TRAVEL EXPERIENCE d.o.o. – Travel Experience Museum
Registered seat: Mate Vlašića 20, 52440 Poreč-Parenzo, Croatia – Museum location: Prolaz Neboder, Ilica 1A, 10000 Zagreb – OIB: 03857142786
Version 3.3 – August 2026 (supersedes all previous versions)

This Policy applies to the website travelexperiencemuseum.com, to the subdomain ticketing.travelexperiencemuseum.com where tickets are purchased, and to processing on the museum premises.

 

I. WHO CONTROLS THE PROCESSING OF MY PERSONAL DATA?

 

The controller is TRAVEL EXPERIENCE d.o.o., Mate Vlašića 20, 52440 Poreč-Parenzo, OIB: 03857142786. We have appointed a Data Protection Officer (DPO) whom you may contact for any question about processing and to exercise your rights:
e-mail: gdpr@travelexperiencemuseum.com – post: Data Protection Officer, TRAVEL EXPERIENCE d.o.o., Mate Vlašića 20, 52440 Poreč-Parenzo.

 

II. FOR WHAT PURPOSES AND ON WHAT BASIS DO WE PROCESS YOUR DATA?

 

1. Purchase of tickets and products. We process your name, e-mail, phone, postal code, date of birth and order and transaction data in order to process the purchase and send you the confirmation, invoice and ticket. Purchases are made on the subdomain ticketing.travelexperiencemuseum.com and order data is stored in our own database with our hosting provider. Card payments are carried out by a payment service provider in its own secure environment; we neither collect nor store your card number. Legal basis: performance of a contract (Art. 6(1)(b)).

2. Bookings and event organisation (birthdays, celebrations, corporate events, school and group visits). We process contact and transaction data to manage the booking and payment. Legal basis: performance of a contract (Art. 6(1)(b)). If you provide allergy/intolerance information for personalisation, please do so without data identifying the individual; we do not process it on a personalised basis.

3. Customer support and enquiries. We process the data in your enquiry to respond and resolve it. Legal basis: steps at your request / legitimate interest (Art. 6(1)(b)/(f)).

4. Abandoned cart and satisfaction surveys. With your consent, or on the basis of our legitimate interest towards existing customers, we may send a reminder or a short survey. Legal basis: consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)); you may object at any time.

5. Newsletter and marketing. Only with your explicit consent do we send information on offers, discounts and museum events (e-mail). We use the Mailchimp platform and a double opt-in process. Legal basis: consent (Art. 6(1)(a)); you may unsubscribe at any time.

6. Social media. If you contact us via the museum’s profiles (Facebook, Instagram), we process the data in that communication to respond. Legal basis: legitimate interest / consent (Art. 6(1)(f)/(a)).

7. Photography and video recording on museum premises. Photography and recording may take place on the premises for promotion on the website, social media and promotional materials. Visitors are informed by a prominent notice at the entrance and may ask not to be recorded; for interviews and featured posts we obtain separate written consent. Legal basis: consent (Art. 6(1)(a)); exceptionally legitimate interest (Art. 6(1)(f)). Retention: until consent is withdrawn, and no longer than 3 years from publication.

8. Memorabilia collection programme (donations). When items are donated to the museum collection, we process the donor’s contact data and details of the donated item. Legal basis: performance of a contract / legitimate interest (Art. 6(1)(b)/(f)).

9. Cookies. We use first- and third-party cookies on the website; details are in our separate Cookie Policy. Analytics and marketing cookies are set only with your consent. Before consent is given we apply Google Consent Mode v2 in Advanced Mode, in which Google Analytics 4 does not place cookies on your device but does send Google cookieless pings containing your IP address, browser and device data and the referring page address. We rely on our legitimate interest in basic audience measurement for that processing (Art. 6(1)(f)) and you may object to it.

