Privacy Policy

Last updated: 1 July 2025

This Privacy Policy explains how (referred to in this document as "we", "us" or "our") collects, uses, discloses and protects your personal information when you visit or use our website at brightcairnworks.com, make a booking, stay at our hotel, use our casino facilities or otherwise interact with us. We are committed to handling your personal information in a transparent, lawful and fair manner in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all other applicable privacy laws.

Please read this Privacy Policy carefully before using our website or providing us with any personal information. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for your personal information is:

Legal Entity Name
Registered Address
Registration Country European Union (EU)
Website brightcairnworks.com
Privacy Contact Email privacy@brightcairnworks.com

As a data controller, we determine the purposes and means of processing your personal information. We are registered within the European Union and, accordingly, are subject to the requirements of the GDPR in relation to any processing of personal data of individuals located within the European Economic Area (EEA), as well as any additional obligations arising under applicable Australian privacy legislation.

1.1 Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our privacy practices generally. If you have any questions, concerns or requests regarding how we handle your personal information, you are welcome to contact our DPO:

Name The Data Protection Officer
Organisation
Address
Email privacy@brightcairnworks.com

2. Personal Information We Collect

We collect personal information that you provide to us directly, that is generated when you use our services, or that we obtain from third parties. The categories of personal information we may collect include the following:

2.1 Information You Provide to Us Directly

  • Identity Information: Full name, date of birth, gender, nationality, passport number, driver's licence number or other government-issued identification details.
  • Contact Information: Postal address, email address, telephone number and any other contact details you provide.
  • Booking and Reservation Information: Arrival and departure dates, room preferences, special requests, number of guests, loyalty programme membership details and payment references.
  • Payment Information: Credit or debit card details, billing address, bank account information and transaction history. Please note that full payment card details are processed securely by our authorised payment processors and are not stored by us in unencrypted form.
  • Account Information: Username, password, profile preferences and communication preferences if you register an account with us.
  • Communications: Content of emails, letters, web enquiries, complaint correspondence and feedback forms you send to us.
  • Marketing Preferences: Your preferences regarding receiving marketing communications from us or our partners.
  • Responsible Gambling Information: Information you provide in connection with our responsible gambling programme, including self-exclusion requests, deposit limits and any voluntary disclosures you make to our gaming staff.

2.2 Information We Collect Automatically

  • Technical Data: IP address, browser type and version, operating system, device identifiers, time zone settings and plug-in types.
  • Usage Data: Pages visited, links clicked, referring URLs, time spent on pages, search queries entered on our website and other browsing activity on our website.
  • Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags and similar tracking technologies. Please refer to our Cookies section below for further information.
  • Location Data: General geographic location inferred from your IP address.

2.3 Information We Collect from Third Parties

  • Booking Platform Data: Personal information provided by online travel agencies (OTAs), booking platforms and corporate travel management companies when you make a reservation through those channels.
  • Social Media Data: If you interact with our social media pages or use social media login features, we may receive information from those platforms in accordance with their own privacy policies and your account privacy settings.
  • Background Verification Data: Where required by law or for the purposes of regulatory compliance (including anti-money laundering checks and gaming licence obligations), we may receive personal information from identity verification services, credit reference agencies or regulatory databases.
  • Analytics Providers: Aggregated or pseudonymous data from third-party analytics services to help us understand how our website is being used.

2.4 Special Categories of Personal Information

In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These categories include information about your health (for example, accessibility requirements or dietary needs related to a medical condition), information that may reveal your racial or ethnic origin (where required for identity verification), and any information you voluntarily provide that discloses your religious beliefs (for example, dietary requirements). We will only process such information where we have a lawful basis to do so, including where you have given your explicit consent or where processing is necessary to protect your vital interests or to comply with a legal obligation.

We also treat information relating to gambling behaviour, problem gambling and self-exclusion with a high degree of sensitivity and in accordance with applicable regulatory requirements.

