Privacy Policy
How Arvenigrandhotel handles personal information and privacy rights.
Last updated: 30 July 2026
1. Scope and status of this policy
This Privacy Policy explains how Arvenigrandhotel Pty Ltd collects, uses, stores, discloses and protects personal information in connection with this website, accommodation enquiries, casino hotel services, event enquiries, accessibility requests and other interactions with the business. It is intended to support transparent handling of personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles where those laws apply. It also describes additional rights that may apply to individuals in the European Economic Area or other locations where the General Data Protection Regulation applies to the relevant processing activity.
This policy is a general website privacy statement. Specific services, reservations, loyalty programmes, recruitment activities or on-premises operations may be subject to additional notices presented at the time information is collected. If an additional notice conflicts with this policy for a specific activity, the more specific notice will apply to that activity to the extent permitted by law.
2. Privacy administrator and contact
Arvenigrandhotel Pty Ltd is the organisation responsible for the personal information described in this policy. Questions, access requests, correction requests, objections, complaints and other privacy communications may be directed to the details below.
Legal entity: Arvenigrandhotel Pty Ltd
Address: 525 Collins Street, Melbourne VIC 3000, Australia
Privacy email: info@arvenigrandhotel.com
Telephone: +61 3 9123 6874
3. Personal information we may collect
Depending on how you interact with us, we may collect identification and contact details such as your name, email address, telephone number, postal address, preferred method of contact and the contents of your enquiry. We may also collect reservation-related information, requested dates, room preferences, accessibility requirements, event requirements, dietary information that you voluntarily provide, records of communications and customer-service history.
When legally required for age-restricted casino access or security purposes, separate on-premises systems may process proof-of-age or identity information. This website does not ask users to upload identity documents. Do not submit government identifiers, payment card information, health records or other highly sensitive material through the general enquiry form.
Technical information may include browser type, device type, operating system, approximate region, referring page, pages viewed, timestamps, security logs and diagnostic data. The current static version of this website does not include third-party analytics, advertising pixels or social-media trackers. Server operators may nevertheless create standard access and security logs when the site is hosted.
4. Sources of personal information
We generally collect personal information directly from you when you complete a form, contact the hotel, request information, make a reservation through an authorised channel, attend the property or communicate with guest services. We may also receive information from a person acting with your authority, an authorised booking agent, an event organiser, a payment or reservation provider, a security provider or a public source where collection is lawful and reasonably necessary.
If you provide information about another person, you should have authority to do so and should make this policy available to that person where appropriate.
5. Purposes of processing
We may process personal information to answer enquiries; provide requested information; manage accommodation, event and service requests; coordinate accessibility support; maintain customer-service records; protect guests, staff and property; prevent fraud and misuse; administer legal claims; meet accounting, taxation, regulatory and record-keeping obligations; improve service quality; maintain website security; and communicate important operational or policy updates.
We do not use general enquiry information to make solely automated decisions that produce legal or similarly significant effects. We do not sell personal information. We do not use the website enquiry form to enrol users in marketing communications without a separate, lawful opt-in mechanism.
6. Legal bases under the GDPR where applicable
Where the GDPR applies, processing may be based on steps requested before entering into a contract, performance of a contract, compliance with a legal obligation, protection of vital interests, legitimate interests that are not overridden by individual rights, or consent where consent is the appropriate basis. Legitimate interests may include responding to enquiries, securing systems, preventing misuse, maintaining service records and establishing or defending legal claims.
Where processing is based on consent, consent may be withdrawn at any time for future processing. Withdrawal does not affect processing that was lawful before withdrawal. Where information is required to enter into or perform a contract, failure to provide it may prevent us from providing the requested service.
7. Data minimisation and accuracy
We seek to collect information that is reasonably necessary for the identified purpose and to keep it accurate, complete and up to date. Please provide only information relevant to your request and notify us if important details change. We may ask for reasonable verification before acting on a correction or rights request.
