Privacy Policy

UNITED STATES PRIVACY STATEMENT

Harry Potter: The Exhibition Privacy Policy

This Privacy Policy was last modified on August 13, 2024.

Your United States Privacy Rights

Overview

This Privacy Policy (the “Policy”) governs the “Harry Potter: The Exhibition” websites (each a “Site” and collectively the “Sites”), mobile applications/apps (each an “App” and collectively the “Apps”) and also the exhibitions operated by HPX LLC Exhibitions, Inc. HPX LLC acts as the data controller for the processing of personal data (”HPX LLC”, ”we”, “us” or “our”). The Sites and the Apps, along with the related content, applications, technology and services that that we offer through them, are referred to collectively as the “Platform”.

This Policy describes:

The types of information we may collect or that you may provide when you download, register with, access, or use the Platform.

Our practices for collecting, using, maintaining, protecting, and disclosing that information.

This Policy applies only to information we collect on or through the Platform. This Policy DOES NOT apply to information that we collect offline, or that you provide to or is collected by any third party, which may have their own privacy policies that we encourage you to read before providing your information on or through them (see “Third-Party Information Collection” below).

Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. In using the Platform, you agree to be bound by this Policy. If you do not accept the terms of this Policy you may not access or use the Platform and you should discontinue your use of it.

This Policy may change from time to time (see “Changes to Our Privacy Policy” below). Your continued use of the Platform after we revise this Policy means you accept those changes, so please check this Policy periodically for updates.

How We Collect Information

We collect information from and about users of the Platform:

Directly from you when you provide it to us.

Automatically when you use the Platform.

Information You Provide Directly to Us

When you download, register with, access, or use any aspect of the Platform, we may ask you to provide the following types of information:

Information by which you may be personally identified, including but not limited to, your name, postal address, email address, and telephone number (“personal information”).

Payment information, including but not limited to, credit card information.

This information may be provided by you in the following ways:

Filling in forms on the Platform. This includes information that you may provide when downloading, registering with, accessing, or using any aspect of the Platform, when requesting further services, and when reporting problems with the Platform.

Contacting us. This includes information you may provide when you correspond with us, including, but not limited to, email addresses and phone numbers.

Participating in surveys. This includes information you may provide when you respond to surveys that we might ask you to complete for research purposes.

Carrying out transactions. Details of transactions you carry out through the Platform and of the fulfillment of your orders. You may be required to provide financial information before placing an order through the Platform.

Searching within the Platform. This includes information you may provide when you perform search queries on the Platform.

If you provide information for publication or display (“Posted”) on public areas of the Platform or websites you access through the Platform (collectively “User Contributions”), then your User Contributions are Posted and transmitted to others at your own risk. Additionally, we cannot control the actions of third parties with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.

Automatic Information Collection And Tracking

When you download, register with, access, or use any aspect of the Platform, the Platform may use technology to automatically collect:

Usage Details. When you access and use the Platform, we may automatically collect certain details of your access to and use of the Platform, including traffic data, location data, logs, and other communication data and the resources that you access and use on or through the Platform.

Device Information. We may collect information about your mobile device and internet connection, including the device’s unique device identifier, IP address, operating system, browser type, mobile network information, and the device’s telephone number.

Stored Information and Files. The Platform may also access metadata and other information associated with other files stored on your device. This may include, for example, photographs, audio and video clips, personal contacts, and address book information.

If you do not want us to collect any of the above information, then you may decide not to use the Platform or not to download the mobile application, or delete the mobile application from your device. For more information, see “Your Choices About Our Collection, Use, and Disclosure of Your Information” below.

Information Collection And Tracking Technologies

The technologies we use for automatic information collection may include:

Cookies. (or mobile cookies). A cookie is a small file placed on your smartphone. It may be possible to refuse to accept mobile cookies by activating the appropriate setting on your smartphone. However, if you select this setting you may be unable to access certain parts of our App.

Web Beacons. The Platform and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that we permit, for example, to count users who have visited those pages or opened an email and for other related app statistics (for example, recording the popularity of certain app content and verifying system and server integrity).

Third-Party Information Collection.

When you use the Platform or its content, certain third parties may use automatic information collection technologies to collect information about you or your device. These third parties may include:

Advertisers, ad networks, and ad servers.

Analytics companies. Please see additional information below under “Our Use of Google Analytics”.

Your mobile device manufacturer.

Your mobile service provider.

These third parties may use tracking technologies to collect information about you when you use the Platform. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites, apps, and other online services websites. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.

Our Use Of Google Analytics

We use a tool called “Google Analytics” to collect information about use of this site. Google Analytics collects information such as how often users visit or use the Platform, what pages users visit when they do so, and what other sites user used prior to coming to the Platform. For more information regarding how Google uses such information, please visit the following website: https://www.google.com/policies/privacy/partners/.

We use the information we get from Google Analytics to improve the Platform. Google’s ability to use and share information collected by Google Analytics about your visits to this the Platform is restricted by the Google Analytics Terms of Use (https://marketingplatform.google.com/about/analytics/terms/us/) and the Google Privacy Policy (https://policies.google.com/privacy). You can prevent Google Analytics from recognizing you on return visits to the Platform by disabling cookies on your browser. For more information on disabling cookies on your browser, see “Your Choices About Our Collection, Use, and Disclosure of Your Information” below.

How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information, to:

Provide you with the Platform and its contents, and any other information, products, or services that you request from us.

Fulfill any other purpose for which you provide it.

Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.

Notify you when updates for the Platform are available, and of changes to any products or services we offer or provide though it.

