Privacy Policy
Last updated: June 2025
Welcome to Mirenoroyalresort. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Australian Privacy Act 1988 (Cth), and all other applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect, how we use it, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.
Please read this Privacy Policy carefully before using our website at www.mirenoroyalresort.com (the "Website") or engaging with our services. By accessing or using our Website, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for processing your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Trading Name | Mirenoroyalresort |
| Registration Country | Australia |
| Legal Address | |
| Website | www.mirenoroyalresort.com |
| info@mirenoroyalresort.com |
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, you may contact our Data Protection Officer (DPO) at any time using the contact details provided in Section 12 of this Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and ensuring our compliance with applicable data protection laws.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| info@mirenoroyalresort.com | |
| Postal Address |
You have the right to contact our DPO directly at any time regarding any matter relating to your personal data or this Privacy Policy.
3. Scope and Application of This Policy
This Privacy Policy applies to all personal data collected and processed by in connection with:
- Use of our Website at www.mirenoroyalresort.com;
- Hotel accommodation bookings and reservations;
- Casino services and gaming activities;
- Restaurant, spa, and entertainment services offered at the resort;
- Loyalty and rewards programme membership;
- Customer service, complaints, and enquiry handling;
- Marketing and promotional communications;
- Employment applications and recruitment processes;
- Any other interactions between you and Mirenoroyalresort.
This Policy applies to all individuals whose personal data we process, including guests, website visitors, potential customers, loyalty programme members, and third parties who interact with us.
4. Personal Data We Collect
We collect and process various categories of personal data depending on your interactions with us. The categories of personal data we may collect include, but are not limited to, the following:
4.1 Identity and Contact Data
- Full name (first name, last name, title);
- Date of birth and age verification information;
- Gender;
- Nationality and country of residence;
- Passport or government-issued identification number (where required by law);
- Email address;
- Telephone number (mobile and/or landline);
- Postal address (home, billing, and/or correspondence address);
- Signature (where applicable for legal documents).
4.2 Reservation and Booking Data
- Check-in and check-out dates;
- Room type, preferences, and special requests;
- Number of guests and guest details;
- Booking confirmation numbers and reservation history;
- Purpose of visit (leisure, business, etc.);
- Dietary requirements and accessibility needs.
4.3 Financial and Payment Data
- Credit or debit card details (processed securely via encrypted payment gateways; we do not store full card numbers);
- Bank account details (where applicable for refunds or direct payments);
- Billing address;
- Transaction history and payment records;
- Casino account balances, gaming credits, and financial transactions related to gaming activities.
4.4 Gaming and Casino Data
- Casino membership and player account information;
- Gaming activity data, including games played, wagers, winnings, and losses;
- Responsible gambling assessments and self-exclusion records;
- Identity verification documents for anti-money laundering (AML) and Know Your Customer (KYC) compliance;
- Source of funds documentation (where required by gaming regulations);
- Bonus and promotional offer participation records.
4.5 Technical and Usage Data
- IP address and geolocation data;
- Browser type, version, and operating system;
- Device type and device identifiers;
- Pages visited, time spent on pages, and navigation paths;
- Referring URLs and exit pages;
- Cookie identifiers and similar tracking technologies (please refer to our Cookie Policy);
- Log data and access records.
4.6 Communication and Interaction Data
- Correspondence via email, telephone, live chat, or post;
- Feedback, reviews, and survey responses;
- Customer service enquiry records and complaint logs;
- Social media interactions (where you contact us through social media platforms).
4.7 Marketing and Preference Data
- Marketing communication preferences;
- Loyalty programme participation and reward redemption history;
- Preferences regarding services, amenities, and activities;
- Responses to marketing campaigns and promotional offers.
4.8 Special Categories of Personal Data
In certain circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These may include:
- Health and medical information (e.g., accessibility requirements, dietary restrictions related to health conditions, or medical emergencies during your stay);
- Biometric data (e.g., where facial recognition or fingerprint scanning is used for security or access control on our premises);
- Information relating to criminal convictions and offences (where required for regulatory compliance, fraud prevention, or under gaming licensing obligations).
