Privacy Policy

Last updated: June 2025

This Privacy Policy describes how (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you visit or interact with our website located at http://northplainstudio.com (the “Website”), make reservations, use our hotel and casino services, or otherwise engage with us. We are committed to protecting your privacy and ensuring full compliance with the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection laws.

Please read this Privacy Policy carefully. By using our Website or services, you acknowledge that you have read and understood this policy. If you do not agree with the terms herein, please discontinue use of our Website and services.

1. Data Controller

The entity responsible for the processing of your personal data (the “Data Controller”) is:

Company Name
Registration Country European Union (EU)
Registration Number N/A
VAT Number N/A
Legal Address
Website http://northplainstudio.com
Privacy Contact Email privacy@northplainstudio.com

As Data Controller, we determine the purposes and means of processing your personal data. We are registered in the European Union and therefore fall within the territorial scope of the GDPR. We take our obligations under the GDPR seriously and have appointed a Data Protection Officer to oversee our compliance efforts.

2. Data Protection Officer (DPO)

In accordance with Article 37 of the GDPR, we have appointed a Data Protection Officer responsible for monitoring our compliance with the GDPR and acting as a point of contact for data subjects and supervisory authorities.

DPO Name The Data Protection Officer
Contact Email privacy@northplainstudio.com
Postal Address

You may contact our DPO at any time regarding any matters relating to the processing of your personal data or to exercise your rights under applicable data protection law.

3. Scope and Applicability

This Privacy Policy applies to all personal data collected, processed, and stored by in connection with:

  • Your use of our Website and any online booking or reservation systems;
  • Your stay at hotel and use of hotel services and amenities;
  • Your participation in casino gaming activities and related services offered at our premises;
  • Your participation in loyalty programmes, promotions, newsletters, or events;
  • Communications you initiate with us via email, telephone, live chat, or any other channel;
  • Transactions, payments, and billing activities related to our services;
  • Any other interaction you may have with us, online or in person.

This policy applies to guests, customers, visitors to our Website, job applicants, business partners, and any other natural persons whose personal data we process. It does not apply to the personal data of our employees, which is governed by separate internal policies.

4. Personal Data We Collect

We collect various categories of personal data depending on how you interact with us. In accordance with the principle of data minimisation under Article 5(1)(c) of the GDPR, we only collect the personal data that is necessary for the specific purposes described in this policy.

4.1 Data You Provide Directly

We collect personal data that you voluntarily provide to us, including:

  • Identity Data: First name, last name, date of birth, gender, nationality, passport or national identity card number, and copies of identification documents as required by applicable law;
  • Contact Data: Email address, telephone number, home address, billing address;
  • Booking and Reservation Data: Check-in and check-out dates, room preferences, number of guests, special requests, dietary requirements, and accessibility needs;
  • Payment and Financial Data: Credit or debit card details (processed securely through our payment service providers), billing information, transaction history, and invoicing data;
  • Casino and Gaming Data: Player account information, gaming history, betting records, winnings, losses, self-exclusion requests, responsible gaming declarations, and age verification data;
  • Loyalty Programme Data: Membership number, points balance, redemption history, tier status, and programme preferences;
  • Account Credentials: Username and encrypted password for your online account, if applicable;
  • Communications Data: Content of messages, emails, feedback, complaints, and enquiries you send to us;
  • Marketing Preferences: Your opt-in or opt-out choices regarding marketing communications, preferred communication channels, and interests.

4.2 Data Collected Automatically

When you visit our Website, we automatically collect certain technical and usage data, including:

  • Device and Technical Data: IP address, browser type and version, operating system, device type, screen resolution, and language settings;
  • Usage Data: Pages visited, time and date of visits, duration of sessions, clickstream data, referral source URLs, and links clicked;
  • Cookie Data: Data collected through cookies, web beacons, pixels, and similar tracking technologies (please refer to our Cookie Policy for further details);
  • Location Data: Approximate geographic location derived from your IP address.

4.3 Data Collected from Third Parties

We may also receive personal data about you from the following third-party sources:

  • Online Travel Agencies and Booking Platforms: Reservation and guest data from platforms through which you book your stay;
  • Payment Processors: Transaction confirmation and fraud prevention data;
  • Identity Verification Services: Results of identity checks conducted for anti-money laundering (AML) or know-your-customer (KYC) compliance purposes in connection with casino services;
  • Credit Reference and Fraud Prevention Agencies: Data used to assess financial risk and prevent fraudulent activity;
  • Social Media Platforms: If you connect to our services via social media accounts or interact with our social media pages, we may receive limited profile information in accordance with your social media privacy settings;
  • Analytics and Advertising Partners: Aggregated or pseudonymised data used for website analytics and targeted advertising.

