Elysium Collection MB Main Logo

Privacy Policy

Elysium Hospitality

Privacy Policy Updated: July 24, 2026

1. About this Policy

Arkadia Hospitality Services Pty Ltd trading as Elysium Hospitality Services (EHS) is committed to protecting the privacy of its guests, members of the public, employees, contractors, suppliers and business partners. This Privacy Policy explains how EHS collects, holds, uses, discloses and protects your personal information.

EHS do not operate under a third-party brand, franchise or hotel chain. There is no brand head office that handles personal information, IT systems, cyber security, customer service or marketing on behalf of the hotel, and no franchise or brand-provided IT, cyber or operational backstopping. EHS is directly accountable to the hotel's owners for hotel operations, risk and performance, including all matters of privacy and information security.

EHS handle personal information in accordance with the Privacy Act, the Australian Privacy Principles (APPs) set out in that Act, and other applicable Australian privacy laws, including the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth).

1.1 Scope

This Policy applies to all personal information that EHS collects, holds, uses or discloses in connection with the operation of the hotel, including its rooms, restaurants and bars the rooftop pool and lounge, the gym, events and conferences, weddings, the hotel website (https://www.elysiumhotels.com), our online booking engine and any direct marketing communications we send.

This Policy does not apply to third-party websites, applications, products or services that may be linked to from our website or referenced in our communications. Where you interact with a third party, that third party's own privacy policy will apply.

If you have any questions about this Policy, please contact us using the details provided in section 17.

1.2 GDPR Applicability Statement

While Elysium Hospitality Services is established in Australia, our website and services may be accessible to individuals located in the European Economic Area (EEA). Where applicable, we process personal information in accordance with the requirements of the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Where GDPR applies, we collect and process personal information only where we have a lawful basis to do so, including:

  1. To perform a service such as processing hotel reservations, payments, and guest services;
  2. To comply with legal and regulatory obligations;
  3. To protect vital interests or establish, exercise, or defend legal claims where applicable.
  4. Where you have provided your consent, including for certain marketing communications and cookies;
  5. For our legitimate business interests, provided those interests do not override your privacy rights and freedom.

2. Key Definitions

2.1 Personal information

Personal information means any information or opinion about an identified individual, or an individual who is reasonably identifiable, regardless of whether the information is true and regardless of whether it is recorded in a material form. Examples include your name, contact details, date of birth, government identifiers, marketing preferences, financial information, complaint details, and information about your use of our website or stays at our hotel.

2.2 Sensitive information

Sensitive information is a subset of personal information that includes information or an opinion about an individual's racial or ethnic origin, political opinions, membership of a political association, religious beliefs, philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, criminal record, health information, genetic information and biometric information. Sensitive information attracts a higher level of protection under the Privacy Act.

We will only collect sensitive information where it is reasonably necessary for our functions or activities and only with your consent, unless an exception under the Privacy Act applies (for example, where collection is required or authorised by law).

2.3 Other terms

"Elysium Hospitality Services" or "EHS" refers to the operator of Elysium hotels under a hotel management agreement with the hotel owners. EHS is the legal entity (the APP entity) responsible for handling personal information under this Policy.

"You" and "your" refer to any individual whose personal information we hold, including guests, prospective guests, visitors to the hotel and the website, employees, prospective employees, contractors, suppliers and business partners.

3. What Personal Information We Collect

The personal information we collect depends on your relationship with us and the products or services you request. The following categories describe what we typically collect.

