Privacy Policy
Last updated: June 2025
This Privacy Policy describes how ("we", "us", "our", or "the Hotel") collects, uses, stores, shares, and protects your personal data when you visit or interact with our website neoaneresorthouse.com, make a reservation, use our hotel or casino facilities, or otherwise communicate with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation.
Please read this Privacy Policy carefully before using our website or services. By accessing our website or providing your personal data to us, you acknowledge that you have read and understood the practices described herein.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | Neoaneresort House |
| Registration Country | New Zealand |
| Company Registration Number | 9429047628 |
| VAT / GST Number | NZ 134-287-619 |
| Registered Legal Address | |
| Website | neoaneresorthouse.com |
| Privacy & Data Protection Email | info@neoaneresorthouse.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. You may contact our DPO directly at any time regarding any data protection matter:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@neoaneresorthouse.com |
2. Personal Data We Collect
We collect various categories of personal data depending on how you interact with us. Personal data means any information relating to an identified or identifiable natural person. The categories we may collect include, but are not limited to, the following:
2.1 Identity and Contact Data
- Full name, title, and date of birth
- Passport or national identity card number and copy (where required by law or for check-in purposes)
- Nationality and country of residence
- Postal address, email address, and telephone number
- Signature
2.2 Reservation and Stay Data
- Booking reference numbers and reservation history
- Dates of arrival and departure
- Room type preferences and special requests (e.g., accessibility needs, dietary requirements)
- Number of guests accompanying you and their details where provided
- Loyalty programme membership details
2.3 Financial and Payment Data
- Credit and debit card details (processed securely via PCI-DSS-compliant payment processors)
- Bank account information where relevant for refunds or corporate billing
- Transaction history and billing records
- Invoice and receipt information
2.4 Casino and Gaming Data
- Casino membership or player card number
- Gaming activity records, including bets placed, wins, and losses
- Identity verification documents required under Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations
- Self-exclusion programme registration and status
- Responsible gambling assessments and interaction records
- Source of funds documentation where legally required
2.5 Technical and Usage Data
- IP address and device identifiers
- Browser type, version, and operating system
- Pages visited, time spent on pages, and clickstream data
- Referring URLs and exit pages
- Cookie identifiers and similar tracking technology data (see our Cookie Policy)
- Log files and access records
2.6 Communications Data
- Records of correspondence, emails, live chat transcripts, and telephone call logs
- Feedback, survey responses, and reviews submitted by you
- Complaints and enquiry records
2.7 Marketing and Preference Data
- Marketing communication preferences and consent records
- Interests and preferences inferred from your use of our services
- Participation in promotions, competitions, and special offers
2.8 Health and Special Category Data
In limited circumstances, we may process special category data as defined under GDPR Article 9. For example, we may process information about dietary requirements or health conditions that you voluntarily provide to us to enable us to accommodate your specific needs during your stay. We may also process health-related data in the context of responsible gambling assessments. We process such data only where we have obtained your explicit consent or where processing is necessary to protect your vital interests or comply with a legal obligation.
2.9 CCTV and Surveillance Data
Our hotel and casino premises are monitored by closed-circuit television (CCTV) cameras for security, safety, and regulatory compliance purposes. Images captured by CCTV systems may constitute personal data where individuals are identifiable.
2.10 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Travel agents, online travel agencies (OTAs), and booking platforms
- Corporate clients booking on your behalf
- Fraud prevention and identity verification agencies
- Credit reference and anti-money laundering screening agencies
- Regulatory authorities, law enforcement bodies, and government agencies
- Publicly available sources such as company registries and sanctions lists
3. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, the legal bases on which we rely are as follows:
3.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. We rely on this basis when processing your data to:
- Process and manage your hotel reservation
- Administer your casino membership and gaming account
- Process payments and issue invoices and receipts
- Fulfil special requests made at the time of booking or check-in
- Respond to your direct enquiries and communications
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation to which we are subject. We rely on this basis when we are required to:
- Verify the identity of guests and casino patrons under New Zealand's Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act)
- Retain financial records for tax and accounting purposes
- Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit
- Comply with responsible gambling obligations under the Gambling Act 2003
- Comply with requests from regulatory and law enforcement authorities
- Register overseas visitors as required by immigration legislation
- Comply with health and safety laws and regulations
3.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on legitimate interests to:
- Operate and improve our website and online booking systems
- Maintain the security of our premises and guests through CCTV surveillance
- Detect, prevent, and investigate fraud, theft, and other criminal activity
- Conduct business analytics and service improvement activities
- Manage and resolve disputes and legal claims
- Send you service-related communications and updates
- Administer our loyalty and rewards programme
- Conduct customer satisfaction surveys
- Share data within our corporate group for internal administrative purposes
Where we rely on legitimate interests, we conduct a balancing test to ensure that your interests and rights are not overridden. You have the right to object to processing carried out on this basis. Please see Section 8 for further information on how to exercise this right.
