Privacy Policy
Last updated: August 2026
1. Who we are
This website, thecyprusplanetarium.com (the "Website"), is operated by V&G Planetarium Limited, a private company limited by shares registered in the Republic of Cyprus under registration number HE 435019, with its registered office at Onisilou 13A, Nicholas Court, Ayios Tychonas 4532, Limassol, Cyprus, trading as The Cyprus Planetarium. In this policy, "we", "us" and "our" mean V&G Planetarium Limited.
V&G Planetarium Limited is the data controller for the personal data described in this policy. It determines why and how your personal data is used, and it is responsible to you for that use.
The Website was developed by AMS Media, a registered business name in the Republic of Cyprus, which continues to provide the Website platform and the technical infrastructure on which the booking, ticketing and customer records are stored. In doing so, AMS Media acts as our data processor, handles personal data only on our documented instructions, and may not use it for its own purposes. That relationship is governed by a written data processing agreement meeting the requirements of Article 28 of the GDPR. The full name of the individual (or partnership) trading as AMS Media, and the registration number of the business name, obtainable from the Registrar of Companies and Intellectual Property. “AMS Media” is a registered business name and not a separate legal person, so the contracts referred to below must be entered into with that individual or partnership.
The domain and the hosting of the Website, and the accounts used for payments, newsletters, analytics and social media, are held by V&G Planetarium Limited in its own name. V&G Planetarium Limited remains the owner of, and retains control over, all customer, booking, account and newsletter data, and may obtain a complete export of it at any time.
You can contact us about this policy or about your personal data at:
-
Email: info@planetariumcyprus.com
-
Telephone: +357 22 278 700
-
Post: V&G Planetarium Limited, Onisilou 13A, Nicholas Court, Ayios Tychonas 4532, Limassol, Cyprus
2. What this policy covers
This policy explains what personal data we collect through the Website and through our ticketing, booking, loyalty and visitor services, why we collect it, the legal basis on which we use it, who we share it with, how long we keep it, and the rights available to you. It applies to visitors to the Website, customers, account holders, newsletter subscribers, and people who contact us or visit the planetarium.
3. The personal data we collect
Depending on how you use the Website and our services, we may collect:
-
Identity and contact details: name, email address, telephone number, and the language in which you prefer to be contacted.
-
Booking and order details: the show, event, experience or pass booked, the date and time, the number and type of tickets, the booking reference, the amount paid, and check-in status.
-
Payment details: the amount, currency, payment status and transaction reference. Card details are entered directly with our payment provider and are never stored on our systems.
-
Account details: your login credentials, held in encrypted form, and your account preferences and history.
-
Loyalty and membership details: loyalty or membership number, stamp or points balance, rewards redeemed, and a mobile number where you choose to verify one.
-
Newsletter details: email address, language preference, subscription status and the date and source of your consent.
-
Correspondence: the content of messages you send us through the contact form, by email or by telephone, and our replies.
-
School, group and organisational booking details: the name of the organisation, the name and contact details of the responsible adult, group size, age range, and any accessibility or allergy information relevant to the visit.
-
Camp and multi-day programme details: where we run educational camps or multi-day programmes booked through a school, we may additionally receive, from the school, the names of participating children, emergency contact details for a parent or guardian, and any allergy, dietary, medical or accessibility information necessary for a child to take part safely.
-
Accessibility and dietary information: where you choose to tell us, so that we can accommodate you safely. Some of this may be health related, and we use it only for the visit in question, with your consent, and we delete it afterwards.
-
Technical and usage data: pages viewed, referring page, approximate location derived from your IP address, browser, operating system and device type.
-
Images: photographs and video footage taken at the planetarium and at our events, photographs taken by you using our photobooth, and closed circuit television (CCTV) footage recorded at our premises, as described in section 8.
4. Where we obtain your personal data
Most of the personal data we hold comes directly from you, when you book, create an account, join the loyalty scheme, subscribe to the newsletter, contact us, or visit us.