The usage information we collect helps us to improve the Platform and to deliver a better and more personalized experience by enabling us to:

Estimate our audience size and usage patterns.

Store information about your preferences, allowing us to customize the Platform according to your individual interests.

Speed up your searches.

Recognize you when you use the Platform.

We may also use your information to contact you about goods and services that may be of interest to you, including our own good and services or the goods and services of third parties. For more information, see “Your Choices About Our Collection, Use, and Disclosure of Your Information” below.

We may use the information we collect to display advertisements. Even though we do not disclose your personal information for these purposes, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.

Disclosure Of Your Information

We may disclose aggregated information about our users, and information that does not identify any individual without restriction.

In addition, we may disclose personal information that we collect or you provide:

To our subsidiaries and affiliates.

To contractors, service providers, and other third parties we use to support our business.

To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information we hold about the Platform’s users is among the assets transferred.

For any other purpose disclosed by us when you provide the information.

With your consent.

To comply with any court order, law, or legal process, including to respond to any government or regulatory request.

To enforce our rights arising from any contracts entered into between you and us and for billing and collection.

If we believe disclosure is necessary or appropriate to protect the rights, property, our safety, our customers, or others.

Your Choices About Our Collection, Use, And Disclosure Of Your Information

This section describes mechanisms that we provide for you to control certain uses and disclosures of your information.

Tracking Technologies. You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. However, if you disable or refuse cookies or block the use of other tracking technologies, some parts of the Platform may then be inaccessible or not function properly.

Promotion by HPX LLC. You can opt-out of receiving promotional materials by logging into the Platform and adjusting your user preferences in your account profile or by selecting “unsubscribe” in emails we send to you.

California residents may have additional personal information rights and choices. Please see “Your California Privacy Rights” below for more information.

Accessing and Correcting Your Personal Information

You can review and change your personal information by logging into the Platform and visiting your account profile page.

You may also send us an email at [email protected] to request access to, correct, or delete any personal information that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

If you delete your User Contributions from the Platform, copies of your User Contributions may remain viewable in cached and archived pages, or might have been copied or stored by other Platform users.

California residents may have additional personal information rights and choices. Please see “Your California Privacy Rights” below for more information.

Children’s Privacy And Age Limitations For The Platform

The Platform is intended for use by persons aged 13 or older, and by your use of this Platform you affirm that you are at least 13 years of age. We do not knowingly collect personal information from children under the age of 13. If we discover or are made aware that we have received personal information from an individual who indicates that he or she is, or whom we otherwise have reason to believe is, under the age of 13, we will delete such information from our systems. If you are a parent or guardian of a child under the age of 13 and believe that your child has disclosed personal information to us we welcome you contacting us as provided below so that we can address such matter.

From time to time there may be instances when we collect information through the Platform about children under the age of 13 but we will only do this when such information is provided to us by that child’s parent or guardian. In all cases where we’ve collected information about a child under the age of 13, the parent or guardian may contact us as provided below to review and request deletion of such child’s personal information as well as to prohibit the further use of such information by us.

California Minors

California residents under 18 years of age may have additional rights regarding the collection and sale of their personal information. Please see “Your California Privacy Rights” below for more information.

Changes To Our Privacy Policy

We may update this Policy from time to time. If we make material changes to how we treat our users’ personal information, we will post the most recent privacy policy on this page.

The date that this Policy was last revised is identified at the top of the page. You are responsible for periodically visiting this Policy to check for any changes.

Contact Information

To ask questions or comment about this Policy and our privacy practices, contact us via email at [email protected], or via regular mail at HPX LLC, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305.

Your California Privacy Rights

The following additional privacy notices for California residents (the “California Notice”) supplement the information contained in the other portions of this Policy and apply solely to individuals who reside in the State of California (“California consumer” or “you”). HPX LLC adopts this California Notice to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and their related regulations (collectively the “California Privacy Law” or the “CPL”) and other applicable California laws.

Overview Of Consumer Rights Under The CPL

Under the CPL, California consumers have certain rights regarding their personal information, including:

The right to know the categories of personal information that HPX LLC has collected and the categories of sources from which we obtained such information.

The right to know HPX LLC’s business purposes for sharing personal information.

The right to know the categories of third parties with whom HPX LLC shared personal information.

The right to know if we sold or disclosed your personal information for a business purpose, comprising two separate lists disclosing:

any sales, which list identifies the personal information categories that each category of recipient purchased (note that at present we do not sell personal information that we collect); and

any disclosures for a business purpose, which list identifies the personal information categories that each category of recipient obtained.

The right to access the specific pieces of personal information that HPX LLC has collected

The right to correct personal information that HPX LLC has collected.

The right to delete your personal information.

The right to not be discriminated against if a California consumer exercise their rights under the CPL.

The provisions below of this California Notice provide further details about these and other rights and certain details about the exercise of such rights.

Information We Collect

We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California consumer, household or device (collectively, “personal information”). Personal information does not include:

Publicly available information from government records.

De-identified or aggregated California consumer information.

Information excluded from the CPL’s scope, including:

Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data; and

Personal information covered by certain other laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.

We have collected the following categories of personal information from consumers within the last twelve (12) months:

Category Examples

Identifiers An individual’s name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number or other similar identifiers

Personal information categories described in Cal. Civ. Code § 1798.80(e) A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information

Commercial information Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies

Internet or other similar network activity Browsing history, search history, information on a California consumer’s interaction with our website, application, or advertisement and any social media sites from which user information is linked, connected or obtained

Inferences drawn from other personal information Examples include a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes

Geolocation data Physical location or movements (Note: Certain precise geolocation data may be considered to be sensitive personal information under the CPL and, to the extent such data is considered to be sensitive, personal information, you have the right to limit the use and disclosure of such data.)

