Privacy Policy

Last updated: 1 July 2025

This Privacy Policy explains how Mapleridgeatelier GmbH ("we", "us", or "our") collects, uses, discloses, and safeguards your personal information when you visit or make use of our website at www.mapleridgeatelier.com (the "Site"), or when you interact with us in connection with our hotel and casino services at Mapleridgeatelier, Sydney ("Services"). This Policy has been prepared in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and other applicable Australian state and territory laws.

Please read this Policy carefully. By accessing or using our Site or Services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Policy.

1. Data Controller

The data controller responsible for your personal information under the GDPR and applicable Australian privacy legislation is:

Registered Company Name Mapleridgeatelier GmbH
Trading Name Mapleridgeatelier
Registration Country European Union (EU)
Legal Address
Website www.mapleridgeatelier.com
Privacy Enquiries Email privacy@mapleridgeatelier.com

If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the GDPR applies to our processing of your personal data. If you are located in Australia, the Privacy Act 1988 (Cth) and the APPs apply. Where both frameworks are relevant, we apply the higher standard of protection.

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer ("DPO") to oversee our compliance with applicable data protection laws. You may contact our DPO at any time using the following details:

Name / Title The Data Protection Officer
Organisation Mapleridgeatelier GmbH
Postal Address
Email Address privacy@mapleridgeatelier.com

2. Personal Information We Collect

We collect personal information that you provide directly to us, that is generated through your use of our Site and Services, and that we receive from third parties. "Personal information" (also referred to as "personal data" under the GDPR) means any information that identifies you or from which you can be reasonably identified.

2.1 Information You Provide Directly

  • Identity Information: Full name, date of birth, gender, title, and photograph (where required for regulatory purposes such as casino identification).
  • Contact Information: Residential or postal address, email address, telephone number, and emergency contact details.
  • Booking and Reservation Details: Room preferences, check-in and check-out dates, number of guests, special requests, dietary requirements, accessibility needs, and loyalty programme membership details.
  • Payment Information: Credit card or debit card numbers (processed through a secure payment gateway — we do not store full card numbers), billing address, and payment transaction records.
  • Casino and Gaming Information: Gaming activity records, player card details, betting history, winnings and losses, responsible gambling self-exclusion requests, and age and identity verification documents required under applicable gaming legislation.
  • Identification Documents: Passport, driver's licence, or other government-issued identity documents (collected where required by law or for age verification purposes under gaming regulations).
  • Account and Profile Information: Username, password, profile preferences, and communication preferences when you create an account on our Site.
  • Communications: Records of correspondence, feedback, complaints, or enquiries you submit to us by email, telephone, post, or through our Site's contact forms.
  • Marketing Preferences: Your preferences for receiving marketing communications from us and our partners.
  • Survey and Competition Entries: Responses to guest satisfaction surveys, prize draw entries, and promotional campaign participation details.

2.2 Information Collected Automatically

When you access or use our Site, certain information is collected automatically through cookies, web beacons, and similar tracking technologies, including:

  • Technical Data: IP address, browser type and version, operating system and platform, device type and identifiers, time zone, and location data (country or city level).
  • Usage Data: Pages visited, links clicked, referring URLs, search terms used on our Site, session duration, and other interaction data.
  • Cookie Data: Information stored in cookies placed on your device — see our Cookie section (Section 8) for full details.
  • CCTV and Security Footage: When you visit our premises, you may be captured on closed-circuit television cameras operated for security, fraud prevention, and regulatory compliance purposes.

2.3 Information Received from Third Parties

  • Travel Agents and Booking Platforms: Reservation details and guest preferences forwarded to us when you book through an authorised third-party agent or online travel platform.
  • Identity Verification Services: Confirmation of identity and age from third-party verification providers used for casino compliance.
  • Payment Processors: Transaction authorisation information and fraud-screening results.
  • Analytics Providers: Aggregated and pseudonymised data about website usage patterns.
  • Publicly Available Sources: Information you have made publicly available, such as publicly visible social media profiles, where relevant to our Services.
  • Regulatory and Law Enforcement Bodies: Where we are required by applicable gaming, anti-money laundering, or other legislation to share or receive information.

