Buy ticket

26.03.2024, version 2.0

1. Why have we prepared this privacy policy?
At Den Gamle By, we place a high priority on confidentiality and data security. This privacy policy applies to our processing of personal data and sets out the guidelines for how Den Gamle By processes your personal data. It also provides you with the information you are entitled to receive under applicable data protection legislation. You should read this privacy policy before providing your personal data to Den Gamle By.


2. Data controller and contact details

The data controller responsible for your personal data is:

Den Gamle By / Ole Bojesen
Address: Viborgvej 2 – 8000 Aarhus C

E-mail: information@dengamleby.dk
Telephone: +45 86 12 31 88

CVR no.: 36 07 90 10

3. Where do we collect personal data about you?
Den Gamle By may potentially collect and process personal data about you from the following sources:

  • Directly from you
  • Through video surveillance.
  • From other visitors.
  • From your employer, if you are an employee of one of our partners or suppliers.


4. Purposes, types of personal data, legal basis and deletion

Den Gamle By's processing of personal data will depend on your purchases, your interactions, any consents you have given, and your behaviour. You should therefore first read the section “Who is covered?” below to determine whether the processing activity, the relevant purposes, types of personal data, legal basis and deletion periods are relevant to you.

Cookies, pixels and social plug-ins

Who does this apply to?
Website visitors who have given their consent via the cookie banner.

For what purposes are personal data used?
Marketing, statistics, preferences and functionality.
You can read more about the purposes via the cookie banner.

What types of personal data are used?
User ID, geographical location, interests, IP address, operating system, browser type, device type, browsing activity on the website, MAC address, click behaviour, interaction with advertisements, data provided when making a purchase, and search history.

The processing of personal data in relation to necessary cookies is based on an agreement to enable you to use the functionality of the websites (Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

What is the legal basis for the processing?
The processing of personal data in relation to statistical and preference cookies is based on our legitimate interest in providing you with the best possible products and services (Article 6(1)(f) of the GDPR).

The processing of personal data in relation to marketing cookies, including processing based on your preferences, is based on your prior consent (Article 6(1)(a) of the GDPR).

In addition, we always obtain valid cookie consent in accordance with the Danish Executive Order on Requirements for Information and Consent when Storing or Accessing Information in End-User Terminal Equipment before cookies are placed on your terminal equipment.

When are personal data deleted?
Please refer to the cookie banner, where the retention periods (expiry periods) are specified.

You can view the cookie banner by clicking this link.

Video surveillance

Which individuals are covered?
Visitors and suppliers.

For what purposes are personal data used?
To create a safe and secure environment, prevent crime, and preserve evidence for use in police investigations.

What types of personal data are processed?
Images of your movements and, in certain cases, information relating to criminal offences in connection with theft or other crimes.

What is the legal basis for the processing?
We process the personal data based on our legitimate interest in creating a safe and secure environment, preventing crime, and preserving evidence for use in police investigations (Article 6(1)(f) of the General Data Protection Regulation (GDPR) and Section 8(3) of the Danish Data Protection Act).

When are the personal data deleted?
The recordings are deleted 30 days after they were made.

Creation of a user profile

Which individuals are covered?
Users.

For what purposes are personal data used?
To create a user profile for the purpose of purchasing and registering annual passes, season passes and tickets, as well as obtaining benefits.

What types of personal data are processed?
Username, password, name, address, date of birth, photograph, discounts, email address and purchase history.

What is the legal basis for the processing?
To enter into and perform a contract (Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
One year after the user profile has been deleted.


Which individuals are covered?
Users.

For what purposes are personal data used?
To create a user profile for the purpose of purchasing and registering annual passes, season passes and tickets, as well as obtaining benefits.

What types of personal data are processed?
Username, password, name, address, date of birth, photograph, discounts, email address and purchase history.

What is the legal basis for the processing?
To enter into and perform a contract (Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
One year after the user profile has been deleted.

Purchases via the Webshop

Which individuals are covered?
Individuals who make purchases via the webshop.

For what purposes are personal data used?
To enter into and fulfil the purchase agreement with you, including delivering the ordered goods and/or tickets, handling order confirmations, complaints and returns, and sending the terms and conditions.