Sources Of Personal Information

In addition to sources of personal information addressed elsewhere in this Policy, we obtain the categories of personal information listed above from the following categories of sources:

Directly From You. For example, from forms you complete or products and services you purchase or from communications with you such as when you contact HPX LLC (whether in person, by mail, by phone, online, via electronic communication or by other means) including our customer support service.

Indirectly From You. For example, from observing your actions on our Platform or from products or services that you have purchased from HPX LLC, if you have enabled such functionality, such as telemetry services.

From Others.

From Third Party Service Providers. For example, if you choose to make an electronic payment directly to HPX LLC, or through a linked website or mobile application, or through an affiliate of ours, HPX LLC may receive personal information about you from third parties such as payment services providers, for the purposes of that payment.

From Affiliates. We may collect personal information about you from our affiliates or others acting on their behalf.

From Public Sources. For example, we may collect information from public records.

Uses Of Personal Information

In addition to uses of personal information addressed elsewhere in this Policy, we may use or disclose the personal information we collect for one or more of the following business purposes:

To fulfill the reason that you provided the information. For example, if you share your name and contact information to request a price quote, request to be contacted by an affiliate, or ask a question about our products or services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a product or service, we may use that information to process your payment and facilitate delivery. We may also save your information to facilitate new product or service orders or to process returns.

To perform services such as customer service, order fulfillment, payment processing, financing and advertising, marketing or analytic services.

To advance our commercial or economic interests, such as by helping you to buy, rent, lease, join, subscribe to, provide, or exchange products, information, or services, or enabling or effecting, directly or indirectly, a commercial transaction.

To verify or maintain quality or safety standards or improve or upgrade a product or service provided or controlled by or for us.

To provide, support, personalize and develop our Platform, products and services such as to perform warranty related services or other post-sale activities such as product or service monitoring or repairs.

To create, maintain, customize and secure your account with us.

To process your requests, purchases, transactions and payments and prevent transactional fraud.

To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.

To personalize your Platform experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Platform, third-party sites and via mail, email or text message (with your consent, where required by law).

To help maintain the safety, security and integrity of our Platform, products and services, databases and other assets and business.

For testing, research and analysis purposes, including to develop and improve our Platform, products and services.

To respond to law enforcement requests and as required by applicable law, court order or governmental regulations.

As described to you when collecting your personal information or as otherwise set forth in the CPL or applicable law.

To send you information relevant to your past purchases and interests, subject to compliance with applicable laws regarding direct marketing.

To otherwise use as reasonably necessary and proportionate to achieve our operational or notified purpose for collecting personal information and as compatible with the context in which we collected the information.

To perform services on behalf of a CPL-covered business or its service provider, such as customer service, order fulfillment, payment processing, financing and advertising, marketing, or analytic services.

To review and audit our business interactions with you.

To detect or prevent security incidents or other illegal activity.

To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of a bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our Platform users, including California consumers, is among the assets transferred.

We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated or incompatible purposes without providing you notice.

Sharing Personal Information

We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.

In the preceding twelve (12) months, HPX LLC has disclosed the following categories of personal information for a business purpose:

Identifiers

Personal information categories described in Cal. Civ. Code § 1798.80(e)

Commercial information

Internet or other similar network activity

Inferences drawn from other personal information

The categories of third parties to which we may disclose personal information collected by us include the following:

Service providers

Affiliates

Recipients of data from cookies

Sales of Personal Information

HPX LLC does not sell personal information to third parties.

Exercising Your CPL Rights And Choices

The sections below describe how you may exercise your rights under the CPL.

Access to Specific Information and Data Portability Rights. You have the right to request that we disclose certain information to you about our collection and use of your personal information. Once we receive and confirm your verifiable consumer request (see “Exercising Access, Data Portability and Deletion Rights” below), we will disclose to you:

The categories of personal information we collected about you.

The categories of sources for the personal information we collected about you.

Our business or commercial purpose for collecting that personal information.

The categories of third parties with whom we share that personal information.

The specific pieces of personal information we collected about you (also called a data portability request).

If we disclosed your personal information for a business purpose, a list disclosing:

The personal information categories that each category of recipient obtained.

As allowed by the CPL, we do not provide these access and data portability rights (i) for business-to-business personal information or (ii), if applicable, as to personal information collected from HPX LLC’s California-based employees, job applicants or contractors when provided or collected in such employee, job applicant or contractor capacities.

Deletion And Correction Request Rights. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see “Exercising Access, Data Portability and Deletion Rights” below), we will delete (and direct our service providers to delete) your personal information from our (and service provider) records, unless an exception applies.

We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.

Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.

Debug products or services to identify and repair errors that impair existing intended functionality.

Exercise free speech, ensure the right of another California consumer to exercise their free speech rights, or exercise another right provided for by law.

Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.).

Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.

Enable solely internal uses that are reasonably aligned with California consumer expectations based on your relationship with us, such as future field campaigns or product safety issues.

Comply with a legal obligation.

Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

As allowed by the CPL, we do not provide these deletion rights (i) for business-to-business personal information or (ii) if applicable, as to personal information collected from HPX LLC’s California-based employees, job applicants or contractors when provided or collected in such employee, job applicant or contractor capacities.

