Privacy Policy

Last updated: June 2025

At Greenridgeadventures, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our website at greenridgeadventures.com, make a booking, or otherwise interact with us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable privacy laws.

Please read this policy carefully. By using our website or services, you acknowledge that you have read and understood the practices described herein.

1. Data Controller

The entity responsible for your personal data (the "Data Controller") is:

Trading Name Greenridgeadventures
Legal Entity Greenridgeadventures Pty Ltd
Registration Number ACN 739 284 516
VAT / Tax Number ABN 42 739 284 516
Registered Address 1 Eastern Beach Rd, Geelong VIC 3220, Australia
Country of Registration Australia
Website greenridgeadventures.com
Privacy Contact Email privacy@greenridgeadventures.com

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection legislation. You may contact our DPO at any time regarding matters relating to your personal data:

DPO Name The Data Protection Officer
Organisation Greenridgeadventures Pty Ltd
Address 1 Eastern Beach Rd, Geelong VIC 3220, Australia
Email privacy@greenridgeadventures.com

2. Personal Data We Collect

We collect personal data that you provide to us directly, that is generated automatically when you use our website, or that we receive from third parties. The categories of personal data we collect include:

2.1 Data You Provide Directly

  • Identity Data: Full name, title, date of birth, nationality, and passport or government-issued identification details (where required for registration purposes).
  • Contact Data: Email address, telephone number, postal address, and city of residence.
  • Booking and Reservation Data: Check-in and check-out dates, room type and preferences, number of guests, special requests, and booking reference numbers.
  • Payment Data: Credit or debit card details, billing address, and transaction history. Please note that full payment card numbers are processed via our secure third-party payment processors and are not stored by us directly.
  • Guest Preferences: Dietary requirements, accessibility needs, room preferences, and other requests you communicate to us.
  • Communications Data: Any correspondence or messages you send to us via email, contact forms, or other channels.
  • Feedback and Reviews: Guest feedback, satisfaction survey responses, and reviews you submit.

2.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device type, and screen resolution.
  • Usage Data: Pages visited, time spent on pages, links clicked, referring website addresses, and navigation paths through our website.
  • Cookie Data: Information stored in cookies and similar tracking technologies placed on your device. Please refer to our Cookie Policy for further details.
  • Log Data: Server access logs, error logs, and other technical records generated during your use of our website.

2.3 Data Received from Third Parties

  • Booking Platform Data: When you make a reservation through third-party online travel agencies (OTAs) or booking platforms (such as Booking.com, Expedia, or similar), we receive your name, contact details, and reservation information from those platforms.
  • Social Media Data: If you interact with us via social media platforms or use a social login feature, we may receive basic profile information permitted by that platform and your privacy settings.
  • Review Platform Data: If you submit a review on a third-party review platform that is shared with or linked to us, we may receive the content of that review.
  • Payment Processor Data: Confirmation and transaction status information from our authorised payment processors.

2.4 Special Categories of Personal Data

We do not ordinarily seek to collect special categories of personal data (also known as sensitive personal data) as defined under Article 9 of the GDPR. However, on occasion, guests may voluntarily disclose health-related information — for example, dietary requirements relating to a medical condition or accessibility needs. Where we receive such information, we will handle it with the utmost care, process it only for the specific purpose for which it was shared, and apply appropriate additional safeguards. Such data will only be processed where you have given your explicit consent or where processing is necessary for a legal obligation.

3. Legal Basis for Processing Personal Data

Under the GDPR, we are required to have a lawful basis for every processing activity involving your personal data. In accordance with Article 6 of the GDPR, we rely on the following legal bases:

3.1 Performance of a Contract (Article 6(1)(b))

Where processing is necessary to fulfil a contract with you, or to take steps at your request prior to entering into a contract. This includes:

  • Processing your reservation and confirming your booking.
  • Managing your check-in and check-out at the hotel.
  • Processing payments for accommodation and ancillary services.
  • Arranging and fulfilling any special requests you make in connection with your stay.
  • Handling cancellations, amendments, or refund requests relating to your booking.