What types of personal data are processed?
Name, address, email address, telephone number, country code, purchase history, geolocation, IP address and payment information. It will be indicated whether providing the information is mandatory or optional.

What is the legal basis for the processing?
To enter into and perform a purchase agreement (Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
Two years after the most recent purchase. However, information subject to statutory accounting requirements will be retained for six years after the purchase in accordance with the Danish Bookkeeping Act.

Newsletter

Which individuals are covered?
Individuals who have given their consent to receive newsletters.

For what purposes are personal data used?
To send marketing communications as described in the consent.

What types of personal data are processed?
Email address, name and telephone number.

What is the legal basis for the processing?
Consent (Article 6(1)(a) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
Two years after the consent has been withdrawn.

Profiling for Marketing Purposes

Which individuals are covered?
Individuals who have given their consent to receive newsletters.

For what purposes are personal data used?
For targeted marketing, including sending personalised emails and newsletters.

What types of personal data are processed?
Email address, name, click behaviour in relation to distributed materials, order history and preferences.

What is the legal basis for the processing?
Our legitimate interests in improving and developing our services (Article 6(1)(f) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
As long as your consent to receive newsletters remains active.

Customer service and general communication

Which individuals are covered?
Individuals who contact customer service or otherwise communicate with us.

For what purposes are personal data used?
To handle your enquiry and, where applicable, your order, exercise your rights, communicate with you generally, and for statistical and analytical purposes.

What types of personal data are processed?
Email address, name, telephone number, the subject of your enquiry, the date of the enquiry, and any other information you provide.

We encourage you not to provide sensitive personal data or your Danish CPR number unless it is strictly necessary for handling your enquiry.

What is the legal basis for the processing?
We may process your personal data based on our legitimate interests in handling your enquiry, communicating with you, and developing our products and services (Article 6(1)(f) of the General Data Protection Regulation (GDPR)).

If your enquiry concerns entering into a potential or actual agreement, we process your personal data in order to take steps at your request prior to entering into an agreement (Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
General enquiries and cases are generally retained for two years, but the retention period may vary depending on the nature and content of the case.

Accounting records, including personal data that we are required to retain under the Danish Bookkeeping Act, are retained for up to six years.

Season pass / Annual pass

Which individuals are covered?
Season pass holders / annual pass holders.

For what purposes are personal data used?
To issue and administer your season pass / annual pass, ensure identification when purchasing a season pass / annual pass, and manage access control.

What types of personal data are processed?
Name, address, telephone number, date of birth, and, where applicable, photograph.

What is the legal basis for the processing?
To enter into an agreement and ensure identification
(Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
Two years after the pass has expired.

Restaurant bookings

Which individuals are covered?
Restaurant guests.

For what purposes are personal data used?
To create and manage restaurant reservations.

What types of personal data are processed?
Contact details and other information you provide in connection with table reservations.

What is the legal basis for the processing?
To enter into an agreement (
Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
Two years after the most recent booking.

Accommodation bookings

Which individuals are covered?
Guests staying overnight.

For what purposes are personal data used?
To manage your booking and enter into an agreement for accommodation.

To comply with the Danish Passport Regulations and the Danish Aliens Regulations.

What types of personal data are processed?
Name and contact details, payment information, and any special requests or preferences relating to your stay, including specific dietary requirements.

Identification information collected at check-in. This may include your name, date of birth, occupation, nationality, permanent residence, date of arrival, and the type and number of your passport or other travel document.

What is the legal basis for the processing?
To enter into and perform an agreement for accommodation
(Article 6(1)(b) of the General Data Protection Regulation (GDPR)).

To comply with our legal obligation to comply with the Danish Passport Regulations and the Danish Aliens Regulations
(Article 6(1)(c) of the General Data Protection Regulation (GDPR)).

When are the personal data deleted?
Two years after the most recent overnight stay.

 

Google custom and lookalike audience

Which individuals are covered?
Individuals who have given their consent to receive newsletters and/or to the use of marketing cookies.

