Privacy Policy
Last updated: June 2025
This Privacy Policy explains how MeedowLineGroup (“we”, “us”, or “our”) collects, uses, discloses, and protects the personal data of visitors and users of the website meedowlinegroup.com (the “Website”), as well as guests and customers who interact with our hotel-casino services. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection legislation.
Please read this Privacy Policy carefully. By using our Website or our services, you acknowledge that you have read and understood this policy. If you do not agree with its terms, please discontinue use of the Website and our services.
1. Data Controller
The entity responsible for processing your personal data (the “Data Controller”) is:
| Company Name | MeedowLineGroup |
|---|---|
| Registration Number | HRB 122356 B |
| VAT Number | DE 123456721 |
| Registered Country | Australia |
| Legal Address | 350 Boundary Rd, Thornlands QLD 4164, Australia |
| Website | meedowlinegroup.com |
| Privacy Contact Email | info@meedowlinegroup.com |
As the Data Controller, MeedowLineGroup determines the purposes and means by which your personal data is processed. We are accountable for ensuring that all processing activities comply with applicable data protection law, including the GDPR where it applies to individuals located in the European Economic Area (EEA).
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection law. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO directly:
| Title | The Data Protection Officer |
|---|---|
| Organisation | MeedowLineGroup |
| Address | 350 Boundary Rd, Thornlands QLD 4164, Australia |
| info@meedowlinegroup.com |
3. Scope of This Privacy Policy
This Privacy Policy applies to:
- All visitors to the Website meedowlinegroup.com;
- Individuals who make reservations, enquiries, or bookings through our Website or by other means;
- Guests who stay at or visit our hotel-casino facilities in Thornlands;
- Participants in our loyalty programmes, promotions, or events;
- Any person whose personal data we process in connection with providing our services.
This policy does not apply to third-party websites, services, or applications that may be linked to or from our Website. We encourage you to review the privacy policies of any third-party services you access via our Website.
4. Personal Data We Collect
We collect personal data that you provide directly to us, data generated through your use of our services, and data obtained from third parties. The categories of personal data we collect include, but are not limited to, the following:
4.1 Identity and Contact Data
- Full name (first name, last name);
- Date of birth and age verification data;
- Gender;
- Nationality and country of residence;
- Passport, national identity card, or other government-issued identification details (where required by law or for age verification);
- Postal address (home or billing address);
- Email address;
- Telephone and/or mobile number.
4.2 Booking and Reservation Data
- Arrival and departure dates;
- Room type and preferences;
- Special requests (accessibility requirements, dietary preferences, etc.);
- Number of guests;
- Booking reference numbers;
- History of previous stays and reservations.
4.3 Payment and Financial Data
- Credit or debit card details (card number, expiry date, cardholder name — processed securely via PCI-DSS-compliant payment processors);
- Bank account details where applicable;
- Billing address;
- Transaction records and payment history;
- Invoices and receipts.
4.4 Casino and Gaming Data
- Player account registration information;
- Gaming activity, history, and transaction logs;
- Responsible gambling self-exclusion or self-limitation requests;
- Winning and loss records;
- Compliance and Know Your Customer (KYC) verification documents, including proof of identity and proof of address;
- Source of funds documentation where required by anti-money laundering (AML) regulations.
4.5 Usage and Technical Data
- IP address;
- Browser type and version;
- Device type, model, and operating system;
- Unique device identifiers;
- Pages visited on our Website and time spent on each page;
- Referring and exit URLs;
- Date and time stamps of Website visits;
- Clickstream data and interaction logs;
- Cookie identifiers and similar tracking data (please see our Cookie Policy for further information).
4.6 Loyalty Programme and Marketing Data
- Loyalty programme membership details and tier status;
- Points balance and redemption history;
- Marketing and communication preferences;
- Survey responses and feedback;
- Participation in competitions, promotions, or prize draws.
4.7 Communications Data
- Content of correspondence and communications with us, including emails, chat messages, and telephone call records;
- Complaints and feedback records.
4.8 Special Categories of Personal Data
In certain limited circumstances, we may collect and process special categories of personal data as defined under Article 9 GDPR. This may include:
- Health or disability information provided voluntarily when requesting accessibility accommodations or special medical assistance;
- Dietary requirements that may indicate religious beliefs or health conditions (processed only where provided voluntarily and necessary for the provision of services).
We process special category data only where you have given your explicit consent or where processing is necessary for reasons of vital interest, compliance with legal obligations, or other GDPR Article 9(2) grounds. We apply enhanced safeguards to all special category personal data.
