Privacy Policy

Last updated: June 2025

This Privacy Policy explains how MeedowLineGroup (“we”, “us”, or “our”) collects, uses, discloses, and protects the personal data of visitors and users of the website meedowlinegroup.com (the “Website”), as well as guests and customers who interact with our hotel-casino services. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection legislation.

Please read this Privacy Policy carefully. By using our Website or our services, you acknowledge that you have read and understood this policy. If you do not agree with its terms, please discontinue use of the Website and our services.

1. Data Controller

The entity responsible for processing your personal data (the “Data Controller”) is:

Company Name MeedowLineGroup
Registration Number HRB 122356 B
VAT Number DE 123456721
Registered Country Australia
Legal Address 350 Boundary Rd, Thornlands QLD 4164, Australia
Website meedowlinegroup.com
Privacy Contact Email info@meedowlinegroup.com

As the Data Controller, MeedowLineGroup determines the purposes and means by which your personal data is processed. We are accountable for ensuring that all processing activities comply with applicable data protection law, including the GDPR where it applies to individuals located in the European Economic Area (EEA).

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection law. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO directly:

Title The Data Protection Officer
Organisation MeedowLineGroup
Address 350 Boundary Rd, Thornlands QLD 4164, Australia
Email info@meedowlinegroup.com

3. Scope of This Privacy Policy

This Privacy Policy applies to:

  • All visitors to the Website meedowlinegroup.com;
  • Individuals who make reservations, enquiries, or bookings through our Website or by other means;
  • Guests who stay at or visit our hotel-casino facilities in Thornlands;
  • Participants in our loyalty programmes, promotions, or events;
  • Any person whose personal data we process in connection with providing our services.

This policy does not apply to third-party websites, services, or applications that may be linked to or from our Website. We encourage you to review the privacy policies of any third-party services you access via our Website.

4. Personal Data We Collect

We collect personal data that you provide directly to us, data generated through your use of our services, and data obtained from third parties. The categories of personal data we collect include, but are not limited to, the following:

4.1 Identity and Contact Data

  • Full name (first name, last name);
  • Date of birth and age verification data;
  • Gender;
  • Nationality and country of residence;
  • Passport, national identity card, or other government-issued identification details (where required by law or for age verification);
  • Postal address (home or billing address);
  • Email address;
  • Telephone and/or mobile number.

4.2 Booking and Reservation Data

  • Arrival and departure dates;
  • Room type and preferences;
  • Special requests (accessibility requirements, dietary preferences, etc.);
  • Number of guests;
  • Booking reference numbers;
  • History of previous stays and reservations.

4.3 Payment and Financial Data

  • Credit or debit card details (card number, expiry date, cardholder name — processed securely via PCI-DSS-compliant payment processors);
  • Bank account details where applicable;
  • Billing address;
  • Transaction records and payment history;
  • Invoices and receipts.

4.4 Casino and Gaming Data

  • Player account registration information;
  • Gaming activity, history, and transaction logs;
  • Responsible gambling self-exclusion or self-limitation requests;
  • Winning and loss records;
  • Compliance and Know Your Customer (KYC) verification documents, including proof of identity and proof of address;
  • Source of funds documentation where required by anti-money laundering (AML) regulations.

4.5 Usage and Technical Data

  • IP address;
  • Browser type and version;
  • Device type, model, and operating system;
  • Unique device identifiers;
  • Pages visited on our Website and time spent on each page;
  • Referring and exit URLs;
  • Date and time stamps of Website visits;
  • Clickstream data and interaction logs;
  • Cookie identifiers and similar tracking data (please see our Cookie Policy for further information).

4.6 Loyalty Programme and Marketing Data

  • Loyalty programme membership details and tier status;
  • Points balance and redemption history;
  • Marketing and communication preferences;
  • Survey responses and feedback;
  • Participation in competitions, promotions, or prize draws.

4.7 Communications Data

  • Content of correspondence and communications with us, including emails, chat messages, and telephone call records;
  • Complaints and feedback records.

4.8 Special Categories of Personal Data

In certain limited circumstances, we may collect and process special categories of personal data as defined under Article 9 GDPR. This may include:

  • Health or disability information provided voluntarily when requesting accessibility accommodations or special medical assistance;
  • Dietary requirements that may indicate religious beliefs or health conditions (processed only where provided voluntarily and necessary for the provision of services).