3.1 Hotel guests and visitors

When you make a reservation, stay at the hotel, dine at one of our restaurants or bars, attend an event or otherwise interact with us as a guest, we may collect:

  1. Identification and contact details, including your full name, date of birth, postal address, email address, phone number, nationality and identification document details (passport, driver licence) where required for check-in or by law;
  2. Reservation and stay details, including arrival and departure dates, room type, room preferences, accompanying guests, special requests, dietary requirements, accessibility needs and notes recorded by hotel staff;
  3. Payment and financial information, including credit card details, billing address and transaction history (note: full card numbers are tokenised by our PCI-compliant payment processors and are not retained by us in clear text);
  4. Information about other guests included in your booking that you provide to us;
  5. Communications between you and the hotel, including emails, telephone calls (which may be recorded for training and quality purposes) and in-room service requests;
  6. Survey responses, reviews, ratings and feedback you provide to us;
  7. Images and footage captured by closed-circuit television (CCTV) in public and back-of-house areas of the hotel for security and safety purposes;
  8. Imagery from events, competitions and special experiences, where appropriate notice is given;
  9. Wi-Fi and device information when you connect to a hotel network, including device identifiers, device type and information about your use of the network.

When you visit our websites, use our online booking engine, subscribe to a newsletter, fill in a form or interact with us through digital channels, we may collect:

  1. Your name, email address, phone number and any other information you provide;
  2. Booking enquiries, preferences and cart-abandonment information;
  3. Technical information about your device and visit, including IP address, browser type and version, device identifiers, operating system, referring URLs and pages viewed;
  4. Cookies and similar tracking technologies (see section 8);
  5. Marketing engagement information, such as whether you opened an email or clicked a link.

3.3 Employees and prospective employees

If you apply for a role at EHS or are employed by us, we will collect personal information that is reasonably necessary for our recruitment, on-boarding, employment management, and HR compliance functions. This may include:

  1. Application materials, including your resume, cover letter, work history and details of qualifications;
  2. Identification documents, evidence of your right to work in Australia, visa status and tax file number;
  3. Bank account, superannuation and remuneration details;
  4. Emergency contact, next-of-kin and family details (including in connection with personal leave);
  5. Pre-employment checks where relevant and lawful, including reference checks, criminal history checks, qualification checks, aptitude or psychometric testing and Know Your Customer (KYC) / anti-money laundering checks;
  6. Performance, training, leave, conduct and workplace health and safety records during your employment;
  7. Information from publicly accessible professional networking sites such as LinkedIn.

Most personal information held in employee records about a current or former employee is exempt from the Privacy Act under the "employee records exemption". Even where the exemption applies, we handle employee information securely and respectfully.

3.4 Suppliers, contractors and business partners

We collect personal information about individuals who work for our suppliers, contractors and business partners, including names, business contact details, billing details, financial-capacity information, insurance details, identification documents (where required for site access or KYC) and information necessary for due diligence and contract management.

3.5 CCTV, access control and event imagery

We operate CCTV systems in public and back-of-house areas of the hotel for the purposes of security, safety, the protection of our property and the prevention and investigation of crime. Notices are displayed where CCTV is in operation. We may also collect images and video from events, competitions and special experiences for marketing and promotional purposes, with appropriate notice.

4. How We Collect Personal Information

Where it is reasonable and practicable, we collect personal information directly from you. We may collect it when you:

  1. Make a reservation directly with us, through our website, by phone or email, or through third-party online travel agents and travel management companies;
  2. Check in or check out at the hotel, including through digital check-in tools;
  3. Use facilities at the hotel (such as restaurants, bars, room service, the gym, the rooftop pool, the spa or in-room amenities);
  4. Attend an event, conference, wedding or function at the hotel;
  5. Subscribe to a newsletter, complete an online form, enter a competition or take part in a survey;
  6. Apply for a job, register interest in working with us or join our talent community;
  7. Contact us by phone, email, social media, or in person.

In some circumstances we collect personal information about you from third parties, including:

  1. Third-party booking platforms, online travel agents and travel management companies that make reservations on your behalf;
  2. Tour operators, event organisers, conference organisers and group booking contacts;
  3. Recruitment agencies, referees, former employers and educational institutions in the context of recruitment;
  4. Identity-verification, credit-reference, anti-money laundering and fraud-prevention service providers;
  5. Publicly available sources, including business directories and professional networking sites.

