Your privacy matters.
Grand Royale Group manages personal information across accommodation, dining, events, property services, employment, partnerships and hospitality simulation activities.
Overview
Grand Royale Group respects the privacy of guests, customers, learners, workers, applicants, property clients, suppliers and business partners.
This policy explains how we collect, hold, use, disclose, secure and manage personal information across our Australian hospitality operations and digital services.
It applies to Grand Royale Group websites, accommodation operations, restaurants, cafés, functions, conferences, property services, recruitment processes, supplier relationships and learning simulation environments.
Transparency
We explain why information is collected and how it is managed.
Protection
We use operational, physical and technical safeguards.
Purpose
We collect information needed for legitimate activities.
Our information handling practices are guided by applicable Australian privacy, workplace, electronic marketing and record management requirements.
Information we collect
The information collected depends on your relationship with Grand Royale Group and the service, property, venue or digital platform you use.
We may collect names, titles, preferred names, postal addresses, email addresses, telephone numbers and emergency contact information.
- Account and profile details
- Communication preferences
- Identity verification details where required
- Authorised representative information
We may collect information needed to manage reservations, stays and guest services.
- Arrival and departure dates
- Room type and package selections
- Names of accompanying guests
- Accessibility and service requirements
- Guest preferences and special requests
- Feedback, complaints and service recovery records
- Vehicle details where parking is provided
We may collect dining reservations, event requirements and venue service information.
- Dining dates, times and party sizes
- Dietary and allergy information
- Function and conference requirements
- Guest lists and attendee information
- Room layouts, run sheets and schedules
- Supplier and event organiser details
- Photography preferences where relevant
We may collect transaction information needed to process charges, deposits, refunds and invoices.
- Billing and invoice details
- Payment status and transaction references
- Deposit and refund information
- Corporate account details
- Limited payment information supplied by payment providers
Payment card processing may be completed by authorised external payment providers.
We may collect information required to manage property enquiries, inspections, applications, sales and rental arrangements.
- Property preferences and enquiry history
- Inspection booking information
- Rental history and references
- Employment and income verification
- Identity and eligibility documentation
- Tenancy, ownership and settlement records
- Maintenance and property communication records
We may collect information needed to assess applicants and manage employment or contractor relationships.
- Résumés and employment history
- Qualifications and hospitality certifications
- References and interview records
- Work rights and identity checks
- Availability and role preferences
- Payroll, taxation and superannuation information
- Training, performance and development records
- Workplace health and safety records
Some employee records may be managed under separate workplace laws and internal policies.
We may collect information required to operate the Grand Royale Group hospitality simulation environment.
- Learner, trainer and assessor account details
- Education provider information
- Portal activity and access records
- Submitted simulation documents
- Learning progress and completion records
- Feedback and support communications
- Technical troubleshooting information
Our digital services may collect technical information needed for performance, security and service improvement.
- Internet Protocol address
- Browser and device information
- Pages viewed and links selected
- Access dates and session duration
- Login and security events
- Cookie and analytics identifiers
- Chatbot and support interaction records
Sensitive information may include health, accessibility, dietary, allergy, religious, biometric or criminal record information.
We collect sensitive information only where it is reasonably necessary, legally authorised or required, and where any required consent has been obtained.
Simulation environment
Users should not enter real guest, payment, health, identity or employment information into simulated documents unless an authorised training process specifically requires it.
How information is collected
We generally collect personal information directly from you. We may also receive information from authorised representatives, booking partners, employers, education providers and service providers.
Direct interactions
Bookings, enquiries, telephone calls, emails, registrations, applications, surveys and face to face service interactions.
Hospitality platforms
Travel agents, booking platforms, event organisers, payment processors and loyalty partners.
Business relationships
Suppliers, employers, referees, property representatives, professional advisers and education providers.
Digital channels
Websites, portals, chatbot tools, cookies, analytics, login systems and security monitoring.
Information about other people
When you provide information about another person, such as an accompanying guest, event attendee, referee or emergency contact, you should have authority to do so and make that person aware of this policy where practical.
Anonymous enquiries
You may contact us anonymously or use a pseudonym where this is practical. We may need your identity to confirm a booking, process payment, assess an application, provide secure account access or meet legal and safety responsibilities.
How information is used
We use personal information for purposes connected with our hospitality operations, property services, workforce, digital platforms and legal responsibilities.
Guest reservations
Confirming accommodation, arrivals, departures, room allocation and guest requests.
Food and beverage
Managing dining reservations, dietary requirements, functions, catering and customer service.
Meetings and events
Coordinating venues, attendees, accommodation, suppliers, schedules and event requirements.
Property services
Managing enquiries, inspections, applications, rentals, sales and property administration.
Recruitment and employment
Assessing candidates, engaging workers, administering payroll, training and workplace safety.
Learning simulations
Providing portal access, resources, support and authorised training activities.
