Virtual Zone
Book

Privacy Policy

Last updated:

The website virtualzonevr.com (hereinafter, “VirtualZone”) is owned by Virtual Zone Nexus, S.L. (hereinafter, “VZ”), with Tax ID (CIF) B42692533 and registered address at Plaza de los Luceros, 17, Planta 1, 03004, Alicante, Spain. Email: info@virtualzone.es. Registered with the Commercial Registry of Alicante, volume 4280, page 32, sheet A-168908, entry 1.

This Privacy Policy governs the processing of users’ personal data (hereinafter, “Users”) by VZ in connection with the website and the services provided at its centers.

VZ processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), and Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI).

VZ reserves the right to modify the content of this Privacy Policy to adapt it to legislative or case-law developments, as well as to the criteria of the Spanish Data Protection Agency (AEPD) or the European Data Protection Board (EDPB).

1. Who is responsible for processing your personal data?

The controller responsible for processing personal data collected through this website and Virtual Zone’s centers in Spain is Virtual Zone Nexus, S.L., with Tax ID (CIF) B42692533, registered address at Plaza de los Luceros, 17, Alicante, Spain, email info@virtualzone.es.

Territorial scope of this policy. This Privacy Policy governs data processing carried out by Virtual Zone Nexus, S.L. in connection with the website and the centers it operates in Spain, in The Hague (Netherlands) and in Pune (India), the latter under the terms described in section 7.3. The centers operated in France (Paris, Bordeaux and Lyon) are run by Virtual Zone Francia, an affiliated company that acts as an autonomous and independent controller with respect to the personal data it collects. That entity has, or must have, its own privacy policy. This policy does not apply to processing carried out by Virtual Zone Francia.

2. What principles do we apply to the processing of your personal data?

  • Lawfulness, fairness and transparency: we only process your data when we have a valid legal basis (contract, consent, legal obligation or legitimate interest), and we inform you clearly beforehand.
  • Data minimization: we only request the data strictly necessary for each purpose.
  • Storage limitation: we keep data only for as long as necessary for its purpose (see section 6).
  • Integrity and confidentiality: we apply technical and organizational measures to guarantee the security of your data, in accordance with Art. 32 GDPR.

3. How have we obtained your personal data?

The personal data processed by VZ comes from:

  • Booking form (website, tablets at our premises, by phone or in person): name and surname, ID number, phone, and email address. VZ never collects bank card data or payment credentials; the payment process is handled directly by the corresponding payment gateway (see section 7).
  • Room access forms (minor authorization, liability waivers): the data described in each form, collected at the time of the experience.
  • Emails and inquiries received at our contact addresses.
  • Images and videos captured during the experience, with the express prior authorization of the User or, in the case of minors, of their parent or legal guardian.

The User is responsible for the accuracy of the data provided and for keeping it up to date.

In accordance with Art. 6 GDPR, the legal basis for processing varies depending on the purpose:

Purpose Legal basis Provision
Managing the booking and providing the contracted service Performance of a contract Art. 6.1.b) GDPR
Invoicing and tax obligations Legal obligation Art. 6.1.c) GDPR
Responding to inquiries submitted by email Pre-contractual measures / legitimate interest Art. 6.1.b) and f) GDPR
Sending commercial and promotional communications Express, free and specific consent (separate, non-pre-checked box) Art. 6.1.a) GDPR; Art. 21 LSSI
Capturing and using images/videos as a personal keepsake Express consent of the User (or of their legal representative, if a minor) Art. 6.1.a) GDPR; Art. 92 LOPDGDD
Commercial distribution of images/videos Express, specific, and differentiated consent Art. 6.1.a) GDPR; Art. 92 LOPDGDD
Analytics and personalization cookies Prior consent of the User Art. 22 LSSI

Important: consent to receive commercial communications and to the commercial distribution of images is never a condition for booking or taking part in the experience. It is requested separately and can be withdrawn at any time without affecting the provision of the service.

5. For what purposes do we process your personal data?

5.1. Booking form

Data from the booking form is processed to manage the booking, provide the contracted service, and inform the User about it.

5.2. Images and video during the experience

Images and video collected during the experience are processed, with express authorization, for the following purposes, which the User may consent to independently:

  • Monitoring of the experience by the VZ team, to ensure the activity is carried out correctly and to safeguard participants’ safety.
  • Sending a summary video or images as a memento of the experience, addressed exclusively to the participants in the group.
  • Commercial or promotional distribution (social media, website, or other channels) of images of adult participants, only if the participant has given express, specific, and differentiated consent for this purpose. Virtual Zone does not use images or videos featuring minors for commercial purposes.

5.3. Other purposes

  • Compliance with legal obligations and responding to requests from competent authorities.
  • Improving our products and services.
  • Managing our presence on social media, in accordance with the terms of use and privacy policies of each platform. For more information on the use of cookies, see our Cookie Policy.

6. How long do we keep your personal data?

Personal data will be kept for the following periods:

  • Booking and service-provision data: for the duration of the contractual relationship and, subsequently, for the statute-of-limitations periods applicable to any resulting legal actions (generally up to 5 years, under the general limitation period for personal actions).
  • Data for tax and accounting purposes: for the legally required period (generally 6 years under the Commercial Code, without prejudice to specific tax deadlines).
  • Personal keepsake images and video: kept for a maximum of 6 months from being sent to the adult responsible for the booking, unless the data subject requests earlier deletion, in which case VZ will delete it within a maximum of 30 days of receiving the request.
  • Images and video for commercial purposes (where consent exists): until the data subject withdraws consent, subject to periodic review of its validity. They will never be kept “indefinitely”.
  • Data processed on the basis of consent (marketing): until the User withdraws consent.