4.4 Special Categories of Personal Data

In certain circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. This includes:

  • Health Data: Dietary requirements, accessibility needs, or medical information provided by you to enable us to accommodate your specific needs during your stay;
  • Data Relating to Criminal Convictions or Offences: Where required by applicable gambling regulations or anti-money laundering obligations, we may be required to process information relating to criminal background checks.

We process such special category data only where we have a valid legal basis under Article 9(2) of the GDPR, such as your explicit consent or where processing is necessary for reasons of substantial public interest.

6. How We Use Your Personal Data

We use your personal data for the following specific purposes, in accordance with the legal bases identified in Section 5 above:

6.1 Hotel and Accommodation Services

  • Processing, confirming, and managing your hotel reservations and check-in/check-out procedures;
  • Preparing your room and accommodating any special requests or accessibility requirements;
  • Providing in-room services, concierge services, spa treatments, dining, and other hotel amenities;
  • Processing invoicing, payment, and billing for all services consumed during your stay;
  • Communicating with you before, during, and after your stay regarding your booking and experience;
  • Managing any complaints, refunds, or disputes related to your stay.

6.2 Casino and Gaming Services

  • Creating and managing your casino player account;
  • Verifying your identity and age in compliance with applicable gambling and AML regulations;
  • Processing gaming transactions, recording wins and losses, and facilitating payouts;
  • Implementing responsible gambling measures, including processing self-exclusion requests, setting betting limits, and monitoring for problematic gambling behaviour;
  • Conducting AML checks and reporting suspicious transactions to relevant authorities as required by law;
  • Preventing and detecting fraud, cheating, and other prohibited activities within the casino.

6.3 Customer Account Management

  • Creating and managing your online account on our Website;
  • Authenticating your identity when you log in;
  • Enabling you to manage your bookings, preferences, and personal information;
  • Administering our loyalty and rewards programme and communicating your points balance and benefits.

6.4 Marketing and Communications

  • Sending you personalised promotional offers, newsletters, and marketing communications about our hotel and casino services, subject to your consent or our legitimate interests where applicable;
  • Conducting surveys and market research to improve our services;
  • Personalising content displayed to you on our Website based on your browsing behaviour and preferences;
  • Retargeting advertising through third-party digital advertising platforms, subject to your cookie preferences.

6.5 Security and Fraud Prevention

  • Operating CCTV surveillance systems on our premises to ensure the safety and security of guests, staff, and property;
  • Detecting, investigating, and preventing fraud, theft, money laundering, and other criminal activities;
  • Protecting the integrity of our gaming operations;
  • Managing access control to restricted areas of our premises.

6.6 Legal Compliance and Regulatory Obligations

  • Complying with applicable gambling, AML, tax, health and safety, and other regulatory requirements;
  • Responding to requests from law enforcement agencies, courts, or regulatory authorities;
  • Establishing, exercising, or defending legal claims;
  • Maintaining statutory records and reports.

6.7 Website and Service Improvement

  • Analysing Website traffic and usage patterns to improve our Website design, content, and functionality;
  • Conducting A/B testing and performance optimisation;
  • Troubleshooting technical issues and ensuring the security of our IT infrastructure.

7. Sharing Your Personal Data

We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients where there is a lawful basis to do so:

7.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf (as data processors under Article 28 of the GDPR). These providers are contractually bound to process your data only on our instructions, implement appropriate security measures, and not use your data for their own purposes. They include:

  • Payment Processing Providers: For the secure processing of credit and debit card transactions;
  • Cloud Hosting and IT Service Providers: For secure storage and management of our IT systems and data;
  • Booking and Reservation System Providers: For managing online reservations and property management systems;
  • Email and Communication Platform Providers: For sending transactional and marketing communications;
  • Analytics Providers: For Website analytics and user behaviour tracking (e.g., Google Analytics);
  • Identity Verification and KYC Service Providers: For verifying the identity and age of casino patrons;
  • Cybersecurity Providers: For protecting our Website and IT infrastructure from threats;
  • Customer Support Platform Providers: For managing customer service enquiries and complaints.

7.2 Business Partners and Third-Party Service Providers

  • Online Travel Agencies (OTAs) and Booking Platforms: Where you made your booking through a third-party platform, we may share relevant booking confirmation and guest information with that platform;
  • Restaurant and Spa Partners: Where hotel services are provided by external partner businesses operating on our premises, we may share relevant booking and preference data with them;
  • Transportation Providers: Where you have requested transportation services arranged by us.

