Fern & Flow Hair logo

Legal

Privacy Policy

Last updated: 19 March 2026

1. Who we are

This Privacy Policy applies to the website fernandflow.co.uk and to the salon services provided by MAD & CO X LIMITED, trading as Fern & Flow Hair.

Registered office: 32 Eglington Drive, Wainscott, Rochester, England, ME3 8BF
Company registration number: 11336967
Salon address: 278 High Street, Beckenham, BR3 1DY
Email: hello@fernandflow.co.uk
Telephone: 020 8658 3868

We are the data controller for the personal data collected through this website and in the course of providing our salon services. We are committed to protecting your personal data and handling it responsibly, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What personal data we collect

We may collect and process the following categories of personal data:

When you make a booking

  • Full name
  • Email address
  • Phone number
  • Appointment history and service preferences
  • Any notes relating to your hair or treatment history shared with your stylist

When you contact us

  • Name and contact details provided in your message
  • The content of your enquiry

When you use our website

  • If you consent to analytics cookies: anonymised usage data collected by Google Analytics (e.g. pages visited, session duration, device type)
  • Your cookie preferences (stored locally in your browser)

3. How we collect your data

We collect personal data through the following means:

  • Our online booking system (provided by Slick, available at book.getslick.com)
  • Telephone and in-person bookings and enquiries
  • Email or contact form messages sent to us
  • Google Analytics, if you consent to analytics cookies on our website

4. How we use your data

We use your personal data for the following purposes:

PurposeLegal basis (UK GDPR)
Managing your appointment bookings and remindersContract performance (Art. 6(1)(b))
Communicating with you about your enquiryLegitimate interests (Art. 6(1)(f))
Keeping a record of your service history and preferencesLegitimate interests (Art. 6(1)(f))
Analysing website usage to improve our servicesConsent (Art. 6(1)(a)) — analytics cookies only
Complying with legal obligations (e.g. financial records)Legal obligation (Art. 6(1)(c))

We will never sell your personal data to third parties, nor will we use it for unsolicited marketing without your explicit consent.

5. Who we share your data with

We do not sell or rent your personal data. We may share it with the following trusted third parties, only where necessary to provide our services:

Slick (booking system)

Our online appointment booking is managed by Slick Appointments Ltd. They process your name, contact details and booking history on our behalf as a data processor.

Slick Privacy Policy

Google LLC (analytics)

If you consent, Google Analytics collects anonymised data about your visit. Google may process data outside the UK; standard contractual clauses are in place.

Google Privacy Policy

Vercel Inc. (website hosting)

Our website is hosted by Vercel. They process server logs on our behalf solely to operate the website infrastructure.

Vercel Privacy Policy

6. International data transfers

Some of our third-party service providers (including Google and Vercel) may process your data outside the United Kingdom. Where this occurs, we ensure that appropriate safeguards are in place — such as the UK International Data Transfer Agreement (IDTA) or standard contractual clauses — in accordance with UK GDPR Chapter V.

7. How long we keep your data

We retain your personal data only for as long as is necessary for the purposes described in this policy:

Data typeRetention period
Booking and appointment records3 years from last appointment
Financial and transaction records6 years (HMRC requirement)
General enquiry communications2 years from last contact
Website analytics dataUp to 14 months (Google Analytics default)
Cookie preference records1 year (stored in your browser)

8. Your rights under UK GDPR

Under UK GDPR, you have the following rights in relation to your personal data:

Right of access

You can request a copy of the personal data we hold about you (a Subject Access Request).

Right to rectification

You can ask us to correct inaccurate or incomplete data.

Right to erasure

You can ask us to delete your personal data, subject to any legal obligations to retain it.

Right to restrict processing

You can ask us to pause processing of your data in certain circumstances.

Right to data portability

You can request your data in a structured, machine-readable format.

Right to object

You can object to processing based on legitimate interests at any time.

Right to withdraw consent

Where processing is based on consent (e.g. analytics cookies), you can withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, please contact us at hello@fernandflow.co.uk. We will respond within one calendar month.

9. Cookies

We use cookies and similar technologies on our website. For full details of the cookies we use, the data they collect, and how to manage your preferences, please read our Cookie Policy.

10. Security of your data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. Our website is served over HTTPS. Access to personal data held in our booking system is restricted to authorised salon staff only.

While we take these measures seriously, please be aware that no method of electronic transmission or storage is completely secure. If you have any concerns about the security of your data, please contact us immediately.

11. Third-party links

Our website contains links to third-party websites, including our booking platform (Slick) and our Instagram profile. These websites have their own privacy policies and we are not responsible for their practices. We encourage you to read their policies before providing any personal data.

12. Children's privacy

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us and we will delete it promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this page periodically.

14. How to complain

If you are unhappy with how we have handled your personal data, please contact us first and we will do our best to resolve the issue:

MAD & CO X LIMITED (trading as Fern & Flow Hair)

278 High Street, Beckenham, BR3 1DY

hello@fernandflow.co.uk

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent data protection authority.

ICO contact details

Information Commissioner’s Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

ico.org.uk · Helpline: 0303 123 1113