GDPR Compliance

Last Updated: September 1, 2024

Our Commitment to GDPR

PharmGo is fully committed to complying with the General Data Protection Regulation (GDPR). We ensure that all personal data is processed lawfully, fairly, and transparently, with appropriate security measures in place to protect your information.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

1. Right to Access

You can request access to your personal data and receive a copy of the data we hold about you.

2. Right to Rectification

You can request correction of inaccurate personal data or completion of incomplete data.

3. Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data under certain circumstances.

4. Right to Restrict Processing

You can request that we limit the processing of your personal data in certain situations.

5. Right to Data Portability

You can request to receive your data in a structured, commonly used, and machine-readable format.

6. Right to Object

You can object to the processing of your personal data for direct marketing or legitimate interests.

7. Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing.

Data We Collect

We collect and process the following categories of personal data:

Pharmacy Account Data

Business name, address, contact details, registration numbers

User Account Data

Name, email, role, authentication credentials

Patient Data

Name, address, contact details, delivery preferences

Delivery Data

Delivery addresses, timestamps, signatures, tracking information

Technical Data

IP addresses, browser type, device information, usage logs

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract: Processing necessary for the performance of our service agreement
  • Legal Obligation: Processing required to comply with legal requirements
  • Legitimate Interests: Processing for our legitimate business interests
  • Consent: Processing based on your explicit consent (for marketing communications)
  • Vital Interests: Processing necessary to protect someone's life (emergency situations)

Data Security Measures

We implement comprehensive security measures to protect your data:

Technical Measures

  • • End-to-end encryption
  • • Secure SSL/TLS connections
  • • Regular security audits
  • • Access controls and authentication

Organizational Measures

  • • Staff training on data protection
  • • Data protection policies
  • • Regular risk assessments
  • • Incident response procedures

Data Retention

We retain personal data only for as long as necessary:

Data TypeRetention Period
Account DataDuration of service + 1 year
Delivery Records7 years (legal requirement)
Financial Records7 years (tax purposes)
Technical Logs90 days

International Data Transfers

When we transfer data outside the UK/EEA, we ensure appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with sufficient data protection laws
  • Binding Corporate Rules for intra-group transfers
  • Your explicit consent for specific transfers

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify the ICO within 72 hours of becoming aware
  • We will inform affected individuals without undue delay
  • We will provide details of the breach and measures taken
  • We maintain a breach register as required by GDPR

Data Protection Officer

Our Data Protection Officer can be contacted for any GDPR-related queries:

Email: [email protected]

Phone: +44 20 7123 4567

Address: Data Protection Officer, PharmGo Limited, London, UK

How to Exercise Your Rights

To exercise any of your GDPR rights:

  1. Contact our DPO at [email protected]
  2. Provide proof of identity for verification
  3. Specify which right(s) you wish to exercise
  4. We will respond within 30 days of receipt

Supervisory Authority

You have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Phone: 0303 123 1113

Website: ico.org.uk

This GDPR compliance document was last reviewed on September 1, 2024, and is regularly updated to ensure ongoing compliance with data protection regulations.