1. Purpose and scope
This Privacy Policy explains how Museum of Illusions in Denmark processes personal data about visitors, ticket purchasers, shop customers, people who contact us, marketing recipients and users of our Danish websites. Separate notices apply to candidates, employees, CCTV/video surveillance and voluntary health/accessibility information.
2. Who is controller?
| Activity | Controller | Role |
|---|---|---|
| Museum operations, ticketing, customer service, local events, employees, local marketing and CCTV/video surveillance | MOI Kopenhagen Opco ApS CVR 44357828 Frederiksberggade 24, 1459 Copenhagen, Denmark | Local controller |
| Physical museum shop: sales, payments, returns/complaints and shop accounting | Museum of Illusions Kopenhagen ApS CVR 43704575 Frederiksberggade 24, 1459 Copenhagen, Denmark | Separate controller for shop |
| Central digital architecture, group CRM, segmentation, campaign measurement and other centrally determined purposes | Metamorfoza d.o.o., RadniÄka cesta 21, 10000 Zagreb, Croatia RP Illusions Corp., 7975 N. Hayden Road, Suite D-280, Scottsdale, AZ 85258, USA | Joint controllers where they actually determine purposes and essential means |
Ownership alone does not create joint controllership. Museum of Illusions Kopenhagen ApS is therefore not controller for the Opcoâs ticketing, employees or marketing unless it actually participates in determining the relevant processing. Where Metamorfoza d.o.o. and RP Illusions Corp. are joint controllers, GDPR Art. 26 requires them to allocate their respective GDPR responsibilities in an arrangement and make the essence of that arrangement available; contact [email protected] for information about that allocation.
3. Contact
Privacy questions and requests: [email protected].
4.Data we process
| Area | Examples |
|---|---|
| Tickets and visits | Name, email, telephone if provided, ticket/order data, payment token/reference, date/time and customer-service enquiries. |
| Shop | Transaction/receipt data, payment reference and contact details for e-receipts, returns, complaints or warranty matters. |
| Website and cookies | IP address, device/browser data, cookie IDs, preferences, traffic, campaign and interaction data in accordance with the Cookie Policy. |
| Marketing | Contact details, consent/opt-out logs, channel preferences, campaign interactions and lawful segmentation. |
| Customer service and incidents | Correspondence, complaint/incident information and relevant documentation. |
| Accessibility | Only information voluntarily provided by the guest to obtain a requested accommodation; health data are processed only where necessary and with an appropriate Article 6 and Article 9 basis. |
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Â Provide tickets, visits, purchases, returns and customer service | GDPR Art. 6(1)(b) (contract) and, where relevant, Art. 6(1)(c) (legal obligation). |
| Accounting, tax, bookkeeping and records | GDPR Art. 6(1)(c), including statutory bookkeeping obligations. |
| Security, abuse/fraud prevention, IT and access security | GDPR Art. 6(1)(f), our legitimate interest in protecting people, assets and systems; specific rules apply to CCTV/video surveillance. |
| Direct marketing by email/SMS/telephone | Valid prior consent/request where required by Danish marketing and consumer-contract law. Where personal data are processed on the basis of consent, GDPR Art. 6(1)(a) applies; necessary administration of consents, opt-outs and evidence may, depending on the circumstances, rely on Art. 6(1)(c) or (f). |
| Cookies and similar non-essential technologies | For non-essential technologies: prior consent under the Danish Cookie Order; where subsequent personal-data processing relies on consent, GDPR Art. 6(1)(a). Technically necessary technologies are exempt from cookie consent, but any personal-data processing still requires an independent GDPR legal basis. |
| Voluntary health data for accessibility | GDPR Art. 6(1)(a) and Art. 9(2)(a) (explicit consent), or exceptionally Art. 6(1)(d) and Art. 9(2)(c) (vital interests), where the conditions are met. |
5A. Required information
Where a field in the ticketing/checkout flow is marked as required, the information is needed to enter into or perform the contract, complete payment or administer the booking. If such information is not provided, the booking or payment cannot be completed. Marketing information and fields marked as optional are not required to purchase a ticket or visit the Museum.
6. Marketing
We do not send B2C marketing by email, SMS, automated calling systems or fax without the required prior consent, except for the narrow existing-customer exception for electronic mail in section 10(2) of the Danish Marketing Practices Act. Telephone marketing to consumers is made only following the consumerâs prior request; Museum of Illusions services do not fall within the specific statutory exceptions to this rule. Consents/requests are voluntary, channel-specific and can be withdrawn free of charge at any time. Under the current operating model, the shop company is not a marketing sender.
7. Cookies and similar technologies
Non-essential cookies and similar technologies are activated only after valid consent. You can reject all non-essential technologies as easily as you can accept them and can change your choices through âManage cookiesâ. See the Cookie Policy and the dynamic provider/cookie list in the CMP.
8. Children and families
We do not knowingly collect more data about children than needed for the visit or requested service. Where an information-society service is offered directly to a child and processing relies on GDPR consent, Danish data-protection law generally permits the child to consent from age 13; for children under 13, consent is given or authorised by the holder of parental responsibility. Separate rules and maturity assessments apply to cookie/terminal-equipment consent; see the Cookie Policy. School/group bookings are handled through the responsible adult or organisation where possible.
9. Recipients and processors
We use only providers needed for operations, such as ticketing/POS, payments, hosting, CRM, email/SMS, analytics, customer support, HR/recruitment, security and IT. Processors may process data only on documented instructions and under appropriate processor agreements. Authorities may receive data where required or permitted by law.
10. International transfers
Metamorfoza d.o.o. is established in the EU/EEA. Where personal data is made available to RP Illusions Corp. in the United States or other recipients outside the EU/EEA, a valid Chapter V transfer mechanism is used. Where no relevant adequacy decision applies, MOI generally uses the European Commission Standard Contractual Clauses (SCCs) 2021/914 with the module matching the partiesâ actual roles, together with supplementary measures where necessary. A copy of the relevant safeguards may be requested at [email protected], subject to appropriate redaction of confidential information.
11. Retention
We retain data only for as long as needed for the purpose for which it was collected and to meet documented legal requirements. Accounting material covered by section 12 of the Danish Bookkeeping Act is generally retained for 5 years from the end of the financial year to which it relates, subject to applicable statutory exceptions. Marketing-consent evidence is kept while the consent is used and for a limited evidence period thereafter. CCTV follows the separate CCTV notice. The internal retention schedule sets operational deletion deadlines.
12. Your rights
Depending on the circumstances, you may request access to your personal data, rectification or erasure of your data, restriction of processing and data portability, and you may object to the processing of your personal data. Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights or ask questions about the processing of your personal data, please contact us at [email protected].
We respond to requests to exercise data-subject rights without undue delay and, in principle, within one month of receipt. Where permitted under the GDPR, this period may be extended by a further two months, taking into account the complexity and number of requests. If the period is extended, we will inform you of the extension and the reasons for it within the initial one-month period.
You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe that the processing of your personal data infringes applicable data-protection law.
Datatilsynet can be contacted at:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Danmark
E-mail: [email protected]
Web: www.datatilsynet.dk
You may also submit a complaint through the complaint facility available on Datatilsynet's website.
13. Security
We use appropriate technical and organisational measures, including role-based access, authentication, logging, vendor management, backups and incident response, proportionate to risk.
14. Automated decisions
We do not make decisions producing legal or similarly significant effects solely by automated means unless we separately inform you and have a valid legal basis.
15. Changes
We update this policy when processing, law or material systems change. The latest version is published on the Danish Museum of Illusions websites.