Banksia Boutique · Policies
Privacy Policy
How Banksia Boutique Resort Pty Ltd collects, uses, stores and protects your personal information — across bookings, stays, casino visits and this website.
Information We Collect
We collect personal information you provide directly — name, contact details, identification where required, reservation and stay preferences, payment details (processed by our PCI-DSS compliant payment provider, not stored by us), loyalty and play activity on the gaming floor, and dietary or accessibility requirements you share with us.
When you use this website we collect technical data automatically: IP address, device and browser type, pages visited and cookie identifiers as described in our Cookie Policy.
How We Use Your Information
We use personal information to operate your reservation and stay: confirming bookings, processing payment, providing concierge and gaming services, meeting safety and licensing obligations, and personalising your experience (with your preferences loaded before arrival where you ask us to).
With your consent we send seasonal offers and the Banksia Letter; every marketing message carries a working unsubscribe. We do not sell personal information to third parties.
Lawful Bases for Processing
Where the GDPR applies (guests in the EU/UK), we process under: contract (fulfilling your reservation), consent (marketing, optional preferences), legitimate interest (safety, fraud prevention, service improvement) and legal obligation (Northern Territory gaming and taxation records).
For Australian guests the Privacy Act 1988 (Cth) and the Australian Privacy Principles govern our handling in the same spirit.
Sharing & Processors
We share personal information only where needed to deliver your stay: our booking-engine and payment processors, chauffeur and tour operators you book through the desk, cloud hosting providers under contract, and regulators or law enforcement where the law requires (including NT gaming authorities).
Each processor is bound by contract to protect your data and use it only for the service provided.
Data Retention
Reservation and folio records are kept for seven years to meet Australian taxation and licensing requirements. Marketing consent records persist until you unsubscribe. Technical website logs rotate within 90 days.
When retention ends, records are securely destroyed or de-identified.
Your Rights
You may request access to, or correction of, your personal information at any time. EU/UK guests additionally hold GDPR rights: erasure, restriction, portability, objection and the right to withdraw consent or lodge a complaint with a supervisory authority.
Requests are answered within 30 days — write to us at the address below, marked Attention: Privacy Officer. Australian guests may also contact the Office of the Australian Information Commissioner (OAIC).
Security & International Transfers
We protect personal information with encryption in transit, role-based access, audited systems and staff privacy training. Some processors are located overseas (including the EU and Singapore); transfers occur only under contractual safeguards consistent with GDPR-standard protections.
Questions about this policy: email [email protected] or call +61 8 8943 8888.
Talk to Us
Questions about this policy?
Our team answers policy and data questions personally — usually within one business day.
Common Questions