We also receive personal data from other people in two situations. Where someone books on your behalf, for example a family member, a friend or a group organiser, we receive your details from them, and we rely on them to have your permission to give them to us. Where a school or organisation books a group visit, we receive the details of the responsible adult and limited information about the group from that school or organisation.
A limited amount of technical data is collected automatically as you browse the Website, as explained in our Cookie Policy.
5. Why we use your personal data, and our legal basis
We use personal data only where the law permits. For each purpose, our legal basis under the General Data Protection Regulation (Regulation (EU) 2016/679) is set out below.
| What we do | Why | Legal basis |
|---|---|---|
| Take and manage your booking, issue tickets and passes, and admit you on the day | To provide the service you have bought | Performance of a contract |
| Process payments and refunds | To complete your purchase | Performance of a contract |
| Operate your account and the loyalty or membership scheme | To provide the features you have signed up for | Performance of a contract |
| Send booking confirmations, reminders and other service messages | To perform the contract and keep you informed about your booking | Performance of a contract |
| Answer your enquiries and handle complaints | To respond to you and resolve issues | Legitimate interests, being the proper running of our visitor services |
| Accommodate accessibility or dietary needs you tell us about | To allow you to visit safely and comfortably | Consent, and, where health information is involved, your explicit consent |
| Send our newsletter, offers and news | To keep you informed about our programme | Consent |
| Keep accounting, tax, VAT and audit records | To meet our legal obligations | Legal obligation |
| Keep the Website and our premises secure, and prevent fraud, abuse and misuse | To protect our visitors, our staff and our business | Legitimate interests |
| Measure how the Website is used, using our own first party analytics | To understand and improve the Website | Consent, given through the cookie banner |
| Use photographs and video footage of events, as described in section 8 | To promote the planetarium and record our activities | Consent |
| Provide the photobooth and make the resulting photographs available to you | To provide the feature you have chosen to use | Consent |
| Operate CCTV at our premises | To protect the safety of visitors and staff, and to protect property against theft, damage and other unlawful acts | Legitimate interests |
| Establish, exercise or defend legal claims | To protect our legal position | Legitimate interests, and legal obligation where applicable |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we have concluded that they are not. You may ask us for more detail about that assessment, and you have the right to object, as explained in section 15.
We do not carry out credit checks, and we do not send your personal data to credit reference agencies.
6. Marketing communications
We send marketing emails only to people who have opted in. You must tick an unticked box or subscribe yourself. We never add you automatically, and subscribing is never a condition of buying a ticket or using the Website.
Every marketing email contains a one click unsubscribe link. You can also unsubscribe at any time by writing to info@planetariumcyprus.com. Unsubscribing takes effect promptly and does not affect transactional messages such as booking confirmations, which we must send in order to perform our contract with you.
We keep a record of your consent, including when and how it was given, so that we can demonstrate that it was properly obtained. Where you unsubscribe, we keep a minimal suppression record so that we do not contact you again in error.
7. Cookies and similar technologies
We use cookies and similar technologies on the Website. Only strictly necessary cookies are set when you arrive. Everything else is set only after you consent through our cookie banner, and you may change or withdraw your choice at any time. Full details are in our Cookie Policy.
8. Images: photography, filming, the photobooth and CCTV
8.1 Photography and filming by us
We sometimes take photographs and video footage at the planetarium, at our events and during activities, and we may use them on the Website, in printed material and on our social media channels.
Where an individual is identifiable, we rely on consent. We will tell you in advance when photography or filming is taking place, and we will ask for your agreement before using an image in which you are recognisable. Where a child is identifiable, we obtain the consent of a parent or guardian, and for school visits we ask the school to obtain that consent. You may withdraw your consent at any time by contacting us, and we will stop using the image in our own channels, although we cannot always recall material that has already been published or shared by others.
