At Merlin ("we", "us", "our"), we regularly collect and use personal data about individuals who visit our website “site”. Personal data is any information that can used to identify you as an individual. The protection of your personal data is very important to us, and we understand our responsibilities to handle your personal data with care, to keep it secure and to comply with legal requirements.
Please read this Policy carefully. It provides important information about how we use personal data and explains your legal rights. This Policy is not intended to override the terms of any contract that you have with us (for example, Wi-Fi terms and conditions or annual pass terms) or any rights you might have available under applicable data protection laws.
We will make changes to this Policy from time to time for example, to keep it up to date or to comply with legal requirements or changes in the way we operate our business. We will make sure that you are aware of any significant changes by sending an email message to the email address you most recently provided to us or by posting a notice on each relevant website so that you are aware of the impact to the data processing activities before you continue to engage. We encourage you to regularly check back and review this policy so that you will always know what information we collect, how we use it, and who we share it with.
Merlin Entertainments ("Merlin") is a British-based entertainment company, with a registered office at Link House, 25 West Street, Poole, Dorset, BH15 1LD, which operates over 120 attractions, and over 20 hotels and holiday villages in 25 countries. Our business is about creating unique, memorable and rewarding visitor experiences. Merlin will be the data controller for your personal data when you use our website.
In relation to Individuals who use our site, we collect the following data:
In emergency circumstances, we will also collect information about you indirectly from other sources where we believe this is necessary to help ensure the security of our site. These other sources may include public registers and social media platforms.
We will not knowingly collect any personal data about children for the purpose of marketing without making it clear that such information should only be provided with parental consent, if this is required by applicable laws - so Merlin will only use the personal data of children as far as is permitted by law where the required parental or guardian consent has been obtained.
We will use your personal data to:
We may also send you marketing materials (where we have appropriate permissions as explained in more detail below under Section 6). This process is likely to include profiling, and more information is provided at Section 8 of this Policy about this. We will also need to use your personal data for purposes associated with our legal and regulatory obligations.
We have to establish a legal ground to use your personal data, so we will make sure that we only use your personal data for the purposes set out in this Section 4 and in Appendix 1 where we are satisfied that:
We will not collect any special categories of personal data.
PLEASE NOTE: If we have previously told you that we were relying on consent as the basis of our processing activities, going forward we will not be relying on that legal basis unless we have said that are in this Policy.
We share your personal data with third parties, to help manage our business and deliver services. These third parties may from time to time need to have access to your personal data, and include:
Also, if we were to sell part of our businesses we would need to transfer your personal data to the purchaser.
We may use your personal data to send you direct marketing communications about our attractions, hotels, experiences or our related services. This will be in the form of email or targeted online advertisements.
Where we require explicit opt-in consent for direct marketing in accordance with the Privacy and Electronic Communications Regulations we will ask for your consent. Otherwise, for non-electronic marketing or where we can rely on the soft opt-in exemption under the Privacy and Electronic Communications Regulations, we will be relying on our Legitimate Interests for the purposes of GDPR as further detailed in section 4 and Appendix 1.
You have a right to stop receiving direct marketing at any time - you can do this by following the opt-out links in electronic communications (such as emails), or by contacting us using the details in Section 11.
We also use your personal data for customising or personalising advertisements, offers and content made available to you based on your visits to and/or usage of our company website, and analysing the performance of those advertisements, offers and content, as well as your interaction with them. We may also recommend content to you based on information we have collected about you and your viewing habits. This constitutes 'profiling', and more information is provided at Section 8 of this Policy about this.
Some of our service providers who have access to your personal data, are located outside the European Union. We may also share your personal data overseas, for example if we receive a legal or regulatory request from a foreign law enforcement body. We will always take steps to ensure that any international transfer of information is carefully managed to protect your rights and interests, in particular we will either:
You have the right to ask us for more information about the safeguards we have put in place as mentioned above. Contact us as set out in Section 11 if you would like further information or to request a copy where the safeguard is documented (which may be redacted to ensure confidentiality).
'Automated Decision Making' refers to a decision which is taken through the automated processing of your personal data alone - this means processing using, for example, software code or an algorithm, which does not involve any human intervention. We do not carry out any automated decision making, however we do carry out profiling using automated processing to tailor marketing materials for a specific customer.
