Privacy Policy
Last updated: June 2025
Welcome to (accessible at wokefieldlabs.com). We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use and protect it, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.
Please read this Privacy Policy carefully before using our website or services. By accessing or using our website and services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
For the purposes of the GDPR and applicable data protection law, the data controller responsible for the processing of your personal data is:
| Legal Entity Name | |
|---|---|
| Trading Name | Hotel-Casino |
| Registration Country | European Union (EU) |
| Legal Address | |
| Website | wokefieldlabs.com |
| Privacy Contact Email | privacy@wokefieldlabs.com |
Any reference to "we", "us", or "our" in this Privacy Policy refers to in its capacity as data controller.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with data protection laws. If you have any questions, concerns, or requests relating to the processing of your personal data, you may contact our DPO directly:
| DPO Name | The Data Protection Officer |
|---|---|
| privacy@wokefieldlabs.com | |
| Postal Address | Data Protection Officer, , |
3. Personal Data We Collect
Depending on how you interact with our website and services, we may collect and process the following categories of personal data:
3.1 Identity and Contact Data
- Full name (first name, last name)
- Date of birth
- Gender
- Nationality and country of residence
- Email address
- Telephone number
- Postal address
- Copy of government-issued identity document (where required for regulatory compliance)
3.2 Account and Profile Data
- Username and password (stored in encrypted form)
- Account preferences and settings
- Loyalty programme membership number and points balance
- Booking and reservation history
- Communication preferences
3.3 Reservation and Stay Data
- Hotel room type, check-in and check-out dates
- Number of guests and special requests
- Dietary requirements or accessibility needs (which may constitute special category data)
- Past stays, complaints, and feedback
3.4 Gaming and Casino Data
- Casino account registration details
- Gaming history, wagers, wins, and losses
- Responsible gambling self-exclusion requests and limits
- Age and identity verification records
- Source of funds documentation (where required by applicable gambling regulations)
3.5 Financial and Payment Data
- Payment card type and last four digits
- Billing address
- Transaction records, amounts, dates, and payment references
- Bank account details (where applicable for withdrawals)
- Anti-money laundering (AML) and Know Your Customer (KYC) documentation
3.6 Technical and Usage Data
- IP address
- Browser type and version
- Operating system and device type
- Pages visited, time spent on pages, and click-through paths
- Referring URLs
- Session identifiers and cookies
- Log files and error reports
3.7 Marketing and Communications Data
- Records of your consent to receive marketing communications
- Email open rates, click rates, and campaign interaction data
- Survey responses and feedback
3.8 Special Categories of Personal Data
In certain limited circumstances, we may process special category data as defined under Article 9 of the GDPR. This may include:
- Health or disability information provided to accommodate specific accessibility needs
- Dietary requirements that may indicate religious beliefs or health conditions
We will only process such special category data where you have provided your explicit consent (Article 9(2)(a) GDPR), or where processing is necessary to protect your vital interests, or on another lawful basis permitted under Article 9(2) GDPR. We apply strict additional safeguards to special category data.
3.9 Data Collected from Third Parties
We may also receive personal data about you from third-party sources, including:
- Online travel agencies and booking platforms (e.g., booking.com, Expedia)
- Payment processors and fraud prevention services
- Identity verification and KYC service providers
- Advertising networks and analytics providers
- Publicly available sources for due diligence purposes
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, the legal bases upon which we rely are set out below:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing hotel reservations and managing your stay
- Creating and managing your casino or loyalty account
- Processing payments for bookings and casino services
- Responding to your service enquiries
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Age verification and identity checks required by gambling regulations
- Anti-money laundering (AML) and counter-terrorism financing obligations
- Know Your Customer (KYC) regulatory requirements
- Tax, accounting, and financial reporting obligations
- Responding to lawful requests from regulatory authorities, law enforcement, or courts
- Responsible gambling obligations including self-exclusion and limit-setting
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Fraud prevention and detection, and the security of our systems and services
- Improving and personalising our website, hotel, and casino services
- Network and information security monitoring
- Business analytics and reporting for internal management purposes
- Sending service-related communications and updates
- Resolving disputes and defending legal claims
- Direct marketing to existing customers of similar products or services (where permitted by law)
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will ask you to provide your consent clearly and separately. This includes:
- Sending you marketing emails, SMS, or other promotional communications where you are not an existing customer
- Placing non-essential cookies and tracking technologies on your device
- Processing special category data (e.g., health or accessibility information) where required
You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw your consent, please contact us at privacy@wokefieldlabs.com.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, such as in a medical emergency during your stay.