8.2 Photobooth
We operate a photobooth at the planetarium. Where you choose to use it, photographs of you, and of any other person appearing with you, are captured and processed so that the resulting images can be made available to you.
Use of the photobooth is entirely voluntary, and the photographs are collected and processed on the basis of your consent, which you give by choosing to use it. Notices are displayed at the photobooth explaining how it works and how the images are handled. Where a child uses the photobooth, we expect the child to be accompanied by a parent, guardian or responsible adult, whose consent is required.
We use photobooth images only for the purpose of providing them to you. We do not use them for marketing, publish them, or share them with third parties, unless you have given your separate, specific consent for that use.
Photobooth photographs are retained only for a predetermined retention period of 30 days, at the end of which they are permanently and securely deleted from our systems and from those of any provider acting on our behalf. You may ask us to delete a photobooth image before the end of that period, and we will do so. All processing of photobooth images is carried out in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679) and the applicable data protection legislation of the Republic of Cyprus.
8.3 Closed circuit television (CCTV)
We operate a CCTV system at our premises for the purposes of protecting the safety and security of visitors, staff and other persons present, and of protecting our property and that of our visitors against theft, damage and other unlawful acts. The legal basis for this processing is our legitimate interests in maintaining the security and safety of our premises, which we have assessed against the rights and freedoms of the individuals recorded.
CCTV cameras operate only in the areas where such monitoring is necessary for those purposes. Signage is displayed in a prominent position at the monitored areas, informing visitors that CCTV is in operation and identifying us as the controller. Cameras are not installed in areas where individuals have a heightened expectation of privacy, such as toilets and changing areas. The system records images only, and does not record sound.
Retention. CCTV footage is retained for a period of 11 days from the date of recording, after which it is securely and permanently deleted or destroyed by automatic overwriting. Footage is retained beyond that period only where a longer retention period is required or permitted by law, or where the footage is required in connection with a specific incident, investigation, complaint, or the establishment, exercise or defence of a legal claim. In such a case, the relevant footage is isolated, retained only for as long as necessary for that purpose, and then securely deleted or destroyed.
Access. Access to CCTV footage is strictly restricted to authorised persons who hold the relevant licence or authorisation issued by the Cyprus Police under the applicable legislation of the Republic of Cyprus governing private security services, and who require access in the performance of their duties. Access is granted on a documented, need to know basis, and viewing of recorded footage is logged.
Disclosure. We do not disclose CCTV footage to third parties, except to the Cyprus Police or other competent authorities where we are required or permitted to do so by law, to our legal advisers and insurers where necessary in connection with a claim, and to a person exercising their right of access to footage in which they appear, in which case the images of other individuals are obscured or otherwise protected.
Your rights. You have the right to request access to CCTV footage in which you appear, and the other rights set out in section 15, including the right to object to this processing on grounds relating to your particular situation. Because footage is retained for a short period, any such request should be made promptly, and in any event within the 11 day retention period, identifying the date, approximate time and location so that the footage can be located.
9. Children's privacy
We welcome families, children and school groups.
Under Cyprus law, a child may consent to the offer of information society services from the age of 14. Below that age, consent must be given, or authorised, by a person with parental responsibility. We do not knowingly create online accounts, loyalty memberships or newsletter subscriptions for children under 14 without such consent, and where we become aware that we hold personal data of a child under 14 without the necessary consent, we delete it.
Bookings for children are made by an adult, and we ask that any account used to book is held by an adult.
If you believe that a child has provided us with personal data without the necessary consent, please contact us and we will delete it.
10. School and group bookings
10.1 School and group bookings
For school and group bookings, our contact is the school or the organisation, and our contract is with them.
We ask schools and organisations to provide only what the visit requires, which is normally the group size, the age range, the name and contact details of the responsible teacher or group leader, and any accessibility or allergy information needed for the visit to proceed safely. We ask that pupils' individual personal details are not sent to us, and pupils' names are not required in order to attend. Where unnecessary personal data reaches us, we delete it.
