Grand Royale Group

Grand Royale Group Privacy and Data Protection
Privacy Policy

Your privacy matters.

Grand Royale Group manages personal information across accommodation, dining, events, property services, employment, partnerships and hospitality simulation activities.

Read the policy
Effective date 9 July 2026
Policy version Version 1.0
Privacy enquiries enquiry@grandroyalegroup.com.au
01

Overview

Our commitment

Grand Royale Group respects the privacy of guests, customers, learners, workers, applicants, property clients, suppliers and business partners.

This policy explains how we collect, hold, use, disclose, secure and manage personal information across our Australian hospitality operations and digital services.

It applies to Grand Royale Group websites, accommodation operations, restaurants, cafés, functions, conferences, property services, recruitment processes, supplier relationships and learning simulation environments.

Transparency

We explain why information is collected and how it is managed.

Protection

We use operational, physical and technical safeguards.

Purpose

We collect information needed for legitimate activities.

Australian privacy framework

Our information handling practices are guided by applicable Australian privacy, workplace, electronic marketing and record management requirements.

02

Information we collect

Information categories

The information collected depends on your relationship with Grand Royale Group and the service, property, venue or digital platform you use.

We may collect names, titles, preferred names, postal addresses, email addresses, telephone numbers and emergency contact information.

  • Account and profile details
  • Communication preferences
  • Identity verification details where required
  • Authorised representative information

We may collect information needed to manage reservations, stays and guest services.

  • Arrival and departure dates
  • Room type and package selections
  • Names of accompanying guests
  • Accessibility and service requirements
  • Guest preferences and special requests
  • Feedback, complaints and service recovery records
  • Vehicle details where parking is provided

We may collect dining reservations, event requirements and venue service information.

  • Dining dates, times and party sizes
  • Dietary and allergy information
  • Function and conference requirements
  • Guest lists and attendee information
  • Room layouts, run sheets and schedules
  • Supplier and event organiser details
  • Photography preferences where relevant

We may collect transaction information needed to process charges, deposits, refunds and invoices.

  • Billing and invoice details
  • Payment status and transaction references
  • Deposit and refund information
  • Corporate account details
  • Limited payment information supplied by payment providers

Payment card processing may be completed by authorised external payment providers.

We may collect information required to manage property enquiries, inspections, applications, sales and rental arrangements.

  • Property preferences and enquiry history
  • Inspection booking information
  • Rental history and references
  • Employment and income verification
  • Identity and eligibility documentation
  • Tenancy, ownership and settlement records
  • Maintenance and property communication records

We may collect information needed to assess applicants and manage employment or contractor relationships.

  • Résumés and employment history
  • Qualifications and hospitality certifications
  • References and interview records
  • Work rights and identity checks
  • Availability and role preferences
  • Payroll, taxation and superannuation information
  • Training, performance and development records
  • Workplace health and safety records

Some employee records may be managed under separate workplace laws and internal policies.

We may collect information required to operate the Grand Royale Group hospitality simulation environment.

  • Learner, trainer and assessor account details
  • Education provider information
  • Portal activity and access records
  • Submitted simulation documents
  • Learning progress and completion records
  • Feedback and support communications
  • Technical troubleshooting information

Our digital services may collect technical information needed for performance, security and service improvement.

  • Internet Protocol address
  • Browser and device information
  • Pages viewed and links selected
  • Access dates and session duration
  • Login and security events
  • Cookie and analytics identifiers
  • Chatbot and support interaction records

Sensitive information may include health, accessibility, dietary, allergy, religious, biometric or criminal record information.

We collect sensitive information only where it is reasonably necessary, legally authorised or required, and where any required consent has been obtained.

Simulation environment

Users should not enter real guest, payment, health, identity or employment information into simulated documents unless an authorised training process specifically requires it.

03

How information is collected

Collection channels

We generally collect personal information directly from you. We may also receive information from authorised representatives, booking partners, employers, education providers and service providers.

01

Direct interactions

Bookings, enquiries, telephone calls, emails, registrations, applications, surveys and face to face service interactions.

02

Hospitality platforms

Travel agents, booking platforms, event organisers, payment processors and loyalty partners.

03

Business relationships

Suppliers, employers, referees, property representatives, professional advisers and education providers.

04

Digital channels

Websites, portals, chatbot tools, cookies, analytics, login systems and security monitoring.

Information about other people

When you provide information about another person, such as an accompanying guest, event attendee, referee or emergency contact, you should have authority to do so and make that person aware of this policy where practical.

Anonymous enquiries

You may contact us anonymously or use a pseudonym where this is practical. We may need your identity to confirm a booking, process payment, assess an application, provide secure account access or meet legal and safety responsibilities.

04

How information is used

Operational purposes

We use personal information for purposes connected with our hospitality operations, property services, workforce, digital platforms and legal responsibilities.

01

Guest reservations

Confirming accommodation, arrivals, departures, room allocation and guest requests.

02

Food and beverage

Managing dining reservations, dietary requirements, functions, catering and customer service.

03

Meetings and events

Coordinating venues, attendees, accommodation, suppliers, schedules and event requirements.

04

Property services

Managing enquiries, inspections, applications, rentals, sales and property administration.

05

Recruitment and employment

Assessing candidates, engaging workers, administering payroll, training and workplace safety.

06

Learning simulations

Providing portal access, resources, support and authorised training activities.

07

Customer support

Responding to enquiries, feedback, complaints, requests and service recovery matters.

