1. Purpose and scope
This Policy explains how Museum of Illusions companies in France and central group functions collect, use, share and retain your personal data when you visit our websites, purchase or use a ticket, visit a Museum, contact our teams, take part in an event, subscribe to communications, use a digital feature or exercise your rights.
It is prepared in accordance with Regulation (EU) 2016/679 (GDPR), the French Data Protection Act and applicable French rules on electronic communications, cookies, marketing and CCTV/video protection. It is not a general consent: where your consent is required, it is requested separately
2. Controllers
For bookings, ticket sales, visits, local enquiries, incidents and other processing specific to a Museum, the French company operating the relevant Museum remains controller for processing for which it is responsible as operator, contracting party, employer or entity subject to a legal obligation
| City | Operator | SIREN | SIRET | Museum address | Contact address |
|---|---|---|---|---|---|
| Paris | PARIS & CRO SAS | 848 130 605 | 84813060500027 | 98 rue Saint-Denis, 75001 Paris | 40 rue Alexandre Dumas, 75011 Paris |
| Lille | MI LILLE SAS | 981 993 363 | 98199336300028 | 101 Avenue Le Corbusier, 59800 Lille | 40 rue Alexandre Dumas, 75011 Paris |
| Bordeaux | MI BORDEAUX SAS | 920 319 480 | 92031948000025 | Rue du Château d'Eau - Les Passages Mériadeck, 33000 Bordeaux | 40 rue Alexandre Dumas, 75011 Paris |
| Marseille | MI MARSEILLE SAS | 911 004 489 | 91100448900033 | 96 Rue Paradis, 13001 Marseille | 96 Rue Paradis, 13001 Marseille |
| Lyon | MOI LYON SAS | 889 120 663 | 88912066300022 | 16 Rue Cuvier, 69006 Lyon | 16 Rue Cuvier, 69006 Lyon |
MOI France HoldCo SAS, SIREN 106 176 217, 40 rue Alexandre Dumas, 75011 Paris, is the French holding company. It is not a controller merely because it is the holding company and acts as controller only for processing activities for which it itself determines the purposes and means.
For group-level processing for which they jointly determine the essential purposes and means - including website and ticketing architecture, CRM, segmentation, marketing, the data warehouse, system administration, retention standards and certain group reporting - Metamorfoza d.o.o., Radnička cesta 21, 10000 Zagreb, Croatia, and RP Illusions Corp., 7975 N. Hayden Road, Suite D-280, Scottsdale, AZ 85258, USA act as joint controllers within the meaning of Article 26 GDPR. The French companies do not become joint controllers of those group-level activities merely because they use the systems or locally implement group-defined processes; however, they remain controllers for local processing specific to them or required by law.
Metamorfoza d.o.o. and RP Illusions Corp. have allocated their responsibilities under an Article 26 joint-controller arrangement. In essence, they jointly determine the essential purposes and means of group-level processing and cooperate on transparency, security, data-subject rights, breach management, processors and international transfers. You may exercise your rights against either joint controller and, where relevant, against the French company concerned. To simplify handling, we use the common contact point stated below.
3. Data protection contact
For any question or request concerning your personal data: [email protected]. This common contact point may receive requests addressed to Metamorfoza d.o.o., RP Illusions Corp. and, where relevant, the French company concerned. You may also write to Data Protection Contact, MOI France HoldCo SAS, 40 rue Alexandre Dumas, 75011 Paris, France, which will route the request to the relevant controller(s)
4. Personal data we may process
- Identity and contact details: name, email, telephone, address or postcode where necessary.
- Booking and transaction data: Museum, date and time, ticket category and quantity, order number, amount, discounts, history, status, cancellations, refunds and complaints.
- Payment: status, amount, reference, payment method and limited information provided by the payment service provider. Full card data is processed by the payment provider and is not retained by MOI.
- Compte, service client et B2B: identifiants de compte, préférences, demandes, réclamations, coordonnées professionnelles, groupes, écoles et événements.
