Privacy Policy
Last updated: 14 August 2026
1. Scope and controller
Calvessianluxeretreat Pty Ltd ("Calvessianluxeretreat", "we", "us" or "our") is the operator responsible for the personal information described in this Privacy Policy. This policy explains how information is collected, used, disclosed, stored and protected when you use this website, make an enquiry, contact our guest services team or interact with our physical hospitality venue.
Our approach is intended to reflect applicable Australian privacy requirements, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. Where the General Data Protection Regulation (GDPR) applies to a particular individual or processing activity, we also address the relevant GDPR transparency and data-subject rights in this policy.
2. Information we may collect
We may collect information that you provide directly, including your name, email address, telephone number, enquiry subject, message content, accommodation or event preferences, accessibility requests that you choose to disclose, and correspondence with our staff.
When the website is hosted on a web server, standard technical records may also contain information such as IP address, browser type, device type, operating system, referring page, requested pages, timestamps and security-related log information. We do not use this static website to request payment-card information or account credentials.
3. How information is collected
Information may be collected when you submit the contact form, correspond with us, request information about accommodation or venue services, or otherwise provide information voluntarily. The contact form on this static website is configured to hand the message to your default email application rather than silently transmitting it to a third-party form processor.
We may also receive limited technical information automatically from the hosting environment for security, reliability and diagnostic purposes. If we introduce analytics, booking systems or other third-party integrations in the future, this policy and the Cookie Policy should be updated before those tools are activated.
4. Purposes and legal bases
We use personal information to answer enquiries, provide requested information, coordinate guest services, manage accommodation and event discussions, respond to accessibility requests, maintain website security, prevent misuse, keep appropriate business records and comply with legal obligations.
Where the GDPR applies, processing may be based on steps requested before entering a contract, performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the website and venue, or consent where consent is the appropriate basis. We do not rely on consent where another legal basis is more suitable.
5. Data minimisation and sensitive information
Please provide only the information reasonably necessary for your enquiry. Do not send payment-card details, passwords, government identifiers or unnecessary health information through the general contact form. If accessibility support requires sensitive information, provide only what is relevant and contact us first if you need a more appropriate communication channel.
6. Disclosure and service providers
Information may be accessed by authorised personnel who need it to respond to your request. We may also use service providers for website hosting, security, IT support, professional advice, communications or business administration. Such providers should receive only the information reasonably required for their function and are expected to protect it appropriately.
We may disclose information where required or authorised by law, to protect the rights or safety of guests or staff, to investigate fraud or misuse, or in connection with a legitimate business restructuring subject to applicable safeguards.
7. International transfers
Website hosting or service providers may process information in jurisdictions outside Australia. If the GDPR applies and personal data is transferred outside the European Economic Area, we will seek to use an available lawful transfer mechanism and appropriate safeguards where required. Australian cross-border disclosure obligations will also be considered where applicable.
8. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, to maintain legitimate business records, resolve disputes, enforce agreements or meet legal and regulatory obligations. Retention periods may differ depending on the type of enquiry and any resulting guest or event relationship. Information that is no longer required should be securely deleted or de-identified where appropriate.
9. Security
We use reasonable administrative and technical measures intended to protect personal information against loss, misuse, unauthorised access, alteration or disclosure. No website, email system or electronic transmission can be guaranteed to be completely secure, so users should avoid sending unnecessary sensitive information through ordinary email.
10. Your privacy rights
Depending on the law that applies to you, you may have rights to request access to personal information, correction of inaccurate information, deletion in certain circumstances, restriction of processing, objection to particular processing, data portability, withdrawal of consent, or information about how data is handled. Some rights are subject to legal exceptions and verification of identity.
You may also have the right to complain to a relevant privacy or data-protection authority. In Australia, privacy complaints may fall within the jurisdiction of the Office of the Australian Information Commissioner where the Privacy Act applies. Individuals covered by the GDPR may also be able to contact the competent supervisory authority in the country in which they live or work.
11. Children and age-restricted venue services
This website is directed to adults seeking information about a hotel and physical entertainment venue. We do not knowingly invite children to provide personal information through the general enquiry form. Access to age-restricted areas of the physical venue is governed by applicable law and venue procedures.
12. Direct marketing
We do not use a general service enquiry as permission to send unrelated marketing. If optional marketing communications are introduced, an appropriate opt-in or other lawful basis will be used where required, and recipients will be given a practical way to stop those communications.
13. Cookies and local technologies
Please read our Cookie Policy for information about browser storage and similar technologies. The current static site does not intentionally include third-party advertising or analytics trackers. This position should be reviewed if the technical implementation changes.
14. Changes to this policy
We may update this Privacy Policy when our services, technology or legal obligations change. The current version will be published on this page with a revised update date. Material changes should be communicated in an appropriate manner where required by law.
15. Administrator and contact
For privacy questions, access or correction requests, or complaints, contact the operator using the details below.
Operator: Calvessianluxeretreat Pty Ltd
Address: 100 Mitchell Street, Bendigo VIC 3550, Australia
Email: info@calvessianluxeretreat.com
Phone: +61 3 5550 4186