Privacy Policy

Last updated: June 2025

Welcome to Ravessianluxecourt (the "Hotel-Casino"), operated by ("we", "us", or "our"). We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation. This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our website at ravessianluxecourt.com (the "Website"), make a reservation, use our hotel or casino services, or otherwise interact with us.

Please read this Privacy Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please discontinue use of our Website and services immediately.

1. Data Controller

The entity responsible for your personal data (the "Data Controller") is:

Registered Company Name
Trading Name Ravessianluxecourt
Registration Country New Zealand
Company Number Company No. 9148263
GST Number GST No. 172-846-395
Registered Address
Website ravessianluxecourt.com
Privacy Contact Email privacy@ravessianluxecourt.com

As the Data Controller, we determine the purposes and means of processing your personal data. We are accountable for ensuring that all processing activities comply with applicable data protection laws, including the GDPR where it applies to individuals located in the European Economic Area (EEA) or the United Kingdom (UK), and the New Zealand Privacy Act 2020 for all other individuals.

2. Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring our compliance with data protection laws. You may contact our DPO directly regarding any matter relating to the processing of your personal data or the exercise of your rights:

Name / Title The Data Protection Officer
Organisation
Address
Email privacy@ravessianluxecourt.com

3. Scope of This Policy

This Privacy Policy applies to:

  • Visitors and users of the Website at ravessianluxecourt.com, including any subdomains or associated pages;
  • Guests who make reservations for hotel accommodation, dining, spa, or other amenities, whether online, by telephone, or in person;
  • Casino patrons and participants in any gaming activities operated on our premises;
  • Members of any loyalty, rewards, or membership programmes administered by us;
  • Individuals who contact us via email, telephone, social media, or any other channel;
  • Job applicants, contractors, suppliers, and business partners to the extent that their data is processed in connection with our operations.

This policy does not apply to third-party websites, services, or applications that may be linked from our Website. We encourage you to review the privacy policies of any third-party sites you visit.

4. Personal Data We Collect

We collect personal data from you directly, from third parties (such as booking platforms and payment processors), and automatically through your use of our Website. The categories of personal data we may collect include the following:

4.1 Identity and Contact Data

  • Full name, title, and date of birth;
  • Gender (where voluntarily provided);
  • Postal address, email address, and telephone number(s);
  • Passport number, national identity card number, or other government-issued identification details (required for hotel check-in and casino regulatory compliance);
  • Nationality and country of residence;
  • Signature (where applicable for registration purposes).

4.2 Reservation and Stay Data

  • Booking reference numbers and reservation details;
  • Check-in and check-out dates;
  • Room type, preferences, and special requests;
  • Length of stay and number of guests;
  • Details of services used during your stay (dining, spa, gym, etc.);
  • Dietary requirements and accessibility needs (which may constitute special category data — see Section 4.7);
  • Loyalty programme membership details and booking history.

4.3 Financial and Payment Data

  • Payment card details (processed securely via PCI-DSS compliant payment processors; we do not store full card numbers);
  • Bank account details (where bank transfer payment is used);
  • Billing address and invoicing information;
  • Transaction history, receipts, and folio records;
  • Deposit and credit information relating to casino gaming activities.

4.4 Casino and Gaming Data

In connection with our casino operations and in compliance with applicable gaming regulations, anti-money laundering (AML) legislation, and responsible gambling obligations, we collect:

  • Proof of identity and age verification documents;
  • Gaming activity records, including wager amounts and game history;
  • Self-exclusion registrations and responsible gambling preferences;
  • Source-of-funds documentation and financial due diligence records as required under AML/CFT compliance obligations;
  • CCTV footage within casino areas (see Section 4.6).

4.5 Communications Data

  • The content of emails, letters, live chat transcripts, and social media messages you send to us;
  • Feedback, reviews, survey responses, and competition entries;
  • Records of your marketing preferences and opt-in/opt-out choices;
  • Customer service records and complaint details.

4.6 Technical and Usage Data

When you visit our Website, we automatically collect certain technical information through cookies and similar tracking technologies, including:

  • IP address and approximate geolocation derived from it;
  • Browser type, version, and operating system;
  • Device identifiers and screen resolution;
  • Pages viewed, links clicked, and time spent on each page;
  • Referring URLs and search terms used to find our Website;
  • Cookie identifiers and session data.

For detailed information about cookies, please refer to our Cookie Policy, available on our Website.

4.7 CCTV and Security Data

We operate closed-circuit television (CCTV) systems throughout our hotel and casino premises for security, fraud prevention, and regulatory compliance purposes. CCTV footage may capture your image and movements within our facilities. Footage is retained for a limited period as set out in Section 9 (Data Retention).

