1. Controller and Data Protection Contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
ILN Hamburg GmbH - Museum of Illusions Hamburg
Lilienstrasse 14-16
20095 Hamburg
Germany
Telephone: +49 40 3070 7105
Email: [email protected]
Website: https://hamburg.museumderillusionen.de/
Represented by its management.
If you have any questions about data protection or wish to exercise your data protection rights, you may
contact us at the email address stated above.
2. Subject Matter and Scope
This Privacy Policy explains how we process personal data when you visit our website, use our online ticket
shop, purchase tickets or vouchers, submit contact or enquiry forms, use our AI chatbot, exercise a right of
withdrawal, or communicate with us by email, telephone or other means.
Personal data means any information relating to an identified or identifiable natural person. This includes, for
example, your name, email address, booking details, payment information, IP address and information you
provide to us in messages or forms.
3. General Legal Bases
We process personal data in particular on the following legal bases:
- Article 6(1)(a) GDPR, where you have given us your consent;
- Article 6(1)(b) GDPR, where processing is necessary in order to take steps prior to entering into a contract,
to perform a contract or to reverse a contract; - Article 6(1)(c) GDPR, where we are required to comply with a legal obligation;
- Article 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights do not override those interests.
The requirements of the German Telecommunications Digital Services Data Protection Act
(Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG) additionally apply to the storage of information on your terminal device or access to information already stored on it. We use cookies and comparable technologies that are not technically necessary only on the basis of your consent. Where the applicable conditions are met, technically necessary access is based on Section 25(2) TDDDG.
4. Retention Period
We retain personal data only for as long as is necessary for the respective purpose. The data will then be
deleted or anonymised unless statutory retention obligations, legitimate interests in continued storage, or the
establishment, exercise or defence of legal claims prevent this.
Contractual, booking and payment records are retained in accordance with commercial and tax law
requirements. Data retained for evidentiary purposes may generally be stored until the applicable statutory
limitation periods have expired.
5. Provision of the Website and Server Log Files
When you access our website, the web server processes technically necessary data. This may include, in particular:
- the IP address of the terminal device accessing the website;
- the date and time of access;
- the page or file accessed;
- the volume of data transferred and the access status;
- the referrer URL;
- browser type, browser version and operating system;
- the hostname of the terminal device accessing the website.
Processing serves to provide the website securely and reliably, analyse errors, prevent attacks and administer the website technically. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our online services.
We use services provided by SiteGround to host our website. SiteGround processes data generated during the operation of the website on our behalf, unless the service provider acts as an independent controller.
6. Cookies and Consent Management
Our website uses cookies, pixels, local storage technologies and comparable technologies. Some of these technologies are necessary to provide the website and its basic functions. Other technologies are used for audience measurement, analytics, personalisation or advertising.
When you first visit our website, you can use the consent banner to select which optional categories you permit. Technologies that are not necessary are activated only after you have given your consent. You can change or withdraw your selection at any time via the "Cookie Settings" link at the bottom of the website.
We store your consent decision so that we can respect and demonstrate your selection. The legal bases are Article 6(1)(c) GDPR in conjunction with statutory accountability obligations and Article 6(1)(f) GDPR for the technically reliable management of your decision.
7. Contact and Enquiry Forms
7.1 Contact by Email or Telephone
If you contact us by email or telephone, we process the data you provide, in particular your name, contact details, the content of your enquiry and, where applicable, booking or contract data.
Processing is carried out in order to respond to your enquiry. If the enquiry relates to a contract or steps taken prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR. In other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the appropriate handling and documentation of enquiries.
We use Microsoft 365 and Exchange Online for email communications. The provider for the European Economic Area is generally Microsoft Ireland Operations Limited. Where Microsoft processes data on our behalf, this is done on the basis of an agreement pursuant to Article 28 GDPR.
7.2 Contact, Group and Event Forms
Our website provides forms for general contact enquiries and for group visits, school classes, birthdays, corporate events and other services. Depending on the form, we may process, in particular, your name, company or institution, email address, telephone number, preferred date and time, number of participants and other information.
Mandatory fields are marked accordingly. The data is used to review your enquiry, prepare a quotation, arrange an appointment and prepare the requested service. The legal basis is Article 6(1)(b) GDPR. Where the enquiry is not aimed at entering into a contract, processing is based on Article 6(1)(f) GDPR.