4. How We Use Your Personal Information

We use your personal information for the following purposes:

4.1 Hotel Services

  • Processing and confirming reservations, including pre-arrival communications;
  • Checking you in and out of the hotel and managing your room allocation;
  • Delivering in-room services, concierge assistance and other hotel amenities;
  • Processing charges for accommodation, food and beverage, spa, parking and other ancillary services;
  • Managing special requests, accessibility requirements and dietary needs;
  • Administering loyalty and rewards programmes; and
  • Contacting you after your stay regarding feedback or unresolved matters.

4.2 Casino and Gaming Services

  • Verifying your identity and age prior to granting access to gaming facilities;
  • Opening and managing your casino account;
  • Processing gaming transactions, including buy-ins, cashouts and chip exchanges;
  • Conducting AML and CTF checks, including screening against sanctions lists and politically exposed persons (PEP) databases;
  • Administering our responsible gambling programme, including processing self-exclusion requests and monitoring for signs of problem gambling;
  • Investigating suspected fraud, cheating or other misconduct; and
  • Complying with reporting obligations under gaming legislation and our regulatory licence conditions.

4.3 Website and Digital Services

  • Operating and maintaining our website in a secure and functional manner;
  • Personalising your browsing experience based on your preferences and previous interactions;
  • Responding to online enquiries and booking requests;
  • Analysing website traffic and usage patterns to improve content and functionality; and
  • Preventing and detecting unauthorised access, fraud and other malicious activity.

4.4 Marketing and Communications

  • Sending you promotional offers, special packages and event invitations (where you have provided consent or where we are otherwise permitted to do so);
  • Conducting customer satisfaction surveys and collecting reviews;
  • Delivering targeted advertising on our website and through third-party platforms (subject to your cookie preferences); and
  • Measuring the effectiveness of our marketing campaigns.

4.5 Security and Safety

  • Operating CCTV and security systems throughout our hotel and casino premises;
  • Managing access control to restricted areas;
  • Investigating security incidents, theft and criminal activity; and
  • Maintaining the safety and wellbeing of guests, staff and visitors.

4.6 Legal, Regulatory and Administrative Purposes

  • Complying with our legal and regulatory obligations;
  • Establishing, exercising or defending legal claims;
  • Maintaining accurate financial and business records; and
  • Managing insurance, audit and risk management functions.

4.7 Cookies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic and deliver relevant advertising. Cookies are small text files stored on your device when you visit our website.

We use the following types of cookies:

  • Strictly Necessary Cookies: These are essential for the operation of our website and cannot be switched off. They enable core functionality such as security, account login and booking management.
  • Performance Cookies: These allow us to count visits and traffic sources so we can measure and improve the performance of our website. All information collected is aggregated and anonymous.
  • Functional Cookies: These enable enhanced functionality and personalisation, such as remembering your language preferences or room type preferences.
  • Targeting and Advertising Cookies: These may be set by us or by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. They work by uniquely identifying your browser and device.

You can manage your cookie preferences through our cookie consent banner when you first visit our website, or at any time by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

5. How We Share Your Personal Information

We do not sell your personal information to third parties. We may share your personal information with the following categories of recipients where necessary and in accordance with this Privacy Policy:

5.1 Service Providers and Data Processors

We engage trusted third-party service providers to assist us in delivering our services. These providers act as data processors on our behalf and are contractually obligated to process your personal information only in accordance with our instructions and to implement appropriate technical and organisational security measures. They include:

  • Payment processing and fraud prevention services;
  • Cloud computing and IT infrastructure providers;
  • Property management system (PMS) and casino management system (CMS) vendors;
  • Online booking platform and distribution channel providers;
  • Email delivery and customer communications platforms;
  • Identity verification and AML compliance services;
  • Website analytics and digital marketing platforms;
  • Customer relationship management (CRM) system providers; and
  • Legal, accounting and professional advisory firms.