4.8 Special Categories of Personal Data

We may, in limited circumstances, process special categories of personal data as defined under GDPR Article 9. This may include:

  • Health or disability information provided to enable accessible accommodation or services;
  • Dietary information that may reveal religious beliefs or health conditions (e.g., halal, kosher, gluten-free requirements);
  • Information relating to problem gambling or self-exclusion, which may touch upon health or mental wellbeing;
  • Biometric data, where used for security access control purposes (where applicable and where required by law).

We process special category data only where we have an appropriate legal basis to do so, such as your explicit consent (GDPR Article 9(2)(a)), compliance with a legal obligation (Article 9(2)(b)), or where processing is necessary to protect vital interests (Article 9(2)(c)).

4.9 Data Relating to Children

Our Website and services are not directed at children under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age without appropriate parental or guardian consent. Casino gaming activities are strictly restricted to adults aged 20 and over in accordance with New Zealand gaming law. If we become aware that we have collected personal data from a minor without appropriate consent, we will take immediate steps to delete that data.

6. How We Use Your Personal Data

We use your personal data for the following specific purposes, always subject to a lawful legal basis as described in Section 5:

6.1 Reservations and Guest Services

  • Processing, confirming, and managing your accommodation bookings;
  • Providing personalised services during your stay, including room preferences, special requests, and accessibility arrangements;
  • Managing check-in and check-out procedures, including identity verification;
  • Facilitating restaurant reservations, spa appointments, and other ancillary service bookings;
  • Processing payments, issuing invoices and receipts, and managing outstanding balances.

6.2 Casino Operations and Regulatory Compliance

  • Verifying your identity and age before permitting access to gaming activities;
  • Maintaining records of gaming activity as required by gambling regulations;
  • Administering responsible gambling programmes, including self-exclusion registers;
  • Conducting AML/CFT due diligence, including customer due diligence (CDD) and enhanced due diligence (EDD) where required;
  • Reporting suspicious transactions and activities to the Financial Intelligence Unit (FIU) and other relevant authorities.

6.3 Marketing and Communications

  • Sending you promotional offers, special packages, event invitations, and newsletters where you have consented to receive them;
  • Personalising marketing communications based on your preferences and previous interactions with us;
  • Administering loyalty and rewards programmes, including tracking points and sending programme updates;
  • Conducting market research, satisfaction surveys, and feedback requests.

6.4 Security and Fraud Prevention

  • Operating CCTV systems to maintain the safety and security of guests, staff, and property;
  • Detecting and preventing fraud, theft, cheating at gaming tables, and other criminal activity;
  • Investigating incidents, accidents, and complaints occurring on our premises;
  • Protecting the integrity of our IT systems and preventing unauthorised access.

6.5 Website and Service Improvement

  • Analysing Website usage patterns and user behaviour to improve functionality and user experience;
  • Performing testing, troubleshooting, and maintenance of our Website and digital systems;
  • Conducting A/B testing and optimisation of Website content and booking flows.

6.6 Legal and Compliance Purposes

  • Complying with our obligations under applicable laws and regulations;
  • Responding to requests from courts, regulators, and law enforcement authorities;
  • Establishing, exercising, or defending legal claims in connection with our business;
  • Maintaining accurate accounting records and fulfilling our tax obligations.

7. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may, however, share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate safeguards:

7.1 Service Providers and Data Processors

We engage carefully selected third-party service providers ("data processors") who process personal data on our behalf and under our instruction. These include:

  • Payment processors: to securely handle credit and debit card transactions and other payments;
  • Property management system (PMS) providers: to manage hotel reservations, guest profiles, and operational records;
  • Casino management system providers: to support gaming operations, player tracking, and regulatory reporting;
  • Online booking platforms and channel managers: such as third-party reservation systems that process bookings made on your behalf;
  • IT service providers and cloud hosting services: to host our Website, databases, and internal systems securely;
  • Email and communications platforms: to deliver transactional and marketing communications;
  • Analytics providers: to help us understand Website traffic and user behaviour (e.g., Google Analytics, subject to appropriate data processing agreements);
  • Security and CCTV monitoring companies: to assist with on-premises security operations;
  • Loyalty programme administrators: to manage rewards points and member benefits.

All data processors are bound by written data processing agreements requiring them to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to assist us in meeting our data protection obligations.

