Effective Date: 15 September, 2025
Barari Blooms (“we”, “our”, “us”) is committed to protecting your privacy and ensuring that your personal data is handled in a safe and responsible manner. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data in compliance with the UAE Personal Data Protection Law (PDPL).
1. Definitions
- Personal Data / Personal Information: Any information relating to an identified or identifiable natural person.
- Sensitive Personal Data: Includes data revealing race, religion, health status, biometric data, or other special categories as identified by law.
- Data Subject: The natural person whose Personal Data is processed.
- Controller: The entity (Barari Blooms) that determines the purposes and means of processing personal data.
- Processor: An entity that processes personal data on behalf of the Controller.
2. What Data We Collect
We may collect the following categories of Personal Data:
| Category | Examples |
| Identity Data | Name, date of birth, gender |
| Contact Data | Email address, phone number, delivery address |
| Account Data | Login credentials, purchase history |
| Payment Data | Payment method information (card/bank), billing address |
| Usage Data | How you use our website, your preferences, device/browser info |
| Marketing & Communication Data | Opt-in preferences, feedback, survey responses |
We do not typically collect Sensitive Personal Data, unless explicitly provided (for example health-related care of a plant allergen, etc.), and only with express consent, as required by law.
3. Legal Basis for Processing
We process your personal data only where we have a lawful basis under the PDPL, such as:
- Your consent (you agree to us collecting and using your data in a particular way).
- Performance of a contract (e.g. fulfilling your order, delivery, customer service).
- Compliance with a legal obligation.
- Protecting your vital interests or those of others.
- Processing necessary for public interest or other lawful grounds permitted under PDPL.
4. How We Use Your Data
We use your personal data for the following purposes:
- Processing and delivering your orders.
- Communicating with you about your orders, shipping status, and customer service.
- Managing your account.
- Improving our services, website, products, and customer experience.
- Sending you marketing or promotional information if you have opted-in.
- Complying with legal obligations.
5. Sharing & Disclosure
We may share your data with:
- Service providers / processors who help us with shipping, payment processing, customer support, IT services.
- Third parties if required by law, with your explicit consent, or for legitimate business purposes (e.g. fraud prevention).
- Authorities / regulators if required under applicable law.
We will put in place contracts with our processors/partners to ensure that they protect your personal data and comply with PDPL requirements.
6. International / Cross-Border Transfers
If we transfer your personal data outside the UAE, we will ensure:
- The destination country provides adequate protection as per UAE Data Office / PDPL standards.
- Alternatively, we use contractual safeguards or obtain your explicit consent, where permitted.
7. Security Measures & Data Retention
- We implement technical and organizational measures to protect your data against unauthorized or unlawful processing, loss, damage, theft or access.
- We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law. After that, we securely delete or anonymize the data.
8. Your Rights
Under the PDPL, you have certain rights over your personal data:
- Right to access the personal data we hold about you.
- Right to correction of inaccurate or incomplete data.
- Right to erasure / deletion under certain circumstances.
- Right to restrict processing or object, including for marketing purposes.
- Right to data portability (where applicable).
- Right to withdraw consent at any time, where processing is based on consent.
If you want to exercise any of these rights, please contact us using the details below. We will respond in accordance with PDPL requirements.
9. Data Breach Notification
In case of a data breach that may impact privacy, confidentiality or security of personal data, we will:
- Notify the UAE Data Office as required by law. UAE Government Portal+2PwC+2
- Where applicable, notify affected Data Subjects if there is a risk to their rights or freedoms. PwC+1
10. Cookies and Tracking Technologies
- We use cookies and similar technologies to improve website functionality, track user behavior, and support marketing efforts.
- You can manage or disable cookies via browser settings. This may affect some features of the site.
11. Minors
- We do not knowingly collect personal data from minors (under the age of [insert age, e.g. 18]) without parental/guardian consent.
- If we become aware that a minor has provided us with personal data without such consent, we will take steps to delete such data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes via our website or other communication channels, and the “Effective Date” will be updated accordingly.
13. Contact Us
If you have any questions, concerns, or complaints about this policy or our data practices, or want to exercise your data subject rights, please contact:
- Name / Position: [e.g. Data Protection Officer or Privacy Contact]
- Email: [insert email]
- Phone: [insert phone number]
- Address: [insert business address]
Legal References
Related guidelines issued by the UAE Data Office DLA Piper Data Protection+2https://secureprivacy.ai/+2
Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (PDPL) ‒ UAE UAE Government Portal+2OneTrust+2