For what purposes are personal data used?
To create audiences for subsequent advertising for sales and marketing purposes, including through banners and other advertisements.

What types of personal data are used?
Non-reversibly hashed email addresses, user IDs, geographic location, interests, IP addresses, MAC addresses, click behaviour, interactions with advertisements, data provided when making a purchase, and search history.

What is the legal basis for the processing?
Our legitimate interest in increasing awareness of our products and services, including among other individuals with similar interests, in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

If you wish to object to Google's processing, you can do so by managing your advertising preferences on Google's services via “Google Custom Match” in your Google Ads settings.

You can also read more about how Google acts as a joint controller together with us. You can read more about Google's processing of your personal data via this link.

When are personal data deleted?
Personal data are deleted in accordance with the retention periods applicable to newsletters and marketing cookies.

Facebook custom and lookalike audiences

Which individuals are covered?
Individuals who have given their consent to receive newsletters and/or to the use of marketing cookies.

For what purposes are personal data used?
To create audiences for subsequent advertising for sales and marketing purposes, including through banners and other advertisements.

What types of personal data are used?
Non-reversibly hashed email addresses, user IDs, geographic location, interests, IP addresses, MAC addresses, click behaviour, interactions with advertisements, data provided when making a purchase, and search history.

What is the legal basis for the processing?
Our legitimate interest in increasing awareness of our products and services, including among other individuals with similar interests, in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

You can object to Facebook's processing by changing your settings on Facebook and disabling “Facebook Custom Audiences and Lookalike Audiences” by following the instructions provided via this link.

Meta (Facebook) acts as a joint controller together with us. You can read more about Facebook's processing of your personal data via this link.

When are personal data deleted?
Personal data are deleted in accordance with the retention periods applicable to newsletters and marketing cookies.

Competitions

Which individuals are covered?
Participants in competitions.

For what purposes are personal data used?
To enable you to participate in the competition and to send the prize if you win, as well as to ensure compliance with the competition terms and conditions.

To publish the winner's name on social media and on our website.

What types of personal data are used?
Name and email address and, where applicable, information that you have won the competition. We also collect your address if you win a prize that needs to be sent physically.

What is the legal basis for the processing?
Our legitimate interest in conducting the competition, potentially publishing your name, and sending the prize if you win, in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

To comply with the competition terms and conditions, in accordance with Article 6(1)(b) of the General Data Protection Regulation (GDPR).

When are personal data deleted?
Personal data are deleted one year after the competition has ended.

Events, tours and other activities

Which individuals are covered?
Participants in events, tours, activities and other events.

For what purposes are personal data used?
For registration, organisation and administration of the event, tour, activity or other event.

What types of personal data are used?
Contact details and information about participation in the event, activity, tour or other event.

What is the legal basis for the processing?
To enter into and perform an agreement, in accordance with
Article 6(1)(b) of the General Data Protection Regulation (GDPR).

When are personal data deleted?
Personal data are deleted two years after the event has ended.

Use of photos and videos for marketing purposes

Which individuals are covered?
Visitors or individuals whose photos or videos have been uploaded to social media.

For what purposes are personal data used?
For marketing purposes.

What types of personal data are used?
Photos and/or videos and contact details.

Your signature and a copy of the contract.
A copy of your consent and, if you are under 15 years of age, a copy of the consent provided by your parent or legal guardian.

What is the legal basis for the processing?
We base the processing of your personal data on our legitimate interest in marketing our organisation, including on social media and our website, where the image is a general atmosphere photo in which it is difficult or impossible to identify you (Article 6(1)(f) of the General Data Protection Regulation (GDPR)). In accordance with the applicable guidelines issued by the Danish Data Protection Agency, we make an overall assessment to determine whether publication of the image requires your prior consent.

If the overall assessment shows that publication requires your prior consent or the conclusion of a contract, we will obtain your consent or enter into the contract before using the photo or video of you for marketing purposes (Article 6(1)(a) of the GDPR (consent) and Article 6(1)(b) of the GDPR (contract)).

When are personal data deleted?
When consent is withdrawn or when the contract expires.

