Privacy Policy

Last updated: June 2025

This Privacy Policy describes how (hereinafter referred to as "we", "us", "our", or "the Company") collects, uses, stores, and protects your personal data when you visit or use our website located at arnoviresortguide.com (hereinafter referred to as "the Website"), make reservations, or interact with our hotel-casino services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable New Zealand privacy legislation, and all other relevant data protection laws.

Please read this Privacy Policy carefully before using our Website or submitting any personal information. By accessing or using our Website, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Company Name
Trading Name Arnoviresortguide
Registered Address
Registration Country New Zealand
Website arnoviresortguide.com
Privacy Contact Email info@arnoviresortguide.com

As the Data Controller, we determine the purposes and means by which your personal data is processed. We take our legal obligations seriously and implement appropriate technical and organisational measures to ensure your data is handled securely and lawfully at all times.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable privacy laws. You may contact our DPO directly for any data protection-related queries or concerns:

DPO Title The Data Protection Officer
Organisation
Postal Address
Email Address info@arnoviresortguide.com

Our DPO is available to answer any questions regarding this Privacy Policy, your rights as a data subject, or any concerns about how your personal data is being processed.

3. Personal Data We Collect

We collect personal data from you in a variety of ways, including directly when you provide it to us, automatically when you use our Website, and in some cases from third parties. The categories of personal data we may collect include the following:

3.1 Data You Provide Directly

  • Identity Data: Full name, title, date of birth, nationality, gender, and passport or national identity document details (where required for check-in or age verification purposes).
  • Contact Data: Email address, telephone number, postal address, and billing address.
  • Reservation and Booking Data: Details of your hotel room bookings, casino table reservations, check-in and check-out dates, special requests, number of guests, and dietary requirements.
  • Payment Data: Credit or debit card details, billing information, and transaction records. Please note that full card details are processed by our secure third-party payment processors and are not stored on our servers.
  • Account Registration Data: Username, password (stored in encrypted form), and account preferences if you register an account on our Website.
  • Communication Data: Messages, enquiries, complaints, or feedback you send to us via email, contact forms, live chat, or any other communication channel.
  • Loyalty Programme Data: Membership details, points balances, redemption history, and preferences associated with our guest loyalty or rewards scheme.
  • Casino and Gaming Data: Where applicable and required by law, data related to your gaming activity, player ID, gaming preferences, and responsible gambling declarations or self-exclusion requests.
  • Marketing Preferences: Your preferences regarding receiving marketing communications from us, including the type of offers or promotions you wish to receive.

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device type, time zone setting, and browser plug-in types and versions.
  • Usage Data: Information about how you use our Website, including the pages you visit, the links you click, the time and date of your visit, the duration of your session, and the referring URL.
  • Cookie and Tracking Data: Data collected through cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy section below for further details.
  • Location Data: Approximate geographic location derived from your IP address.

3.3 Data Received from Third Parties

  • Online Travel Agencies (OTAs) and Booking Platforms: Personal data transmitted to us when you make a booking through a third-party platform such as Booking.com, Expedia, or similar services.
  • Social Media Platforms: If you interact with our social media profiles or use social login features, we may receive certain information from those platforms in accordance with your privacy settings and their terms of service.
  • Payment and Fraud Prevention Services: Information from payment processors and fraud prevention agencies used to verify your identity and protect against fraudulent transactions.
  • Analytics Providers: Aggregated or pseudonymised data from analytics service providers used to better understand Website usage patterns.
  • Regulatory Authorities: In limited circumstances, we may receive data from regulatory or law enforcement bodies in connection with our legal obligations, particularly in relation to anti-money laundering (AML) or gaming compliance requirements.

3.4 Special Categories of Personal Data

We do not intentionally collect special categories of personal data (also known as sensitive personal data), such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation, unless:

  • You have provided explicit consent to the processing of such data for a specified purpose;
  • Processing is necessary for reasons of substantial public interest or compliance with legal obligations;
  • You have voluntarily disclosed such information to us (for example, a dietary requirement indicating a religious or health-related need), in which case we will treat it with the highest degree of care.