If we collect information about you from someone else, we will take reasonable steps to make you aware of that collection and the matters set out in APP 5,except where we are exempt under law.

5. Why We Collect and Use Personal Information

We collect, hold, use and disclose personal information for purposes related to the operation of EHS. The main purposes include:

5.1 Hotel and hospitality services

  1. Taking and managing your reservation, processing your stay, providing requested services and managing your account with us;
  2. Personalising your experience and recognising preferences across stays;
  3. Processing payments, refunds, deposits and incidentals, and recovering amounts owed;
  4. Managing food and beverage, events, conferences, weddings and group bookings;
  5. Responding to your enquiries, requests, feedback, and complaints.

5.2 Communications and marketing

  1. Sending you transactional and service-related communications relating to your booking or stay;
  2. With your consent or as otherwise permitted by law, sending you direct marketing communications about the hotel, our restaurants and bars, offers and partner programs;
  3. Conducting customer research, surveys, analytics and competitions, and improving our products, services and content.

You can opt out of direct marketing at any time by following the unsubscribe instructions in the relevant communication or by contacting us using the details in section 17.

5.3 Property safety, security and operations

  1. Operating CCTV and access-control systems for the safety of guests, visitors and staff;
  2. Monitoring and protecting workplace health and safety;
  3. Investigating incidents, claims, complaints and conduct, including in connection with insurance;
  4. Detecting, investigating and preventing fraud, theft, malpractice, and other crimes.

5.4 Legal and regulatory

  1. Complying with our legal obligations, including under the Privacy Act, Spam Act, anti-money laundering and counter-terrorism financing laws, modern slavery laws, taxation laws (including FATCA and CRS), liquor licensing laws, work health and safety laws and consumer protection laws;
  2. Conducting Know Your Customer (KYC) checks and screening against publicly available sanctions lists;
  3. Responding to regulator enquiries, subpoenas, court orders and other lawful requests;
  4. Establishing, exercising or defending legal rights and obtaining legal advice;
  5. Reporting hotel performance, risk and incidents (including privacy and information security matters), and managing the sale, restructure or transfer of all or part of the hotel business.

5.5 Employment and workforce management

  1. Recruiting, on-boarding, employing, paying, training, developing, managing and (where applicable) terminating personnel, contractors and consultants at the hotel;
  2. Workplace investigations, performance management, leave management and managing workplace health and safety;
  3. Complying with workplace, taxation and superannuation laws.

6. Who We Disclose Personal Information To

We do not sell, trade, or rent your personal information. Because EHS do not operate under a third-party brand or franchise, we do not disclose your personal information to a brand head office, brand-level loyalty program or brand-level marketing platform. We may, however, disclose personal information to the following categories of third parties for the purposes set out in section 5:

  1. Other entities within the EHS group of hotels, on a need-to-know basis, where this is necessary to deliver shared corporate functions for the hotel (such as finance, payroll, IT, risk management or legal);
  2. The Hotel Owners, in summary or aggregate form for governance, performance, risk and audit purposes, and in case-specific form where reporting on a material privacy or security matter is required;
  3. Online travel agents, global distribution systems, channel managers and booking engines that we use or that you book through;
  4. Service providers we engage to help us operate the hotel, including IT, Cyber Security and cloud-hosting providers, the hotel property management system (PMS), payment processors, customer-relationship-management providers, marketing service providers, analytics providers, email and SMS distribution providers, and providers of cleaning, catering, security, telecommunications and laundry services;
  5. Identity-verification, credit-reference, KYC, anti-money laundering and fraud-prevention providers;
  6. Auditors, lawyers, accountants, insurers, brokers and other professional advisers;
  7. Government, regulatory or law enforcement bodies where required or authorised by law;
  8. Acquirers, transferees and their advisers in connection with a sale, merger, restructure or financing of the hotel business;
  9. Any other third party where you have consented to the disclosure.