In addition, if you provide us with a verifiable consumer request to correct inaccurate personal information that we maintain about you, we will use commercially reasonable efforts to correct such information in accordance with your instructions

Exercising Access, Data Portability, Deletion And Correction Rights. To exercise the access, data portability, deletion and correction rights described above, you should submit a verifiable consumer request to us by one of the following methods:

Emailing us at [email protected]

By postal mail at: HPX LLC Exhibitions, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305

Accessing your online account that you maintain with us

By calling us toll-free at 844-622-8724

Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of a minor child for whom you are a parent or legal guardian.

You may only make a verifiable consumer request for access or data portability twice within a twelve (12) month period. The verifiable consumer request must provide sufficient information that allows us to reasonably verify that you are the person about whom we collected personal information or an authorized representative, which may include:

Your name

Your address

Additional information depending upon the type of request and the sensitivity of the information involved with such request

Describe your request with sufficient detail to enable us to properly understand, evaluate and respond to such request.

We cannot respond to your request or provide you with personal information if we cannot verify your identity or your authority to make the request and confirm that the personal information involved with the request relates to you.

Making a verifiable consumer request does not require you to create an account with us. However, we will consider requests made through a password-protected online account that you maintain with us to be sufficiently verified when the request relates to personal information associated with that online account, provided such online account functionality is then made available by us on the Platform.

We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.

Response Timing And Format

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing.

If you have an online account with us, we may deliver our written response to that online account, provided that such online account functionality is then made available by us on the Platform. If you do not have an online account with us, or such functionality is not available for your online account we will deliver our written response by mail or electronically, at your option.

If we’re unable to comply with your request, the response we provide will also explain the reasons we cannot comply with the request. For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Non-Discrimination

We will not discriminate against you for exercising any of your CPL rights. Unless permitted by the CPL or other applicable law, we will not as a result of you exercising any of your rights under the CPL:

Deny you goods or services;

Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;

Provide you a different level or quality of goods or services; or

Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

However, we may offer you certain financial incentives permitted by the CPL that can result in different prices, rates, or quality levels. Any CPL-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.

Retention Of Personal Information

Our policy is to retain personal information only for as long as is necessary to fulfill the reason for which the personal information was collected and as necessary to process such personal information. 

In addition to the above, we will retain your personal information for the purposes of satisfying any professional, legal, accounting or reporting requirements to which we are subject.

 To determine the appropriate retention period for personal information, we consider the scope, nature and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of the personal information, the purposes for which we collected and processed your personal information and whether we can reasonably achieve those purposes through other means, as well as any applicable legal and professional requirements

Other California Privacy-Related Disclosures

Sharing Personal Information for Direct Marketing Purposes. Before sharing personal information of California consumers with third parties for direct marketing purposes we will obtain opt-in consent from the applicable California consumers or provide such California consumers with a cost-free method to opt out.

California Do-Not-Track Disclosure. At this time, the Platform is not set up to honor web browser do-not-track settings. Do-not-track is a privacy preference that users can set in their web browsers. When a user activates the do-not-track settings in browsers that offer this setting, the browser sends a message to websites or applications requesting them not to track the user. For more information about do-not-track matters, please visit www.allaboutdnt.org.

Information on Marketing Disclosures. California Civil Code Section 1798.83 permits our users who are California residents to request and obtain from us once a year, free of charge, information about the personal information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of personal information that was shared and the names and addresses of all third parties with which we shared information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us at: [email protected] or HPX LLC Exhibitions, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305.

Content Removal Requests for Platform Users Under 18 Years Old. If you are a Platform user under 18 years of age and reside in California, you may request and obtain removal of, content or information that you have posted on the Platform. You may send us any such requests by one of the following methods: (i) by email (writing “Privacy Policy/Removal Request” in the subject line) at [email protected]; or (ii) by writing to us at HPX LLC Exhibitions, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305. We will review the request and respond promptly. You should be aware that a request to remove content or information posted by you on the Platform does not ensure or require complete or comprehensive removal of such content or information from our databases.

Complaints

If you have any complaint about use of the Platform, you may contact us by email at [email protected], or by postal mail at HPX LLC Exhibitions, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305. In accordance with California Civil Code Section 1789.3, California residents may also file complaints with the Complaint Assistance Unit, Division of Consumer Services, California Department of Consumer Affairs by postal mail at 1625 North Market Road, Suite N112, Sacramento, CA 95834 or by telephone at 800-952-5210.

Changes to Our California Notice

We reserve the right to amend this California Notice at our discretion and at any time. When we make changes to this California Notice, we will post the updated California Notice on the Platform and update the California Notice’s effective date. Your continued use of our Platform following the posting of changes constitutes your acceptance of such changes.

Your Brazil Privacy Rights

Privacy Policy

Last Updated: June 26, 2024.

Please read this Privacy Policy carefully. By participating in Harry Potter: The Exhibition, accessing Our website, or using Our mobile application, You are acknowledging and agreeing to the terms outlined in this Privacy Policy.

This Policy may change from time to time, so please check it periodically for updates and review the date of the last modification at the top of the page.

1. Privacy Policy

This Privacy Policy (“Policy”) describes the processing and treatment of Personal Data and information made available or collected on the websites and applications where this Policy is disclosed, including Our websites (“Sites”), mobile applications (“App”), and RFID bracelet (“RFID”) that use Radio Frequency Identification technology, collectively referred to as the “Platform.”

This Policy also applies to information We collect offline. However, it does not apply to information You provide to or that is collected by Third Parties, which may have their own privacy policies. We encourage You to read the privacy policies of Third Parties before providing your information to or through them.

