Privacy Policy
Last Updated: 1 July 2025
This Privacy Policy explains how ("we", "us", "our") collects, uses, discloses, and safeguards your personal information when you visit our website at quietfieldmedia.com (the "Website"), make a reservation, use our hotel-casino facilities, or otherwise interact with us. This Policy is issued in accordance with the requirements of the EU General Data Protection Regulation (GDPR) (EU) 2016/679, as well as applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Please read this Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood the practices described herein. If you do not agree with this Policy, please refrain from using our Website or services.
1. Data Controller
The data controller responsible for your personal information is:
| Legal Entity Name | |
|---|---|
| Trading Name | Hotel & Casino |
| Registered Address | |
| Registration Territory | European Union (EU) |
| Website | quietfieldmedia.com |
| Privacy Enquiries | privacy@quietfieldmedia.com |
As an entity registered in the EU and offering services to individuals in the European Economic Area (EEA), the United Kingdom, and Australia, we are subject to the GDPR and we commit to full compliance with its requirements regarding the processing of personal data.
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable privacy laws. You may contact our DPO directly for any privacy-related matters:
| DPO Name | The Data Protection Officer |
|---|---|
| privacy@quietfieldmedia.com | |
| Postal Address | The Data Protection Officer, , |
2. Personal Data We Collect
We collect personal data from you in a variety of ways, depending on how you interact with us. "Personal data" means any information that identifies you or could reasonably be used to identify you as an individual. The categories of personal data we collect include, but are not limited to, the following:
2.1 Information You Provide to Us Directly
- Identity Data: Full name, date of birth, gender, title, nationality, and copies of government-issued identification documents (e.g., passport or driver's licence) where required for check-in, age verification, or regulatory compliance purposes.
- Contact Data: Email address, postal address, telephone number, and mobile number.
- Reservation & Booking Data: Arrival and departure dates, room preferences, special requests, number of guests, and details of ancillary services booked (e.g., dining, spa, entertainment, casino credits).
- Financial Data: Credit or debit card details, billing address, transaction history, gaming account credits, wagering history, and win/loss records. Please note that full payment card numbers are processed through PCI-DSS-compliant payment providers and are not stored on our own systems.
- Account & Loyalty Programme Data: Loyalty programme membership number, account credentials (username and hashed password), points balance, redemption history, and tier status.
- Communications Data: Records of correspondence with us, including emails, live chat transcripts, call recordings (where notified), and feedback or survey responses.
- Responsible Gaming Data: Self-exclusion requests, voluntary betting limits, problem gambling support referrals, and related documentation, which we are legally required to collect and retain under applicable gaming regulations.
- Dietary & Accessibility Requirements: Dietary preferences or restrictions and physical accessibility requirements where provided to assist with your stay.
2.2 Information We Collect Automatically
- Technical Data: IP address, browser type and version, operating system and platform, device identifiers, time zone settings, browser plug-in types and versions, and other technology on the devices you use to access our Website.
- Usage Data: Pages visited, links clicked, referring URLs, time spent on pages, search queries entered on our Website, and clickstream data.
- Cookie & Tracking Data: Information collected via cookies, web beacons, pixels, and similar technologies. Please refer to our separate Cookie Policy for full details.
- Location Data: General geographic location derived from your IP address, or precise location data where you grant permission via a mobile device or application.
2.3 Information We Collect from Third Parties
- Booking Platforms & Travel Agents: Reservation and contact details received from online travel agencies (OTAs), global distribution systems (GDS), and travel management companies.
- Identity Verification Providers: Verification results and fraud-risk signals from third-party identity verification services used for gaming regulatory compliance.
- Credit Reference & Fraud Prevention Agencies: Information used to detect, prevent, and investigate fraud, money laundering, and other financial crime.
- Social Media Platforms: Limited profile information (name, email address, profile picture) where you choose to connect or log in using a third-party social media account.
- Analytics & Advertising Partners: Aggregated or pseudonymous data from analytics and advertising networks to help us understand how users engage with our Website.
2.4 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health Data: Dietary requirements, allergies, or mobility/accessibility needs that you voluntarily disclose to us to enable us to provide appropriate services during your stay.
- Responsible Gaming & Problem Gambling Data: Information that may relate to or reveal details about your health or behavioural circumstances, collected under our legal obligations as a licensed gaming operator.
We process special category data only where you have given explicit consent (Article 9(2)(a) GDPR), where processing is necessary for reasons of substantial public interest under applicable law (Article 9(2)(g) GDPR), or where processing is necessary for the establishment, exercise, or defence of legal claims (Article 9(2)(f) GDPR).
3. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data only where we have a valid legal basis for doing so. The legal bases we rely upon are set out below, together with examples of the types of processing to which each basis applies.
