Privacy Policy
Last updated: 1 July 2025
(ACN 814 726 399 / ABN 44 814 726 399), trading as Marcella Grand Inn, operates the website marcellagrandinn.com (the "Website"). This Privacy Policy explains how we collect, use, disclose, store and protect personal information obtained through the Website, and how you may exercise your rights in relation to that information.
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
Please read this Privacy Policy carefully before using the Website or submitting any personal information to us. By continuing to use the Website you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal information is:
| Legal entity | |
|---|---|
| Trading name | Marcella Grand Inn |
| ACN | 814 726 399 |
| ABN | 44 814 726 399 |
| Registered address | |
| Privacy enquiries | privacy@marcellagrandinn.com |
References to "we", "us" or "our" throughout this Privacy Policy refer to .
2. Personal Information We Collect
We collect personal information only to the extent reasonably necessary to provide you with our services and to operate the Website. The categories of personal information we collect through the Website are set out below.
2.1 Contact and Reservation-Request Data
When you submit an enquiry, reservation request, or any other form on the Website, we may collect:
- Full name
- Email address
- Telephone number
- Postal or billing address
- Intended arrival and departure dates
- Room or accommodation preferences
- Number of guests (including whether any guests are under 18 years of age where relevant to room configuration)
- Special requests or accessibility requirements you choose to disclose
- Payment card details (processed securely via our payment service provider; we do not store full card numbers on our own systems)
- Correspondence content when you contact us by email or through the Website's contact form
2.2 Device and Technical Data
When you visit the Website, our servers and analytics tools automatically collect certain technical information, including:
- IP address
- Browser type and version
- Operating system
- Referring URL
- Pages viewed and navigation paths on the Website
- Date and time of access
- Duration of visit
2.3 Cookie and Consent Data
We use cookies and similar tracking technologies on the Website. When you first visit the Website, we record your consent preferences via our cookie consent tool. The data we collect in connection with cookies includes:
- Your consent status (accepted, declined, or customised by category)
- Timestamp of consent
- The version of this Privacy Policy in force at the time consent was given
- Session identifiers
- Functional preference data (for example, language or currency preferences you set)
Further information about the specific cookies we use, their purposes and their retention periods is set out in Section 4 below and in our Cookie Notice, which is accessible from the Website footer.
2.4 Special-Category Personal Data
We do not seek to collect special-category personal data through the Website. If you voluntarily include such information in a free-text field (for example, within a special requests box), we will treat it with an additional level of care and use it solely to fulfil your request. We will not use it for any other purpose.
2.5 Information About Children
The Website is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. Access to our casino facilities requires guests to be 18 years of age or older, consistent with applicable New South Wales regulatory requirements. If we become aware that we have inadvertently collected personal information from a person under 18 without appropriate parental consent, we will take prompt steps to delete that information.
4. Purposes of Processing and Legal Bases
We process personal information only for specified, legitimate purposes. The table below sets out our processing activities, the purpose of each activity, and the legal basis under the Privacy Act 1988 (Cth) and the APPs on which we rely.
| Processing activity | Purpose | Legal basis / APP authority |
|---|---|---|
| Handling reservation requests and enquiries | To respond to your enquiry, process a reservation request, confirm bookings and communicate pre-arrival information. | Necessary to take steps at your request prior to entering a contract, and to perform our contract with you (APP 3.2(a)). |
| Processing payments | To securely process payment card transactions in connection with reservation requests and deposits. | Performance of a contract; compliance with legal obligations relating to financial record-keeping (APP 3.2(a) and (b)). |
| Customer service and correspondence | To respond to questions, complaints or feedback you submit through the Website or by email. | Legitimate interests — providing and improving our services (APP 3.2(a)). |
| Website operation and security | To maintain, secure and improve the Website; to detect and prevent fraudulent or unauthorised activity; to troubleshoot technical issues. | Legitimate interests — protecting the integrity and security of our systems (APP 3.2(a)). |
| Analytics and Website improvement | To understand how visitors interact with the Website so that we can improve content, structure and functionality. | Consent, where analytics cookies are used (APP 3.3); legitimate interests for aggregated, non-identifiable reporting. |
| Compliance with legal and regulatory obligations | To comply with obligations imposed by Australian law, including record-keeping requirements, anti-money laundering obligations applicable to casino operations, and obligations arising from regulatory guidance. | Compliance with a legal obligation (APP 3.2(b)). |
| Marketing communications (where you have opted in) | To send you information about special offers, events and news relating to Marcella Grand Inn that you have requested. | Consent (APP 3.3); you may withdraw consent at any time by using the unsubscribe link in any marketing email or by contacting privacy@marcellagrandinn.com. |
| Cookie consent management | To record and give effect to your cookie consent choices. | Legal obligation and legitimate interests — demonstrating compliance with privacy obligations (APP 1). |
We will not use your personal information for any purpose that is incompatible with the purposes described in this Privacy Policy without first obtaining your consent or as otherwise permitted by the Privacy Act 1988 (Cth).
