privacy policy
What is this policy?
This is our data protection and privacy policy. It explains who we are, and why and how we process personal data. If you are the subject of any of the personal data that we process, this policy explains what rights you have, and how to get in touch with us if you wish to. For the gut stuff app users, please see our app privacy policy here.
Who are we?
We are The Gut Stuff Limited (“The Gut Stuff”). Our contact and other details are set out at the end of this policy. We are the controller in relation to the personal data processed in accordance with this policy, except where this policy explains otherwise.
What do we do?
We are a UK company that provides a platform for all things gut health, including education, partnerships and products.
How do we process personal data?
How we process personal data depends on the purpose for which we obtain it and the individual to whom it relates. We will normally only process personal data relating to you if:
- If you are a purchaser or potential purchaser of our services or products.
- If we wish to send you advertising, marketing or promotional material in relation to our services or products.
- If you browse any of our websites.
- If you interact with us via social media.
- If you provide goods or services (or if we are assessing your suitability to provide such goods or services) or you work for, or are agent for or otherwise represent, someone who supplies or is being considered as a supplier of goods or services in relation to our business.
We explain our personal data processing in more detail, below, in relation to each of these categories.
If you are a customer or potential customer for our goods or services:
Purpose
If:
- You are an individual who purchases, or who is a potential purchaser of, our goods or services; or
- You are an individual who works for a business which purchases, or which is a potential purchaser of, our goods or services;
We may process information relating to you to enable us, or other suppliers of ours (for example, if we use a third party to manage our fulfilment of orders), to manage and administer the supply of our goods or services to you or the person that you work for and to communicate with you in relation to that provision. This may include (where relevant) processing any information necessary to enable us to provide or arrange any facilities, resources, insurance or anything else necessary to supply the goods or services.
Information
- Name
- Contact details (name, address, email address, phone number).
- Communications sent or received.
- Goods or services purchased and/or delivered.
- Bank account or other financial details.
- Details relevant to facilities being organised or provided in order to assist in supply the goods or services.
- Other details provided by you or the person that you work for that are relevant to the supply of goods or services to you or the person that you work for.
Legal basis
Where you are individual customer, the processing is necessary for the performance of a contract to which you are a party or to take steps at your request to enter into such a contract – article 6(1)(b) GDPR.
Where you are an individual who works for a business customer, the processing is necessary for the purpose of legitimate interests pursued by us in relation to our business; that is, the sale and supply of our goods and services – article 6(1)(f) GDPR.
How long we keep it for
We keep the personal information relating to you for as long as is necessary in relation to your purchase or potential purchase, and then for a period of at least 6 years after which we will delete it unless it is necessary to retain it for archival purposes.
If we wish to send you advertising, marketing or promotional material in relation to our goods or services:
Purpose
To send marketing material to you, or advertise our goods or services to you
Information
- Name
- Contact details (email address, phone number, address)
- Communications sent or received
- Whether you have consented to receive marketing communications
- Whether you have opted out of receiving marketing communications
- Use of our website
- Your consent to receive relevant communications – article 6(1)(a) GDPR
Legal basis
The processing is necessary for the purpose of legitimate interests pursued by us in relation to our products – article 6(1)(f) GDPR
How long we keep it for
We will keep the personal information for a reasonable period consistent with sending you marketing communications, after which we will either confirm that you are happy for us to continue to do so, or delete it (except to the extent we need to retain it for the sole purpose of supressing further marketing communications to you).
If you browse our website:
Purpose
We may collect information on your visits to our website and how you move around different sections of our website for analytics purposes to understand how people use our website so that we can make it more intuitive. We may keep a record of the content on our website that you have clicked on and use that information to target advertising on this website to you that is relevant to your interests and which we have identified based on content you have looked at. [This information is set out in our Cookies Policy.
Information
- Your name and/or other identifier.
- Your visits to our website.
- Content viewed by you.
- Links followed by you.
- Information downloaded by you
Legal basis
You give consent to the processing – Article 6(1)(a) GDPR.
The processing is necessary for the purpose of legitimate interests pursued by us in relation to the development – article 6(1)(f) GDPR.
How long we keep it
We will keep the information for a reasonable period and then delete it.
If you interact with us via social media:
Purpose
If we are carrying out social media monitoring and you interact with, or mention or tag us on social media, we may process details regarding that interaction and your social media ID for the purposes of keeping ourselves informed in relation to the interaction concerned and, if appropriate, communicating with you.
Information
- Your name (if available on the relevant social media platform).
- Your social media ID.
- Other information relevant to our products that you communicate via social media or other public forum
Legal basis
The purpose of legitimate interests pursued by us in relation to the development – article 6(1)(f) GDPR
How long we keep it for
We keep the personal information relating to you for as long as is necessary in order to enable us to communicate with you, after which we will delete it. Normally, we will not keep this information for more than 6 months following its collection.
