Total Access Health Ltd. (trading as Evaro), a company incorporated in England and Wales under company number 10681825, whose registered office is at The Enterprise Centre, University of East Anglia, Norwich NR4 7TJ (and whose primary trading and registered pharmacy address is 42 Barnard Road, Norwich NR5 9JB) (“Evaro”, “we”, “us” or “our”). References to “we” or “us” throughout this policy shall refer to Evaro. For the purposes of this privacy policy, and in accordance with the UK GDPR and the Data Protection Act 2018, we are the data controller of your personal information.
Evaro operates a regulated online healthcare platform providing online consultations, prescribing, dispensing and pharmacy services. This privacy policy explains what personal information we collect, why we collect it, and what we do with it. It should be read alongside, and in addition to, our Terms and Conditions of Website Use, our Terms of Service and our Cookies Policy.
The information we collect depends on our relationship with you and the specific product or service you are interested in. Where Evaro is the data controller, we may collect the following categories of personal information about you:
This is not an exhaustive list, and at times we may need to collect other data from you provided it is consistent with the purposes outlined in this policy.
We collect personal information in the following ways.
Some of the personal information we collect is more sensitive and is treated as “special category data” under Article 9 of the UK GDPR — in particular, information concerning your physical or mental health, and information that may reveal your sex life or sexual orientation. You provide us with special category data, for example, when you complete an online consultation.
We will only process special category data where we have both a lawful basis under Article 6 of the UK GDPR and a separate condition under Article 9 of the UK GDPR (and, where required, a corresponding condition under Schedule 1 to the Data Protection Act 2018). In most cases, we rely on:
Where we rely on a Schedule 1 condition that requires it, we maintain an Appropriate Policy Document. You may withdraw your consent at any time, although this may mean we are unable to provide, or continue to provide, the services you have requested.
We use your personal information to provide our services both directly to patients through our own website (evaro.com) and through white-label and platform partnerships with consumer brands and healthcare companies. Where you access our services through a partner’s website or app:
We use your personal information to provide our products and services to you and to operate our platform safely and lawfully. Specifically, we may use your data to:
We will only process your personal information where we have a legally valid reason to do so. Under the UK GDPR, this is called a lawful basis, and more than one lawful basis may apply depending on the processing activity. The table below summarises the lawful bases we rely on.
| How we use your information | Personal information we may process | Lawful grounds for processing |
|---|---|---|
| To register you, manage your account and provide the services you request | Identity, contact, account and financial information | Performance of a contract and taking steps at your request to enter into a contract. |
| To conduct online consultations, clinical review, prescribing and pharmacy/dispensing services | Identity, contact and health information | Performance of a contract (Article 6); and, for special category data, Article 9(2)(a) explicit consent and/or Article 9(2)(h) provision of health care or treatment (Schedule 1, condition 2). |
| To verify your identity and age | Identity and identity verification information | Legal obligation and legitimate interests in preventing supply of medicines to ineligible persons where a legal obligation does not apply. |
| To comply with legal, clinical and regulatory obligations | Identity, contact, health, financial and order information | Legal obligation and, for special category data, provision of a healthcare service (Article 9(2)(h)) and/or substantial public interest (Article 9(2)(g)) |
| To detect, prevent and investigate fraud, medication abuse and crime | Identity, contact, health and usage information | Legal obligation and legitimate interests in detecting and preventing fraud or other crime where a legal obligation does not apply. For special category data, substantial public interest (Article 9(2)(g), with the relevant Schedule 1 condition). |
| For research, analytics and service improvement | Usage, technical and (where relevant) pseudonymised health information | Legitimate interests in understanding and improving our services; or Where health data is in scope, the research basis under Art. 9(2)(j) |
| To send marketing communications | Contact information and marketing preferences | Consent; or The soft opt-in exception and our legitimate interests in understanding and improving our services |
| To protect and secure our business, systems and services | Identity, technical and usage information | Legitimate interests in protecting our operations, systems and services. |
Where we rely on legitimate interests, we have completed a legitimate interests assessment.
Our online consultation uses questionnaires and search technology, which may include natural language processing and AI-assisted tools, to help gather relevant information and support the clinical process. Consultations are reviewed by a qualified clinician (an independent pharmacist prescriber or doctor) before any prescription is issued, and a clinician remains individually responsible for each prescribing decision.
We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing without meaningful human involvement. Where any element of decision-making might otherwise be solely automated and use special category data, we will only carry it out with your explicit consent or where a substantial public interest condition applies, and we will put suitable safeguards in place. You have the right not to be subject to such solely automated decisions and to request human intervention.
We may share your personal information with the following categories of recipient, in each case in accordance with this privacy policy and subject to appropriate safeguards and confidentiality obligations:
The collection of information and its processing prior to transfer are subject to the national laws where it is collected and/or where the data subject is located, and conditions for or restrictions on its transfer according to those laws are respected by Evaro.
