Privacy Policy

Last updated: June 2025

This Privacy Policy explains how Ivorybrookcreative Pty Ltd collects, uses, stores, shares, and protects your personal data when you visit our website at ivorybrookcreative.com, make reservations, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), as well as applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Please read this policy carefully. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The entity responsible for the processing of your personal data (the Data Controller) is:

Company Name Ivorybrookcreative Pty Ltd
Trading As Ivorybrookcreative
Registration Country Australia
Registration Number ACN 684 219 573
VAT / Tax Number ABN 37 684 219 573
Registered Address 89 Liebig Street, Warrnambool VIC 3280, Australia
Website ivorybrookcreative.com
Privacy Contact Email privacy@ivorybrookcreative.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:

Name / Title The Data Protection Officer
Organisation Ivorybrookcreative Pty Ltd
Address 89 Liebig Street, Warrnambool VIC 3280, Australia
Email privacy@ivorybrookcreative.com

3. Personal Data We Collect

We collect personal data about you in a variety of ways, depending on how you interact with us. The categories of personal data we may collect include:

3.1 Identity and Contact Data

  • Full name, title, date of birth, and gender
  • Postal address, email address, and telephone number
  • Government-issued identification document details (e.g., passport, driver's licence) where required for identity verification or regulatory compliance
  • Nationality and country of residence

3.2 Reservation and Stay Data

  • Booking reference numbers and reservation details
  • Check-in and check-out dates, room type, and special requests
  • Number of guests and any accompanying person's details provided by you
  • Loyalty programme membership number and preferences
  • Records of your stay history and previous interactions with us

3.3 Financial and Payment Data

  • Payment card details (processed securely via our payment service provider; we do not store full card numbers)
  • Bank account information where applicable
  • Billing address and invoice details
  • Transaction history relating to hotel and casino spending

3.4 Casino and Gaming Data

  • Gaming activity records, including games played, wagers placed, and outcomes
  • Casino account information and account balance
  • Responsible gambling self-exclusion records and any limits set by you or imposed by us
  • Age verification records required by law
  • Anti-money laundering (AML) and Know Your Customer (KYC) records

3.5 Technical and Usage Data

  • IP address, browser type and version, operating system, and device identifiers
  • Pages visited, links clicked, and time spent on our website
  • Referral source and search terms used to find our website
  • Cookie identifiers and similar tracking technology data (see our Cookie Policy)
  • Log files and server access records

3.6 Communication and Marketing Data

  • Records of correspondence, complaints, and feedback submitted to us
  • Email communication history
  • Marketing preferences and opt-in/opt-out records
  • Survey responses and guest satisfaction scores

3.7 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR, such as:

  • Health-related information you voluntarily provide (e.g., dietary requirements, accessibility needs, or medical conditions relevant to your stay)
  • Biometric data, where used for access control purposes and where you have given explicit consent

We will only process such data where we have a lawful basis to do so, including your explicit consent or where processing is necessary for reasons of substantial public interest. You are never obliged to provide special category data; however, failure to do so may limit our ability to accommodate certain requests.

3.8 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies and booking platforms (e.g., Booking.com, Expedia)
  • Travel agents and corporate booking partners
  • Credit reference and fraud prevention agencies
  • Regulatory authorities and law enforcement bodies
  • Social media platforms, where you interact with us through those channels

5. How We Use Your Personal Data

We use your personal data for the following purposes:

5.1 Hotel Services

  • Processing and managing hotel reservations, including check-in and check-out
  • Providing accommodation, dining, spa, and other ancillary services
  • Managing your loyalty programme account and awarding loyalty points
  • Handling complaints, feedback, and special requests
  • Sending booking confirmations, pre-arrival information, and post-stay follow-up communications

5.2 Casino and Gaming Services

  • Opening and managing your casino account
  • Processing gaming transactions and maintaining accurate gaming records
  • Conducting mandatory age and identity verification
  • Implementing responsible gambling measures, including self-exclusion and spending limits
  • Complying with AML, KYC, and other regulatory reporting obligations

