Eureka! Privacy Statement for Museum Visitors

Looking after your personal information is very important to us.
We want you to be confident that your personal data is kept safely and securely.

Eureka! The National Children’s Museum (“Eureka!”) is committed to complying with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. We will only use your personal data on relevant lawful grounds as permitted by the GDPR and the Data Protection Act.

Eureka! will be what is known as the ‘Data Controller’ for the personal data visitors provide to us.

We have published this notice to help you understand:-

  • how and why Eureka! collects information from you;
  • who we share your information with, why and on what basis; and
  • what your rights are.

 

What information we gather, from whom, and how and why we use it:


Who

What

How

Why

Legal Basis*
Families
Names, address, dates of birth, phone number and email address
At our admissions desk or on our website
To enable you to use our annual pass system and receive unlimited visits to the museum for free for a year.
Legitimate interest

Name and address

At our admissions desk or on our website

To process your Gift Aid donation

Legitimate interest
Email address At our admissions desk or on our website To receive our regular marketing emails telling you about what’s happening at Eureka! and other offers, news and events that might be of interest. Consent
Schools and Groups Booking organiser’s name, email address and telephone number Over the phone or by email To discuss and confirm essential information about your booking Legitimate interest
Booking organiser’s name and email address Over the phone or by email To receive our schools marketing emails, sent occasionally to tell you about education events and programmes at Eureka! Consent
Attendees at Access All Areas activities or Home Educator Days Booking organiser’s name, email address and phone number Over the phone or by email To confirm essential information about your booking Legitimate interest
Personal information relating to specific access requirements Over the phone or by email To help us meet your needs during your visit. Legitimate interest
Booking organiser’s name, email address Over the phone or by email To receive our marketing emails, sent occasionally to tell you about Access All Areas or Home Educator events, as appropriate,  at Eureka! Consent
All of the above Names, address, dates of birth, phone number and email address At our information desk, over the phone or by email To respond to complaints and/or accidents Legitimate interest
Closed Circuit TV Cameras are located in communal areas inside and outside the Eureka! building To ensure safety of visitors, contractors and staff Legitimate interest

Eureka! may also collect, use and process the following information which is designated as a special category and which requires a higher level of protection because it is of a more sensitive nature:

  • Information about medical or health conditions, including whether or not you have a disability for which the organisation needs to make reasonable adjustments

* Explanation of legal basis for processing

Consent: where you have provided your consent to receive certain marketing from us. You can withdraw your consent at any time, including by clicking on the “unsubscribe” link at the bottom of any marketing email we send you or by contacting us at the address below.

Legitimate interests: where it is necessary for us to hold your personal data in order for us to effectively facilitate your visit(s) to Eureka!

The above grounds for processing may overlap and there may be several grounds which justify our use of personal information.

Keeping your information safe and up-to-date

Eureka! is committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.

Data relating to your visit is held securely in our visitor database and, for annual pass holders, our online system, for five years or until you request we delete it – whichever comes soonest. Where a Gift Aid donation has been made, we are required by law to hold data relating to the donation for six years. CCTV images are retained for no longer than four weeks.

We will not share your information with anyone other than:

  • our approved Data Processors, who are fully compliant with General Data Protection Regulations (GDPR) and who will only process your data in accordance with this privacy notice.
  • HMRC, where a Gift Aid declaration has been made
  • official regulators

We will not transfer information to a country or territory outside the EEA (European Economic Area) unless that country or territory ensures an adequate level of protection for the rights, and freedoms of data subjects in relation to the processing of personal data. In the unlikely event that personal data needs to be transferred outside the EEA, your personal information will be anonymised.

The organisation may also share your data with third parties in the context of a sale of some or all of its business. In these circumstances the data will be subject to confidentiality arrangements.

We will not use your personal data for marketing purposes without your express consent.

Automated decision-making

Automated decision-making occurs when an electronic system uses your personal information to make a decision without human intervention. Eureka! does not make any decisions based on automated decision-making.

Your rights

You have the right to:

  • Request access to your personal information
    This is usually known as making a data subject access request and it enables you to receive a copy of the personal information we hold about you.
  • Request rectification of your personal information
    This enables you to have any inaccurate or incomplete personal information we hold about you corrected.
  • Request the erasure of your personal information where there is no compelling reason for its continued use – although this may prevent us from providing a service, e.g. such as use of the annual pass.
  • Restrict the processing of your personal information
    This enables you to ask us to suspend the processing of your personal information e.g. if you contest its accuracy and so want us to verify its accuracy.
  • Object to the processing of your personal information
    This enables you to ask us to stop processing your personal information where we are relying on the legitimate interest of the organisation as our legal basis for processing and there is something relating to your particular situation which makes you decide to object to processing on these grounds.
  • Data portability
    This gives you the right, in specific circumstances only, to request the transfer of your personal information to another party so that you can reuse it across different services for your own purposes.

If you would like to exercise any of these rights, or for any other data protection queries, please contact us at:

Data Compliance Manager
Eureka! The National Children’s Museum
Discovery Road
Halifax
HX1 2NE
data@eureka.org.uk

Changes to this privacy notice

We will keep our privacy policy under regular review and we will place any updates on our website. This policy was last updated on 24th May 2018.

Eureka! The National Children’s Museum
Discovery Road, Halifax HX1 2NE. Map