7.2 Regulatory Authorities and Law Enforcement

We are required by law to share certain personal data with regulatory and government bodies. This includes:

  • The Department of Internal Affairs (DIA), which regulates gambling in New Zealand;
  • The Financial Intelligence Unit (FIU) of the New Zealand Police, in connection with AML/CFT reporting obligations;
  • The Inland Revenue Department (IRD) for tax compliance purposes;
  • New Zealand Police and other law enforcement agencies, where required by law or court order;
  • Any other regulatory or governmental authority with jurisdiction over our operations.

Where we are required by law to share your personal data with authorities, we will do so only to the extent required and, where legally permissible, we will attempt to notify you.

7.3 Professional Advisers

We may share personal data with our legal advisers, accountants, auditors, insurance brokers, and other professional advisers where necessary for the performance of their professional services, subject to duties of confidentiality.

7.4 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceedings involving , your personal data may be transferred to a third party as part of that transaction. We will take reasonable steps to ensure that any such transfer is subject to appropriate confidentiality and data protection safeguards, and we will notify you as required by law.

7.5 International Transfers of Personal Data

Our primary operations are based in New Zealand. However, some of our service providers may be located in countries outside New Zealand, including countries within the European Economic Area (EEA) and other jurisdictions. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place, which may include:

  • Transfers to countries recognised by the European Commission as providing an adequate level of data protection;
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into contracts with our data processors and data recipients;
  • Reliance on binding corporate rules (BCRs) where applicable;
  • Other appropriate safeguards permitted under Chapter V of the GDPR.

New Zealand has been recognised by the European Commission as providing an adequate level of protection for personal data. Where transfers occur to other third countries, we take additional steps to ensure an equivalent level of protection is maintained. You may request a copy of the relevant safeguards by contacting us at privacy@ravessianluxecourt.com.

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data; the potential risk of harm from unauthorised use or disclosure; the purposes for which we process the data; whether we can achieve those purposes through other means; and applicable legal requirements.

8.1 Retention Periods by Data Category

Category of Data Retention Period Reason
Hotel reservation and guest records 7 years from the date of stay Legal obligation (tax, GST, accounting compliance)
Financial and payment records 7 years from the date of transaction Tax Act requirements and financial regulatory compliance
Casino gaming and player records 7 years from the date of gaming activity (or as required by applicable gambling regulations) Gambling Act 2003 (NZ) and AML/CFT Act 2009 (NZ)
AML/CFT due diligence records 5 years from the end of the business relationship or the date of the transaction AML and Countering Financing of Terrorism Act 2009 (NZ)
Self-exclusion and responsible gambling records Duration of the exclusion period plus 5 years Legal and regulatory gaming obligations
CCTV footage (standard areas) 31 days Security purposes; overwritten unless required for an investigation
CCTV footage (casino floor) Up to 15 days or as required by the Department of Internal Affairs Gambling regulatory compliance
Marketing preferences and consent records Until you withdraw consent or object, plus 3 years thereafter Proof of consent and legitimate interests
Website usage data and cookies Session cookies: deleted upon browser close; persistent cookies: up to 24 months (see Cookie Policy) Website functionality and analytics
Customer service records and complaints 3 years from the resolution of the matter Legitimate interests; potential legal claims
Employment and contractor records 7 years after termination of employment or contract Employment law and tax compliance

At the end of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with you. Where data cannot be immediately deleted due to technical constraints (e.g., backup systems), it will be isolated from active processing until deletion is possible.

9. How We Protect Your Personal Data

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of personal data in transit using Transport Layer Security (TLS) technology across our Website and communications;
  • Encryption of sensitive personal data at rest within our systems;
  • Role-based access controls ensuring that only authorised personnel have access to personal data relevant to their duties;
  • Multi-factor authentication for access to sensitive internal systems;
  • Regular security assessments, penetration testing, and vulnerability scanning of our IT infrastructure;
  • Staff training and awareness programmes on data protection and information security;
  • Data processing agreements with all third-party processors imposing security obligations;
  • Physical security measures at our premises, including restricted access zones and CCTV surveillance;
  • Incident response procedures to detect, investigate, and report personal data breaches in accordance with GDPR Article 33 and 34 obligations.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, will notify you directly.

While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is entirely secure. If you believe your data has been compromised, please contact us immediately at privacy@ravessianluxecourt.com.

10. Your Data Protection Rights

Subject to applicable data protection law, you have the following rights in relation to your personal data. We will respond to all legitimate requests within one month of receipt, free of charge. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you.

10.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how it is processed. This is known as a Subject Access Request (SAR). We will provide you with a copy of your personal data in a commonly used electronic format, unless you request otherwise.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will take reasonable steps to verify the accuracy of any correction requested.

