Privacy Policy
Last updated: 1 July 2025
This Privacy Policy explains how (referred to in this document as "we", "us" or "our") collects, uses, discloses and protects your personal information when you visit or use our website at brightcairnworks.com, make a booking, stay at our hotel, use our casino facilities or otherwise interact with us. We are committed to handling your personal information in a transparent, lawful and fair manner in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all other applicable privacy laws.
Please read this Privacy Policy carefully before using our website or providing us with any personal information. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The data controller responsible for your personal information is:
| Legal Entity Name | |
|---|---|
| Registered Address | |
| Registration Country | European Union (EU) |
| Website | brightcairnworks.com |
| Privacy Contact Email | privacy@brightcairnworks.com |
As a data controller, we determine the purposes and means of processing your personal information. We are registered within the European Union and, accordingly, are subject to the requirements of the GDPR in relation to any processing of personal data of individuals located within the European Economic Area (EEA), as well as any additional obligations arising under applicable Australian privacy legislation.
1.1 Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our privacy practices generally. If you have any questions, concerns or requests regarding how we handle your personal information, you are welcome to contact our DPO:
| Name | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@brightcairnworks.com |
2. Personal Information We Collect
We collect personal information that you provide to us directly, that is generated when you use our services, or that we obtain from third parties. The categories of personal information we may collect include the following:
2.1 Information You Provide to Us Directly
- Identity Information: Full name, date of birth, gender, nationality, passport number, driver's licence number or other government-issued identification details.
- Contact Information: Postal address, email address, telephone number and any other contact details you provide.
- Booking and Reservation Information: Arrival and departure dates, room preferences, special requests, number of guests, loyalty programme membership details and payment references.
- Payment Information: Credit or debit card details, billing address, bank account information and transaction history. Please note that full payment card details are processed securely by our authorised payment processors and are not stored by us in unencrypted form.
- Account Information: Username, password, profile preferences and communication preferences if you register an account with us.
- Communications: Content of emails, letters, web enquiries, complaint correspondence and feedback forms you send to us.
- Marketing Preferences: Your preferences regarding receiving marketing communications from us or our partners.
- Responsible Gambling Information: Information you provide in connection with our responsible gambling programme, including self-exclusion requests, deposit limits and any voluntary disclosures you make to our gaming staff.
2.2 Information We Collect Automatically
- Technical Data: IP address, browser type and version, operating system, device identifiers, time zone settings and plug-in types.
- Usage Data: Pages visited, links clicked, referring URLs, time spent on pages, search queries entered on our website and other browsing activity on our website.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags and similar tracking technologies. Please refer to our Cookies section below for further information.
- Location Data: General geographic location inferred from your IP address.
2.3 Information We Collect from Third Parties
- Booking Platform Data: Personal information provided by online travel agencies (OTAs), booking platforms and corporate travel management companies when you make a reservation through those channels.
- Social Media Data: If you interact with our social media pages or use social media login features, we may receive information from those platforms in accordance with their own privacy policies and your account privacy settings.
- Background Verification Data: Where required by law or for the purposes of regulatory compliance (including anti-money laundering checks and gaming licence obligations), we may receive personal information from identity verification services, credit reference agencies or regulatory databases.
- Analytics Providers: Aggregated or pseudonymous data from third-party analytics services to help us understand how our website is being used.
2.4 Special Categories of Personal Information
In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These categories include information about your health (for example, accessibility requirements or dietary needs related to a medical condition), information that may reveal your racial or ethnic origin (where required for identity verification), and any information you voluntarily provide that discloses your religious beliefs (for example, dietary requirements). We will only process such information where we have a lawful basis to do so, including where you have given your explicit consent or where processing is necessary to protect your vital interests or to comply with a legal obligation.
We also treat information relating to gambling behaviour, problem gambling and self-exclusion with a high degree of sensitivity and in accordance with applicable regulatory requirements.
3. Legal Basis for Processing Your Personal Information
We are required under Article 13 of the GDPR to inform you of the legal basis upon which we rely when processing your personal information. We process your personal information on one or more of the following legal bases, as set out in Article 6 of the GDPR:
3.1 Performance of a Contract (Article 6(1)(b))
We process your personal information where it is necessary to enter into or perform a contract with you. This includes processing your identity, contact, booking and payment information in order to:
- Accept and confirm your hotel reservation;
- Provide you with accommodation and hotel services during your stay;
- Process payments for your booking and any ancillary services;
- Manage your casino account and facilitate your participation in gaming activities;
- Respond to your pre-arrival and in-stay requests; and
- Administer your loyalty programme membership.
