Privacy Notice
Introduction
Total Access Health Ltd takes the privacy of your information very seriously. This privacy policy applies to our use of any and all Data collected by us or provided by you in relation to your use of our website and services. By using our services you agree to our use of your data, if you do not agree with any of the terms included in this policy, please refrain from using our services.
This privacy policy applies between you, the User of this Website and Total Access Health Ltd. (Trading as e-Pharmacy), the owner and provider of this Website. Total Access Health is a company registered in England and Wales under company number 10681825. Our registered address is Total Access Health, The Enterprise Centre, University of East Anglia NR4 7TJ. In accordance with to the Data Protection Act 2018, we act as controllers for your data.
This privacy policy should be read alongside, and in addition to, our Terms and Conditions of Website Use and Terms and Conditions.
In this privacy policy, unless the context requires a different interpretation:
- the singular includes the plural and vice versa;
- references to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this privacy policy;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- âincludingâ is understood to mean âincluding without limitationâ;
- reference to any statutory provision includes any modification or amendment of it;
- the headings and sub-headings do not form part of this privacy policy.
Scope of this privacy policy
- This privacy policy applies only to the actions of Total Access Health Ltd. and Users with respect to this website (e-pharmacy.co.uk). It does not extend to any websites that can be accessed from this Website including, but not limited to, any links we may provide to social media websites.
- For purposes of the applicable Data Protection Laws, Total Access Health Ltd. is the âdata controllerâ. This means that Total Access Health Ltd. determines the purposes for which, and the manner in which, your Data is processed.
Data collected
We may collect the following Data, which includes personal Data, from you:
- Identity information such as name, usernames, identifiers, date of birth, gender;
- Contact information such as email addresses, telephone numbers and billing and shipping address;
- Health information such as the responses to the online consultations you chose to give and any follow ups with our prescribers. This includes gender, sexual history, medication history, consultation notes (see Special Category Data below);
- Technical information such as IP addresses, web browser type and version, browser plugin type and version, time zone, platform and operating system;
- Information about user browsing behaviour including page response times, length of visit, errors on pages, page interaction such as scrolling and clicks, and navigation away from pages.
- Any phone numbers used to call our customer service;
- Financial information such as credit / debit card numbers;
- in each case, in accordance with this privacy policy.
This is not an exhaustive list and at times we may need to collect other data from you for the purposes outlined in this policy.
How we collect data
We collect Data in the following ways:
- data is given to us by you;
- data is received from other sources; and
- data is collected automatically.
Data that is given to us by you
Total Access Health Ltd. will collect your Data in a number of ways, for example:
- when you contact us through our website, by telephone, post, e-mail or through any other means;
- when you register with us and set up an account to receive our products/services;
- when you make payments to us, through our website or otherwise;
- when you elect to receive marketing communications from us;
- when you use our services;
in each case, in accordance with this privacy policy.
Special category data that is given to us by you
This includes sensitive information that you give to us by filling of online forms on our site or by communicating with us by phone, email, or in other ways. For example, you provide us with special category data by completing the online consultation questions. The data might include, but is not limited to, ethnicity, general health, other health biometrics, sexual activity and/or sexual orientation, or information relating to genetics.
We rely on your explicit consent to permit us to process special category data that pertains to you, which we need for the purpose of providing preventative or occupational medicine, medical diagnosis, and the provision of health treatment. Such activities are performed in accordance with all regulatory guidelines.
We will use special category data to carry out the obligations agreed upon to in any contracts entered between you and Total Access Health. We will use special category data to enable us to supply you with the information, products and/or services that you have requested from us.
Data that is received from third parties
This is information that we may receive about you from other sources. We work with a select list of third parties (for example information technology sub-contractors, payment, and delivery services, advertising networks, site analytics providers, search information providers, credit reference and identity information agencies, and other business partners) and will notify you when we receive information about you from them and the purposes for which we intend to use that information.
We use LexisNexis and AgeVerifyUK to verify our customersâ identities. This is to ensure we comply with GPhC regulations, prevent medication abuse and prevent the use of our service by individuals under the age of 18.
This is not an exhaustive list, and in specific cases, we may need to collect additional data for the purposes set out in this policy.