3.2 Compliance with a Legal Obligation (Article 6(1)(c))

Where processing is necessary for compliance with a legal obligation to which we are subject. This includes:

  • Retaining financial and accounting records in accordance with Australian taxation and corporate law requirements.
  • Collecting and verifying guest identity information where required by applicable law or regulatory authority.
  • Responding to lawful requests from law enforcement, government bodies, or courts of competent jurisdiction.
  • Meeting our obligations under applicable anti-money laundering legislation.

3.3 Legitimate Interests (Article 6(1)(f))

Where processing is necessary for the purposes of our legitimate interests, provided that those interests are not overridden by your interests, rights, or freedoms. Our legitimate interests include:

  • Improving and personalising the services and experiences we offer to guests.
  • Operating, maintaining, and improving our website and digital infrastructure.
  • Conducting internal analytics and business reporting to understand how our services are used.
  • Protecting the security and integrity of our premises, systems, and staff.
  • Fraud prevention, risk management, and protecting our legal rights.
  • Sending service-related follow-up communications, such as post-stay satisfaction surveys, to guests with whom we have an existing relationship.
  • Managing and responding to guest enquiries, complaints, or feedback.

3.4 Consent (Article 6(1)(a))

Where you have given us your freely given, specific, informed, and unambiguous consent to process your personal data for a particular purpose. We rely on consent for:

  • Sending you marketing communications, newsletters, promotional offers, or updates about our hotel and services by email or other channels, where you have opted in to receive such communications.
  • Placing non-essential cookies and similar tracking technologies on your device.
  • Processing any special category data (such as health-related information) that you voluntarily provide.

You have the right to withdraw your consent at any time without detriment. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw your consent, please contact us at privacy@greenridgeadventures.com or use the unsubscribe link in any marketing email we send you.

3.5 Protection of Vital Interests (Article 6(1)(d))

In limited circumstances, where processing is necessary to protect the vital interests of you or another individual — for example, in a medical emergency during your stay — we may process relevant personal data on this basis.

3.6 Public Task (Article 6(1)(e))

This legal basis is not ordinarily relied upon in our day-to-day operations but may apply where we are required to cooperate with or assist a public authority in carrying out a task in the public interest.

4. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

4.1 Reservation and Accommodation Services

  • Processing, confirming, and managing your hotel booking and reservation.
  • Communicating with you regarding your reservation, including confirmation emails, reminders, and pre-arrival information.
  • Facilitating check-in and check-out procedures.
  • Managing room allocations, guest preferences, and in-stay service requests.
  • Processing payments, deposits, and handling refunds or disputes.

4.2 Customer Service and Communication

  • Responding to your enquiries, requests, complaints, or comments promptly and effectively.
  • Providing you with information about our hotel, facilities, local attractions in Geelong, and available services.
  • Sending post-stay follow-up communications, including satisfaction surveys and thank-you messages.

4.3 Marketing and Promotional Activities

  • Sending you marketing communications, special offers, and promotional updates about Greenridgeadventures — but only where you have provided your consent or we have a legitimate interest to do so (for example, to existing customers in accordance with applicable law).
  • Personalising marketing content based on your known preferences and past stays.

4.4 Website Operation and Improvement

  • Ensuring the technical functionality, security, and performance of our website.
  • Analysing website usage and visitor behaviour to improve site design, content, and user experience.
  • Administering and optimising our online booking engine.

4.5 Legal, Compliance, and Security Purposes

  • Complying with our legal and regulatory obligations under Australian and applicable international law.
  • Maintaining accurate accounting, financial, and tax records.
  • Detecting, investigating, and preventing fraudulent activity, unauthorised access, or other unlawful conduct.
  • Establishing, exercising, or defending legal claims in the event of a dispute.
  • Ensuring the safety and security of our guests, staff, and property.

4.6 Business Operations and Analytics

  • Conducting internal business analysis, reporting, and performance measurement.
  • Improving our accommodation offerings, facilities, and guest experience based on aggregated feedback and usage data.
  • Staff training and quality assurance purposes.

5. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and support our marketing activities. Cookies are small text files placed on your device when you visit a website.