5.3 Security and Fraud Prevention

  • Monitoring our premises using CCTV systems for the safety and security of guests and staff
  • Detecting, investigating, and preventing fraudulent transactions and other criminal activity
  • Verifying your identity to prevent identity fraud
  • Sharing data with fraud prevention agencies and law enforcement where required

5.4 Marketing and Communications

  • Sending you information about our offers, events, and services where you have given consent or where we have a legitimate interest to do so
  • Personalising communications and offers based on your preferences and stay history
  • Conducting market research and guest satisfaction surveys

5.5 Website and Technology

  • Operating, maintaining, and improving our website and digital booking systems
  • Analysing website usage to understand user behaviour and improve user experience
  • Administering cookies and similar tracking technologies in accordance with your preferences

5.6 Legal and Regulatory Compliance

  • Meeting our legal and regulatory obligations under Australian law and, where applicable, EU law
  • Responding to requests from regulatory authorities, courts, and law enforcement agencies
  • Establishing, exercising, or defending legal claims

6. Sharing of Personal Data

We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients, strictly for the purposes described in this policy:

6.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf. These include:

  • Payment processing companies and financial institutions
  • Cloud hosting and IT infrastructure providers
  • Property management system (PMS) and casino management system (CMS) software providers
  • Email marketing and customer relationship management (CRM) platform providers
  • Website analytics providers (e.g., Google Analytics)
  • Printing, mailing, and fulfilment service providers

All data processors are required to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to comply with applicable data protection law.

6.2 Booking and Distribution Partners

  • Online travel agencies and global distribution systems through which you made a reservation
  • Corporate travel management companies acting on your employer's behalf

6.3 Regulatory and Law Enforcement Authorities

  • Gambling regulatory bodies and licensing authorities
  • Australian Taxation Office (ATO) and other revenue authorities
  • Australian Transaction Reports and Analysis Centre (AUSTRAC) for AML reporting obligations
  • Police and other law enforcement agencies, where required by law or court order
  • Supervisory authorities including, where applicable, EU data protection authorities

6.4 Professional Advisors

  • Lawyers, auditors, accountants, and insurance providers, where necessary for the conduct of our business

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and the applicable privacy policy changes.

6.6 International Transfers

Ivorybrookcreative is based in Australia. Some of our service providers may be located outside Australia and, where our guests are located in the European Economic Area (EEA), personal data may be transferred to countries outside the EEA. Where such transfers occur, we ensure that adequate safeguards are in place as required under Chapter V of the GDPR, including:

  • Transfers to countries recognised by the European Commission as providing an adequate level of data protection
  • Use of the European Commission's Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules, where applicable
  • Other appropriate safeguards as permitted under Article 46 GDPR

You may request a copy of the relevant transfer mechanisms by contacting us at privacy@ivorybrookcreative.com.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The following retention periods generally apply:

Category of Data Retention Period Basis
Guest reservation and stay records 7 years from date of check-out Legal obligation (tax and accounting law)
Payment and financial transaction records 7 years from date of transaction Legal obligation (ATO requirements)
Casino account and gaming records 7 years from account closure or last transaction Legal obligation (gambling regulation, AML)
AML / KYC identification documents 7 years from the end of the business relationship Legal obligation (AUSTRAC / AML/CTF Act)
CCTV footage Up to 31 days, unless retained for investigation Legitimate interests (security)
Marketing preferences and consent records Until withdrawal of consent + 3 years Legal obligation (evidence of consent)
Website analytics data 26 months from date of collection Legitimate interests
Complaint and correspondence records 6 years from resolution Legitimate interests (legal claims)
Responsible gambling / self-exclusion records Duration of exclusion + 5 years Legal obligation

After the applicable retention period has expired, your personal data will be securely deleted or anonymised so that it can no longer be associated with you. In some cases, we may retain anonymised data for statistical and analytical purposes indefinitely.