Where we have permissions to send a consumer marketing updates, we may use profiling to ensure that marketing materials are tailored to your preferences and to what we think you will be interested in.
We will retain your personal data for as long as is reasonably necessary for the purposes listed in Section 4 of this Policy. In particular, where there has been no interaction from a consumer (e.g. a purchase, email open, newsletter sign up), a record will be archived after 1 year and deleted after 3 years.
Where we are required to do so to meet legal, regulatory, tax or accounting requirements, we will retain your personal data for longer periods of time, but only where permitted to do so, including so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a possibility of legal action relating to your personal data or dealings.
We maintain a data retention policy which we apply to records in our care. Where your personal data is no longer required and we do not have a legal requirement to retain it, we will ensure it is either securely deleted or stored in a way such that it is anonymised and the Personal Data is no longer used by the business.
You have a number of rights in relation to your personal data. In summary, you have the right to request: access to your data; rectification of any mistakes in our files; erasure of records where no longer required; restriction on the processing of your data; objection to the processing of your data; data portability; and various information in relation to any automated decision making and profiling or the basis for international transfers. You also have the right to complain to your supervisory authority (further details of which are set out in Section 11 below). These are defined in more detail as follows:
WHAT THIS MEANS
You can ask us to:
You can ask us to rectify inaccurate personal data. We may seek to verify the accuracy of the data before rectifying it.
Erasure / Right to be Forgotten
You can ask us to erase your personal data, but only where:
We are not required to comply with your request to erase your personal data if the processing of your personal data is necessary: for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims, in relation to the freedom of expression or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. In the context of marketing, please note that we will maintain a suppression list if you have opted out from receiving marketing content to ensure that you do not receive any further communications.
You can ask us to restrict (i.e. keep but not use) your personal data, but only where:
We can continue to use your personal data following a request for restriction, where:
You can ask us to provide your personal data to you in a structured, commonly used, machine-readable format, or you can ask to have it 'ported' directly to another Data Controller, but in each case only where: the processing is based on your consent or the performance of a contract with you; and the processing is carried out by automated means.
You can object to any processing of your personal data which has our 'Legitimate Interests' as its legal basis (see Appendix 2 for further details), if you believe your fundamental rights and freedoms outweigh our Legitimate Interests. Once you have objected, we have an opportunity to demonstrate that we have compelling Legitimate Interests which override your rights, however this does not apply as far as the objections refers to the use of personal data for direct marketing purposes.
To exercise your rights you can contact us as set out in Section 11. Please note the following if you do wish to exercise these rights:
The primary point of contact for all issues arising from this Policy, including requests to exercise data subject rights, is our Data Protection Officer. The Data Protection team can be contacted in the following way:
If you have a complaint or concern about how we use your personal data, please contact us in the first instance and we will attempt to resolve the issue as soon as possible. You also have a right to lodge a complaint with your national data protection supervisory authority at any time. In the UK, the supervisory authority for data protection is the ICO (https://ico.org.uk/). We do ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
APPENDIX 1 - LEGAL BASIS FOR PROCESSING
Type of information collected
The basis on which we use the information
Comply with legal and regulatory obligations
APPENDIX 2 - GLOSSARY
Data Controller: means a natural or legal person which determines the means and purposes of processing of personal data.
Data Subject: means an individual whom the personal data is about.
EEA: means the European Economic Area.
GDPR: means the General Data Protection Regulation, which comes into force on 25 May 2018 and replaces the previous Data Protection Directive 95/46/EC.
ICO: the Information Commissioner's Office regulates the processing of personal data by all organisations within the UK.
Legitimate Interests: this is a ground which can be used by organisations as a lawful basis of processing, for example where personal data is used in ways that could reasonably be expected, or there is a compelling reason for the processing.
Member States: means those countries which are part of the European Union.
Privacy Shield: means a framework which has been adopted to protect the rights of those individuals whose data has been transferred to the US.
Profiling: means to analyse your personal data in order to evaluate your behaviour or to predict things about you which are relevant in an entertainment context, such as how likely you are to attend a certain event that we host.
Service Providers: these are a range of third parties to whom we outsource certain functions of our business. For example, we have service providers who provide / support 'cloud based' IT applications or systems, which means that your personal data will be hosted on their servers, but under our control and direction. We require all our service providers to respect the confidentiality and security of personal data.