The retention period for general atmosphere photos depends on the specific circumstances. However, such photos will generally not be deleted from social media unless you object to their use. See below for information on how to object.

Injuries

Which individuals are covered?
Individuals who have been injured.

For what purposes are personal data used?
To handle physical injuries occurring at the museum and to establish, exercise or defend legal claims.

What types of personal data are used?
Name, address, telephone number, email address and a description of the injury. The description of the injury may contain special categories of personal data in the form of health information.

What is the legal basis for the processing?
Our legitimate interest in handling the injury, including in relation to compensation, legal claims and insurance, in accordance with 
Article 6(1)(f) of the General Data Protection Regulation (GDPR).

To establish, exercise or defend legal claims where the processing of health information is strictly necessary, in accordance with
Article 9(2)(f) of the GDPR.

When are personal data deleted?
Personal data are deleted three years after the handling of the injury has been completed.

Legal claims, compliance with guidelines/articles of association and bans

Which individuals are covered?
Individuals involved in incidents that are contrary to applicable legislation or internal guidelines/articles of association.

For what purposes are personal data used?
To establish, exercise and defend legal claims and, in certain cases, to exclude individuals from future visits or report the matter to the police.

What types of personal data are used?
A description of the incident, which may include ordinary personal data, information relating to criminal offences and, in certain cases, special categories of personal data, such as information about racial or ethnic origin or health.

What is the legal basis for the processing?
Our legitimate interest in establishing, exercising and defending legal claims and in excluding individuals from future visits if they have acted in breach of applicable guidelines or legislation, in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

For ordinary personal data: Section 8(3) of the Danish Data Protection Act.

For information relating to criminal offences: Section 8(3) of the Danish Data Protection Act.

If the processing involves special categories of personal data, such as information about racial or ethnic origin or health: Article 9(2)(f) of the GDPR.

When are personal data deleted?

Personal data are deleted when the case is closed or three years after the matter has been reported.

A list of individuals who have been banned from visiting is retained for as long as the ban remains in effect.

Compliance with the Danish Bookkeeping Act

Which individuals are covered?
Individuals who make payments.

For what purposes are personal data used?
To ensure documentation of purchases in accordance with the Danish Bookkeeping Act.

What types of personal data are used?
Transaction information.

What is the legal basis for the processing?
Compliance with a legal obligation under the Danish Bookkeeping Act, in accordance with Article 6(1)(c) of the General Data Protection Regulation (GDPR).

When are personal data deleted?
Accounting records, including personal data that we are required to retain under the Danish Bookkeeping Act, are retained for up to six years.

Sponsorships and contributions

Which individuals are covered?
Sponsors and contributors.

For what purposes are personal data used?
To administer the sponsorship or contribution and issue invoices.

What types of personal data are used?
Name, address, email address, telephone number, amount of the sponsorship or contribution, company name, position, signature and, in certain cases, CPR number (Danish personal identification number).

What is the legal basis for the processing?
Compliance with a legal obligation under the Danish Bookkeeping Act and tax legislation, in accordance with Article 6(1)(c) of the General Data Protection Regulation (GDPR).

Where a CPR number is required for reporting to the Danish tax authorities, the legal basis is Section 11(2)(1) of the Danish Data Protection Act.

To enter into and perform an agreement concerning the sponsorship or contribution, in accordance with Article 6(1)(b) of the GDPR.

When are personal data deleted?
Personal data are deleted six years after the sponsorship or contribution has been completed.

Booking Educational Programmes

Which individuals are covered?
Participants in educational programmes.

For what purposes are personal data used?
To register participants and conduct educational programmes.

What types of personal data are used?
Name, address, email address, telephone number, name of school and year group.

What is the legal basis for the processing?
To enter into and perform an agreement concerning the educational programme, in accordance with
Article 6(1)(b) of the General Data Protection Regulation (GDPR).

Our legitimate interest in registering and verifying participants, in accordance with
Article 6(1)(f) of the GDPR.

When are personal data deleted?
Personal data are deleted six months after completion of the educational programme.

Handling complaints

Which individuals are covered?
Individuals who submit complaints about our products, visits or services.

