Privacy statement
Last updated: July 2026. This statement is issued in accordance with EU Regulation 2016/679 (GDPR).
Controller
The controller of your personal data is the EU-registered legal entity that operates this website ("Operator"). Contact for privacy matters: privacy@example.com.
What data we process
- Booking data: full name, email, phone number, country of residence, chosen ticket type, visit date and time, number and category of visitors.
- Payment data: card details are captured and processed exclusively by our PCI-DSS certified payment processor; the Operator receives only a masked reference and the amount.
- Technical data: IP address, browser user-agent, session identifier, page view sequence, timestamps of clicks and step transitions, referrer.
Purpose and legal basis
- Executing the booking contract (art. 6(1)(b) GDPR).
- Complying with tax and consumer-protection record-keeping duties (art. 6(1)(c) GDPR).
- Improving the service, detecting fraud and abuse (art. 6(1)(f) GDPR — legitimate interest).
Retention
Booking records are retained for 6 years to comply with EU tax record-keeping rules. Technical session data is retained for 90 days for security and analytics, then aggregated and pseudonymised.
Processors
- Payment processor: for card capture and settlement.
- Email delivery provider: for e-ticket and confirmation delivery.
- Cloud hosting: for encrypted storage of booking and session data (EU region).
Your rights under GDPR
You have the right to access, rectify, erase and port your personal data, to restrict or object to processing, and to lodge a complaint with your national data-protection authority. Send requests to privacy@example.com; we respond within one month.
Cookies
The site uses a strictly necessary session cookie to keep your wizard progress and language preference. No advertising or third-party tracking cookies are set without explicit consent. See the cookie banner for granular choices.