Privacy Policy
Last updated: June 2025
This Privacy Policy explains how Ivorybrookcreative Pty Ltd collects, uses, stores, shares, and protects your personal data when you visit our website at ivorybrookcreative.com, make reservations, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), as well as applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Please read this policy carefully. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal data (the Data Controller) is:
| Company Name | Ivorybrookcreative Pty Ltd |
|---|---|
| Trading As | Ivorybrookcreative |
| Registration Country | Australia |
| Registration Number | ACN 684 219 573 |
| VAT / Tax Number | ABN 37 684 219 573 |
| Registered Address | 89 Liebig Street, Warrnambool VIC 3280, Australia |
| Website | ivorybrookcreative.com |
| Privacy Contact Email | privacy@ivorybrookcreative.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:
| Name / Title | The Data Protection Officer |
|---|---|
| Organisation | Ivorybrookcreative Pty Ltd |
| Address | 89 Liebig Street, Warrnambool VIC 3280, Australia |
| privacy@ivorybrookcreative.com |
3. Personal Data We Collect
We collect personal data about you in a variety of ways, depending on how you interact with us. The categories of personal data we may collect include:
3.1 Identity and Contact Data
- Full name, title, date of birth, and gender
- Postal address, email address, and telephone number
- Government-issued identification document details (e.g., passport, driver's licence) where required for identity verification or regulatory compliance
- Nationality and country of residence
3.2 Reservation and Stay Data
- Booking reference numbers and reservation details
- Check-in and check-out dates, room type, and special requests
- Number of guests and any accompanying person's details provided by you
- Loyalty programme membership number and preferences
- Records of your stay history and previous interactions with us
3.3 Financial and Payment Data
- Payment card details (processed securely via our payment service provider; we do not store full card numbers)
- Bank account information where applicable
- Billing address and invoice details
- Transaction history relating to hotel and casino spending
3.4 Casino and Gaming Data
- Gaming activity records, including games played, wagers placed, and outcomes
- Casino account information and account balance
- Responsible gambling self-exclusion records and any limits set by you or imposed by us
- Age verification records required by law
- Anti-money laundering (AML) and Know Your Customer (KYC) records
3.5 Technical and Usage Data
- IP address, browser type and version, operating system, and device identifiers
- Pages visited, links clicked, and time spent on our website
- Referral source and search terms used to find our website
- Cookie identifiers and similar tracking technology data (see our Cookie Policy)
- Log files and server access records
3.6 Communication and Marketing Data
- Records of correspondence, complaints, and feedback submitted to us
- Email communication history
- Marketing preferences and opt-in/opt-out records
- Survey responses and guest satisfaction scores
3.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR, such as:
- Health-related information you voluntarily provide (e.g., dietary requirements, accessibility needs, or medical conditions relevant to your stay)
- Biometric data, where used for access control purposes and where you have given explicit consent
We will only process such data where we have a lawful basis to do so, including your explicit consent or where processing is necessary for reasons of substantial public interest. You are never obliged to provide special category data; however, failure to do so may limit our ability to accommodate certain requests.
3.8 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia)
- Travel agents and corporate booking partners
- Credit reference and fraud prevention agencies
- Regulatory authorities and law enforcement bodies
- Social media platforms, where you interact with us through those channels
4. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:
4.1 Performance of a Contract (Article 6(1)(b))
We process your personal data when it is necessary to fulfil a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing your reservation, managing your hotel stay, processing payments, and administering your casino account.
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal data where we are required to do so by law. This includes obligations under anti-money laundering legislation, gambling regulatory requirements, tax law, consumer protection legislation, and other applicable legal frameworks in Australia and, where applicable, the European Union.
4.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests (or those of a third party), provided that your interests and fundamental rights do not override those interests. Our legitimate interests include:
- Fraud prevention, security monitoring, and the protection of our property, guests, and staff
- Improving the quality of our services and personalising your guest experience
- Direct marketing of our own similar services to existing customers (where permitted)
- Administration of our loyalty programme
- Conducting internal analytics and business intelligence
- Exercising or defending legal claims
4.4 Consent (Article 6(1)(a))
Where required, we will ask for your explicit consent before processing your personal data. This applies in particular to:
- Sending you marketing communications by email, SMS, or post where you are not an existing customer
- Placing non-essential cookies on your device
- Processing special categories of personal data (Article 9(2)(a))
You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at privacy@ivorybrookcreative.com.
