PharmaEthical

Healthcare Solution

GDPR PRIVACY STATEMENT

Effective Date: June 2025 Last Updated: June 2025 Website: www.pharmaethical.com

1. Introduction

PharmaEthical Ltd ("PharmaEthical", "we", "our", or "us") is a healthcare technology company based in the United Kingdom, operating Amal Pharmacy and providing innovative health tech solutions to Community Pharmacies, Nursing Homes, Residential Homes, and Care Homes.

We are committed to protecting the privacy and rights of individuals whose personal data we process. This Privacy Statement explains how we collect, use, store, share, and protect your personal data in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)
  • The Data Protection Act 2018 (DPA 2018)
  • The EU General Data Protection Regulation 2016/679 (EU GDPR), where applicable
  • Any other applicable data protection legislation

This statement applies to all individuals whose data we process, including patients, healthcare professionals, business partners, website visitors, and employees.

2. Data Controller

PharmaEthical Ltd is the Data Controller for personal data processed in connection with its services and website (www.pharmaethical.com).

If you have any questions regarding your personal data or this Privacy Statement, please contact our Data Protection Officer (DPO):

Data Protection Officer
PharmaEthical Ltd
Website: www.pharmaethical.com
Email: privacy@pharmaethical.com

3. Personal Data We Collect

Depending on your relationship with PharmaEthical, we may collect and process the following categories of personal data:

3.1 Patient and Healthcare Data

  • Full name, date of birth, gender, and contact details
  • NHS number and other patient identifiers
  • Medical history, diagnoses, prescriptions, and medication records
  • Allergy information and clinical notes
  • Healthcare professional referrals and correspondence

3.2 Website and Contact Form Data

  • Name, email address, and subject of enquiry submitted via our contact form
  • IP address, browser type, device information, and browsing behaviour on our website
  • Cookie data and analytics information (see Section 10 – Cookies)

3.3 Business Partner and Professional Data

  • Contact details of representatives from pharmacies, care homes, and nursing homes
  • Professional credentials, role, and organisational information
  • Communications and correspondence records

3.4 Employee and Contractor Data

  • Recruitment information, employment records, payroll data
  • Training records, performance data, and emergency contact details

4. Special Category (Sensitive) Personal Data

As a healthcare organisation, PharmaEthical processes special category data as defined under Article 9 of the UK GDPR. This includes:

  • Health and medical data
  • Genetic and biometric data (where applicable)
  • Racial or ethnic origin (where relevant to care)

We process such data only where we have a lawful basis and, where required, explicit consent or another qualifying condition under Schedule 1 of the Data Protection Act 2018 (e.g., health and social care purposes, vital interests).

5. Legal Basis for Processing

We rely on the following lawful bases under Article 6 (and Article 9 where applicable) of the UK GDPR:

Contractual Necessity: Processing required to deliver pharmacy or healthcare technology services to you.

Legal Obligation: Processing required to comply with NHS, regulatory, or statutory obligations.

Legitimate Interests: Processing for purposes such as improving our services, fraud prevention, and business administration, where your interests do not override ours.

Consent: For marketing communications and certain data uses where we request your explicit agreement.

Vital Interests / Public Task: Where processing is necessary to protect life or fulfil a public health function.

6. How We Use Your Personal Data

We use your personal data for the following purposes:

  • Providing, managing, and improving pharmacy services and healthcare technology platforms
  • Processing prescriptions and facilitating medication management
  • Communicating with patients, carers, healthcare professionals, and business partners
  • Responding to enquiries submitted via our website contact form
  • Ensuring clinical governance, patient safety, and quality assurance
  • Complying with NHS requirements, regulatory obligations, and legal duties
  • Operating and improving our website and digital platforms
  • Fraud detection, security, and the protection of our systems
  • Conducting research and developing new healthcare technology solutions
  • Sending relevant updates and communications (where consent has been given)

7. Sharing Your Personal Data

PharmaEthical does not sell your personal data to third parties. We may share your data only in the following circumstances:

7.1 Healthcare Partners

We share relevant clinical data with NHS bodies, GPs, hospitals, and other healthcare providers involved in your care, as necessary for the provision of healthcare services.

