Your privacy matters to us. This policy explains what personal information we collect when you visit this website, make an enquiry, book or stay at The Rock, and how we use, store and protect it.
The Rock is operated by Master Key Destinations Pty Ltd (ABN 59 682 341 617) (we, us, our). We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Information we collect
We only collect personal information that we need to respond to you, run bookings and operate the property safely. Depending on how you deal with us, this may include:
Enquiries and viewing requests
- your name, business or organisation, email address and phone number
- where you are based, the type of programme you run and your typical group size
- preferred dates, your website and social media handle
- anything else you tell us about your programme
Bookings and stays
- billing and contact details for the person or business making the booking (the Hirer)
- arrival and departure dates, guest numbers and the services you request
- payment records, such as amounts, dates and bank transfer references. We do not collect or store credit card numbers.
- where you choose to share them, details such as dietary requirements, allergies, accessibility needs or an emergency contact. Some of this may be sensitive (health) information. We only collect it with your consent and only use it to look after guests during the stay.
- insurance certificates and professional details that facilitators provide to us
Website visits
When you browse this website we record basic usage information so we can understand how the site is used and keep it secure:
- your IP address
- pages viewed, time spent on each page and how far you scroll
- the website or campaign link that referred you
- device type, browser, operating system and screen size
- language setting, time zone and approximate location (state or country)
- clicks on phone, email and social media links, and enquiry submissions
We collect this ourselves, on our own server. We do not use Google Analytics, advertising networks or tracking pixels.
Security cameras
For the safety of guests and the property, security cameras operate at the entries and exits of the buildings and in the parking area. Cameras are not used inside the house, bedrooms, bathrooms or wellness areas.
Communications
We keep records of emails, messages and notes of phone calls with you, including any feedback or testimonials you give us.
How we collect it
We collect personal information directly from you wherever we can: when you fill in a form on this website, email or call us, make a booking, or visit the property. Website usage information is collected automatically by our website when pages load.
Sometimes we receive information about guests from the Hirer who books on their behalf, for example a facilitator sharing participant numbers or dietary needs. If you give us information about other people, please make sure they know you are sharing it and have read this policy.
You can deal with us without identifying yourself when you are just browsing. We will need your name and contact details to answer an enquiry or take a booking.
How we use it
We use personal information to:
- answer enquiries, arrange private viewings and prepare quotes
- confirm, manage and invoice bookings, and receive payments
- prepare the property and any services you request, and look after guests during their stay
- keep guests, staff and the property safe, including responding to incidents
- understand how people find and use our website so we can improve it
- detect and prevent fraud, spam, misuse and security threats
- send you information about The Rock that you may be interested in (see Marketing)
- meet our legal, tax, insurance and accounting obligations
We will not use your information for a purpose you would not reasonably expect without your consent, unless the law allows or requires it.
Marketing
If you have enquired with us, booked with us or asked to hear from us, we may email you occasional news, availability and offers about The Rock. Every marketing email includes an easy way to unsubscribe, and you can also ask us to stop at any time by contacting us. We comply with the Spam Act 2003 (Cth).
We never sell, rent or trade your personal information.
Storage and overseas disclosure
Our website and booking records are hosted on servers located in Australia. Some of the services we use, such as email or online tools, may store or process information on servers overseas, including in the United States. Where that happens, we take reasonable steps to make sure those providers protect your information in a way that is consistent with the APPs.
Security and how long we keep it
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our booking system is password protected, uses encrypted (HTTPS) connections and is only accessible to authorised people.
We keep information only as long as we need it:
- Booking, invoice and payment records: 7 years, as required for tax and company records.
- Enquiries that do not become bookings: generally up to 3 years after our last contact, unless you ask us to delete them sooner.
- Website usage data, including IP addresses: 14 months, after which it is automatically deleted.
- Security camera footage: overwritten automatically, usually within 30 days, unless it is needed to investigate an incident.
When we no longer need information, we securely delete it or de-identify it.
Other websites
Our website links to other sites, such as Instagram. When you follow those links, the other site's privacy policy applies, and we are not responsible for how it handles your information.
Accessing and correcting your information
You can ask for a copy of the personal information we hold about you, or ask us to correct it if it is wrong, out of date or incomplete. Contact us using the details below. We will respond within 30 days. We do not charge for making a request, though we may charge a reasonable fee for providing large amounts of information. If we refuse a request, we will explain why in writing.
You can also ask us to delete your information. We will do so unless we need to keep it by law, for example booking and tax records.
Data breaches
If a data breach is likely to cause serious harm to anyone affected, we will notify them and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.
Complaints
If you have a concern about how we have handled your personal information, please contact us first so we can try to put it right. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
Changes to this policy
We may update this policy from time to time. The latest version will always be on this page, with the date it was last updated. If a change significantly affects how we handle your information, we will let you know.
See also our Terms and Conditions.