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another person — for example, in a medical emergency situation on our premises.
4.6 Public Task (Article 6(1)(e))
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, where applicable under relevant legislation.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Hotel Services
- Processing and managing hotel reservations, including check-in and check-out
- Providing accommodation, dining, spa, and other ancillary services
- Managing your loyalty programme account and awarding loyalty points
- Handling complaints, feedback, and special requests
- Sending booking confirmations, pre-arrival information, and post-stay follow-up communications
5.2 Casino and Gaming Services
- Opening and managing your casino account
- Processing gaming transactions and maintaining accurate gaming records
- Conducting mandatory age and identity verification
- Implementing responsible gambling measures, including self-exclusion and spending limits
- Complying with AML, KYC, and other regulatory reporting obligations
5.3 Security and Fraud Prevention
- Monitoring our premises using CCTV systems for the safety and security of guests and staff
- Detecting, investigating, and preventing fraudulent transactions and other criminal activity
- Verifying your identity to prevent identity fraud
- Sharing data with fraud prevention agencies and law enforcement where required
5.4 Marketing and Communications
- Sending you information about our offers, events, and services where you have given consent or where we have a legitimate interest to do so
- Personalising communications and offers based on your preferences and stay history
- Conducting market research and guest satisfaction surveys
5.5 Website and Technology
- Operating, maintaining, and improving our website and digital booking systems
- Analysing website usage to understand user behaviour and improve user experience
- Administering cookies and similar tracking technologies in accordance with your preferences
5.6 Legal and Regulatory Compliance
- Meeting our legal and regulatory obligations under Australian law and, where applicable, EU law
- Responding to requests from regulatory authorities, courts, and law enforcement agencies
- Establishing, exercising, or defending legal claims
6. Sharing of Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients, strictly for the purposes described in this policy:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf. These include:
- Payment processing companies and financial institutions
- Cloud hosting and IT infrastructure providers
- Property management system (PMS) and casino management system (CMS) software providers
- Email marketing and customer relationship management (CRM) platform providers
- Website analytics providers (e.g., Google Analytics)
- Printing, mailing, and fulfilment service providers
All data processors are required to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to comply with applicable data protection law.
6.2 Booking and Distribution Partners
- Online travel agencies and global distribution systems through which you made a reservation
- Corporate travel management companies acting on your employer's behalf
6.3 Regulatory and Law Enforcement Authorities
- Gambling regulatory bodies and licensing authorities
- Australian Taxation Office (ATO) and other revenue authorities
- Australian Transaction Reports and Analysis Centre (AUSTRAC) for AML reporting obligations
- Police and other law enforcement agencies, where required by law or court order
- Supervisory authorities including, where applicable, EU data protection authorities
6.4 Professional Advisors
- Lawyers, auditors, accountants, and insurance providers, where necessary for the conduct of our business
6.5 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and the applicable privacy policy changes.
6.6 International Transfers
Ivorybrookcreative is based in Australia. Some of our service providers may be located outside Australia and, where our guests are located in the European Economic Area (EEA), personal data may be transferred to countries outside the EEA. Where such transfers occur, we ensure that adequate safeguards are in place as required under Chapter V of the GDPR, including:
- Transfers to countries recognised by the European Commission as providing an adequate level of data protection
- Use of the European Commission's Standard Contractual Clauses (SCCs)
- Binding Corporate Rules, where applicable
- Other appropriate safeguards as permitted under Article 46 GDPR
You may request a copy of the relevant transfer mechanisms by contacting us at privacy@ivorybrookcreative.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The following retention periods generally apply:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from date of check-out | Legal obligation (tax and accounting law) |
| Payment and financial transaction records | 7 years from date of transaction | Legal obligation (ATO requirements) |
| Casino account and gaming records | 7 years from account closure or last transaction | Legal obligation (gambling regulation, AML) |
| AML / KYC identification documents | 7 years from the end of the business relationship | Legal obligation (AUSTRAC / AML/CTF Act) |
| CCTV footage | Up to 31 days, unless retained for investigation | Legitimate interests (security) |
| Marketing preferences and consent records | Until withdrawal of consent + 3 years | Legal obligation (evidence of consent) |
| Website analytics data | 26 months from date of collection | Legitimate interests |
| Complaint and correspondence records | 6 years from resolution | Legitimate interests (legal claims) |
| Responsible gambling / self-exclusion records | Duration of exclusion + 5 years | Legal obligation |
After the applicable retention period has expired, your personal data will be securely deleted or anonymised so that it can no longer be associated with you. In some cases, we may retain anonymised data for statistical and analytical purposes indefinitely.
