Privacy Policy
Last updated: June 2025
At Morqessialuxelodge, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how collects, uses, stores, and shares your personal data when you visit our website at www.morqessialuxelodge.com, make a reservation, use our hotel-casino facilities, or otherwise interact with us. This policy is drafted in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR), as well as applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Please read this Privacy Policy carefully before using our website or services. By accessing our website or engaging with our services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal data (the Data Controller) is:
| Company Name | |
|---|---|
| Trading Name | Morqessialuxelodge |
| Registration Number | ACN 758 294 613 |
| VAT / Tax Number | ABN 61 758 294 613 |
| Registered Address | |
| Website | www.morqessialuxelodge.com |
| Privacy Contact Email | privacy@morqessialuxelodge.com |
If you have any questions, concerns, or requests regarding your personal data, please contact us using the details provided in the Contact Information section of this policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details below:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@morqessialuxelodge.com |
3. Personal Data We Collect
We collect various categories of personal data depending on how you interact with us. Personal data means any information that can identify you directly or indirectly as a natural person. We collect personal data in the following circumstances:
3.1 Data You Provide to Us Directly
- Identity Data: Full name, date of birth, gender, nationality, passport or government-issued identification number.
- Contact Data: Email address, telephone number, postal address, billing address.
- Reservation & Stay Data: Booking details, room preferences, check-in and check-out dates, length of stay, special requests, and any information relevant to the provision of hotel services.
- Payment Data: Credit or debit card details, bank account information, billing information, transaction history. Note: full payment card details are processed securely through our payment service providers and are not stored by us in full.
- Casino & Gaming Data: Player registration details, gaming activity, membership or loyalty programme data, self-exclusion requests, responsible gambling declarations, and records required under applicable gaming regulations.
- Account & Profile Data: Username, password, loyalty programme membership number, preferences, feedback, and survey responses.
- Communications Data: Records of your communications with us, including emails, live chat transcripts, complaint or feedback forms, and telephone call recordings (where permitted by law).
- Health & Special Category Data: Where you voluntarily provide information about dietary requirements, allergies, disabilities, or accessibility needs to enable us to provide appropriate services. This data is treated with the highest level of care and only processed with your explicit consent or where necessary to protect your vital interests.
- Marketing Preferences: Your preferences regarding receiving marketing communications from us and our selected partners.
3.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, time zone setting, browser plug-in types, operating system and platform, and other technology identifiers on the devices you use to access our website.
- Usage Data: Information about how you use our website, products, and services, including pages visited, links clicked, time spent on pages, referral URLs, and navigation patterns.
- Cookie & Tracking Data: Data collected through cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy section for further details.
3.3 Data Received from Third Parties
- Booking Platform Data: Personal data provided when you make a reservation through third-party booking platforms or travel agents (e.g., name, contact details, booking reference).
- Social Media Data: If you interact with us via social media platforms or choose to log in using a social media account, we may receive information from those platforms in accordance with your privacy settings on those platforms.
- Background Check & Regulatory Data: For casino and gaming operations, we may receive data from regulatory bodies, identity verification services, or anti-money laundering (AML) screening providers as required by law.
- Analytics Providers: Aggregated or pseudonymised data from analytics providers to help us understand website usage.
3.4 Data We Are Required to Collect by Law
In connection with casino and gaming operations, we are required under applicable gaming, anti-money laundering, and counter-terrorism financing legislation to collect and retain certain categories of personal data, including verified identity documents, source of funds declarations, and records of gaming transactions.
3.5 Data About Minors
Our website and casino services are not directed at, and we do not knowingly collect personal data from, persons under the age of 18 years. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data. If you believe we have collected data about a minor, please contact us immediately at privacy@morqessialuxelodge.com.
4. Legal Basis for Processing Personal Data
In accordance with Article 6 of the GDPR, we only process your personal data where we have a valid legal basis for doing so. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay.
- Processing payments for accommodation, dining, and other services.
- Managing your loyalty programme membership.
- Providing casino gaming services to registered members.
- Responding to service requests and fulfilling bookings.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where it is necessary for compliance with a legal obligation to which we are subject, including:
- Complying with anti-money laundering (AML) and counter-terrorism financing (CTF) obligations.
- Complying with gaming regulatory requirements, including Know Your Customer (KYC) obligations.
- Retaining financial and transaction records as required by tax and accounting legislation.
- Complying with law enforcement requests and court orders.
- Responsible gambling obligations, including self-exclusion registers.
- Guest registration obligations under applicable hospitality and immigration law.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of our legitimate interests (or those of a third party), except where such interests are overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Operating and improving our website and digital services.
- Fraud prevention, security monitoring, and risk management.
- Conducting analytics and research to improve our products and services.
- Maintaining and improving the safety and security of our premises through CCTV surveillance.
- Sending direct marketing communications about our services to existing customers (subject to your right to opt out).
