you may also have the right to lodge a complaint with the supervisory authority in your country of habitual residence or place of work.
10. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- Encryption of data in transit using SSL/TLS protocols
- Encryption of sensitive data at rest
- Access controls and role-based permissions limiting data access to authorised personnel only
- Firewalls, intrusion detection systems, and network monitoring
- Regular security assessments, penetration testing, and vulnerability management
- Staff training on data protection and information security
- Data processing agreements with all third-party processors
- Incident response procedures for data breach management
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, inform affected individuals without undue delay, in accordance with GDPR Articles 33 and 34.
11. Children and Minors
Our hotel and casino services are intended for adults only. We do not knowingly collect personal data from individuals under the age of 18. Our casino gaming services are strictly prohibited to persons under the legal gambling age as set out by New Zealand law.
If we become aware that we have inadvertently collected personal data from a child under 18 without verifiable parental consent, we will take immediate steps to delete that information from our records. If you believe we may hold data about a minor, please contact us at info@lavenohotelinsight.com.
12. Third-Party Websites and Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit.
13. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will post the updated policy on this page with a revised "Last updated" date and, where appropriate, notify you by email or by a prominent notice on our website prior to the change becoming effective.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website and services after any changes constitutes your acknowledgement of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Address | |
| info@lavenohotelinsight.com | |
| Website | lavenohotelinsight.com |
We aim to respond to all privacy-related enquiries and Subject Access Requests within 30 days of receipt. Where requests are complex or numerous, we may extend this period by a further two months, and we will notify you accordingly.