Privacy Policy

Last updated: June 2025

This Privacy Policy explains how ("we", "us", "our", or the "Hotel-Casino") collects, uses, stores, shares, and protects personal data of visitors to our website serelihotelinsight.com, guests, and any other individuals who interact with our services. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR (where applicable), and all other relevant data protection laws.

Please read this Privacy Policy carefully before using our website or services. By continuing to use our website, making a reservation, or otherwise engaging with us, you acknowledge that you have read and understood the contents of this policy.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name serelihotel Insight
Registered Address
Country of Registration New Zealand
Company Registration Number 9429051234567
VAT / Tax Number 143-856-921
Website serelihotelinsight.com
Privacy Contact Email privacy@serelihotelinsight.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee our data protection practices and to act as a point of contact for all data protection matters.

DPO Title The Data Protection Officer
Organisation
Postal Address
Email privacy@serelihotelinsight.com

You may contact our DPO at any time regarding any aspect of this Privacy Policy or the processing of your personal data.

3. Scope and Applicability

This Privacy Policy applies to:

  • All visitors to our website serelihotelinsight.com;
  • Individuals who make room, table, or event reservations with us, whether online, by telephone, or in person;
  • Hotel guests who check in at serelihotel Insight, Wellington;
  • Casino patrons and gaming participants;
  • Attendees of events, conferences, or functions hosted at our premises;
  • Individuals who contact us for customer service or general enquiries;
  • Subscribers to our newsletter or promotional communications;
  • Loyalty programme members;
  • Job applicants and prospective employees;
  • Business partners, suppliers, and contractors.

This policy does not apply to personal data processed in connection with the employment relationship of our existing staff, which is governed by a separate internal employee privacy notice.

4. Personal Data We Collect

We collect and process various categories of personal data depending on the nature of your interaction with us. Below we describe the categories of data we may collect.

4.1 Identity and Contact Data

  • Full name (first name, last name, title);
  • Date of birth and age verification information;
  • Gender (where voluntarily provided);
  • Nationality and country of residence;
  • Government-issued identification document details (passport number, national ID, driving licence — required by law for hotel check-in and casino compliance);
  • Postal and billing address;
  • Email address;
  • Telephone and mobile number.

4.2 Reservation and Stay Data

  • Booking reference numbers and dates;
  • Check-in and check-out dates and times;
  • Room type and accommodation preferences;
  • Number and details of accompanying guests;
  • Special requests (e.g. accessibility requirements, dietary preferences);
  • Purpose of visit (business or leisure).

4.3 Financial and Payment Data

  • Payment card type, last four digits, and expiry date;
  • Billing information and invoicing records;
  • Transaction history and amounts;
  • Bank account details (where bank transfer is used);
  • Records of casino credits, chips, and winnings where required by regulation.

Please note: Full payment card numbers are processed exclusively by our certified Payment Card Industry Data Security Standard (PCI-DSS) compliant payment processor and are never stored on our own servers.

4.4 Casino and Gaming Data

As a hotel-casino, we are subject to strict regulatory obligations in respect of gaming activities. We collect and process:

  • Age verification and identity documents to confirm you are of legal gaming age;
  • Player registration and casino membership information;
  • Gaming activity records (games played, duration, wager amounts, winnings and losses) as required by gaming regulations;
  • Self-exclusion requests and responsible gambling records;
  • Anti-Money Laundering (AML) compliance records, including source of funds information where legally required;
  • Politically Exposed Person (PEP) and sanctions screening results.

4.5 Website and Technical Data

  • IP address and approximate geolocation derived from IP;
  • Browser type and version;
  • Operating system and device type;
  • Pages visited, time spent on each page, and navigation paths;
  • Referring URL and exit pages;
  • Cookie identifiers and similar tracking data (see our separate Cookie Policy);
  • Session identifiers and log-in timestamps.

4.6 Marketing and Communications Data

  • Marketing preferences and communication opt-in/opt-out records;
  • Records of email opens, clicks, and unsubscribes;
  • Survey responses and feedback form submissions;
  • Loyalty programme tier and points balance.