- Exercising or defending legal claims.
- Managing business operations, including staff administration and internal reporting.
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent to process your personal data, we will clearly inform you and request your affirmative consent at the time of collection. You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. We rely on consent for:
- Sending you marketing communications where you are a new customer or have specifically opted in.
- Placing non-essential cookies and tracking technologies on your device.
- Processing special category data (e.g., health information for accessibility purposes) where no other legal basis applies.
- Profiling activities that are not strictly necessary for the provision of our services.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data to protect the vital interests of you or another natural person, for example in a medical emergency on our premises.
4.6 Special Categories of Personal Data (Article 9 GDPR)
Where we process special categories of personal data (such as health information, biometric data, or data revealing racial or ethnic origin), we rely on explicit consent (Article 9(2)(a)), the necessity for the establishment, exercise, or defence of legal claims (Article 9(2)(f)), or other applicable grounds under Article 9(2) of the GDPR. We apply enhanced safeguards to such data at all times.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Provision of Hotel Services
- Processing, confirming, and managing hotel reservations and check-ins.
- Providing accommodation, room service, dining, spa, and other on-site services.
- Processing payments and issuing invoices and receipts.
- Managing special requests, accessibility requirements, and guest preferences.
- Communicating with you about your booking before, during, and after your stay.
5.2 Casino & Gaming Operations
- Registering and verifying your identity as a casino member or player.
- Managing gaming accounts, player rewards, and loyalty programmes.
- Conducting AML/CTF checks and ongoing monitoring as required by law.
- Administering responsible gambling programmes, including self-exclusion.
- Complying with gaming regulatory reporting obligations.
- Detecting and preventing fraudulent or suspicious activity.
5.3 Website & Digital Services
- Operating and maintaining our website and online booking systems.
- Personalising your online experience based on your preferences and browsing history.
- Analysing website traffic and usage patterns to improve functionality and content.
- Administering online accounts, including password management and security.
5.4 Marketing & Communications
- Sending you information about our offers, promotions, events, and services that may be of interest to you, where you have provided consent or where we have a legitimate interest to do so.
- Conducting customer satisfaction surveys and requesting reviews.
- Personalising marketing communications based on your preferences and past interactions.
- Managing your marketing preferences and opt-out requests.
5.5 Security & Fraud Prevention
- Operating CCTV surveillance systems throughout our premises for the safety and security of guests, staff, and property.
- Detecting, investigating, and preventing fraudulent transactions and other illegal activities.
- Verifying your identity and conducting background checks where required.
5.6 Legal & Regulatory Compliance
- Complying with all applicable laws, regulations, and regulatory obligations.
- Responding to legal processes, court orders, and government or regulatory inquiries.
- Establishing, exercising, or defending legal claims.
- Maintaining required records and documentation.
5.7 Business Operations & Improvement
- Conducting internal analysis, research, and reporting to improve our services.
- Managing and auditing our business operations, including financial and operational reporting.
- Training staff using anonymised or aggregated data.
- Carrying out due diligence in connection with business transactions.
7. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may, however, share your personal data with the following categories of recipients for the purposes described in this Privacy Policy:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:
- Payment processing and fraud prevention providers.
- Hotel property management system (PMS) providers.
- IT infrastructure, cloud hosting, and cybersecurity providers.
- Email marketing and customer relationship management (CRM) platforms.
- Website analytics providers (e.g., Google Analytics).
- Identity verification and KYC/AML screening providers.
- Customer support and helpdesk software providers.
- Gaming platform and casino management system providers.
- Printing, mailing, and document management services.
All service providers are bound by contractual obligations (including Data Processing Agreements where required under GDPR) to keep your personal data confidential and secure, and to process it only in accordance with our instructions.
7.2 Business Partners
We may share your personal data with carefully selected business partners where this is necessary to provide services you have requested or to offer you relevant products and services. We will only share your data with partners in this context where we have a valid legal basis to do so.
7.3 Regulatory and Government Authorities
We may disclose your personal data to regulatory authorities, law enforcement agencies, government bodies, or other competent authorities where required to do so by applicable law or regulation, including:
- Gaming regulatory authorities and commissions.
- Financial intelligence units and AML/CTF authorities.
- Tax authorities (e.g., the Australian Taxation Office).
- Law enforcement agencies and courts.
7.4 Professional Advisers
We may share personal data with our legal advisers, accountants, auditors, and insurers where necessary in connection with the provision of professional services to us.
7.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or other business transaction, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you in advance of any such transfer that materially affects the use of your personal data, and we will ensure that appropriate safeguards are in place.
7.6 International Transfers
is based in Australia. Some of our service providers and partners may be located in countries outside of Australia and the European Economic Area (EEA). Where we transfer personal data to countries that do not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place in accordance with applicable law, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the European Commission recognising the recipient country as providing an adequate level of protection.