We process special category data only where we have a lawful basis to do so under both Article 6 and Article 9 of the GDPR, and we implement enhanced safeguards to protect such data.
4.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia);
- Travel agents and tour operators;
- Corporate clients making reservations on your behalf;
- Social media platforms (where you interact with our social media presence);
- Fraud prevention and identity verification service providers;
- Credit reference agencies and background check providers;
- Regulatory bodies and law enforcement agencies (where applicable).
5. Legal Basis for Processing Your Personal Data
In accordance with Article 6 of the GDPR, we rely on one or more of the following lawful bases when processing your personal data:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This applies, for example, when:
- Processing your hotel reservation and managing your stay;
- Administering your casino account and processing gaming transactions;
- Providing the services you have requested, including dining, spa, and entertainment;
- Processing payments and managing billing;
- Administering loyalty programme membership and reward redemption.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where necessary to comply with our legal and regulatory obligations, including:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under applicable gaming and financial regulations;
- Know Your Customer (KYC) and identity verification requirements;
- Tax reporting and financial record-keeping obligations;
- Compliance with gaming licensing conditions issued by the relevant regulatory authorities;
- Responding to lawful requests from law enforcement, regulatory bodies, or courts;
- Health and safety obligations, including incident reporting;
- Responsible gambling obligations, including self-exclusion scheme administration.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of the legitimate interests pursued by us or a third party, except where those interests are overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Improving and developing our Website, services, and guest experience;
- Detecting, preventing, and investigating fraud, security incidents, and other unlawful activity;
- Protecting the safety and security of our guests, staff, and premises through CCTV surveillance and access control;
- Conducting internal analytics and business intelligence to optimise our operations;
- Sending you relevant direct marketing communications about our services (subject to your right to object);
- Managing and resolving disputes and legal claims;
- Maintaining our reputation and business relationships.
When we rely on legitimate interests as our lawful basis, we conduct a legitimate interests assessment (LIA) to ensure that your interests and rights are appropriately balanced against ours.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the lawful basis for processing, we will obtain your explicit and freely given consent before processing your personal data. This applies, for example, to:
- Sending you marketing communications via email, SMS, or other channels (where required by law);
- Placing non-essential cookies and tracking technologies on your device (in accordance with our Cookie Policy);
- Processing special categories of personal data (where applicable);
- Sharing your data with selected third-party partners for their own marketing purposes.
You have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to the withdrawal. To withdraw your consent, please contact us using the details in Section 12 of this Policy.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process your personal data where it is necessary to protect your vital interests or those of another person, for example, in the event of a medical emergency during your stay at Mirenoroyalresort.
5.6 Public Task (Article 6(1)(e) GDPR)
Where applicable, we may process personal data in the exercise of official authority or for the performance of a task carried out in the public interest, including cooperation with regulatory and law enforcement authorities.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Providing and Managing Our Services
- Processing and managing hotel reservations, check-in and check-out procedures;
- Allocating rooms and accommodating special requests and preferences;
- Providing casino and gaming services, including account management and transaction processing;
- Delivering restaurant, spa, entertainment, and ancillary services;
- Processing payments and issuing invoices and receipts;
- Managing loyalty programme accounts and reward redemptions.
6.2 Customer Service and Communications
- Responding to your enquiries, requests, and complaints;
- Sending booking confirmations, pre-arrival information, and post-stay communications;
- Notifying you of important changes to our services, terms, or this Privacy Policy;
- Conducting post-stay satisfaction surveys and collecting feedback.
6.3 Marketing and Personalisation
- Sending you promotional offers, newsletters, and marketing communications about our services and special offers (where you have consented or where we have a legitimate interest to do so);
- Personalising your experience on our Website and tailoring offers to your preferences;
- Conducting targeted advertising on third-party platforms (where you have consented);
- Analysing your preferences and behaviour to make relevant recommendations.
6.4 Regulatory Compliance and Legal Obligations
- Verifying your identity and age for gaming and legal compliance purposes;
- Complying with AML, KYC, and responsible gambling regulations;
- Maintaining records required by gaming regulators, tax authorities, and other statutory bodies;
- Investigating and reporting suspicious activity as required by law;
- Cooperating with regulatory investigations and audits.