Where health-related information is provided to us in connection with accessibility requirements or medical dietary needs, such data is used solely for the purpose of fulfilling your specific request and is not processed for any other purpose without your explicit consent.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes, consistent with the legal bases described above:

5.1 Reservation and Service Delivery

  • Processing and confirming hotel room reservations, restaurant bookings, spa appointments, and casino access;
  • Facilitating check-in and check-out processes;
  • Communicating with you about your booking, including confirmation emails, pre-arrival information, and post-stay follow-ups;
  • Managing special requests such as accessibility requirements, dietary needs, or room preferences;
  • Processing payments and issuing invoices and receipts.

5.2 Account Management

  • Creating and maintaining your online account on our Website;
  • Managing your loyalty programme membership and rewards;
  • Allowing you to view your booking history and manage preferences.

5.3 Casino and Gaming Operations

  • Verifying your age and identity in compliance with gaming regulations;
  • Managing your gaming account, if applicable;
  • Implementing and recording responsible gambling measures, including self-exclusion requests and spending limits;
  • Complying with AML and gaming regulatory reporting obligations.

5.4 Customer Support

  • Responding to your enquiries, complaints, and requests;
  • Resolving disputes and troubleshooting issues;
  • Maintaining records of communications for quality and training purposes.

5.5 Marketing and Promotional Activities

  • Sending you newsletters, promotional offers, and information about our events, subject to your marketing preferences and applicable consent;
  • Personalising the content and offers displayed on our Website or in communications based on your preferences and past interactions;
  • Conducting prize draws, competitions, or surveys with your participation.

5.6 Website Improvement and Analytics

  • Analysing how visitors use our Website to improve its content, functionality, and user experience;
  • Monitoring Website performance and identifying technical issues;
  • Conducting A/B testing and research to enhance our digital services.

5.7 Security and Fraud Prevention

  • Detecting, investigating, and preventing fraudulent transactions, unauthorised access, and other illegal activities;
  • Maintaining the physical security of our hotel and casino premises through CCTV surveillance and access management;
  • Verifying the identity of guests where required for security or regulatory purposes.

5.8 Legal and Regulatory Compliance

  • Meeting our obligations under applicable laws and regulations;
  • Responding to requests from law enforcement, regulatory authorities, or courts;
  • Establishing, exercising, or defending legal claims;
  • Maintaining accurate financial and operational records for auditing purposes.

5.9 Automated Decision-Making and Profiling

We may use automated processing to analyse your personal data in order to personalise your experience on our Website or tailor marketing communications to your interests. However, we do not make decisions that produce significant legal effects or similarly significant effects on you based solely on automated processing, without human involvement, unless we have obtained your explicit consent or such processing is required by law. You have the right to object to profiling and to request human review of any automated decisions. For more information, please contact our DPO.

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. However, we may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate contractual and legal safeguards:

6.1 Service Providers and Data Processors

We engage trusted third-party companies and individuals to perform services on our behalf. These parties act as data processors and are contractually bound to process your personal data only in accordance with our instructions and applicable data protection law. They include:

  • Payment Processing Providers: Secure payment gateways and financial institutions that process your payment transactions;
  • IT and Hosting Providers: Cloud service providers, website hosting companies, and IT support providers who maintain and support our digital infrastructure;
  • Property Management System (PMS) Providers: Software providers that operate our hotel reservation and management systems;
  • Email and Communication Platforms: Providers of email marketing, transactional email, and customer communication tools;
  • Analytics and Marketing Technology Providers: Providers of website analytics, advertising, and marketing automation tools;
  • Customer Support Platforms: Providers of helpdesk, live chat, and customer relationship management (CRM) software;
  • Security and Surveillance Providers: Companies that maintain our on-site security and CCTV systems.

6.2 Online Travel Agencies and Distribution Partners

Where you have made a booking via an online travel agency or third-party booking platform, we may exchange necessary booking and guest information with that platform to manage your reservation and provide the requested services.

