GDPR Compliance
Learn about your data protection rights and our commitment to GDPR.
Last Updated: September 1, 2024
Our Commitment to GDPR
PharmGo is fully committed to complying with the General Data Protection Regulation (GDPR). We ensure that all personal data is processed lawfully, fairly, and transparently, with appropriate security measures in place to protect your information.
Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
1. Right to Access
You can request access to your personal data and receive a copy of the data we hold about you.
2. Right to Rectification
You can request correction of inaccurate personal data or completion of incomplete data.
3. Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data under certain circumstances.
4. Right to Restrict Processing
You can request that we limit the processing of your personal data in certain situations.
5. Right to Data Portability
You can request to receive your data in a structured, commonly used, and machine-readable format.
6. Right to Object
You can object to the processing of your personal data for direct marketing or legitimate interests.
7. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing.
Data We Collect
We collect and process the following categories of personal data:
Pharmacy Account Data
Business name, address, contact details, registration numbers
User Account Data
Name, email, role, authentication credentials
Patient Data
Name, address, contact details, delivery preferences
Delivery Data
Delivery addresses, timestamps, signatures, tracking information
Technical Data
IP addresses, browser type, device information, usage logs
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: Processing necessary for the performance of our service agreement
- Legal Obligation: Processing required to comply with legal requirements
- Legitimate Interests: Processing for our legitimate business interests
- Consent: Processing based on your explicit consent (for marketing communications)
- Vital Interests: Processing necessary to protect someone's life (emergency situations)
Data Security Measures
We implement comprehensive security measures to protect your data:
Technical Measures
- • End-to-end encryption
- • Secure SSL/TLS connections
- • Regular security audits
- • Access controls and authentication
Organizational Measures
- • Staff training on data protection
- • Data protection policies
- • Regular risk assessments
- • Incident response procedures
Data Retention
We retain personal data only for as long as necessary:
| Data Type | Retention Period |
|---|---|
| Account Data | Duration of service + 1 year |
| Delivery Records | 7 years (legal requirement) |
| Financial Records | 7 years (tax purposes) |
| Technical Logs | 90 days |
International Data Transfers
When we transfer data outside the UK/EEA, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries with sufficient data protection laws
- Binding Corporate Rules for intra-group transfers
- Your explicit consent for specific transfers
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms:
- We will notify the ICO within 72 hours of becoming aware
- We will inform affected individuals without undue delay
- We will provide details of the breach and measures taken
- We maintain a breach register as required by GDPR
Data Protection Officer
Our Data Protection Officer can be contacted for any GDPR-related queries:
Email: [email protected]
Phone: +44 20 7123 4567
Address: Data Protection Officer, PharmGo Limited, London, UK
How to Exercise Your Rights
To exercise any of your GDPR rights:
- Contact our DPO at [email protected]
- Provide proof of identity for verification
- Specify which right(s) you wish to exercise
- We will respond within 30 days of receipt
Supervisory Authority
You have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk
This GDPR compliance document was last reviewed on September 1, 2024, and is regularly updated to ensure ongoing compliance with data protection regulations.