The Privacy Policy described here aims to demonstrate how your Personal Data is treated by HPX LLC Exhibitions, Inc., reinforcing Our commitment to important values, including good relationships and transparency with Data Subjects, in line with the provisions of the General Data Protection Law (Law 13,709/18).

2. Definitions

a)LGPD”: Lei Geral de Proteção de Dados, is the Brazilian data protection law that sets guidelines for the collection, use, processing, and storage of personal data.

b)Personal Data“: information related to an identified or identifiable natural person.

c) “Sensitive Personal Data“: Personal Data concerning racial or ethnic origin, religious belief, political opinion, union membership, or religious, philosophical, or political organization affiliation, health or sexual life data, genetic or biometric data, when linked to a natural person.

d) “Anonymized Data”: data related to the Data Subject that cannot be identified, considering the use of reasonable and available technical means at the time of its processing.

e) “Personal Data Processing”: any operation performed with Personal Data, including collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, disposal, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction.

f) “Data Subject” or “You“: a natural person to whom the Personal Data being processed refers.

g) “Controller”: a natural or legal person, public or private, responsible for decisions regarding the processing of Personal Data.

h) “Processor”: a natural or legal person, public or private, who processes Personal Data on behalf of the Controller.

i) “Data Protection Officer”: a person appointed by the Controller and Processor to act as a channel of communication between the Controller, Data Subjects, and the National Data Protection Authority (NDPA).

j) “Consent”: a free, informed, and unequivocal manifestation by which the Data Subject agrees to the processing of their Personal Data for a specific Purpose.

k) “Purpose”: the processing for legitimate, specific, explicit, and informed purposes to the Data Subject, without the possibility of subsequent processing incompatible with these purposes.

l) “Exhibition”: the name of the “Harry Potter: The Exhibition”, held in São Paulo, at Pavilhão Lucas Nogueira Garcez – Oca Ibirapuera (Av. Pedro Álvares Cabral, S/N, Gate 2, Moema, ZIP code: 04094-050).

m) “HPX LLC,” “We,” “Us,” or “Our“: responsible for the production, promotion, and management of the Platforms and the Exhibition, as well as the Controller and Processor of Personal Data.

n) “Platform”: Our websites (“Sites”), mobile applications (“App”), and RFID bracelets (“RFID”).

3. How And When We Collect Your Personal Data

We collect your Personal Data in the following ways:

a) Directly from You: when You provide it to Us through the Platform, forms, surveys, transactions, in person, etc.

b) Automatically: when You use the Platform, your Personal Data may be collected automatically without Us needing to request your Consent.

c) From Affiliates: We may collect personal information about You from Our affiliates or other persons acting on their behalf.

d) From service providers: when You use services from Our providers such as Eventim, Google Analytics, PhotoShoots, META, and sponsors, your data may be shared with these Third Parties.

e) From public data sources: when We collect your data made previously and manifestly public by You.

4. What Personal Data We Process

We may process various personals data that can be divided into the following categories:

a) Identifiers: name, pseudonym, address, ZIP code, online identifier, IP address, email address, driver’s license number, student ID number, passport number, or other similar identifiers of an individual, sounds, voice, image.

b) Commercial: purchase records and/or services acquired on Our Platform or during the Exhibition or other purchasing or consumption histories or trends to which We have access.

c) Internet: browsing history, search history, information on consumer interaction or experience with Our Platform.

d) Geolocation data: physical location or movements within the Platform or during your visit to the Exhibition.

5. How We Use Your Personal Data

We process your Personal Data to provide You with access and navigation to the Platform, as well as content, information, products, advertisements, experiences, and services online or offline or at the Exhibition that You request from Us or that We understand to be of interest to You.

Your Personal Data is also used to fulfill Our obligations arising from contracts entered between Us and You or between Us and Third Parties or legal obligations under Brazilian General Data Protection Law (LGPD) or and other international laws.

Personal data is also used to help Us improve and personalize your experience on the Platform and at the Exhibition, as well as to help Us estimate the size of Our audience and usage patterns.

6. Personal Data Processing

It is important for Us that You know how your data is processed, how We obtain it, and what this data is. Therefore, We have compiled the table below to exemplify data processing, although We may use other information in addition to those listed below:

Data SourceData Processed
Information You provide              We collect Personal Data provided by You through the Platforms or your presence at the Exhibition, in the following situations:

Signup for email marketing: (i) email

Press mailing list: (i) name; (ii) email; and (iii) phone number. Registration, download, access, or use of the Platform: (i) name; (ii) address; (iii) email; (iv) phone number; (v) payment information; (vi) address.Ticket booth: (i) name; (ii) email; (iii) purchase data (e.g., product, value, etc.), (iv) billing and shipping address.Press accreditation: (i) name; (ii) email; (iii) landline and cell phone number; (iv) passport photo.Half-price benefit confirmation: (i) name; (ii) email; (iii) student ID; (iv) RG; (v) Birth Certificate; (vi) Elderly Card; (vii) medical certificate (PCD); (viii) INSS card. Sponsorship: (i) name; (ii) email.Group tickets: (i) name; (ii) email; (iii) phone number.Chat and comments (social media): (i) name and profile photo; (ii) email; (iii) order number. Authorization for minors’ entry: (i) name; (ii) date of birth; (iii) RG; (iv) identification document. Survey: (i) name; (ii) email. Purchase of Photographs: (i) name; (ii) email; (iii) image  
Automatically collected information          We collect and automatically track: Platform usage: (i) usage details; (ii) traffic data; (iii) location data; (iv) browsing history; (v) IP address; (vi) operating system); (vii) browser type; (viii) mobile network information; (ix) phone number; (x) metadata; (xi) photographs; (xii) audio and video clips; (xiii) personal contacts and address book.   Participation in the Exhibition: (i) voice; (ii) image; (iii) footage.  
Information provided by partner companies and other sourcesWe may have access to your Personal Data through Third Parties to assist in the provision of Our services in the following situations:   Delivery of group tickets to a representative or authorized beneficiary: (i) name; (ii) email; (iii) phone number; (iv) RG.Ticket sales reports provided by Eventim: (i) name; (ii) email; (iii) phone number; (iv) purchase details (e.g., product, amount, etc.); (v) billing and shipping address.Accreditation of service providers and suppliers: (i) name and email of the person responsible for accreditation; (ii) name; (iii) function; (iv) photo; (v) vehicle model and license plate; (vi) biometrics.    

