Website Privacy Policy

September 8, 2026

Museum of Illusions — United Kingdom

1. Purpose and scope

This Privacy Policy explains how Museum of Illusions companies in the United Kingdom and central Museum of Illusions group functions collect, use, share and retain personal information. It applies when you use our websites, purchase or use a ticket, visit an operational UK museum, contact us, attend an event, subscribe to communications, apply for a role, or exercise your data protection rights.

It is prepared under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended), and the Data (Use and Access) Act 2025. It is not a general consent. Where consent is required, we ask for it separately.

2. Controllers

For local ticket sales, visits, local enquiries, incidents, employment and other processing attributable to a UK operating company, the relevant UK company acts as controller for the processing for which it is responsible.

LocationUK companyCompany no.AddressStatus
LondonMUSEUM OF ILLUSIONS LONDON LTD16464435Unit 6A, 15 - 17 Tottenham Court Road, Ground, First And Second Floors, London, England, W1T 1BJOperational museum
ManchesterMUSEUM OF ILLUSIONS MANCHESTER LTD1496413158-66 Market Street, Manchester, United Kingdom, M1 1PWOperational museum

For centrally determined group processing, including website and ticketing architecture, CRM, marketing, segmentation and profiling, the data warehouse, system administration, group retention standards and group reporting, Metamorfoza d.o.o., Radnička cesta 21, 10000 Zagreb, Croatia and RP Illusions Corp., 7975 N. Hayden Road, Suite D-280, Scottsdale, AZ 85258, USA act as joint controllers because they jointly determine the purposes and essential means of that processing.

Where a UK company has its own controller role for a local activity, that role exists alongside the central joint-controller role. A UK company does not become a joint controller of central processing merely because it supplies data to or receives services from the group.

Metamorfoza d.o.o. and RP Illusions Corp. have appointed Museum of Illusions Manchester Ltd, 58-66 Market Street, Manchester, United Kingdom, M1 1PW, as their representative in the United Kingdom under Article 27 UK GDPR.

The UK representative may be contacted regarding UK data protection matters at [email protected]

3. Data protection contact

Data protection matters are coordinated through the Museum of Illusions Group Privacy Function. For privacy questions, rights requests, or complaints, please contact: [email protected]

4. Personal information we may process
  • Identity and contact details: name, email address, telephone number, address or postcode where needed.
  • Booking and transaction data: museum, visit date/time, ticket type and quantity, order number, value, discounts, refunds and complaints.
  • Payment information: payment status, amount, reference, payment method and limited card information supplied by the payment provider. Full payment-card data is handled by the payment provider and is not retained by MOI.
  • Account, customer-service and B2B information: enquiries, complaints, preferences, professional contacts, schools, groups and events.
  • Marketing and profiling information: consent choices, source and time of choice, opt-outs, purchase/visit history, segments based on location, spend, frequency and behaviour, and advertising audiences where permitted.
  • Website/device information: IP address, device/browser identifiers, page views, events and storage/access technology information according to your choices and applicable PECR exceptions.
  • Images and content: photographs, video and user-generated content where you are informed of the use.
  • Security information: CCTV footage and security logs at operational museums.
  • Health/accessibility information: only where you choose to provide information needed for an accessibility request or emergency.
  • Candidate information where you apply for a role with a UK MOI company. Employee and worker information is handled under the applicable Employee Privacy Notice and internal HR privacy documentation.

Where we obtain personal information indirectly, it may come from a person making a group booking, a school or employer, another MOI group company, a service provider or business partner, or a public source where lawful. Where Article 14 UK GDPR applies, we provide the required information about the source and processing.

5. Purposes and lawful bases
PurposeMain lawful basis
Booking, payment, ticket delivery, entry, changes and refundsContract / steps at your request; legal obligations where applicable
Customer service, complaints, safety and lost propertyContract, legal obligation and/or legitimate interests
System security, fraud prevention, access control and loggingLegitimate interests and legal/security obligations
Email and SMS direct marketingConsent under PECR/UK GDPR as MOI operational policy; MOI does not rely on the soft opt-in
Live telephone marketingMOI consent-first policy; PECR/TPS requirements also apply
Profiling, retargeting and advertising audiencesConsent where PECR/storage-access rules require it; otherwise documented UK GDPR lawful basis
Cookies / storage and access technologiesConsent where required; narrow PECR exceptions where all statutory conditions are met
Voluntary health/accessibility informationAn applicable Article 6 lawful basis (for example, contract/steps at your request, legitimate interests or vital interests) together with an applicable Article 9 condition, such as explicit consent where appropriate or vital interests in an emergency
CCTVLegitimate interests in protecting people/property; DPA 2018/UK GDPR
Legal claims, audits, compliance and statutory recordsLegal obligation and/or legitimate interests
6. Marketing

We do not automatically enrol ticket customers into marketing. Our UK operational policy is consent-first: email, SMS and live telephone marketing choices are separate, optional and unticked. Refusal does not affect ticket purchase or admission. We do not operationally rely on the PECR soft opt-in.

Marketing about a specific museum is presented under that museum brand. Metamorfoza d.o.o. and RP Illusions Corp. act as joint controllers for the centrally determined marketing. We do not market another MOI location to you unless your choice or the campaign scope clearly covers it. National UK campaigns may relate to both operational UK museums where the consent wording makes that scope clear.

