The Worlds
Discover all the worlds →
The Manoir

Where he was simply Charlie.

The Studio

Where he became the Tramp.

The Park

Four hectares. No fixed route.

The Shop

In the garage where the Bentley used to be.

The Restaurant

Sit down. Stay a while.

The Life of Chaplin

Before the Tramp, there was Charlie.

Discover
What's on
Plan your visit
See all visitor information →
General information

Hours, address, access…

Accessibility

Cloakroom, disabled access, accompanying person...

FAQ

We answer recurring questions

You are an individual

Prices, passes, gift cards, combined tickets...

Discover
You are a group

Companies, associations, schools...

Discover
Private events
Language : EN
FrenchGerman
My account
English
English
Book a ticket

Privacy policy

Publication version — updated 20 August 2026

Legal framework

This Policy is primarily based on the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. The European Union General Data Protection Regulation (GDPR) is taken into account only where a processing activity falls within its territorial scope.

1. Purpose and scope

This Policy explains how Chaplin's World SA collects, uses, discloses, retains and protects your personal data. It covers our website, ticketing and digital services, as well as the activities offered at Chaplin's World.

It applies in particular to visitors, customers, prospective customers, partners, applicants and users of our services, whether data are collected online or on site.

2. Data controller and contact details

The data controller is:

Chaplin's World SA
A Swiss public limited company with share capital of CHF 200'000
Route de Fenil 2, 1804 Corsier-sur-Vevey, Switzerland
UID: CHE-100.468.361 — federal no.: CH-660.0.618.000-4
Telephone: +41 (0)21 903 01 20 or +41 (0)842 422 422
Email: contact@chaplinsworld.com

Certain Belgrano group companies and service providers supply IT, security, customer relations, payment, marketing or hosting services. They process data on behalf of Chaplin's World SA, on its instructions and under appropriate agreements. Where another entity determines its own purposes and means, its identity and role are stated at the point of collection or in the relevant service.

For any data protection question, you may write to contact@chaplinsworld.com. The Belgrano group Data Protection Officer may also be contacted at contact@chaplinsworld.com.

3. Applicable law

Our processing activities are primarily subject to the Swiss FADP and the Data Protection Ordinance. The FADP requires, in particular, lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and data security.

The GDPR applies in addition only where its territorial scope requirements are met, for example where processing relates to an offer of goods or services specifically directed at individuals in the European Economic Area, or to monitoring their behaviour there. In that case, the additional information and rights provided by the GDPR apply to the relevant processing.

4. How do we collect your data?

We collect data:

  • directly from you when you create an account, purchase or book a service, complete a form, subscribe to communications, take part in an activity or contact us;
  • during your visit, including in connection with accessibility services, rentals, lost property, first aid, photographs, public Wi-Fi and CCTV;
  • automatically when you browse, through technical logs, cookies and similar technologies, in accordance with your choices;
  • from partners through which you booked our services, including travel agencies, distributors and ticketing platforms;
  • from a social sign-in provider if you voluntarily choose to sign in with an Apple, Google or Facebook account.

5. What data do we process?

Depending on your relationship with us and the services used, we may process the following categories:

  • identification and contact data: title, surname, first name, postal address, email address, telephone number and date of birth;
  • account and order data: login details, purchase and visit history, tickets, bookings, preferences and correspondence;
  • payment and billing data: amount, payment method and status, transaction references and accounting data; full card data are handled by the payment provider and Chaplin's World does not retain the card security code;
  • browsing and technical data: IP address, device identifiers, pages viewed, interactions, language, operating system, connection logs and cookie choices;
  • photographs and CCTV images;
  • data relating to accompanying persons, group members or relatives where required for a booking;
  • sensitive data strictly required for accessibility, a reduced fare or priority entitlement, or first aid, including health or disability information;
  • application data: career history, qualifications, contact details and submitted documents;
  • any other information you choose to provide in a request.

Fields marked as mandatory are required to provide the requested service. Without them, we may be unable to process the request or perform the service.