7.3 Regulatory and Law Enforcement Authorities

We may disclose your personal data to competent public authorities, regulatory bodies, law enforcement agencies, or courts where we are required to do so by applicable law, judicial order, or regulatory mandate. This includes:

  • Financial intelligence units and AML regulatory authorities for mandatory suspicious transaction reporting;
  • Gambling regulatory and licensing authorities;
  • Tax authorities for statutory reporting obligations;
  • Law enforcement agencies in connection with criminal investigations;
  • Courts and tribunals in connection with legal proceedings.

7.4 Corporate Transactions

In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction involving , your personal data may be transferred to the relevant successor entity. We will ensure that any such transfer is subject to appropriate confidentiality protections and that you are notified in accordance with applicable law.

7.5 Professional Advisors

We may share your personal data with our lawyers, accountants, auditors, insurers, and other professional advisors where necessary in connection with the services they provide to us, subject to appropriate confidentiality obligations.

8. International Transfers of Personal Data

As an entity registered in the European Union with operations in Australia, your personal data may be transferred to and processed in countries outside of the European Economic Area (EEA). Such countries may not provide the same level of data protection as the EEA.

Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your data in accordance with the GDPR. These safeguards may include:

  • Adequacy Decisions: Transfers to countries that the European Commission has determined provide an adequate level of data protection;
  • Standard Contractual Clauses (SCCs): Use of the European Commission’s approved standard contractual clauses incorporated into agreements with recipients;
  • Binding Corporate Rules: Where applicable for intra-group transfers;
  • Other Appropriate Safeguards: As permitted under Chapter V of the GDPR.

With respect to transfers to Australia specifically, we implement Standard Contractual Clauses and additional technical and organisational safeguards to ensure an adequate level of protection. You may request a copy of the relevant transfer safeguards by contacting our DPO at privacy@northplainstudio.com.

9. Data Retention

In accordance with the storage limitation principle under Article 5(1)(e) of the GDPR, we retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law.

The following retention periods apply to the main categories of personal data we process:

Category of Personal Data Retention Period Basis
Hotel reservation and guest records 7 years from date of stay Legal obligation (tax and accounting records)
Payment and financial transaction data 7 years from date of transaction Legal obligation (financial and tax regulations)
Casino player account and gaming records 5 years from account closure or last activity Legal obligation (AML and gambling regulations)
AML and KYC identity verification records 5 years from the end of the business relationship Legal obligation (AML Directive)
Self-exclusion records Duration of exclusion plus 5 years Legal obligation (responsible gambling regulations)
CCTV footage from premises 30 days, unless retained for investigation purposes Legitimate interests (security)
Marketing and communication preferences Until withdrawal of consent or opt-out, plus 1 year Consent / Legitimate interests
Customer service correspondence and complaints 3 years from resolution of enquiry Legitimate interests / Legal obligation
Website usage and analytics data 26 months from collection Consent / Legitimate interests
Cookie consent records 3 years from date of consent Legal obligation (demonstrating consent)
Loyalty programme data Duration of membership plus 3 years Contract performance / Legitimate interests

At the end of the applicable retention period, personal data is securely deleted, anonymised, or destroyed in accordance with our data deletion procedures. In certain circumstances, we may retain data for longer periods where necessary for the establishment, exercise, or defence of legal claims.

10. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights with respect to the processing of your personal data. These rights apply subject to the conditions and limitations set out in the GDPR and applicable national law.

10.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process personal data concerning you and, if so, to receive a copy of that data along with information about the purposes of processing, categories of data, recipients, retention periods, and your other rights.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request the correction of inaccurate personal data concerning you. Where appropriate, you also have the right to have incomplete personal data completed, including by providing a supplementary statement.

10.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)

You have the right to request the deletion of your personal data in the following circumstances:

  • The personal data is no longer necessary for the purposes for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to the processing and there are no overriding legitimate grounds;
  • The personal data has been unlawfully processed;
  • Erasure is required to comply with a legal obligation.

This right is not absolute. We may refuse erasure where processing is necessary for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defence of legal claims.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in the following circumstances:

  • You contest the accuracy of the personal data, pending verification;
  • Processing is unlawful and you oppose erasure, requesting restriction instead;
  • We no longer need the data, but you require it for legal claims;
  • You have objected to processing based on legitimate interests, pending our assessment.

10.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract, and where processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

10.6 Right to Object (Article 21 GDPR)

You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where it is based on our legitimate interests (Article 6(1)(f) GDPR). If you raise a valid objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for legal claims.

You also have an absolute right to object at any time to the processing of your personal data for direct marketing purposes, including profiling carried out for direct marketing. Upon exercising this right, we will immediately cease such processing.

10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we conduct such automated decision-making (for