Privacy Policy

Last updated: 1 June 2025

1. Introduction

("we", "us" or "our") operates the website at dorvessianroyalinn.com (the "Site") and the physical hotel and casino premises known as Dorvessian Royal Inn, located in Paraparaumu, New Zealand. We are committed to protecting the personal information of every person who visits or interacts with our Site.

This Privacy Policy explains what personal information we collect through the Site, how and why we use it, with whom we share it, how long we keep it, what rights you have and how to exercise them. Please read this policy carefully before submitting any personal information to us.

Our processing of personal information is governed by the Privacy Act 2020 (New Zealand) and the Information Privacy Principles contained within it.

2. Data Controller

The data controller responsible for personal information collected through this Site is:

Legal entity
Registered address
Company registration number 7842913
GST/VAT number 138-472-905
Privacy contact email info@dorvessianroyalinn.com

If you have any questions or concerns about this Privacy Policy or our handling of your personal information, please contact us at the email address above.

3. Personal Information We Collect

We collect personal information only to the extent necessary for the purposes described in this policy. The categories below reflect information collected directly from you through the Site or automatically when you browse it.

3.1 Information You Provide Directly

When you use our contact forms, reservation request forms or other interactive features on the Site, we may collect the following:

  • Full name
  • Email address
  • Telephone number
  • Postal or billing address
  • Arrival and departure dates
  • Room type preference and number of guests
  • Special requests and accessibility requirements
  • Payment card details (where you submit a reservation request that requires a card guarantee; this information is processed through our secure payment processor and is not retained on our servers)
  • Any other information you voluntarily include in a free-text message field

Where relevant to our casino facilities, we may also collect date of birth for the purpose of verifying that guests are at least 18 years of age, in accordance with New Zealand gaming legislation.

3.2 Information Collected Automatically

When you visit the Site, certain technical information is collected automatically through your browser and device:

  • IP address
  • Browser type and version
  • Operating system
  • Device type
  • Referring URL
  • Pages viewed and navigation path through the Site
  • Date, time and duration of your visit
  • Clicks and interactions with Site content

3.3 Cookie and Consent Data

We use cookies and similar tracking technologies on the Site. When you first visit the Site, a consent notice gives you the opportunity to accept or decline non-essential cookies. We record your consent choice, including the date and time it was made and the version of the consent notice presented to you. This record is retained as evidence of your preference and to enable you to update or withdraw your consent at any time.

Essential cookies, which are strictly necessary to enable core Site functionality and security, are placed without requiring consent. All other cookies require your prior opt-in. For full details about the cookies we use, their purposes and their retention periods, please see our Cookie Policy.

3.4 Special-Category Personal Data

We do not seek to collect special-category personal data through this Site. If you voluntarily disclose such data in a free-text field (for example, an accessibility or dietary request), we will process it solely to fulfil that specific request and will not use it for any other purpose.

5. Recipients of Personal Information

We do not sell, rent or trade your personal information to third parties. We may share your personal information with the following categories of recipient only to the extent necessary for the purposes described in this policy:

  • Service providers and processors. Third-party organisations that provide services on our behalf, including IT hosting and infrastructure, payment processing, reservation management software, website analytics and email delivery services. These organisations are permitted to use your personal information only to provide services to us and are bound by confidentiality and data-protection obligations.
  • Professional advisers. Lawyers, accountants and auditors where disclosure is necessary in the context of professional advice or services obtained by us.
  • Regulatory and law enforcement authorities. Government agencies, regulators or courts where we are required to disclose personal information by law, court order or other legal process, or where disclosure is necessary to protect the safety of any person or to prevent or report fraudulent activity.
  • Business transferees. If undergoes a merger, acquisition, restructure or sale of assets, your personal information may be transferred to the successor entity. We will notify you in advance if such a transfer occurs and if it would result in a materially different use of your personal information.

6. International Transfers of Personal Information

Some of our third-party service providers are based outside New Zealand. Where personal information is transferred to a country that does not have privacy laws equivalent to those in New Zealand, we take steps to ensure that appropriate protections are in place. These steps may include contractual clauses approved for cross-border data transfers, or confirmation that the recipient is subject to binding obligations that provide a comparable level of protection to that required under the Privacy Act 2020.

If you would like further information about the specific safeguards we apply to international transfers, please contact us at info@dorvessianroyalinn.com.

7. Retention of Personal Information

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or to comply with legal, regulatory, accounting or reporting requirements. The following general retention periods apply:

Category of personal information Retention period
Reservation and guest records (including payment records) Seven years from the date of the stay or cancelled reservation, to satisfy financial and tax record-keeping obligations
General enquiries and correspondence Three years from the date of last contact, unless the enquiry resulted in a reservation (in which case the reservation retention period applies)
Marketing opt-in records Until you withdraw consent, plus a further three years as evidence of consent having been given
Website analytics data (pseudonymous) Twenty-six months from the date of collection
Cookie consent records Three years from the date the consent was given or last updated
Age-verification records As required by applicable gaming legislation, and in any event no longer than seven years

At the end of the applicable retention period, personal information is securely deleted or anonymised so that it can no longer be associated with you.