6. Purposes, justifications and retention periods

The FADP does not use a list of legal bases identical to the GDPR. We process data in accordance with the FADP principles and, where a justification is required, on the basis of consent, the conclusion or performance of a contract, an overriding private or public interest, or the law. Where the GDPR applies, the corresponding legal bases are set out below.

Accounts, orders and payments

  • Purpose: manage accounts, bookings, tickets, payments, invoices and evidence.
  • Justification / GDPR basis where applicable: contract; legal obligations; legitimate interests.
  • Indicative maximum retention period: account: while active, then 2 years. Accounting records and evidence: up to 10 years. The card security code is not retained.

Customer service and competitions

  • Purpose: respond to requests, handle complaints and administer promotional operations.
  • Justification / GDPR basis where applicable: contract or competition rules; legitimate interests; legal obligations.
  • Indicative maximum retention period: time needed to handle the matter; up to 10 years where required as evidence. Competitions: 6 months, subject to records that must be retained.

Marketing and personalisation

  • Purpose: send communications, measure effectiveness and tailor content to presumed interests.
  • Justification / GDPR basis where applicable: consent where required; legitimate interest for permitted communications to customers, with a simple right to object.
  • Indicative maximum retention period: until withdrawal or objection; prospect: 3 years after last contact; customer: 5 years. Browsing data used for personalisation: no more than 12 months.

Statistics and improvement

  • Purpose: measure attendance and satisfaction, compile statistics and improve services.
  • Justification / GDPR basis where applicable: legitimate interest; consent where required for tracking technologies.
  • Indicative maximum retention period: time needed for the analysis, followed by deletion or anonymisation.

On-site services

  • Purpose: manage passes, photos, rentals, lost property, fare evidence and accessibility services.
  • Justification / GDPR basis where applicable: contract; legitimate interests; explicit consent where required for sensitive data.
  • Indicative maximum retention period: depending on the service: visit or contract duration. Exceptional copy of evidence: 24 hours; purchased photo: 2 months; pass: 6 months after expiry; lost-property report: 1 year.

Security and incidents

  • Purpose: ensure safety, operate CCTV, provide assistance and manage liabilities.
  • Justification / GDPR basis where applicable: legitimate or vital interests; legal obligations; defence of legal claims.
  • Indicative maximum retention period: CCTV: 7 days unless an incident occurs. Incident file: up to 20 years for bodily injury and 10 years for property damage, or for the duration of proceedings.

Applications

  • Purpose: assess and manage job applications.
  • Justification / GDPR basis where applicable: pre-contractual measures; legitimate interest.
  • Indicative maximum retention period: 6 months after the decision; up to 2 years with consent for a candidate pool.

IT security and rights

  • Purpose: prevent misuse, document incidents and handle data-rights requests.
  • Justification / GDPR basis where applicable: legal obligations; legitimate interest in security and evidence.
  • Indicative maximum retention period: as long as necessary; records of a rights request generally 5 years after closure, unless a different period is required.

7. Recipients and processors

Access to data is limited to persons who need it for their duties. Depending on the processing activity, recipients may include:

  • authorised Chaplin's World SA departments, including reception, ticketing, reservations, customer service, sales, marketing, finance, human resources, security and IT;
  • Belgrano group companies providing shared functions;
  • ticketing, payment, hosting, cloud, maintenance, communications, printing, survey, security, audience measurement and advertising providers;
  • guides, food-service operators, service partners and distributors, to the extent required to perform a booking;
  • social sign-in providers and social networks when you choose to use their service or interact with their content;
  • professional advisers, insurers, auditors and competent authorities where required by law or to establish, exercise or defend rights.

Our processors must handle data only on our instructions, implement appropriate security measures and comply with applicable confidentiality, sub-processing, deletion and return requirements.

8. Disclosure of data abroad

Some data are hosted in or accessible from Switzerland, the European Union, the European Economic Area, the United Kingdom, the United States, Israel or other countries in which our providers or group companies operate.