4.7 Security and Premises Data

  • Closed-circuit television (CCTV) footage captured on our premises, including casino floor, lobby, corridors, and car park;
  • Access control records (key card entry and exit logs);
  • Incident and accident reports.

4.8 Special Categories of Personal Data

We may, in limited circumstances, process special categories of personal data as defined under Article 9 GDPR, including:

  • Health and disability data: Where you request accessibility services, medical facilities, or inform us of a health condition relevant to your stay or participation in gaming, we will process this information solely to fulfil your request or comply with our duty of care;
  • Responsible gambling data: Information about self-exclusion or problem gambling that may be inferred from gaming behaviour, processed for compliance with gaming regulations and the protection of your welfare.

We will only process special category data where we have a valid legal basis under Article 9(2) GDPR, such as your explicit consent, or where processing is necessary for reasons of substantial public interest in the context of gambling harm prevention, or for vital interests.

4.9 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies and booking platforms (e.g. Booking.com, Expedia);
  • Travel agents and corporate travel management companies;
  • Payment processors and fraud prevention services;
  • Identity verification and AML screening providers;
  • Public databases and sanctions lists (for AML/KYC compliance);
  • Analytics providers (in aggregated or pseudonymised form).

6. How We Use Your Personal Data

We use the personal data we collect for the following specific purposes:

6.1 Reservations and Guest Services

  • To process, confirm, and manage hotel room bookings and related services;
  • To communicate booking confirmations, amendments, and pre-arrival information;
  • To verify your identity on check-in and register your stay as required by law;
  • To personalise your stay based on your preferences and prior visit history;
  • To arrange transportation, dining reservations, concierge services, and other amenities you request.

6.2 Casino and Gaming Operations

  • To register you as a casino patron and verify your eligibility to participate in gaming activities;
  • To manage your casino account, player card, credits, and winnings;
  • To comply with legal obligations relating to gaming regulation, AML, and KYC;
  • To implement and record self-exclusion requests and responsible gambling measures;
  • To monitor gaming activity for fraud, cheating, and regulatory compliance purposes.

6.3 Payment Processing and Financial Management

  • To process payments for all goods and services provided;
  • To issue invoices, receipts, and statements;
  • To manage billing disputes and refunds;
  • To comply with accounting and tax record retention obligations.

6.4 Security and Safety

  • To operate CCTV systems for the security of guests, staff, and our premises;
  • To prevent, detect, and investigate theft, fraud, and other unlawful activity;
  • To manage access to restricted areas of our premises;
  • To ensure health and safety compliance.

6.5 Marketing and Loyalty

  • To send you promotional offers, newsletters, and information about our services and events (subject to your preferences and applicable law);
  • To manage your participation in our loyalty programme and communicate points, tier status, and rewards;
  • To conduct market research and customer satisfaction surveys;
  • To display relevant advertising on third-party platforms (subject to your consent where required).

6.6 Website and Digital Services

  • To operate, maintain, and improve our website and online booking system;
  • To analyse website traffic and user behaviour for performance optimisation;
  • To manage online accounts and user profiles;
  • To detect and prevent technical attacks, unauthorised access, and data breaches.

6.7 Legal and Compliance

  • To comply with all applicable legal, regulatory, and governmental obligations;
  • To establish, exercise, or defend legal claims;
  • To respond to enquiries from law enforcement and regulatory authorities;
  • To conduct internal audits and compliance reviews.

7. How We Share Your Personal Data

We respect the confidentiality of your personal data and will not sell, rent, or trade your personal data to third parties for their own marketing purposes without your explicit consent. However, we may share your personal data with the following categories of recipients in accordance with the purposes and legal bases described in this Privacy Policy.

7.1 Service Providers and Data Processors

We engage trusted third-party companies to provide services on our behalf. These processors are contractually bound to process personal data only on our documented instructions and in accordance with GDPR requirements. They include:

  • Payment processing and PCI-DSS compliant transaction service providers;
  • Hotel Property Management System (PMS) software providers;
  • Online booking engine and channel management platforms;
  • Casino management system providers;
  • Identity verification and AML/KYC screening service providers;
  • IT infrastructure, cloud hosting, and cybersecurity providers;
  • Email marketing and CRM platform providers;
  • Analytics and website performance tool providers;
  • CCTV monitoring and security service providers;
  • Customer satisfaction survey platforms.