Where we disclose personal information to a service provider, we require that they handle the information in accordance with this Policy and applicable privacy laws and only use the information for the purposes for which it was disclosed.

7. Sending Personal Information Overseas

Some of the recipients identified in section 6 are located outside Australia or use technology infrastructure that is based outside Australia. In particular:

  1. Cloud-hosting and software-as-a-service providers we use may store or process personal information in jurisdictions outside of Australia;
  2. Hotel-distribution and channel-management systems may transmit reservations through systems hosted outside Australia;
  3. Some online travel agents and global distribution systems we work with operate internationally and may process bookings outside Australia.

Before disclosing personal information overseas, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, including by entering into contractual commitments that require the overseas recipient to handle the information in accordance with the APPs (or equivalent standards).

Where GDPR applies and personal information is transferred outside the EEA, we take reasonable steps to ensure appropriate safeguards are implemented, including contractual protections and other lawful transfer mechanisms recognised under applicable privacy laws.

8. Cookies and Online Tracking

Our hotel website uses cookies, pixels, web beacons, software development kits and similar technologies (collectively, cookies) to operate the website, remember your preferences, deliver relevant content and advertising, measure performance and improve user experience. Cookies are small data files stored on your device when you visit a website.

We may also use experience analytics tools to understand how users interact with our website, including through heatmaps, click and scroll analytics, and session replay functionality. These tools help us identify usability issues, improve website performance, and enhance the user experience. Where used, we apply privacy controls such as masking, redaction and other configuration settings designed to avoid capturing personal sensitive information.

8.1 Categories of cookies we use

  1. Strictly necessary cookies, which are required for the website to function (for example, to maintain a booking session). These cookies cannot be disabled in our systems;
  2. Performance and analytics cookies, which help us understand how visitors interact with our website, including which pages are most visited and whether users encounter errors;
  3. Functional cookies, which enable enhanced functionality and personalisation, such as remembering your language preference;
  4. Targeting and advertising cookies, which are used to deliver advertising that is relevant to you on our website and on third-party sites, and to measure the effectiveness of advertising campaigns.

Where required by law, we obtain your consent before placing non-essential cookies on your device. You can manage your cookie preferences through the cookie consent banner on our website or by adjusting your browser settings. Disabling certain cookies may affect the functionality of our website.

In jurisdictions where consent for non-essential cookies is not required, continued use of our website may be taken as acceptance of the use of such cookies. Where consent is required by applicable law such as GDPR, non-essential cookies will not be activated until your consent has been obtained.

9. Direct Marketing and Your Choices

With your consent or as otherwise permitted under the Privacy Act and the Spam Act, we may send you direct marketing communications about the hotel, our restaurants and bars, offers, programmes and partner experiences. These communications may be sent by email, SMS, telephone, post or through digital advertising.

Each marketing email and SMS we send will include a clear and simple way to opt out (for example, an "unsubscribe" link). You can also opt out at any time by contacting us using the details in section 17. Once you opt out, we will stop sending you marketing communications, but we may still send you transactional or service-related messages relating to your bookings or stays.

10. How We Store and Secure Personal Information

We take the security of personal information seriously. We adopt appropriate data collection, storage, transmission and processing practices and security measures to protect against misuse, interference, loss, unauthorised access, modification or disclosure of personal information.

Our security measures include access-control procedures, role-based access, network firewalls, encryption in transit and at rest where appropriate, password-protected systems, multi-factor authentication for sensitive systems, secure data-transfer protocols (including TLS for sensitive data exchange between our website and users), physical security at the hotel and ongoing staff training.

Because EHS do not benefit from a brand head office or brand-provided cyber security capability, EHS maintains its own information-security program for the hotel, including direct contracts and operational responsibility for the systems that hold personal information.

