Privacy statement
When you use the Muiderslot website, we process your personal data. We handle your personal data with care and we do so in accordance with the General Data Protection Regulation (AVG).
In this privacy statement we describe who we are, how and for what purpose we process your data, how you can exercise your privacy rights and any other information that may be of interest to you.
We have done our best to write down all the information clearly and comprehensibly. If you have any questions about the use of your personal data after reading this privacy statement, please contact us using the contact details at the bottom of this privacy statement.
For information on how we use cookies and similar techniques, please see our cookie statement.
We are constantly improving and developing our services at the Muiderslot. If this brings changes to the way we process personal data, it will be updated in this privacy statement. We therefore advise you to check this privacy statement regularly for changes. At the bottom of this privacy statement you can check when this privacy statement was last amended.
1. Privacy statement: who are we?
Rijksmuseum Muiderslot Foundation is the data controller for all processing of personal data by the Muiderslot. Our contact details are: Herengracht 1, 1398 AA Muiden, tel. +31 (0) 294 256262. If you wish to contact us, please use the contact details at the bottom of this privacy statement.
2. For what purposes do we use your data?
The Muiderslot processes your personal data for the following purposes:
Communications and marketing
We process your personal data to conduct marketing activities.
- Through this website or when purchasing an e-ticket, you can sign up for the online newsletter of the Muiderslot, which you will then receive by email up to 6 times a year.
- We ask for your phone number when purchasing an e-ticket or online group booking. This is to provide any practical information and to possibly call you once for questions about our program (education, Friends, etc.).
- We also ask online or at checkout for your zip code or country of origin to know where our visitors come from.
- This website uses Google Analytics Cookies. Data is not shared with Google and no other Google services are used in conjunction with Google Analytics cookies. A processor agreement has been concluded with Google for this purpose. Your full IP address cannot be traced (anonymizeip tracking). The Google Analytics cookies are automatically deleted after 26 months.
- We also use social media to answer your questions about our services.
For the following purposes, parties we work with process data from you:
Sale of e-tickets
For the sale of e-tickets for access to the Muiderslot you will enter the online environment of Gantner. Gantner is the data controller for this data processing and for questions regarding this, please refer to their website.
Audience survey
Of course we are curious about the opinion of our visitors. During or after your visit to the Muiderslot, we may ask you to participate in our online audience survey that is conducted by Hendrik Beerda Brand Consultancy (HBBC). HBBC is the data controller for this data processing and for questions about this we would like to refer you to their general terms and conditions. The Muiderslot only receives an aggregated report from HBBC on the results of the audience survey. This does not contain any personal data.
Digital newsletter
We send our digital newsletter with the program Mailchimp. For questions about how they handle your data, please refer to their terms and conditions.
3. What personal data do we process from you?
Muiderslot processes the following categories of personal data that you provide to us yourself when you visit our website, book a group visit with us, leave your details with us or contact us:
- Contact information (name, e-mail address, address, zip code, phone number, etc.)
- Marketing & Communications data (social media data etc.)
- Data read through cookies (geographic data, etc.)
4. On what legal basis do we process your personal data?
Any processing of personal data must be based on a legal basis as stated in the General Data Protection Regulation (GDPR). We process your personal data based on the basis “consent” given by you. It is always possible to withdraw your consent. See the heading “Can I withdraw my consent again?” below.
5. To whom do we provide your personal data?
We may provide your personal data to third parties if consistent with this privacy statement and to the extent permitted by law.
In certain cases it is required by law to provide your personal data to the police or other governmental parties. For example, if we have to comply with a court order or if this is necessary in the context of detecting criminal offenses.
These parties process your personal data only on the basis of our instructions and for the purposes we determine. The processors are contractually bound not to use your personal data for other purposes.
6. Is your personal data processed outside the European Economic Area?
Your personal data may be processed outside the European Economic Area. We have measures in place to ensure secure transmission whereby we comply with all legal requirements.
Your personal data is processed in the following countries:
- United States
To ensure an adequate level of data protection for transfers to the above countries, we have taken the following measures:
The parties processing our data:
- Are affiliated with the EU-US Privacy Shield, or
- have entered into standard contractual terms with us as established by the European Commission.
7. What is our retention period?
We delete or anonymize your personal data when it is no longer needed for the purposes outlined in this privacy statement. For example, if you have signed up for the newsletter, we will keep your data for as long as you wish to continue receiving this newsletter.
8. How can you exercise your privacy rights?
At any time, you can ask us to access, correct or delete your data. Furthermore, you can ask to restrict the processing of your personal data or object to your data processing, for example in the context of direct marketing or profiling. You can also exercise your right to data portability. If you wish to exercise any of these rights, please contact us using the contact details at the bottom of this privacy statement. Please note that we may ask for additional information to verify your identity.
9. Can I withdraw my consent again?
You can withdraw your given consent at any time. However, this withdrawal does not have retroactive effect.
If you no longer wish to receive our newsletter, you can unsubscribe at the bottom of the newsletter.
If you wish to withdraw your consent to other processing, please contact us using the contact information at the bottom of this privacy statement.
10. Where can I file a complaint?
If you have a complaint about how we handle your personal data, you can submit it to us using the contact information at the bottom of this privacy statement.
You can also file a complaint about how we handle your personal data with the privacy regulator, the Personal Data Authority. Address: Bezuidenhoutseweg 30, 2594 AV, The Hague or via www.autoriteitspersoonsgegevens.nl.
11. How can I contact the Muiderslot?
If you have any questions about the Muiderslot’s use of your personal data that are not answered in this privacy statement or you wish to exercise any of your privacy rights, please contact us using the information below:
Rijksmuseum Muiderslot Foundation
Attn: Ms. S. Heldens
Herengracht 1
1398 AA Muiden
info@muiderslot.nl
12. When was this privacy statement last modified?
This privacy statement was last modified on July 1, 2020.
Visit
Explore
Education
Stories
About us