5. Disclosure of Personal Information
We do not sell, rent or trade personal information. We may disclose personal information to the following categories of recipients only to the extent necessary for the purposes described in Section 4:
5.1 Service Providers and Technology Partners
We engage third-party service providers who process personal information on our behalf under contractual obligations that are consistent with this Privacy Policy and with the APPs. These providers include:
- Payment processing providers — to securely process card payments in connection with reservation requests. These providers operate under applicable payment card industry standards.
- Website hosting and infrastructure providers — to host, maintain and deliver the Website.
- Analytics service providers — to provide aggregated Website usage data, where you have consented to analytics cookies.
- Email delivery service providers — to transmit reservation confirmations, correspondence and, where you have opted in, marketing communications.
- IT security and fraud prevention providers — to protect the security of our systems and data.
We require all service providers to maintain appropriate technical and organisational security measures and to process personal information only on our documented instructions.
5.2 Legal and Regulatory Disclosures
We may disclose personal information where required or authorised by law, including to:
- Government agencies, law enforcement bodies or regulatory authorities where we are required or authorised to do so under Australian law;
- Courts or tribunals in connection with legal proceedings; or
- Our legal, financial or professional advisers where necessary to obtain advice or to protect our legal rights.
5.3 Business Transfers
In the event of a merger, acquisition, restructure, sale of assets or similar corporate transaction involving , personal information held by us may be transferred to the relevant successor entity, subject to that entity assuming the same privacy obligations set out in this Privacy Policy. We will notify you of any such transfer where required by law.
6. Overseas Disclosure of Personal Information
Some of our third-party service providers may be located outside Australia, which may result in your personal information being disclosed to entities in overseas countries. We take steps that are reasonable in the circumstances to ensure that any overseas recipient handles personal information in a manner consistent with the APPs, including by:
- Entering into contractual arrangements that require overseas recipients to protect personal information in a manner that is at least equivalent to the protections required under the APPs; and
- Selecting service providers that operate under recognised privacy frameworks or are subject to laws that provide comparable protection.
Where we disclose personal information to an overseas recipient and that recipient handles it in a way that breaches the APPs, we accept accountability in accordance with APP 8. We will not disclose personal information overseas in circumstances where we cannot take such reasonable steps, unless we have obtained your express consent, or disclosure is otherwise required or authorised by law.
7. Retention of Personal Information
We retain personal information for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, resolve disputes and enforce our agreements. The key retention periods that apply to information collected through the Website are described below.
| Category of information | Retention period |
|---|---|
| Reservation request and booking correspondence | 7 years from the date of the booking or reservation request, to satisfy Australian taxation and financial record-keeping requirements. |
| Payment transaction records | 7 years from the date of the transaction, in accordance with the Income Tax Assessment Act 1997 (Cth) and applicable financial record-keeping obligations. |
| General enquiry and customer service correspondence | 3 years from the date of the final communication, unless a longer period is required by law or is necessary to resolve a dispute. |
| Marketing opt-in and opt-out records | For the duration of the marketing relationship, plus 3 years after you unsubscribe or withdraw consent, to demonstrate compliance with the Spam Act 2003 (Cth). |
| Website analytics data | In aggregated or de-identified form, up to 26 months from collection. Raw session-level data is deleted or anonymised after 14 months. |
| Cookie consent records | 3 years from the date of consent, to enable us to demonstrate the lawful basis on which cookies were deployed. |
| Technical access logs (IP addresses, server logs) | 90 days, unless required for longer for security investigation purposes. |
At the end of the applicable retention period, personal information will be securely deleted or de-identified so that it can no longer be associated with you.
8. Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference, loss, and from unauthorised access, modification or disclosure. Our security measures include:
- Encryption of data in transit using industry-standard TLS (Transport Layer Security) protocols for all pages of the Website;
- Encryption of personal information at rest in our systems where appropriate;
- Access controls that restrict access to personal information to those personnel and service providers who need it to perform their functions;
- Regular review of our information security practices and procedures;
- Contractual obligations placed on service providers to maintain appropriate security standards; and
- Procedures for detecting, assessing and responding to data breaches, including notification obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth).
While we employ these measures, no data transmission over the internet or storage system can be guaranteed to be completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@marcellagrandinn.com.
If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required by the NDB scheme.