For what purposes are personal data used?
To handle the complaint in accordance with applicable legislation, guidelines and terms and conditions.

What types of personal data are used?
Description of the complaint, date and time of the purchase, visit or experience, as well as contact details.

What is the legal basis for the processing?
To assess whether the agreement has been complied with, in accordance with
Article 6(1)(b) of the General Data Protection Regulation (GDPR).

To assess the complaint in accordance with the Danish Sale of Goods Act and the Danish Consumer Contracts Act, in accordance with
Article 6(1)(c) of the GDPR.

When are personal data deleted?
Personal data are deleted two years after the complaint has been resolved.

Cooperation with companies

Which individuals are covered?
Suppliers and business partners.

For what purposes are personal data used?
For general planning, performance and administration of business relationships, including contracts.

For administrative purposes, such as processing payments, evaluating credit assessments, maintaining accounts, conducting audits and providing support.

  • Product and service development.
  • Statistics and analysis.
  • Handling disputes and conflicts.


What types of personal data are used?
Name, email address, telephone number and similar contact details.

Individual information, such as preferred language.

Organisational information, such as the company's name and address, job title, area of employment, primary place of work and country of employment.

Contractual information, such as orders, invoices, contracts and other agreements with your company, which may contain, for example, your contact details.

Financial information, such as payment terms, bank details and credit assessments (where you operate as a sole proprietor).

What is the legal basis for the processing?
In certain cases, the processing of your personal data is necessary to perform a contract, in accordance with Article 6(1)(b) of the General Data Protection Regulation (GDPR).

We may process your personal data based on our legitimate interests, including administering our day-to-day operations in accordance with lawful and fair business practices, including planning, carrying out and administering the business relationship. This may also include our legitimate interest in carrying out credit assessments, statistics and analyses, conducting marketing activities (where consent is not required), providing support, and improving and developing our products and services.

The processing may also be necessary for our legitimate interest in preventing fraud or establishing, exercising or defending legal claims, in accordance with Article 6(1)(f) of the GDPR.

In certain cases, the processing of your personal data may be necessary to comply with legal obligations, such as our obligation to prevent unlawful activities, in accordance with Article 6(1)(c) of the GDPR.

When are personal data deleted?
Personal data are deleted two years after the most recent contact.

5. Hvem videregiver vi dine personoplysninger til?
I nogle særlige tilfælde videregiver vi dine personoplysninger til selvstændige dataansvarlige. I det følgende skema har vi angivet kategorierne af disse tredjeparter, hvilke personoplysninger, der kan blive videregivet om dig til tredjeparterne samt retsgrundlaget for videregivelsen.

Vi bemærker, at dine personoplysninger også kan blive videregivet med dit forudgående samtykke, herunder til tredjeparter via cookiesamtykket.

 

Categories of recipients

Types of
personal data

Legal basis

Lawyers, insurance companies, public authorities, the police and the courts.

Relevant information relating to a specific dispute, including, in certain cases, video recordings and information concerning incidents involving injuries.

Article 6(1)(f) of the General Data Protection Regulation (GDPR) (legitimate interest).

Article 6(1)(c) of the GDPR (legal obligation to report descriptions of injuries to the relevant safety authorities).

Suppliers of prizes for competitions Address

Article 6(1)(f) of the General Data Protection Regulation (GDPR) (legitimate interest).

Tax authorities in connection with sponsorships

Contact details and CPR number (Danish personal identification number).

Article 6(1)(c) of the General Data Protection Regulation (GDPR) (legal obligation), cf. applicable tax legislation.

Section 11(2)(1) of the Danish Data Protection Act, where a CPR number is required for reporting to the tax authorities.

Event agencies

Contact details

Article 6(1)(f) of the General Data Protection Regulation (GDPR) (legitimate interest).

Payment service providers

Payment and card details.

Article 6(1)(b) of the General Data Protection Regulation (GDPR) (contract).

6. Who do we share your personal data with?
Third-party service providers may have access to your personal data on the basis of a contractual relationship with Den Gamle By when they provide relevant services to Den Gamle By, such as providers of video surveillance solutions, hosting services, customer satisfaction surveys, newsletter distribution, cookie placement, and general marketing.

