Privacy Policy
Last updated: June 2025
This Privacy Policy explains how ("we", "us", "our", or the "Hotel-Casino") collects, uses, stores, shares, and protects personal data of visitors to our website serelihotelinsight.com, guests, and any other individuals who interact with our services. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR (where applicable), and all other relevant data protection laws.
Please read this Privacy Policy carefully before using our website or services. By continuing to use our website, making a reservation, or otherwise engaging with us, you acknowledge that you have read and understood the contents of this policy.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | serelihotel Insight |
| Registered Address | |
| Country of Registration | New Zealand |
| Company Registration Number | 9429051234567 |
| VAT / Tax Number | 143-856-921 |
| Website | serelihotelinsight.com |
| Privacy Contact Email | privacy@serelihotelinsight.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection practices and to act as a point of contact for all data protection matters.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@serelihotelinsight.com |
You may contact our DPO at any time regarding any aspect of this Privacy Policy or the processing of your personal data.
3. Scope and Applicability
This Privacy Policy applies to:
- All visitors to our website serelihotelinsight.com;
- Individuals who make room, table, or event reservations with us, whether online, by telephone, or in person;
- Hotel guests who check in at serelihotel Insight, Wellington;
- Casino patrons and gaming participants;
- Attendees of events, conferences, or functions hosted at our premises;
- Individuals who contact us for customer service or general enquiries;
- Subscribers to our newsletter or promotional communications;
- Loyalty programme members;
- Job applicants and prospective employees;
- Business partners, suppliers, and contractors.
This policy does not apply to personal data processed in connection with the employment relationship of our existing staff, which is governed by a separate internal employee privacy notice.
4. Personal Data We Collect
We collect and process various categories of personal data depending on the nature of your interaction with us. Below we describe the categories of data we may collect.
4.1 Identity and Contact Data
- Full name (first name, last name, title);
- Date of birth and age verification information;
- Gender (where voluntarily provided);
- Nationality and country of residence;
- Government-issued identification document details (passport number, national ID, driving licence — required by law for hotel check-in and casino compliance);
- Postal and billing address;
- Email address;
- Telephone and mobile number.
4.2 Reservation and Stay Data
- Booking reference numbers and dates;
- Check-in and check-out dates and times;
- Room type and accommodation preferences;
- Number and details of accompanying guests;
- Special requests (e.g. accessibility requirements, dietary preferences);
- Purpose of visit (business or leisure).
4.3 Financial and Payment Data
- Payment card type, last four digits, and expiry date;
- Billing information and invoicing records;
- Transaction history and amounts;
- Bank account details (where bank transfer is used);
- Records of casino credits, chips, and winnings where required by regulation.
Please note: Full payment card numbers are processed exclusively by our certified Payment Card Industry Data Security Standard (PCI-DSS) compliant payment processor and are never stored on our own servers.
4.4 Casino and Gaming Data
As a hotel-casino, we are subject to strict regulatory obligations in respect of gaming activities. We collect and process:
- Age verification and identity documents to confirm you are of legal gaming age;
- Player registration and casino membership information;
- Gaming activity records (games played, duration, wager amounts, winnings and losses) as required by gaming regulations;
- Self-exclusion requests and responsible gambling records;
- Anti-Money Laundering (AML) compliance records, including source of funds information where legally required;
- Politically Exposed Person (PEP) and sanctions screening results.
4.5 Website and Technical Data
- IP address and approximate geolocation derived from IP;
- Browser type and version;
- Operating system and device type;
- Pages visited, time spent on each page, and navigation paths;
- Referring URL and exit pages;
- Cookie identifiers and similar tracking data (see our separate Cookie Policy);
- Session identifiers and log-in timestamps.
4.6 Marketing and Communications Data
- Marketing preferences and communication opt-in/opt-out records;
- Records of email opens, clicks, and unsubscribes;
- Survey responses and feedback form submissions;
- Loyalty programme tier and points balance.
4.7 Security and Premises Data
- Closed-circuit television (CCTV) footage captured on our premises, including casino floor, lobby, corridors, and car park;
- Access control records (key card entry and exit logs);
- Incident and accident reports.
4.8 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 GDPR, including:
- Health and disability data: Where you request accessibility services, medical facilities, or inform us of a health condition relevant to your stay or participation in gaming, we will process this information solely to fulfil your request or comply with our duty of care;
- Responsible gambling data: Information about self-exclusion or problem gambling that may be inferred from gaming behaviour, processed for compliance with gaming regulations and the protection of your welfare.
