Privacy Policy

Effective date: 21 July 2026 · Website: towardriveragency.com

1. Scope and status of this policy

This Privacy Policy explains how Towardriveragency Pty Ltd (we, us or our) handles personal information in connection with towardriveragency.com, enquiries, accommodation and venue-related communications, customer service, events, promotions, responsible gaming interactions and other services described on the website. It is intended to be read together with our Terms & Conditions and Cookie Policy.

We are based in Australia. We seek to handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. Where we offer services to, monitor, or otherwise process personal data of individuals in the European Economic Area, the United Kingdom or another jurisdiction with equivalent privacy rules, we also apply the relevant requirements of the General Data Protection Regulation or local implementing law to the extent required.

2. Administrator and contact details

Towardriveragency Pty Ltd is the organisation responsible for the personal information described in this policy. Our principal contact address is 88 Southbank Boulevard, Southbank VIC 3006, Australia. Privacy enquiries, access requests, correction requests and complaints may be sent to info@towardriveragency.com or by post to the address shown above.

If the GDPR applies to a particular processing activity, we act as the data controller unless another party is identified at the point of collection. Our contact channel is available for questions about legal bases, safeguards, overseas disclosures and the exercise of data-subject rights.

3. Information we may collect

We may collect identity and contact details such as your name, email address, telephone number, postal address, preferred contact method and any information you include in an enquiry. If you request accommodation, event, accessibility or guest services, we may collect booking preferences, arrival information, room requirements, accessibility needs and details necessary to respond to the request.

Where legally permitted and operationally necessary, venue interactions may involve age-verification information, identification checks, responsible gaming communications, incident records, security information and exclusion or self-exclusion information. We do not request that you send sensitive identity documents through the general website contact form. Any enhanced verification process should be completed only through an authorised secure channel.

When you use the website, our hosting environment may automatically receive technical information such as IP address, browser type, device type, operating system, referring page, requested URL, date and time of access, and security or diagnostic logs. The current website is designed to operate without advertising trackers or third-party analytics cookies.

4. How information is collected

We generally collect information directly from you when you submit a form, call or email us, request information, communicate with staff, make a venue-related request, participate in a promotion or otherwise interact with us. We may also receive information from authorised representatives, booking or event partners, payment or identity-verification providers, security contractors, regulators or public sources where lawful and reasonably necessary.

If you provide information about another person, you must have authority to do so and should ensure that the person is aware of this policy. We may ask you to confirm that authority before acting on the information.

5. Purposes of processing

We use personal information to answer enquiries; provide information about accommodation, gaming, entertainment and guest services; administer reservations or event requests; maintain safety and security; verify age where required; support responsible gaming obligations; manage customer relationships; resolve complaints; prevent fraud and misuse; maintain business and accounting records; comply with law, court orders and regulatory requirements; and protect our legal rights.

We may use contact details to send service messages that are necessary to respond to a request. Promotional electronic messages are sent only where permitted by applicable law and with an available unsubscribe mechanism. You may opt out of marketing communications at any time without affecting essential service communications.

6. Legal bases under the GDPR

Where the GDPR applies, processing may be based on one or more of the following grounds: taking steps at your request before entering into a contract; performing a contract; complying with a legal obligation; protecting vital interests; carrying out a task in the public interest where applicable; pursuing legitimate interests that are not overridden by your rights; or your consent.

Our legitimate interests may include responding to enquiries, operating and securing the website, preventing fraud, protecting guests and staff, improving service quality, maintaining records and defending legal claims. Where consent is the legal basis, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

7. Australian Privacy Principles considerations

Where the Australian Privacy Principles apply, we take reasonable steps to manage personal information openly and transparently, collect information by lawful and fair means, explain collection where required, use or disclose information for the primary purpose of collection or a permitted secondary purpose, maintain appropriate security, and provide access and correction mechanisms subject to lawful exceptions.

You may deal with us anonymously or by pseudonym where lawful and practicable. This may not be possible where we must verify identity or age, complete a transaction, meet security obligations, comply with venue rules or respond to a request that cannot reasonably be fulfilled without identifying information.

8. Sensitive information and responsible gaming information

Sensitive information is collected only where legally permitted and reasonably necessary, normally with consent or under another applicable exception. Information relating to health, accessibility, exclusion, self-exclusion, identity verification or incidents may require enhanced protection and restricted access.

Responsible gaming information is handled for safety, support, compliance and record-keeping purposes. It is not used to encourage gambling activity. Access is limited to personnel and service providers who need the information for authorised duties.

