QUENDARIO GRAND HAVEN
HomePrivacy PolicyTerms & ConditionsCookie Policy

Privacy Policy

Effective: 27 August 2026

Privacy information for Quendario Grand Haven covering Australian privacy obligations, GDPR rights, security, retention and data handling.

1. Scope and identity of the controller

This Privacy Policy explains how Quendario Grand Haven Pty Ltd. ("Quendario", "we", "us" or "our") handles personal information when you browse this website, make an enquiry, request accommodation or event information, subscribe to updates, or otherwise interact with our casino hotel services. For the purposes of the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and, where applicable, the EU General Data Protection Regulation (GDPR), we act as the organisation responsible for the processing described here. The website is intended for adults and the casino-related sections are intended only for persons who satisfy the applicable legal age requirements.

2. Personal information we may collect

Depending on how you interact with us, we may collect your name, contact details, booking or enquiry preferences, requested stay dates, accessibility or service preferences that you voluntarily provide, correspondence, newsletter choices, and information contained in messages submitted through forms. We may also process technical information such as browser type, device category, operating system, approximate region, referring page, page interactions, timestamps, and security logs. We do not intentionally request special-category information through ordinary website forms and ask that you avoid sending sensitive information unless it is genuinely necessary for a specific request.

3. Sources of information

We collect information directly from you when you enter it into a form, communicate with our team, or otherwise provide it. Some technical information is generated automatically by your browser and our local website infrastructure when pages are requested. Where a booking, event or hospitality request involves another person, you should provide their details only when you have authority to do so and have informed them of the relevant privacy implications.

4. Purposes of processing

We use personal information to respond to enquiries, provide requested information about rooms, dining, casino entertainment and leisure experiences, administer reservations where applicable, maintain website security, prevent misuse, keep appropriate business records, improve content and usability, manage consent choices, and comply with legal obligations. We do not use personal information for unrelated purposes without a lawful basis or appropriate notice.

5. Legal bases under the GDPR

Where the GDPR applies, processing is carried out on one or more recognised legal bases. These may include performance of a contract or steps requested before entering a contract, compliance with a legal obligation, our legitimate interests in operating a secure and effective hospitality website, and consent where consent is required for optional storage or communications. When we rely on legitimate interests, we consider the necessity of the processing and balance those interests against your rights and reasonable expectations.

6. Australian Privacy Principles

For users in Australia, we handle personal information in accordance with the APP framework to the extent applicable. This includes taking reasonable steps to provide transparency about collection, using information for permitted purposes, protecting it against misuse, interference, loss and unauthorised access, and responding to valid access or correction requests. If an eligible privacy complaint cannot be resolved directly with us, you may have the right to contact the Office of the Australian Information Commissioner.

7. Cookies, local storage and similar technologies

The website may use strictly necessary browser storage to preserve basic functionality and security. Optional analytics or preference storage, if introduced, will be used only in accordance with the choices presented to you and the Cookie Policy. You can remove stored data through browser controls. Disabling necessary browser functions may affect parts of the website, while declining optional storage should not prevent access to core informational content.

8. Analytics and performance information

We may use first-party, privacy-conscious measurements to understand aggregate traffic and page performance. We aim to minimise the data collected and avoid using analytics information to create advertising profiles. Technical logs may be retained for a limited period where reasonably necessary to identify failures, maintain security and understand aggregate usage. Any optional analytics requiring consent will not be activated before a valid choice where such consent is required by law.

9. Disclosure to service providers

We may disclose limited information to suppliers that support legitimate business operations, such as website hosting, secure infrastructure, reservation administration, communications, professional advisers, and fraud or security support. Suppliers are expected to process information only for authorised purposes and subject to appropriate confidentiality, security and data-protection commitments. We do not sell personal information.

10. International transfers

Some operational suppliers may process information outside Australia or outside the country where you are located. Where the GDPR applies to an international transfer, we use an available lawful transfer mechanism and supplementary safeguards where required. Under Australian privacy law, we take reasonable steps relevant to overseas disclosures in accordance with applicable APP obligations.

11. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to maintain appropriate business and legal records, to resolve disputes, and to meet regulatory or taxation requirements. Retention periods vary according to the type of information and the context. When information is no longer required, we take reasonable steps to delete it, de-identify it, or securely dispose of it.

12. Security

We use proportionate administrative, organisational and technical controls designed to protect information from unauthorised access, alteration, disclosure, loss or misuse. These controls may include restricted access, secure configuration, backups, software maintenance, access logging and staff procedures. No internet service can guarantee absolute security, and you should use reasonable care when sending information online.

13. Data breaches

Where a security incident involves personal information, we assess the nature and likely consequences of the incident and take containment and remediation steps. If notification is required under the Australian Notifiable Data Breaches scheme, the GDPR or another applicable law, we will make notifications within the time and manner required by that law.

14. Your rights under the GDPR

If the GDPR applies to you, you may have rights to request access, rectification, erasure, restriction, portability, or objection to certain processing, and to withdraw consent where processing depends on consent. These rights are subject to legal conditions and exceptions. You also have the right to lodge a complaint with a competent supervisory authority. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

15. Access and correction in Australia

Australian users may request access to personal information we hold about them and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, subject to applicable exceptions. We may need to verify identity before acting on a request. If we refuse a request where the law permits refusal, we will provide the reasons and available complaint options where required.

16. Direct communications

If you choose to receive updates, we may use the contact details you provide for that purpose. You can opt out of non-essential direct communications using the mechanism provided in the communication or by making a request through the contact details displayed on this website. Service or transactional communications necessary to respond to an active request may continue where appropriate.

17. Children and casino-related content

The website is not directed to children. Casino-related content is intended only for adults who meet the applicable legal age requirements. We do not knowingly collect personal information from children through casino-related areas. If we become aware that information has been submitted by a person who does not meet the relevant age threshold, we will take reasonable steps consistent with applicable law.

18. Automated decisions

We do not make decisions producing legal or similarly significant effects solely through automated processing based on ordinary website browsing. If that changes, we will provide the additional information and safeguards required by applicable law before such processing begins.

19. Links and third-party environments

The website may refer to services or destinations operated independently from Quendario. When you leave our local website environment, another operator may process information under its own terms. This policy governs only processing for which Quendario is responsible. We encourage you to review the privacy information presented by any independent service before submitting personal information.

20. Changes to this policy

We may update this policy to reflect operational, legal or technical developments. The current version will be identified by its effective date. Material changes may be highlighted on the website where appropriate. Continued use of the website after an update does not replace any consent that the law requires us to obtain separately.

21. Privacy enquiries and complaints

You may contact us regarding privacy questions, access or correction requests, GDPR rights, or complaints using the ordinary contact information displayed on the website. Please provide enough information for us to identify the request without sending unnecessary sensitive information. We aim to acknowledge and address privacy concerns within a reasonable period and within any mandatory statutory timeframe.

Administrator and contact

Legal entity: Quendario Grand Haven Pty Ltd.

Business address: 17 Marlin Parade, Mermaid Beach, QLD, Australia

Jurisdiction: Queensland, Australia. Privacy obligations may also include the GDPR where its territorial scope applies.

Return to Home

© 2026 Quendario Grand Haven Pty Ltd. · 17 Marlin Parade, Mermaid Beach, QLD, Australia

Privacy PolicyTerms & ConditionsCookie Policy