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal information where it is necessary for compliance with a legal obligation to which we are subject. This includes:
- Verifying the identity of guests and casino patrons as required by anti-money laundering (AML) and counter-terrorism financing (CTF) legislation;
- Maintaining records as required by gaming regulators and licensing authorities;
- Complying with taxation obligations and financial reporting requirements;
- Responding to lawful requests from law enforcement agencies, courts or regulatory authorities;
- Implementing responsible gambling obligations, including self-exclusion registers; and
- Meeting our obligations under data protection legislation, including responding to data subject requests.
3.3 Legitimate Interests (Article 6(1)(f))
We process your personal information where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security of our premises, staff, guests and assets through CCTV monitoring and access controls;
- Preventing fraud, cheating and other unlawful activity on our premises or through our website;
- Improving and optimising our website, products and services based on usage data and analytics;
- Managing and developing our business operations, including IT infrastructure and systems;
- Sending you administrative communications regarding your booking or account;
- Conducting customer satisfaction surveys and market research (subject to your right to opt out); and
- Defending or pursuing legal claims where necessary.
Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests; please see the Your Rights section below.
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as a legal basis for processing, we will request your consent in a clear and specific manner at the time we collect your personal information. We rely on consent for the following processing activities:
- Sending you direct marketing communications by email, SMS or post about our offers, promotions, events and services;
- Placing non-essential cookies and similar tracking technologies on your device; and
- Processing special categories of personal data where no other legal basis applies.
Where we rely on consent, you have the right to withdraw your consent at any time without detriment. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to your withdrawal. To withdraw your consent, please contact us at privacy@brightcairnworks.com or use the unsubscribe link included in any marketing email we send you.
3.5 Vital Interests (Article 6(1)(d))
In rare circumstances, we may process your personal information where it is necessary to protect your vital interests or the vital interests of another person. This may include, for example, sharing medical information with emergency services if you experience a medical emergency on our premises.
3.6 Public Task (Article 6(1)(e))
In limited circumstances, we may process personal information where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. This basis is unlikely to apply to our processing activities in most circumstances but may be relevant where we are required to cooperate with public authorities in the exercise of their statutory functions.
4. How We Use Your Personal Information
We use your personal information for the following purposes:
4.1 Hotel Services
- Processing and confirming reservations, including pre-arrival communications;
- Checking you in and out of the hotel and managing your room allocation;
- Delivering in-room services, concierge assistance and other hotel amenities;
- Processing charges for accommodation, food and beverage, spa, parking and other ancillary services;
- Managing special requests, accessibility requirements and dietary needs;
- Administering loyalty and rewards programmes; and
- Contacting you after your stay regarding feedback or unresolved matters.
4.2 Casino and Gaming Services
- Verifying your identity and age prior to granting access to gaming facilities;
- Opening and managing your casino account;
- Processing gaming transactions, including buy-ins, cashouts and chip exchanges;
- Conducting AML and CTF checks, including screening against sanctions lists and politically exposed persons (PEP) databases;
- Administering our responsible gambling programme, including processing self-exclusion requests and monitoring for signs of problem gambling;
- Investigating suspected fraud, cheating or other misconduct; and
- Complying with reporting obligations under gaming legislation and our regulatory licence conditions.
4.3 Website and Digital Services
- Operating and maintaining our website in a secure and functional manner;
- Personalising your browsing experience based on your preferences and previous interactions;
- Responding to online enquiries and booking requests;
- Analysing website traffic and usage patterns to improve content and functionality; and
- Preventing and detecting unauthorised access, fraud and other malicious activity.
4.4 Marketing and Communications
- Sending you promotional offers, special packages and event invitations (where you have provided consent or where we are otherwise permitted to do so);
- Conducting customer satisfaction surveys and collecting reviews;
- Delivering targeted advertising on our website and through third-party platforms (subject to your cookie preferences); and
- Measuring the effectiveness of our marketing campaigns.
4.5 Security and Safety
- Operating CCTV and security systems throughout our hotel and casino premises;
- Managing access control to restricted areas;
- Investigating security incidents, theft and criminal activity; and
- Maintaining the safety and wellbeing of guests, staff and visitors.
4.6 Legal, Regulatory and Administrative Purposes
- Complying with our legal and regulatory obligations;
- Establishing, exercising or defending legal claims;
- Maintaining accurate financial and business records; and
- Managing insurance, audit and risk management functions.
4.7 Cookies
We use the following types of cookies:
- Strictly Necessary Cookies: These are essential for the operation of our website and cannot be switched off. They enable core functionality such as security, account login and booking management.
- Performance Cookies: These allow us to count visits and traffic sources so we can measure and improve the performance of our website. All information collected is aggregated and anonymous.
