Privacy Policy for The Village Pharmacy
1. Introduction
Welcome to The Village Pharmacy’s Privacy Policy. At The Village Pharmacy, we respect and are committed to safeguarding your privacy and personal data. This Privacy Policy outlines how we collect, process, use, store, and protect the personal information you provide to us, whether online or in-person at our location in Newton Aycliffe.
We adhere to the principles of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our website or services, you agree to the terms of this policy.
2. Data We Collect
We collect several types of personal data to ensure that we deliver effective and professional services, such as prescription dispensing and health consultations. The data we collect includes:
- Personal Identification Information: This includes your full name, date of birth, home address, phone number, and email address when you use our prescription services or engage with us online.
- Health Information: Relevant medical data, including your prescription history, current medications, allergies, and vaccination records. This information is essential for us to deliver safe and accurate medical services.
- Financial Data: Payment details when you purchase products or services. We ensure that all financial data is securely processed through our payment service providers.
- Communications Data: Any data provided when contacting us through our website’s contact forms, email, or phone, including queries about our services, complaints, or customer service inquiries.
- Technical Data: Data about your browsing device, browser type, IP address, and interactions with our website. This helps us improve our site’s performance and user experience.
- Cookies Data: Information on your website use through cookies, including session cookies for website functionality and tracking cookies for analytics and marketing.
We only collect information necessary for the services we provide and ensure that the data is processed in line with legal obligations and ethical standards.
3. How We Use Your Data
The data we collect is used for several purposes, including but not limited to:
- Prescription and Healthcare Services: To process and manage your prescriptions and provide health services such as medical consultations and vaccinations.
- NHS Services Compliance: As an NHS-contracted pharmacy, we are legally required to retain and process certain patient data for regulatory purposes, ensuring all healthcare services are properly documented and safely delivered.
- Payment Processing: We use financial data to process transactions for purchases made through our pharmacy. This includes any online orders or in-store purchases. All payment information is securely handled by third-party processors, and no payment information is stored directly on our systems.
- Customer Communication: To respond to any questions, inquiries, or complaints. We may also contact you with relevant health-related information, appointment reminders, or customer service communications.
- Marketing Communications: If you have opted in, we use your contact information to send updates about new products, services, or promotions.
- Website Functionality and Improvements: We use technical and cookies data to enhance your user experience on our website, improve its performance, and gather analytics for improving our services.
- Legal and Regulatory Compliance: We retain and process data in line with UK healthcare regulations, including data protection laws and obligations to the NHS.
4. Legal Basis for Data Processing
We process personal data under the following legal bases:
- Consent: For marketing communications or when you voluntarily provide your information through forms or inquiries.
- Contractual Necessity: To fulfill our obligations in delivering healthcare services and products to you, including prescription fulfillment and health consultations.
- Legal Obligations: We are required by law to collect, store, and process certain types of data in line with UK healthcare regulations, such as maintaining accurate patient prescription records.
- Legitimate Interests: To improve our services, manage internal administrative processes, and enhance the safety and performance of our website.
In cases where we rely on consent, you have the right to withdraw consent at any time.
5. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to provide a tailored experience. The types of cookies we use include:
- Essential Cookies: These are necessary for the basic operation of the website, such as enabling you to log in or use shopping cart functions.
- Analytics Cookies: Used to track how visitors use our website, which helps us improve functionality and understand user behaviour. These may include Google Analytics.
- Marketing Cookies: When consented, these cookies track your browsing activity for advertising purposes and allow us to provide more relevant promotions based on your interactions.
You can adjust your cookie preferences through our cookie management tool or modify your browser settings. Declining certain cookies may affect website functionality.
6. Data Sharing and Third-Party Disclosures
We may share your personal data with third parties under certain circumstances:
- NHS and Healthcare Providers: For the proper fulfillment of prescriptions and healthcare services, your data is shared with the NHS and other healthcare professionals as required.
- Payment Processors: Third-party services handle the secure processing of financial transactions made through our website or in-store. These providers adhere to strict security protocols.
- Regulatory Bodies: If required by law, we may share your information with government authorities or regulatory bodies to comply with legal or public health requirements.
- Marketing Services: If you’ve opted into marketing communications, we may share your data with marketing service providers who assist us with sending newsletters or promotional materials.
We never sell your personal data to third parties. All data sharing is done in compliance with legal requirements and with necessary safeguards in place.
7. Data Security
We employ a range of security measures to protect your personal data from loss, misuse, and unauthorized access:
- Encryption: All sensitive data, including payment and medical records, are encrypted both in transit and at rest.
- Access Controls: Access to personal data is restricted to authorised personnel who require it for operational purposes, with robust authentication protocols in place.
- Data Breach Prevention: We have measures in place to detect and prevent data breaches. In the event of a breach, we will notify affected individuals and relevant authorities in accordance with legal requirements.
8. Data Retention Policies
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy, including:
- Prescription Records: Retained in line with NHS guidelines and healthcare regulations, ensuring we maintain proper healthcare records for patient safety and legal compliance.
- Marketing Data: Retained until you unsubscribe or withdraw consent for marketing communications.
- Payment Data: Retained for financial record-keeping purposes, typically for a period of six years in line with UK tax regulations.
When the retention period expires, personal data will be securely deleted or anonymised.
9. Your Rights
Under the UK GDPR, you have several rights regarding your personal data:
- Right to Access: You can request access to the personal data we hold about you and ask how we are processing it.
- Right to Rectification: You can request corrections to inaccurate or incomplete personal data.
- Right to Erasure: You can request the deletion of your data under certain conditions, such as when the data is no longer necessary for the purposes it was collected.
- Right to Restrict Processing: You can request to limit the processing of your data in specific circumstances.
- Right to Data Portability: You have the right to request that we transfer your data to another provider in a structured, commonly used format.
- Right to Object: You can object to your data being used for direct marketing purposes.
To exercise any of these rights, please contact us via the details below.
10. International Data Transfers
If your data is transferred outside the UK, we ensure that adequate safeguards are in place, such as binding corporate rules or standard contractual clauses, to ensure your data is protected to the same standards as required under UK law.
11. Updates to This Privacy Policy
We may occasionally update this privacy policy to reflect changes in legal requirements or our business operations. When we make significant changes, we will notify you via email or a prominent notice on our website. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions or concerns regarding this privacy policy or wish to exercise your rights, please contact us at:
The Village Pharmacy
Owner: Alisdair McConnell
Address: 3 Neville Parade, Newton Aycliffe, DL5 5DH, United Kingdom
Email: info@thevillage-pharmacy.co.uk
Phone: 01325 319932