5.2 Regulatory and Law Enforcement Authorities

We may disclose your personal information to government authorities, regulators, law enforcement agencies or courts where we are required or permitted to do so by law. This includes, but is not limited to:

  • Disclosures required under AML and CTF legislation, including suspicious matter reports to AUSTRAC or equivalent authorities;
  • Reporting obligations under our gaming licence to the relevant gaming regulator;
  • Responses to court orders, subpoenas and other legal processes; and
  • Cooperation with law enforcement investigations involving suspected criminal activity on our premises.

5.3 Business Partners

We may share your personal information with carefully selected business partners where you have requested services that involve those partners, or where you have provided consent. This may include:

  • Partner loyalty programme operators;
  • Transport and shuttle service providers;
  • Restaurant, entertainment and event partners operating within our venue; and
  • Travel insurance providers where you have opted in.

5.4 Corporate Transactions

In the event of a merger, acquisition, restructure, sale of assets or other corporate transaction involving , your personal information may be disclosed to prospective or actual acquirers, investors or their advisers, subject to appropriate confidentiality obligations. We will notify you in advance if your personal information is to be subject to a materially different privacy policy as a result of such a transaction.

5.5 International Transfers of Personal Information

As a business with operations and service providers across multiple jurisdictions, your personal information may be transferred to, stored in or processed in countries outside of the European Economic Area (EEA) or Australia. Where such transfers occur in respect of individuals whose data is protected by the GDPR, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries that have been granted an adequacy decision by the European Commission;
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules where applicable; or
  • Other appropriate transfer mechanisms as permitted under Chapter V of the GDPR.

You may request a copy of the relevant transfer safeguards by contacting our DPO at privacy@brightcairnworks.com.

6. How Long We Keep Your Personal Information

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting or reporting requirements. The specific retention period applicable to your personal information will depend on the nature of the information and the purpose for which it is processed.

Our general retention periods are as follows:

Category of Personal Information Retention Period Reason
Guest reservation and stay records 7 years from the date of check-out Legal and financial record-keeping obligations
Payment and financial transaction records 7 years from the date of transaction Taxation, AML and financial reporting obligations
Casino account and gaming transaction records 7 years from closure of account or last transaction Gaming regulatory requirements and AML obligations
Identity verification documents (AML/KYC) 5 years from the end of the business relationship AML and CTF legislative requirements
Self-exclusion and responsible gambling records Duration of exclusion plus 5 years Gaming regulatory obligations and patron safety
Website usage and analytics data 26 months from collection Website improvement and legitimate business interests
Marketing consent and preferences Until withdrawal of consent or 3 years after last engagement Consent management and legitimate interests
CCTV footage 31 days unless required for an investigation Security and crime prevention
Complaint and dispute records 6 years from resolution Legal claims and regulatory compliance
Job application records (unsuccessful applicants) 12 months from notification of outcome Legitimate interests and potential future recruitment

Where we are required by law to retain personal information for a minimum period, we will comply with that requirement. At the end of the applicable retention period, personal information will be securely deleted or anonymised so that it can no longer be associated with any individual.

In some circumstances, we may retain your personal information for longer than the periods specified above where it is necessary for the purpose of establishing, exercising or defending legal claims, in which case we will retain the information until those proceedings are concluded.

7. Your Rights Under the GDPR

Under the GDPR, individuals whose personal information we process have a number of rights. These rights apply to individuals located within the EEA and, to the extent provided for under applicable Australian privacy legislation, to individuals in Australia. We will respond to all requests within one calendar month, although we may extend this period by a further two months in complex or high-volume cases, in which case we will notify you.

Your rights are as follows:

7.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal information we hold about you, along with information about how we use it, who we share it with, how long we retain it and the legal basis for processing. This is commonly known as a "subject access request" or SAR.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal information we hold about you without undue delay. You can update certain personal information directly by logging into your account on our website, or by contacting us at privacy@brightcairnworks.com.

