Privacy Policy
How we collect, use, protect and disclose personal information.
1. Scope and purpose
This Privacy Policy explains how Amberpathstudio Pty Ltd ("Amberpathstudio", "we", "us" or "our") collects, uses, stores, discloses and protects personal information when you visit amberpathstudio.com, contact us, submit an enquiry, request information about accommodation or gaming services, or otherwise interact with us. It applies to information handled through this website and related communications.
We are established in Australia and aim to comply with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and, where applicable, the European Union General Data Protection Regulation and the United Kingdom GDPR. Where another mandatory privacy law provides stronger rights, that law will prevail to the extent of any inconsistency.
2. Administrator and contact
The controller or responsible organisation for website personal information is Amberpathstudio Pty Ltd, located at 88 Market Street, Sydney NSW 2000, Australia. Privacy enquiries, access requests and complaints may be sent to info@amberpathstudio.com or by post to the address above.
3. Information we collect
Information you provide
We may collect your name, email address, telephone number, message content, preferred contact method, booking or service interests, accessibility requirements that you choose to disclose, correspondence history and any other information you voluntarily provide. Please avoid sending payment-card details, government identifiers, health information or other highly sensitive information through the general contact form.
Information collected automatically
When the website is accessed, technical information may be generated, including IP address, browser type, device type, operating system, language, referring page, pages viewed, approximate region, date and time of access, error logs and basic interaction information. This information may be collected through essential storage, server logs and consent-based analytics technologies as described in the Cookie Policy.
Information from third parties
We may receive information from service providers supporting hosting, security, communications, booking administration or fraud prevention. We require such providers to process information only for authorised purposes and subject to appropriate confidentiality and security commitments.
4. Purposes of processing
We process personal information to respond to enquiries; provide requested information; administer expressions of interest and service requests; maintain website security; prevent misuse and fraud; diagnose technical problems; comply with legal, regulatory, licensing and responsible-gaming obligations; protect our rights and the rights of others; manage records; improve website accessibility and usability; and send direct marketing only where permitted and subject to available opt-out rights.
5. Legal bases under GDPR
Where GDPR applies, processing is based on one or more of the following grounds: taking steps at your request before entering a contract; performing a contract; complying with a legal obligation; pursuing legitimate interests such as website security, service administration and fraud prevention, provided those interests are not overridden by your rights; protecting vital interests in exceptional circumstances; or your freely given consent, which may be withdrawn at any time without affecting earlier lawful processing.
6. Sensitive information and age restrictions
This website is intended for adults aged 18 years or older. We do not knowingly collect information from children. Gaming-related services are restricted in accordance with applicable Australian law and venue requirements. We do not intentionally request sensitive information through the general website form. Where sensitive information is necessary and lawful, it will be handled with additional safeguards and, where required, explicit consent.
7. Cookies and similar technologies
Essential technologies may be used to provide core functionality, protect forms, remember basic preferences and maintain security. Optional analytics or marketing technologies will not be used where consent is legally required unless valid consent has been obtained. Detailed information about categories, choices and retention is provided in the Cookie Policy.
8. Disclosure of personal information
We may disclose personal information to hosting providers, IT and security vendors, communications providers, professional advisers, insurers, auditors, regulators, law-enforcement bodies or courts where reasonably necessary and lawful. We do not sell personal information. Providers are given only the information reasonably required for their services and must protect it under contractual or legal obligations.
9. International transfers
Some service providers may process information outside Australia or outside the country where you are located. Where GDPR applies, international transfers will rely on an adequacy decision, approved standard contractual clauses, another recognised transfer mechanism or a lawful derogation. We assess transfer risks and use supplementary safeguards where appropriate.
10. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including responding to enquiries, maintaining records, resolving disputes, enforcing agreements and meeting legal, tax, accounting, security or licensing requirements. Contact enquiries are generally reviewed for deletion or anonymisation after 24 months unless an ongoing relationship, complaint, legal hold or mandatory retention period requires longer storage.
