1. Purpose and scope
This Privacy Policy explains how Museum of Illusions companies in the United Kingdom and central Museum of Illusions group functions collect, use, share and retain personal information. It applies when you use our websites, purchase or use a ticket, visit an operational UK museum, contact us, attend an event, subscribe to communications, apply for a role, or exercise your data protection rights.
It is prepared under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended), and the Data (Use and Access) Act 2025. It is not a general consent. Where consent is required, we ask for it separately.
2. Controllers
For local ticket sales, visits, local enquiries, incidents, employment and other processing attributable to a UK operating company, the relevant UK company acts as controller for the processing for which it is responsible.
| Location | UK company | Company no. | Address | Status |
| London | MUSEUM OF ILLUSIONS LONDON LTD | 16464435 | Unit 6A, 15 - 17 Tottenham Court Road, Ground, First And Second Floors, London, England, W1T 1BJ | Operational museum |
| Manchester | MUSEUM OF ILLUSIONS MANCHESTER LTD | 14964131 | 58-66 Market Street, Manchester, United Kingdom, M1 1PW | Operational museum |
For centrally determined group processing, including website and ticketing architecture, CRM, marketing, segmentation and profiling, the data warehouse, system administration, group retention standards and group reporting, Metamorfoza d.o.o., Radnička cesta 21, 10000 Zagreb, Croatia and RP Illusions Corp., 7975 N. Hayden Road, Suite D-280, Scottsdale, AZ 85258, USA act as joint controllers because they jointly determine the purposes and essential means of that processing.
Where a UK company has its own controller role for a local activity, that role exists alongside the central joint-controller role. A UK company does not become a joint controller of central processing merely because it supplies data to or receives services from the group.
Metamorfoza d.o.o. and RP Illusions Corp. have appointed Museum of Illusions Manchester Ltd, 58-66 Market Street, Manchester, United Kingdom, M1 1PW, as their representative in the United Kingdom under Article 27 UK GDPR.
The UK representative may be contacted regarding UK data protection matters at [email protected]
3. Data protection contact
Data protection matters are coordinated through the Museum of Illusions Group Privacy Function. For privacy questions, rights requests, or complaints, please contact: [email protected]
4. Personal information we may process
- Identity and contact details: name, email address, telephone number, address or postcode where needed.
- Booking and transaction data: museum, visit date/time, ticket type and quantity, order number, value, discounts, refunds and complaints.
- Payment information: payment status, amount, reference, payment method and limited card information supplied by the payment provider. Full payment-card data is handled by the payment provider and is not retained by MOI.
- Account, customer-service and B2B information: enquiries, complaints, preferences, professional contacts, schools, groups and events.
- Marketing and profiling information: consent choices, source and time of choice, opt-outs, purchase/visit history, segments based on location, spend, frequency and behaviour, and advertising audiences where permitted.
- Website/device information: IP address, device/browser identifiers, page views, events and storage/access technology information according to your choices and applicable PECR exceptions.
- Images and content: photographs, video and user-generated content where you are informed of the use.
- Security information: CCTV footage and security logs at operational museums.
- Health/accessibility information: only where you choose to provide information needed for an accessibility request or emergency.
- Candidate information where you apply for a role with a UK MOI company. Employee and worker information is handled under the applicable Employee Privacy Notice and internal HR privacy documentation.
Where we obtain personal information indirectly, it may come from a person making a group booking, a school or employer, another MOI group company, a service provider or business partner, or a public source where lawful. Where Article 14 UK GDPR applies, we provide the required information about the source and processing.
5. Purposes and lawful bases
| Purpose | Main lawful basis |
| Booking, payment, ticket delivery, entry, changes and refunds | Contract / steps at your request; legal obligations where applicable |
| Customer service, complaints, safety and lost property | Contract, legal obligation and/or legitimate interests |
| System security, fraud prevention, access control and logging | Legitimate interests and legal/security obligations |
| Email and SMS direct marketing | Consent under PECR/UK GDPR as MOI operational policy; MOI does not rely on the soft opt-in |
| Live telephone marketing | MOI consent-first policy; PECR/TPS requirements also apply |
| Profiling, retargeting and advertising audiences | Consent where PECR/storage-access rules require it; otherwise documented UK GDPR lawful basis |
| Cookies / storage and access technologies | Consent where required; narrow PECR exceptions where all statutory conditions are met |
| Voluntary health/accessibility information | An applicable Article 6 lawful basis (for example, contract/steps at your request, legitimate interests or vital interests) together with an applicable Article 9 condition, such as explicit consent where appropriate or vital interests in an emergency |
| CCTV | Legitimate interests in protecting people/property; DPA 2018/UK GDPR |
| Legal claims, audits, compliance and statutory records | Legal obligation and/or legitimate interests |
6. Marketing
We do not automatically enrol ticket customers into marketing. Our UK operational policy is consent-first: email, SMS and live telephone marketing choices are separate, optional and unticked. Refusal does not affect ticket purchase or admission. We do not operationally rely on the PECR soft opt-in.
Marketing about a specific museum is presented under that museum brand. Metamorfoza d.o.o. and RP Illusions Corp. act as joint controllers for the centrally determined marketing. We do not market another MOI location to you unless your choice or the campaign scope clearly covers it. National UK campaigns may relate to both operational UK museums where the consent wording makes that scope clear.