- Account, customer service and B2B data: account identifiers, preferences, enquiries, complaints, professional contact details, groups, schools and events.
- Marketing and profiling: consent choices, source and date of choice, unsubscribe history, purchases and visits, segments based for example on location, spend, frequency and behaviour, and advertising audiences where the required choices have been made.
- Browsing and device data: IP address, technical identifiers, device, browser, pages viewed, events and cookie or tracker data according to your choices.
- Photos, videos and content: only under the conditions communicated when collected.
- Security: CCTV/video-protection footage, security logs and information needed to manage an incident.
- Health and accessibility: only where you choose to provide information needed to respond to an accessibility request or manage an emergency.
- Competitions, prize draws and surveys: where we offer these activities, entry data, responses, preferences, eligibility information and contact details needed to administer the activity and, where applicable, deliver a prize.
Where certain data is necessary to enter into or perform a contract, comply with a legal obligation or provide a service you request, the relevant fields are identified as required at the point of collection. If you do not provide that data, we may be unable to complete your booking or provide the requested service. Marketing consents and other optional information are not required to purchase a ticket or visit a Museum.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Booking, purchase, ticket delivery, admission, changes and refunds | Contract or pre-contractual steps |
| Payment, invoicing, accounting and tax | Contract and legal obligations |
| Customer service, complaints, lost property, visit safety | Contract, legal obligations and legitimate interests |
| Competitions, prize draws and surveys where offered | Performance of applicable rules or participation terms where necessary; legitimate interests in improving our services for non-promotional satisfaction surveys; separate consent for any direct marketing |
| System security, fraud prevention and logging | Legitimate interests and security obligations |
| Newsletter, email, SMS and B2C telephone marketing | Prior consent; MOI France does not use soft opt-in as an operational practice |
| Segmentation, retargeting, advertising audiences and non-essential cookies | Consent where required; legitimate interests only where legally permitted |
| Audience measurement | Consent unless the tool is lawfully configured to qualify for a CNIL exemption |
| Voluntary health or accessibility information | Explicit consent where required; vital interests or other lawful bases in emergencies |
| CCTV | Legitimate interest in protecting people and property, within the French Internal Security Code framework |
| Due diligence, financing, restructuring, merger, acquisition or disposal | Legitimate interests in organising and completing corporate transactions, subject to individuals’ rights and freedoms; legal obligation where applicable |
| Legal claims, audits, compliance and regulatory duties | Legal obligation or legitimate interests |
6. Marketing and communications
Visitors are not automatically enrolled in a newsletter. Email, SMS and telephone consents are separate, optional and unticked. Refusal does not prevent ticket purchase or a visit. You may withdraw consent at any time.
We retain evidence of marketing choices, including at least the channel, date and time, source, relevant identifier and the version of the wording displayed. Where a person unsubscribes or objects, we retain only the minimum information needed on a suppression list to prevent accidental re-enrolment.
Transactional emails necessary for a booking, payment, ticket, refund or service expressly requested are not marketing communications.
7. Cookies and other trackers
Non-essential trackers are blocked until you make a choice. You can accept, reject or customise your preferences and later change them through the “Manage cookies” link. Current categories, providers, purposes and lifetimes are available in the cookie manager and our Cookie Policy.
8. Children, families and school groups
Our services are not specifically directed at young children. We minimise children’s data. Information for birthday parties or school groups is kept to the minimum and deleted when no longer needed. We do not use children’s data to create behavioural advertising audiences.
Where a child’s consent is relied on for an information-society service offered directly to that child, the applicable French rules are followed. For a child under fifteen, joint consent of the child and the holder of parental responsibility is obtained where that rule applies.
9. Recipients and service providers
On a need-to-know basis, data relating to group-level processing may be handled by authorised teams of Metamorfoza d.o.o. and RP Illusions Corp. in their capacity as joint controllers. Data relating to local processing may be handled by authorised teams of the relevant French company. Service providers may also be involved for ticketing, payments, CRM, email/SMS, cloud, cybersecurity, analytics, advertising, hosting and support, according to their contractual role.
