Privacy Policy - Chemitex Pharmacy

Who We Are

Chemitex Pharmacy is located at 332 Hornsey Road, London, N7 7HE. We are registered with the General Pharmaceutical Council (GPhC premises number: 1040360). Our Superintendent Pharmacist is Dipesh Jogi (GPhC 2073384).

For the purposes of UK data protection law, Chemitex Pharmacy is the data controller. This means we decide why and how your personal data is used when you interact with us — online, by phone, or in person.

You can contact us about anything in this policy at:

Email: chemitex.pharmacy@nhs.net
Phone: +44 20 7272 4869
Post: 332 Hornsey Road, London, N7 7HE

What This Policy Covers

This policy explains what personal data we collect, why we collect it, how long we keep it, and what your rights are under UK GDPR and the Data Protection Act 2018.

It covers:

  • The Chemitex Pharmacy website at chemitexpharmacylondon.co.uk
  • NHS and private services provided in pharmacy
  • Enquiries and bookings made by phone, email, or online

It does not cover third-party websites we may link to. If you follow a link to another site, their own privacy policy applies from that point.

The Data We Collect

When You Use Our Website

We collect technical data automatically when you visit our site. This includes your IP address, browser type, the pages you visit, and how long you spend on them. This data is collected via cookies and analytics tools. It’s used to understand how the site is performing and to improve the patient experience; it doesn’t identify you individually.

If you use our online booking system (Treat Local), you’ll be asked to provide your name, date of birth, contact details, and the service you’re booking. That information goes directly into the booking system and is used to manage your appointment.

When You Contact Us

If you email or phone us to ask about a service, we’ll use the details you give us to respond. We don’t add enquiry contacts to any marketing list without your explicit consent.

When You Receive Clinical Services

This is where we handle the most sensitive data. When you attend for any clinical service, NHS or private, we collect and process health information. That includes your name, date of birth, address, NHS number where applicable, medical history relevant to the service, medication details, and the clinical records generated during your visit.

Health data is classified as a special category of personal data under UK GDPR, which means it receives a higher level of legal protection. We only process it where we have a lawful basis to do so.

Why We Process Your Data

We process personal data for the following reasons:

Providing NHS services. Where we deliver services on behalf of the NHS (repeat dispensing, Pharmacy First, Electronic Repeat Dispensing), we process data under our contract with the NHS and in line with NHS data processing standards. Your GP practice is notified of any treatment provided under NHS Pharmacy First, as required.

Providing private clinical services. For private consultations, vaccinations, weight loss programmes, and other private services, we process health data with your explicit consent and to fulfil the contract for care. You give consent at the point of consultation.

Legal obligations. As a registered pharmacy, we are subject to GPhC regulatory requirements and NHS contractual obligations that require us to keep accurate clinical records. We also have legal obligations under medicines legislation, public health law, and safeguarding frameworks.

Legitimate interests. For non-clinical interactions such as general enquiries or website use, we rely on legitimate interests where we judge that our interest in running a lawful and effective pharmacy business is not overridden by your privacy interests.

Booking and appointment management. We use the personal data you provide when booking to schedule, confirm and manage your appointment. This includes sending reminder communications if you’ve opted in.

Who We Share Your Data With

We do not sell your data. We do not share it with advertisers. We share it only where necessary to deliver your care or to meet a legal obligation.

GP practices. Where required under NHS Pharmacy First or other commissioned services, we notify your registered GP of treatment provided.

NHS systems. We use NHS-integrated systems for prescription processing and Electronic Repeat Dispensing. Data shared through these systems is governed by NHS data processing agreements.

Treat Local (booking system). Your booking data is held in Treat Local’s system. Their own privacy policy governs how they process that data on our behalf, and they act as a data processor under our instruction.

Map My Mole (mole screening). If you use our mole screening service, your screening data is processed by Map My Mole to produce your report. Their privacy policy applies to that processing.

Clear Clinics (earwax training provider). Our earwax removal staff are trained by Clear Clinics. We do not share patient data with them as part of service delivery.

Regulatory bodies. In certain circumstances, we may be required to share information with the GPhC, NHS England, or other regulatory or public health bodies. We’d only do this where we have a legal obligation to do so, or where there is a serious risk to public health or individual safety.

Legal requirements. If required by law, for example, by a court order or a lawful police request, we will disclose information as required.

Health Data and Confidentiality

Patient confidentiality is a core professional obligation, not just a legal one. The team at Chemitex Pharmacy are bound by professional codes of conduct that require them to keep your health information confidential except in specific circumstances.

Those circumstances are narrow: a serious risk to your life or someone else’s, a statutory reporting requirement, or your explicit consent to share. We don’t discuss patient health information with family members, employers, or anyone else without your consent, except where we have a legal duty to do so.

Clinical records created during your visits are kept for the period required by NHS and regulatory guidance. For most adult patients, that’s a minimum of 8 years from the last entry. Records for children are kept until their 25th birthday, or 26th if they were 17 at the time of the last entry.

Cookies

Our website uses cookies. Some are strictly necessary for the site to function, these can’t be turned off. Others are analytical, helping us understand how visitors use the site, and some are set by third-party tools like our booking system.

When you first visit the site, you’ll be asked to accept or manage your cookie preferences. You can change these at any time through the cookie settings on the site. Refusing non-essential cookies won’t stop you from using any part of the site.

Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of access. You can ask us for a copy of the personal data we hold about you. This is called a Subject Access Request (SAR). We’ll respond within one month. There’s no charge in most cases.

Right to rectification. If the data we hold is inaccurate or incomplete, you can ask us to correct it.

Right to erasure. In certain circumstances, you can ask us to delete your data. This right doesn’t apply where we have a legal obligation to keep records, for example, clinical records that fall within the required retention period.

Right to restrict processing. You can ask us to limit how we use your data while a dispute about its accuracy or lawfulness is being resolved.

Right to data portability. Where processing is based on your consent or a contract, and is carried out by automated means, you can ask us to provide your data in a structured, machine-readable format.

Right to object. Where we rely on legitimate interests as our lawful basis, you can object to that processing. We’ll consider your objection and stop unless we have compelling grounds to continue.

Rights related to automated decision-making. We don’t use automated decision-making or profiling to make clinical decisions about you.

To exercise any of these rights, contact us at chemitex.pharmacy@nhs.net or write to us at 332 Hornsey Road, London, N7 7HE. We’ll respond within one calendar month. If your request is complex or you’ve made multiple requests, we may extend this by a further two months; we’ll let you know if that’s the case.

How We Keep Your Data Secure

We take data security seriously. Patient records are stored in password-protected systems with access limited to clinical and administrative staff who need it to do their jobs. Paper records are stored securely on the premises.

We don’t transfer personal data outside the UK unless we have an appropriate safeguard in place under UK GDPR.

If we become aware of a data breach that’s likely to affect your rights and freedoms, we’ll notify the ICO within 72 hours as required, and we’ll contact you directly if you’re at risk.

Complaints

If you’re unhappy with how we’ve handled your data, please contact us first. We’d rather resolve it directly.

If you’re still not satisfied after raising it with us, you have the right to complain to the Information Commissioner’s Office (ICO):

Website: ico.org.uk
Phone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Changes to This Policy

We’ll update this policy when our practices change or when required by law. The date at the top of the page shows when it was last revised. Significant changes will be flagged on the website.