11. Security
We use proportionate administrative, technical and physical safeguards, which may include access controls, least-privilege permissions, secure hosting configurations, software maintenance, backups, monitoring and staff confidentiality obligations. No internet transmission or storage system can be guaranteed completely secure. If a qualifying data breach occurs, we will assess notification duties under applicable law, including Australia’s Notifiable Data Breaches scheme and GDPR.
12. Your rights
Depending on applicable law, you may request access to personal information, correction of inaccurate information, deletion, restriction of processing, objection to processing based on legitimate interests, withdrawal of consent, data portability, or information about automated decision-making. You may also opt out of direct marketing at any time.
We may ask for reasonable information to verify identity and authority before completing a request. Requests will be handled within the time required by applicable law. Some rights are subject to exemptions, including legal obligations, public-interest requirements, freedom of expression, legal claims and the rights of others.
13. Automated decisions
We do not use website contact-form information to make solely automated decisions that produce legal or similarly significant effects. Security systems may automatically identify suspicious traffic, but material decisions are subject to human review where required.
14. Complaints and supervisory authorities
Please contact us first so we can investigate and respond. Australian privacy complaints may also be directed to the Office of the Australian Information Commissioner. Individuals in the European Economic Area or United Kingdom may lodge a complaint with the supervisory authority in their place of residence, work or the location of the alleged infringement.
15. Third-party links
The website may contain links to third-party services. Their privacy practices are governed by their own notices. We are not responsible for third-party content, security or privacy practices, and users should review the relevant policies before providing information.
16. Changes to this policy
We may update this policy to reflect legal, operational or technical changes. The updated version will be published on this page with a revised date. Material changes may be highlighted through an additional website notice where appropriate.
17. Data quality, minimisation and accountability
We take reasonable steps to ensure that personal information is relevant, accurate, complete and limited to what is necessary for the stated purpose. Staff and service providers are expected to follow documented privacy and security responsibilities. Where appropriate, we maintain records of processing, review privacy risks, apply privacy-by-design principles and conduct impact assessments before introducing processing that may create a high risk to individuals.
18. Direct marketing and communications
We may send service-related communications when necessary to respond to a request or administer an existing relationship. Promotional communications are sent only where permitted by applicable law. Each electronic marketing message will provide a practical method to unsubscribe. An unsubscribe request does not prevent essential administrative, security, legal or transactional communications.
19. De-identified and aggregated information
We may create aggregated or de-identified statistics to understand website reliability, enquiry trends and service demand. We take reasonable measures to reduce the likelihood that such information can be linked back to an identifiable person. If information is later re-identified or reasonably capable of re-identification, it will again be treated as personal information.
20. Service providers acting as processors
Where a provider processes personal information on our instructions, we seek contractual terms addressing confidentiality, security, permitted purposes, sub-processors, assistance with individual rights, breach notification, deletion or return of information and audit or assurance rights. Providers must not use information for their own unrelated purposes unless they independently provide a lawful notice and legal basis.
21. Data breach response
Suspected privacy incidents are assessed promptly. Our response may include containment, preservation of evidence, risk analysis, remediation, provider coordination and notification. Where the Australian Notifiable Data Breaches scheme, GDPR or another law requires notification, affected individuals and the relevant authority will be informed within the legally required period and supplied with available information about the incident, likely consequences and protective steps.
22. Specific retention considerations
General contact enquiries are usually retained for no longer than 24 months after the last meaningful interaction. Complaint, dispute, exclusion, security or legal records may be retained longer where necessary to establish, exercise or defend legal claims or comply with regulatory obligations. Consent records may be retained for the period necessary to demonstrate compliance. Backup copies are removed through normal rotation schedules and are protected from routine use.
17. Contact
Privacy requests may be sent to info@amberpathstudio.com or to Amberpathstudio Pty Ltd, 88 Market Street, Sydney NSW 2000, Australia.