You may withdraw consent or object to direct marketing at any time. We retain only the minimum suppression information needed to ensure that an opt-out is respected.

7. Cookies and other storage/access technologies

Our Cookie Policy explains cookies, pixels, tags, local storage and similar technologies. Advertising and tracking technologies that require consent are blocked until the required choice is made. UK law now contains specific exceptions for communications, strictly necessary purposes, statistical purposes, appearance/functionality preferences and emergency assistance; we use an exception only where all conditions are met.

8. Children and families

Our services are intended for families and general audiences, not specifically directed at young children. We minimise children’s personal information, do not use children’s data to create behavioural advertising audiences, and use parent/guardian authorisation for identifiable promotional use of a child’s image where appropriate.

9. Recipients and service providers

Personal information may be accessed on a need-to-know basis by authorised Operations, Customer Service, Marketing, Finance, HR, IT, Data, Legal and management teams of the relevant controllers. We also use processors and other service providers for ticketing, payments, CRM, email/SMS, cloud hosting, analytics, advertising, recruitment, HR and security. Group systems currently include tools such as Roller, Microsoft 365/Azure/OneDrive, Klaviyo, HubSpot, Snowflake, Workday and TalentLyft, together with advertising platforms such as Meta, Google and TikTok, where applicable.

10. International transfers from the UK

MOI UK personal information may be transferred from the United Kingdom to Croatia and other EEA countries. The EEA is covered by UK adequacy regulations, so these transfers can rely on UK adequacy.

Personal information may also be transferred or remotely accessed from the United States, including by RP Illusions Corp. and certain service providers. Where a US recipient is actively certified to the UK Extension to the EU-US Data Privacy Framework for the relevant data, MOI may rely on that UK adequacy mechanism. Otherwise, MOI uses an approved UK transfer safeguard such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with the required transfer risk assessment/data protection test where applicable. You may contact [email protected] for further information about the safeguards used for restricted transfers and, where applicable, to obtain a copy.

11. Retention
CategoryMOI UK retention rule
Customer profile / bookingNormally 3 years after the last purchase, visit or active contact, then delete or anonymise, subject to legal archives.
Accounting, tax and VAT recordsNormally 6 years from the relevant financial year/record date, or longer where UK tax law requires.
Marketing profileWhile consent/relationship remains current; review and delete/anonymise after 3 years without relevant active engagement unless a justified longer period applies.
Suppression / do-not-contact recordMinimum identifier retained for as long as needed to prevent renewed marketing; not used for any other purpose.
Advertising audiencesMOI control: refresh/revalidate at least every 180 days; remove earlier after withdrawal/objection where applicable.
CCTVShortest period necessary; MOI default normally no more than 30 days unless footage is extracted for an incident, claim or investigation.
Accessibility/health requestDelete when the request/visit is complete unless an incident or legal reason requires retention.
Candidate recordsRecruitment process + normally 6 months after decision; talent-pool retention only if separately justified/informed.
Employee recordsEmployment + applicable UK statutory/limitation periods; see Employee Privacy Notice and internal schedule.
Rights requests / privacy complaintsHandling period + normally 3 years after closure unless litigation/regulatory action requires longer.
BackupsPersonal information contained in system backups is retained in accordance with documented system-specific backup and disaster-recovery schedules and is deleted or overwritten as the relevant backup cycle expires.
12. Your rights
  • access and a copy of your personal information;
  • rectification of inaccurate information;
  • erasure where the legal conditions are met;
  • restriction of processing;
  • objection to processing based on legitimate interests and objection to direct marketing;
  • data portability where applicable;
  • withdrawal of consent at any time without affecting earlier lawful processing; and
  • rights relating to significant automated decisions where applicable.

To exercise your rights, contact [email protected]

We respond without undue delay and normally within one month. We make reasonable and proportionate searches for requested information and may ask for proportionate identity verification where necessary.

Your right to object — You may object at any time to the use of your personal information for direct marketing, and we will stop using it for that purpose. Where we rely on legitimate interests, you may also object on grounds relating to your particular situation. Contact [email protected] or use the unsubscribe or other opt-out method provided in a marketing communication.

13. Data protection complaints

You may complain to us about how we handle personal information using [email protected]

We will acknowledge a data protection complaint within 30 days, investigate it appropriately, keep you informed as needed and communicate the outcome without undue delay.

You may also complain to the Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; 0303 123 1113; https://ico.org.uk/.

14. Security

We use technical and organisational measures appropriate to risk, including access controls, multi-factor authentication on relevant systems, encrypted devices and cloud services where configured, backups, joiner/mover/leaver controls, access reviews, staff training and incident response. Security controls are reviewed and evidence is maintained internally.

15. Profiling and automated decisions

We use marketing segments and audiences to tailor and measure campaigns. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on you. If that changes, we will assess the UK GDPR as amended by the Data (Use and Access) Act 2025, provide required safeguards and update this Policy.

16. Changes

We may update this Policy to reflect legal, organisational, technical or service changes. The current version will show its update date. A new purpose that requires consent will be subject to a new consent request.