6.3 Legal and Regulatory Authorities

We may disclose your personal data to government authorities, law enforcement agencies, courts, regulators, or other public bodies where required or permitted by law, including in connection with:

  • Anti-money laundering and counter-terrorism financing obligations;
  • Gaming and casino regulatory reporting requirements;
  • Tax and customs authorities;
  • Court orders, subpoenas, or other legal processes.

6.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, your personal data may be transferred to the acquiring entity as part of the transaction. We will endeavour to notify you before your data is transferred and becomes subject to a different privacy policy.

6.5 Professional Advisers

We may share your personal data with our lawyers, accountants, auditors, and insurers where necessary for the provision of professional advisory services or for the purposes of managing insurance claims or legal proceedings.

6.6 Consent-Based Sharing

We may share your personal data with other third parties where you have given us your explicit consent to do so.

7. International Transfers of Personal Data

As a New Zealand-based business, your personal data is primarily processed and stored within New Zealand. However, some of our third-party service providers and technology partners may be located in countries outside of New Zealand and, where applicable, outside of the European Economic Area (EEA). In such cases, your personal data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.

Where we transfer personal data outside of New Zealand or the EEA, we take appropriate steps to ensure that such transfers are protected by adequate safeguards, which may include:

  • Transferring to countries recognised as providing an adequate level of data protection by the relevant authorities;
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Relying on Binding Corporate Rules (BCRs) where applicable;
  • Obtaining your explicit consent to the transfer where no other safeguard is available.

You may request further information about the specific safeguards applied to international data transfers by contacting our DPO at info@arnoviresortguide.com.

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting obligations. The criteria we use to determine retention periods include:

  • The duration of your relationship with us (for example, while you hold an active account or loyalty programme membership);
  • Legal and regulatory obligations that require us to retain records for a specified period (for example, financial records are typically retained for a minimum of seven years under accounting legislation);
  • The nature of the data and the sensitivity of the information involved;
  • The potential risk of harm from unauthorised use or disclosure of the data;
  • The purposes for which we process your data and whether those purposes can be achieved through other means.

The following general retention periods apply to the main categories of data we hold:

Category of Data Retention Period
Guest booking and reservation records 7 years from the date of the stay
Payment and financial transaction records 7 years from the date of transaction
Customer account data Duration of account activity plus 3 years following account closure
Marketing preferences and communications Until you withdraw consent or object, plus a reasonable period thereafter for record-keeping
Customer support and complaint records 3 years from the date of resolution
Casino and gaming records (where applicable) As required by applicable gaming regulations, typically up to 5 years
Website usage and analytics data Up to 26 months (anonymised data may be retained indefinitely)
CCTV footage Up to 30 days, unless required for a specific investigation or legal proceeding
Anti-money laundering records 5 years from the end of the customer relationship, as required by applicable AML legislation

Upon expiry of the applicable retention period, your personal data will be securely deleted or anonymised in accordance with our internal data disposal procedures.

9. Your Data Subject Rights

Under the GDPR and applicable data protection legislation, you have a number of rights in relation to the personal data we hold about you. These rights are described below. Please note that certain rights are subject to conditions, limitations, or exemptions, and may not apply in every circumstance.

9.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how we process it. This is known as a Subject Access Request (SAR). We will respond to your request within one calendar month of receipt, and this service is provided free of charge (unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to act on the request).

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will act on such requests without undue delay. If we have shared the inaccurate data with third parties, we will, where reasonably practicable, inform them of the correction.

9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request that we delete your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purposes for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • The data must be erased to comply with a legal obligation.

Please note that the right to erasure does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defence of legal claims.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have contested, or where you have objected to processing pending verification of our legitimate interests. Where processing is restricted, we will continue to store your data but will not process it further without your consent (except for limited purposes such as legal claims).

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit that data directly to another controller, where technically feasible.

9.6 Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis for processing, including profiling based on legitimate interests. Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defence of legal claims.

You also have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. We will act on such requests without undue delay.

9.7 Right to Withdraw Consent (Article 7(3) GDPR)

Where we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing that took place prior to withdrawal. To withdraw your consent, please contact us at info@arnoviresortguide.com or use the opt-out mechanism provided in our marketing communications.