8. Online Ticket Shop and Booking Processing via bookingkit
We use the bookingkit platform to sell and manage tickets, vouchers and other bookable services. The provider is bookingkit GmbH, Sonnenallee 223, 12059 Berlin, Germany.
When you place an order, the following data in particular may be processed:
- first name and surname;
- email address and, where applicable, telephone number;
- booking and order details, ticket categories, date of visit and number of participants;
- voucher codes and redemption information;
- payment status and billing-related information;
- IP address, timestamps, device and browser information;
- communications relating to the booking.
Processing serves to take steps prior to entering into and to perform the contract, send the booking confirmation and tickets, control admission, communicate with customers, process payments, handle rebookings, complaints and refunds, and comply with statutory retention obligations.
The legal bases are Article 6(1)(b) GDPR for contract processing, Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for fraud prevention, protection against misuse and technical security.
bookingkit processes data partly as our processor. Where bookingkit or integrated payment service providers fulfil their own legal obligations or independently determine certain processing purposes, they may act as independent controllers. Further information: https://bookingkit.com/de/datenschutzerklaerung/
9. Payment Processing
The payment and transaction data required to process online payments is transmitted to the payment service provider selected during the ordering process. Depending on the payment method, this may include your name, billing details, amount, currency, payment method, transaction identifier, device and connection data, and information used to prevent fraud.
Processing is carried out for the performance of the contract pursuant to Article 6(1)(b) GDPR and, where necessary, to comply with legal obligations and prevent fraud.
Stripe is used for part of the payment processing. Stripe processes certain payment data under its own responsibility, particularly for payment authorisation, fraud prevention and compliance with regulatory obligations. Further information: https://stripe.com/de/privacy
If you select a digital wallet such as Apple Pay or Google Pay, data may additionally be transmitted to the
respective wallet provider. The privacy policies of the respective provider also apply to such processing.
10. Electronic Withdrawal Function
If you exercise a statutory right of withdrawal, in particular via the electronic withdrawal function we provide pursuant to Section 356a of the German Civil Code (Buergerliches Gesetzbuch, BGB), we process the personal data you submit.
10.1 Purposes of Processing
- receiving and assigning your notice of withdrawal;
- identifying the relevant contract or part of the contract;
- sending the legally required acknowledgement of receipt;
- reviewing and processing the withdrawal;
- communicating in connection with the withdrawal;
- reversing the contract and arranging any necessary refund;
- complying with statutory documentation and retention obligations;
- establishing, exercising or defending legal claims.
10.2 Data Processed
- identification data, in particular first name and surname;
- contract and booking data, in particular the booking or order number and the part of the contract affected by the withdrawal;
- contact details, in particular an email address or another means of electronic communication for the acknowledgement of receipt;
- the content of the notice of withdrawal, date and time of receipt, and processing status;
- payment and refund data, where required for repayment;
- technical log data, in particular the timestamp of receipt and, where applicable, the IP address;
- voluntary additional information, for example a voluntarily stated reason for withdrawal.
10.3 Legal Bases
The legal bases are Article 6(1)(c) GDPR in conjunction with Section 356a BGB, insofar as we comply with legal obligations to provide and document the withdrawal function, Article 6(1)(b) GDPR for reviewing the withdrawal and reversing the contract, and Article 6(1)(f) GDPR for preserving evidence and defending against unjustified claims.
10.4 Mandatory and Voluntary Information
To use the electronic withdrawal function, you must provide your name, information identifying the contract or part of the contract, and a means of electronic communication for the acknowledgement of receipt. Providing a reason for withdrawal is voluntary and does not affect the validity of the withdrawal.
The data is transmitted to bookingkit as the technical provider of the withdrawal function and, where required for a refund, to the original payment service provider.
11. PUNKU AI Chatbot
We offer an AI-powered chatbot on our website through which you can ask general questions about the museum, tickets, opening hours and services. The chatbot solution is provided by PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn, Germany. Processing is performed via the PUNKU API using the Anthropic Claude API (USA) for AI language processing. The chat widget is technically delivered via a content delivery network (CDN) at cdn.jsdelivr.net. Processing takes place in Germany, the USA and Poland (jsDelivr CDN).