6.5 Security and Fraud Prevention
- Monitoring and securing our premises through CCTV and security systems;
- Detecting, preventing, and investigating fraudulent transactions, cheating, and other illicit activity;
- Protecting the integrity of our gaming operations;
- Ensuring the physical safety of guests and staff.
6.6 Business Operations and Improvement
- Conducting internal analytics, reporting, and business intelligence;
- Improving our Website functionality, user experience, and service quality;
- Training our staff and improving service delivery;
- Managing our IT systems, network security, and data infrastructure;
- Conducting risk assessments and internal audits.
7. Sharing Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients where there is a lawful basis for doing so:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions, including:
- IT and technology service providers (hosting, software, cybersecurity);
- Payment processing and banking service providers;
- Customer relationship management (CRM) platform providers;
- Email marketing and communication service providers;
- Analytics and web optimisation service providers;
- Identity verification and fraud prevention service providers;
- Printing and mailing service providers.
All third-party processors are subject to appropriate data processing agreements and are required to implement adequate technical and organisational security measures to protect your personal data.
7.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to regulatory bodies, law enforcement agencies, courts, and other public authorities where we are legally required or permitted to do so, including:
- Gaming and casino regulatory authorities in Australia;
- The Australian Transaction Reports and Analysis Centre (AUSTRAC) and other AML/CTF authorities;
- The Australian Taxation Office (ATO) and other tax authorities;
- Police and law enforcement agencies (pursuant to lawful requests or court orders);
- Any other competent authority where disclosure is required by applicable law.
7.3 Business Partners and Group Companies
We may share your personal data with affiliated companies within our corporate group and with carefully selected business partners for the purposes of providing integrated services, joint marketing activities, or operational support.
7.4 Online Travel Agencies and Booking Platforms
Where your reservation was made through a third-party booking platform or travel agent, we may exchange necessary booking and guest information with such parties to fulfil your reservation.
7.5 Professional Advisors
We may share your personal data with our legal advisors, auditors, accountants, and insurers where necessary for the provision of professional services to us.
7.6 Transfers in the Event of Corporate Transactions
In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer where required by law.
7.7 International Transfers of Personal Data
Where we transfer your personal data to recipients located outside the European Economic Area (EEA) or Australia, we ensure that appropriate safeguards are in place to protect your personal data in accordance with applicable data protection laws. Such safeguards may include:
- Adequacy decisions by the European Commission confirming that the recipient country ensures an adequate level of data protection;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Other legally recognised transfer mechanisms under the GDPR and the Australian Privacy Act.
You may request a copy of the safeguards we have implemented for international transfers by contacting our DPO using the details provided in Section 12.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The following retention periods apply:
| Category of Personal Data | Retention Period | Reason |
|---|---|---|
| Guest reservation and booking records | 7 years from the date of the last stay | Legal and tax compliance; potential dispute resolution |
| Financial and payment records | 7 years from the date of the transaction | Tax law obligations (Australian Taxation Law) |
| Casino account and gaming records | 7 years from account closure or last activity | AML/CTF regulatory obligations and gaming licence conditions |
| Identity verification (KYC) documents | 7 years from account closure or last transaction | AML/CTF legal obligations |
| Responsible gambling and self-exclusion records | Duration of exclusion plus 7 years | Regulatory compliance and duty of care |
| Marketing communications and preferences | Until consent is withdrawn or opt-out is actioned, plus 3 years | Legitimate interests and consent management |
| CCTV footage | Up to 31 days (unless retained for longer due to an incident) | Security and safety; investigation of incidents |
| Website technical logs and cookies | Up to 13 months | Technical operations and analytics |
| Customer service and complaint records | 5 years from resolution | Legal claims limitation periods |
| Job application and recruitment records | 6 months (unsuccessful applicants); duration of employment plus 7 years (successful applicants) | Legal obligation and employment law compliance |
At the expiry of the applicable retention period, your personal data will be securely deleted, anonymised, or archived in accordance with our data retention and destruction procedures.
