How we look after your personal and health information, why we hold it, and the rights you have over it.
Lyng Pharmacy, operated by Gurdal Ltd, is the data controller for the information we hold about you. We are registered with the Information Commissioner’s Office and regulated by the General Pharmaceutical Council.
Our Superintendent Pharmacist, Jeetender Singh Sahota, is responsible for data protection at the pharmacy and acts as our point of contact for any question about your information.
Your name, date of birth, address, phone number, email address and NHS number where relevant.
Your prescriptions and medication history, allergies and adverse reactions, the conditions we treat you for, consultation notes, vaccination records, and the answers you give to any clinical questionnaire — including the screening questions for pharmacy medicines sold online.
What you order, your delivery address, and your order history. We never see or store your card details — card payments are handled entirely by Stripe, who are PCI-DSS certified. We only receive confirmation that a payment succeeded.
Basic technical data such as pages visited and approximate location from your IP address. Where you create an account we store your email address and a securely hashed password — we cannot see your password.
Under UK GDPR we must have a lawful basis for using your information. Health data is “special category” data and needs an additional condition.
To provide pharmacy services and NHS care
Lawful basis: Article 6(1)(e) public task, and Article 9(2)(h) provision of health care. This covers dispensing, Pharmacy First, vaccinations, blood pressure checks and similar services.
To fulfil shop orders
Lawful basis: Article 6(1)(b) performance of a contract. Where an order includes a pharmacy medicine, the clinical check uses Article 9(2)(h).
To meet legal and regulatory duties
Lawful basis: Article 6(1)(c) legal obligation. This covers record keeping required by the Human Medicines Regulations, controlled drug registers, and NHS contractual requirements.
To keep patients safe
Lawful basis: Article 9(2)(i) public interest in public health, for example reporting a suspected adverse drug reaction or a safeguarding concern.
To send you marketing, if you have asked for it
Lawful basis: Article 6(1)(a) consent. You can withdraw this at any time and we will stop.
We monitor repeat purchases of certain medicines that can be misused or become habit-forming. This is a patient safety measure required of us as pharmacy professionals, and it may mean a pharmacist contacts you before supplying again.
We only share your information where we need to, and only what is necessary:
We never sell your information, and we never share it for advertising.
Patient records are held in an access-controlled database hosted in the EU, encrypted in transit and at rest. Access to our admin systems is restricted to named authorised staff on an approved list, and every sign-in attempt is logged and rate limited to resist attacks.
Paper records are kept in the dispensary, which is not accessible to the public. All staff are trained in confidentiality and data protection as part of induction, and confidentiality obligations continue after they leave.
If a data breach occurs that risks your rights and freedoms, we will report it to the ICO within 72 hours and tell you directly where the risk to you is high.
You have the right to:
You can exercise any of these by contacting us. We may ask for identification first, to make sure we don’t give your records to someone else.
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you.
Our website uses only what it needs to work — keeping you signed in and remembering your basket. See our cookie policy for detail, and our privacy policy for how the website itself handles data.
For anything to do with your information, contact the Superintendent Pharmacist at lyngpharmacy@gmail.com, call 0121 500 5756, or write to us at 1 Lyng Lane, West Bromwich B70 7RW.
If you’re unhappy with how we’ve handled your data you can complain to the Information Commissioner’s Office — 0303 123 1113, ico.org.uk. We’d appreciate the chance to put things right first.