 In chats and social media comments, there is the possibility of freely inserting data, whether in conversation or as an attachment. However, We do not require excessive, unnecessary, or non-compliant data according to the LGPD.        

7. When Your Personal Data Will Be Processed By Us

We will only process your Personal Data in accordance with LGPD guidelines in the following cases:

a) upon your Consent; or

b) to comply with Our legal or regulatory obligations; or

c) when necessary for the execution of a contract or preliminary procedures related to a contract of which You are a party or the Data Subject, at your request; or

d) for the regular exercise of rights in judicial, administrative, or arbitration proceedings; or

e) when necessary to meet Our legitimate interests or those of Third Parties, but only after conducting a thorough legitimate interest assessment and where your fundamental rights and freedoms that require the protection of Personal Data do not prevail.

8. Personal Data Of Minors

 The processing of Personal Data of children and adolescents is done in their best interest and in compliance with the provisions of the Child and Adolescent Statute (Law No. 8,069/1990 – “ECA”) and the General Data Protection Law.

In this case, the primary legal basis for the processing of Personal Data of minors is the specific Consent of at least one of the responsible parties, pursuant to article 14, §1, of the LGPD. However, Personal Data collected with due Consent may also be processed to comply with legal or regulatory obligations (Art. 7, II, of the LGPD) or for the regular exercise of rights in judicial, administrative, or arbitration proceedings (Art. 7, VI, of the LGPD).

To access the Exhibition and the Platform, specific Consent of at least one of the responsible parties is essential, and participation without the collection of the data listed in item 6 above is not possible. Consent will be provided at the time of entry to the Exhibition, through reliable and specific means.

9. Purpose Of Processing And Adopted Legal Basis

In Our commitment to transparency, We list below the main Purposes of Our operations involving Personal Data, along with their respective legal bases for processing. Check:

Purpose                                                                                                            Legal Basis
Providing the service, ensuring its proper functionality.Art. 7, V of the LGPD – execution of          the contract between Us and You.
Responding to requests, fulfilling orders, and providing technical support.     Art. 7, V of the LGPD – execution of the contract between Us and You.
Sending administrative information about the Platforms and announcements about the Exhibition.Art. 7, V of the LGPD – execution of the contract between Us and You.
For advertising Purposes – targeted or not – via email marketing, banners, cookies, or other                    methods.Art. 7, IX of the LGPD – Our legitimate interest. If You do not wish to receive this type of content, simply inform Us and the sending will be interrupted.
For the regular exercise of rights related to processes or requests from public or governmental authorities.Art. 7, VI of the LGPD – regular exercise of rights in judicial, administrative, or arbitration proceedings by Us.
For backup and information management in databases.Art. 7, IX of the LGPD – Our legitimate interest.
For registering suppliers and sponsors.Art. 7, V of the LGPD – execution of the contract between Us and You.
To protect rights, privacy, security, property, operations, adopting storage of information in cloud, antivirus, and Firewall by Us.Art. 7, IX of the LGPD – Our legitimate interest.

For each category of Personal Data that We process, We rely on a specific legal basis. These include compliance with legal or regulatory obligations, execution of a contract or preliminary contractual procedures, regular exercise of rights in a legal process, legitimate interest, or your Consent, in accordance with articles 7 and 11 of the LGPD.

However, the processing of Personal Data undertaken by Us will always be based on some legal basis, as provided for in articles 7 and 11 of the LGPD, even if it has not been included in the table above.

10. Rights Of Data Subjects

You have the right to request information regarding the processing of your Personal Data from Us through the following requests:

a) Confirmation of the existence of processing: You can contact Us to confirm whether any of your Personal Data is processed by Us.

b) Access to data: You have the right to request access to existing data processed by Us.

c) Correction of incomplete, inaccurate, or outdated data: You can request that We, at any time, change your Personal Data in case it is incorrect, inaccurate, or outdated. Examples include name correction, phone number and address change. It is important that Personal Data be accurate and current, so it is up to You to keep Us informed in cases where your Personal Data needs to be corrected.

d) Anonymization, blocking, or elimination of unnecessary, excessive, or data processed in non-compliance with LGPD: You may request the blocking and deletion of your Personal Data. Such a request will only be denied by Us in cases where the request cannot be met or where its storage is mandatory or allowed according to the hypotheses listed in article 7 of the LGPD and other applicable provisions. Because anonymization prevents the identification of the individual, Anonymized Data is no longer considered Personal Data and therefore falls outside the scope of the LGPD.

e) Elimination of Personal Data processed with your Consent: your Personal Data will be deleted after the Purpose is fulfilled, except in cases of:

  1. Compliance with legal or regulatory obligations by Us; or
  2.  Transfer to a Third Party, provided that the data processing requirements set forth in the LGPD are respected; or
  3. Exclusive use by Us, with access by Third Parties prohibited, and provided that the data is anonymized.

f) Information from public and private entities with which We share data: You have the right to request access to Personal Data that has been sent to public and private entities.

g) Information on the possibility of not giving Consent and on the consequences of refusal: We are available to answer and assist transparently with any questions that may arise regarding the processing of your Personal Data, including the possible impacts of not providing Consent.

h) Revocation of Consent: The Consent provided by You may be revoked at any time through a written request to Us via a free procedure when this is the legal basis for the processing of data.

