Privacy Policy

How we collect, use, and protect your personal data

Effective date: 17th March 2026

Fornoza (www.fornoza.com) is owned and operated by Fornoza. Fornoza is the data controller and can be contacted at hello@fornoza.net or by post at Lea Farm, Reading, RG10 0SS, UK.

1. About This Policy

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK GDPR and the Data Protection Act 2018. We are committed to handling your data responsibly and transparently.

We have not appointed a Data Protection Officer as we do not fall within the categories of controllers required to do so under Article 37 of UK GDPR.

2. Data We Collect and Why

2.1 - Website visitors (automatic)

When you visit our site we automatically collect:

  • IP address and approximate location
  • Browser type and version
  • Pages viewed and time spent
  • Device and operating system information

This is used solely for analytics, security, and improving the site. Legal basis: legitimate interests.

2.2 - Enquiry and contact forms

When you submit an enquiry we collect:

  • Name and email address
  • Phone number
  • Event details (date, location, guest count, event type, budget range)

This is used to respond to your enquiry and provide a quote. Legal basis: performance of a contract / pre-contractual steps.

2.3 - Click & Collect orders

When you place a click and collect order we collect:

  • Name and email address
  • Order details (items, quantities, prices, discounts applied)
  • Chosen pickup time
  • Payment confirmation details (processed securely by Square – we do not store card details)

This is used to process and fulfil your order, send you an order confirmation email, and maintain transaction records. Legal basis: performance of a contract.

2.4 - Marketing emails

If you sign up to our mailing list we collect your email address to send you updates, specials and news. Legal basis: consent. You can unsubscribe at any time via the link in any email.

Who We Share Personal Data With

Employees

We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Other Disclosures

We will not sell or share your data with other third parties, except in the following cases:

  • If the law requires it;
  • If it is required for any legal proceeding;
  • To prove or protect our legal rights;
  • To buyers or potential buyers of this company in the event that we seek to sell the company;
  • With service providers who assist us in operating our website and providing services (under strict confidentiality agreements).

How Long We Store Personal Data

User data will be stored until the purpose the data was collected for has been achieved. Specifically:

  • Contact form submissions: 3 years from last contact;
  • Event booking data: 7 years for legal and accounting purposes;
  • Website analytics: 26 months (Google Analytics default);
  • Marketing communications: Until consent is withdrawn.

You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data

In order to protect your security, we use the strongest available browser encryption and store all of our data on servers in secure facilities. All data is only accessible to our employees. Our employees are bound by strict confidentiality agreements and a breach of this agreement would result in the employee's termination.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

Your Rights as a User

Under the GDPR, you have the following rights:

  • Right to be informed;
  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restrict processing;
  • Right to data portability; and
  • Right to object.

Children

We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer at hello@fornoza.net.

How to Access, Modify, Delete, or Challenge the Data Collected

If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact us via hello@fornoza.net.

How to Opt-Out of Data Collection, Use or Disclosure

In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:

  • You can opt-out of the use of your personal data for marketing emails. You can opt-out by clicking "unsubscribe" on the bottom of any marketing email or by contacting us directly.

Cookies Policy

A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our Site:

  • Essential cookies: Necessary for the website to function properly and cannot be disabled;
  • Functional cookies: Used to remember your selections on our Site so that your selections are saved for your next visits;
  • Analytical cookies: Allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc.;
  • Marketing cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns (only with your consent).

Embedded Content from Other Websites

Pages and popups on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Modifications

This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints

If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting us via hello@fornoza.net.

Contact Information

If you have any questions, concerns or complaints, you can contact us using the contact form on our website or by emailing hello@fornoza.net.