8. Disclosure and service providers
Personal information may be disclosed to authorised personnel and service providers that support hosting, cybersecurity, reservations, communications, payment processing, professional advice, records management, property operations and customer support. Providers are expected to handle information only for authorised purposes and subject to appropriate confidentiality, security and contractual controls.
Information may also be disclosed where required or authorised by law, to courts or regulators, to protect rights or safety, in connection with a corporate transaction, or with your direction or consent. We do not permit service providers to use personal information for their own unrelated advertising.
9. Overseas disclosure and international transfers
Some service providers may operate or store information outside Australia. Where Australian Privacy Principle 8 applies, we take reasonable steps required by law in relation to overseas disclosures. Where the GDPR applies to an international transfer, we use an available transfer mechanism such as an adequacy decision, standard contractual clauses or another lawful safeguard, together with supplementary measures where appropriate.
Because hosting and service arrangements can change, specific destination countries may vary. You may request further information about material transfer arrangements relevant to your information.
10. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, security, dispute-resolution and record-keeping requirements. Enquiry records may be retained for a reasonable follow-up period and then deleted or de-identified unless they become part of a reservation, complaint, incident or legal record requiring longer retention.
Retention periods are assessed by considering the sensitivity and volume of information, the nature of the relationship, operational needs, limitation periods, regulatory duties and the feasibility of secure deletion or de-identification.
11. Security
We use administrative, technical and physical safeguards proportionate to the risks, which may include access controls, authentication, encryption in transit where hosting supports it, secure configuration, logging, staff confidentiality, vendor review, backup controls and incident-response procedures. No internet transmission or storage method is completely secure, and absolute security cannot be guaranteed.
You should not send payment card data, identity-document images or sensitive information through the general website form. If you believe information has been exposed or misused, contact us promptly.
12. Data breaches
We assess suspected data incidents and take containment, remediation and notification steps required by applicable law. This may include the Australian Notifiable Data Breaches scheme and, where applicable, notification obligations under the GDPR. Notifications will be made when the relevant legal thresholds are met.
13. Your Australian privacy rights
You may request access to personal information we hold about you and request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information. We may need to verify your identity. In limited circumstances permitted by law, access may be refused, in which case we will generally provide written reasons and available complaint options.
You may also complain about how personal information has been handled. We will acknowledge and investigate privacy complaints within a reasonable period. If you are not satisfied, you may be able to contact the Office of the Australian Information Commissioner.
14. Additional GDPR rights where applicable
Where the GDPR applies, you may have rights to information, access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests or direct marketing, and withdrawal of consent. You may also have the right not to be subject to certain solely automated decisions and the right to lodge a complaint with a competent supervisory authority.
These rights are not absolute. Legal exemptions may apply, and we may retain information needed to comply with law or establish, exercise or defend legal claims. We will explain material limitations when responding to a request.
15. Children and age-restricted services
This website provides information about an adult casino hotel. Casino gaming is restricted to persons aged 18 and over. The general website is not directed to children, and we do not knowingly seek personal information from children through the enquiry form. A parent or guardian who believes a child has provided personal information should contact us so the matter can be assessed.
16. Cookies and tracking technologies
The current static website uses no non-essential advertising or analytics cookies and contains no third-party tracking pixels. Essential technical storage may be introduced by a hosting provider for security, load balancing or session integrity. More detail appears in the Cookie Policy.
If non-essential analytics, personalisation or advertising technology is introduced in the future, the website should provide an appropriate notice and consent controls before those technologies are activated where required by law.
17. External links
This website may later contain links to third-party services. Those services control their own privacy practices. Review their privacy notices before providing personal information. We are not responsible for third-party content or practices merely because a link is provided.
18. Changes to this policy
We may update this policy to reflect changes in law, technology, services or business practices. The revised version will be posted on this page with an updated date. Material changes may be highlighted through an additional notice where appropriate.