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will obtain your freely given, specific, informed, and unambiguous consent before processing your data. We rely on consent to:
- Send you direct marketing communications by email, SMS, or post about our offers, promotions, and news
- Place non-essential cookies and tracking technologies on your device
- Process special category data, such as health or dietary information, where no other legal basis applies
Where we rely on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw your consent, please contact us at info@neoaneresorthouse.com or use the unsubscribe mechanism included in our marketing communications.
3.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where such processing is necessary to protect your vital interests or those of another natural person, for example in a medical emergency occurring on our premises.
3.6 Public Task (Article 6(1)(e))
Where applicable, we may process personal data in the exercise of official authority vested in us or in the performance of tasks carried out in the public interest, such as cooperation with regulatory bodies overseeing casino operations.
3.7 Special Category Data (Article 9)
Where we process special category data (e.g., health data, data concerning criminal convictions in the context of responsible gambling or AML compliance), we rely on the following additional conditions under GDPR Article 9(2):
- Your explicit consent (Article 9(2)(a))
- Protecting your vital interests where you are unable to give consent (Article 9(2)(c))
- Processing necessary for reasons of substantial public interest under applicable law (Article 9(2)(g))
- Processing necessary for the establishment, exercise, or defence of legal claims (Article 9(2)(f))
4. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
4.1 Hotel Operations and Guest Services
- Processing and confirming reservations, check-in, and check-out
- Allocating and preparing rooms and facilities according to your preferences
- Providing in-stay services, including room service, concierge, and facilities access
- Managing billing, payments, and refunds
- Communicating with you before, during, and after your stay
- Managing loyalty programme accounts and benefits
4.2 Casino and Gaming Operations
- Verifying your identity and age for casino entry and gaming account registration
- Managing and administering your casino player account
- Conducting AML/CFT checks, including transaction monitoring and sanctions screening
- Administering self-exclusion, responsible gambling, and player protection measures
- Complying with reporting obligations to regulatory bodies
4.3 Website and Digital Services
- Operating and maintaining our website and online booking engine
- Personalising your online experience and displaying relevant content
- Analysing website traffic and user behaviour to improve functionality
- Managing cookie preferences and consent
4.4 Marketing and Communications
- Sending marketing communications about our offers, events, and promotions (where you have given consent or we have a legitimate interest to do so)
- Conducting surveys and collecting feedback to improve our services
- Inviting you to participate in competitions and special programmes
4.5 Security, Safety, and Fraud Prevention
- Monitoring our premises via CCTV to protect the safety of guests, staff, and property
- Detecting, investigating, and preventing fraud, theft, cheating, and other criminal activity
- Managing access control to restricted areas of the hotel and casino
4.6 Legal and Regulatory Compliance
- Complying with legal obligations imposed by applicable laws and regulations
- Responding to lawful requests from courts, regulators, and law enforcement agencies
- Establishing, exercising, or defending legal claims
- Maintaining records as required by law
4.7 Business Management and Improvement
- Conducting internal audits, risk management, and business analytics
- Training staff to improve service delivery
- Managing corporate relationships and group bookings
5. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate contractual and legal safeguards:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf in accordance with our instructions and applicable data protection laws. These include:
- Payment processing and card scheme providers
- Cloud computing, hosting, and IT infrastructure providers
- Property management system (PMS) and casino management system (CMS) vendors
- Online booking and reservation platform providers
- Customer relationship management (CRM) platform providers
- Email marketing and communication service providers
- CCTV and physical security system operators
- Identity verification and KYC service providers
- Fraud detection and prevention service providers
- Legal, accounting, and auditing advisors
5.2 Regulatory and Government Authorities
We may disclose your personal data to regulatory bodies, government agencies, and law enforcement authorities where we are required to do so by law, including:
- New Zealand Police and the Financial Intelligence Unit (FIU)
- The Department of Internal Affairs (DIA) as the casino regulator
- New Zealand Customs Service and Immigration New Zealand
- Inland Revenue Department (IRD)
- Any other authority with lawful jurisdiction
5.3 Business Partners
Where you have booked through a travel agent, online travel agency, tour operator, or corporate client, we may share relevant booking and stay information with that party for the purpose of managing your reservation and providing services to you.
5.4 Professional Advisors
We may share your data with our legal counsel, insurers, accountants, and other professional advisors where necessary for the purposes of obtaining professional advice or managing legal proceedings.
5.5 Corporate Transactions
In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and any changes to this Privacy Policy that may result.
5.6 International Transfers
Your personal data may be transferred to, and processed in, countries outside of New Zealand and the European Economic Area (EEA). Where such transfers occur, we ensure that appropriate safeguards are in place to protect your personal data, including:
- Transfers to countries recognised as providing an adequate level of data protection by the European Commission or the New Zealand Privacy Commissioner
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Other legally approved transfer mechanisms
You may obtain a copy of the applicable transfer safeguards by contacting us at info@neoaneresorthouse.com.
6. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting obligations. The criteria we use to determine the appropriate retention period include:
- The nature and sensitivity of the personal data
- The purpose for which we hold the data and whether that purpose has been fulfilled
- Applicable statutory retention requirements under New Zealand law, GDPR, and other relevant legislation
- Whether there is an ongoing legal claim or dispute that requires us to retain relevant data
- Our legitimate business needs, such as maintaining accurate accounting records
As a general guide, we apply the following indicative retention periods:
| Category of Data | Indicative Retention Period | Legal Basis for Retention |
|---|---|---|
| Reservation and stay records | 7 years from date of stay | Legal obligation (tax and accounting); legitimate interests |
| Financial and payment records | 7 years from transaction date | Legal obligation (Inland Revenue, financial regulations) |
| Casino membership and gaming records | 7 years from account closure or last activity | Legal obligation (AML/CFT Act, Gambling Act) |
| AML/KYC identity verification documents | 5–7 years from the end of the business relationship | Legal obligation (AML/CFT Act 2009) |
| CCTV footage | 30 days, unless retained for investigation purposes | Legitimate interests; legal obligation |
| Marketing preference records and consent | 3 years from last interaction or until consent is withdrawn | Consent; legitimate interests |
| Customer complaint and correspondence records | 6 years from resolution | Legitimate interests; legal obligation |
| Website usage and cookie data | Up to 13 months from collection | Consent; legitimate interests |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data retention and disposal procedures. In some circumstances, you may request the earlier erasure of your personal data — please see Section 8 below.
8. Your Rights Under Data Protection Law
Subject to applicable law, you have the following rights in relation to your personal data. You may exercise these rights by contacting us using the details provided in Section 9 of this Privacy Policy.
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data together with information about the purposes of processing, categories of data involved, recipients, retention periods, and your other rights.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete personal data completed.
8.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw consent on which processing is based, or where you object to processing and there are no overriding legitimate grounds. This right is not absolute and does not apply where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of your data while we verify it, or where processing is unlawful but you prefer restriction to erasure.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where such processing is based on our legitimate interests (Article 6(1)(f)). Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
You also have an absolute right to object at any time to the processing of your personal data for direct marketing purposes, including profiling to the extent it relates to direct marketing.
8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects on you. Where we make decisions using automated processing that has such effects, we will inform you and you will have the right to request human review, express your point of view, and contest the decision.
8.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at info@neoaneresorthouse.com or use the unsubscribe link in any marketing email.
8.9 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. In New Zealand, the relevant authority is:
- Office of the Privacy Commissioner of New Zealand
- Website: privacy.org.nz
- Phone: 0800 803 909
- PO Box 10094, The Terrace, Wellington 6143, New Zealand
If you are located in the European Economic Area (EEA) and believe that our processing of your personal data does not comply with the GDPR, you also have the right to lodge a complaint with the data protection supervisory authority in your Member State of habitual residence, place of work, or the place of the alleged infringement.
8.10 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to us by email at info@neoaneresorthouse.com or by post to . We may need to verify your identity before processing your request. We will respond to your request within one calendar month of receipt, though this period may be extended by a further two months in cases of complex or multiple requests, in which case we will notify you accordingly.
There is no charge for exercising your rights in most circumstances. However, where requests are manifestly unfounded, excessive, or repetitive, we reserve the right to charge a reasonable administrative fee or refuse to act on the request.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include, but are not limited to:
- Encryption of personal data in transit and at rest using industry-standard protocols
- Strict access controls and role-based authentication for staff accessing personal data
- Regular security assessments, penetration testing, and vulnerability management
- Staff training on data protection and information security
- Data processing agreements with all third-party processors
- Physical security measures protecting our IT infrastructure and premises
- Incident response and data breach notification procedures
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR and applicable New Zealand law.
10. Children's Privacy
Our casino services are strictly restricted to persons aged 20 years and over in accordance with the New Zealand Gambling Act 2003. Our hotel services may be available to guests of all ages; however, we do not knowingly collect personal data from children under the age of 16 without verifiable parental or guardian consent. If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at info@neoaneresorthouse.com so that we can take appropriate action.
11. Third-Party Links and Services
Our website may contain links to third-party websites, social media platforms, or external booking services. This Privacy Policy applies solely to information collected by us and does not cover the practices of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit, as we have no control over and assume no responsibility for the content, privacy policies, or practices of those sites.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or regulatory requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or by placing a prominent notice on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the revised Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please do not hesitate to contact us using the details below:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| Email Address | info@neoaneresorthouse.com |
| Website | neoaneresorthouse.com |
We aim to respond to all privacy-related enquiries within 30 days of receipt. If your enquiry is complex or if you have submitted multiple requests, we may require up to 90 days, and we will inform you of any extension within the initial 30-day period.