You may withdraw consent or object to direct marketing at any time. We retain only the minimum suppression information needed to ensure that an opt-out is respected.
7. Cookies and other storage/access technologies
Our Cookie Policy explains cookies, pixels, tags, local storage and similar technologies. Advertising and tracking technologies that require consent are blocked until the required choice is made. UK law now contains specific exceptions for communications, strictly necessary purposes, statistical purposes, appearance/functionality preferences and emergency assistance; we use an exception only where all conditions are met.
8. Children and families
Our services are intended for families and general audiences, not specifically directed at young children. We minimise children’s personal information, do not use children’s data to create behavioural advertising audiences, and use parent/guardian authorisation for identifiable promotional use of a child’s image where appropriate.
9. Recipients and service providers
Personal information may be accessed on a need-to-know basis by authorised Operations, Customer Service, Marketing, Finance, HR, IT, Data, Legal and management teams of the relevant controllers. We also use processors and other service providers for ticketing, payments, CRM, email/SMS, cloud hosting, analytics, advertising, recruitment, HR and security. Group systems currently include tools such as Roller, Microsoft 365/Azure/OneDrive, Klaviyo, HubSpot, Snowflake, Workday and TalentLyft, together with advertising platforms such as Meta, Google and TikTok, where applicable.
10. International transfers from the UK
MOI UK personal information may be transferred from the United Kingdom to Croatia and other EEA countries. The EEA is covered by UK adequacy regulations, so these transfers can rely on UK adequacy.
Personal information may also be transferred or remotely accessed from the United States, including by RP Illusions Corp. and certain service providers. Where a US recipient is actively certified to the UK Extension to the EU-US Data Privacy Framework for the relevant data, MOI may rely on that UK adequacy mechanism. Otherwise, MOI uses an approved UK transfer safeguard such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with the required transfer risk assessment/data protection test where applicable. You may contact [email protected] for further information about the safeguards used for restricted transfers and, where applicable, to obtain a copy.
11. Retention
| Category | MOI UK retention rule |
| Customer profile / booking | Normally 3 years after the last purchase, visit or active contact, then delete or anonymise, subject to legal archives. |
| Accounting, tax and VAT records | Normally 6 years from the relevant financial year/record date, or longer where UK tax law requires. |
| Marketing profile | While consent/relationship remains current; review and delete/anonymise after 3 years without relevant active engagement unless a justified longer period applies. |
| Suppression / do-not-contact record | Minimum identifier retained for as long as needed to prevent renewed marketing; not used for any other purpose. |
| Advertising audiences | MOI control: refresh/revalidate at least every 180 days; remove earlier after withdrawal/objection where applicable. |
| CCTV | Shortest period necessary; MOI default normally no more than 30 days unless footage is extracted for an incident, claim or investigation. |
| Accessibility/health request | Delete when the request/visit is complete unless an incident or legal reason requires retention. |
| Candidate records | Recruitment process + normally 6 months after decision; talent-pool retention only if separately justified/informed. |
| Employee records | Employment + applicable UK statutory/limitation periods; see Employee Privacy Notice and internal schedule. |
| Rights requests / privacy complaints | Handling period + normally 3 years after closure unless litigation/regulatory action requires longer. |
| Backups | Personal information contained in system backups is retained in accordance with documented system-specific backup and disaster-recovery schedules and is deleted or overwritten as the relevant backup cycle expires. |
12. Your rights
- access and a copy of your personal information;
- rectification of inaccurate information;
- erasure where the legal conditions are met;
- restriction of processing;
- objection to processing based on legitimate interests and objection to direct marketing;
- data portability where applicable;
- withdrawal of consent at any time without affecting earlier lawful processing; and
- rights relating to significant automated decisions where applicable.
To exercise your rights, contact [email protected]
We respond without undue delay and normally within one month. We make reasonable and proportionate searches for requested information and may ask for proportionate identity verification where necessary.
Your right to object — You may object at any time to the use of your personal information for direct marketing, and we will stop using it for that purpose. Where we rely on legitimate interests, you may also object on grounds relating to your particular situation. Contact [email protected] or use the unsubscribe or other opt-out method provided in a marketing communication.
13. Data protection complaints
You may complain to us about how we handle personal information using [email protected]
We will acknowledge a data protection complaint within 30 days, investigate it appropriately, keep you informed as needed and communicate the outcome without undue delay.
You may also complain to the Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; 0303 123 1113; https://ico.org.uk/.
14. Security
We use technical and organisational measures appropriate to risk, including access controls, multi-factor authentication on relevant systems, encrypted devices and cloud services where configured, backups, joiner/mover/leaver controls, access reviews, staff training and incident response. Security controls are reviewed and evidence is maintained internally.
15. Profiling and automated decisions
We use marketing segments and audiences to tailor and measure campaigns. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on you. If that changes, we will assess the UK GDPR as amended by the Data (Use and Access) Act 2025, provide required safeguards and update this Policy.
16. Changes
We may update this Policy to reflect legal, organisational, technical or service changes. The current version will show its update date. A new purpose that requires consent will be subject to a new consent request.