PRIVACY POLICY

1. Purpose and scope

This Privacy Policy explains how Museum of Illusions in Denmark processes personal data about visitors, ticket purchasers, shop customers, people who contact us, marketing recipients and users of our Danish websites. Separate notices apply to candidates, employees, CCTV/video surveillance and voluntary health/accessibility information.

2. Who is controller?
ActivityControllerRole
Museum operations, ticketing, customer service, local events, employees, local marketing and CCTV/video surveillanceMOI Kopenhagen Opco ApS
CVR 44357828
Frederiksberggade 24, 1459 Copenhagen, Denmark
Local controller
Physical museum shop: sales, payments, returns/complaints and shop accountingMuseum of Illusions Kopenhagen ApS
CVR 43704575
Frederiksberggade 24, 1459 Copenhagen, Denmark 
Separate controller for shop
Central digital architecture, group CRM, segmentation, campaign measurement and other centrally determined purposesMetamorfoza d.o.o., Radnička cesta 21, 10000 Zagreb, Croatia
RP Illusions Corp., 7975 N. Hayden Road, Suite D-280, Scottsdale, AZ 85258, USA
Joint controllers where they actually determine purposes and essential means

Ownership alone does not create joint controllership. Museum of Illusions Kopenhagen ApS is therefore not controller for the Opco’s ticketing, employees or marketing unless it actually participates in determining the relevant processing. Where Metamorfoza d.o.o. and RP Illusions Corp. are joint controllers, GDPR Art. 26 requires them to allocate their respective GDPR responsibilities in an arrangement and make the essence of that arrangement available; contact [email protected] for information about that allocation.

3. Contact

Privacy questions and requests: [email protected].

4.Data we process

AreaExamples
Tickets and visitsName, email, telephone if provided, ticket/order data, payment token/reference, date/time and customer-service enquiries.
ShopTransaction/receipt data, payment reference and contact details for e-receipts, returns, complaints or warranty matters.
Website and cookiesIP address, device/browser data, cookie IDs, preferences, traffic, campaign and interaction data in accordance with the Cookie Policy.
MarketingContact details, consent/opt-out logs, channel preferences, campaign interactions and lawful segmentation.
Customer service and incidentsCorrespondence, complaint/incident information and relevant documentation.
AccessibilityOnly information voluntarily provided by the guest to obtain a requested accommodation; health data are processed only where necessary and with an appropriate Article 6 and Article 9 basis.
5. Purposes and legal bases
PurposeLegal basis
 Provide tickets, visits, purchases, returns and customer serviceGDPR Art. 6(1)(b) (contract) and, where relevant, Art. 6(1)(c) (legal obligation).
Accounting, tax, bookkeeping and recordsGDPR Art. 6(1)(c), including statutory bookkeeping obligations.
Security, abuse/fraud prevention, IT and access securityGDPR Art. 6(1)(f), our legitimate interest in protecting people, assets and systems; specific rules apply to CCTV/video surveillance.
Direct marketing by email/SMS/telephoneValid prior consent/request where required by Danish marketing and consumer-contract law. Where personal data are processed on the basis of consent, GDPR Art. 6(1)(a) applies; necessary administration of consents, opt-outs and evidence may, depending on the circumstances, rely on Art. 6(1)(c) or (f).
Cookies and similar non-essential technologiesFor non-essential technologies: prior consent under the Danish Cookie Order; where subsequent personal-data processing relies on consent, GDPR Art. 6(1)(a). Technically necessary technologies are exempt from cookie consent, but any personal-data processing still requires an independent GDPR legal basis.
Voluntary health data for accessibilityGDPR Art. 6(1)(a) and Art. 9(2)(a) (explicit consent), or exceptionally Art. 6(1)(d) and Art. 9(2)(c) (vital interests), where the conditions are met.
5A. Required information

Where a field in the ticketing/checkout flow is marked as required, the information is needed to enter into or perform the contract, complete payment or administer the booking. If such information is not provided, the booking or payment cannot be completed. Marketing information and fields marked as optional are not required to purchase a ticket or visit the Museum.

6. Marketing

We do not send B2C marketing by email, SMS, automated calling systems or fax without the required prior consent, except for the narrow existing-customer exception for electronic mail in section 10(2) of the Danish Marketing Practices Act. Telephone marketing to consumers is made only following the consumer’s prior request; Museum of Illusions services do not fall within the specific statutory exceptions to this rule. Consents/requests are voluntary, channel-specific and can be withdrawn free of charge at any time. Under the current operating model, the shop company is not a marketing sender.

7. Cookies and similar technologies

Non-essential cookies and similar technologies are activated only after valid consent. You can reject all non-essential technologies as easily as you can accept them and can change your choices through “Manage cookies”. See the Cookie Policy and the dynamic provider/cookie list in the CMP.

8. Children and families

We do not knowingly collect more data about children than needed for the visit or requested service. Where an information-society service is offered directly to a child and processing relies on GDPR consent, Danish data-protection law generally permits the child to consent from age 13; for children under 13, consent is given or authorised by the holder of parental responsibility. Separate rules and maturity assessments apply to cookie/terminal-equipment consent; see the Cookie Policy. School/group bookings are handled through the responsible adult or organisation where possible.

9. Recipients and processors

We use only providers needed for operations, such as ticketing/POS, payments, hosting, CRM, email/SMS, analytics, customer support, HR/recruitment, security and IT. Processors may process data only on documented instructions and under appropriate processor agreements. Authorities may receive data where required or permitted by law.

10. International transfers

Metamorfoza d.o.o. is established in the EU/EEA. Where personal data is made available to RP Illusions Corp. in the United States or other recipients outside the EU/EEA, a valid Chapter V transfer mechanism is used. Where no relevant adequacy decision applies, MOI generally uses the European Commission Standard Contractual Clauses (SCCs) 2021/914 with the module matching the parties’ actual roles, together with supplementary measures where necessary. A copy of the relevant safeguards may be requested at [email protected], subject to appropriate redaction of confidential information.

11. Retention

We retain data only for as long as needed for the purpose for which it was collected and to meet documented legal requirements. Accounting material covered by section 12 of the Danish Bookkeeping Act is generally retained for 5 years from the end of the financial year to which it relates, subject to applicable statutory exceptions. Marketing-consent evidence is kept while the consent is used and for a limited evidence period thereafter. CCTV follows the separate CCTV notice. The internal retention schedule sets operational deletion deadlines.

12. Your rights

Depending on the circumstances, you may request access to your personal data, rectification or erasure of your data, restriction of processing and data portability, and you may object to the processing of your personal data. Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights or ask questions about the processing of your personal data, please contact us at [email protected].

We respond to requests to exercise data-subject rights without undue delay and, in principle, within one month of receipt. Where permitted under the GDPR, this period may be extended by a further two months, taking into account the complexity and number of requests. If the period is extended, we will inform you of the extension and the reasons for it within the initial one-month period.

You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe that the processing of your personal data infringes applicable data-protection law.

Datatilsynet can be contacted at:

Datatilsynet

Carl Jacobsens Vej 35

2500 Valby

Danmark

E-mail: [email protected]

Web: www.datatilsynet.dk

You may also submit a complaint through the complaint facility available on Datatilsynet's website.

13. Security

We use appropriate technical and organisational measures, including role-based access, authentication, logging, vendor management, backups and incident response, proportionate to risk.

14. Automated decisions

We do not make decisions producing legal or similarly significant effects solely by automated means unless we separately inform you and have a valid legal basis.

15. Changes

We update this policy when processing, law or material systems change. The latest version is published on the Danish Museum of Illusions websites.