Banksia Boutique · Policies

Privacy Policy

How Banksia Boutique Resort Pty Ltd collects, uses, stores and protects your personal information — across bookings, stays, casino visits and this website.

Last updated: 1 September 2026

Information We Collect

We collect personal information you provide directly — name, contact details, identification where required, reservation and stay preferences, payment details (processed by our PCI-DSS compliant payment provider, not stored by us), loyalty and play activity on the gaming floor, and dietary or accessibility requirements you share with us.

When you use this website we collect technical data automatically: IP address, device and browser type, pages visited and cookie identifiers as described in our Cookie Policy.


How We Use Your Information

We use personal information to operate your reservation and stay: confirming bookings, processing payment, providing concierge and gaming services, meeting safety and licensing obligations, and personalising your experience (with your preferences loaded before arrival where you ask us to).

With your consent we send seasonal offers and the Banksia Letter; every marketing message carries a working unsubscribe. We do not sell personal information to third parties.


Lawful Bases for Processing

Where the GDPR applies (guests in the EU/UK), we process under: contract (fulfilling your reservation), consent (marketing, optional preferences), legitimate interest (safety, fraud prevention, service improvement) and legal obligation (Northern Territory gaming and taxation records).

For Australian guests the Privacy Act 1988 (Cth) and the Australian Privacy Principles govern our handling in the same spirit.


Sharing & Processors

We share personal information only where needed to deliver your stay: our booking-engine and payment processors, chauffeur and tour operators you book through the desk, cloud hosting providers under contract, and regulators or law enforcement where the law requires (including NT gaming authorities).

Each processor is bound by contract to protect your data and use it only for the service provided.


Data Retention

Reservation and folio records are kept for seven years to meet Australian taxation and licensing requirements. Marketing consent records persist until you unsubscribe. Technical website logs rotate within 90 days.

When retention ends, records are securely destroyed or de-identified.


Your Rights

You may request access to, or correction of, your personal information at any time. EU/UK guests additionally hold GDPR rights: erasure, restriction, portability, objection and the right to withdraw consent or lodge a complaint with a supervisory authority.

Requests are answered within 30 days — write to us at the address below, marked Attention: Privacy Officer. Australian guests may also contact the Office of the Australian Information Commissioner (OAIC).


Security & International Transfers

We protect personal information with encryption in transit, role-based access, audited systems and staff privacy training. Some processors are located overseas (including the EU and Singapore); transfers occur only under contractual safeguards consistent with GDPR-standard protections.

Questions about this policy: email [email protected] or call +61 8 8943 8888.

Talk to Us

Questions about this policy?

Our team answers policy and data questions personally — usually within one business day.

Common Questions

Quick answers

No. We never sell personal information. Data is shared only with contracted processors needed to deliver your stay, or where the law requires.
Email [email protected] marked 'Attention: Privacy Officer'. Access, correction and deletion requests are answered within 30 days.