7.2 Business Partners and Distribution Channels

When you make a reservation through a third-party platform, certain data will be shared with or received from:

  • Online travel agencies (OTAs) and global distribution systems (GDS);
  • Corporate travel management companies;
  • Event organisers and conference booking agents;
  • Restaurant and spa booking partners.

7.3 Regulatory and Government Authorities

We are legally required to share certain personal data with:

  • New Zealand Department of Internal Affairs and gaming regulatory bodies;
  • New Zealand Police and law enforcement agencies, upon lawful request;
  • Inland Revenue (New Zealand tax authority) for tax compliance purposes;
  • Immigration New Zealand, as required for visitor registration;
  • Financial Intelligence Unit (FIU) under AML/CFT reporting obligations;
  • Courts and tribunals, in connection with legal proceedings;
  • Other regulatory bodies as required by applicable law.

7.4 Professional Advisers

We may share personal data with our legal advisers, auditors, accountants, and insurers where necessary for the conduct of their professional services.

7.5 Corporate Transactions

In the event of a merger, acquisition, sale of assets, or other corporate restructuring, personal data held by us may be transferred to the relevant successor entity, subject to that entity assuming the obligations of this Privacy Policy or providing equivalent protections.

7.6 International Data Transfers

Some of our service providers and partners may be located outside of New Zealand and the European Economic Area (EEA). Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the European Commission or a relevant New Zealand authority;
  • Standard Contractual Clauses (SCCs) approved by the European Commission (Module 2 or Module 3 as applicable);
  • Binding Corporate Rules (BCRs) where applicable;
  • Other approved transfer mechanisms under applicable data protection law.

You may request further information about international transfer safeguards by contacting our DPO at privacy@serelihotelinsight.com.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in accordance with applicable legal, regulatory, accounting, and reporting obligations. The following retention periods apply as a general guide:

Category of Data Retention Period Basis / Reason
Hotel guest registration records 7 years from date of stay Legal obligation (hospitality and tax regulations)
Reservation and booking records 7 years from date of stay Legal obligation and contractual purposes
Financial and payment records 7 years from the end of the relevant financial year Legal obligation (New Zealand Companies Act, tax law)
Casino player registration and gaming records 7 years from last gaming activity Legal obligation (gaming regulations, AML/CFT)
AML/KYC compliance records 5–7 years from end of business relationship Legal obligation (AML/CFT Act)
Self-exclusion and responsible gambling records Duration of exclusion plus 7 years Legal obligation and legitimate interests
CCTV footage 31 days (standard); extended if required for an investigation Legitimate interests (security)
Marketing preferences and consent records Until withdrawal of consent or 3 years from last interaction Consent / legitimate interests
Website analytics data 26 months Legitimate interests
Customer service correspondence 3 years from resolution of the enquiry Legitimate interests (dispute resolution)
Job applications (unsuccessful) 12 months from decision Legitimate interests

At the end of the applicable retention period, personal data will be securely deleted, anonymised, or otherwise destroyed in accordance with our data disposal procedures. Where data is retained in anonymised or aggregated form, it will no longer be treated as personal data and may be retained indefinitely for statistical purposes.

9. Your Rights Under GDPR

Subject to applicable law and certain conditions and exceptions, you have the following rights in respect of your personal data. These rights apply where we process your data in a manner that engages GDPR or equivalent data protection legislation.

9.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation from us as to whether or not we process personal data about you, and, where we do, to access that personal data together with supplementary information including the purposes of processing, categories of data processed, recipients, retention periods, and the existence of your other rights.

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct inaccurate personal data concerning you without undue delay. Taking into account the purposes of processing, you also have the right to have incomplete personal data completed, including by providing a supplementary statement.