If you provide goods or services (or if we are assessing your suitability to provide such goods or services) or you work for, or are agent for or otherwise represent, someone who supplies or is being considered as a supplier of goods or services in relation to our business:
Purpose
If:
- You provide goods or services in relation to our products.
- You work for, or are agent for or otherwise represent, someone who provides or is being considered as a provider of such goods or services.
- We are assessing your suitability (or that of the person you work for) to provide such goods or services.
We may process information relating to you to enable us, or other suppliers of ours, to manage and administer the provision of goods or services by you or the person that you work for and to communicate with you in relation to that provision. This may include (where relevant) processing any information necessary to enable us to provide or arrange any facilities, resources, insurance or anything else necessary to enable or assist you to provide goods or services in relation to our products.
Information
- Name
- Contact details (name, address, email address, phone number).
- Communications sent or received.
- Goods or services purchased and/or delivered.
- Professional or other accreditation details.
- Bank account or other financial details.
- Details relevant to facilities being organised or provided in order to assist you in providing the goods or services.
- Other details provided by you or the person that you work for that are relevant to the provision of goods or services by you or the person that you work for
Legal basis
The processing is necessary for the performance of a contract to which you are a party or to take steps at your request to enter into such a contract – article 6(1)(b) GDPR.
The processing is necessary for the purpose of legitimate interests pursued by us in relation to our products – article 6(1)(f) GDPR.
Details relating to your health will only be processed with your prior explicit consent, or to the extent necessary for carrying out our legal obligations or protecting your vital interests, or in relation to legal claims – Article 9(2) GDPR.
How long we keep it for
We will keep the information for as long as necessary to facilitate the provision of the relevant goods or services and then for a period of up to 6 years afterwards, after which we will normally delete it. If we consider you or the person that you work for, but decide not to select you or the person that you work for, to provide such goods or services, then we will normally keep any relevant information provided by you for a period of 6 months, after which we will delete it (unless it has been agreed that we will retain it in case, for example, we may wish to contact you in the future regarding other opportunities to provide goods or services).
Disclosures of your information we may make
Where appropriate, we may disclose your personal data to third parties:
- Appropriate third parties including:
- Our business partners, suppliers and sub-contractors for the performance of any contract we enter into or other dealings we have in the normal course of business with you or the person that you work for.
- Our auditors, legal advisors and other professional advisors or service providers.
- Credit or other similar reference agencies for the purpose of assessing your suitability or ability where this is in the context of us entering (or proposing to enter) into a contract with you or the person that you work for.
- In relation to information obtained via our website:
- Our advertisers and advertising networks that require the data to select and serve relevant adverts to you and others. We do not disclose information about identifiable individuals to our advertisers, but we will provide them with aggregate information about our users. We may also use such aggregate information to help advertisers reach the kind of audience they want to target. We may make use of the personal data we have collected from you to enable us to comply with our advertisers’ wishes by displaying their advertisement to that target audience and subject to the cookie section of this policy.
- Analytics and search engine providers that assist us in the improvement and optimisation of our site and subject to the cookie section of this policy.
In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets subject to the terms of this privacy policy.
If we or substantially all of our assets are acquired by a third party, in which case personal data held by us about our customers and suppliers will be one of the transferred assets.
If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of supply terms and other agreements with you; or to protect the rights, property, or our safety or that of our customers or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Where do we process personal data?
The data that we process in relation to you will be processed within the European Economic Area (“EEA”).
All personal data processed by us is stored securely. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website and any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Your rights
Under data protection law, you have certain rights. Your rights depend on our reason for processing your personal information.
- You may request access to the personal data concerned (please see the section on obtaining access to your personal data, below).
- You may request that incorrect personal data that we are processing be rectified.
- In certain circumstances (normally where the personal data has been provided by you and it is no longer necessary for us to continue to process it), you may be entitled to request that we erase the personal data concerned.
- Where we are processing personal data relating to you on the basis of your prior consent to that processing, you may withdraw your consent at any time, after which we shall stop the processing concerned.
If you have a complaint about any processing of your personal data being conducted by us, you can contact us or lodge a formal complaint with the Information Commissioner.
How to withdraw your consent to processing
You can withdraw your consent to any relevant processing of personal data:
- By emailing us at [email protected]; or
- By writing to us at the address below.
How to exercise your right of access to your personal data
You can exercise your right of access to your personal data:
- By emailing us at [email protected];
- By writing to us at the address below.
Please note that we may be required to ask you for further information in order to confirm your identity before we provide the information requested.
Our details – contacting us
Our full details are:
The Gut Stuff Limited
30 Oval Road
London
NW1 7DE
Contact: Data Protection Officer, The Gut Stuff, [email protected]
Updates to this policy
Any changes we make to our privacy policy in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy policy.
Date of this policy
This policy was last updated on 1 July 2020