When you use the chatbot, chat messages, timestamps, session ID, browser and device information, and technical connection data may be processed in particular. Please do not submit health data, payment data, identity document data or other particularly sensitive information via the chatbot.
Processing is carried out in order to respond to your enquiry and provide efficient customer service. For enquiries relating to a contract, the legal basis is Article 6(1)(b) GDPR. For general requests for information, processing is based on Article 6(1)(f) GDPR.
PUNKU may engage additional service providers for technical language processing, including AI and CDN providers. This may involve transfers to third countries. PUNKU processes the data within the scope of the commissioned processing agreed with us. According to the information currently available, chat histories are deleted after 30 days.
Further information: https://www.punku.ai/de/privacy
12. Spam and Misuse Protection by CleanTalk
We use CleanTalk to protect our forms and website functions against spam, automated submissions, misuse and technical attacks. The provider is CleanTalk Inc., 111 Barclay Blvd, Suite 202, Lincolnshire, IL 60069, USA.
CleanTalk may process, in particular, your IP address, email address, technical browser and device
information, timestamps, form data and other characteristics required to detect automated or abusive submissions.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the security of our website, protection against spam and misuse, and the reliable processing of legitimate enquiries. Where CleanTalk uses cookies or similar technologies that are not technically necessary, these are activated only after you have given your consent.
As the provider is based in the USA, data may be transferred to the USA. Any such transfer is made only in compliance with Articles 44 et seq. GDPR. Further information: https://cleantalk.org/privacy
13. Google Analytics 4
We use Google Analytics 4 to analyse the use of our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics may process, in particular, information about page views, sessions, interactions,
approximate location, browser, operating system, device type, referrer URL and pseudonymous online identifiers. According to Google, IP addresses of users from the European Union are discarded before being logged.
Google Analytics is activated only if you have consented via the consent banner. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future via the Cookie Settings.
Google may also process data in the USA. Data is transferred on the basis of the statutory requirements governing transfers to third countries, in particular an applicable adequacy decision or appropriate safeguards.
The retention period is 14 months.
Further information: https://policies.google.com/privacy
14. Google Ads Conversion Tracking
We use Google Ads conversion tracking on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Conversion tracking allows us to determine whether users perform certain actions on our website after clicking on or interacting with one of our Google advertisements, for example completing a ticket booking. This enables us to measure the effectiveness of our advertising and evaluate and optimise our Google Ads campaigns.
Depending on the technical configuration, the following information in particular may be processed:
- IP address and technical connection data;
- browser, device and operating system information;
- pages accessed and referrer information;
- the time and type of an interaction;
- cookie or comparable online identifiers;
- information on whether a conversion defined by us has been completed;
- where applicable, the conversion value and currency.
Google uses conversion and event data, among other things, to create campaign and performance reports and to optimise advertising campaigns and automated bidding strategies.
Google Ads conversion tracking is activated on our website only if you have previously given your consent via our consent management system. The legal bases are your consent pursuant to Article 6(1)(a) GDPR and, insofar as information is stored on or read from your terminal device, Section 25(1) TDDDG.
You may withdraw or change your consent at any time with effect for the future via the Cookie Settings on our website.
Google may also process the collected data under its own responsibility for data protection purposes. The Google Ads Controller-Controller Data Protection Terms apply to certain Google Ads services.
The use of Google Ads may also involve the processing of personal data outside the European Union or the European Economic Area, in particular in the USA. Data is transferred in accordance with the statutory requirements of Articles 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or appropriate safeguards.
Further information on Google's processing of personal data can be found in Google's Privacy Policy and privacy information.
15. Meta Pixel
We use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland ("Meta") on our website.
The Meta Pixel enables us to measure whether users perform certain actions on our website after clicking on or viewing an advertisement on Facebook or Instagram, for example completing a ticket booking. This allows us to measure the effectiveness of our advertising, attribute conversions to our advertising campaigns, and evaluate and optimise our campaigns.
Depending on the configuration of the Meta Pixel, the following information in particular may be processed and transmitted to Meta:
- IP address and technical connection data;
- browser, device and operating system information;
- pages accessed and referrer information;
- the time and type of interactions on our website;
- cookies and other online identifiers;
- information about events defined by us, for example completion of a ticket booking;
- where applicable, the conversion value and currency.
