Last updated: 6 August 2026
1. Who we are
[Registered company name Ltd], the operator of Royal Club Resorts, is the data controller for personal data processed in connection with the resort, this website, our reservations systems and our accommodation, catering, spa and gaming services. Registered office: [street address], Kavallier Bay, [postcode], Malta. Company number [C 00000].
2. What we collect
- Identity — name, date of birth, and government photo identification, which gaming law requires us to check before anyone is admitted to the gaming floor, and which hotel law requires on check-in.
- Contact — address, email and telephone number.
- Reservation — room, dining, spa and event bookings, stay preferences and dietary requirements you tell us about.
- Payment — card details tokenised by our payment provider. We do not store full card numbers. Where law requires it, source-of-funds information for high-value play.
- Play data — table and machine activity, where relevant to membership tiering, limits you have set, or player protection monitoring.
- CCTV and access control — on the gaming floor and in public areas, as our licence requires.
- Technical — IP address, browser and device information when you use this website.
3. Why we process it
To verify age and identity; to fulfil room, dining, spa and event reservations; to administer membership; to meet obligations under gaming, anti-money-laundering, hospitality and tax law; to monitor for signs of gambling harm; to keep the property secure; and to reply to your enquiries. Where we rely on consent — marketing, for instance — you may withdraw it at any time without affecting what came before.
4. Legal bases
Performance of a contract (your booking); compliance with a legal obligation (identity checks, anti-money-laundering, CCTV retention, guest registration); our legitimate interests (security, fraud prevention, service improvement); and your explicit consent (marketing and any optional profiling).
5. Retention
- Identity and financial records connected to gaming: as gaming and anti-money-laundering law requires, generally five years from the relevant transaction.
- CCTV from the gaming floor: 90 days, unless a specific investigation requires longer.
- Reservation and stay records: six years, for tax and contractual purposes.
- Marketing data: until you withdraw consent, or three years without engagement.
- Website technical logs: 30 to 90 days.
6. Who we share it with
With our gaming regulator, tax authorities and other competent authorities where law requires it; with payment processors, identity verification providers, booking channels you chose to use, and IT and hosting suppliers acting on our instructions under data processing agreements. We do not sell personal data.
7. Transfers outside the EEA
Where a supplier is outside the European Economic Area we put an appropriate safeguard in place first, usually the European Commission's standard contractual clauses.
8. Your rights
You may ask for access to your data, correction of anything inaccurate, erasure where no legal obligation requires us to keep it, restriction of or objection to certain processing, and a portable copy of what you gave us. Write to privacy@royalclubresorts.website and we will answer within one calendar month. You may also complain to the Office of the Information and Data Protection Commissioner in Malta, or to the supervisory authority where you live.
9. Security
Encrypted storage of payment data, restricted staff access to identity records, controlled CCTV access, and regular review of our reservations and website systems.
10. Contact
privacy@royalclubresorts.website, or [Registered company name Ltd], [street address], Kavallier Bay, Malta.