Data that is collected automatically
To the extent that you access the Website, we will collect your Data automatically, for example:
- we automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed âCookiesâ.
Our use of Data
Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- improvement of our products / services;
in each case, in accordance with this privacy policy.
- We may use your data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed âYour rightsâ below).
- When you register with us and set up an account to receive our services, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
Who we share Data with
We may share your Data with the following groups of people for the following reasons:
- Our employees, agents and/or professional advisors (for example for clinical assessment by our prescribers).
- Third party service providers who provide services to us which require the processing of personal data â (For example to help third party service providers in receipt of any shared data to perform functions on our behalf to help ensure the website runs smoothly).
- Third party providers that provide services to us that ensure we comply with GPhC regulations -such as identity verification services like LexisNexis.
- Third party payment providers who process payments made over the Website â To enable third party payment providers to process user payments and refunds.
- advertisers and advertising networks that require the data to select and serve relevant adverts to you and others. We do not disclose information about identifiable individuals to our advertisers but have the right to provide them with aggregate information about our users. We may make use of the personal data that we have collected from you to enable us to comply with our advertisersâ wishes by displaying their advertisement to that target audience;
- analytics and search engine companies that assist us in the improvement of our site; and
- Relevant authorities â To facilitate the detection of crime in exceptional circumstances.
in each case, in accordance with this privacy policy.
Keeping Data secure
- We will use technical and organisational measures to safeguard your Data, for example:
- access to your account is controlled by a password and a username that is unique to you.
- we store your Data on secure servers.
- payment details are encrypted using SSL technology (typically you will see a lock icon or green address bar (or both) in your browser when we use this technology.
- We follow the standards set by ISO 27001. This family of standards helps us manage your Data and keep it secure.
- Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: [email protected].
- Our Data Protection Officer (DPO) is Thuria Wenbar and can be contacted at: [email protected].
- The transfer of information via the internet is never completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
- If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
Data retention
- Unless a longer retention period is required or permitted by law, we will only hold your Data on our systems for the period necessary to fulfil the purposes outlined in this privacy policy or until you request that the Data be deleted.
- Even if we delete your Data, it may persist on backup or archival media for legal, tax or regulatory purposes.
Your rights
You have the following rights in relation to your Data:
- Right to access â the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is âmanifestly unfounded or excessive.â Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- Right to correct â the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase â the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data â the right to âblockâ us from using your Data or limit the way in which we can use it.
- Right to data portability â the right to request that we move, copy or transfer your Data.
- Right to object â the right to object to our use of your Data including where we use it for our legitimate interests.
To make inquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: [email protected].
If you are not satisfied with the way a complaint you make in relation to your Data is handled by us, you may be able to refer your complaint to the relevant data protection authority. For the UK, this is the Information Commissionerâs Office (ICO). The ICOâs contact details can be found on their website at www.ico.org.uk.
It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
Links to other websites
This Website may, from time to time, provide links to other websites. We have no control over such websites and are not responsible for the content of these websites. This privacy policy does not extend to your use of such websites. You are advised to read the privacy policy or statement of other websites prior to using them.
Changes of business ownership and control
- Total Access Health Ltd. may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of Total Access Health Ltd. Data provided by Users will, where it is relevant to any part of our business so transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this privacy policy, be permitted to use the Data for the purposes for which it was originally supplied to us.
- We may also disclose Data to a prospective purchaser of our business or any part of it.
- In the above instances, we will take steps with the aim of ensuring your privacy is protected.
General
- You may not transfer any of your rights under this privacy policy to any other person. We may transfer our rights under this privacy policy where we reasonably believe your rights will not be affected.
- If any court or competent authority finds that any provision of this privacy policy (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this privacy policy will not be affected.
- Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
- This Agreement will be governed by and interpreted according to the law of England and Wales. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the English and Welsh courts.
Changes to this privacy policy
Total Access Health Ltd. reserves the right to change this privacy policy as we may deem necessary from time to time or as may be required by law. Any changes will be immediately posted on the Website and you are deemed to have accepted the terms of the privacy policy on your first use of the Website following the alterations. You may contact Total Access Health Ltd. by email at [email protected].