4.9 Data Collected from Third Parties
We may receive personal data about you from the following third-party sources:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia, Hotels.com);
- Travel agents and tour operators;
- Credit reference agencies and fraud prevention organisations;
- Government and regulatory authorities (for compliance purposes);
- Social media platforms, where you interact with our pages or log in using social credentials;
- Business partners and affiliated companies.
5. Legal Basis for Processing Personal Data
We process your personal data only when we have a valid legal basis for doing so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary to enter into or perform a contract with you. This includes processing your booking details, identity information, and payment data in order to complete a hotel reservation, provide gaming services, or fulfil any other agreement between us and you. Without this processing, we would be unable to provide the services you have requested.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary to comply with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations;
- Know Your Customer (KYC) verification requirements;
- Responsible gambling obligations, including age verification and self-exclusion registers;
- Tax and accounting obligations;
- Obligations to cooperate with law enforcement, regulatory, or judicial authorities;
- Health and safety obligations.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for the purposes of legitimate interests pursued by us or a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Improving and personalising our Website and services;
- Preventing fraud, cheating, and other criminal activity;
- Ensuring network and information security;
- Operating and administering our loyalty and rewards programmes;
- Conducting market research and business analytics;
- Communicating with you about relevant service updates and changes;
- Managing and defending legal claims;
- Ensuring the safety and security of guests, staff, and premises (including CCTV monitoring).
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your rights. You have the right to object to processing based on legitimate interests at any time (see Section 10).
5.4 Consent (Article 6(1)(a) GDPR)
Where required by law, we will ask for your explicit and informed consent before processing your personal data. We rely on consent for:
- Sending you direct marketing communications, including newsletters, promotional offers, and personalised recommendations by email, SMS, or push notification;
- Placing non-essential cookies and similar tracking technologies on your device (see our Cookie Policy);
- Processing special categories of personal data in limited circumstances;
- Any other processing activities for which we specifically request your consent.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@meedowlinegroup.com or use the unsubscribe link in any marketing email.
5.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another individual. This may arise in emergency situations such as a medical emergency on our premises.
5.6 Public Task (Article 6(1)(e) GDPR)
Where applicable, we may process personal data in the exercise of official authority vested in us or in connection with a task carried out in the public interest, such as cooperation with regulatory or supervisory bodies in the gambling and hospitality sector.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Providing Hotel and Accommodation Services
- Processing and managing your room reservations and cancellations;
- Checking guests in and out of the property;
- Handling special requests, accessibility accommodations, and preferences;
- Processing payments and issuing invoices and receipts;
- Providing concierge and customer support services;
- Managing restaurant bookings, spa treatments, and other on-site amenity bookings.
6.2 Providing Casino and Gaming Services
- Registering and managing your player account;
- Verifying your identity and age in compliance with gaming regulations;
- Processing gaming transactions and maintaining accurate gaming records;
- Monitoring gaming activity for compliance, fraud prevention, and responsible gambling purposes;
- Implementing self-exclusion, deposit limits, or other responsible gambling tools at your request or as required by law;
- Detecting and preventing cheating, money laundering, and other illegal activity.
6.3 Legal and Regulatory Compliance
- Conducting identity verification (KYC) and background checks as required by AML regulations;
- Reporting to relevant authorities as required by law;
- Maintaining records required under gaming, tax, and hospitality regulations;
- Responding to court orders, legal proceedings, or regulatory investigations.
6.4 Marketing and Communications
- Sending you promotional offers, newsletters, and personalised recommendations where you have provided consent or where permitted under applicable law;
- Informing you about new services, special packages, events, and loyalty programme updates;
- Conducting customer satisfaction surveys and feedback questionnaires;
- Administering competitions, prize draws, and promotional events.
6.5 Website Operation and Improvement
- Monitoring and analysing Website traffic, usage patterns, and visitor behaviour;
- Improving the design, functionality, and content of our Website;
- Detecting and preventing technical issues, security breaches, and fraudulent activity on our Website;
- Personalising your browsing experience based on your preferences and history.
6.6 Security and Safety
- Operating CCTV and security systems on our premises to ensure the safety of guests and staff;
- Preventing, detecting, and investigating fraud, theft, cheating, and other unlawful behaviour;
- Managing access control to restricted areas of the premises;
- Protecting the information technology systems and networks of MeedowLineGroup.
6.7 Business Administration
- Administering our loyalty and rewards programme;
- Conducting internal audits, risk assessments, and management reporting;
- Training staff and quality assurance processes;
- Mergers, acquisitions, or restructuring of our business (subject to appropriate safeguards).
7. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. However, we may share your personal data with the following categories of recipients for the purposes described in this Privacy Policy:
7.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf under written data processing agreements in accordance with Article 28 GDPR. These include:
- Cloud hosting and IT infrastructure providers;
- Payment processing and fraud prevention providers;
- Customer relationship management (CRM) platform providers;
- Email marketing and communication service providers;
- Website analytics and optimisation providers;
- Booking and reservation management systems;
- KYC and identity verification service providers;
- Legal, audit, and professional services providers.
All processors are contractually bound to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.
7.2 Online Travel Agencies and Distribution Partners
Where your booking originates from a third-party platform such as an online travel agency, we may receive your booking details from them and share relevant data back with them for the purpose of managing and confirming your reservation.
7.3 Regulatory and Law Enforcement Authorities
We may disclose your personal data to competent public authorities, regulators, or law enforcement agencies where we are required or permitted to do so by applicable law, including:
- Gaming and gambling regulatory authorities;
- Tax and revenue authorities;
- Financial intelligence units and AML/CTF authorities;
- Police, courts, or other law enforcement bodies in response to a valid legal request.
7.4 Business Transfers
In the event of a merger, acquisition, sale of assets, or other corporate reorganisation involving MeedowLineGroup, your personal data may be transferred to the acquiring entity or successor business. We will notify you of any such transfer and ensure that your personal data continues to be protected in accordance with this Privacy Policy.
7.5 Affiliated Companies
We may share personal data with other entities within our corporate group for internal administrative and operational purposes, subject to appropriate internal data sharing agreements.
7.6 International Transfers
Some of our service providers and partners are located outside the European Economic Area (EEA) or Australia. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including:
- Transfers to countries with an adequacy decision issued by the European Commission;
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Other appropriate safeguards as permitted under applicable data protection law.
You may request a copy of the safeguards we have put in place for international transfers by contacting us at info@meedowlinegroup.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting obligations, resolving disputes, and enforcing our agreements. The specific retention periods we apply are as follows:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Hotel booking and guest records | 7 years from the date of stay | Legal and tax obligations; contractual necessity |
| Payment and financial transaction records | 7 years from the date of transaction | Tax, accounting, and financial regulatory obligations |
| Casino player account data and gaming transaction records | 7 years from account closure or last activity | Gaming regulatory and AML/CTF legal obligations |
| KYC and identity verification documents | 5–7 years from the end of the business relationship | AML and KYC regulatory obligations |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Evidence of consent; legitimate interests |
| Website analytics and technical data | Up to 26 months | Legitimate interests (Website improvement) |
| CCTV footage | 30 days, unless retained for investigation purposes | Security and legitimate interests |
| Customer communications and correspondence | 3 years from the date of the last communication | Legitimate interests; legal claims |
| Self-exclusion records (responsible gambling) | Duration of self-exclusion plus 7 years | Legal obligation under gaming regulations |
At the end of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures. Where data must be retained for longer periods due to ongoing legal proceedings or regulatory investigations, we will retain it until the matter is resolved.
10. Your Rights Under the GDPR
Subject to applicable data protection law, you have the following rights in relation to your personal data. We will respond to your request within one calendar month of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data (a “Subject Access Request”) along with information about how it is processed, including the purposes of processing, categories of data, recipients, retention periods, and the source of the data.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
10.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose for which it was collected;
- You have withdrawn your consent and there is no other legal basis for processing;
- You have objected to processing based on legitimate interests and there are no overriding legitimate grounds;
- The personal data has been unlawfully processed;
- Deletion is required to comply with a legal obligation.
Please note that the right to erasure is not absolute and may be overridden where processing is necessary for compliance with legal obligations, the exercise of legal claims, or other legally permitted purposes.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, object to processing, or where the processing is unlawful but you prefer restriction over erasure. Where processing is restricted, we will continue to store the data but will not process it further without your consent, except for limited purposes such as legal claims.
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another data controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to processing of your personal data based on our legitimate interests (Article 6(1)(f) GDPR) or in the public interest (Article 6(1)(e) GDPR). Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. We will immediately cease processing your data for marketing purposes upon receipt of your objection.
10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. Where we carry out automated decision-making that significantly affects you, you have the right to request human review of the decision, to express your point of view, and to challenge the outcome.
10.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out before the withdrawal.
10.9 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to us by email at info@meedowlinegroup.com or by post to:
The Data Protection Officer
MeedowLineGroup
350 Boundary Rd, Thornlands QLD 4164, Australia
We may ask you to provide proof of identity to verify your request before proceeding. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which