4.6 Public Interest (Article 6(1)(e) GDPR)
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority, for example, in relation to responsible gambling public safety obligations or cooperation with regulatory bodies.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Hotel Services
- Processing, confirming, and managing hotel room reservations and check-ins
- Communicating with you about your booking before, during, and after your stay
- Providing in-room and hotel amenity services tailored to your preferences
- Managing loyalty programme memberships and reward points
- Sending post-stay satisfaction surveys
5.2 Casino and Gaming Services
- Registering and verifying your casino account
- Verifying your age and identity in compliance with gambling legislation
- Processing gaming transactions, deposits, and withdrawals
- Implementing and monitoring responsible gambling tools (self-exclusion, deposit limits, etc.)
- Detecting and preventing problem gambling behaviours
- Complying with AML, KYC, and other regulatory obligations
5.3 Payment Processing
- Processing payments for hotel stays, dining, spa, and casino services
- Detecting and preventing fraudulent transactions
- Maintaining accurate financial records
5.4 Marketing and Personalisation
- Sending you promotional offers, newsletters, and personalised recommendations (with your consent or under legitimate interests where applicable)
- Conducting market research and analysing service usage to improve our offerings
- Displaying targeted advertising on our website and third-party platforms
- Personalising your online experience based on your preferences and browsing behaviour
5.5 Security and Compliance
- Ensuring the security and integrity of our website, systems, and premises
- Complying with legal, regulatory, and contractual obligations
- Investigating and resolving complaints, disputes, or suspected fraudulent activity
- Cooperating with regulatory authorities, law enforcement agencies, and courts where required
5.6 Website and Service Improvement
- Analysing website traffic, user behaviour, and service performance
- Conducting A/B testing and improving user experience
- Diagnosing technical issues and maintaining system reliability
7. Data Sharing and Disclosure
We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients for the purposes described in this Privacy Policy:
7.1 Service Providers and Data Processors
We engage third-party service providers who process personal data on our behalf under written data processing agreements in compliance with Article 28 of the GDPR. These include:
- Cloud hosting and IT infrastructure providers
- Payment processing and acquiring banks
- Identity verification and KYC service providers
- Fraud prevention and AML screening services
- Email marketing and CRM platform providers
- Customer support and live chat software providers
- Website analytics and performance monitoring tools (e.g., Google Analytics)
- Online booking and property management system (PMS) providers
7.2 Regulatory and Legal Authorities
We may disclose your personal data to:
- Gambling regulatory authorities as required under applicable gambling licences
- Financial intelligence units and law enforcement agencies in connection with AML obligations
- Tax authorities and government agencies for legal compliance
- Courts, tribunals, or arbitration bodies in connection with legal proceedings
7.3 Business Partners
We may share data with trusted business partners where you have consented or where it is in our legitimate interests, including:
- Online travel agencies and booking platforms through which you made your reservation
- Affiliated hotel and entertainment group members where applicable
- Loyalty programme partners
7.4 Professional Advisors
We may share personal data with our legal advisors, auditors, accountants, and insurers where necessary for the provision of professional services and where appropriate confidentiality obligations are in place.
7.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or other business transfer, your personal data may be transferred to the relevant third party. We will notify you of any such change and of any choices you may have regarding your data in accordance with applicable law.
8. International Data Transfers
As a company registered in the EU operating a website and physical establishment in Australia, your personal data may be transferred to, stored, or processed in countries outside the European Economic Area (EEA) that may not provide the same level of data protection as your home country.
Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place in accordance with Articles 44–49 of the GDPR, including:
- Adequacy Decisions: Transfers to countries recognised by the European Commission as providing an adequate level of data protection.
- Standard Contractual Clauses (SCCs): Transfers governed by the European Commission's approved Standard Contractual Clauses, which contractually bind the recipient to protect your data.
- Binding Corporate Rules: Where applicable, transfers within corporate groups governed by approved Binding Corporate Rules.
- Derogations: In limited circumstances, transfers may be made on the basis of your explicit consent, or where the transfer is necessary for the performance of a contract or for the establishment, exercise, or defence of legal claims.
You may request a copy of the safeguards in place for international transfers by contacting us at privacy@wokefieldlabs.com.
9. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria we use to determine appropriate retention periods include:
- The duration of our contractual relationship with you
- Legal and regulatory obligations requiring us to retain data for minimum periods
- Applicable limitation periods for bringing legal claims
- The nature and sensitivity of the personal data
- Guidance from supervisory authorities on appropriate retention periods
The following indicative retention periods apply:
| Category of Data | Retention Period | Reason |
|---|---|---|
| Hotel reservation and guest records | 7 years from check-out | Tax, accounting, and legal compliance |
| Casino account and gaming records | 5–7 years from account closure | Gambling regulatory and AML obligations |
| KYC and identity verification documents | 5 years from end of business relationship | AML regulatory requirement |
| Payment and financial transaction records | 7 years | Tax and accounting legal obligation |
| Marketing consent records | Until consent is withdrawn + 3 years | Demonstrating compliance with consent obligations |
| Website analytics and technical logs | 13 months (rolling) | Security and performance monitoring |
| Responsible gambling self-exclusion records | Duration of exclusion + 5 years | Regulatory obligation and user safety |
| Customer service and complaint records | 3 years from resolution | Dispute resolution and legal claims |
Upon expiry of the applicable retention period, your personal data will be securely deleted or anonymised in accordance with our data retention and disposal procedures.
10. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month of receipt, which may be extended by a further two months where requests are complex or numerous (in which case we will notify you).
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data about you, and if so, to receive a copy of that personal data together with information about how it is processed (a "Subject Access Request").
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed.
10.3 Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, where you have withdrawn your consent, or where the data has been unlawfully processed. This right is not absolute and may be subject to legal obligations that require us to retain certain data.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing (pending verification of whether our legitimate interests override yours).
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where processing is based on legitimate interests (Article 6(1)(f)) or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately.
10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you. Where we engage in such processing, we will inform you and provide you with the ability to request human review, express your point of view, and contest the decision.
10.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
10.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer:
- Email: privacy@wokefieldlabs.com
- Post: Data Protection Officer, , 21 Binara Street, Canberra ACT 2601, Australia
We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse the request.
10.10 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a competent supervisory authority. As we are registered in the EU, the lead supervisory authority may be the data protection authority in the EU member state of our establishment. You may also contact the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
A full list of EU data protection supervisory authorities is available at the European Data Protection Board website: https://edpb.europa.eu.
We would, however, appreciate the opportunity to address your concerns directly before you contact the supervisory authority. Please contact us first at privacy@wokefieldlabs.com.
11. Data Security
We have implemented appropriate technical and organisational security measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction, in accordance with Article 32 of the GDPR. These measures include:
- Encryption of personal data in transit (TLS/SSL) and at rest
- Access controls and role-based permissions limiting access to personal data on a need-to-know basis
- Multi-factor authentication for systems holding personal data
- Regular security assessments, penetration testing, and vulnerability management
- Staff training and awareness programmes on data protection and security
- Data processing agreements with all third-party processors
- Incident response and data breach notification procedures
- Regular backups and business continuity planning
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, notify you directly in accordance with Articles 33 and 34 of the GDPR.
12. Children's Privacy
Our hotel and casino services are intended for adults only. Our casino services are strictly restricted to individuals aged 18 years or over (or such higher age as required by applicable local law). We do not knowingly collect or process personal data from children under the age of 18 in connection with our gaming services, and we do not knowingly collect personal data from children under the age of 16 in connection with our hotel services without verifiable parental or guardian consent.
If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete that information as promptly as possible. If you believe we have collected data from a minor, please contact us immediately at privacy@wokefieldlabs.com.
13. Responsible Gambling and Data Processing
We are committed to responsible gambling. In accordance with applicable gambling regulatory obligations, we process personal data in order to:
- Monitor gaming behaviour and identify signs of problem gambling
- Implement and enforce self-exclusion requests across applicable platforms
- Apply deposit limits, loss limits, and session time limits at your request
- Communicate with you about responsible gambling support resources
- Share self-exclusion data with national or regional responsible gambling exclusion registers as required by law
Processing for responsible gambling purposes is carried out on the basis of our legal obligations (Article 6(1)(c) GDPR) and, where applicable, our legitimate interests in protecting the welfare of our customers (Article 6(1)(f) GDPR).
14. Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable laws, or regulatory requirements. The date at the top of this Privacy Policy indicates when it was last revised.
Where we make material changes to this Privacy Policy, we will notify you by email (if we hold your email address) or by placing a prominent notice on our website prior to the changes taking effect. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Your continued use of our website and services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing activities, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| privacy@wokefieldlabs.com | |
| Postal Address | Data Protection Officer, , |
| Website | wokefieldlabs.com |
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist you satisfactorily, you have the right to lodge a complaint with the competent data protection supervisory authority as described in Section 10.10 above.