This policy explains how personal information may be collected, used, shared, protected and retained when Pharma Available services are used.
Scope
This policy applies to information collected through the website, accounts, forms, consultations, orders, support journeys and related digital services.
Service-specific notices shown when information is collected may also apply.
Information We May Collect
Identity, account, verification, order, payment-status, consultation, health, communication, preference, device, browser, security-log and cookie information may be collected where relevant.
Only information reasonably required for the relevant purpose should be requested.
Health Information
Consultation and medical information may receive additional protection under data-protection law.
Access should be limited to authorised people and providers who require it for clinical, pharmacy, safety, legal or regulatory purposes.
How Information May Be Used
Information may be used to operate the website, provide consultations, assess treatment suitability, verify eligibility, process transactions, arrange fulfilment, maintain records, improve services, prevent fraud and meet professional or legal duties.
Lawful Bases
The lawful basis depends on the purpose and may include contract, legal obligation, legitimate interests, consent, vital interests or another basis permitted by law.
Special category information requires an additional lawful condition.
Sharing Information
Information may be shared where necessary with authorised pharmacy professionals, prescribers, dispensing providers, payment services, technology providers, delivery providers, advisers, regulators, public authorities or safeguarding bodies.
Appropriate confidentiality, security and data-processing arrangements should apply.
International Processing
Where a provider processes information outside the United Kingdom, appropriate safeguards should be used according to the destination and type of processing.
Retention and Security
Records should be kept only for as long as required for clinical, legal, accounting, fraud-prevention, professional or regulatory purposes.
Reasonable technical and organisational safeguards should protect information against unauthorised access, loss, alteration or misuse.
Your Rights
Depending on the circumstances, individuals may have rights to information, access, correction, deletion, restriction, objection, portability and withdrawal of consent.
Some rights may be limited where records must be retained for legal, clinical or public-interest reasons.
Cookies, Children and Automated Tools
Cookies and similar technologies are described in the Cookie Policy.
Age and eligibility restrictions may apply to services involving children.
Digital tools may assist routing, security and completeness checks, but completing an online form does not automatically approve treatment.
Questions, Concerns and Updates
Privacy requests or concerns should be submitted through the designated privacy or support route on the website.
This policy may be updated when services, technologies, data flows or legal requirements change.