8. Your Rights as a Data Subject
Depending on your location and the applicable data protection law, you may have the following rights in relation to your personal data. Where GDPR applies, these rights are set out in Articles 15–22 of the GDPR.
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and information about how we process it. We will provide this information in the form of a Subject Access Request (SAR) response within one month of receipt, extendable by a further two months where the request is complex.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete data completed.
8.3 Right to Erasure — "Right to be Forgotten" (Article 17 GDPR)
You have the right to request that we delete your personal data where there is no compelling reason for its continued processing. Please note that this right is not absolute and does not apply where processing is necessary for compliance with a legal obligation, the exercise or defence of legal claims, or other grounds set out in Article 17(3) GDPR.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest its accuracy or have objected to processing.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
8.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data where that processing is based on legitimate interests (Article 6(1)(f)) or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we conduct such processing, we will inform you and provide you with the opportunity to request human review, express your point of view, and contest the decision.
8.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing conducted prior to withdrawal.
8.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority:
- In Australia: The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- In the European Union / EEA: The data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority and ask that you contact us in the first instance at privacy@ivorybrookcreative.com.
8.10 Exercising Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at privacy@ivorybrookcreative.com or by post to:
The Data Protection Officer
Ivorybrookcreative Pty Ltd
89 Liebig Street
Warrnambool VIC 3280
Australia
We may need to verify your identity before processing your request. We will respond to all legitimate requests within one month. If your request is particularly complex, or you have made a number of requests, we may extend this period by a further two months and will notify you accordingly.
There is no charge for exercising your rights; however, we may charge a reasonable administrative fee or refuse to act on requests that are manifestly unfounded or excessive.
10. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 GDPR and the Australian Privacy Principles. These measures include:
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest
- Role-based access controls and the principle of least privilege
- Regular security assessments, penetration testing, and vulnerability scanning
- Staff training on data protection and information security
- Physical security measures at our premises
- Incident response and data breach notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.
Despite our best efforts, no transmission of data over the internet or electronic storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@ivorybrookcreative.com.
11. Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.
12. Children and Minors
Our hotel and casino services are intended exclusively for adults aged 18 years and over. We do not knowingly collect personal data from persons under the age of 18. As part of our regulatory obligations, we conduct age verification checks for access to our casino facilities. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete such data promptly. If you believe we may have collected data from or about a minor, please contact us at privacy@ivorybrookcreative.com.
13. Responsible Gambling and Personal Data
We take our responsible gambling obligations seriously. We collect and process data related to your gaming activity in order to monitor for signs of problem gambling, enforce self-exclusion agreements, implement voluntary and mandatory spending limits, and comply with our legal obligations under applicable gambling legislation. This processing is based on compliance with our legal obligations (Article 6(1)(c) GDPR) and, where applicable, substantial public interest (Article 9(2)(g) GDPR). Records relating to responsible gambling measures will be retained for the period specified in Section 7 of this policy.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by sending you a direct notification by email or displaying a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website or services after any changes to this policy constitutes your acceptance of the updated terms.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us:
| By Email | privacy@ivorybrookcreative.com |
|---|---|
| By Post |
The Data Protection Officer Ivorybrookcreative Pty Ltd 89 Liebig Street Warrnambool VIC 3280 Australia |
| Website | ivorybrookcreative.com |
We are committed to working with you to resolve any concerns you may have about the processing of your personal data and aim to respond to all enquiries within a reasonable timeframe and in any event within 30 days.