At GYM FOOD we are fully committed to protecting the privacy of all our customers. This includes protecting the personal information and data of all visitors who access our website, order online or over the phone, or use our services in any way.
GYM FOOD Ltd (GYM FOOD) runs a food delivery business and currently operates from premises on Gales Gardens, London E2 0EJ, but GYM FOOD is expanding and this policy also relates to any new stores GYM FOOD may open.
GYM FOOD is the data controller of this site and the services it offers. If you have any questions about how we treat your personal data, please contact George Streatfield, the data protection officer (DPO), by emailing firstname.lastname@example.org
We collect personal information from you and may share it within our organisation. Some of this information is processed on the basis of contract, for instance your name and address for delivery, and some of the information we collect is on the basis of legitimate interest, because it enables us to provide our service to you. If you fail to provide this information, then you may not be able to place an order.
When you register to place an order, we collect personal information such as your name, address, telephone number and email address. You provide this information so that we can:
We engage third-party processors to process the payment of your order online when you pay by card. If you consent to them doing so, the third-party processors may store your payment card details to speed up your transaction time.
The password you create on our website is stored by us, but fully encrypted and not accessible to us.
We collect digital information such as your computer IP address, browser type and version, and anonymous information is collected by cookies when you browse our site. We collect this information to help us understand how to improve our service and site, and to ensure that the content on our site is presented to you in an effective manner.
Once you have registered or placed an order on our site, GYM FOOD will send you occasional direct marketing via email and SMS about similar products, services, deals and information about our service and brand, as well as any franchisees, sub-brands or subsidiaries.
We have a legitimate interest in sending you direct marketing materials in order to promote our products and services and to make sure you are aware of the best offers and deals available.
We will also send you information when our menu/service changes or with details of new store openings, so you have a full knowledge of the availability of our services.
In terms of personal data we use for marketing, we will keep this data for as long as we are able to market to you. If you withdraw your consent or opt-out of marketing communications, we will keep your contact details only to ensure that we do not contact you again for marketing purposes.
You can unsubscribe from direct marketing at any time via your account settings. You can also contact us directly at email@example.com to opt out of direct marketing. We will stop sending you marketing messages as soon as possible, but no later than 30 days from your request.
Your preferences to unsubscribe and re-subscribe can be changed at any point and will have no effect on the service that we offer you.
In order to deliver your order, GYM FOOD shares your personal information with our staff in store, including drivers. This is necessary so they can deliver an order to your address and call you if necessary to complete the order or resolve any issues.
On occasion we use third-party contractors and freelance drivers to complete deliveries. In order to complete our service, your personal information needs to be shared with them.
We may share your data with any franchisees, sub-brands or subsidiaries to make sure you get the best service, and in the case of shared loyalty schemes, any organisations within our group.
We may share your data with data matching, data analysis or direct marketing companies to perform services on our behalf. However, they will only be permitted to use your personal information for the purpose of performing that particular function and not for any other purposes.
We may also share your personal information with a purchaser or potential purchaser of the business to assist with the sale or potential sale of our business.
In some circumstance, we may have to disclose your personal information by law, because a court, the police or other legal or regulatory enforcement agency has asked us for it.
We require all third parties that we work with to treat your personal information as confidential and to fully comply with all applicable UK and Ireland data protection and consumer legislation.
Your data is automatically shared with our third-party web developer, Livepepper and our EPOS customers, so that we can process your order.
We will never sell, distribute or otherwise share your personal information unless we have your permission.
GYM FOOD places great importance on protecting your information from and against unauthorised access, and against unlawful processing, accidental loss, destruction and damage. We trust Livepepper and our EPOS companies to implement appropriate technical and organisational measures to safeguard your information. Your information is stored on their secure servers.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of any data transmitted to our site and any transmission is at your own risk.
For legitimate operational reasons, such as record-keeping, and to comply with our legal obligations, we may also retain certain elements of your personal information for a period after you delete or deactivate your account. However, whenever we retain your information we will do so in compliance with the applicable laws.
If you close your account, you will lose all the loyalty points attached to your account.
You can access your account at any time to review and update your personal information. You can also contact us to ask us to delete your personal information, restrict its processing or request that it be ported to a third party. You also have the right to unsubscribe from the marketing communications we send you by using the unsubscribe function or by amending your profile.
You have rights in respect of your personal data. GYM FOOD will need to confirm your identity before we can consider your request so, if you wish to exercise any of these rights, the DPO will need to see your photo ID, for example your passport or driving licence.
Right of access: you have the right to know whether we are processing your personal data, and to a copy of that data. We would need as much information as possible to enable us to locate your data. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/
Right to rectification: you have the right to have any incorrect personal data corrected or completed if it is incomplete. You can make this request verbally or in writing. We will need as much information as possible to enable us to locate your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-rectification/
Right to erasure: this right, often referred to as the right to be forgotten allows you to ask us to erase personal data where there is no valid reason for us to keep it. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/
Right to restrict processing: you have the right to ask us to restrict processing of your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DP at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-restrict-processing/
Right to data portability: you have the right to move, copy or transfer your personal data from one IT environment to another. This right applies to data that you have provided to us and that we are processing on the legal basis of consent or in the performance of a contract and that processing is by automated means. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/
Right to object: you have the right to object to our processing of your personal data based on (i) legitimate interests, or for the performance of a task in the public interests/exercise of official authority (including profiling); (ii) direct marketing (including profiling); and (iii) for purposes of scientific/historical research and statistics.
If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/
Rights relating to automated decision-making, including profiling: you have the right in respect of automated decision-making, including profiling. Where we carry out solely automated decision making, including profiling, which has legal or similarly significant effects on you, we can only do this if it is in connection with a contract with you, we have a right under law or you have provided your explicit consent. We will tell you if this happens and tell you how you can request human intervention or challenge the decision. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/
We encourage you to review this page from time to time for the latest information on our privacy practices.