Meta may combine information collected via the Meta Pixel with other information. If you use Facebook or Instagram and are logged in, Meta may be able to associate the collected information with your user account.
The Meta Pixel may also collect data from individuals who do not have a Facebook or Instagram account.
The Meta Pixel is activated on our website only if you have previously given your consent via our consent management system. The legal bases are your consent pursuant to Article 6(1)(a) GDPR and, insofar as information is stored on or read from your terminal device, Section 25(1) TDDDG.
You may withdraw or change your consent at any time with effect for the future via the Cookie Settings on our website.
With regard to the collection and transmission of certain event data via the Meta Business Tools, we and Meta act in part as joint controllers pursuant to Article 26 GDPR in accordance with Meta's terms. Meta has provided a corresponding Controller Addendum for this purpose. Meta is generally independently responsible for subsequent processing of the data for its own purposes.
Meta may also process personal data outside the European Union or the European Economic Area, in particular in the USA. Data is transferred in accordance with the statutory requirements of Articles 44 et seq.
GDPR, in particular on the basis of an applicable adequacy decision or appropriate safeguards.
Further information about Meta's processing of personal data and options for managing privacy and advertising settings can be found in Meta's privacy information.
16. Reviews on Google and Tripadvisor
Our website provides links that visitors can use to review our museum on Google or Tripadvisor. We do not offer our own review form and do not process review data through our website.
When you click on a review link, you will be redirected to the website of the respective platform operator. From that point onwards, the respective provider processes personal data under its own responsibility for data protection purposes. Google's or Tripadvisor's privacy policies apply to this processing. We have no influence over the nature, scope or duration of such data processing.
External Links and Social Media Profiles
Our website contains links to external websites and social media platforms. When you open such a link, you leave our online services. From that point onwards, the respective operator is responsible for any further processing of personal data. Please refer to the privacy policies of the respective providers.
18. Job Applications
If you apply to us by email, we process your contact details, application documents, qualifications and other information you submit for the purpose of conducting the application procedure.
The legal basis is Section 26 of the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) in conjunction with Article 6(1)(b) GDPR. If you expressly consent to longer retention for future job opportunities, processing is based on Article 6(1)(a) GDPR. Application data is generally deleted after the procedure has been completed, as soon as there are no statutory or legal grounds for further retention.
19. Data Security
We take appropriate technical and organisational measures to protect the personal data we manage against accidental or intentional manipulation, loss or destruction, and against access by unauthorised third parties.
Data transmission between your browser and our website is encrypted using TLS/SSL. Our security measures are continuously improved in line with technological developments.
Despite appropriate safeguards, data transmission over the internet cannot be entirely risk-free. Please do not send particularly confidential information by unencrypted email.
20. Rights of Data Subjects
Subject to the applicable statutory requirements, you have the following rights in particular:
- access to the personal data processed about you pursuant to Article 15 GDPR;
- rectification of inaccurate data or completion of incomplete data pursuant to Article 16 GDPR;
- erasure of your data pursuant to Article 17 GDPR;
- restriction of processing pursuant to Article 18 GDPR;
- data portability pursuant to Article 20 GDPR;
- objection pursuant to Article 21 GDPR to processing based on Article 6(1)(e) or (f) GDPR;
- withdrawal of consent with effect for the future pursuant to Article 7(3) GDPR;
- lodging a complaint with a data protection supervisory authority pursuant to Article 77 GDPR.
21.Complaints to a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority with particular responsibility for us is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Klosterwall 6 (Block C), 20095 Hamburg, Germany
Telephone: +49 (0)40 42854-4040
E-Fax: +49 (0)40 4279-11811
Email: [email protected]
Website: https://datenschutz-hamburg.de/
You may also contact another data protection supervisory authority, in particular the authority at your habitual residence, place of work or the place of the alleged infringement.
22. Obligation to Provide Data
The provision of personal data is generally voluntary. However, certain information is required in order to enter into a contract, process a booking, make a payment, assign a withdrawal or respond to an enquiry. Without the information marked as mandatory, we may be unable to provide the respective service.
23. Amendments to this Privacy Policy
We amend this Privacy Policy whenever legal requirements, our data processing activities or the services we use change. The version published on our website at the relevant time applies.
24. Right to Object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you may object to such processing at any time without stating reasons.
Version: August 2026