The school or organisation remains responsible for having a lawful basis for providing any personal data to us, and for obtaining any parental consent required.
10.2 Camps and multi-day programmes
We run educational camps and multi-day programmes for children. These are organised through schools, and our contract is with the school. The school is responsible for enrolling participants, for having a lawful basis for passing us their information, and for obtaining the consent of parents and guardians where that is required.
Because a camp involves children taking part over an extended period, we necessarily receive more information than we would for a single visit. This is limited to what is needed for a child to take part safely, and normally consists of the child's name, the child's age or school year, emergency contact details for a parent or guardian, and any allergy, dietary, medical or accessibility information relevant to participation. We ask schools not to send us information beyond this, and where unnecessary personal data reaches us, we delete it.
Information about a child's health, allergies or medical needs is special category data. We process it only where explicit consent has been obtained through the school, or, in an emergency, where processing is necessary to protect the vital interests of the child or another person. It is made available only to those members of our staff who need it in order to supervise the programme safely and respond to an incident, and it is not used for any other purpose.
Information collected for a camp is retained only for as long as the programme requires. Health, allergy, dietary and emergency contact information is deleted within 30 days of the end of the camp, unless it is required in connection with an incident, complaint or legal claim, in which case it is retained only for as long as necessary for that purpose. Records of the booking itself are retained as set out in section 13.
Photographs and video footage taken during a camp are handled as set out in section 8. Where a child is identifiable, we use an image only where consent has been obtained from a parent or guardian, and we ask the school to obtain that consent as part of the enrolment process.
Throughout a camp, the children remain under the supervision of the school's own teaching staff. We provide the activities and the venue. This means that the school, not us, holds the participant records, and we ask schools to give us only what we need in order to run the activities safely, and to keep individual pupil details with the supervising teachers wherever possible.
11. Who we share your personal data with
We do not sell your personal data, and we do not share it with advertising networks.
We use a limited number of service providers who process personal data on our behalf, under a written contract that meets the requirements of Article 28 of the GDPR, and only on our instructions:
-
Website hosting, database and ticketing platform: AMS Media, which hosts the Website and stores bookings, passes and accounts.
-
Payment provider: Viva Wallet, which processes card payments and refunds.
-
Email delivery provider: which sends booking confirmations, tickets and service messages.
-
Newsletter platform: Mailchimp, which sends our newsletter to subscribers.
-
Analytics: our first party analytics, operated on our own infrastructure, as described in our Cookie Policy.
-
Accounting and invoicing system: WinMax, used to issue invoices and keep statutory sales records.
-
Cloud backup: Microsoft OneDrive, used for encrypted backups of our records.
Each of these providers acts only on our instructions, is bound by confidentiality, and may not use your personal data for its own purposes. A provider may engage a sub-processor only with our prior written authorisation, and remains responsible to us for that sub-processor. On termination of any of these arrangements, the provider must return the personal data to us in a usable format and then delete its own copies, save where it is required by law to retain them.
We may also disclose personal data to our professional advisers, such as our lawyers, auditors and accountants, where they are bound by confidentiality, to public authorities where we are required to do so by law, and to a purchaser or successor in the event of a sale or reorganisation of our business.
12. International transfers
We store personal data within the European Union wherever possible. Some providers, for example our newsletter platform and our cloud backup provider, may process personal data outside the European Economic Area.
Where that happens, the transfer is covered by an adequacy decision of the European Commission, or by the European Commission's Standard Contractual Clauses, together with appropriate technical and organisational safeguards. You may request a copy of the relevant safeguards by contacting us.
13. How long we keep your personal data
We keep personal data only for as long as we need it:
-
Booking, ticket, payment and invoicing records: 7 years, to meet Cypriot accounting and tax requirements.
-
Account, loyalty and membership records: for as long as the account is active, and for 24 months after your last activity, after which the account is deleted or anonymised.
