Privacy Policy
How we handle personal information for website, casino hotel and guest service enquiries.
1. Scope and purpose
This Privacy Policy explains how Harborbrookstudio Pty Ltd collects, uses, stores, discloses and protects personal information when you use this website, submit an enquiry, request casino hotel information or communicate with our team. It is intended to support transparent handling under the Australian Privacy Act 1988 and the Australian Privacy Principles, and to address the General Data Protection Regulation where that regulation applies to a person located in the European Economic Area or the United Kingdom.
This policy applies to website visitors, prospective guests, event organisers, contractors and other people who contact us. It does not create rights beyond those provided by applicable law.
2. Administrator and contact
The organisation responsible for the personal information described in this policy is the entity shown below. The company name and address are loaded from the local adress.json file so they can be updated consistently across the site.
Harborbrookstudio Pty LtdLevel 5, 123 Eagle Street, Brisbane QLD 4000, Australia
Privacy contact: info@harborbrookstudio.com
3. Information we may collect
We may collect identity and contact details such as your name, email address, telephone number, preferred visit date, enquiry category and the information you include in a message. When you communicate with us, we may retain correspondence and records necessary to respond, manage a request, resolve a complaint or protect legal interests.
Technical information may include browser type, device category, operating system, approximate region, pages viewed, referring page, date and time of access, consent selections and basic security logs. This static project does not include external analytics by default.
4. How information is collected
Information may be collected directly when you complete a form, contact our team, provide feedback or request information about accommodation, casino access, dining, accessibility or events. Limited technical information may be generated automatically by the browser or hosting environment.
We ask that you do not submit sensitive information unless it is reasonably necessary for your request. If accessibility or dietary information is provided, we use it only to assist with the relevant request and apply additional care appropriate to its sensitivity.
5. Purposes and legal bases
We use personal information to respond to enquiries, provide requested information, coordinate accommodation or event discussions, support casino access questions, improve service quality, maintain website security, keep business records, meet legal obligations and establish or defend legal claims.
Where GDPR applies, processing may rely on consent, steps requested before entering a contract, performance of a contract, compliance with a legal obligation, protection of vital interests or legitimate interests such as responding to enquiries, preventing misuse and improving services. We balance legitimate interests against individual rights and expectations.
6. Disclosure and service providers
We may share information with personnel who need it to perform their duties and with carefully selected service providers supporting hosting, communications, security, professional advice, booking administration or event coordination. Providers are expected to use information only for the agreed purpose and to protect it appropriately.
We may also disclose information when required by law, regulatory process, court order, law enforcement request or when reasonably necessary to protect a person, property, safety or legal rights. We do not sell personal information.
7. Overseas transfers
Some service providers may process information outside Australia. Where a transfer occurs, we take reasonable steps to assess the recipient, apply contractual protections and comply with applicable cross-border disclosure requirements. Where GDPR applies, an international transfer may use an adequacy decision, standard contractual clauses or another lawful safeguard.
8. Storage and retention
We retain personal information only for as long as reasonably necessary for the purpose collected, including responding to a request, maintaining appropriate records, resolving disputes and meeting tax, accounting, insurance or legal requirements. Retention periods vary according to the type of record and applicable obligations.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to backup cycles, legal holds and technical limitations.
9. Security
We use reasonable administrative, technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access controls, role restrictions, secure configuration, updates, backups, logging and staff procedures.
No internet transmission or storage method is completely secure. You should avoid sending unnecessary confidential information through an open website form.
10. Cookies and local storage
This website uses essential local storage to remember your cookie preference. Optional preference or analytics categories remain disabled unless selected through the cookie controls and would require additional implementation before use.
More detail is provided in the Cookie Policy. You can clear stored preferences through your browser and reopen the banner by clearing site data.
11. Individual rights
Depending on applicable law, you may request access to personal information, correction of inaccurate information, deletion, restriction, objection, portability or withdrawal of consent. GDPR rights are not absolute and may be limited by legal obligations, contractual necessity, overriding legitimate grounds or the rights of others.
Australian residents may request access or correction under applicable privacy law. We may need to verify identity before acting and may ask for enough information to locate the relevant records.
12. Complaints
Contact info@harborbrookstudio.com with the subject “Privacy Request” and describe the issue. We will acknowledge and assess the matter within a reasonable period. If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner or, where GDPR applies, the competent European supervisory authority.
13. Children and age restrictions
The website is intended for adults. Casino participation is restricted to people aged 18 and over. We do not knowingly seek personal information from children for casino-related purposes. If information about a child is submitted in error, contact us so it can be assessed and removed where appropriate.
14. Automated decisions and marketing
This static website does not make decisions producing legal or similarly significant effects solely through automated processing. We do not send direct marketing without an appropriate legal basis, and any future marketing message must provide a practical method to opt out.
15. Changes to this policy
We may update this policy to reflect legal, operational or technical changes. The current version is published on this page. Material changes should be communicated in a proportionate manner. Last updated: 22 July 2026.