Privacy Policy

‍Last updated: May 2025

Solent Pharmacy is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other relevant legislation.
By using our services, you consent to the practices described in this policy.

1. Who We Are
PHARMHT LTD T/A Solent Pharmacy
Address: 9 St James Road, Southampton, Hampshire, SO15 5FB
Telephone: 02381 229024
Website: https://solentpharmacy.co.uk
We are a registered NHS and private healthcare provider under the General Pharmaceutical Council (GPhC).
For purposes of data protection law, Solent Pharmacy is the Data Controller of your personal information.

2. What Information We Collect
We may collect and process the following types of personal data:
• Identity Data: Name, date of birth, NHS number.
• Contact Data: Address, telephone number.
• Health Information: Medical history, prescription details, clinical records.
• Transactional Data: Details of services provided, payments made.
• Technical Data: IP address, browser type, and website usage data (only if interacting with our website).
• Communication Data: Any information you provide when contacting us, booking services, or attending consultations.
We collect only the data that is necessary to provide safe and effective healthcare services.

3. How We Collect Your Data
We collect data through:
• In-person interactions at our pharmacy premises.
• Telephone calls.
• NHS electronic systems (e.g., Electronic Prescription Service).
• Our website and online forms.
• Referral services (e.g., NHS 111, NHS Pharmacy First, vaccination programs).

4. Why We Process Your Information
We process your data to:
• Dispense NHS and private prescriptions safely.
• Deliver healthcare services (e.g., consultations, Pharmacy First treatments).
• Manage appointments, clinical services, and medication delivery.
• Comply with NHS contractual requirements and regulatory obligations.
• Handle payment transactions and manage accounts.
• Communicate with you regarding your healthcare.
• Maintain medical records in accordance with healthcare regulations.
We process special category (sensitive) health information based on legal obligations and public interest in the area of public health.

5. Lawful Basis for Processing
Under the UK GDPR, the main lawful bases for processing your personal data include:
• Consent: Where you have given clear consent for specific processing (e.g., vaccination appointments).
• Performance of a Contract: To provide you with requested healthcare services.
• Legal Obligation: To comply with NHS regulations, safeguarding laws, and pharmacy practice standards.
• Vital Interests: In emergency situations to protect your life or health.
• Public Task: Providing healthcare services as part of our role under NHS contracts.
For health data, we rely on additional lawful bases under Article 9 of the UK GDPR (healthcare purposes and substantial public interest).

6. Sharing Your Data
We may share your personal data with:
• NHS bodies (e.g., NHS England, NHS Digital, GP surgeries).
• Healthcare professionals involved in your care.
• IT and data hosting providers (strictly for service delivery).
• Regulators and public authorities where legally required (e.g., GPhC, MHRA).
• External courier services (for paid medication deliveries, where necessary).
We ensure all third parties respect your data and process it only in accordance with our instructions and the law.
We do not sell, rent, or trade your personal information to third parties.

7. How We Protect Your Data
We use appropriate technical and organisational measures to safeguard your information, including:
• Secure patient record systems.
• Staff training on confidentiality and GDPR compliance.
• Access controls and password protections.
• Physical security measures within our premises.
• Regular audits and risk assessments.

8. How Long We Keep Your Data
We retain your personal data only for as long as necessary for the purposes we collected it, including:
• NHS Records: Typically kept for a minimum of 8 years (or longer where required under NHS retention schedules).
• Private Service Records: Retained in line with applicable medical and legal guidelines.
• Marketing Consents (if any): Until you withdraw consent.
After the retention period expires, we securely delete or anonymise your data.

9. Your Data Protection Rights
Under data protection law, you have rights including:
• Access: Request a copy of the information we hold about you.
• Rectification: Request correction of inaccurate or incomplete data.
• Erasure: Request deletion of your data under certain circumstances ("right to be forgotten").
• Restriction: Request limited processing of your data.
• Objection: Object to data processing where we rely on public interest or legitimate interest.
• Portability: Request data transfer to another provider (where technically feasible).
To exercise any of these rights, please contact the pharmacy directly by telephone or in writing.

10. Cookies and Website Usage
Our website uses cookies for basic functionality and to improve user experience.
For more information, please see our Cookie Policy (available on our website).
We do not use cookies for advertising or profiling.

11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Any changes will be posted on our website. We encourage you to check this page periodically.
Continued use of our services after changes have been posted constitutes your acceptance of the revised Privacy Policy.

12. Contact Information
If you have any questions or concerns about how your data is handled, please contact us by telephone at:
02381 229024
If you are unhappy with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
https://ico.org.uk/