Publication version — updated 20 August 2026
Legal framework
This Policy is primarily based on the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. The European Union General Data Protection Regulation (GDPR) is taken into account only where a processing activity falls within its territorial scope.
This Policy explains how Chaplin's World SA collects, uses, discloses, retains and protects your personal data. It covers our website, ticketing and digital services, as well as the activities offered at Chaplin's World.
It applies in particular to visitors, customers, prospective customers, partners, applicants and users of our services, whether data are collected online or on site.
The data controller is:
Chaplin's World SA
A Swiss public limited company with share capital of CHF 200'000
Route de Fenil 2, 1804 Corsier-sur-Vevey, Switzerland
UID: CHE-100.468.361 — federal no.: CH-660.0.618.000-4
Telephone: +41 (0)21 903 01 20 or +41 (0)842 422 422
Email: contact@chaplinsworld.com
Certain Belgrano group companies and service providers supply IT, security, customer relations, payment, marketing or hosting services. They process data on behalf of Chaplin's World SA, on its instructions and under appropriate agreements. Where another entity determines its own purposes and means, its identity and role are stated at the point of collection or in the relevant service.
For any data protection question, you may write to contact@chaplinsworld.com. The Belgrano group Data Protection Officer may also be contacted at contact@chaplinsworld.com.
Our processing activities are primarily subject to the Swiss FADP and the Data Protection Ordinance. The FADP requires, in particular, lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and data security.
The GDPR applies in addition only where its territorial scope requirements are met, for example where processing relates to an offer of goods or services specifically directed at individuals in the European Economic Area, or to monitoring their behaviour there. In that case, the additional information and rights provided by the GDPR apply to the relevant processing.
We collect data:
Depending on your relationship with us and the services used, we may process the following categories:
Fields marked as mandatory are required to provide the requested service. Without them, we may be unable to process the request or perform the service.
The FADP does not use a list of legal bases identical to the GDPR. We process data in accordance with the FADP principles and, where a justification is required, on the basis of consent, the conclusion or performance of a contract, an overriding private or public interest, or the law. Where the GDPR applies, the corresponding legal bases are set out below.
Access to data is limited to persons who need it for their duties. Depending on the processing activity, recipients may include:
Our processors must handle data only on our instructions, implement appropriate security measures and comply with applicable confidentiality, sub-processing, deletion and return requirements.
Some data are hosted in or accessible from Switzerland, the European Union, the European Economic Area, the United Kingdom, the United States, Israel or other countries in which our providers or group companies operate.
Where the destination country is recognised by the Swiss Federal Council as providing adequate protection, disclosure relies on that decision. In other cases, we use a safeguard recognised under Swiss law, including standard contractual clauses adapted to Swiss law, and implement additional technical, contractual or organisational measures where necessary. The Swiss-U.S. Data Privacy Framework may also be used for certified U.S. recipients. Statutory exceptions may apply in specific situations.
You may request further information about destination countries and applicable safeguards using the contact details in section 2.
The website uses cookies and similar technologies to ensure its operation and security, remember your choices, measure audiences, personalise content and, with your agreement where required, conduct analytics or advertising campaigns.
Strictly necessary trackers may be used without consent where they are indispensable for the requested service or security. Other trackers are activated in accordance with your choices. You can accept, refuse or change your preferences at any time using the "Manage my cookie preferences" link in the website footer. Withdrawal does not affect the lawfulness of prior processing.
Detailed information on cookie categories, providers, purposes and durations appears in the Cookie Policy and the preference management tool.
With your consent where required, we may combine purchase history with browsing data to personalise content, communications and advertising campaigns. You may withdraw consent or object to this personalisation at any time.
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. If such a decision were introduced, you would be informed and could request human review, in accordance with applicable law.
Our services are not designed to collect data directly from children without an adult's involvement. Purchases, bookings and account creation for a minor must be carried out by an adult or with the adult's authorisation where the minor does not have the required capacity of judgement.
Where a legal representative's consent is required, we may request appropriate confirmation. If the GDPR applies to an information society service offered directly to a child, the age-of-consent rules under European law and, where applicable, the relevant national law are observed.
We implement technical and organisational measures proportionate to the risks, including access controls, authorisation management, backups, logging, encryption where appropriate, and incident detection and response procedures. Our providers are subject to corresponding requirements.
Where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected individuals, we notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. We also inform affected individuals where necessary for their protection or at the FDPIC's request. Where the GDPR applies, its notification rules are observed for the relevant processing.
Subject to the limits and conditions of applicable law, you may:
To exercise your rights, write to contact@chaplinsworld.com or to Chaplin's World SA, Data Protection, Route de Fenil 2, 1804 Corsier-sur-Vevey, Switzerland. Provide the information needed to identify the relevant relationship. If there is serious doubt and where necessary, we may request proof of identity; it is deleted once verification is complete.
We generally respond within thirty (30) days. This period may be extended where the request is complex or the law permits; we will inform you. Exercising your rights is generally free of charge, subject to statutory exceptions.
If you believe the processing of your data does not comply with Swiss law, you may contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, www.edoeb.admin.ch.
Where the GDPR applies, you may also lodge a complaint with the competent supervisory authority in the European Union or European Economic Area, in particular in the place of your habitual residence, place of work or place of the alleged infringement.
We may amend this Policy to reflect changes in our processing activities, services or applicable law. The current version and its update date are published on our website. In the event of a material change, additional notice may be provided by an appropriate means.