Privacy Notice

At The Lily & Leaf Co Ltd t/a The Leaf Co, we respect your personal data. This Privacy Notice explains how we will use your personal data when you use our website or become a customer. Your information will be filed securely on our computers and servers and any paper copies will be stored securely.

Our Offices

UK
34 Bogmoor Place
Glasgow
Scotland
G51 4TQ
United Kingdom

What personal data do we collect about you?

When you use our website, we will collect the following personal data about you:

  • Name, contact details and the nature of your enquiry via our ‘Contact Us’ or ‘Enquire’ form
  • Name and contact details if you sign up for our email marketing list
  • IP Address/MAC address when you use the website


If you become a The Leaf Co customer we will collect your name, contact and payment details from you

How will we use that personal data? What is our legal basis for processing your personal data?

We need a legal basis in order to process your personal data

  • When you become a The Leaf Co customer we hold your personal data on the basis of the contract we have with you to supply you with the service you’ve selected and to manage your account. If you agree, we will send you marketing information and newsletters which we may think will be of interest to you. You have the right to unsubscribe to marketing at any time
  • We need your name and contact details in order to answer your enquiry and we process this data with your consent
  • We need your IP address and MAC address so that we can monitor the use of our website, this is a legitimate interest for a business
  • We will send you marketing information and newsletters when you consent for us to do so. You have the right to unsubscribe to marketing at any time. If you do choose to unsubscribe, we will keep your name and email address on a suppression list so that we don’t email you again by accident

Do we have a statutory or contractual requirement to process your personal data?

There is a contractual requirement for us to process your personal data if you become a customer and we need to fulfil our contractual responsibilities

Do we use any automated decision making?

We do not use any automated decision making. We do use cookies to monitor the use of our website.

Who do we share your personal data with?

  • Companies that provide services to us. Our telephone service providers will get to see your phone number if we call you, and our broadband supplier could see your email address (but not the content of what you send us, if you encrypt it)
  • Cloud service & IT providers. We use a number of cloud services & IT providers, such as our CRM systems and webhosting. We also share with IT professionals who not only ensure that our systems run smoothly, but are also committed to the highest standards of data protection compliance.
  • We use PayPal and Shopify to process payments when buying a product from The Leaf Co
  • We use an Accountant to help us with our finances
  • We use a marketing consultancy and an email service so that we can update you with our regular content, news and events
  • We use a webhosting company to assist us with building and hosting our website
  • In response to a court order, it is possible, though unlikely, that we might be forced to disclose your information

Do we transfer your personal data outside of the EU or EEA?

We use Microsoft, Mailchimp and Shopify which are based in the USA. However adequate safeguards are in place as these organisations are certified to the EU-US Privacy Shield Framework or have standard contractual clauses in place.

How long do we keep your personal data for?

  • If you purchase goods or services from us, we will keep your data for the duration of what is legally required by law
  • If you make an enquiry, we will keep your data for a maximum of 12 months once we’ve answered your enquiry unless you’ve chosen to become a customer or joined our email list
  • If you are on our email marketing list, you are welcome to unsubscribe at any time, but we will keep your personal data in a suppression list so that we don’t email you again by accident

Changes to our privacy notice

Any changes we make to our privacy notice in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy notice

Your rights as a data subject

The GDPR gives you rights as a data subject. You have:

1. the right to request from us access to your personal data;

2. the right to request from us rectification of your personal data;

3. the right to request from us erasure of your personal data;

4. the right to request from us restriction of processing your personal data;

5. the right to object to our processing of your personal data;

6. the right of data portability;

7. if we are processing your personal data on the basis of your consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of processing based on your consent before you withdrew it; and

8. You have the right to complain to the ICO

More information on your rights can be found in Chapter 3 of the GDPR

Exercising your rights

You can exercise such rights by contacting us.