Privacy Policy (UK GDPR Compliant)

Last updated: 10th July 2025
This Privacy Policy outlines how Bella Boxes (“we”, “us”, or “our”) collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Bella Boxes
[Optional: Registered address]
Contact: Bellaboxes@email.com
We are the Data Controller responsible for your personal data under this Privacy Policy.

2. What Personal Data We Collect

We may collect and process the following data about you:

✅ Information you provide:

  • Name, email, postal address, phone number

  • Payment details (processed securely via third-party providers)

  • Messages, reviews, or communications you send to us

  • Marketing preferences

✅ Information collected automatically:

  • IP address, browser type, device information

  • Website usage data through cookies or analytics tools

3. Lawful Basis for Processing

We only process your data when we have a lawful reason to do so under UK GDPR:

PurposeLawful BasisTo fulfill ordersContractual obligationTo communicate order updates or respond to enquiriesLegitimate interestTo send marketing emails (if opted-in)ConsentTo improve website performanceLegitimate interestTo comply with legal obligationsLegal requirement

4. How We Use Your Data

We use your data to:

  • Process and fulfill orders

  • Provide customer support

  • Manage your account or communication preferences

  • Improve website functionality

  • Comply with legal and tax obligations

  • Send marketing messages (if you’ve opted in)

5. Marketing & Consent

You will only receive marketing emails if you have opted in. You can withdraw your consent at any time by:

  • Clicking “unsubscribe” in any email, or

  • Contacting us at Bellaboxes@email.com

We do not sell or rent your data to third parties.

6. Cookies

We use cookies to:

  • Enable essential site functionality

  • Analyse website traffic

  • Remember user preferences

You can manage your cookie preferences through your browser settings.

7. Third-Party Services

We use third-party services (e.g. payment processors, email platforms, website hosting) who process your data on our behalf. These providers are contractually obligated to keep your data secure and comply with UK GDPR.

Examples include:

  • Create – site and order processing

  • PayPal – payment processing

  • Google Analytics – site usage data (anonymous)

8. Data Retention

We retain personal data:

  • For as long as necessary to fulfil the purpose it was collected for

  • As required for legal, tax, or accounting obligations

You can request deletion of your data unless we are required to keep it for compliance reasons.

9. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure ("right to be forgotten")

  • Object to or restrict processing

  • Data portability (receive a copy in a usable format)

  • Withdraw consent at any time (where applicable)

To exercise any of these rights, please contact:
📧 Bellaboxes@email.com

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
📍 https://ico.org.uk/
📞
0303 123 1113

10. Children’s Privacy

Our products are marketed to adults for children's use. We do not knowingly collect data from children under 13. If you believe a child has submitted personal data, please contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with the date of the last update noted above.

12. Contact Us

If you have any questions or concerns about how we handle your data, please get in touch:

📧Bellaboxes@email.com