10.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purpose for which it was collected;
  • You withdraw your consent and there is no other lawful basis for processing;
  • You object to processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • Erasure is required to comply with a legal obligation.

Please note that this right is not absolute. We may be required to retain certain data to comply with our legal obligations (e.g., AML/CFT records, tax records) or to establish, exercise, or defend legal claims.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds. Where processing is restricted, we will only retain the data and not process it further without your consent, unless required for legal claims or to protect the rights of others.

10.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit it to another controller where technically feasible.

10.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where we rely on our legitimate interests or the public interest as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.

You have an absolute right to object to the processing of your personal data for direct marketing purposes, including profiling carried out for direct marketing. Where you object to direct marketing, we will cease processing your data for this purpose immediately.

10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. Where we engage in such processing, we will inform you and provide you with the right to obtain human intervention, express your point of view, and contest the decision.

10.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@ravessianluxecourt.com or use the unsubscribe mechanism in any marketing communication.

10.9 Right to Lodge a Complaint

If you believe we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority. Depending on your location, this may be:

  • For individuals in New Zealand: The Office of the Privacy Commissioner (OPC) — www.privacy.org.nz;
  • For individuals in the EU/EEA: The data protection supervisory authority in your country of residence or the country in which the alleged infringement occurred;
  • For individuals in the United Kingdom: The Information Commissioner's Office (ICO) — www.ico.org.uk.

We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority. Please contact us at privacy@ravessianluxecourt.com in the first instance.

10.10 Exercising Your Rights

To exercise any of the rights described above, please submit a written request to:

  • Email: privacy@ravessianluxecourt.com
  • Postal address: The Data Protection Officer, ,

We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable administrative fee or decline to act on the request.

11. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to distinguish you from other users, to enhance your browsing experience, and to provide us with information about how the Website is used. A cookie is a small text file placed on your device when you visit a website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential to the operation of the Website. These enable core functionality such as security, session management, and accessibility. These cookies do not require your consent.
  • Functional Cookies: Enable enhanced functionality and personalisation, such as remembering your language preferences and login details. These require your consent.
  • Performance and Analytics Cookies: Allow us to recognise and count visitors and understand how they navigate the Website, enabling us to improve its performance and content. These require your consent.
  • Marketing and Advertising Cookies: Used to display relevant advertising and to track the effectiveness of our marketing campaigns. These require your consent.

You can manage your cookie preferences through our Cookie Consent tool, displayed when you first visit the Website, or at any time through the Cookie Settings link in the Website footer. You may also configure your browser to refuse cookies or delete them; however, this may affect the functionality of certain parts of the Website.

For detailed information about the specific cookies we use, their purposes, and their duration, please refer to our full Cookie Policy, available on our Website.

12. Direct Marketing and Your Choices

We may use your personal data to send you promotional communications about our hotel and casino services, special offers, events, and loyalty programme benefits. We will only send you direct marketing communications where:

  • You have given us your explicit consent to do so; or
  • You are an existing customer and we are marketing similar products or services (the "soft opt-in" rule), provided you have not opted out.

You may opt out of receiving marketing communications from us at any time by:

  • Clicking the "unsubscribe" link in any marketing email we send you;
  • Contacting us at privacy@ravessianluxecourt.com with your request to be removed from our marketing lists;
  • Writing to us at: , .

Please note that opting out of marketing communications does not prevent us from sending you service-related communications that are necessary for the performance of your contract with us (e.g., booking confirmations, check-in instructions, or security alerts).

14. Automated Decision-Making and Profiling

We may use automated processing and profiling in limited circumstances, for example to personalise marketing communications based on your booking history or loyalty programme activity, or to conduct fraud screening during payment processing. Where any automated decision produces a legal or similarly significant effect on you, we will ensure that appropriate human oversight is applied and that you are informed of your right to contest such decisions as described in Section 10.7.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will notify you by posting the updated policy on our Website with a revised "Last updated" date and, where required by law, by sending you a direct notification. We encourage you to review this policy periodically to stay informed about how we protect your data.

Your continued use of our Website or services after the posting of changes constitutes your acknowledgement of the revised Privacy Policy. If you do not agree with any changes, please discontinue use of our Website and services and contact us to close any accounts you hold with us.

16. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please do not hesitate to contact us:

Data Controller
Contact Person The Data Protection Officer
Address
Email privacy@ravessianluxecourt.com
Website ravessianluxecourt.com

We are committed to working with you to reach a fair resolution of any privacy concern. We aim to respond to all enquiries and Subject Access Requests within one calendar month of receipt.