Museum Vests
Privacy policy
1. Data controller
Museum Vest
CVR no.: 45299716
Tarphagevej 2
6710 Esbjerg V
E-mail: kontakt@musvest.dk
Phone: 76 12 20 00
Museum Vest is the data controller for the processing of personal data in connection with our activities and the following websites:
- musvest.dk
- shop.musvest.dk
- fimus.dk
- ribesvikinger.dk
- hexmuseum.dk
- jacobariismuseum.dk
- esbjergmuseum.dk
2. What personal data do we process?
We only process personal data when necessary and on a lawful basis.
2.1 Inquiries and forms
When you contact us via email or digital forms, we process:
- Name
- Email address
- Phone number
- Information you provide yourself
Purpose: To answer inquiries and manage registrations and bookings.
Legal basis: GDPR Art. 6 para. 1 lit. f (legitimate interest).
Retention: Data is deleted when the purpose is fulfilled and it is no longer relevant.
2.2 Booking training and group visits
When booking via Gecko, the contact details of the responsible contact person are processed.
No information is collected about children.
Purpose: Administration and booking completion.
Legal basis: GDPR Art. 6(1)(b) (performance of contract).
Storage: Data is stored for as long as necessary to complete and document the event and then deleted.
2.3 Annual pass
When purchasing an annual pass, we process:
- Name
- Address
- Email address
- Phone number
- Date of birth
- Purchase information
The information is used for administration of the annual pass, including registration, identification and contact in connection with expiration or renewal.
Contact information is transferred to our email platform for the purpose of annual pass administration. Marketing is only sent out if separate consent has been given.
Purpose: Fulfillment and administration of annual pass agreement.
Legal basis: GDPR Art. 6(1)(b) (performance of contract).
Storage: Data is stored as long as the annual pass is active and in accordance with applicable accounting rules.
2.4 Newsletter and marketing
By signing up for our newsletter we process:
- Name
- Email address
Sign up can be done via our websites, including via popup solution (Sleeknote). Newsletters are sent via our email platform (ActiveCampaign).
Purpose: Sending news, event information and marketing.
Legal basis: Consent (GDPR Art. 6(1)(a)).
Consent can be withdrawn at any time via the unsubscribe link in the newsletter.
Annual pass holders will only receive marketing if separate consent has been given.
2.5 Ticket purchase and webshop
When purchasing tickets, annual passes or goods via our websites, we process
- Name
- Contact details
- Purchase information
- Payment information
Purpose: Completion of purchase.
Legal basis: GDPR Art. 6 para. 1 lit. b.
Accounting information is stored according to the Bookkeeping Act (5 years).
2.6 Job applications
When applying via our recruitment system (Garuda), the information you submit yourself is processed, including application, CV and attachments.
Garuda acts as data processor and only processes data according to our instructions.
Purpose: Completing the recruitment process.
Legal basis: GDPR Art. 6(1)(b) and GDPR Art. 6(1)(f)
Storage: Applications are generally deleted no later than 6 months after recruitment is completed, unless consent has been given for longer storage.
2.7 TV surveillance
CCTV surveillance is used in selected areas, including retail areas, to prevent and detect theft and vandalism.
Purpose: Security and crime prevention.
Legal basis: GDPR Art. 6 para. 1 lit. f (legitimate interest).
Storage: Recordings are generally stored for up to 30 days and then deleted unless they are part of a specific case.
There is signage at the relevant locations.
3. Statistics and marketing
We use analytics and marketing tools, including:
- Google Analytics (GA4)
- Meta Pixel
- Google Tag Manager
Processing is based on consent via our cookie solution (Cookiebot).
You can read more in the cookie policy further down the page.
4. Transfer to third countries
Some of our suppliers, including Google, Meta and ActiveCampaign, may process data outside the EU/EEA.
Transfers are made on lawful basis, including the EU-U.S. Data Privacy Framework or EU Commission Standard Contractual Clauses.
5. Data processors
We use external suppliers for the operation of:
- Websites (WordPress and Craft CMS)
- Web operations and hosting (Morningtrain)
- Ticket and webshop solution (JCD)
- Newsletter (ActiveCampaign)
- Forms and booking solutions
- Recruitment system (Garuda)
Where required, data processing agreements are in place.
6. Your rights
You have the right to:
- Insights
- Correction
- Deletion
- Limitation
- Objection
- Withdrawing consent
Inquiries can be made to kontakt@musvest.dk.
You have the right to complain to the Danish Data Protection Agency(www.datatilsynet.dk).
7. cookies
We use cookies and similar technologies on our websites.
Read more about purposes, categories and changing consent in the cookie policy below.
8. changes
We may update this privacy policy from time to time. It was last updated on March 1, 2026.