08

Safety and security

Protecting guests, workers, learners, premises, systems and business assets.

09

Business improvement

Reviewing service quality, website performance, operational results and customer experience.

10

Legal compliance

Maintaining records, managing claims and responding to lawful regulatory or government requests.

05

Disclosure and service providers

Controlled information sharing

We may disclose personal information where reasonably required to deliver a service, operate the business, protect people or property, or comply with law.

Grand Royale Group teams

Authorised hotel, restaurant, event, property, finance, technology, human resources, security and administration personnel.

Booking and payment providers

Reservation platforms, payment processors, banks, travel agents and corporate booking partners.

Hospitality service providers

Event suppliers, caterers, transport providers, maintenance contractors, cleaners and venue partners.

Property service providers

Property owners, agents, inspectors, tradespeople, valuers and settlement providers.

Technology providers

Website hosts, cloud platforms, software suppliers, communication providers and security services.

Education providers

Registered training organisations, trainers, assessors, employers and authorised platform administrators.

Professional and government bodies

Lawyers, accountants, auditors, insurers, regulators, emergency services, courts and law enforcement bodies.

Overseas service providers

Some cloud, booking, communication, analytics or technology providers may store or process information outside Australia. The countries involved depend on the provider and service configuration.

Where required, we take reasonable steps to assess relevant contractual, privacy and security arrangements before using an overseas provider.

Business changes

Information may be disclosed under appropriate controls as part of a proposed or completed restructure, acquisition, financing arrangement, management transfer or sale of business assets.

06

Website, cookies and marketing

Digital privacy

Our website may use cookies and similar technologies to operate securely, remember preferences, understand website use and improve digital services.

Essential cookies

Support security, forms, sessions, navigation and core website functions.

Preference cookies

Remember interface choices, selected settings and accessibility preferences.

Analytics cookies

Help us understand website performance, visits and general interaction patterns.

Functionality cookies

Support chatbots, embedded media, maps and other enhanced website services.

Cookie controls

You may manage cookies through available website controls or your browser settings. Disabling cookies may affect forms, account access, media and other website functions.

Chatbot interactions

Chatbot messages may be processed to answer questions, locate resources, support website navigation, maintain service security and improve support quality.

Do not enter passwords, payment card details, government identifiers or private health information into a general website chatbot.

Marketing communications

We may send information about hospitality services, events, property opportunities, partnerships and resources where we have permission or another lawful basis.

Electronic marketing messages will include an unsubscribe option where required. Withdrawing from marketing does not prevent necessary booking, transaction, account or safety communications.

07

Security and retention

Information protection

We use administrative, physical and technical measures appropriate to the information, the way it is held and the related security risks.

Access controls

Access is limited according to role and operational need.

Approved systems

Authorised systems support hosting, backup and monitoring.

Workforce controls

Workers have confidentiality and information handling duties.

Physical protection

Premises, devices and records use appropriate safeguards.

Record management

Records are classified, retained and securely disposed of.

Incident response

Suspected incidents are assessed, contained and escalated.

Retention and disposal

Personal information is retained for as long as reasonably required for service delivery, taxation, employment, safety, training, contractual, insurance, dispute management or legal purposes.

When information is no longer required, we take reasonable steps to destroy it securely or remove identifying details, subject to legal and system backup requirements.

CCTV and premises security

CCTV and electronic access systems may be used at selected premises for guest safety, worker safety, security, loss prevention and incident investigation. Appropriate signs may be displayed where surveillance operates.

08

Your privacy rights

Access and correction

Subject to applicable requirements and exceptions, you may request access to personal information held about you or ask us to correct information that is inaccurate, incomplete, outdated, irrelevant or misleading.

Step 1

Submit your request

Explain the information or action you require.

Step 2

Verify your identity

We may request identification before releasing information.

Step 3

Receive a response

We will assess the request and respond within a reasonable period.

You may contact us to

  • Request access to your personal information
  • Request correction of inaccurate information
  • Update your contact or account details
  • Change marketing communication preferences
  • Withdraw consent where consent applies
  • Ask how specific information has been handled
  • Authorise a representative to act for you

Access may be limited where providing information would unreasonably affect another person, create a serious safety risk, reveal protected material or be restricted by law.

09

Complaints and data breaches

Resolution and response

Contact us if you believe personal information has been handled incorrectly or you are dissatisfied with our response to a privacy request.

Step 1

Submit the concern

Explain the issue, relevant circumstances and requested outcome.

Step 2

Internal assessment

We will review relevant information and consult suitable personnel.

Step 3

Written response

We will explain our findings and available next steps.

Data breach response

A data breach may occur when personal information is lost or becomes subject to unauthorised access or disclosure.

Identify Record the suspected incident
Contain Limit further access or loss
Assess Review information and potential harm
Respond Remediate and provide required notices

Where applicable, we will notify affected individuals and the Office of the Australian Information Commissioner when an eligible data breach is likely to result in serious harm.

External complaint options

Where a privacy complaint cannot be resolved directly, you may be entitled to contact the Office of the Australian Information Commissioner or another relevant regulator.

Privacy support

Contact Grand Royale Group

Contact us to request access or correction, update your preferences, report a privacy concern or ask how your information is managed.

Privacy request subject line

Use the subject line Privacy Request and include your name, contact details, relationship with Grand Royale Group and a clear description of your request.

Grand Royale Group

Privacy Policy. Version 1.0. Effective 9 July 2026.

Back to top
Scroll to Top