What are cookies?
Cookies are small text files containing a string of characters that can be placed on your computer or mobile device that uniquely identify your browser or device.
What are cookies used for?
Cookies allow a site or services to know if your computer or device has visited that site or service before. Cookies can then be used to help understand how the site or service is being used, help you navigate between pages efficiently, help remember your preferences, and generally improve your browsing experience. Cookies can also help ensure marketing you see online is more relevant to you and your interests.
You can edit your browser options to block cookies in the future at any time. The Help portion of the toolbar on most browsers will tell you how to prevent your computer from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. Visitors to our website who disable cookies will be able to browse certain areas of the website, but some features may not function. You can find out more about cookies at www.allaboutcookies.org and the site will give you guidance on how to control and delete unwanted cookies you have already accepted. You may also opt-out of certain third party cookies that we and other websites may use for targeted advertising through the European Interactive Digital Advertising Alliance (EDAA) Your Online Choices Page or http://www.aboutads.info
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
Merlin use the following cookies on the Site:
|Cookie||Cookie Code||Description||Default expiration time|
|Umbraco CMS**||UMB_UCONTEXT_C||This cookie is set by websites using the Umbraco CMS. It is necessary for CMS and is usually only seen by site administrators accessing the back end of the website, rather than general visitors.||End of session|
|XSRF-TOKEN||Used for preventing Cross-site request forgery attacks.||*|
|XSRF-V||Used for preventing Cross-site request forgery attacks.||*|
|UMB_UPDCHK||Umbraco specific cookies - Strictly necessary for the website to work correctly. This cookie is set by websites using the Umbraco web content management system. It is usually only seen by site administrators accessing the back end of the website, rather than general visitors.||1 year|
|UMB_UCONTEXT||This cookie is set by websites using the Umbraco web content management system. It is usually only seen by site administrators accessing the back end of the website, rather than general visitors. The main purpose of this cookie is: Strictly Necessary||Same day|
|Umbraco.org||__cfduid||Cookie is set by the CloudFlare service to identify trusted web traffic. It does not correspond to any user id in the web application, nor does the cookie store any personally identifiable information||1 year|
|Technical-analytics||_ga||This cookie name is asssociated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners.||2 years|
|ASP.NET||ASP.NET_SessionId||General purpose platform session cookie, used by sites written with Miscrosoft .NET based technologies. Usually used to maintain an anonymised user session by the server.||*|
|__RequestVerificationToken||This is an anti-forgery cookie set by web applications built using ASP.NET MVC technologies. It is designed to stop unauthorised posting of content to a website, known as Cross-Site Request Forgery. It holds no information about the user and is destroyed on closing the browser.||*|
|Merlin Entertainments||MerlinEntertainments||Application cookie||1 year|
|ShareThis plugin||__sharethis_cookie_test__||This cookie is set as part of the ShareThis service and monitors “click-stream” activity, e.g. web pages viewed, navigation from page to page, time spent on each page etc.||*|
|_attrb||This cookie is set as part of the ShareThis service||1 year|
|_attrg||This cookie is set as part of the ShareThis service||1 year|
|_attru||This cookie is set as part of the ShareThis service||1 year|
|_fbp||This cookie is set as part of the ShareThis service||2 months|
|_ga||This cookie is set as part of the ShareThis service||2 years|
|__stid||This cookie is set as part of the ShareThis service||1 year|
|_vis_opt_s||This cookie is set as part of the ShareThis service||2 months|
|_vis_opt_test_cookie||This cookie is set as part of the ShareThis service||*|
|_vwo_ds||This cookie is set as part of the ShareThis service||2 months|
|_vwo_uuid||This cookie is set as part of the ShareThis service||10 years|
|_vwo_uuid_v2||This cookie is set as part of the ShareThis service||1 year|
|contently_insights_user||This cookie is set as part of the ShareThis service||2 years|
|mp_eb4c820161f6ead8054c94e14c144900_mixpanel||This cookie is set as part of the ShareThis service||1 year|
|__cfduid||Cookie associated with sites using CloudFlare, used to speed up page load times. According to CloudFlare it is used to override any security restrictions based on the IP address the visitor is coming from. It does not contain any user identification information.The main purpose of this cookie is: Strictly Necessary||1 year|