3.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your reservation and accommodation booking;
- Managing your hotel stay, room service requests, and facility access;
- Administering your casino gaming account and processing gaming transactions;
- Enrolling you in and administering your loyalty programme membership;
- Responding to pre-booking enquiries;
- Processing payments for goods and services received.
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Verifying your age and identity to comply with gaming licensing conditions;
- Complying with anti-money laundering (AML) and counter-terrorism financing (CTF) obligations;
- Maintaining mandatory responsible gambling records and self-exclusion registers;
- Meeting tax reporting and financial record-keeping obligations;
- Responding to lawful requests from regulatory authorities, law enforcement, and courts;
- Fulfilling occupational health and safety obligations.
3.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on this basis for:
- Detecting, preventing, and investigating fraud, theft, and other unlawful activity on our premises and on our Website;
- Operating CCTV surveillance on our premises for security and safety purposes;
- Improving our Website, services, and customer experience through analytics;
- Sending you service-related communications (e.g., booking confirmations, updates to bookings);
- Conducting internal audits, business analysis, and operational reporting;
- Managing IT security, network infrastructure, and business continuity;
- Enforcing our Terms & Conditions and other contractual rights;
- Sharing data within our corporate group for internal administrative purposes.
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as a legal basis, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to your withdrawal. We rely on consent for:
- Sending you direct marketing communications by email, SMS, or post about our offers, promotions, events, and services;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category data (such as health and dietary data) where no other legal basis applies;
- Sharing your personal data with selected third-party marketing partners where you have opted in.
You may withdraw your consent at any time by contacting us at privacy@quietfieldmedia.com, using the unsubscribe link in any marketing email, or by adjusting your cookie preferences via our Cookie Consent Manager.
3.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person — for example, in the event of a medical emergency on our premises.
3.6 Public Task (Article 6(1)(e))
Where applicable, we may process personal data in the performance of a task carried out in the public interest or in the exercise of official authority vested in us — for example, in our capacity as a licensed gaming operator subject to regulatory oversight.
4. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
4.1 Providing and Managing Our Services
- Processing, confirming, and managing hotel reservations and check-in/check-out procedures;
- Delivering the accommodation, dining, spa, entertainment, and gaming services you have requested;
- Administering your gaming account, processing deposits and withdrawals, and maintaining wagering records;
- Managing your loyalty programme account, calculating points, and processing reward redemptions;
- Facilitating payment processing and issuing invoices and receipts.
4.2 Communication and Customer Support
- Sending you transactional communications such as booking confirmations, pre-arrival information, and post-stay follow-ups;
- Responding to your enquiries, complaints, and requests for assistance;
- Providing concierge and guest services support during your stay.
4.3 Marketing and Promotions
- Sending you promotional communications about our offers, special packages, events, tournaments, and loyalty rewards where you have consented to receive such communications;
- Personalising marketing content based on your preferences, booking history, and engagement;
- Conducting targeted advertising on third-party platforms where permitted by applicable law.
4.4 Regulatory Compliance and Responsible Gaming
- Verifying your identity and age for gaming regulatory compliance;
- Monitoring gaming activity to identify signs of problem gambling and to enforce self-exclusion;
- Fulfilling AML, CTF, and Know Your Customer (KYC) obligations;
- Maintaining records required by our gaming licence and applicable law.
4.5 Security and Fraud Prevention
- Operating security surveillance (CCTV) across our premises;
- Detecting, investigating, and preventing fraudulent transactions, identity theft, and other unlawful conduct;
- Protecting the safety and security of our guests, staff, and assets.
4.6 Improving Our Services
- Analysing Website usage patterns to improve navigation, content, and functionality;
- Conducting customer satisfaction surveys and reviewing feedback;
- Carrying out internal research and business analytics to enhance our offerings.
5. How We Share Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, and only to the extent necessary for the purposes described in this Policy:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf under written data processing agreements, as required by Article 28 of the GDPR. These include:
- Cloud hosting and IT infrastructure providers;
- Payment processing and card scheme operators;
- Identity verification and KYC service providers;
- Customer relationship management (CRM) platform providers;
- Email marketing and communications platform providers;
- Website analytics providers (e.g., Google Analytics);
- Reservation and property management system (PMS) providers;
- Responsible gambling support and self-exclusion scheme operators;
- Security and surveillance system operators.
5.2 Regulatory Authorities and Law Enforcement
We may disclose your personal data to regulatory authorities, gaming commissions, tax authorities, law enforcement agencies, and courts where required or permitted by law, including in response to lawful requests, court orders, or subpoenas.
5.3 Professional Advisers
We may share personal data with our lawyers, accountants, auditors, and insurers where necessary for the provision of professional services and advice, subject to applicable professional confidentiality obligations.
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and any applicable changes to this Privacy Policy.
5.5 Online Travel Agencies and Distribution Partners
Where necessary to complete a reservation made through a third-party booking platform, we may share confirmation and stay-related information with the relevant OTA or distribution partner.