Payment card data we accept on our website or at the hotel is handled in accordance with Payment Card Industry Data Security Standard (PCI-DSS) requirements. Card numbers are tokenised by our payment processors and are not stored by us in clear text.

Despite the security measures we use, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your personal information, but we will respond promptly to any suspected or actual incident in accordance with applicable law (see section 16).

11. How Long We Keep Personal Information

We keep personal information for only as long as is reasonably necessary for the purposes for which it was collected, or as required by applicable law, contracts or regulatory requirements (including taxation, employment, anti-money laundering and counter-terrorism financing, liquor licensing and consumer protection requirements).

When personal information is no longer needed for any of the purposes set out in this Policy, we will take reasonable steps to securely delete, de-identify or destroy personal information in accordance with APP 11.2.

12. Access to and Correction of Your Information

You have the right to ask us for access to the personal information we hold about you and to request that we correct that information if it is inaccurate, out of date, incomplete, irrelevant or misleading.

You may make an access or correction request by contacting our Privacy Officer using the details in section 17. We will need to verify your identity before responding to your request. We will respond within a reasonable period (typically within 30 days) and ordinarily without charge. If we refuse to provide access or correct information, we will notify you in writing our reasons and the complaint mechanisms available to you.

Employee records are exempt from some requirements of the Privacy Act, but employees can access records as permitted under relevant workplace laws and internal policies.

13. Anonymity and Pseudonymity

Where it is lawful and practicable, you have the option of dealing with us anonymously or under a pseudonym. However, in many cases (for example, when you make a reservation, check into the hotel, apply for a job or undertake KYC) it will not be lawful or practicable for us to deal with you on an anonymous or pseudonymous basis.

14. Children and Young People

Our website and marketing programs are not directed at children. We do not knowingly collect personal information from children under the age of 16 without the consent of a parent or guardian. We do collect personal information about children in connection with hotel stays (for example, names and ages of children travelling with parents or guardians) where this is necessary to deliver the booking and to comply with safety and licensing requirements.

15. CCTV, Photography and Videography

CCTV is used in public and back-of-house areas of the hotel for the safety of guests, visitors and staff and the protection of our property. CCTV recordings are accessed only by authorised personnel and are retained only for as long as needed for the relevant purpose, after which they are securely deleted.

Where photography or videography is undertaken at events, competitions or experiential moments at the hotel, we will provide notice and, where appropriate, an option to opt out. Imagery used in marketing or promotional material is used in accordance with this Policy and any specific consents we obtain.

16. Notifiable Data Breaches

EHS takes proactive steps to prevent, prepare for and respond to data breaches. If a data breach occurs that is likely to result in serious harm to any individual whose personal information is affected, or triggers notification requirements under applicable privacy laws, EHS shall notify relevant regulators, affected individuals and other stakeholders within the required timeframes.

If you suspect that there has been unauthorised access to your personal information held by us, please contact our Privacy Officer immediately using the details in section 17.

17. Contact, Complaints and Resolution

If you have a question, request or complaint about this Policy or how EHS handles your personal information, please contact our Privacy Officer:

Privacy Officer
Pedro Porto

Email
privacy@elysiumhotels.com

Phone
(02) 9908 0408

Mail
Elysium Hospitality Services, Level 1, 202 Military Road, Neutral Bay NSW 2089

Hotel address
1/202-212 Military Road, Neutral Bay, NSW 2089

We will acknowledge your enquiry or complaint promptly and aim to provide a substantive response in writing within 30 days. If we are unable to do so within that period, we will keep you informed of progress.

If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):

  1. Website: www.oaic.gov.au
  2. Phone: 1300 363 992
  3. Mail: GPO Box 5288, Sydney NSW 2001

18. Changes to this Policy

We may update this Policy from time to time, including to reflect changes in our practices, business, technology, the legal and regulatory environment, or the privacy expectations of our guests and people. The current version of this Policy will be published on the EHS website. Where the changes are material, we will take reasonable steps to bring them to your attention.