Important: Online ordering is temporarily unavailable. Please order by phone at +44 207 871 3056

Privacy Policy

PRIVACY POLICY

This privacy policy sets out the data processing practices of GYM FOOD. Please note that all customer data will be used and held in accordance with the requirements of the Data Protection Act 2018.

At GYM FOOD we are fully committed to protecting the privacy of all our customers. This includes protecting the personal information and data of all visitors who access our website, order online or over the phone, or use our services in any way.

This privacy policy explains how GYM FOOD collects, shares and uses your personal information when you visit our website, gymfood.co.uk, via desktop, tablet or mobile. You’ll also find information about how you can exercise your privacy rights.

By using our services, you agree to GYM FOOD using your personal information as described in this privacy policy.

WHO WE ARE

GYM FOOD Ltd (GYM FOOD) runs a food delivery business and currently operates from premises on Gales Gardens, London E2 0EJ, but GYM FOOD is expanding and this policy also relates to any new stores GYM FOOD may open.

GYM FOOD is the data controller of this site and the services it offers. If you have any questions about how we treat your personal data, please contact George Streatfield, the data protection officer (DPO), by emailing privacy@gymfood.co.uk

THE INFORMATION WE COLLECT AND WHY WE COLLECT IT

We collect personal information from you and may share it within our organisation. Some of this information is processed on the basis of contract, for instance your name and address for delivery, and some of the information we collect is on the basis of legitimate interest, because it enables us to provide our service to you. If you fail to provide this information, then you may not be able to place an order.

When you register to place an order, we collect personal information such as your name, address, telephone number and email address. You provide this information so that we can:

  • process and deliver your order
  • send status updates on your order
  • contact you directly via phone or SMS to facilitate delivering your order correctly or to resolve an issue
  • send you a receipt and transaction information directly related to your order
  • use activity information to improve your experience and give you access to your order history preferences
  • reply to you in order to resolve problems (including when you contact us through third-party websites and survey plug-ins)
  • enable you to collect loyalty points as part of any loyalty programme we may institute
  • ensure you receive marketing and offers that are of interest and relevance to you (to understand your purchasing options we may share your data with third-party analytics companies)
  • develop our products and services (for instance by asking for feedback on our service)
  • notify you of changes or updates to our services, terms of service or privacy policy

We engage third-party processors to process the payment of your order online when you pay by card. If you consent to them doing so, the third-party processors may store your payment card details to speed up your transaction time.

The password you create on our website is stored by us, but fully encrypted and not accessible to us.

We collect digital information such as your computer IP address, browser type and version, and anonymous information is collected by cookies when you browse our site. We collect this information to help us understand how to improve our service and site, and to ensure that the content on our site is presented to you in an effective manner.

DIRECT MARKETING

Once you have registered or placed an order on our site, GYM FOOD will send you occasional direct marketing via email and SMS about similar products, services, deals and information about our service and brand, as well as any franchisees, sub-brands or subsidiaries.

We have a legitimate interest in sending you direct marketing materials in order to promote our products and services and to make sure you are aware of the best offers and deals available.

We will also send you information when our menu/service changes or with details of new store openings, so you have a full knowledge of the availability of our services.

In terms of personal data we use for marketing, we will keep this data for as long as we are able to market to you. If you withdraw your consent or opt-out of marketing communications, we will keep your contact details only to ensure that we do not contact you again for marketing purposes.

You can unsubscribe from direct marketing at any time via your account settings. You can also contact us directly at privacy@gymfood.co.uk to opt out of direct marketing. We will stop sending you marketing messages as soon as possible, but no later than 30 days from your request.

Your preferences to unsubscribe and re-subscribe can be changed at any point and will have no effect on the service that we offer you.

WHO WE SHARE YOUR DATA WITH

In order to deliver your order, GYM FOOD shares your personal information with our staff in store, including drivers. This is necessary so they can deliver an order to your address and call you if necessary to complete the order or resolve any issues.

On occasion we use third-party contractors and freelance drivers to complete deliveries. In order to complete our service, your personal information needs to be shared with them.

We may share your data with any franchisees, sub-brands or subsidiaries to make sure you get the best service, and in the case of shared loyalty schemes, any organisations within our group.

We may share your data with data matching, data analysis or direct marketing companies to perform services on our behalf. However, they will only be permitted to use your personal information for the purpose of performing that particular function and not for any other purposes.

We may also share your personal information with a purchaser or potential purchaser of the business to assist with the sale or potential sale of our business.

In some circumstance, we may have to disclose your personal information by law, because a court, the police or other legal or regulatory enforcement agency has asked us for it.