If You wish to exercise any of the rights provided in this clause, You must contact Us, through the email: [email protected]. We will make every effort to adopt the necessary measures within the deadlines indicated in the LGPD and other relevant regulations.

11. Cookie Policy

We use cookies on Our Platform. However, if You wish, You can disable some cookies by adjusting your browser settings. Note that disabling cookies may impair navigation performance on the Platform. The cookies used by Us have the following functionalities:

a) Necessary cookies: required to enable basic features of this site, such as providing secure login or adjusting your Consent preferences. These cookies do not store any personal identification data. They will always be activated.

b) Functional cookies: help perform certain functionalities, such as sharing site content on social media Platforms, collecting feedback, and other third-party features.

c) Analytical cookies: used to understand how visitors interact with the site. These cookies help provide information on metrics such as number of visitors, bounce rate, traffic source, etc.

d) Performance cookies: used to understand and analyze key performance indices of the site, which helps provide a better user experience for visitors.

e) Advertising cookies: used to provide visitors with personalized ads based on pages visited previously and to analyze the effectiveness of advertising campaigns.

f) Unclassified cookies: those that are being analyzed and have not yet been classified into a category.

12. Payment Data For Tickets

The sale of tickets for participation in the Exhibition takes place through the Platform https://www.eventim.com.br/campaign/harrypotterexhibition/?affiliate=HP0. Thus, We outsource the sale, issuance, and payment of tickets to Eventim, so We do not collect or store credit card data or other means of payment.

All financial transactions are handled by the Eventim Brasil São Paulo Sistemas e Serviços de Ingressos Ltda (“Eventim Brasil”). Only Eventim Brasil, responsible for the ticket sale and purchase transaction, has access to this data.

All information about the acquisition and use of tickets for access to the Exhibition can be accessed through the link: https://www.eventim.com.br/artist/harry-potter/harry-potter-the-exhibition-3634208/?affiliate=HP0. Furthermore, the Privacy Policy of Eventim Brasil is available at: https://www.eventim.com.br/help/data-protection/?affiliate=HP0.

Please note that by purchasing and using tickets, you agree to the terms and conditions of the Third Party site, as stated in the documents mentioned above.

Ticket issuance will be handled by Eventim Brasil, a duly accredited ticket issuer by Us. In this case, data sharing will be necessary for the execution of the contract and for the proper provision of the contracted service.

Eventim Brasil acts as Controller of the Personal Data entered by Users on the ticket sales Platform, being responsible for the collection, as provided by law, within the limits justified by legal basis set forth in articles 7 and 11 of the LGPD.

13. Sharing Data With Third Parties

We may share or collect your Personal Data with Third Parties, which may include:

a) Service providers, suppliers, etc., to fulfill contractual or legal obligations, such as: Eventim, Photoshoot, and META

b) Advertisers, ad networks, and ad servers.

c) Analytics companies, such as Google Analytics.

These Third Parties may use tracking technologies to collect your Personal Data when You use the Platform. Third Parties may use this Personal Data to provide You with (behavioral) targeted advertising or other targeted content.

While We do not control the tracking technologies of these Third Parties, any interactions with these Third Parties on Our Platform are governed by the respective privacy policies of these Third Parties.   If You have any questions about an advertisement or other targeted content from a Third Party, contact the responsible provider directly, read their Terms and Conditions of Use and Privacy Policy.

In addition, We share or collect your Personal Data to comply with legal or regulatory obligations, at the request of the Public Administration or the Judiciary, or for the provision of their services, with contracted staff.

All sharing is done with the adoption of necessary technical and administrative security measures.

In addition to these cases, We share Personal Data when sharing is necessary to comply with applicable law or upon request from public or governmental authorities.

14. Security Measures And Data Confidentiality

We are committed to maintaining the confidentiality, integrity, and security of any data provided by You.

Without prejudice to other measures, all information is stored on Our internal server and on the cloud server used by Us, located in [insert location].

In summary, We adopt appropriate technical and administrative security measures to protect Personal Data under your control, and We keep a record of the Personal Data processing operations We perform.

Whenever possible, We will use anonymization mechanisms to ensure greater confidentiality and security of your Personal Data.

15. Retention And Disposal Of Personal Data

Processed Personal Data will be stored for the duration of the contract (Art. 7, V of the LGPD). After the contract ends, your information, including Personal Data of Third Parties, will be stored as prescribed by Brazilian law, unless processing is based on Consent, which may be revoked at any time by emailing [email protected]. If there is a legitimate interest justifying storage, the possibility of opting out will be offered in cases involving marketing communications.