7.3 Right to Erasure (Article 17 GDPR)

You have the right to request the deletion of your personal information in certain circumstances, including where:

  • The personal information is no longer necessary for the purpose for which it was collected;
  • You withdraw consent and there is no other legal basis for processing;
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds;
  • The personal information has been unlawfully processed; or
  • Erasure is required to comply with a legal obligation.

This right is not absolute. We may be required to retain certain personal information to comply with our legal obligations (for example, AML record-keeping requirements) or to establish, exercise or defend legal claims.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal information in certain circumstances, including where:

  • You contest the accuracy of the personal information, pending verification;
  • Processing is unlawful and you prefer restriction to erasure;
  • We no longer need the personal information but you require it for legal claims; or
  • You have objected to processing and we are assessing whether our legitimate grounds override your rights.

Where processing is restricted, we will continue to store your personal information but will only process it with your consent, for legal claims, or for the protection of another person's rights.

7.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used and machine-readable format and to request that we transmit this information directly to another data controller, where technically feasible.

7.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal information where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims.

You also have an unconditional right to object to the processing of your personal information for direct marketing purposes, including profiling related to direct marketing. If you object, we will cease processing for that purpose immediately.

7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal or similarly significant effects on you. We will notify you if we use your personal information in this way and provide you with an opportunity to request human review of the decision, express your point of view or contest the decision.

7.8 Right to Withdraw Consent

Where we process your personal information on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. To withdraw consent, please contact us at privacy@brightcairnworks.com or use the relevant opt-out mechanism.

7.9 How to Exercise Your Rights

To exercise any of the rights set out above, please submit a written request to:

We will need to verify your identity before processing your request. We may ask you to provide proof of identity, such as a copy of a government-issued identification document. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act on the request.

7.10 Right to Lodge a Complaint

If you believe that we have not handled your personal information in accordance with the GDPR or applicable privacy laws, you have the right to lodge a complaint with the relevant supervisory authority. For individuals located in the EEA, the relevant supervisory authority will be the data protection authority of your EU Member State of habitual residence or place of work.

For individuals located in Australia, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority, and we encourage you to contact us at privacy@brightcairnworks.com in the first instance.

8. Security of Your Personal Information

We have implemented appropriate technical and organisational security measures to protect your personal information against unauthorised access, disclosure, alteration, loss or destruction. These measures include, but are not limited to:

  • Encryption of personal information in transit and at rest;
  • Access controls and authentication protocols limiting access to personal information to authorised personnel on a need-to-know basis;
  • Regular security assessments, penetration testing and vulnerability management;
  • Staff training on data protection and information security;
  • Data minimisation and pseudonymisation practices where appropriate; and
  • Incident response and data breach notification procedures.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify you directly where there is a high risk to your rights and freedoms, in accordance with our obligations under Articles 33 and 34 of the GDPR.

Whilst we take all reasonable steps to protect your personal information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of information transmitted to us over the internet.

9. Children's Privacy

Our casino and gaming services are strictly restricted to adults aged 18 years and over. Our website is not directed at children under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under the age of 18 without parental consent, we will take prompt steps to delete that information.

If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at privacy@brightcairnworks.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or the services we offer. We will notify you of any material changes by posting an updated version of this Privacy Policy on our website with a revised "last updated" date. Where changes are significant, we may also notify you directly by email (if you have provided us with your email address) or through a prominent notice on our website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information. Your continued use of our website or services following the posting of changes constitutes your acknowledgement of the updated Privacy Policy.

12. Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy or our handling of your personal information, please do not hesitate to contact us:

Organisation
Data Protection Officer The Data Protection Officer
Email privacy@brightcairnworks.com
Postal Address
Website brightcairnworks.com

We aim to respond to all privacy enquiries within 30 days. For complex matters or subject access requests, we may require up to three months to provide a full response, and we will keep you informed of any such extension.

If you are not satisfied with our response to your enquiry or complaint, you have the right to escalate your concern to the relevant data protection supervisory authority as described in Section 7.10 above.