Some of our service providers store or access personal data outside the UK. Where we transfer personal data to a country that is not covered by UK adequacy regulations, we ensure an appropriate transfer mechanism is in place under Article 46 of the UK GDPR — such as the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another appropriate safeguard — and, where required, we carry out a transfer risk assessment and put in place any additional measures needed to ensure the standard of protection is not materially lower than in the UK. You may contact us using the details provided at the end of this policy for more information about the safeguards in place.
We will only keep your personal information for as long as reasonably necessary to fulfil the purposes set out in this privacy policy and to comply with our legal, clinical and regulatory obligations. The period varies depending on the nature of the personal information and what we do with it.
In practice, this means we keep your personal information only for as long as it is necessary to:
We retain each category of personal information for a set period, which runs from a defined trigger point (for example, the date we first collect the information, the date of your last consultation or order, or the date you close your account). This is known as a “retention period”. Our retention periods are set out in our records management policy and retention schedule. They are determined by reference to applicable laws, our regulatory and clinical obligations, and recognised sector guidance. In particular, the NHS Records Management Code of Practice, and guidance issued by the Care Quality Commission (CQC) and the General Pharmaceutical Council (GPhC).
By way of illustration, and unless a longer period is required in a particular case:
We retain health and clinical records (including consultation notes, prescribing and medication records) for 8 years from the date of your last consultation or treatment, in line with the NHS Records Management Code of Practice 2023, except where a longer period applies to a particular record type;
We retain records relating to prescription-only and pharmacy medicines for the minimum periods required under the Human Medicines Regulations 2012 and applicable GPhC guidance (generally at least 2 years);
We retain financial and transaction records for 6 years plus the current year, to meet our tax, audit and accounting obligations; and
At the end of the applicable retention period, we will securely delete, anonymise or archive your personal information in accordance with our retention schedule. We may, however, retain certain personal information for longer where:
Where we delete your data, certain data may needed to be retained on backup or archival media for legal, tax or regulatory purposes.
You have various rights regarding your personal information. To exercise any of them, or to withdraw consent where consent is our lawful basis, please contact us using the details provided at the end of this policy. We will always respond to any request you make, and if we cannot comply we will tell you why. In some cases we may not be able to comply with a request because of our own legal, clinical or regulatory obligations.
Your rights include:
We use cookies and similar technologies (such as pixels and web beacons) on our website. These include strictly necessary cookies, analytical/performance cookies, functionality cookies, and targeting/advertising cookies. Full details are set out in our Cookies Policy.
We will only place non-essential cookies (including analytics, targeting and advertising cookies) on your device with your consent, obtained through our cookie banner, which allows you to accept or reject non-essential cookies. Strictly necessary cookies do not require consent. Declining non-essential cookies will not affect your ability to use the core functionality of our website. You can withdraw or change your consent at any time through the cookie settings.
Where you have agreed to receive marketing communications, or where we are otherwise permitted to contact you (for example under the “soft opt-in” in the Privacy and Electronic Communications Regulations 2003 (PECR) in respect of our own similar products and services), we may send you information about our products, services and offers by post, email, telephone or other electronic means in line with your preferences. You can opt out of receiving marketing communications at any time by using the unsubscribe link in any marketing email or by contacting us using the details in this policy.
Please note that certain communications relating to your treatment, orders and ongoing care (including medication information and patient-safety and follow-up messages required by GPhC and CQC regulations) are service communications essential to your health and safety and are not marketing. Opting out of marketing will not stop these service communications.
We take the security of your personal information seriously and implement appropriate technical and organisational measures designed to protect it against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include access controls (including unique account credentials), storage on secure servers, encryption of payment details, staff confidentiality and training obligations, and procedures to deal with any suspected personal data breach. We follow the standards set by ISO 27001.
We restrict access to your personal information to those who need it to carry out their duties. Where we are legally required to do so, we will notify you and the Information Commissioner’s Office of a personal data breach.
The transmission of information via the internet is never completely secure, and any transmission is at your own risk. If you suspect any misuse, loss or unauthorised access to your data, please contact us immediately at [email protected]
Our services are directed at individuals aged 18 or over, and we do not knowingly provide our consultation, prescribing or pharmacy services to, or collect personal information from, anyone under 18 in that context. We use identity and age verification to help prevent use of our services by individuals under 18. If we become aware that we have inadvertently collected personal information from a person under 18 without an appropriate basis, we will take reasonable steps to delete it.
Our website may contain links to third-party websites, plug-ins and applications, including partner and social media websites. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. This privacy policy applies only to our processing of your personal information. When you leave our website, we encourage you to read the privacy policy of every website you visit.
If you have any questions about this privacy policy or wish to exercise any of your rights, please contact our Data Protection Officer:
The Data Protection Officer
Total Access Health Ltd. (trading as Evaro)
42 Barnard Road, Norwich NR5 9JB
England
Email address: [email protected]
We may need to make changes to this policy from time to time. This could be to reflect a new processing activity, government regulation, the deployment of new technologies or other developments in data protection laws generally. You should check the Evaro website periodically to see our most up to date privacy policy.
This Policy was last updated on: 2nd October 2026