Where the destination country is recognised by the Swiss Federal Council as providing adequate protection, disclosure relies on that decision. In other cases, we use a safeguard recognised under Swiss law, including standard contractual clauses adapted to Swiss law, and implement additional technical, contractual or organisational measures where necessary. The Swiss-U.S. Data Privacy Framework may also be used for certified U.S. recipients. Statutory exceptions may apply in specific situations.

You may request further information about destination countries and applicable safeguards using the contact details in section 2.

9. Cookies and similar technologies

The website uses cookies and similar technologies to ensure its operation and security, remember your choices, measure audiences, personalise content and, with your agreement where required, conduct analytics or advertising campaigns.

Strictly necessary trackers may be used without consent where they are indispensable for the requested service or security. Other trackers are activated in accordance with your choices. You can accept, refuse or change your preferences at any time using the "Manage my cookie preferences" link in the website footer. Withdrawal does not affect the lawfulness of prior processing.

Detailed information on cookie categories, providers, purposes and durations appears in the Cookie Policy and the preference management tool.

10. Profiling and automated decisions

With your consent where required, we may combine purchase history with browsing data to personalise content, communications and advertising campaigns. You may withdraw consent or object to this personalisation at any time.

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. If such a decision were introduced, you would be informed and could request human review, in accordance with applicable law.

11. Children's data

Our services are not designed to collect data directly from children without an adult's involvement. Purchases, bookings and account creation for a minor must be carried out by an adult or with the adult's authorisation where the minor does not have the required capacity of judgement.

Where a legal representative's consent is required, we may request appropriate confirmation. If the GDPR applies to an information society service offered directly to a child, the age-of-consent rules under European law and, where applicable, the relevant national law are observed.

12. Security and data breaches

We implement technical and organisational measures proportionate to the risks, including access controls, authorisation management, backups, logging, encryption where appropriate, and incident detection and response procedures. Our providers are subject to corresponding requirements.

Where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected individuals, we notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. We also inform affected individuals where necessary for their protection or at the FDPIC's request. Where the GDPR applies, its notification rules are observed for the relevant processing.

13. Your rights

Subject to the limits and conditions of applicable law, you may:

  • ask whether we process data about you and obtain the information required by law together with a copy of the data;
  • have inaccurate data corrected or incomplete data completed;
  • request deletion or object to unlawful processing, subject to our retention duties and legitimate interests;
  • withdraw consent at any time, without retroactive effect;
  • request the release or transfer of certain data in a commonly used electronic format where the legal conditions for portability are met;
  • request human review of an individual automated decision where provided by law;
  • where the GDPR applies, request restriction of processing and exercise the other rights it provides.

To exercise your rights, write to contact@chaplinsworld.com or to Chaplin's World SA, Data Protection, Route de Fenil 2, 1804 Corsier-sur-Vevey, Switzerland. Provide the information needed to identify the relevant relationship. If there is serious doubt and where necessary, we may request proof of identity; it is deleted once verification is complete.

We generally respond within thirty (30) days. This period may be extended where the request is complex or the law permits; we will inform you. Exercising your rights is generally free of charge, subject to statutory exceptions.

14. Supervisory authorities

If you believe the processing of your data does not comply with Swiss law, you may contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, www.edoeb.admin.ch.

Where the GDPR applies, you may also lodge a complaint with the competent supervisory authority in the European Union or European Economic Area, in particular in the place of your habitual residence, place of work or place of the alleged infringement.

15. Changes to this Policy

We may amend this Policy to reflect changes in our processing activities, services or applicable law. The current version and its update date are published on our website. In the event of a material change, additional notice may be provided by an appropriate means.

Rte de Fenil 2, 1804 Corsier-sur-Vevey, Suisse
+41 842 422 422
contact@chaplinsworld.com
The Worlds
What's on
Practical information
Individuals
Groups
Privatisate events
Press
FAQ
Our commitments
Legal notice
Cookies policy
Privacy policy
Terms and Conditions
Credits
Subscribe
What's on, news, and a special gift just for you. A little of Chaplin's World. Straight to your inbox.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting your email.
By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.
Follow us on:
CHAPLIN'S WORLD™ © BUBBLES INCORPORATED SA