7.2 Technology and Service Providers

We use trusted third-party service providers (data processors) to support our operations, including cloud hosting, IT infrastructure, and analytics platforms. All processors are bound by Data Processing Agreements (DPAs) and required to comply with UK GDPR.

7.3 Regulatory and Legal Bodies

We may disclose data to regulators (such as the General Pharmaceutical Council, Care Quality Commission, or Information Commissioner's Office), law enforcement, or courts when required by law.

7.4 Business Transfers

In the event of a merger, acquisition, or business restructuring, personal data may be transferred to the successor entity, subject to appropriate safeguards.

8. International Data Transfers

Where personal data is transferred outside the UK or European Economic Area (EEA), we ensure adequate protection through:

  • UK Adequacy Regulations recognising the destination country
  • Standard Contractual Clauses (SCCs) approved by the UK ICO or European Commission
  • Binding Corporate Rules or other appropriate safeguards

We will not transfer your data to a jurisdiction without ensuring an adequate level of protection.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Our retention periods are guided by:

  • NHS and healthcare regulatory requirements (patient records typically retained for a minimum of 8 years from last treatment, or until age 25 for children)
  • Legal and contractual obligations
  • Operational and business continuity needs

Once data is no longer required, it is securely deleted or anonymised in accordance with our Data Retention Policy.

10. Cookies and Website Tracking

Our website (www.pharmaethical.com) may use cookies and similar tracking technologies to:

  • Ensure the proper functioning of the website
  • Analyse usage and improve user experience
  • Gather statistical information on visitor behaviour

You may control cookie settings through your browser preferences. Where required by law, we will seek your consent before placing non-essential cookies. For full details, please refer to our Cookie Policy.

11. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • Right of Access (Article 15): Request a copy of the personal data we hold about you (Subject Access Request).
  • Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Right to Erasure (Article 17): Request deletion of your data where there is no legitimate reason to continue processing.
  • Right to Restrict Processing (Article 18): Request that we limit how we use your data in certain circumstances.
  • Right to Data Portability (Article 20): Receive your data in a structured, commonly used format and transfer it to another controller.
  • Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes.
  • Rights Related to Automated Decision-Making (Article 22): Not to be subject to solely automated decisions that produce significant effects, without human review.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at: privacy@pharmaethical.com

We will respond to your request within one calendar month. In complex cases, we may extend this by a further two months, and will notify you accordingly.

12. Data Security

PharmaEthical implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. Our security measures include:

  • Encryption of data in transit and at rest
  • Access controls and role-based permissions
  • Regular security assessments and staff training
  • Incident response and data breach notification procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and, where required, inform affected individuals without undue delay.

13. Children's Data

Where we process data relating to individuals under the age of 18, we apply additional safeguards in accordance with the Children's Code (Age Appropriate Design Code) and applicable data protection legislation. Parental or guardian consent is obtained where required, and particular care is taken in healthcare contexts involving minors.

14. Complaints and Supervisory Authority

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK's data protection supervisory authority:

Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, welcome the opportunity to address your concerns directly before you contact the ICO. Please reach out to us at privacy@pharmaethical.com in the first instance.

15. Changes to This Privacy Statement

We review and update this Privacy Statement periodically to reflect changes in our processing activities, legal obligations, or regulatory guidance. When we make significant changes, we will notify you via our website or other appropriate communication channels.

The most current version of this Privacy Statement is always available at www.pharmaethical.com. We encourage you to review it regularly.

PharmaEthical Ltd

Healthcare Technology | Amal Pharmacy | www.pharmaethical.com

Document Reference: PE-GDPR-2025-001