After the prescription period, processed Personal Data will be deleted, except in cases where processing is necessary due to the hypotheses provided for in the items of Art. 16 of the LGPD, highlighted below:

I. compliance with legal or regulatory obligation by the Controller.

II. study by research body, ensuring, whenever possible, anonymization of Personal Data.

III. transfer to a Third Party, provided that the data processing requirements set forth in this Law are respected; or

IV. exclusive use by the Controller, access by Third Parties prohibited, and data anonymized.

16. Modification Of Privacy Policy

We may modify, alter, or replace this Privacy Policy at any time, so it is important for You to stay attentive to the date indicated at the beginning of this Policy.

Your EU Privacy Rights

Persons who are residents of the member countries of the European Union (“EU”) or other data subjects covered by the EU’s General Data Protection Regulation, (EU) 2016/679 (the “GDPR”), have certain additional privacy rights under applicable law. The following provisions of this Privacy Policy provide an overview of these additional rights.

Legal Bases For Processing Personal Information Of European Union Citizens

When processing your personal information, HPX LLC may rely on one or more of the following legal bases (or other available legal grounds), depending on the circumstances:

Legitimate Interests. We may process your personal information where HPX LLC has a legitimate interest in such processing for managing, operating or promoting our business, and that legitimate interest is not overridden by your interests, fundamental rights or freedoms.

We may process your personal information where HPX LLC has obtained your consent to the processing.

Contractual Necessity. We may process your personal information where such processing is necessary in connection with any contract that HPX LLC has with you.

Legal Requirements. We may process your personal information where such processing is required by applicable law.

Disclosures To Third Parties

Your personal information will not be disclosed to third parties except for where it is necessary for fulfillment of HPX LLC’s obligations to you or where HPX LLC is obliged or permitted to do so by law (including, without limitation, through the terms of any agreement HPX LLC may have with you), or where HPX LLC makes disclosures that are otherwise consistent with the uses described in this Policy.

HPX LLC may also disclose any information (including personal information) relating to you to law enforcement authorities or any regulatory or government authority in response to any request including requests in connection with the investigation of any suspected illegal activities.

HPX LLC reserves the right to transfer any personal information HPX LLC has about you in the event HPX LLC sells or transfers all or a portion of our business or assets, or merges with another organization. Should such a sale, transfer or merger occur, HPX LLC will use reasonable efforts seeking to require that the transferee uses personal information you have provided to HPX LLC in a manner that is consistent with this Policy.

We will not sell, resell or lease your personal information to any third parties but HPX LLC may, if required for the purpose(s) for which your personal information was collected and processed, share it with HPX LLC partners and/or service providers to enable them to provide their services to HPX LLC or to you, as applicable. The foregoing are in addition to the other uses described elsewhere in this Policy.

Security Of Personal Information Of European Citizens

HPX LLC has policies and technical and organizational measures in place which are intended to safeguard and protect your personal information against unauthorized access, accidental loss, improper use and disclosure. However, you should be aware that information transmitted over the internet is not completely secure because of the nature of the internet and that systems and measures used to secure information are not flawless. For these reasons, although HPX LLC will use reasonable efforts to protect your personal information, HPX LLC does not warrant the security of personal information transmitted to HPX LLC or stored by HPX LLC, and personal information that is transmitted to HPX LLC by you electronically is done at your own risk.

Retention Of Personal Information Of European Citizens

Our policy is to retain your personal information only for as long as is necessary to fulfill the purposes for which HPX LLC collected such personal information, including for the purposes of satisfying any professional, legal, accounting or reporting requirements to which HPX LLC is subject. 

The visitors’ personal data are stored as long as the accounts remain active. In the event of prolonged inactivity, this data will be kept for a period of 3 years from the date of their visit to the exhibition. If visitors choose to unsubscribe, their data are archived and no longer processed. The data are archived, to meet our legal, regulatory, or other obligations. 

The photographs of visitors are associated with the visitor’s account and are kept for as long as the account remains active. If the account is closed, the account data will be deleted within 30 days and a written confirmation will be sent when completed; otherwise, the account data will be archived after 3 years of inactivity. 

Your Rights As A European Citizen

You have a number of rights concerning your personal information that HPX LLC holds and uses, including the following:

Right of Access. You have the right to be informed about what personal information HPX LLC holds about you and to a copy of this personal information.

Right to Rectification. You have the right to have any inaccurate personal information which HPX LLC holds about you updated or corrected.

Right to Erasure. In certain circumstances you may request that HPX LLC delete the personal information that HPX LLC holds about you.

Right to Complain. You have the right to lodge a complaint regarding the processing of your personal information to an applicable governmental or supervisory authority in your country.

Right to Withdraw Consent. Where processing of personal information is based on your consent, you have the right to withdraw such consent at any time.

Right to Object. Where HPX LLC relies on our legitimate interests to process your personal information, you have the right to object to such use and HPX LLC is required to discontinue such processing unless HPX LLC can demonstrate an overriding legitimate interest in such processing.

Right to Restriction. You have the right to request that HPX LLC stop using your personal information in certain circumstances including if you believe that the personal information HPX LLC holds about you is inaccurate or that HPX LLC’s use of your personal information is unlawful. If you validly exercise this right, HPX LLC will store your personal information and will not carry out any other processing until the issue is resolved.

Right to Data Portability. Where you have provided personal information to us based on consent or for us to perform a contract with you or where the processing is performed by automated means, then in such circumstance you have the right to obtain personal information that you’ve provided to us to be made available to you in a structured, commonly used and machine-readable format so that you can use it elsewhere.

You may exercise any of the above rights and/or request that HPX LLC stop using your personal information for marketing purposes at any time by writing to HPX LLC via email at [email protected], or via regular mail at HPX LLC Exhibitions, 2870 Peachtree Road, Suite 418, Atlanta, GA 30305.