- Functional Cookies: These enable enhanced functionality and personalisation, such as remembering your language preferences or room type preferences.
- Targeting and Advertising Cookies: These may be set by us or by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. They work by uniquely identifying your browser and device.
You can manage your cookie preferences through our cookie consent banner when you first visit our website, or at any time by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
5. How We Share Your Personal Information
We do not sell your personal information to third parties. We may share your personal information with the following categories of recipients where necessary and in accordance with this Privacy Policy:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers to assist us in delivering our services. These providers act as data processors on our behalf and are contractually obligated to process your personal information only in accordance with our instructions and to implement appropriate technical and organisational security measures. They include:
- Payment processing and fraud prevention services;
- Cloud computing and IT infrastructure providers;
- Property management system (PMS) and casino management system (CMS) vendors;
- Online booking platform and distribution channel providers;
- Email delivery and customer communications platforms;
- Identity verification and AML compliance services;
- Website analytics and digital marketing platforms;
- Customer relationship management (CRM) system providers; and
- Legal, accounting and professional advisory firms.
5.2 Regulatory and Law Enforcement Authorities
We may disclose your personal information to government authorities, regulators, law enforcement agencies or courts where we are required or permitted to do so by law. This includes, but is not limited to:
- Disclosures required under AML and CTF legislation, including suspicious matter reports to AUSTRAC or equivalent authorities;
- Reporting obligations under our gaming licence to the relevant gaming regulator;
- Responses to court orders, subpoenas and other legal processes; and
- Cooperation with law enforcement investigations involving suspected criminal activity on our premises.
5.3 Business Partners
We may share your personal information with carefully selected business partners where you have requested services that involve those partners, or where you have provided consent. This may include:
- Partner loyalty programme operators;
- Transport and shuttle service providers;
- Restaurant, entertainment and event partners operating within our venue; and
- Travel insurance providers where you have opted in.
5.4 Corporate Transactions
In the event of a merger, acquisition, restructure, sale of assets or other corporate transaction involving , your personal information may be disclosed to prospective or actual acquirers, investors or their advisers, subject to appropriate confidentiality obligations. We will notify you in advance if your personal information is to be subject to a materially different privacy policy as a result of such a transaction.
5.5 International Transfers of Personal Information
As a business with operations and service providers across multiple jurisdictions, your personal information may be transferred to, stored in or processed in countries outside of the European Economic Area (EEA) or Australia. Where such transfers occur in respect of individuals whose data is protected by the GDPR, we ensure that appropriate safeguards are in place, including:
- Transfers to countries that have been granted an adequacy decision by the European Commission;
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules where applicable; or
- Other appropriate transfer mechanisms as permitted under Chapter V of the GDPR.
You may request a copy of the relevant transfer safeguards by contacting our DPO at privacy@brightcairnworks.com.
6. How Long We Keep Your Personal Information
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting or reporting requirements. The specific retention period applicable to your personal information will depend on the nature of the information and the purpose for which it is processed.
Our general retention periods are as follows:
| Category of Personal Information | Retention Period | Reason |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of check-out | Legal and financial record-keeping obligations |
| Payment and financial transaction records | 7 years from the date of transaction | Taxation, AML and financial reporting obligations |
| Casino account and gaming transaction records | 7 years from closure of account or last transaction | Gaming regulatory requirements and AML obligations |
| Identity verification documents (AML/KYC) | 5 years from the end of the business relationship | AML and CTF legislative requirements |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 5 years | Gaming regulatory obligations and patron safety |
| Website usage and analytics data | 26 months from collection | Website improvement and legitimate business interests |
| Marketing consent and preferences | Until withdrawal of consent or 3 years after last engagement | Consent management and legitimate interests |
| CCTV footage | 31 days unless required for an investigation | Security and crime prevention |
| Complaint and dispute records | 6 years from resolution | Legal claims and regulatory compliance |
| Job application records (unsuccessful applicants) | 12 months from notification of outcome | Legitimate interests and potential future recruitment |
Where we are required by law to retain personal information for a minimum period, we will comply with that requirement. At the end of the applicable retention period, personal information will be securely deleted or anonymised so that it can no longer be associated with any individual.
In some circumstances, we may retain your personal information for longer than the periods specified above where it is necessary for the purpose of establishing, exercising or defending legal claims, in which case we will retain the information until those proceedings are concluded.
7. Your Rights Under the GDPR
Under the GDPR, individuals whose personal information we process have a number of rights. These rights apply to individuals located within the EEA and, to the extent provided for under applicable Australian privacy legislation, to individuals in Australia. We will respond to all requests within one calendar month, although we may extend this period by a further two months in complex or high-volume cases, in which case we will notify you.
