Privacy Policy (UK GDPR Compliant)
Last updated: 10th July 2025
This Privacy Policy outlines how Bella Boxes (“we”, “us”, or “our”) collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Bella Boxes
[Optional: Registered address]
Contact: Bellaboxes@email.com
We are the Data Controller responsible for your personal data under this Privacy Policy.
2. What Personal Data We Collect
We may collect and process the following data about you:
✅ Information you provide:
Name, email, postal address, phone number
Payment details (processed securely via third-party providers)
Messages, reviews, or communications you send to us
Marketing preferences
✅ Information collected automatically:
IP address, browser type, device information
Website usage data through cookies or analytics tools
3. Lawful Basis for Processing
We only process your data when we have a lawful reason to do so under UK GDPR:
PurposeLawful BasisTo fulfill ordersContractual obligationTo communicate order updates or respond to enquiriesLegitimate interestTo send marketing emails (if opted-in)ConsentTo improve website performanceLegitimate interestTo comply with legal obligationsLegal requirement
4. How We Use Your Data
We use your data to:
Process and fulfill orders
Provide customer support
Manage your account or communication preferences
Improve website functionality
Comply with legal and tax obligations
Send marketing messages (if you’ve opted in)
5. Marketing & Consent
You will only receive marketing emails if you have opted in. You can withdraw your consent at any time by:
Clicking “unsubscribe” in any email, or
Contacting us at Bellaboxes@email.com
We do not sell or rent your data to third parties.
6. Cookies
We use cookies to:
Enable essential site functionality
Analyse website traffic
Remember user preferences
You can manage your cookie preferences through your browser settings.
7. Third-Party Services
We use third-party services (e.g. payment processors, email platforms, website hosting) who process your data on our behalf. These providers are contractually obligated to keep your data secure and comply with UK GDPR.
Examples include:
Create – site and order processing
PayPal – payment processing
Google Analytics – site usage data (anonymous)
8. Data Retention
We retain personal data:
For as long as necessary to fulfil the purpose it was collected for
As required for legal, tax, or accounting obligations
You can request deletion of your data unless we are required to keep it for compliance reasons.
9. Your Rights Under UK GDPR
You have the right to:
Access your personal data
Request correction of inaccurate data
Request erasure ("right to be forgotten")
Object to or restrict processing
Data portability (receive a copy in a usable format)
Withdraw consent at any time (where applicable)
To exercise any of these rights, please contact:
📧 Bellaboxes@email.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
📍 https://ico.org.uk/
📞 0303 123 1113
10. Children’s Privacy
Our products are marketed to adults for children's use. We do not knowingly collect data from children under 13. If you believe a child has submitted personal data, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with the date of the last update noted above.
12. Contact Us
If you have any questions or concerns about how we handle your data, please get in touch:
📧Bellaboxes@email.com