Such providers (data processors) will only process personal data on the basis of a data processing agreement and in accordance with our instructions.

7. Do we transfer your personal data to third countries that do not provide an adequate level of protection?

If your personal data is transferred to data processors or data controllers established in countries outside the EU/EEA that do not provide an adequate level of protection, such transfers will only take place once an appropriate transfer mechanism has been established, such as the European Commission’s Standard Contractual Clauses.

Transfers of personal data to the United States may also take place on the basis of the EU-U.S. Data Privacy Framework.

If you have any questions regarding the legal basis for transfers to countries outside the EU/EEA, please contact us at information@dengamleby.dk.

8. If you visit our profiles or pages on social media
This section sets out Den Gamle By’s policy for the processing of personal data collected through Den Gamle By’s profiles or pages on social media.

Den Gamle By has profiles or pages on the following social media platforms:

  • Facebook (Meta Platforms Ireland Ltd.)
    Facebook’s privacy policy is available here.

    Meta and Den Gamle By are joint data controllers for Facebook pixels, which you can accept via cookies as described in more detail above. The Meta privacy policy and the information in this section also apply to Facebook pixels, except for information that relates solely to our Facebook profile.

  • YouTube (Google Ireland Ltd.)
    Google’s privacy policy is available here.

  • LinkedIn (LinkedIn Ireland Unlimited Company)
    LinkedIn’s privacy policy is available here.

  • Twitter (Twitter, Inc.)
    Twitter’s privacy policy is available here.

  • Instagram (Meta Platforms Ireland Ltd.)
    Instagram’s privacy policy is available here.

For LinkedIn, Facebook, and Instagram, Den Gamle By and the providers of the social media platforms are joint data controllers for the processing of personal data collected in connection with your interactions with the profiles, including posts on the profiles.

Den Gamle By and the providers of LinkedIn, Facebook, and Instagram have entered into agreements regarding the allocation of data protection responsibilities. Under these agreements, Den Gamle By and the respective social media providers are each responsible for the processing activities they carry out. However, Den Gamle By and the providers of Facebook and Instagram have agreed that the providers are responsible for enabling you to exercise your rights as described in the section “Your Rights” below in connection with your use of Facebook and Instagram, while Den Gamle By is responsible for providing you with the information described below. In addition, Den Gamle By and LinkedIn have agreed that LinkedIn is responsible for responding to requests from you concerning the rights described in the section “Your Rights” below.

Den Gamle By also uses the provider of YouTube as a data processor in connection with the use of YouTube by these entities and, in this context, also shares certain information about your interactions, interests, etc. with YouTube. This sharing is based on the legitimate interests of Den Gamle By and Google in optimising marketing and the service, including our videos on YouTube
(Article 6(1)(f) of the General Data Protection Regulation).


Collection of Personal Data

When you visit or interact with our social media profiles, Den Gamle By and the provider of the relevant social media platform may collect, process, and store the following types of personal data about you:

  • Information available on your profile, including your name, gender, marital status, place of employment, interests, photo, and city
  • Whether you “like” or use other reactions on our profile
  • Comments you leave on our posts
  • The fact that you have visited our profile
  • Your IP address

 

Purposes of Processing
Den Gamle By processes your personal data for the following purposes:

  • Improving our products and services, including our social media profiles and pages
  • Statistics and analysis
  • Communicating with you if you comment on a post, leave a review, or send us a message
  • Marketing in general
  • The social media providers process your personal data for, among other things, the following purposes:
  • Improving their advertising systems
  • Providing Den Gamle By with statistics, which the social media providers compile, among other things, on the basis of your visits to our profiles and pages
  • Advertising and customising activities on the page


Legal Basis for Processing
The processing of your personal data is based on the following legal basis:

  • Legitimate interests: Den Gamle By relies on our legitimate interests in being able to communicate with and market to you through our social media profiles, as well as our legitimate interest in improving our products and services
    (Article 6(1)(f) of the General Data Protection Regulation).