Your rights are as follows:
7.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal information we hold about you, along with information about how we use it, who we share it with, how long we retain it and the legal basis for processing. This is commonly known as a "subject access request" or SAR.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal information we hold about you without undue delay. You can update certain personal information directly by logging into your account on our website, or by contacting us at privacy@brightcairnworks.com.
7.3 Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal information in certain circumstances, including where:
- The personal information is no longer necessary for the purpose for which it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing based on legitimate interests and there are no overriding legitimate grounds;
- The personal information has been unlawfully processed; or
- Erasure is required to comply with a legal obligation.
This right is not absolute. We may be required to retain certain personal information to comply with our legal obligations (for example, AML record-keeping requirements) or to establish, exercise or defend legal claims.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal information in certain circumstances, including where:
- You contest the accuracy of the personal information, pending verification;
- Processing is unlawful and you prefer restriction to erasure;
- We no longer need the personal information but you require it for legal claims; or
- You have objected to processing and we are assessing whether our legitimate grounds override your rights.
Where processing is restricted, we will continue to store your personal information but will only process it with your consent, for legal claims, or for the protection of another person's rights.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used and machine-readable format and to request that we transmit this information directly to another data controller, where technically feasible.
7.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal information where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims.
You also have an unconditional right to object to the processing of your personal information for direct marketing purposes, including profiling related to direct marketing. If you object, we will cease processing for that purpose immediately.
7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal or similarly significant effects on you. We will notify you if we use your personal information in this way and provide you with an opportunity to request human review of the decision, express your point of view or contest the decision.
7.8 Right to Withdraw Consent
Where we process your personal information on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. To withdraw consent, please contact us at privacy@brightcairnworks.com or use the relevant opt-out mechanism.
7.9 How to Exercise Your Rights
To exercise any of the rights set out above, please submit a written request to:
- Email: privacy@brightcairnworks.com
- Post: The Data Protection Officer, ,
We will need to verify your identity before processing your request. We may ask you to provide proof of identity, such as a copy of a government-issued identification document. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act on the request.
7.10 Right to Lodge a Complaint
If you believe that we have not handled your personal information in accordance with the GDPR or applicable privacy laws, you have the right to lodge a complaint with the relevant supervisory authority. For individuals located in the EEA, the relevant supervisory authority will be the data protection authority of your EU Member State of habitual residence or place of work.
For individuals located in Australia, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority, and we encourage you to contact us at privacy@brightcairnworks.com in the first instance.
8. Security of Your Personal Information
We have implemented appropriate technical and organisational security measures to protect your personal information against unauthorised access, disclosure, alteration, loss or destruction. These measures include, but are not limited to:
- Encryption of personal information in transit and at rest;
- Access controls and authentication protocols limiting access to personal information to authorised personnel on a need-to-know basis;
- Regular security assessments, penetration testing and vulnerability management;
- Staff training on data protection and information security;
- Data minimisation and pseudonymisation practices where appropriate; and
- Incident response and data breach notification procedures.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify you directly where there is a high risk to your rights and freedoms, in accordance with our obligations under Articles 33 and 34 of the GDPR.
Whilst we take all reasonable steps to protect your personal information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of information transmitted to us over the internet.
9. Children's Privacy
Our casino and gaming services are strictly restricted to adults aged 18 years and over. Our website is not directed at children under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under the age of 18 without parental consent, we will take prompt steps to delete that information.
If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at privacy@brightcairnworks.com.
10. Links to Third-Party Websites
Our website may contain links to third-party websites, social media platforms, partner services or online booking platforms. This Privacy Policy applies only to our website and services. We are not responsible for the privacy practices or content of third-party websites, and we encourage you to read the privacy policies of any third-party websites you visit.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or the services we offer. We will notify you of any material changes by posting an updated version of this Privacy Policy on our website with a revised "last updated" date. Where changes are significant, we may also notify you directly by email (if you have provided us with your email address) or through a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information. Your continued use of our website or services following the posting of changes constitutes your acknowledgement of the updated Privacy Policy.
12. Contact Us
If you have any questions, concerns or requests regarding this Privacy Policy or our handling of your personal information, please do not hesitate to contact us:
| Organisation | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| privacy@brightcairnworks.com | |
| Postal Address | |
| Website | brightcairnworks.com |
We aim to respond to all privacy enquiries within 30 days. For complex matters or subject access requests, we may require up to three months to provide a full response, and we will keep you informed of any such extension.
If you are not satisfied with our response to your enquiry or complaint, you have the right to escalate your concern to the relevant data protection supervisory authority as described in Section 7.10 above.