5.6 International Transfers
As an entity registered in the EU with operations in Australia, your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA) or Australia. Where such transfers occur, we ensure that appropriate safeguards are in place, including:
- Transfers to countries that the European Commission has determined provide an adequate level of data protection (adequacy decisions under Article 45 GDPR);
- The use of Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46 GDPR;
- Binding Corporate Rules (BCRs) where applicable within our corporate group;
- Other appropriate safeguards as permitted under Article 46 GDPR.
You may request a copy of the relevant transfer mechanism by contacting our DPO at privacy@quietfieldmedia.com.
6. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting obligations. In determining the appropriate retention period, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.
The following indicative retention periods apply to key categories of data:
| Category of Personal Data | Indicative Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of stay | Legal obligation (tax, financial records) |
| Gaming account and wagering records | 5–7 years from account closure | Gaming regulatory obligations, AML |
| Identity verification documents (KYC) | 5 years from the end of the business relationship | AML/CTF legal obligations |
| Financial transaction records | 7 years from the date of transaction | Legal obligation (tax and accounting law) |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Legitimate interest (proof of consent) |
| Customer service communications | 3 years from the date of communication | Legitimate interest (dispute resolution) |
| Responsible gambling records | 7 years from the date of record creation | Gaming regulatory obligations |
| CCTV footage | 31 days (unless required for an investigation) | Legitimate interest (security) |
| Website analytics data | 26 months from collection | Legitimate interest (service improvement) |
| Loyalty programme data | Duration of membership plus 3 years | Contract performance |
Upon expiry of the applicable retention period, we will securely delete or anonymise your personal data in accordance with our data destruction procedures.
7. Your Rights Under the GDPR
Under the GDPR, you have a number of rights in relation to your personal data. These rights are set out below. Please note that some of these rights are not absolute and are subject to certain exceptions and limitations. We will respond to all valid requests within one month of receipt, unless the request is particularly complex or we receive a high volume of requests, in which case we may extend this period by a further two months. We will notify you of any such extension within one month of receiving your request.
We do not charge a fee for handling rights requests unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
7.1 Right of Access (Article 15 GDPR)
You have the right to request confirmation of whether we process personal data about you and, if so, to obtain a copy of that personal data together with supplementary information about how it is processed (a "Subject Access Request" or SAR).
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed.
7.3 Right to Erasure ("Right to Be Forgotten") (Article 17 GDPR)
You have the right to request that we delete your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw your consent (and there is no other legal basis for processing), or where you object to processing and there are no overriding legitimate grounds. This right does not apply where we are required to retain the data under a legal obligation.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where processing is unlawful but you do not wish the data to be erased.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
7.6 Right to Object (Article 21 GDPR)
You have the right to object, at any time, to the processing of your personal data where that processing is based on legitimate interests (Article 6(1)(f)). Where you object, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
You also have an absolute right to object to the processing of your personal data for direct marketing purposes (including profiling to the extent it relates to direct marketing). Where you object to direct marketing, we will cease processing for that purpose immediately.
7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you, unless such processing is necessary for a contract, is authorised by law, or is based on your explicit consent. Where we engage in such processing, we will notify you accordingly and provide information about the logic involved.
7.8 Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
7.9 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes the GDPR. In the EU, the lead supervisory authority will depend on our establishment. You may also contact the supervisory authority in your country of residence or place of work. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority, so please consider contacting us in the first instance at privacy@quietfieldmedia.com.
7.10 Exercising Your Rights
To exercise any of your rights, please submit a written request to:
- Email: privacy@quietfieldmedia.com
- Post: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will request only the information reasonably necessary to confirm your identity, and we will handle such information securely and in accordance with this Policy.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- Encryption of data in transit using TLS/SSL protocols;
- Encryption of sensitive data at rest;
- Access controls, role-based permissions, and multi-factor authentication for internal systems;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures.
While we take all reasonable steps to protect your personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR.
10. Children's Privacy
Our casino facilities and certain services are restricted to persons aged 18 years and over. Our Website and services are not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe that we have inadvertently collected personal data from a child, please contact us immediately at privacy@quietfieldmedia.com and we will take steps to delete such data promptly.
11. Third-Party Links
Our Website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control those third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of any material changes by posting the updated Policy on our Website and updating the "Last Updated" date at the top of this page. Where changes are significant, we may also notify you by email or through a prominent notice on our Website.
We encourage you to review this Policy periodically to stay informed about how we protect your personal information.
13. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our data protection practices, or if you wish to exercise any of your rights, please contact us using the following details:
| Organisation | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| privacy@quietfieldmedia.com | |
| Postal Address | |
| Website | quietfieldmedia.com |
We are committed to working with you to resolve any concerns fairly and promptly. If you are not satisfied with our response, you have the right to lodge a complaint with your relevant data protection supervisory authority, as described in Section 7.9 above.