9. Children and age restrictions

The website is not intended to facilitate gambling by anyone under 18. Persons under 18 are not permitted to enter gambling areas or participate in gambling activities. We do not knowingly collect personal information from a child for gambling purposes. If we become aware that such information has been submitted, we will take reasonable steps to delete or appropriately restrict it, subject to legal and safeguarding obligations.

General accommodation or family-related enquiries may involve information about minors where relevant to a lawful hotel request, but such information should be provided by a parent, guardian or authorised adult and limited to what is necessary.

10. Disclosure to service providers and other recipients

We may disclose personal information to hosting and IT providers, communications providers, professional advisers, insurers, auditors, booking or event service providers, security contractors, identity-verification providers, payment processors, related entities, regulators, law-enforcement bodies, courts and other recipients where disclosure is authorised or required.

Service providers are expected to use information only for the agreed purpose, maintain appropriate confidentiality and security, and comply with applicable privacy obligations. We do not sell personal information.

11. Overseas disclosures and international transfers

Some service providers or recipients may operate outside Australia. Before an overseas disclosure, we take reasonable steps required by applicable law and consider contractual, technical and organisational safeguards. Countries involved may vary according to the service provider used at the relevant time.

Where the GDPR applies to an international transfer, we rely on a recognised transfer mechanism where required, such as an adequacy decision, standard contractual clauses, binding corporate rules or a permitted derogation. You may contact us for further information about safeguards relevant to your data.

12. Data retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to meet legal, regulatory, taxation, accounting, insurance, security, responsible gaming and dispute-resolution obligations, or to establish, exercise or defend legal claims.

Retention periods differ by record type. Enquiry data may be retained for a limited customer-service period; contractual and financial records may be retained for statutory periods; security and incident records may be retained according to risk and regulatory requirements. When information is no longer required, we take reasonable steps to delete, destroy or de-identify it.

13. Security

We use reasonable technical and organisational measures designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Measures may include access controls, least-privilege permissions, secure configuration, backups, logging, staff training, provider due diligence and incident-response procedures.

No internet transmission or storage system is completely secure. You should not send payment-card data, government identifiers, passwords or identity documents through the general contact form. If you believe information has been compromised, contact us promptly.

14. Data breaches

We assess suspected privacy incidents and take containment, investigation and remediation steps. Where the Notifiable Data Breaches scheme or another mandatory notification regime applies, we will notify affected individuals and the relevant regulator when the legal threshold is met.

Notifications may describe the nature of the incident, the information involved, recommended protective steps and our response. We may also cooperate with law enforcement, cyber-security specialists, insurers and service providers.

15. Access and correction

You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding. We will respond within the period required by applicable law and explain any lawful refusal.

Access may be limited where disclosure would unreasonably affect another person, reveal commercially sensitive evaluative information, prejudice an investigation, conflict with legal privilege or fall within another statutory exception. Where appropriate, we will discuss an alternative form of access.

16. Additional GDPR rights

Where the GDPR applies, you may have rights to erasure, restriction, objection, data portability and withdrawal of consent, as well as the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to legal conditions and exceptions.

You may also lodge a complaint with the supervisory authority in the country where you live, work or believe an infringement occurred. We encourage you to contact us first so that we can investigate and attempt to resolve the concern.

17. Direct marketing

We may send marketing only where permitted by the Privacy Act, Spam Act 2003 (Cth), GDPR or other applicable rules. Each electronic marketing message will identify the sender and provide a functional unsubscribe method. We will action opt-out requests within the legally required period.

Opting out of marketing does not prevent us from sending non-promotional messages concerning an active request, safety issue, legal notice, booking or service communication.

18. Cookies and local technologies

The website may use strictly necessary browser storage or similar technologies to provide core functionality and security. It is not currently configured to deploy third-party advertising or behavioural analytics cookies. More information is provided in our Cookie Policy.

If non-essential analytics, personalisation or advertising technologies are introduced, we will update the Cookie Policy and implement any consent controls required by applicable law before using them.

19. Links to third-party sites

The website may link to third-party websites or services. We do not control their privacy practices, security or content. You should review the privacy information supplied by the relevant third party before providing personal information.

20. Complaints

You may complain about our handling of personal information by contacting us using the details in section 2. Please describe the issue and the outcome you seek. We will acknowledge and investigate the complaint, request further information if needed and provide a response within a reasonable time.

If you are not satisfied and Australian privacy law applies, you may be able to contact the Office of the Australian Information Commissioner. If the GDPR applies, you may contact the competent data-protection authority.

21. Changes to this policy

We may update this Privacy Policy to reflect changes in law, technology, services or business practices. The updated version will be published on this page with a revised effective date. Material changes may be communicated through an additional notice where appropriate.