9. Your Rights Under the GDPR and Applicable Data Protection Law
Subject to applicable law and certain exemptions, you have the following rights in relation to your personal data:
9.1 Right of Access (Article 15 GDPR)
You have the right to request confirmation of whether we process personal data about you and, if so, to receive a copy of that personal data along with information about how it is processed (a "Subject Access Request" or "SAR"). We will respond to your request within one month of receipt, which may be extended by a further two months in complex cases.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you or complete any incomplete personal data without undue delay.
9.3 Right to Erasure ("Right to Be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data where:
- The personal data is no longer necessary for the purposes for which it was collected;
- You have withdrawn your consent and there is no other lawful basis for processing;
- You have objected to processing and there are no overriding legitimate grounds;
- The personal data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute and may be subject to exemptions, for example, where we are required to retain data to comply with a legal obligation or for the establishment, exercise, or defence of legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, where you contest the accuracy of the data or where you have objected to processing, while we verify our legitimate grounds.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where processing is based on our legitimate interests or on the performance of a public task. You also have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. Where you object to direct marketing, we will cease processing your data for that purpose without undue delay.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for the performance of a contract, is authorised by law, or is based on your explicit consent. Where we engage in automated decision-making that has a significant impact on you, we will inform you of this and provide you with the opportunity to request human review of the decision.
9.8 Right to Withdraw Consent
Where we rely on your consent as the lawful basis for processing your personal data, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent, please contact us at info@mirenoroyalresort.com.
9.9 Right to Lodge a Complaint with a Supervisory Authority
If you believe that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority. In Australia, the relevant authority is:
-
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Telephone: 1300 363 992
If you are located in the European Union or European Economic Area, you also have the right to lodge a complaint with the data protection supervisory authority in your country of residence or place of work.
9.10 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to our Data Protection Officer using the contact details in Section 12 of this Policy. We may require you to provide proof of your identity before processing your request in order to protect your personal data from unauthorised disclosure. We will respond to all valid requests within one calendar month. In complex or multiple cases, this period may be extended by a further two months, and we will notify you accordingly.
There is no fee for exercising your rights in most circumstances. However, we reserve the right to charge a reasonable administrative fee or refuse to act on manifestly unfounded or excessive requests.
11. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- SSL/TLS encryption for data transmitted via our Website;
- Secure, encrypted storage of personal data;
- Access controls and role-based permissions limiting access to personal data to authorised personnel only;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures;
- Physical security measures at our premises, including access control and CCTV surveillance.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR.
Please note that while we take all reasonable steps to protect your personal data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your personal data transmitted to our Website.
12. Third-Party Websites and Links
Our Website may contain links to third-party websites, social media platforms, and external services. This Privacy Policy applies solely to our Website and our processing activities. We are not responsible for the privacy practices of third-party websites and encourage you to review the privacy policies of any third-party websites you visit.
13. Children's Privacy
Our casino services are strictly restricted to individuals aged 18 years and over. We do not knowingly collect personal data from children under the age of 18 in connection with our gaming services. Our Website is not directed at children under 18.
For other hotel and resort services, where we collect data about children (for example, as part of a family reservation), we do so only with the consent of the child's parent or legal guardian, and we process such data solely for the purposes of providing the relevant services.
If we become aware that we have inadvertently collected personal data from a child under the age of 18 without parental consent in connection with casino services, we will take immediate steps to delete that information. If you believe we may have collected personal data from a child, please contact us at info@mirenoroyalresort.com.
14. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or regulatory requirements. The updated Privacy Policy will be published on our Website with the revised "Last Updated" date at the top of the document.
Where changes to this Privacy Policy are material, we will take reasonable steps to notify you, for example, by posting a prominent notice on our Website or by sending you a notification via email. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Your continued use of our Website or services after the effective date of any revised Privacy Policy constitutes your acceptance of the changes.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing activities, or if you wish to exercise any of your rights described in Section 9, please contact our Data Protection Officer using the following details:
| Contact | The Data Protection Officer |
|---|---|
| Organisation | |
| info@mirenoroyalresort.com | |
| Postal Address | |
| Website | www.mirenoroyalresort.com |
We are committed to addressing your concerns and will make every effort to respond to your enquiries and requests in a timely and transparent manner. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 9.9 above.