Privacy Policy
Last updated: June 2025
Welcome to Varorolodge Haven. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation. This Privacy Policy explains who we are, how we collect, use, share, and retain your personal data, and what rights you have in relation to your personal data when you visit our website at varorolodgehaven.com, make a reservation, or use any of our hotel and casino services.
Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please refrain from using our website and services.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Registered Company Name | |
|---|---|
| Trading Name | Varorolodge Haven |
| Registration Country | New Zealand |
| Company Registration Number | 9184736 |
| VAT Number | 9429051847362 |
| Registered Legal Address | |
| Website | varorolodgehaven.com |
| Privacy Contact Email | privacy@varorolodgehaven.com |
Any reference to "we", "us", "our", or "Varorolodge Haven" in this Privacy Policy refers to as the Data Controller.
2. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our compliance with applicable data protection legislation. If you have any questions about this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact our DPO:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@varorolodgehaven.com |
3. Personal Data We Collect
We collect different categories of personal data depending on how you interact with us. Personal data means any information that can directly or indirectly identify you as a natural person. The categories of personal data we collect include, but are not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name, middle name, and surname)
- Date of birth and age verification information
- Gender
- Nationality and country of residence
- Passport number, national identity card number, or other government-issued identification details
- Postal address (home and/or billing address)
- Email address
- Telephone number (landline and/or mobile)
- Profile photographs (where provided or captured for security purposes)
3.2 Reservation and Stay Data
- Booking reference numbers and reservation details
- Check-in and check-out dates and times
- Room type preferences and special requests
- Number of guests and details of accompanying guests
- Dietary requirements and accessibility needs
- Loyalty programme membership details and stay history
- Feedback, complaints, and correspondence relating to your stay
3.3 Financial and Payment Data
- Credit card, debit card, or other payment instrument details (processed securely via our payment provider)
- Bank account details (where applicable for refunds or direct payments)
- Billing address and invoicing information
- Transaction history, charges, and receipts
- Financial due diligence information required by anti-money laundering regulations
3.4 Casino and Gaming Data
- Casino membership or player card details
- Gaming activity, session history, and wagering records
- Winnings, losses, and transaction records related to gaming
- Self-exclusion requests and responsible gambling information
- Age verification and identity verification documentation
- Source of funds documentation as required by gaming regulatory authorities
3.5 Technical and Usage Data
- Internet Protocol (IP) address
- Browser type, version, and language settings
- Operating system and device type
- Pages visited, links clicked, and time spent on our website
- Referring URLs and exit pages
- Cookie identifiers and similar tracking technology data (see our Cookie Policy for more details)
- Log files and server access data
3.6 Marketing and Communications Data
- Marketing preferences and communication opt-in or opt-out records
- Details of promotional offers and vouchers redeemed
- Survey responses and competition entries
- Records of your interactions with our marketing communications
3.7 Security and Safety Data
- Closed-circuit television (CCTV) footage recorded on our premises
- Access control records and entry logs
- Incident reports and security investigation records
3.8 Special Categories of Personal Data
In certain limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR, such as:
- Health and medical information (for example, where you disclose accessibility requirements, dietary restrictions relating to a medical condition, or where an incident occurs on our premises)
- Information relating to gambling addiction or self-exclusion (processed for responsible gambling compliance purposes)
We will only process special category data where we have a lawful basis to do so, including where processing is necessary to protect your vital interests, to comply with legal obligations, or where you have given your explicit consent.
3.9 Data We Collect About Third Parties
If you provide us with personal data about other individuals (for example, accompanying guests), you confirm that you have their authority to do so and that they have been informed about how their data will be used in accordance with this Privacy Policy.
4. How We Collect Your Personal Data
We collect personal data through a variety of means, including:
- Direct interactions: Information you provide when making a booking, creating an account, registering for our casino membership, completing forms, corresponding with us by email, telephone, post, or in person.
- Automated technologies: As you interact with our website, we may automatically collect technical data about your equipment, browsing actions, and patterns through cookies, server logs, and other similar technologies.
- Third parties and public sources: We may receive data about you from third parties such as online travel agencies, booking platforms, loyalty programme partners, payment processors, credit reference agencies, identity verification providers, gaming regulatory authorities, and fraud prevention agencies.
- On-premises systems: CCTV systems, access control systems, and casino floor management systems may collect data while you are on our premises.