9.8 Rights Related to Automated Decision-Making (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. Where such processing takes place, you have the right to obtain human intervention, express your point of view, and contest the decision.

9.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In New Zealand, the relevant authority is:

If you are located within the European Economic Area (EEA), you may also have the right to lodge a complaint with your local data protection supervisory authority.

We encourage you to contact us in the first instance so that we may attempt to resolve your concern directly.

9.10 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to us using the contact details below. We may need to verify your identity before processing your request. We will respond to all verified requests within one calendar month of receipt. In complex cases, we may extend this period by a further two months, in which case we will notify you of the extension within the initial one-month period.

10. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your browsing experience, analyse Website traffic, and deliver personalised content and advertising. A cookie is a small text file that is placed on your device when you visit a website. Cookies help us recognise your device on subsequent visits and remember your preferences.

We use the following categories of cookies:

  • Strictly Necessary Cookies: These cookies are essential for the operation of our Website and cannot be switched off. They include cookies that enable you to navigate the site, use secure areas, and complete bookings. No consent is required for these cookies.
  • Performance and Analytics Cookies: These cookies collect information about how visitors use our Website, including which pages are visited most often and any error messages received. This data is used to improve the Website's performance. These cookies require your consent.
  • Functional Cookies: These cookies allow the Website to remember choices you make (such as your preferred language or currency) and provide enhanced, personalised features. These cookies require your consent.
  • Targeting and Advertising Cookies: These cookies are used to deliver advertisements that are more relevant to you and your interests. They may also limit the number of times you see an advertisement and help measure the effectiveness of advertising campaigns. These cookies require your consent and may be set by third-party advertising networks.

When you first visit our Website, you will be presented with a cookie consent banner that allows you to choose which categories of cookies you wish to accept. You can update your cookie preferences at any time by clicking on the "Cookie Settings" link located in the footer of our Website.

You can also control cookies through your web browser settings. Most browsers allow you to refuse to accept cookies, delete existing cookies, and receive notification before a cookie is set. Please note that disabling certain cookies may affect the functionality of our Website.

11. Data Security

We take the security of your personal data extremely seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, alteration, disclosure, or destruction. Our security measures include, but are not limited to:

  • Encryption of data in transit using industry-standard TLS (Transport Layer Security) protocols;
  • Encryption of sensitive data at rest;
  • Access controls and role-based permissions to limit access to personal data to authorised personnel only;
  • Regular security assessments, vulnerability scans, and penetration testing;
  • Staff training on data protection and information security;
  • Physical security measures for our premises and server environments;
  • Data breach response procedures to enable prompt detection, investigation, and notification of any personal data breaches.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and provide information about the nature of the breach, the data affected, and the steps we have taken or propose to take to address it.

Please be aware that no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. You are responsible for keeping any account credentials or passwords confidential.

12. Children's Privacy

Our Website and casino services are not directed at, or intended for use by, children under the age of 18. We do not knowingly collect personal data from children under 18 years of age. Casino and gaming areas of our resort are strictly restricted to adults of legal gaming age in accordance with applicable gaming regulations.

If we become aware that we have inadvertently collected personal data from a child under 18 without appropriate parental or guardian consent, we will take immediate steps to delete that data from our records. If you believe that we may have collected personal data from a child under 18, please contact us immediately at info@arnoviresortguide.com.

14. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or operational requirements. When we make material changes to this Privacy Policy, we will notify you by posting the updated policy on this page with a revised "Last updated" date. Where required by applicable law, we will provide more prominent notice of material changes, such as via email notification to registered account holders or via a notification on our Website.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website after the posting of any changes constitutes your acceptance of those changes.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the manner in which we process your personal data, please do not hesitate to contact us using the details below:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address
Email Address info@arnoviresortguide.com
Website arnoviresortguide.com

We are committed to resolving any privacy-related concerns you may have in a fair, timely, and transparent manner. Please allow up to 30 calendar days for us to respond to your enquiry.

If you are not satisfied with our response, you have the right to escalate your complaint to the relevant data protection supervisory authority as described in Section 9.9 of this Privacy Policy.