Group systems include, depending on the processing, Roller, Microsoft 365/Azure, Klaviyo, HubSpot, Snowflake, Workday, TalentLyft and advertising platforms such as Meta, Google or TikTok. Providers and roles may change; the current record is maintained internally and, for cookies, in the consent manager.
We may also disclose personal data, where necessary and within the limits permitted by law, to courts, supervisory authorities, tax authorities, law-enforcement bodies and other competent public authorities, and to our lawyers, advisers, auditors and other professional advisers to establish, exercise or defend legal claims or comply with legal obligations.
In connection with a contemplated or completed financing, restructuring, merger, acquisition or disposal, we may disclose strictly necessary personal data to investors, lenders, prospective purchasers, counterparties and their advisers, subject to appropriate confidentiality and data-minimisation safeguards.
Our websites and communications may contain links to third-party websites or social-media platforms. Those third parties process certain data under their own privacy notices. Where you provide information directly to such a platform, its own terms also apply; where MOI subsequently receives or processes data about you through that platform, MOI’s processing is covered by this Policy.
10. International transfers
RP Illusions Corp. is a joint controller established in the United States, and certain teams or service providers may also access data from countries outside the European Economic Area, including the United States and the United Kingdom. Where required by the GDPR, the transfer to RP Illusions Corp. or another recipient outside the EEA relies on the applicable transfer mechanism documented by the group, including an adequacy decision where it validly covers the recipient or appropriate safeguards such as the European Commission Standard Contractual Clauses, supplemented where necessary by a transfer assessment and additional measures.
You may request information about the applicable safeguards by writing to [email protected].
11. Retention
| Category | Period |
|---|---|
| Customer profile and booking | Generally 3 years after the last purchase, visit or active contact, then deletion or anonymisation subject to legal archives |
| Invoices and accounting documents | 10 years from the relevant financial year-end |
| Contract evidence and complaints | For the relationship and applicable limitation period, generally up to 5 years |
| Customer marketing | During the relationship and up to 3 years after its end or last active contact |
| Prospect marketing | Up to 3 years after collection or the prospect’s last active contact |
| Suppression list | At least 3 years, minimum data only |
| Cookies | According to Cookie Policy; consent/refusal choice generally 6 months |
| CCTV | A few days where possible and no more than 30 days, except footage extracted for an incident or proceeding |
| Child event data | Deleted shortly after the event where no other purpose remains |
| Competitions and surveys | For the period needed to administer the activity and, where applicable, deliver a prize, followed only by limited evidence for the applicable limitation period; data separately used for marketing follows the marketing periods above |
| Promotional photo/video | For the period stated in the authorisation and reviewed on expiry |
| Rights requests | During handling and evidence retained 3 years unless a dispute requires longer |
| Backups | System-specific rotation cycle; backups are not used for active processing and are overwritten according to the technical schedule |
12. Your rights
- access and a copy;
- rectification;
- erasure where the conditions are met;
- restriction of processing;
- objection to processing based on legitimate interests and an absolute right to object to direct marketing;
- portability where the conditions are met;
- withdrawal of consent at any time, without affecting prior lawful processing;
- instructions concerning your data after death under French law.
To exercise your rights, write to [email protected]. We generally respond within one month. Proportionate identity verification may be requested where necessary.
You may lodge a complaint with the CNIL: Commission nationale de l’informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France - www.cnil.fr.
13. Security
We use technical and organizational measures appropriate to risk, including permission management, multi-factor authentication on relevant systems, encryption of devices and services where available and configured, backups, user onboarding and offboarding procedures, access reviews, training and incident response.
14. Automated decisions and profiling
We use marketing segments and audiences to tailor and measure campaigns. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you unless we specifically inform you and apply the safeguards required by law.
15. Changes to this Policy
We may update this Policy to reflect legal, organisational, technical or service changes. The current version is published with its update date. A new purpose requiring consent will be subject to a new consent request.
The French and English versions are provided to assist understanding. In the event of inconsistency, the French version prevails, subject to applicable mandatory law.