We use the following types of cookies:

  • Strictly Necessary Cookies: Essential for the basic functioning of our website, including enabling you to navigate pages and access secure areas. These cookies cannot be disabled.
  • Performance and Analytics Cookies: These help us understand how visitors interact with our website by collecting anonymous usage data. We use this information to improve how our website works.
  • Functionality Cookies: These enable the website to remember your preferences (such as language or region) and provide enhanced, more personalised features.
  • Marketing and Targeting Cookies: These are used to deliver advertisements and content more relevant to you and your interests. They may also be used to limit the number of times you see an advertisement.

When you first visit our website, you will be presented with a cookie consent banner through which you can manage your preferences for non-essential cookies. You may also update your cookie preferences at any time through your browser settings, although please note that disabling certain cookies may affect the functionality of our website.

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties. However, we may share your personal data with the following categories of recipients in order to deliver our services, comply with our legal obligations, or pursue our legitimate business interests:

6.1 Service Providers and Data Processors

We engage trusted third-party companies and individuals to perform services on our behalf. These service providers are authorised to use your personal data only as necessary to provide services to us, and are bound by appropriate data processing agreements. They include:

  • Payment Processors: To securely process card payments and transactions on our behalf.
  • Online Booking and Property Management Systems: Software platforms that manage reservations, availability, and guest data.
  • Email and Communication Service Providers: Platforms used to send booking confirmations, marketing emails, and other communications.
  • IT and Website Hosting Providers: Companies that host our website, store data, and provide IT infrastructure and support.
  • Analytics Providers: Services such as Google Analytics that help us understand website usage patterns.
  • Marketing and Advertising Platforms: Digital marketing tools and advertising networks used to deliver relevant content and promotions.
  • Customer Feedback and Survey Platforms: Tools used to collect and manage guest satisfaction surveys and reviews.

6.2 Online Travel Agencies and Booking Platforms

Where you make a reservation through a third-party online travel agency or booking platform, we may share relevant booking and guest data with that platform in connection with your reservation — for example, to process cancellations or modifications.

6.3 Legal and Regulatory Authorities

We may disclose your personal data to law enforcement agencies, government bodies, courts, or other public authorities where we are required or permitted to do so by law, or where disclosure is necessary to protect our legal rights or comply with a legal process.

6.4 Professional Advisers

We may share your personal data with our lawyers, accountants, auditors, insurers, and other professional advisers where necessary in the context of professional services they provide to us. All such advisers are bound by applicable professional confidentiality obligations.

6.5 Business Transfers

In the event that Greenridgeadventures Pty Ltd undergoes a business transaction such as a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred as part of that transaction. We will take reasonable steps to ensure your data remains protected and that you are notified of any such transfer where required by applicable law.

6.6 International Transfers

Some of our third-party service providers may be located outside of Australia or the European Economic Area (EEA). Where we transfer personal data internationally, we ensure that appropriate safeguards are in place to protect your data in accordance with applicable law, including:

  • Transferring data to countries that have been determined to provide an adequate level of data protection by the relevant regulatory authority.
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission where required.
  • Relying on binding corporate rules, certifications, or other legally recognised transfer mechanisms.

You may request further information about international data transfers by contacting us at privacy@greenridgeadventures.com.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal, regulatory, and accounting obligations, to resolve disputes, and to enforce our agreements. Retention periods vary depending on the type of data and the purpose for which it is processed:

  • Booking and Reservation Data: Retained for a period of seven (7) years from the date of your stay, in accordance with Australian taxation and financial record-keeping requirements.
  • Guest Identity and Contact Data: Retained for a period of up to seven (7) years following your last interaction with us, unless a longer retention period is required by law or we have a legitimate ongoing reason to retain it.
  • Payment Records: Retained for seven (7) years to comply with financial and tax obligations. Full payment card data is not stored by us beyond the immediate processing of your transaction.
  • Marketing Consent Records: Retained for the duration of your consent and for a further period of up to three (3) years after you withdraw consent, for the purpose of demonstrating compliance with consent requirements.
  • Communications and Correspondence: Retained for a period of up to three (3) years from the date of the communication, unless relevant to a legal claim or complaint, in which case they may be retained for longer.
  • Website Analytics and Log Data: Typically retained for up to twenty-six (26) months, depending on the analytics tools we use and their respective data retention settings.
  • Cookie Data: Retained for the period specified in our cookie consent management platform, which varies by cookie type and provider.
  • Legal Claims Data: Where personal data is relevant to a potential or existing legal claim, complaint, or regulatory investigation, we may retain that data for as long as is necessary to resolve the matter and for a further period thereafter in accordance with applicable limitation periods.