5. Legal Basis for Processing Your Personal Data
We will only process your personal data where we have a lawful basis for doing so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into such a contract. This applies, for example, when you make a reservation, check in to the hotel, use our casino services, or otherwise engage with us as a paying customer.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where we are required to do so in order to comply with a legal obligation to which we are subject. This includes, without limitation:
- Anti-money laundering (AML) and counter-terrorism financing obligations
- Know Your Customer (KYC) identity verification requirements under gaming regulations
- Responsible gambling obligations, including mandatory self-exclusion register compliance
- Tax, accounting, and financial reporting obligations
- Obligations to cooperate with law enforcement, regulatory, and judicial authorities
- Health and safety obligations
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Operating and improving our hotel and casino business
- Ensuring the security and safety of our guests, staff, and premises through CCTV and access controls
- Preventing, detecting, and investigating fraud, theft, cheating, and other unlawful activities
- Analysing website usage to improve our digital services and user experience
- Sending marketing communications to existing customers about similar products and services (subject to your right to opt out at any time)
- Managing and defending legal claims
- Conducting due diligence on business partners and suppliers
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will ask you to provide explicit and informed consent before we process your data for that purpose. This applies, for example, to:
- Sending marketing communications by email, SMS, or post to non-existing customers
- Placing non-essential cookies and tracking technologies on your device
- Processing special category data where no other lawful basis applies
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to your withdrawal. To withdraw your consent, please contact us at privacy@varorolodgehaven.com or use the unsubscribe mechanism in any marketing communication.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process your personal data where it is necessary to protect your vital interests or those of another natural person, for example in a medical emergency occurring on our premises.
5.6 Public Task (Article 6(1)(e) GDPR)
We may, where applicable and required by law, process personal data in the performance of a task carried out in the public interest or in the exercise of official authority, including cooperation with licensed gaming regulators or public health authorities.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Providing Hotel and Accommodation Services
- Processing and managing your reservation, check-in, and check-out
- Communicating with you about your booking, including confirmations, reminders, and updates
- Providing services tailored to your preferences and special requests
- Processing payments and managing your account balance
- Administering our loyalty and rewards programme
6.2 Providing Casino and Gaming Services
- Verifying your identity and age for casino access and gaming account registration
- Managing your gaming account, recording gaming activity, and processing winnings and payments
- Complying with gaming licensing and regulatory obligations
- Administering responsible gambling measures, including self-exclusion programmes
- Detecting and preventing cheating, collusion, or fraudulent gaming activity
6.3 Security and Fraud Prevention
- Operating CCTV systems on our premises for the safety and security of guests and staff
- Detecting, investigating, and preventing fraud, theft, money laundering, and other criminal activity
- Managing access to restricted areas of our property
- Cooperating with law enforcement agencies and regulatory authorities where required
6.4 Legal and Regulatory Compliance
- Fulfilling our obligations under anti-money laundering legislation
- Maintaining records required by tax and financial regulatory authorities
- Responding to lawful requests from courts, law enforcement, and government agencies
- Establishing, exercising, or defending legal claims
6.5 Marketing and Communications
- Sending you promotional offers, newsletters, and information about our services and events where you have provided consent or where we have a legitimate interest to do so
- Personalising your experience on our website and in our marketing communications
- Conducting customer satisfaction surveys and collecting feedback
- Administering prize draws, competitions, and promotional campaigns
6.6 Website and Service Improvement
- Analysing how visitors use our website to improve functionality and content
- Troubleshooting technical issues
- Conducting internal research, reporting, and business analytics
7. Sharing Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients, in each case only to the extent necessary and in accordance with applicable law:
7.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions (acting as data processors). These include:
- Payment processing and fraud prevention providers
- Cloud hosting and IT infrastructure providers
- Booking and reservation platform providers
- Casino management system providers
- Customer relationship management (CRM) platform providers
- Email and marketing communication service providers
- Identity verification and Know Your Customer (KYC) service providers
- Website analytics providers (such as web analytics tools)
- Security and CCTV system operators
- Legal, accounting, and auditing service providers
All our data processors are subject to contractual obligations requiring them to keep your personal data secure, to process it only on our instructions, and to comply with applicable data protection legislation.
7.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to regulatory bodies, gaming authorities, tax authorities, law enforcement agencies, courts, and other public authorities where we are required or permitted to do so by applicable law, including:
- The Department of Internal Affairs (New Zealand gaming regulator)
- The New Zealand Police and other law enforcement agencies
- Inland Revenue (New Zealand tax authority)
- Financial Intelligence Units in connection with AML obligations
- Courts and tribunals in connection with legal proceedings
7.3 Group Companies and Business Transfers
We may share your personal data with other companies within our corporate group for internal administrative purposes. In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, personal data may be transferred to the relevant third party, subject to appropriate safeguards.
7.4 Professional Advisers
We may share your personal data with lawyers, auditors, insurers, and other professional advisers where necessary in connection with our business operations or the management of legal claims.
7.5 International Transfers
Our primary operations are based in Wellington, New Zealand. Some of our service providers may be located outside New Zealand and the European Economic Area (EEA). Where we transfer personal data to countries that do not offer an equivalent level of data protection, we ensure that appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions issued by the European Commission or the Office of the Privacy Commissioner of New Zealand
- Binding Corporate Rules (BCRs) where applicable
- Your explicit consent, where no other safeguard is available
You may request further information about the safeguards we have in place for international transfers by contacting us at privacy@varorolodgehaven.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and the applicable legal requirements.