2.4 Special Categories of Personal Information

In limited circumstances, we may process special categories of personal information (as defined under Article 9 GDPR), including:

  • Health Information: Accessibility and dietary requirements that may indicate a health condition or disability, where you choose to share this with us for service personalisation purposes.
  • Biometric Data: Facial recognition images captured via CCTV for security purposes, where permitted by applicable law.
  • Information Relating to Criminal Convictions and Offences: Where required by gaming regulatory obligations or for fraud prevention under Australian law.

We process special category data only where we have a valid legal basis under Article 9(2) GDPR, such as your explicit consent, compliance with legal obligations, or where processing is necessary for reasons of substantial public interest. Under Australian law, we handle sensitive information in accordance with APP 3.

2.5 Children's Information

Our Site and casino Services are strictly intended for adults aged 18 years and over. We do not knowingly collect personal information from individuals under the age of 18. Where we become aware that we have inadvertently collected information from a minor, we will take prompt steps to delete that information. If you believe we have collected personal information about a child, please contact us immediately at privacy@mapleridgeatelier.com.

4. How We Use Your Personal Information

We use the personal information we collect for the following purposes:

4.1 Providing and Managing Our Services

  • Processing and managing hotel accommodation bookings, reservations, and check-in and check-out procedures;
  • Delivering food and beverage, spa, entertainment, concierge, and other ancillary services;
  • Administering casino gaming accounts, processing gaming transactions, and maintaining accurate gaming records;
  • Processing payments and issuing receipts, tax invoices, and refunds;
  • Managing your loyalty programme account and rewards;
  • Responding to your enquiries, requests, and complaints in a timely and efficient manner; and
  • Facilitating online account registration and management on our Site.

4.2 Regulatory and Legal Compliance

  • Verifying your identity and age in accordance with gaming legislation;
  • Complying with anti-money laundering, counter-terrorism financing, and know-your-customer obligations;
  • Administering responsible gambling programmes, including self-exclusion registers and pre-commitment schemes;
  • Maintaining statutory records and fulfilling tax and financial reporting obligations; and
  • Cooperating with regulatory inspections, audits, and investigations.

4.3 Security and Fraud Prevention

  • Operating CCTV surveillance systems to protect the safety of guests, staff, and assets on our premises;
  • Detecting, preventing, and investigating fraud, theft, cheating, and other unlawful activity;
  • Monitoring and safeguarding our IT systems and network infrastructure; and
  • Screening against sanctions lists and other prohibited person databases where required by law.

4.4 Marketing and Communications

  • Sending you promotional offers, news, and information about our Services, special packages, events, and promotions where you have consented or where we have a legitimate interest in doing so;
  • Personalising our communications and marketing to your known interests and preferences;
  • Conducting prize draws, competitions, and loyalty reward campaigns; and
  • Inviting you to participate in guest satisfaction surveys and provide feedback.

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any email, by adjusting your account preferences on our Site, or by contacting us at privacy@mapleridgeatelier.com. Opting out of marketing will not affect communications necessary for the performance of your booking or contract.

4.5 Analytics and Service Improvement

  • Analysing Site usage patterns to understand how guests interact with our online platforms and to improve their design, functionality, and content;
  • Monitoring service delivery standards and identifying opportunities for improvement;
  • Conducting internal business analysis, reporting, and strategic planning; and
  • Developing new products, services, and features.

4.6 Legal Claims and Dispute Resolution

  • Establishing, exercising, or defending legal claims; and
  • Complying with court orders, tribunal orders, and other legal processes.

5. Disclosure of Your Personal Information

We may disclose your personal information to the following categories of recipients, always in accordance with applicable law and subject to appropriate safeguards.

5.1 Our Group Companies and Affiliates

We may share your personal information with other entities within the Mapleridgeatelier GmbH corporate group for internal administrative, operational, and reporting purposes, subject to equivalent privacy protections.

