Privacy Policy
Dorvessian Royal Lodge — operated by
Effective date: 1 June 2025
This Privacy Policy explains how collects, uses, stores, shares and protects personal data in connection with the website dorvessianroyallodge.com (the "Website") and the enquiries, reservation requests and other interactions you make through it. Please read this document carefully before submitting any personal data through the Website.
1. Data Controller
The data controller responsible for your personal data is:
| Legal entity | |
|---|---|
| Trading name | Dorvessian Royal Lodge |
| Registered address | |
| Company registration number | 9429051786349 |
| GST/VAT number | 9429051786349 |
| Privacy enquiries | info@dorvessianroyallodge.com |
All references to "we", "us" or "our" in this Privacy Policy refer to .
2. Scope of This Policy
This Privacy Policy applies solely to personal data collected or processed through the Website. It covers:
- Information you provide when submitting a reservation request or general enquiry.
- Information collected automatically when you browse the Website.
- Preferences and consents you record through the Website's cookie or consent management tools.
This Policy does not govern personal data collected in person at the property, through third-party booking platforms, or through any other channel not expressly listed above.
3. Personal Data We Collect
3.1 Contact and Reservation-Request Data
When you submit a reservation request, availability enquiry or general contact form on the Website, we may collect:
- Full name
- Email address
- Telephone number
- Preferred arrival and departure dates
- Number of guests and room-type preference
- Special requests or accessibility requirements you choose to disclose
- Any other information you include in the free-text message field
We will handle any special-category personal data you voluntarily include in a free-text field with additional care and will use it only to fulfil the specific request to which it relates.
3.2 Device and Technical Data
When you visit the Website, our servers and analytics tools automatically record certain technical information, including:
- IP address (collected in truncated or pseudonymised form where technically possible)
- Browser type and version
- Operating system
- Referring URL and exit pages
- Pages viewed and time spent on each page
- Date and time of access
- Device type (desktop, tablet, mobile)
3.3 Consent and Cookie Preference Data
Where the Website presents a consent or cookie-preference mechanism, we record the choices you make, the date and time of those choices, and the version of the consent notice presented to you. This record is stored to demonstrate compliance with applicable privacy law.
3.4 Data You Choose Not to Provide
Certain fields in our contact and reservation forms are marked as mandatory. If you do not complete those fields, we may be unable to respond to your enquiry or process your reservation request.
4. Purposes and Legal Bases for Processing
We process your personal data only where we have a lawful basis to do so under applicable New Zealand privacy legislation and, where relevant, other applicable data-protection frameworks. The table below sets out each processing purpose, the data categories involved and the legal basis relied upon.
| Purpose | Data categories | Legal basis |
|---|---|---|
| Responding to reservation requests and general enquiries | Contact and reservation-request data | Performance of a contract or steps taken at your request prior to entering a contract; or our legitimate interest in managing guest communications |
| Operating and maintaining the Website | Device and technical data | Legitimate interest in ensuring the technical functionality, stability and security of the Website |
| Analysing Website usage and improving user experience | Device and technical data; aggregated behavioural data | Legitimate interest in understanding how visitors use the Website so we can enhance its content and navigation; or consent, where required for analytics cookies |
| Recording and managing cookie and marketing consents | Consent preference data | Compliance with our legal obligations; legitimate interest in demonstrating accountability |
| Sending promotional communications about the Lodge and its facilities (where you have opted in) | Contact data; stated preferences | Your consent, which you may withdraw at any time |
| Complying with legal and regulatory obligations, including record-keeping requirements | All categories as necessary | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | All categories as relevant to the claim | Legitimate interest in protecting our legal rights and the safety of the property |
4.1 Legitimate Interests Assessment
Where we rely on legitimate interests as our legal basis, we have assessed that those interests are not overridden by your privacy rights and fundamental freedoms. You have the right to object to processing carried out on legitimate-interest grounds; see Section 9 for details.
6. Recipients of Personal Data
We do not sell your personal data. We may share your personal data with the following categories of recipients where it is necessary to fulfil one of the purposes described in Section 4:
6.1 Internal Recipients
Personal data is accessible within on a need-to-know basis, including our reservations, guest services, marketing and IT teams.
6.2 Service Providers and Data Processors
We engage third-party service providers who process personal data on our behalf and under our instruction, subject to written data-processing agreements. These include providers in the following categories:
- Website hosting and cloud infrastructure providers
- Email delivery and communication platforms
- Website analytics providers
- Consent management platform operators
- Cybersecurity and fraud-prevention services
- Customer relationship management software providers
6.3 Professional Advisers
We may disclose personal data to our legal, accounting or insurance advisers where necessary to obtain professional advice or to establish, exercise or defend legal claims.
6.4 Regulatory and Law-Enforcement Authorities
We may disclose personal data to government bodies, regulators or law-enforcement agencies where we are required to do so by law, court order or other binding legal process.
6.5 Business Transfers
If undergoes a merger, acquisition, restructuring or sale of all or part of its business, personal data held by us may be transferred to the acquiring entity, subject to equivalent privacy protections.
7. International Transfers of Personal Data
Dorvessian Royal Lodge is based in Queenstown, New Zealand. Some of the service providers we use to operate the Website may store or process your data in countries outside New Zealand. Where such transfers occur, we take steps to ensure that your personal data receives a level of protection consistent with the New Zealand Privacy Act 2020 and applicable guidance issued by the Office of the Privacy Commissioner. These steps may include:
- Transferring data only to countries that the Office of the Privacy Commissioner or relevant international frameworks recognise as providing comparable privacy protections; or
- Entering into contractual arrangements with our service providers that impose appropriate data-protection obligations.