The following general retention periods apply:
| Category of Data | Retention Period | Legal Basis for Retention |
|---|---|---|
| Hotel reservation and guest records | 7 years from the date of the last stay | Legal obligation (tax and accounting); Legitimate interests |
| Financial and payment records | 7 years from the date of transaction | Legal obligation (tax and financial regulation) |
| Casino gaming records and KYC documents | 5–7 years from the end of the business relationship | Legal obligation (gaming regulation; AML legislation) |
| Anti-money laundering records | 5 years from the end of the business relationship or transaction | Legal obligation (AML legislation) |
| CCTV footage | 30 days, unless required for an ongoing investigation | Legitimate interests (security); Legal obligation |
| Marketing communication preferences | Until you withdraw consent or opt out, plus 1 year | Consent; Legitimate interests |
| Website and cookie data | Up to 2 years, depending on cookie type | Consent; Legitimate interests |
| Responsible gambling and self-exclusion records | For the duration of the self-exclusion period plus 5 years | Legal obligation; Vital interests |
| Legal claims and dispute records | 7 years from resolution of the matter | Legitimate interests; Legal obligation |
At the end of the applicable retention period, we will securely delete or anonymise your personal data. In some circumstances, we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such anonymised data indefinitely without further notice.
9. Your Data Protection Rights
Subject to applicable law, you have the following rights in relation to your personal data. We will respond to your request within one calendar month of receipt, unless the request is complex or numerous, in which case we may extend this period by a further two months, notifying you accordingly.
9.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will provide this information free of charge; however, we may charge a reasonable administrative fee where requests are manifestly unfounded or excessive.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
9.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you have withdrawn consent, or where the data has been unlawfully processed. Please note that this right is subject to exceptions, including where we are required to retain the data to comply with a legal obligation or to establish, exercise, or defend legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, or where you object to our processing and we are considering whether our legitimate interests override yours.
9.5 Right to Data Portability (Article 20 GDPR)
Where we process your personal data by automated means on the basis of your consent or the performance of a contract, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- On grounds relating to your particular situation: where we are processing your personal data on the basis of legitimate interests (Article 6(1)(f) GDPR), unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
- For direct marketing purposes: where we process your personal data for direct marketing purposes, including profiling to the extent that it is related to direct marketing. If you object, we will cease processing your data for this purpose immediately.
9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. If we rely on automated decision-making in any context, we will inform you of this and provide you with the opportunity to request human review, to express your point of view, and to contest the decision.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing that was carried out prior to your withdrawal. To withdraw consent, please contact us at privacy@varorolodgehaven.com.
9.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at the contact details provided in Section 2 of this Privacy Policy. We may ask you to verify your identity before processing your request in order to protect your personal data and prevent unauthorised access.
We will not charge a fee for exercising your rights unless your request is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to act on the request. We will notify you accordingly.
9.10 Right to Lodge a Complaint
If you believe that we have not handled your personal data in accordance with applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In New Zealand, the relevant authority is:
-
Office of the Privacy Commissioner of New Zealand
PO Box 10094, The Terrace, Wellington 6143, New Zealand
Website: privacy.org.nz
If you are located in the European Union or the European Economic Area, you also have the right to lodge a complaint with the supervisory authority of the EU Member State in which you reside, work, or where the alleged infringement took place.
We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority, and we encourage you to contact us in the first instance at privacy@varorolodgehaven.com.
11. Security of Your Personal Data
We have implemented appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology
- Encryption of sensitive data at rest
- Access controls and role-based permissions limiting staff access to personal data on a need-to-know basis
- Regular security assessments, penetration testing, and vulnerability scanning
- Staff training on data protection and information security obligations
- Physical security measures at our premises
- Incident response and data breach notification procedures
While we take all reasonable steps to protect your personal data, the transmission of information over the internet is not completely secure. Any transmission of data to our website is at your own risk. Once we have received your data, we will apply the security measures described above.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify you directly where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Articles 33 and 34 of the GDPR.
12. Third-Party Links and Services
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policies of every website you visit.
13. Children's Privacy
Our hotel and casino services are not directed at children under the age of 18. We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental or guardian consent. Access to our casino facilities requires proof of age, and we operate strict age verification procedures in compliance with applicable gaming legislation.
If you believe that we have inadvertently collected personal data from a child under the age of 18, please contact us immediately at privacy@varorolodgehaven.com and we will take prompt steps to delete such data.
14. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, applicable law, or regulatory requirements. The date at the top of this Privacy Policy indicates when it was last revised. Where changes are material, we will notify you by posting a prominent notice on our website or by sending you a direct communication.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website and services after any changes constitutes your acceptance of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, the way we handle your personal data, or if you wish to exercise any of your data protection rights, please contact us using the details below:
| Data Controller | |
|---|---|
| Attention | The Data Protection Officer |
| Postal Address | |
| Email Address | privacy@varorolodgehaven.com |
| Website | varorolodgehaven.com |
We are committed to working with you to resolve any concerns you may have about our handling of your personal data. We aim to acknowledge all written enquiries within five business days and to provide a full response within one calendar month.