9.a Meta pixel and joint controllership. In respect of the collection of data via the Meta pixel and its transmission to Meta, we and Meta Platforms Ireland Limited act as joint controllers within the meaning of Art. 26 GDPR and in line with the case law of the Court of Justice of the European Union in Case C-40/17 (Fashion ID). Meta is responsible for any further processing it carries out for its own purposes. The essence of the joint controller arrangement is set out in Meta’s Controller Addendum, and enquiries may also be directed to gdpr@travelexperiencemuseum.com.

10. Legal obligations. We also process data to meet tax, accounting and other legal obligations. Legal basis: legal obligation (Art. 6(1)(c)).

Note: we do not carry out profiling or automated decision-making that produces legal effects or similarly significantly affects data subjects.

 

III. RETENTION PERIODS

 

Data relating to purchases, bookings and events are kept for the duration of the contractual relationship. Accounting records and invoice data are kept for eleven years from the end of the business year to which they relate, in accordance with the Croatian Accounting Act; this is a separate and longer period than those applying to marketing purposes. Customer support data is kept for as long as needed to resolve the enquiry and no longer than two years. Survey data is kept for up to 12 months. Data processed on the basis of consent (newsletter, recordings) is kept until consent is withdrawn, with recordings kept no longer than 3 years from publication. Records of cookie consent given or refused are kept for 12 months in order to demonstrate compliance. Once the purpose has expired we block the data for the limitation period and then erase it permanently.

 

IV. RECIPIENTS

 

We may disclose data to competent public authorities where required by law. We also use processors that act solely on our instructions under contracts compliant with Art. 28 GDPR: hosting and web platform (Plus Hosting Grupa d.o.o., Valturska 82, 52100 Pula, Croatia), card payment processing (payment service provider), maintenance of the ticket purchase system, cookie consent management (Usercentrics A/S, Denmark), newsletter delivery (Mailchimp), web analytics (Google), management of social media profiles and campaigns (external digital marketing and analytics agency), and IT and customer support. We generally engage processors within the EU/EEA. A list of the specific processors is available on request at gdpr@travelexperiencemuseum.com.

 

V. TRANSFERS TO THIRD COUNTRIES

 

Certain service providers (Mailchimp, Google and Meta/Facebook/Instagram) may process data outside the EU/EEA, including in the United States. We carry out such transfers with appropriate safeguards under Art. 46 GDPR – the EU-US Data Privacy Framework or standard contractual clauses – or to countries covered by a European Commission adequacy decision. You may request a copy of the applied safeguards at gdpr@travelexperiencemuseum.com.

 

VI. YOUR RIGHTS

 

You have the right to access, rectification, erasure, restriction, portability and objection, including objection to direct marketing. You may withdraw consent at any time (without affecting the lawfulness of prior processing). Submit requests to the DPO at gdpr@travelexperiencemuseum.com or by post to the registered seat; we may request proof of identity. We respond without undue delay and at the latest within one month (extendable by two months depending on complexity). Exercising your rights is free of charge.

 

VII. SOURCE OF DATA

 

We generally collect data directly from you, via the website and during our relationship. If you provide data of other individuals (e.g. co-visitors or a child), you undertake to first obtain their consent, or that of the parent/guardian.

 

VIII. MINORS

 

Under the Croatian Act implementing the GDPR (Art. 19), processing a child’s personal data based on consent in relation to information society services is lawful where the child is at least 16 years old; for younger children, the consent of a parent or guardian is required. Where a parent/guardian voluntarily provides a child’s data (e.g. to organise an event), they do so on the child’s behalf and on the basis of their own consent, confirming they hold parental responsibility.

 

IX. COMPLAINT TO THE SUPERVISORY AUTHORITY

 

If you believe your rights have been infringed, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb; e-mail: azop@azop.hr; web: www.azop.hr. We recommend contacting our DPO first for a faster resolution.

 

X. CHANGES TO THIS POLICY

 

We may update this policy from time to time; the current version is published on the museum’s website with the date of update.

Version 3.3 – August 2026 (supersedes all previous versions)