5.2 Service Providers and Data Processors

We engage trusted third-party service providers who process personal information on our behalf as data processors. These include:

  • IT and Cloud Infrastructure Providers: Hosting, data storage, and platform support services;
  • Payment Processors: Secure processing of credit and debit card transactions;
  • Identity Verification Services: Age and identity verification for casino compliance purposes;
  • Property Management System Providers: Hotel reservation, front desk, and guest management software;
  • Casino Management System Providers: Gaming account management and transaction processing;
  • Email and SMS Marketing Platforms: Delivery of marketing and transactional communications;
  • Analytics Providers: Website performance monitoring and usage analytics (e.g., Google Analytics);
  • CCTV and Security Contractors: Operation and maintenance of security surveillance systems;
  • Legal, Accounting, and Professional Advisers: Provision of legal, financial, and risk management advice; and
  • Loyalty Programme Partners: Administration of guest reward and recognition programmes.

All service providers are required to process your information only on our documented instructions and to implement appropriate technical and organisational security measures. We enter into data processing agreements with all processors that comply with Article 28 GDPR requirements.

5.3 Regulatory and Government Authorities

We will disclose personal information to regulatory bodies, government authorities, law enforcement agencies, and courts where we are required or permitted to do so by applicable law, including:

  • The NSW Independent Casino Commission;
  • The Australian Transaction Reports and Analysis Centre (AUSTRAC);
  • The Australian Taxation Office (ATO);
  • The Office of the Australian Information Commissioner (OAIC);
  • New South Wales Police and other law enforcement agencies; and
  • EU supervisory authorities where required under GDPR.

5.4 Business Transfers

In the event of a merger, acquisition, sale of business assets, restructuring, or similar corporate transaction, your personal information may be transferred to the relevant successor entity. We will notify you of any such transfer and ensure that the recipient provides equivalent privacy protections.

5.5 With Your Consent

We may share your personal information with other third parties where you have given your explicit consent for us to do so.

5.6 International Data Transfers

As Mapleridgeatelier GmbH is registered in the European Union and operates in Australia, your personal information may be transferred between these jurisdictions and, where our service providers are located, to other countries. When transferring personal data from the EEA to a third country (including Australia), we ensure that one of the following safeguards is in place:

  • The European Commission has issued an adequacy decision for the destination country;
  • Standard Contractual Clauses (SCCs) approved by the European Commission are in place with the recipient;
  • The recipient has implemented Binding Corporate Rules (BCRs) approved by a competent supervisory authority; or
  • Another derogation under Article 49 GDPR applies (e.g., explicit consent, necessity for performance of a contract).

Under Australian law, where we transfer personal information outside Australia, we take reasonable steps to ensure that the recipient handles that information in a manner consistent with the APPs, in accordance with APP 8.

You may request a copy of the safeguards we have in place for international transfers by contacting our DPO at privacy@mapleridgeatelier.com.

6. Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, and to resolve any disputes or enforce our agreements.

Our general retention periods are as follows:

Category of Personal Information Retention Period Reason
Hotel booking and reservation records 7 years after the date of stay Tax and financial record-keeping obligations; contractual purposes
Casino gaming records and player account data 7 years from account closure or last transaction Gaming regulatory requirements; AML/CTF compliance
Identity verification documents 7 years from the date of collection AML/CTF Act obligations; gaming regulatory compliance
Financial transaction records 7 years from the date of transaction Taxation law; accounting standards
Marketing preferences and communications history 3 years from last interaction or until consent withdrawn Legitimate interests; consent-based processing
CCTV footage 31 days from recording, unless required for an investigation Security and fraud prevention; regulatory requirements
Customer service correspondence and complaints 3 years from resolution Legal claims; service quality management
Website usage data and cookies Up to 2 years (as specified in our Cookie Policy) Analytics; Site improvement
Self-exclusion records Indefinitely or as required by gaming legislation Responsible gambling regulatory obligations

At the end of the applicable retention period, we will securely delete or anonymise your personal information so that it can no longer be associated with you. Where anonymisation is not possible, we will securely destroy the relevant records.

Retention periods may be extended where required by law, where a dispute is ongoing, or where we have a legitimate need to retain the information for the purpose of legal proceedings.

7. Your Privacy Rights

Depending on your location and the applicable privacy law, you may have the following rights in respect of your personal information. We will handle all requests in accordance with the GDPR and the Privacy Act 1988 (Cth) as applicable.

7.1 Right of Access (Article 15 GDPR / APP 12)

You have the right to request a copy of the personal information we hold about you, together with information about how and why we process it, who we share it with, and how long we retain it. Under Australian law, you also have the right to access personal information we hold about you under APP 12.