9. Your Privacy Rights
Under the Privacy Act 1988 (Cth) and the APPs, you have the following rights in relation to personal information we hold about you:
9.1 Right of Access
You may request access to the personal information we hold about you. We will provide access within a reasonable time (generally within 30 days) of receiving a written request, except in circumstances where we are permitted or required by law to refuse access. If we refuse or restrict access, we will provide you with written reasons.
9.2 Right to Correction
If you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it. We will take reasonable steps to correct the information within 30 days of your request. If we do not agree that the information requires correction, we will explain our reasons and note your request in association with the information in question.
9.3 Right to Withdraw Consent
Where we process personal information on the basis of your consent (for example, for marketing communications or certain analytics cookies), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent for marketing, use the unsubscribe link in any marketing communication or email us at privacy@marcellagrandinn.com. To adjust cookie consent, use the preference centre in the Website footer.
9.4 Right to Complain
If you are not satisfied with how we have handled your personal information or with our response to a request, you have the right to complain to us in the first instance, and to escalate your complaint to the OAIC. Details of our complaints process are set out in Section 11 below.
9.5 Anonymity and Pseudonymity
Where lawful and practicable, you may interact with us on an anonymous basis or using a pseudonym. However, if you wish to submit a reservation request or receive a personalised response to an enquiry, we will need to collect sufficient identifying information to process your request.
9.6 Opting Out of Direct Marketing
You may opt out of receiving direct marketing communications from us at any time by:
- Clicking the "unsubscribe" or equivalent link in any marketing email we send you; or
- Emailing us at privacy@marcellagrandinn.com with the subject line "Marketing Opt-Out".
We will process your opt-out request promptly and in any event within 5 business days. Note that opting out of marketing does not affect our ability to send you transactional or service-related communications, such as reservation confirmations.
9.7 How to Exercise Your Rights
To exercise any of the rights described above, please send a written request to:
Privacy OfficerEmail: privacy@marcellagrandinn.com
We may need to verify your identity before we can respond to your request. We will not charge you for making a request unless the request is vexatious or manifestly excessive, in which case we will advise you of any applicable fee before proceeding.
10. Responsible Gaming and Regulatory Resources
Casino facilities at Marcella Grand Inn are open to guests who are 18 years of age or older. The New South Wales Government and relevant regulatory bodies provide publicly available responsible gaming resources, self-exclusion tools and guidance for individuals who wish to manage their gaming activity or seek information about gaming-related concerns. These public resources include information published by:
- NSW Responsible Gambling Fund — providing information and support resources for individuals and their families;
- Gambling Help Online (gamblinghelponline.org.au) — a national resource offering guidance and self-exclusion information.
Personal information submitted through any responsible gaming self-exclusion or assistance process administered by government or independent bodies is collected and held by those bodies in accordance with their own privacy policies and legal frameworks, which are separate from this Privacy Policy.
Any personal information you provide to us directly in connection with responsible gaming requests will be handled strictly in accordance with this Privacy Policy and relevant legal obligations.
11. Complaints
11.1 Internal Complaints Process
If you have a complaint about the way we have collected, used, disclosed or otherwise handled your personal information, or about a refusal to provide access or to correct personal information, please contact our Privacy Officer in the first instance:
Privacy OfficerEmail: privacy@marcellagrandinn.com
Please provide as much detail as possible about the nature of your complaint and your preferred contact details. We will acknowledge receipt of your complaint within 5 business days and aim to provide a substantive response within 30 days. If your complaint is complex and requires additional time, we will advise you of the extended timeframe.
11.2 Escalation to the Office of the Australian Information Commissioner
If you are not satisfied with our response, or if 30 days have passed without a resolution, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). The OAIC is the independent national regulator for privacy and freedom of information.
You can contact the OAIC at:
Office of the Australian Information CommissionerGPO Box 5218, Sydney NSW 2001
Website: www.oaic.gov.au
The OAIC website provides information about how to lodge a complaint and the steps involved in the investigation process.
12. Third-Party Links
The Website may contain links to third-party websites, resources or social media platforms. This Privacy Policy applies only to information collected through the Website (marcellagrandinn.com). We are not responsible for the privacy practices or content of any third-party website. We encourage you to read the privacy policy of any website you visit via a link from our Website.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Website, or applicable legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide you with additional notice (for example, by displaying a notification on the Website).
We encourage you to review this Privacy Policy periodically. Your continued use of the Website after any changes take effect constitutes your acceptance of the updated Privacy Policy, subject to any additional consent obligations that may apply under the Privacy Act 1988 (Cth).
14. Contact Us
If you have any questions, concerns or requests relating to this Privacy Policy or to the way in which we handle your personal information, please do not hesitate to contact us:
Attn: Privacy Officer
Email: privacy@marcellagrandinn.com
Website: www.marcellagrandinn.com
We are committed to working with you to resolve any privacy concerns in a fair, timely and transparent manner.