We will only process special category data where we have a valid legal basis under Article 9(2) GDPR, such as your explicit consent, or where processing is necessary for reasons of substantial public interest in the context of gambling harm prevention, or for vital interests.
4.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g. Booking.com, Expedia);
- Travel agents and corporate travel management companies;
- Payment processors and fraud prevention services;
- Identity verification and AML screening providers;
- Public databases and sanctions lists (for AML/KYC compliance);
- Analytics providers (in aggregated or pseudonymised form).
5. Legal Basis for Processing
We only process your personal data where we have a lawful basis to do so under Article 6 GDPR. The applicable legal bases for our processing activities are set out below.
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. Examples include:
- Processing your reservation and managing your hotel stay;
- Processing payments for accommodation, dining, and other services;
- Providing casino gaming services in accordance with your membership or player registration;
- Administering loyalty programme membership and associated benefits;
- Responding to pre-booking enquiries.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where this is necessary to comply with a legal obligation to which we are subject, including:
- Verification of identity and age upon hotel check-in as required by New Zealand immigration and hospitality regulations;
- Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations under applicable gaming and financial crime prevention laws;
- Retention of financial and accounting records for statutory periods;
- Reporting obligations to gaming regulators, tax authorities, and law enforcement agencies;
- Compliance with responsible gambling legislation, including self-exclusion register obligations;
- Health and safety obligations;
- Responding to lawful requests from courts or regulatory authorities.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is necessary for the purposes of our legitimate interests or those of a third party, provided that your fundamental rights and freedoms do not override those interests. Our legitimate interests include:
- Ensuring the security of our premises, assets, guests, and staff through CCTV surveillance and access control;
- Preventing and detecting fraud, cheating, and criminal activity on our premises and in relation to our online services;
- Improving the quality of our services and website through analytics;
- Sending direct marketing communications about our services to existing customers (where permitted under applicable law and subject to your right to opt out);
- Managing and resolving disputes, complaints, and legal claims;
- Conducting customer satisfaction surveys;
- Network and information security management.
You have the right to object to processing based on legitimate interests. Please see Section 9 (Your Rights) for details.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will ask you to provide that consent clearly and unambiguously before processing commences. Consent-based processing includes:
- Sending you marketing emails, SMS, or other communications where you are not an existing customer;
- Placing non-essential cookies and similar tracking technologies on your device (see our Cookie Policy);
- Processing special category health data for purposes beyond your immediate service request;
- Sharing your data with selected third-party partners for their own marketing purposes.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@serelihotelinsight.com.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person. This would typically apply in medical emergencies occurring on our premises.
5.6 Public Interest (Article 6(1)(e) GDPR)
We may process personal data where this is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. This may apply, for example, in relation to our obligations to report suspicious transactions to relevant authorities under anti-money laundering law.
6. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
6.1 Reservations and Guest Services
- To process, confirm, and manage hotel room bookings and related services;
- To communicate booking confirmations, amendments, and pre-arrival information;
- To verify your identity on check-in and register your stay as required by law;
- To personalise your stay based on your preferences and prior visit history;
- To arrange transportation, dining reservations, concierge services, and other amenities you request.
6.2 Casino and Gaming Operations
- To register you as a casino patron and verify your eligibility to participate in gaming activities;
- To manage your casino account, player card, credits, and winnings;
- To comply with legal obligations relating to gaming regulation, AML, and KYC;
- To implement and record self-exclusion requests and responsible gambling measures;
- To monitor gaming activity for fraud, cheating, and regulatory compliance purposes.
6.3 Payment Processing and Financial Management
- To process payments for all goods and services provided;
- To issue invoices, receipts, and statements;
- To manage billing disputes and refunds;
- To comply with accounting and tax record retention obligations.
6.4 Security and Safety
- To operate CCTV systems for the security of guests, staff, and our premises;
- To prevent, detect, and investigate theft, fraud, and other unlawful activity;
- To manage access to restricted areas of our premises;
- To ensure health and safety compliance.
6.5 Marketing and Loyalty
- To send you promotional offers, newsletters, and information about our services and events (subject to your preferences and applicable law);
- To manage your participation in our loyalty programme and communicate points, tier status, and rewards;
- To conduct market research and customer satisfaction surveys;
- To display relevant advertising on third-party platforms (subject to your consent where required).
