Privacy Policy
Last Updated: May 31, 2025
1. Introduction
Croydon Pharmacy ("we", "our", or "us") is committed to protecting the privacy of our patients, customers, and website visitors. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, receive our pharmacy services, or interact with us in-store.
We handle personal data, including sensitive health information, in compliance with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and the confidentiality obligations set out by the NHS and the General Pharmaceutical Council (GPhC).
2. Data Controller
Croydon Pharmacy is the Data Controller responsible for your personal information.
44 South End, Croydon, Surrey, CR0 1DP
0208 688 5544
3. Information We Collect
Personal Information
We may collect the following types of personal information:
- Full name and contact details (address, phone, email)
- Date of birth
- NHS number
- Health information, including prescriptions, medication history, and clinical notes
- Payment and transaction information
Website and Device Information
- IP address and location (approximate)
- Browser type and version
- Pages visited, duration, and referral source
- Cookies and similar tracking technologies
4. Legal Basis for Processing
We process personal data under the following lawful bases:
- Contractual obligation – to provide pharmacy services and fulfill your requests
- Legal obligation – to comply with UK pharmacy and health regulations
- Consent – where you have explicitly given permission (e.g., for marketing)
- Legitimate interests – such as service improvement and fraud prevention
Special Category Data (Health Information)
We process health data under Article 9(2)(h) of UK GDPR: "Processing is necessary for the purposes of preventive or occupational medicine, the provision of health or social care or treatment or the management of health or social care systems and services."
5. How We Use Your Information
- Dispense medications and manage prescriptions
- Provide pharmacy and healthcare services
- Process payments
- Respond to enquiries and provide customer support
- Improve our website and services
- Send service-related messages (not marketing) unless you've opted in
6. Sharing Your Information
We may share data with:
- NHS bodies and other healthcare providers involved in your care
- Professional regulators and health authorities as required
- IT and website service providers (under strict confidentiality agreements)
- Payment processors (for purchases)
- Legal or regulatory bodies if required by law
We do not sell or rent your personal data to any third parties.
7. Cookies
We use cookies to enhance website functionality and analyze site traffic. For more information, please refer to our Cookie Policy.
8. Data Security
We implement appropriate technical and organizational measures to protect your information from unauthorised access, alteration, or loss. This includes encrypted systems, staff training, and secure storage practices.
9. Data Retention
We retain personal data only as long as necessary for the purposes stated above or as required by NHS record-keeping guidelines and applicable laws.
10. Your Rights
You have the following rights under UK data protection law:
- Access – Request a copy of the personal data we hold
- Rectification – Correct inaccurate or incomplete data
- Erasure – Request deletion of your data (subject to NHS/legal retention obligations)
- Restriction or Objection – Limit how your data is used in certain circumstances
- Data Portability – Request your data in a commonly used format
- Withdraw Consent – Where processing is based on your consent
To exercise these rights, contact us at 0208 688 5544 or visit the pharmacy.
11. Children's Privacy
Our services are intended for individuals over the age of 16. We do not knowingly collect data from children under 13 without appropriate consent from a parent or guardian.
12. Complaints
If you have concerns about how your data is handled, please contact us first. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113
www.ico.org.uk
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Your continued use of the site or services after changes are made constitutes your acceptance of those changes.