9.3 Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)

You have the right to request that we erase your personal data without undue delay in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and there is no other legal basis for processing, or where you successfully object to processing. This right is subject to certain exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, while we verify that accuracy.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

9.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where it is based on our legitimate interests (Article 6(1)(f)) or on public interest grounds (Article 6(1)(e)), on grounds relating to your particular situation. We will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time and we will stop processing for that purpose immediately.

9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently make solely automated decisions that produce legal effects. Where we engage in any form of profiling for marketing personalisation, you retain the right to object as described above.

9.8 Right to Withdraw Consent

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal. To withdraw consent, please contact us at privacy@serelihotelinsight.com or use the unsubscribe mechanism in any marketing communication.

9.9 Exercising Your Rights

To exercise any of the rights listed above, please submit a written request to us:

We will respond to your request within one calendar month of receipt. Where a request is complex or we have received a high volume of requests, we may extend this period by a further two months, in which case we will inform you of the extension within one month of receipt of your request, together with the reasons for the delay.

We do not generally charge a fee for responding to requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.

We may need to verify your identity before we can respond to your request. We may ask you to provide one or more pieces of identifying information to confirm your identity.

9.10 Right to Lodge a Complaint

If you are located in the European Economic Area or the United Kingdom and you believe that we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement. In the UK, the relevant authority is the Information Commissioner's Office (ICO).

If you are located in New Zealand, you may contact the Office of the Privacy Commissioner at www.privacy.org.nz.

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact our DPO at privacy@serelihotelinsight.com in the first instance.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to operate effectively, analyse usage, and deliver personalised content and advertising. By using our website, you consent to our use of cookies in accordance with our Cookie Policy, except where cookies are strictly necessary for the operation of our website, in which case no consent is required.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our website, including session management and security features. These cannot be disabled.
  • Functional Cookies: Enable enhanced functionality and personalisation, such as remembering your preferences and log-in details.
  • Analytics and Performance Cookies: Allow us to measure and improve the performance of our website by collecting information about how visitors use it (e.g. pages visited, error messages).
  • Marketing and Advertising Cookies: Used to deliver targeted advertisements and to measure the effectiveness of marketing campaigns. These are only placed with your consent.

You can manage your cookie preferences at any time through the cookie consent banner on our website or through your browser settings. Please note that disabling certain cookies may affect the functionality of our website and your user experience.

For full details of the cookies we use, their purposes, durations, and the third parties who may set cookies through our website, please refer to our separate Cookie Policy, available on our website.

11. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encryption of personal data in transit using TLS/SSL protocols;
  • Encryption of sensitive data at rest;
  • Role-based access controls, ensuring that personal data is accessible only to authorised staff who require it for their job functions;
  • Regular security testing, vulnerability assessments, and penetration testing;
  • Firewalls, intrusion detection systems, and endpoint protection;
  • Staff training on data protection and information security;
  • Contractual data processing agreements with all third-party processors;
  • A documented data breach response and notification procedure.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and in accordance with our obligations under Article 34 GDPR.

Please note that no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data using commercially acceptable means, we cannot guarantee its absolute security.

12. Children's Privacy

Our casino gaming services are strictly restricted to individuals who are of legal gambling age in accordance with the laws of New Zealand. Our website is not directed at children under the age of 18, and we do not knowingly collect personal data from anyone under this age.

Hotel accommodation services may be provided to families with children; however, the personal data of children accompanying guests will only be collected where strictly necessary (for example, for room allocation or safety purposes) and will be processed in accordance with this Privacy Policy. A parent or legal guardian must provide any necessary consent on behalf of a minor.

If you believe that we have inadvertently collected personal data relating to a child without appropriate parental consent, please contact us immediately at privacy@serelihotelinsight.com and we will take steps to delete such data promptly.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or by a prominent notice on our website prior to the changes taking effect.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes to this Privacy Policy will constitute your acknowledgement of the revised policy.

All previous versions of this Privacy Policy are available upon request by contacting our DPO.

15. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below.

Data Controller
Trading as serelihotel Insight
Attn The Data Protection Officer
Postal Address
Email privacy@serelihotelinsight.com
Website serelihotelinsight.com

We are committed to working with you to resolve any concerns about your personal data in a fair and transparent manner.