8. Security of Personal Information

We implement appropriate technical and organisational measures to protect personal information against accidental loss, unauthorised access, disclosure, alteration or destruction. These measures include:

  • Transport Layer Security (TLS) encryption for all data transmitted between your browser and our servers
  • Access controls restricting access to personal information to authorised personnel who need it to perform their duties
  • Regular review of our information security practices
  • Staff training on privacy and data security obligations
  • Contractual data-protection requirements imposed on all service providers who handle personal information on our behalf

While we take all reasonable steps to protect your personal information, no method of electronic transmission or storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at info@dorvessianroyalinn.com.

In the event of a privacy breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals in accordance with our obligations under the Privacy Act 2020.

9. Your Rights

Under the Privacy Act 2020, you have rights in relation to the personal information we hold about you. These rights are described below.

9.1 Right of Access

You have the right to request confirmation of whether we hold personal information about you, and to receive a copy of that information. We will respond to access requests within 20 working days of receiving your request, or notify you if a reasonable extension of that timeframe is required.

9.2 Right to Correction

If you believe that personal information we hold about you is inaccurate, incomplete, misleading or not up to date, you have the right to request that we correct it. Where we disagree that a correction is warranted, you may request that we attach a statement of the correction you sought to the relevant record.

9.3 Right to Withdraw Consent

Where we process your personal information on the basis of your consent (including consent to non-essential cookies and to direct marketing), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

  • To withdraw consent to marketing communications, click the unsubscribe link in any marketing email we send you, or contact us at info@dorvessianroyalinn.com.
  • To withdraw or update cookie consent, use the cookie preference tool accessible via the cookie notice on the Site.

9.4 Right to Object

Where we rely on legitimate interests as the legal basis for processing, you have the right to object to that processing. We will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise or defence of legal claims.

9.5 Right to Make a Complaint

If you believe we have not complied with our obligations under the Privacy Act 2020, you have the right to make a complaint to the Office of the Privacy Commissioner. You may wish to raise your concern with us first so that we have the opportunity to address it.

9.6 How to Exercise Your Rights

To exercise any of the rights described above, please contact us in writing:

Privacy Officer


Email: info@dorvessianroyalinn.com

We may ask you to verify your identity before we process your request. This is to ensure that personal information is not disclosed to any person who does not have the right to receive it. We will not charge a fee for handling a request unless your request is clearly excessive or repetitive, in which case we will notify you in advance.

10. Casino Facilities and Responsible Gambling

Dorvessian Royal Inn operates casino gaming facilities on its premises. Under New Zealand law, only persons aged 18 years or over may participate in casino gaming. We may collect and use personal information for the purpose of verifying age eligibility as described in this policy.

The Gambling Commission is the New Zealand government body responsible for regulating casino gambling. It provides publicly available guidance on gambling harm, information about self-exclusion programmes and resources for people seeking support. You can access these resources through the Gambling Commission website. The Problem Gambling Foundation of New Zealand also publishes guidance and support resources that are freely accessible to the public.

Personal information collected in connection with self-exclusion requests or responsible-gambling measures will be processed for the purpose of giving effect to those measures and in accordance with any applicable legal obligations. Such information will not be used for marketing purposes.

11. Children

This Site is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18 through this Site. If you believe that a person under 18 has provided personal information to us through the Site, please contact us at info@dorvessianroyalinn.com and we will take steps to delete that information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or operational circumstances. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Your continued use of the Site after the revised policy has been posted constitutes your acknowledgement of the updated terms.

If we make changes that significantly affect how we use personal information that we have already collected from you, we will endeavour to notify you directly by email where it is practicable to do so.

14. Complaints and Contact Details

If you have a question, concern or complaint about how we handle your personal information, we encourage you to contact us in the first instance so that we can try to resolve the matter directly:

Privacy Officer


Email: info@dorvessianroyalinn.com

We will acknowledge your complaint promptly and aim to provide a substantive response within 20 working days.

If you are not satisfied with our response, or if you prefer to raise your concern directly with the regulator, you may contact the Office of the Privacy Commissioner:

Office of the Privacy Commissioner
PO Box 10094, Wellington 6143, New Zealand
Website: www.privacy.org.nz

The Office of the Privacy Commissioner can receive complaints about alleged interference with privacy under the Privacy Act 2020, conduct investigations and, where appropriate, make recommendations or refer matters to the Human Rights Review Tribunal.

Check availability