Legal
Privacy Policy
Last updated: 19 March 2026
1. Who we are
This Privacy Policy applies to the website fernandflow.co.uk and to the salon services provided by MAD & CO X LIMITED, trading as Fern & Flow Hair.
Registered office: 32 Eglington Drive, Wainscott, Rochester, England, ME3 8BF
Company registration number: 11336967
Salon address: 278 High Street, Beckenham, BR3 1DY
Email: hello@fernandflow.co.uk
Telephone: 020 8658 3868
We are the data controller for the personal data collected through this website and in the course of providing our salon services. We are committed to protecting your personal data and handling it responsibly, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What personal data we collect
We may collect and process the following categories of personal data:
When you make a booking
- Full name
- Email address
- Phone number
- Appointment history and service preferences
- Any notes relating to your hair or treatment history shared with your stylist
When you contact us
- Name and contact details provided in your message
- The content of your enquiry
When you use our website
- If you consent to analytics cookies: anonymised usage data collected by Google Analytics (e.g. pages visited, session duration, device type)
- Your cookie preferences (stored locally in your browser)
3. How we collect your data
We collect personal data through the following means:
- Our online booking system (provided by Slick, available at book.getslick.com)
- Telephone and in-person bookings and enquiries
- Email or contact form messages sent to us
- Google Analytics, if you consent to analytics cookies on our website
4. How we use your data
We use your personal data for the following purposes:
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Managing your appointment bookings and reminders | Contract performance (Art. 6(1)(b)) |
| Communicating with you about your enquiry | Legitimate interests (Art. 6(1)(f)) |
| Keeping a record of your service history and preferences | Legitimate interests (Art. 6(1)(f)) |
| Analysing website usage to improve our services | Consent (Art. 6(1)(a)) — analytics cookies only |
| Complying with legal obligations (e.g. financial records) | Legal obligation (Art. 6(1)(c)) |
We will never sell your personal data to third parties, nor will we use it for unsolicited marketing without your explicit consent.
5. Who we share your data with
We do not sell or rent your personal data. We may share it with the following trusted third parties, only where necessary to provide our services:
Slick (booking system)
Our online appointment booking is managed by Slick Appointments Ltd. They process your name, contact details and booking history on our behalf as a data processor.
Slick Privacy Policy ↗Google LLC (analytics)
If you consent, Google Analytics collects anonymised data about your visit. Google may process data outside the UK; standard contractual clauses are in place.
Google Privacy Policy ↗Vercel Inc. (website hosting)
Our website is hosted by Vercel. They process server logs on our behalf solely to operate the website infrastructure.
Vercel Privacy Policy ↗6. International data transfers
Some of our third-party service providers (including Google and Vercel) may process your data outside the United Kingdom. Where this occurs, we ensure that appropriate safeguards are in place — such as the UK International Data Transfer Agreement (IDTA) or standard contractual clauses — in accordance with UK GDPR Chapter V.
7. How long we keep your data
We retain your personal data only for as long as is necessary for the purposes described in this policy:
| Data type | Retention period |
|---|---|
| Booking and appointment records | 3 years from last appointment |
| Financial and transaction records | 6 years (HMRC requirement) |
| General enquiry communications | 2 years from last contact |
| Website analytics data | Up to 14 months (Google Analytics default) |
| Cookie preference records | 1 year (stored in your browser) |
8. Your rights under UK GDPR
Under UK GDPR, you have the following rights in relation to your personal data:
Right of access
You can request a copy of the personal data we hold about you (a Subject Access Request).
Right to rectification
You can ask us to correct inaccurate or incomplete data.
Right to erasure
You can ask us to delete your personal data, subject to any legal obligations to retain it.
Right to restrict processing
You can ask us to pause processing of your data in certain circumstances.
Right to data portability
You can request your data in a structured, machine-readable format.
Right to object
You can object to processing based on legitimate interests at any time.
Right to withdraw consent
Where processing is based on consent (e.g. analytics cookies), you can withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us at hello@fernandflow.co.uk. We will respond within one calendar month.
9. Cookies
We use cookies and similar technologies on our website. For full details of the cookies we use, the data they collect, and how to manage your preferences, please read our Cookie Policy.
10. Security of your data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. Our website is served over HTTPS. Access to personal data held in our booking system is restricted to authorised salon staff only.
While we take these measures seriously, please be aware that no method of electronic transmission or storage is completely secure. If you have any concerns about the security of your data, please contact us immediately.
11. Third-party links
Our website contains links to third-party websites, including our booking platform (Slick) and our Instagram profile. These websites have their own privacy policies and we are not responsible for their practices. We encourage you to read their policies before providing any personal data.
12. Children's privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this page periodically.
14. How to complain
If you are unhappy with how we have handled your personal data, please contact us first and we will do our best to resolve the issue:
MAD & CO X LIMITED (trading as Fern & Flow Hair)
278 High Street, Beckenham, BR3 1DY
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent data protection authority.
ICO contact details
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk · Helpline: 0303 123 1113