-
Newsletter subscriptions: until you unsubscribe, after which we retain only a minimal suppression record.
-
Correspondence and contact form messages: 24 months from the conclusion of the matter.
-
Accessibility and dietary information: deleted after the visit to which it relates.
-
Camp health, allergy, dietary and emergency contact information: deleted within the period applied, to match section 10.2 of the end of the camp, unless required in connection with an incident, complaint or legal claim.
-
Photobooth photographs: the retention period, as mentioned to the section 8.2, after which they are permanently and securely deleted.
-
CCTV footage: 11 days, after which it is securely deleted or destroyed, unless it is required in connection with a specific incident, investigation, complaint or legal claim, or a longer period is required or permitted by law.
-
Consent records, including marketing and image consents: for the duration of the consent and for 24 months afterwards, so that we can demonstrate compliance.
-
Analytics data: aggregated and retained for 24 months.
-
Records relating to a dispute or legal claim: until the claim is resolved and any applicable limitation period has expired.
When a retention period ends, we delete the data or irreversibly anonymise it.
14. Security
We protect personal data using encrypted connections (HTTPS), access controls, role based permissions and database level security, so that our staff and systems can reach only the data they need. Where personal data is held on infrastructure operated by our platform provider, that provider is contractually required to apply equivalent security measures, to notify us without undue delay of any personal data breach, and to assist us in meeting our own obligations. Payment card details never reach our servers. Backups are encrypted. We keep our security measures under review, and we have procedures for identifying and responding to personal data breaches, including notifying the supervisory authority and affected individuals where the law requires it.
15. Your rights
You have the right to:
-
Access: obtain confirmation of whether we hold personal data about you and receive a copy of it.
-
Rectification: have inaccurate data corrected and incomplete data completed.
-
Erasure: ask us to delete your personal data, where we have no overriding lawful reason to keep it.
-
Restriction: ask us to suspend our use of your personal data in certain circumstances.
-
Object: object to processing based on our legitimate interests, and object at any time, absolutely, to direct marketing.
-
Portability: receive personal data you provided to us in a structured, commonly used and machine readable format, or have it transmitted to another controller.
-
Withdraw consent: where we rely on consent, withdraw it at any time, without affecting the lawfulness of what we did beforehand.
Exercising these rights is free of charge. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain our reasons if that ever arises.
We respond within one month. Where a request is complex, or where you have made a number of requests, we may extend that period by up to two further months, and we will tell you within the first month if we do.
To exercise a right, email info@planetariumcyprus.com. We may ask you for information to verify your identity before we act.
16. Automated decision making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not carry out profiling of that kind.
17. Whether you have to provide personal data
Where we need personal data in order to perform a contract with you, for example to issue a ticket, providing it is a requirement of entering into that contract, and we cannot complete the booking without it. Where we ask for personal data on the basis of consent, for example for the newsletter or for accessibility needs, providing it is entirely voluntary, and refusing has no effect on your ability to browse the Website or to book.
18. Complaints
If you are unhappy with how we handle your personal data, please tell us first, at info@planetariumcyprus.com, so that we have the opportunity to put it right.
You also have the right to lodge a complaint with the Cypriot supervisory authority:
Office of the Commissioner for Personal Data Protection
15 Kypranoros Street, 1061 Nicosia, Cyprus
P.O. Box 23378, 1682 Nicosia
Telephone: +357 22 818 456
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy
You also have the right to an effective judicial remedy.
19. Other websites
The Website contains links to other websites and to our social media channels. This policy applies only to the Website. We are not responsible for the privacy practices of other operators, and we encourage you to read their privacy notices.
20. Changes to this policy
We review this policy regularly and publish any updated version on this page, with the date at the top amended accordingly. Where a change is significant, we will draw attention to it on the Website and, where the law requires, notify you directly.
21. Languages
This policy is published in English, Greek and Russian. In the event of any discrepancy between the language versions, the Greek version prevails.