7.2 Right to Rectification (Article 16 GDPR / APP 13)

You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. Under APP 13, we must take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request that we delete your personal information in certain circumstances, including where the information is no longer necessary for the purposes for which it was collected, where you withdraw consent (and there is no other lawful basis), or where you object to processing and there are no overriding legitimate grounds. This right is subject to exceptions, including where we are required to retain information to comply with a legal obligation.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal information in certain circumstances, such as where you contest the accuracy of the data, where processing is unlawful and you prefer restriction over deletion, or where we no longer need the data but you require it for legal claims.

7.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive a copy of the personal information you provided to us in a structured, commonly used, and machine-readable format, and to have that information transmitted directly to another controller where technically feasible.

7.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal information:

  • On grounds of legitimate interests: We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.
  • For direct marketing purposes: You have an absolute right to object to processing for direct marketing purposes at any time. We will cease such processing promptly upon receipt of your objection.

7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. If we engage in such automated decision-making, we will inform you, provide you with an opportunity to obtain human review, and allow you to express your point of view and contest the decision.

7.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw that consent at any time without detriment. Withdrawal will not affect the lawfulness of any processing carried out prior to the withdrawal.

7.9 Right to Complain to a Supervisory Authority

If you are located in the EEA or UK and believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement.

If you are located in Australia, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Telephone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

We encourage you to contact us first before making a regulatory complaint so that we have the opportunity to address your concern directly.

7.10 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to our DPO at:

We will acknowledge receipt of your request within 5 business days and respond substantively within 30 calendar days of receipt. In complex or multiple cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it, in accordance with Article 12(3) GDPR. We may be required to verify your identity before processing certain requests.

We will not charge a fee for reasonable requests. However, where requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, as permitted by applicable law.

8. Cookies and Tracking Technologies

Our Site uses cookies and similar tracking technologies (such as web beacons, pixel tags, and local storage objects) to deliver and improve our services, personalise content and advertisements, and analyse Site usage.

8.1 Types of Cookies We Use

Cookie Type Purpose Legal Basis
Strictly Necessary Cookies Essential for the operation of our Site, including enabling you to navigate the Site and use its features (e.g., maintaining your session, completing a booking transaction). Legitimate interests (these cookies cannot be disabled without impairing core Site functionality)
Performance and Analytics Cookies Collect information about how visitors use our Site (e.g., pages visited, error messages received) to help us improve Site performance. Data is aggregated and anonymous. Consent
Functionality Cookies Remember choices you make (e.g., language preferences, room type selections) to provide an enhanced, personalised experience. Consent
Marketing and Advertising Cookies Track your browsing activity across our Site and third-party sites to serve you relevant advertisements and measure the effectiveness of our marketing campaigns. Consent

8.2 Managing Your Cookie Preferences

When you first visit our Site, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You may update your cookie preferences at any time by clicking the "Cookie Settings" link in our Site footer.

You can also manage cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our Site. For more information about managing cookies, visit www.aboutcookies.org.

9. Data Security

We implement appropriate technical and organisational security measures to protect your personal information against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest;
  • Access controls and role-based permissions, ensuring that only authorised personnel can access personal information on a need-to-know basis;
  • Regular security assessments, penetration testing, and vulnerability management;
  • Staff training on data protection and information security best practices;
  • Incident response and data breach notification procedures; and
  • Regular review and audit of our security controls.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR and the notifiable data breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, applicable law, or regulatory requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or via a prominent notice on our Site prior to the change taking effect.

We encourage you to review this Policy periodically to stay informed about how we are protecting your information. Your continued use of our Site or Services after any changes to this Policy constitutes your acceptance of the updated terms.

12. Contact Us

If you have any questions, concerns, or feedback about this Privacy Policy or the way we handle your personal information, or if you wish to exercise any of your rights as described in this Policy, please contact us using the following details:

Contact Name / Title The Data Protection Officer
Organisation Mapleridgeatelier GmbH
Postal Address
Email Address privacy@mapleridgeatelier.com
Website www.mapleridgeatelier.com

If you are not satisfied with our response, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC) (for Australian residents) or to the relevant EU or EEA national data protection supervisory authority (for EEA residents), as described in Section 7.9 above.