6.6 Website and Digital Services
- To operate, maintain, and improve our website and online booking system;
- To analyse website traffic and user behaviour for performance optimisation;
- To manage online accounts and user profiles;
- To detect and prevent technical attacks, unauthorised access, and data breaches.
6.7 Legal and Compliance
- To comply with all applicable legal, regulatory, and governmental obligations;
- To establish, exercise, or defend legal claims;
- To respond to enquiries from law enforcement and regulatory authorities;
- To conduct internal audits and compliance reviews.
7. How We Share Your Personal Data
We respect the confidentiality of your personal data and will not sell, rent, or trade your personal data to third parties for their own marketing purposes without your explicit consent. However, we may share your personal data with the following categories of recipients in accordance with the purposes and legal bases described in this Privacy Policy.
7.1 Service Providers and Data Processors
We engage trusted third-party companies to provide services on our behalf. These processors are contractually bound to process personal data only on our documented instructions and in accordance with GDPR requirements. They include:
- Payment processing and PCI-DSS compliant transaction service providers;
- Hotel Property Management System (PMS) software providers;
- Online booking engine and channel management platforms;
- Casino management system providers;
- Identity verification and AML/KYC screening service providers;
- IT infrastructure, cloud hosting, and cybersecurity providers;
- Email marketing and CRM platform providers;
- Analytics and website performance tool providers;
- CCTV monitoring and security service providers;
- Customer satisfaction survey platforms.
7.2 Business Partners and Distribution Channels
When you make a reservation through a third-party platform, certain data will be shared with or received from:
- Online travel agencies (OTAs) and global distribution systems (GDS);
- Corporate travel management companies;
- Event organisers and conference booking agents;
- Restaurant and spa booking partners.
7.3 Regulatory and Government Authorities
We are legally required to share certain personal data with:
- New Zealand Department of Internal Affairs and gaming regulatory bodies;
- New Zealand Police and law enforcement agencies, upon lawful request;
- Inland Revenue (New Zealand tax authority) for tax compliance purposes;
- Immigration New Zealand, as required for visitor registration;
- Financial Intelligence Unit (FIU) under AML/CFT reporting obligations;
- Courts and tribunals, in connection with legal proceedings;
- Other regulatory bodies as required by applicable law.
7.4 Professional Advisers
We may share personal data with our legal advisers, auditors, accountants, and insurers where necessary for the conduct of their professional services.
7.5 Corporate Transactions
In the event of a merger, acquisition, sale of assets, or other corporate restructuring, personal data held by us may be transferred to the relevant successor entity, subject to that entity assuming the obligations of this Privacy Policy or providing equivalent protections.
7.6 International Data Transfers
Some of our service providers and partners may be located outside of New Zealand and the European Economic Area (EEA). Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision from the European Commission or a relevant New Zealand authority;
- Standard Contractual Clauses (SCCs) approved by the European Commission (Module 2 or Module 3 as applicable);
- Binding Corporate Rules (BCRs) where applicable;
- Other approved transfer mechanisms under applicable data protection law.
You may request further information about international transfer safeguards by contacting our DPO at privacy@serelihotelinsight.com.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in accordance with applicable legal, regulatory, accounting, and reporting obligations. The following retention periods apply as a general guide:
| Category of Data | Retention Period | Basis / Reason |
|---|---|---|
| Hotel guest registration records | 7 years from date of stay | Legal obligation (hospitality and tax regulations) |
| Reservation and booking records | 7 years from date of stay | Legal obligation and contractual purposes |
| Financial and payment records | 7 years from the end of the relevant financial year | Legal obligation (New Zealand Companies Act, tax law) |
| Casino player registration and gaming records | 7 years from last gaming activity | Legal obligation (gaming regulations, AML/CFT) |
| AML/KYC compliance records | 5–7 years from end of business relationship | Legal obligation (AML/CFT Act) |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 7 years | Legal obligation and legitimate interests |
| CCTV footage | 31 days (standard); extended if required for an investigation | Legitimate interests (security) |
| Marketing preferences and consent records | Until withdrawal of consent or 3 years from last interaction | Consent / legitimate interests |
| Website analytics data | 26 months | Legitimate interests |
| Customer service correspondence | 3 years from resolution of the enquiry | Legitimate interests (dispute resolution) |
| Job applications (unsuccessful) | 12 months from decision | Legitimate interests |
At the end of the applicable retention period, personal data will be securely deleted, anonymised, or otherwise destroyed in accordance with our data disposal procedures. Where data is retained in anonymised or aggregated form, it will no longer be treated as personal data and may be retained indefinitely for statistical purposes.