Customer support
Responding to enquiries, feedback, complaints, requests and service recovery matters.
Safety and security
Protecting guests, workers, learners, premises, systems and business assets.
Business improvement
Reviewing service quality, website performance, operational results and customer experience.
Legal compliance
Maintaining records, managing claims and responding to lawful regulatory or government requests.
Disclosure and service providers
We may disclose personal information where reasonably required to deliver a service, operate the business, protect people or property, or comply with law.
Authorised hotel, restaurant, event, property, finance, technology, human resources, security and administration personnel.
Reservation platforms, payment processors, banks, travel agents and corporate booking partners.
Event suppliers, caterers, transport providers, maintenance contractors, cleaners and venue partners.
Property owners, agents, inspectors, tradespeople, valuers and settlement providers.
Website hosts, cloud platforms, software suppliers, communication providers and security services.
Registered training organisations, trainers, assessors, employers and authorised platform administrators.
Lawyers, accountants, auditors, insurers, regulators, emergency services, courts and law enforcement bodies.
Overseas service providers
Some cloud, booking, communication, analytics or technology providers may store or process information outside Australia. The countries involved depend on the provider and service configuration.
Where required, we take reasonable steps to assess relevant contractual, privacy and security arrangements before using an overseas provider.
Business changes
Information may be disclosed under appropriate controls as part of a proposed or completed restructure, acquisition, financing arrangement, management transfer or sale of business assets.
Website, cookies and marketing
Our website may use cookies and similar technologies to operate securely, remember preferences, understand website use and improve digital services.
Support security, forms, sessions, navigation and core website functions.
Remember interface choices, selected settings and accessibility preferences.
Help us understand website performance, visits and general interaction patterns.
Support chatbots, embedded media, maps and other enhanced website services.
Cookie controls
You may manage cookies through available website controls or your browser settings. Disabling cookies may affect forms, account access, media and other website functions.
Chatbot interactions
Chatbot messages may be processed to answer questions, locate resources, support website navigation, maintain service security and improve support quality.
Do not enter passwords, payment card details, government identifiers or private health information into a general website chatbot.
Marketing communications
We may send information about hospitality services, events, property opportunities, partnerships and resources where we have permission or another lawful basis.
Electronic marketing messages will include an unsubscribe option where required. Withdrawing from marketing does not prevent necessary booking, transaction, account or safety communications.
Security and retention
We use administrative, physical and technical measures appropriate to the information, the way it is held and the related security risks.
Access controls
Access is limited according to role and operational need.
Approved systems
Authorised systems support hosting, backup and monitoring.
Workforce controls
Workers have confidentiality and information handling duties.
Physical protection
Premises, devices and records use appropriate safeguards.
Record management
Records are classified, retained and securely disposed of.
Incident response
Suspected incidents are assessed, contained and escalated.
Retention and disposal
Personal information is retained for as long as reasonably required for service delivery, taxation, employment, safety, training, contractual, insurance, dispute management or legal purposes.
When information is no longer required, we take reasonable steps to destroy it securely or remove identifying details, subject to legal and system backup requirements.
CCTV and premises security
CCTV and electronic access systems may be used at selected premises for guest safety, worker safety, security, loss prevention and incident investigation. Appropriate signs may be displayed where surveillance operates.
Your privacy rights
Subject to applicable requirements and exceptions, you may request access to personal information held about you or ask us to correct information that is inaccurate, incomplete, outdated, irrelevant or misleading.
Submit your request
Explain the information or action you require.
Verify your identity
We may request identification before releasing information.
Receive a response
We will assess the request and respond within a reasonable period.
You may contact us to
- Request access to your personal information
- Request correction of inaccurate information
- Update your contact or account details
- Change marketing communication preferences
- Withdraw consent where consent applies
- Ask how specific information has been handled
- Authorise a representative to act for you
Access may be limited where providing information would unreasonably affect another person, create a serious safety risk, reveal protected material or be restricted by law.
Complaints and data breaches
Contact us if you believe personal information has been handled incorrectly or you are dissatisfied with our response to a privacy request.
Submit the concern
Explain the issue, relevant circumstances and requested outcome.
Internal assessment
We will review relevant information and consult suitable personnel.
Written response
We will explain our findings and available next steps.
Data breach response
A data breach may occur when personal information is lost or becomes subject to unauthorised access or disclosure.
Where applicable, we will notify affected individuals and the Office of the Australian Information Commissioner when an eligible data breach is likely to result in serious harm.
External complaint options
Where a privacy complaint cannot be resolved directly, you may be entitled to contact the Office of the Australian Information Commissioner or another relevant regulator.
Contact Grand Royale Group
Contact us to request access or correction, update your preferences, report a privacy concern or ask how your information is managed.
Use the subject line Privacy Request and include your name, contact details, relationship with Grand Royale Group and a clear description of your request.