When personal data is no longer required, we will securely delete or anonymise it in accordance with our internal data retention and disposal procedures.

8. Your Rights Under the GDPR

If you are located in the European Union, the European Economic Area, or another jurisdiction where the GDPR or equivalent data protection legislation applies, you have the following rights in relation to your personal data. We also seek to honour these rights for all guests and users of our services, regardless of location, where reasonably practicable.

8.1 Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will respond to your request within one month of receipt, free of charge, unless your request is manifestly unfounded or excessive.

8.2 Right to Rectification (Article 16)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

8.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request the deletion of your personal data in certain circumstances — for example, where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent (and no other legal basis applies), or where the data has been unlawfully processed. This right is not absolute and may be limited by our legal obligations.

8.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, or where you have objected to processing pending verification of our legitimate grounds.

8.5 Right to Data Portability (Article 20)

Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible.

8.6 Right to Object (Article 21)

You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests or is carried out for direct marketing purposes. Where you object to processing for direct marketing, we will cease that processing immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.

8.7 Right to Withdraw Consent (Article 7(3))

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal.

8.8 Rights Related to Automated Decision-Making and Profiling (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently engage in automated decision-making that produces legal or similarly significant effects. If this changes, we will update this Privacy Policy and take appropriate steps to protect your rights.

8.9 Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes your rights under the GDPR, you have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence or place of work. In Australia, the relevant authority is:

  • Office of the Australian Information Commissioner (OAIC)
  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

If you are based in the EU or EEA, you may also contact the relevant data protection authority in your member state. We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority, and we encourage you to contact us first.

8.10 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to us at:

  • Email: privacy@greenridgeadventures.com
  • Postal Address: The Data Protection Officer, Greenridgeadventures Pty Ltd, 1 Eastern Beach Rd, Geelong VIC 3220, Australia

We may need to verify your identity before processing your request. We will respond to all legitimate requests within one (1) month. In complex cases or where we receive a high volume of requests, we may extend this period by up to a further two (2) months, in which case we will notify you accordingly.

9. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using industry-standard Transport Layer Security (TLS) protocols.
  • Secure storage of personal data with access controls limiting access to authorised personnel only.
  • Regular review and testing of our security systems and processes.
  • Staff training on data protection obligations and information security practices.
  • Use of reputable and vetted third-party service providers who maintain appropriate security standards.

While we take all reasonable steps to protect your personal data, please be aware that no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your data. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and take all necessary steps to mitigate the impact.

10. Third-Party Links

Our website may contain links to third-party websites, applications, or services — including booking platforms, local attractions in Geelong, or social media platforms. This Privacy Policy applies solely to our website and services. We are not responsible for the privacy practices of any third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.

11. Children's Privacy

Our website and hotel services are not directed at children under the age of sixteen (16), and we do not knowingly collect personal data from children without appropriate parental or guardian consent. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at privacy@greenridgeadventures.com and we will take prompt steps to delete such information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or business operations. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email or by placing a prominent notice on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.

Your continued use of our website or services after any changes to this Privacy Policy take effect constitutes your acknowledgement of those changes.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us:

Contact Person The Data Protection Officer
Organisation Greenridgeadventures Pty Ltd
Address 1 Eastern Beach Rd, Geelong VIC 3220, Australia
Email privacy@greenridgeadventures.com
Website greenridgeadventures.com

We are committed to resolving any concerns you may have in a timely and transparent manner. We will endeavour to respond to all privacy-related enquiries within five (5) business days.