9. Your Rights Under GDPR
Subject to applicable law and certain conditions and exceptions, you have the following rights in respect of your personal data. These rights apply where we process your data in a manner that engages GDPR or equivalent data protection legislation.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation from us as to whether or not we process personal data about you, and, where we do, to access that personal data together with supplementary information including the purposes of processing, categories of data processed, recipients, retention periods, and the existence of your other rights.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct inaccurate personal data concerning you without undue delay. Taking into account the purposes of processing, you also have the right to have incomplete personal data completed, including by providing a supplementary statement.
9.3 Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)
You have the right to request that we erase your personal data without undue delay in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and there is no other legal basis for processing, or where you successfully object to processing. This right is subject to certain exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, while we verify that accuracy.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where it is based on our legitimate interests (Article 6(1)(f)) or on public interest grounds (Article 6(1)(e)), on grounds relating to your particular situation. We will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time and we will stop processing for that purpose immediately.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently make solely automated decisions that produce legal effects. Where we engage in any form of profiling for marketing personalisation, you retain the right to object as described above.
9.8 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal. To withdraw consent, please contact us at privacy@serelihotelinsight.com or use the unsubscribe mechanism in any marketing communication.
9.9 Exercising Your Rights
To exercise any of the rights listed above, please submit a written request to us:
- By email: privacy@serelihotelinsight.com
- By post: The Data Protection Officer, ,
We will respond to your request within one calendar month of receipt. Where a request is complex or we have received a high volume of requests, we may extend this period by a further two months, in which case we will inform you of the extension within one month of receipt of your request, together with the reasons for the delay.
We do not generally charge a fee for responding to requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
We may need to verify your identity before we can respond to your request. We may ask you to provide one or more pieces of identifying information to confirm your identity.
9.10 Right to Lodge a Complaint
If you are located in the European Economic Area or the United Kingdom and you believe that we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement. In the UK, the relevant authority is the Information Commissioner's Office (ICO).
If you are located in New Zealand, you may contact the Office of the Privacy Commissioner at www.privacy.org.nz.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact our DPO at privacy@serelihotelinsight.com in the first instance.
11. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:
- Encryption of personal data in transit using TLS/SSL protocols;
- Encryption of sensitive data at rest;
- Role-based access controls, ensuring that personal data is accessible only to authorised staff who require it for their job functions;
- Regular security testing, vulnerability assessments, and penetration testing;
- Firewalls, intrusion detection systems, and endpoint protection;
- Staff training on data protection and information security;
- Contractual data processing agreements with all third-party processors;
- A documented data breach response and notification procedure.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and in accordance with our obligations under Article 34 GDPR.
Please note that no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data using commercially acceptable means, we cannot guarantee its absolute security.
12. Children's Privacy
Our casino gaming services are strictly restricted to individuals who are of legal gambling age in accordance with the laws of New Zealand. Our website is not directed at children under the age of 18, and we do not knowingly collect personal data from anyone under this age.
Hotel accommodation services may be provided to families with children; however, the personal data of children accompanying guests will only be collected where strictly necessary (for example, for room allocation or safety purposes) and will be processed in accordance with this Privacy Policy. A parent or legal guardian must provide any necessary consent on behalf of a minor.
If you believe that we have inadvertently collected personal data relating to a child without appropriate parental consent, please contact us immediately at privacy@serelihotelinsight.com and we will take steps to delete such data promptly.
13. Third-Party Websites and Links
Our website may contain links to third-party websites, including booking platforms, social media pages, and partner services. This Privacy Policy applies solely to our website and our processing activities. We are not responsible for the privacy practices of third-party websites, and we encourage you to review the privacy policies of any third-party site you visit. The inclusion of a link on our website does not constitute our endorsement of that third party's privacy practices.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or by a prominent notice on our website prior to the changes taking effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes to this Privacy Policy will constitute your acknowledgement of the revised policy.
All previous versions of this Privacy Policy are available upon request by contacting our DPO.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below.
| Data Controller | |
|---|---|
| Trading as | serelihotel Insight |
| Attn | The Data Protection Officer |
| Postal Address | |
| privacy@serelihotelinsight.com | |
| Website | serelihotelinsight.com |
We are committed to working with you to resolve any concerns about your personal data in a fair and transparent manner.