- Binding Corporate Rules (BCRs) where applicable.
- Other legally recognised transfer mechanisms under the GDPR and the Australian Privacy Act.
You may request further information about our international transfer safeguards by contacting us at privacy@morqessialuxelodge.com.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting obligations. The criteria we use to determine appropriate retention periods include:
- The nature and sensitivity of the personal data.
- The purposes for which the data is processed and whether those purposes can be achieved by other means.
- Applicable statutory, regulatory, or contractual retention requirements.
- Whether you have made a request for deletion.
8.1 Key Retention Periods
| Category of Data | Retention Period | Legal Basis / Reason |
|---|---|---|
| Hotel reservation and guest records | 7 years from date of stay | Legal obligation (tax, accounting); legitimate interests |
| Payment transaction records | 7 years from date of transaction | Legal obligation (tax and financial regulations) |
| Casino gaming and player records | 7 years from closure of account or last transaction | Legal obligation (gaming regulation, AML/CTF) |
| AML/KYC identity verification records | 5–7 years from end of business relationship | Legal obligation (AML/CTF legislation) |
| Marketing and communication preferences | Until you opt out or withdraw consent, plus 1 year | Consent; legitimate interests |
| Website cookies and analytics data | As specified in our Cookie Policy (typically up to 2 years) | Consent; legitimate interests |
| CCTV footage | Up to 31 days, unless required for an investigation | Legitimate interests; legal obligation |
| Correspondence and complaints | 3 years from resolution of the matter | Legitimate interests; legal claims |
| Self-exclusion records (responsible gambling) | Duration of exclusion plus 5 years | Legal obligation; vital interests |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data has been anonymised, it may be retained indefinitely for statistical or research purposes.
9. Your Rights Under the GDPR
Under the GDPR, you have a number of important rights in relation to the personal data we hold about you. We have set out these rights below, together with information on how to exercise them.
9.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This is known as a Subject Access Request (SAR). We will provide this information free of charge within one calendar month of receiving your request (which may be extended by a further two months in complex cases).
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will use reasonable efforts to update or correct the information promptly upon receiving your request.
9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw consent on which processing is based and there is no other legal ground.
- You object to processing and there are no overriding legitimate grounds.
- The data has been unlawfully processed.
- The data must be erased to comply with a legal obligation.
Please note that this right is not absolute and may be limited where we are required to retain data under legal or regulatory obligations.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have disputed, or where you have objected to processing pending verification of our legitimate grounds.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another data controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests or is carried out for direct marketing purposes (including profiling for direct marketing). Where you object to direct marketing, we will cease processing your data for those purposes immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects concerning you. We will inform you where any such automated decision-making is taking place, and you will have the right to request human review, express your point of view, and contest the decision.
9.8 Right to Withdraw Consent
Where we rely on consent as the legal basis for processing your personal data, you have the right to withdraw your consent at any time without detriment. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@morqessialuxelodge.com or use the unsubscribe link in any marketing communication we send you.
9.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at:
- Email: privacy@morqessialuxelodge.com
- Post: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will respond to your request within one calendar month of receipt. If your request is complex or we have received a number of requests, we may extend this period by a further two months, in which case we will notify you within the first month.
There is no charge for exercising your rights. However, we reserve the right to charge a reasonable administrative fee or refuse to act on a request that is manifestly unfounded or excessive.
9.10 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR or other applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. For individuals located in the European Economic Area, the relevant supervisory authority is typically the data protection authority of your country of habitual residence, place of work, or the place of the alleged infringement.
For individuals located in Australia, complaints may be made to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001, Australia
We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority, and encourage you to contact us in the first instance at privacy@morqessialuxelodge.com.
10. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption of personal data in transit (using SSL/TLS protocols) and at rest where appropriate.
- Strict access controls and role-based access permissions for staff handling personal data.
- Regular security assessments, penetration testing, and vulnerability management.
- Staff training on data protection and information security.
- Physical security measures at our premises.
- Data minimisation and pseudonymisation practices where feasible.
- Incident response and data breach notification procedures.
While we take all reasonable steps to protect your personal data, no data transmission over the internet or data storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at privacy@morqessialuxelodge.com.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR. We will also notify the relevant supervisory authority as required by Article 33 of the GDPR.
11. Third-Party Links and Websites
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control those third-party websites and are not responsible for their privacy policies or practices. We encourage you to review the privacy policy of every website you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or regulatory requirements. When we make material changes to this policy, we will notify you by:
- Posting the updated Privacy Policy on our website with a revised "Last Updated" date.
- Sending you an email notification where you have provided us with your email address and the change is materially significant.
- Displaying a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us using the details below:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Address | |
| privacy@morqessialuxelodge.com | |
| Website | www.morqessialuxelodge.com |
We are committed to resolving any complaints or concerns regarding your personal data promptly and fairly. Please do not hesitate to reach out to us at any time.