We require all third parties that we work with to treat your personal information as confidential and to fully comply with all applicable UK and Ireland data protection and consumer legislation.

Your data is automatically shared with our third-party web developer, Livepepper and our EPOS customers, so that we can process your order.

We will never sell, distribute or otherwise share your personal information unless we have your permission.

SECURITY

GYM FOOD places great importance on protecting your information from and against unauthorised access, and against unlawful processing, accidental loss, destruction and damage. We trust Livepepper and our EPOS companies to implement appropriate technical and organisational measures to safeguard your information. Your information is stored on their secure servers.

Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of any data transmitted to our site and any transmission is at your own risk.

DATA RETENTION

GYM FOOD will retain your personal information in connection with the services we have provided to you for XXXXX years after your last purchase from us. We need to retain this data to fulfil the purposes described in this privacy policy, for our own accounting purposes and for legal and tax purposes.

For legitimate operational reasons, such as record-keeping, and to comply with our legal obligations, we may also retain certain elements of your personal information for a period after you delete or deactivate your account. However, whenever we retain your information we will do so in compliance with the applicable laws.

If you close your account, you will lose all the loyalty points attached to your account.

YOUR DATA PROTECTION RIGHTS

You can access your account at any time to review and update your personal information. You can also contact us to ask us to delete your personal information, restrict its processing or request that it be ported to a third party. You also have the right to unsubscribe from the marketing communications we send you by using the unsubscribe function or by amending your profile.

DATA SUBJECT’S RIGHTS

You have rights in respect of your personal data. GYM FOOD will need to confirm your identity before we can consider your request so, if you wish to exercise any of these rights, the DPO will need to see your photo ID, for example your passport or driving licence.

 

The right to be informed: you have the right to be told about the collection and use of the personal data you provide. This privacy policy sets out the purpose for which we process your personal data, how long we will keep your data, who we will share your data with. If you have any questions on how and why we process your data please contact the DPO. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed/

 

Right of access: you have the right to know whether we are processing your personal data, and to a copy of that data. We would need as much information as possible to enable us to locate your data. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/

 

Right to rectification: you have the right to have any incorrect personal data corrected or completed if it is incomplete. You can make this request verbally or in writing. We will need as much information as possible to enable us to locate your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-rectification/

 

Right to erasure: this right, often referred to as the right to be forgotten allows you to ask us to erase personal data where there is no valid reason for us to keep it. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/

 

Right to restrict processing: you have the right to ask us to restrict processing of your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DP at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-restrict-processing/

 

Right to data portability: you have the right to move, copy or transfer your personal data from one IT environment to another. This right applies to data that you have provided to us and that we are processing on the legal basis of consent or in the performance of a contract and that processing is by automated means. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/

 

Right to object: you have the right to object to our processing of your personal data based on (i) legitimate interests, or for the performance of a task in the public interests/exercise of official authority (including profiling); (ii) direct marketing (including profiling); and (iii) for purposes of scientific/historical research and statistics. 

  1. Legitimate interests/legal task – your objection should be based on your particular situation. We can continue to process the data if we can demonstrate compelling legitimate grounds which override your interests.
  2. Direct marketing – you have an absolute right to ask us to stop processing for the purposes of direct marketing. We will action your request as soon as possible.
  3. Scientific/historical research and statistics - your objection should be based on your particular situation. If we are conducting research where the processing is necessary for the performance of a public task, we can refuse to comply with your objection.

If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/

 

Rights relating to automated decision-making, including profiling: you have the right in respect of automated decision-making, including profiling. Where we carry out solely automated decision making, including profiling, which has legal or similarly significant effects on you, we can only do this if it is in connection with a contract with you, we have a right under law or you have provided your explicit consent. We will tell you if this happens and tell you how you can request human intervention or challenge the decision. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/

 

LINKS TO THIRD PARTY SITES

We may link to other websites which are not within our control. Once you have left our site, we cannot be responsible for the protection and privacy of any information which you provide. You should exercise caution and review the privacy policy of the website in question.

CHANGES TO OUR PRIVACY POLICY

From time to time we may update this privacy policy in response to changing legal, technical or business developments.

When we update our privacy policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material privacy policy changes if and where this is required by applicable data protection laws.

We encourage you to review this page from time to time for the latest information on our privacy practices.

We also encourage you to read this privacy policy in conjunction with the GYM FOOD terms & conditions.

HOW TO CONTACT US

If you have any questions about our privacy policy, please contact us via email at privacy@gymfood.co.uk