We process special category data only where you have given your explicit consent or where processing is necessary for reasons of vital interest, compliance with legal obligations, or other GDPR Article 9(2) grounds. We apply enhanced safeguards to all special category personal data.

4.9 Data Collected from Third Parties

We may receive personal data about you from the following third-party sources:

  • Online travel agencies and booking platforms (e.g., Booking.com, Expedia, Hotels.com);
  • Travel agents and tour operators;
  • Credit reference agencies and fraud prevention organisations;
  • Government and regulatory authorities (for compliance purposes);
  • Social media platforms, where you interact with our pages or log in using social credentials;
  • Business partners and affiliated companies.

6. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

6.1 Providing Hotel and Accommodation Services

  • Processing and managing your room reservations and cancellations;
  • Checking guests in and out of the property;
  • Handling special requests, accessibility accommodations, and preferences;
  • Processing payments and issuing invoices and receipts;
  • Providing concierge and customer support services;
  • Managing restaurant bookings, spa treatments, and other on-site amenity bookings.

6.2 Providing Casino and Gaming Services

  • Registering and managing your player account;
  • Verifying your identity and age in compliance with gaming regulations;
  • Processing gaming transactions and maintaining accurate gaming records;
  • Monitoring gaming activity for compliance, fraud prevention, and responsible gambling purposes;
  • Implementing self-exclusion, deposit limits, or other responsible gambling tools at your request or as required by law;
  • Detecting and preventing cheating, money laundering, and other illegal activity.

6.3 Legal and Regulatory Compliance

  • Conducting identity verification (KYC) and background checks as required by AML regulations;
  • Reporting to relevant authorities as required by law;
  • Maintaining records required under gaming, tax, and hospitality regulations;
  • Responding to court orders, legal proceedings, or regulatory investigations.

6.4 Marketing and Communications

  • Sending you promotional offers, newsletters, and personalised recommendations where you have provided consent or where permitted under applicable law;
  • Informing you about new services, special packages, events, and loyalty programme updates;
  • Conducting customer satisfaction surveys and feedback questionnaires;
  • Administering competitions, prize draws, and promotional events.

6.5 Website Operation and Improvement

  • Monitoring and analysing Website traffic, usage patterns, and visitor behaviour;
  • Improving the design, functionality, and content of our Website;
  • Detecting and preventing technical issues, security breaches, and fraudulent activity on our Website;
  • Personalising your browsing experience based on your preferences and history.

6.6 Security and Safety

  • Operating CCTV and security systems on our premises to ensure the safety of guests and staff;
  • Preventing, detecting, and investigating fraud, theft, cheating, and other unlawful behaviour;
  • Managing access control to restricted areas of the premises;
  • Protecting the information technology systems and networks of MeedowLineGroup.

6.7 Business Administration

  • Administering our loyalty and rewards programme;
  • Conducting internal audits, risk assessments, and management reporting;
  • Training staff and quality assurance processes;
  • Mergers, acquisitions, or restructuring of our business (subject to appropriate safeguards).

7. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. However, we may share your personal data with the following categories of recipients for the purposes described in this Privacy Policy:

7.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf under written data processing agreements in accordance with Article 28 GDPR. These include:

  • Cloud hosting and IT infrastructure providers;
  • Payment processing and fraud prevention providers;
  • Customer relationship management (CRM) platform providers;
  • Email marketing and communication service providers;
  • Website analytics and optimisation providers;
  • Booking and reservation management systems;
  • KYC and identity verification service providers;
  • Legal, audit, and professional services providers.

All processors are contractually bound to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.

7.2 Online Travel Agencies and Distribution Partners

Where your booking originates from a third-party platform such as an online travel agency, we may receive your booking details from them and share relevant data back with them for the purpose of managing and confirming your reservation.

7.3 Regulatory and Law Enforcement Authorities

We may disclose your personal data to competent public authorities, regulators, or law enforcement agencies where we are required or permitted to do so by applicable law, including:

  • Gaming and gambling regulatory authorities;
  • Tax and revenue authorities;
  • Financial intelligence units and AML/CTF authorities;
  • Police, courts, or other law enforcement bodies in response to a valid legal request.

7.4 Business Transfers

In the event of a merger, acquisition, sale of assets, or other corporate reorganisation involving MeedowLineGroup, your personal data may be transferred to the acquiring entity or successor business. We will notify you of any such transfer and ensure that your personal data continues to be protected in accordance with this Privacy Policy.

