1. Who we are
This Privacy Policy explains how Dravelliongrandstay Pty Ltd ("Dravelliongrandstay", "we", "us" or "our") handles personal information when you visit our website, contact our guest services team, submit an enquiry, request accommodation information, or interact with our venue-related services. Our legal contact address is 80 Pyrmont St, Pyrmont NSW 2009, Australia.
We aim to handle information in accordance with applicable Australian privacy requirements, including the Privacy Act 1988 and the Australian Privacy Principles where they apply. If the General Data Protection Regulation (GDPR) applies to a particular individual or processing activity, we also apply the relevant GDPR requirements described below.
2. Information we may collect
Depending on how you interact with us, we may collect identification and contact details such as your name, email address, telephone number, country or region, preferred dates, guest numbers, requested services, and information you choose to include in an enquiry. We may also collect records of communications with our team and service preferences that are necessary to respond to a request.
Technical information may include browser type, device type, operating system, approximate region derived from network information, pages viewed, referral information, interaction events, and diagnostic data used to maintain website security and performance. We do not intentionally request special-category data through ordinary website forms. Please avoid including sensitive information unless it is genuinely necessary for a specific request.
3. How we collect information
Information may be collected directly from you when you complete a form, contact us, request assistance, or otherwise provide details. Technical data may be collected automatically through essential browser storage, server logs, security controls, and, where permitted, optional analytics or preference technologies. We may also receive limited information from service providers acting on our instructions, for example where they support website hosting, security, communications, or reservation administration.
4. Purposes of processing
We may use personal information to respond to enquiries; administer accommodation or guest-service requests; provide requested information; maintain records; protect the website and our systems; prevent misuse; comply with legal obligations; improve accessibility, usability and performance; handle complaints; and establish, exercise or defend legal claims.
Where marketing communications are offered, they will be sent only where permitted by law and subject to applicable consent or opt-out requirements. We do not use ordinary website enquiry data to make decisions producing legal or similarly significant effects solely by automated means.
5. GDPR legal bases where applicable
Where GDPR applies, processing may rely on one or more legal bases: performance of a contract or steps taken at your request before entering a contract; compliance with a legal obligation; our legitimate interests in operating, securing and improving our services; your consent where consent is required; or, in exceptional circumstances, protection of vital interests or performance of a task permitted by applicable law.
When we rely on legitimate interests, we consider the necessity of the processing and balance those interests against the rights and reasonable expectations of the individual. Where processing is based on consent, consent may be withdrawn for future processing at any time without affecting the lawfulness of processing that occurred before withdrawal.
6. Sharing and service providers
We may disclose personal information to carefully selected providers that perform services on our behalf, such as hosting, cybersecurity, communications, maintenance, professional advisory, or reservation-support services. Providers are expected to process information only for authorised purposes and to apply appropriate confidentiality and security safeguards.
Information may also be disclosed where required by law, court order, regulatory request, or where reasonably necessary to protect rights, safety, property, systems or users. If our business structure changes, information may be transferred as part of a legitimate corporate transaction subject to appropriate safeguards.
7. International transfers
Some providers may process information outside Australia or outside the country in which you are located. Where GDPR or another transfer-restriction regime applies, we use an available lawful transfer mechanism and supplementary safeguards where required. Depending on the circumstances, this may include adequacy decisions, approved contractual clauses, contractual confidentiality controls, access restrictions, encryption, or other recognised measures.
8. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to respond to requests, maintain appropriate business and security records, comply with legal or accounting obligations, resolve disputes, and enforce agreements. Retention periods may vary according to the type of record, legal requirements, risk, and whether an ongoing relationship exists.
When information is no longer required, we take reasonable steps to delete, de-identify, or securely archive it in accordance with applicable obligations and technical limitations.
9. Security
We use administrative, organisational and technical safeguards designed to protect personal information against unauthorised access, alteration, disclosure, loss or misuse. Measures may include access controls, least-privilege practices, secure configuration, monitoring, backups, staff confidentiality requirements, and periodic review of service-provider safeguards. No online system can be guaranteed completely secure, so users should also take reasonable steps to protect their devices and communications.
10. Your rights and choices
Depending on applicable law, you may have rights to request access to personal information, correction of inaccurate information, deletion, restriction of processing, objection to certain processing, data portability, withdrawal of consent, or information about how your data is handled. Australian privacy law may also provide rights to seek access and correction and to make a privacy complaint.
Where GDPR applies, you may also have the right to lodge a complaint with a competent supervisory authority. Rights are subject to legal conditions and exceptions, and we may need to verify identity before acting on a request. We will not discriminate against a person for exercising a privacy right where such protection is required by law.
11. Children and age restrictions
Our venue-related services are intended for adults. We do not knowingly use this website to solicit personal information from children for restricted activities. If we learn that personal information has been provided in circumstances where it should not have been collected, we will review the situation and take appropriate steps in accordance with applicable law.
12. Cookies and similar technologies
Our use of browser storage and similar technologies is described in the Cookie Policy. Essential technologies may be used where necessary for security or basic functionality. Optional technologies, if introduced, will be handled in accordance with applicable consent and transparency requirements.
13. Third-party destinations
The website may from time to time refer users to independent third-party services. Those services operate under their own privacy notices and practices. We encourage users to review the privacy information of any third party before providing personal information to it. We are not responsible for independent third-party privacy practices except to the extent required by applicable law.
14. Complaints and contact
Privacy contact: info@dravelliongrandstay.com
Legal entity: Dravelliongrandstay Pty Ltd
Address: 80 Pyrmont St, Pyrmont NSW 2009, Australia
Please provide enough detail for us to understand and investigate a privacy request or complaint. We will aim to acknowledge and handle requests within the timeframes required by applicable law. If you remain dissatisfied, you may have the right to approach the relevant privacy regulator or supervisory authority.
15. Changes to this policy
We may update this Privacy Policy to reflect legal, operational, security or service changes. The current version will be published on this page with an updated effective date. Material changes will be highlighted or otherwise communicated where required by law.