You may request further information about the safeguards applicable to any specific transfer by contacting us at the address in Section 11.
8. Retention of Personal Data
We retain personal data only for as long as is necessary to fulfil the purposes described in this Privacy Policy or as required by applicable law. The table below gives indicative retention periods for the main categories of data collected through the Website.
| Data category | Indicative retention period | Rationale |
|---|---|---|
| Reservation-request and enquiry data (unanswered or not converted to a booking) | 12 months from date of enquiry | To allow follow-up and record-keeping of guest interest |
| Reservation-request data (converted to an on-property reservation) | 7 years from the date of the associated stay | Tax, accounting and legal compliance obligations |
| Marketing consent records | 3 years from the date of last consent or withdrawal | Demonstration of lawful basis for marketing communications |
| Cookie and consent preference logs | 13 months from the date of consent | Compliance with accountability obligations |
| Website server logs and technical data | Up to 12 months | Security, fraud prevention and Website performance |
| Legal-claim related data | Until the expiry of the applicable limitation period or final resolution of the claim, whichever is later | Legal defence and compliance |
At the end of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you.
9. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, loss or destruction. These measures include:
- Encryption of data in transit using industry-standard Transport Layer Security (TLS) protocols
- Access controls that restrict data to authorised personnel on a need-to-know basis
- Regular review of our information security practices and systems
- Contractual requirements imposed on service providers regarding the security of personal data they process on our behalf
- Procedures for identifying, assessing and responding to personal data incidents
No method of electronic transmission or storage is completely secure. While we apply commercially reasonable safeguards, we cannot guarantee the absolute security of personal data transmitted to or from the Website. If you believe your personal data has been compromised, please contact us immediately at info@dorvessianroyallodge.com.
10. Your Privacy Rights
Under the New Zealand Privacy Act 2020 and, where applicable, other privacy legislation, you have the following rights in relation to personal data we hold about you:
10.1 Right of Access
You have the right to request confirmation of whether we hold personal data about you and, if so, to receive a copy of that data together with information about how it is used.
10.2 Right to Correction
You have the right to request that we correct any personal data that is inaccurate, incomplete, misleading or out of date. Where we cannot agree that a correction is warranted, you have the right to request that we attach a note of your requested correction to the data.
10.3 Right to Erasure
In certain circumstances, you have the right to request the deletion of your personal data — for example, where the data is no longer necessary for the purposes for which it was collected, or where you have successfully withdrawn consent and there is no other lawful basis for continued processing.
10.4 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while the accuracy of the data is contested.
10.5 Right to Data Portability
Where processing is based on your consent or a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another data controller.
10.6 Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis. We will cease that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is necessary for the establishment, exercise or defence of legal claims.
You have an unconditional right to object at any time to the processing of your personal data for direct marketing purposes, including any profiling related to such marketing. We will act on such objection without delay.
10.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing that took place before withdrawal.
10.8 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to:
Privacy OfficerEmail: info@dorvessianroyallodge.com
We will respond to your request within the timeframes required by applicable law. We may ask you to verify your identity before processing your request to protect against unauthorised disclosure. We will not charge a fee for handling a privacy request unless it is manifestly unfounded or excessive, in which case we will notify you before proceeding.
11. Casino Facilities and Age Verification
Access to the casino facilities at Dorvessian Royal Lodge is restricted to persons aged 18 years or over, as required by New Zealand law. Where you indicate an interest in casino-related amenities through the Website, we process the personal data you provide solely for the purpose of managing your enquiry. We do not use such data for any purpose other than those described in this Privacy Policy.
Dorvessian Royal Lodge is committed to the promotion of responsible gaming. The Department of Internal Affairs administers gambling-related legislation in New Zealand and publishes publicly available guidance and self-exclusion resources on its website at www.dia.govt.nz. The Problem Gambling Foundation of New Zealand also provides publicly available support and self-help tools at www.pgf.nz. We encourage any person who has concerns about their gaming behaviour, or that of someone they know, to make use of these publicly available resources.
12. Third-Party Links
The Website may contain links to third-party websites, including tourism information portals, mapping services and partner attractions in the Queenstown region. We have no control over the content or privacy practices of those external sites. This Privacy Policy applies only to dorvessianroyallodge.com, and we encourage you to review the privacy notices of any third-party sites you visit.
13. Children's Privacy
The Website is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 through the Website. If you believe that we have inadvertently collected personal data from a child under 16, please contact us at info@dorvessianroyallodge.com and we will take prompt steps to delete that data.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data-processing practices, applicable law or the services offered through the Website. The revised policy will be published on this page with an updated effective date. We encourage you to review this page periodically. Where a change is material, we will take reasonable steps to draw it to your attention prior to the change taking effect.
15. Complaints
If you have a concern about how we handle your personal data and you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner of New Zealand, which is the independent regulatory authority responsible for overseeing compliance with the Privacy Act 2020.
The Office of the Privacy Commissioner provides publicly available guidance, complaint-handling procedures and self-help resources. You can access these at:
Office of the Privacy CommissionerPO Box 10094, The Terrace, Wellington 6143, New Zealand
Website: www.privacy.org.nz
We nonetheless encourage you to contact us first so that we have the opportunity to address your concern directly.
16. Contact Us
For any questions, requests or concerns relating to this Privacy Policy or the handling of your personal data, please contact our Privacy Officer:
Privacy Officer —Email: info@dorvessianroyallodge.com
We aim to acknowledge all privacy enquiries within five business days and to provide a substantive response within 20 working days, in accordance with the timeframes set out in the Privacy Act 2020.