Retention Period

Your personal data will be stored for 2 years. However, the information may be stored for a longer period in anonymised form.

Please refer to the privacy policy of the provider of each individual social media platform for information on how long they retain your personal data.

Who Do Social Media Providers Share Your Personal Data With?
Social media providers may, among other things, share your personal data with the following categories of recipients:

  • Other entities within the corporate group to which the social media provider belongs
  • External partners providing analytics and research services
  • Advertisers
  • Other individuals who visit our profile or page on the social media platform, to the extent that your information is publicly available
  • Researchers and other academics

You can find more information about who the social media providers share your personal data with in the respective providers’ privacy policies.

The social media providers may transfer your personal data to recipients outside the EU/EEA in accordance with applicable data protection legislation. You can find more information in the respective providers’ privacy policies.

You can find more information about who Den Gamle By shares your personal data with in the sections above entitled “Who Do We Disclose Your Personal Data To?” and “Who Do We Entrust Your Personal Data To?”.

9. What Rights Do You Have?
General Rights

When Den Gamle By processes personal data about you as described above, you have a number of rights under applicable data protection legislation:

  1. You have the right to access the personal data we process about you.
  2. You have the right to object to our collection and further processing of your personal data.
  3. You have the right to have your personal data rectified and erased, subject to certain statutory exceptions, including the Danish Bookkeeping Act.
  4. You have the right to request that we restrict the processing of your personal data.
  5. Under certain circumstances, you may request to receive a copy of your personal data and request the transmission of the personal data you have provided to us to another data controller (data portability).
  6. You may withdraw any consent you have given at any time. We will then delete your personal data unless we are able to continue processing it on another legal basis. You can unsubscribe from our newsletter by clicking the link at the bottom of the newsletter. Withdrawal of consent will apply to the future processing of your personal data. Withdrawal of consent therefore does not affect the lawfulness of processing carried out on the basis of your consent before it was withdrawn.


Right to Object

You always have the right to object to the collection and further processing of your personal data, including the right to object to our processing based on the balancing-of-interests rule under Article 6(1)(f) of the General Data Protection Regulation. This applies, among other things, when we process your data for marketing purposes.

Required Information
Den Gamle By notes that the processing of certain personal data listed in the table under section 2 above is required by law or is contractually necessary as a prerequisite for us to comply with applicable legislation and to administer purchases and visits, respectively. This applies where we have stated that the legal basis for processing is Article 6(1)(b) of the General Data Protection Regulation (contract) or Article 6(1)(c) (legal obligation). Information that you are required to provide in order to enter into a contract may also be marked with an asterisk (*) on the website.

Refusal to provide this information, objection to our processing of this information, or a request for its deletion may therefore result in you being unable to purchase our services or enter into an agreement with us.

10. Do You Have Any Questions or Wish to Exercise Your Rights?
If you have any questions regarding this privacy policy or if you wish to lodge a complaint about the way we process your personal data, please feel free to contact us:

Den Gamle By
Address: Viborgvej 2, 8000 Aarhus C, Denmark
CVR no.: 36 07 90 10
Email: information@dengamleby.dk
Telephone: +45 86 12 31 88

If your complaint is not resolved by us and you wish to pursue the matter, you may lodge a complaint with the Danish Data Protection Agency:

Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Email: dt@datatilsynet.dk

11. Links to Other Websites
Our website may contain links to other websites. We are not responsible for the content of other websites (third-party websites) or for the procedures used by such third parties to collect and process personal data. When you visit a third-party website, you should read the website owner’s privacy policy and other relevant policies.

12. Changes to the Privacy Policy
This privacy policy does not constitute an agreement between Den Gamle By and you, but instead forms the basis for our obligation to provide information under applicable data protection legislation.

We reserve the right to make changes to this privacy policy from time to time in accordance with applicable data protection legislation. In the event of changes, the date and version number at the top of the privacy policy will be updated.

The privacy policy applicable at any given time will always be available at: https://www.dengamleby.dk/en/privacy-policy/

In the event of material changes to the privacy policy, you will receive an email or other notification referring you to the updated privacy policy.