7.5 Affiliated Companies

We may share personal data with other entities within our corporate group for internal administrative and operational purposes, subject to appropriate internal data sharing agreements.

7.6 International Transfers

Some of our service providers and partners are located outside the European Economic Area (EEA) or Australia. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including:

  • Transfers to countries with an adequacy decision issued by the European Commission;
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules (BCRs) where applicable;
  • Other appropriate safeguards as permitted under applicable data protection law.

You may request a copy of the safeguards we have put in place for international transfers by contacting us at info@meedowlinegroup.com.

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting obligations, resolving disputes, and enforcing our agreements. The specific retention periods we apply are as follows:

Category of Data Retention Period Basis
Hotel booking and guest records 7 years from the date of stay Legal and tax obligations; contractual necessity
Payment and financial transaction records 7 years from the date of transaction Tax, accounting, and financial regulatory obligations
Casino player account data and gaming transaction records 7 years from account closure or last activity Gaming regulatory and AML/CTF legal obligations
KYC and identity verification documents 5–7 years from the end of the business relationship AML and KYC regulatory obligations
Marketing consent records Until consent is withdrawn, plus 3 years Evidence of consent; legitimate interests
Website analytics and technical data Up to 26 months Legitimate interests (Website improvement)
CCTV footage 30 days, unless retained for investigation purposes Security and legitimate interests
Customer communications and correspondence 3 years from the date of the last communication Legitimate interests; legal claims
Self-exclusion records (responsible gambling) Duration of self-exclusion plus 7 years Legal obligation under gaming regulations

At the end of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures. Where data must be retained for longer periods due to ongoing legal proceedings or regulatory investigations, we will retain it until the matter is resolved.

9. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your browsing experience, analyse Website traffic, and support our marketing activities. A cookie is a small text file stored on your device when you visit a website.

We use the following types of cookies:

  • Strictly Necessary Cookies: Essential for the Website to function properly, including session management and security. These cookies cannot be disabled.
  • Analytical/Performance Cookies: Used to collect information about how visitors use our Website, enabling us to improve its performance and content. These cookies require your consent.
  • Functional Cookies: Allow the Website to remember your preferences and settings to provide a more personalised experience. These cookies require your consent.
  • Marketing and Targeting Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns. These cookies require your consent.

When you first visit our Website, you will be shown a cookie consent banner through which you can manage your cookie preferences. You can change or withdraw your cookie consent at any time by adjusting the settings in your browser or by contacting us at info@meedowlinegroup.com.

For detailed information about the specific cookies we use, their purpose, duration, and the third parties involved, please refer to our full Cookie Policy, which is available on our Website.

10. Your Rights Under the GDPR

Subject to applicable data protection law, you have the following rights in relation to your personal data. We will respond to your request within one calendar month of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you.

10.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data (a “Subject Access Request”) along with information about how it is processed, including the purposes of processing, categories of data, recipients, retention periods, and the source of the data.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

10.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purpose for which it was collected;
  • You have withdrawn your consent and there is no other legal basis for processing;
  • You have objected to processing based on legitimate interests and there are no overriding legitimate grounds;
  • The personal data has been unlawfully processed;
  • Deletion is required to comply with a legal obligation.

Please note that the right to erasure is not absolute and may be overridden where processing is necessary for compliance with legal obligations, the exercise of legal claims, or other legally permitted purposes.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, object to processing, or where the processing is unlawful but you prefer restriction over erasure. Where processing is restricted, we will continue to store the data but will not process it further without your consent, except for limited purposes such as legal claims.

10.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another data controller where technically feasible.

10.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to processing of your personal data based on our legitimate interests (Article 6(1)(f) GDPR) or in the public interest (Article 6(1)(e) GDPR). Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.

You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. We will immediately cease processing your data for marketing purposes upon receipt of your objection.

10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. Where we carry out automated decision-making that significantly affects you, you have the right to request human review of the decision, to express your point of view, and to challenge the outcome.

10.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out before the withdrawal.

10.9 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to us by email at info@meedowlinegroup.com or by post to:

The Data Protection Officer
MeedowLineGroup
350 Boundary Rd, Thornlands QLD 4164, Australia

We may ask you to provide proof of identity to verify your request before proceeding. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which