Who this statement covers
Tokaj Grove operates the website at tokajgrove.pro and the community space at Office 1012, 205 Queen Street, Auckland CBD, Auckland 1010, New Zealand. This statement applies when you use the website, send an enquiry or communicate with us about a visit or programme.
Information we collect
Visit and programme enquiries
The enquiry form collects the programme or visit type you choose, full name, email address, optional phone number, preferred visit date, optional arrival time, number of guests, optional first-visit answer and optional message. If you choose Social poker, it also records the required programme confirmation. We record the source page and the time of the privacy acknowledgement and, where applicable, poker confirmation.
We collect this information directly from you because it is reasonably necessary to understand and answer your enquiry, discuss programme arrangements and communicate about your preferred visit.
Direct communications
If you email or telephone us, we receive the contact details and information you choose to provide. We use them to answer the communication and manage any resulting visit or programme enquiry.
Technical security information
The website uses a session identifier for form security and temporary error recovery. For rate limiting, the form handler creates a one-way hash derived from the requesting IP address and stores recent submission timestamps. The hosting service may also create ordinary security and access logs containing items such as IP address, request time, requested path, response status and browser information.
Privacy preference record
The site stores your Necessary, Analytics and Marketing category choices, consent version and timestamp in your browser’s local storage. This lets the site restore and honour your settings.
How we use personal information
- To receive, assess and answer visit, programme and social poker enquiries.
- To communicate about your preferred date, group details or an arranged activity.
- To keep the enquiry form secure, prevent repeated automated submissions and investigate technical problems.
- To retain and apply the privacy choices you make in the cookie settings interface.
- To meet legal obligations, resolve complaints and protect the rights or safety of visitors and the venue where reasonably necessary.
Reading the Privacy Statement and acknowledging it in the form confirms that this information has been provided. It is not treated as a blanket consent for unrelated uses.
Information supplied by another person
A group organiser may sometimes give us another guest’s contact or visit information. If we receive personal information indirectly and the Privacy Act 2020 requires notice, we will take reasonable steps to tell the person about the collection as soon as practicable, unless a lawful exception applies. Group organisers should share only information that is needed for the enquiry.
Who receives information
Enquiry details are delivered to [email protected] and are available only to people handling Tokaj Grove enquiries and venue administration. Website hosting, email delivery, security or IT service providers may process information for Tokaj Grove under appropriate confidentiality and security arrangements. We may disclose information when required or permitted by New Zealand law.
We do not sell enquiry information and do not use the enquiry form to create a marketing subscription.
Overseas processing
A hosting, email or IT service provider may process information outside New Zealand. Before making an overseas disclosure covered by Information Privacy Principle 12, Tokaj Grove will use a permitted basis, such as reasonable grounds that the recipient is subject to comparable privacy safeguards or contractual safeguards that provide comparable protection. Where authorisation is relied on, the person will be informed that the overseas recipient may not be required to protect the information in a way comparable to the New Zealand Privacy Act 2020.
Retention
- Enquiries and related communications: kept while the enquiry or arrangement is active and ordinarily for up to 24 months after the last substantive contact, then deleted or de-identified unless a longer period is reasonably needed for a complaint, legal obligation or established dispute.
- Rate-limit records: recent one-way IP-derived hashes and timestamps are used within a 15-minute rate-limit window and are eligible for automated or opportunistic deletion after 24 hours.
- Server security logs: kept according to the hosting security cycle and ordinarily no longer than 90 days unless a security incident requires longer retention.
- Browser consent preference: kept until you change it, the consent version materially changes or browser storage is cleared.
- Session record: intended for the current browser session and removed under the server’s session-cleanup process.
Security
Tokaj Grove uses HTTPS, server-side validation, CSRF protection, a honeypot, rate limiting, restricted server directories and access controls appropriate to the website’s enquiry function. No internet transmission or storage system can provide absolute security. If a privacy breach creates a risk of serious harm, Tokaj Grove will assess notification obligations under the Privacy Act 2020.
Access and correction
You may ask for access to personal information Tokaj Grove holds about you, or ask for it to be corrected. Email [email protected] with enough information to identify the relevant enquiry. We may need to verify your identity. We will respond in accordance with the Privacy Act 2020 and explain any lawful reason for withholding information.
Complaints
Send a privacy concern to [email protected] so it can be investigated. You may also complain to the Office of the Privacy Commissioner.
Changes to this statement
We may update this statement when the website’s information practices or applicable requirements change. The effective date at the top identifies the current version. A material change to consent categories will trigger a new preference request.