8. Your Rights as a Data Subject

Depending on your location and the applicable data protection law, you may have the following rights in relation to your personal data. Where GDPR applies, these rights are set out in Articles 15–22 of the GDPR.

8.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you and information about how we process it. We will provide this information in the form of a Subject Access Request (SAR) response within one month of receipt, extendable by a further two months where the request is complex.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete data completed.

8.3 Right to Erasure — "Right to be Forgotten" (Article 17 GDPR)

You have the right to request that we delete your personal data where there is no compelling reason for its continued processing. Please note that this right is not absolute and does not apply where processing is necessary for compliance with a legal obligation, the exercise or defence of legal claims, or other grounds set out in Article 17(3) GDPR.

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest its accuracy or have objected to processing.

8.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.

8.6 Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data where that processing is based on legitimate interests (Article 6(1)(f)) or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we conduct such processing, we will inform you and provide you with the opportunity to request human review, express your point of view, and contest the decision.

8.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing conducted prior to withdrawal.

8.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority:

  • In Australia: The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
  • In the European Union / EEA: The data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority and ask that you contact us in the first instance at privacy@ivorybrookcreative.com.

8.10 Exercising Your Rights

To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at privacy@ivorybrookcreative.com or by post to:

The Data Protection Officer
Ivorybrookcreative Pty Ltd
89 Liebig Street
Warrnambool VIC 3280
Australia

We may need to verify your identity before processing your request. We will respond to all legitimate requests within one month. If your request is particularly complex, or you have made a number of requests, we may extend this period by a further two months and will notify you accordingly.

There is no charge for exercising your rights; however, we may charge a reasonable administrative fee or refuse to act on requests that are manifestly unfounded or excessive.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and deliver personalised content. Cookies are small text files placed on your device when you visit our website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our website, including session management and security features. These cannot be disabled.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous statistical information.
  • Functionality Cookies: Enable enhanced functionality and personalisation, such as remembering your preferences.
  • Marketing and Targeting Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns. These are placed only with your consent.

You can manage your cookie preferences at any time through our cookie consent banner or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website. For more detailed information, please refer to our full Cookie Policy, available on our website.

10. Security of Personal Data

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 GDPR and the Australian Privacy Principles. These measures include:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest
  • Role-based access controls and the principle of least privilege
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Staff training on data protection and information security
  • Physical security measures at our premises
  • Incident response and data breach notification procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.

Despite our best efforts, no transmission of data over the internet or electronic storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@ivorybrookcreative.com.

12. Children and Minors

Our hotel and casino services are intended exclusively for adults aged 18 years and over. We do not knowingly collect personal data from persons under the age of 18. As part of our regulatory obligations, we conduct age verification checks for access to our casino facilities. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete such data promptly. If you believe we may have collected data from or about a minor, please contact us at privacy@ivorybrookcreative.com.

13. Responsible Gambling and Personal Data

We take our responsible gambling obligations seriously. We collect and process data related to your gaming activity in order to monitor for signs of problem gambling, enforce self-exclusion agreements, implement voluntary and mandatory spending limits, and comply with our legal obligations under applicable gambling legislation. This processing is based on compliance with our legal obligations (Article 6(1)(c) GDPR) and, where applicable, substantial public interest (Article 9(2)(g) GDPR). Records relating to responsible gambling measures will be retained for the period specified in Section 7 of this policy.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by sending you a direct notification by email or displaying a prominent notice on our website.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website or services after any changes to this policy constitutes your acceptance of the updated terms.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us:

By Email privacy@ivorybrookcreative.com
By Post The Data Protection Officer
Ivorybrookcreative Pty Ltd
89 Liebig Street
Warrnambool VIC 3280
Australia
Website ivorybrookcreative.com

We are committed to working with you to resolve any concerns you may have about the processing of your personal data and aim to respond to all enquiries within a reasonable timeframe and in any event within 30 days.