Privacy Policy & GDPR Data Protection

1. Data Controller

This Privacy Policy explains how personal data is collected, processed, and protected when you use our website https://www.chocotopia.cz/.

The data controller responsible for processing your personal data is:

Musée Grévin Prague s.r.o.
Company ID (IČO): 29128285
Registered office: Celetná 596/15
Prague 1 – Staré Město
110 00 Prague
Czech Republic

Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 202065.

If you have any questions regarding the processing of your personal data, you can contact us at:

📧 gdpr@chocotopia.cz


2. What Personal Data Means

Personal data refers to any information that can identify a natural person, either directly or indirectly.

This includes, for example:

  • Name and surname

  • Email address

  • Phone number

  • Postal code

  • Date of birth

  • IP address

  • Online identifiers such as cookies


3. Personal Data We Collect

We only process personal data that is necessary to provide our services and improve the user experience.

Data provided directly by you

If you register or interact with our services, we may collect:

  • Email address

  • First name and last name

  • Postal code

  • Date of birth

  • Consent of a legal guardian if a child is registered

If a complaint or claim must be handled, we may also process:

  • Phone number

  • Address for handling complaints

Data collected automatically

When you visit our website or social media pages, certain technical data may be collected automatically:

  • IP address

  • Date and time of your visit

  • Operating system and browser type

  • Screen resolution

  • Website interaction data

  • Cookies and similar technologies

We use cookies and tracking technologies such as:

  • Google Analytics

  • Google Ads

  • Facebook Pixel

These technologies help us analyze traffic, improve website functionality, and provide relevant content.

Cookies do not directly identify users and are never used to obtain sensitive personal data.


4. Purpose of Processing Personal Data

Your personal data may be processed for the following purposes:

  • Responding to inquiries and handling customer requests

  • Managing complaints or service requests

  • Sending newsletters and marketing communications (with your consent)

  • Providing special offers or benefits to registered customers

  • Analyzing customer preferences and website usage

  • Improving website functionality and user experience

  • Measuring marketing campaign performance


5. Legal Basis for Processing

We process personal data based on one or more of the following legal grounds under Article 6 of the GDPR:

  • Consent – for newsletters and marketing communications

  • Contractual necessity – when processing is required to provide requested services

  • Legitimate interest – for website analytics, service improvements, and communication with customers

  • Legal obligations – where required by applicable law


6. Data Sharing and Third Parties

Your personal data may be processed by:

  • Authorized employees of the company

  • Selected service providers or partners supporting our operations

These partners may include providers of:

  • Website hosting

  • Analytics services

  • Marketing and advertising platforms

  • IT infrastructure and support

All partners are contractually obligated to maintain confidentiality and process data in accordance with GDPR requirements.

Personal data may also be disclosed to public authorities if required by law.


7. Data Security

We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or disclosure.

These measures include:

  • Secure data storage systems

  • Password protection

  • Encrypted data transmission

  • Access control for authorized personnel only


8. Data Retention

Personal data is stored only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Legal and accounting obligations

  • Customer service requirements

  • Legitimate business needs

Once the retention period expires, personal data is securely deleted or anonymized.


9. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • The right to access your personal data

  • The right to correct inaccurate or incomplete data

  • The right to request deletion of personal data (“right to be forgotten”)

  • The right to restrict processing

  • The right to data portability

  • The right to object to processing based on legitimate interests

  • The right to withdraw consent at any time

  • The right to lodge a complaint with a supervisory authority

If you wish to exercise any of these rights, please contact us at:

📧 gdpr@chocotopia.cz


10. Cookies

Our website uses cookies to improve user experience and analyze website performance.

Cookies are small text files stored on your device when visiting our website.

You may manage or disable cookies through your browser settings at any time.

However, disabling certain cookies may affect website functionality.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or our data processing practices.

The latest version will always be available on our website.

 

Hey! Did you know that chocolate have a secret story behind?

Come to Choco-Story museum and find out!