7. Who receives your personal data? Data processors and international transfers

Your personal data will not be sold, rented, or disclosed to third parties without your express consent or a legal obligation to do so. To provide its services, VZ relies on the following providers, which act as data processors under Art. 28 GDPR:

7.1. Providers established in the European Union

Provider Purpose Notes
Connectif (Spain) Marketing automation and customer communications management Established in the EU; does not involve an international data transfer.
Redsys Payment gateway (online POS and Bizum), connected to Banco Santander Established in Spain; does not involve an international data transfer.

7.2. Providers with international data transfers (outside the European Economic Area)

When a provider is located outside the European Economic Area (EEA), the GDPR requires the transfer to be based on an adequacy decision of the European Commission (Art. 45 GDPR) or on appropriate safeguards, such as standard contractual clauses (SCCs) (Art. 46 GDPR). The situation of each provider is detailed below:

Provider Purpose Country Transfer basis
Mailchimp (The Rocket Science Group LLC, a subsidiary of Intuit Inc.) Sending transactional emails United States EU-U.S. Data Privacy Framework, with standard contractual clauses incorporated as an additional safeguard should that framework be invalidated or become inapplicable.
Google Analytics (Google LLC) Measuring website usage and statistical analysis of browsing United States EU-U.S. Data Privacy Framework, with standard contractual clauses incorporated as an additional safeguard.
PayPal Payment gateway (alternative payment option) United States / Luxembourg Standard contractual clauses (PayPal does not participate in the Data Privacy Framework).

Note on the stability of this regime: the EU-U.S. Data Privacy Framework was adopted by an adequacy decision of the European Commission on 10 July 2023, replacing the former “Privacy Shield”, which was invalidated by the Court of Justice of the European Union in 2020 (the Schrems II ruling, case C-311/18). The new framework withstood an initial legal challenge before the General Court of the EU in September 2025, although that ruling has been appealed and the framework remains under review. VZ will periodically review the certification status of its providers and, if necessary, will adopt additional safeguards.

7.3. Pune (India) center and other international centers

In addition to its centers in Spain, VZ operates a center in Pune (India) and a center in The Hague (Netherlands). The Hague center operates under Virtual Zone Nexus, S.L. and is governed by this policy. As it is located in a European Union country, it does not involve an international data transfer outside the European Economic Area.

The Pune center shares a booking and user-data management system with the Spanish headquarters, to which Virtual Zone Nexus, S.L. has access from Spain. India does not have an adequacy decision from the European Commission (Art. 45 GDPR), so this access constitutes an international data transfer subject to Chapter V of the GDPR, covered by the appropriate safeguards provided for in Art. 46 GDPR.

7.4. Centers operated by Virtual Zone Francia

The centers in Paris, Bordeaux, and Lyon are operated by Virtual Zone Francia, an affiliated company that acts as an autonomous and independent data controller. This policy does not apply to personal data collected by that entity.

7.5. Nexus Consultores

VZ may engage Nexus Consultores as a data processor for advisory services related to VZ’s business activity, always acting under VZ’s instructions and with the safeguards required by Art. 28 GDPR.

7.6. Social media

VZ maintains a presence on social media (Facebook, Instagram, YouTube, and others it may use in the future). The processing of data of followers of these profiles is governed by this policy and, additionally, by the terms of use and privacy policies of each social network. VZ does not share followers’ personal data through these platforms beyond what the social network itself permits.

7.7. Capacity and centers

Virtual Zone Nexus, S.L. currently operates the following centers: Alicante, Valencia, Manises (Valencia), Murcia, Seville, Bilbao, Madrid (2 rooms), Pamplona, The Hague (Netherlands), and Pune, India (2 rooms). The list of centers may be updated as new centers open; the current version is always available at virtualzonevr.com.

8. What are your rights regarding your personal data?

Under the GDPR, you have the following rights:

  • Access: to know what data of yours we process, for what purpose, and its origin.
  • Rectification: to correct inaccurate or incomplete data.
  • Erasure: to request deletion of your data when it is no longer necessary, you withdraw your consent, you object to the processing, or the processing has been unlawful.
  • Objection: to object to the processing of your data on legitimate grounds, particularly regarding direct marketing.
  • Restriction of processing: to request restriction of processing in the cases set out in Art. 18 GDPR.
  • Portability: to receive your data in a structured, commonly used format, and to transmit it to another controller.
  • Withdrawal of consent: to withdraw, at any time, consent given for a specific purpose, without affecting the lawfulness of processing carried out prior to that withdrawal.

You can exercise these rights by contacting Virtual Zone Nexus, S.L., in writing at the address indicated in section 1, or by email to info@virtualzone.es, with the subject “Exercise of data protection rights” and a copy of your ID document.

If you believe that the processing of your data does not comply with applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid (www.aepd.es).

9. Minors

In accordance with Art. 7 LOPDGDD, the processing of a minor’s personal data may only be based on their own consent from the age of 14. Below that age, consent must be given by the minor’s parent or legal guardian.

The recommended minimum age for access to Virtual Zone’s experiences is 8 for cultural experiences and 10 for gaming experiences. This access age is distinct from the digital age of consent (14): for minors taking part in an experience between the minimum access age and 14, consent for the processing of their personal data must always be given by their parent or legal guardian, and not by the minor themselves, regardless of whether the minor physically takes part in the activity. This distinction is reflected in the minor authorization form.

Bookings made through the website may only be made by a person over 18 years of age, who will act as the person responsible for the booking and, where applicable, for any minors accompanying them.

10. Security measures

VZ applies appropriate technical and organizational measures to guarantee the security of personal data, including pseudonymization and encryption where relevant, in accordance with Art. 32 GDPR. In the event of a personal data breach, VZ will notify the affected individuals and the AEPD within the terms and deadlines set out in Art. 33 GDPR, where applicable.