How Lyng Pharmacy collects, uses and protects your personal information.
Lyng Pharmacy, 1 Lyng Lane, West Bromwich B70 7RW, operated by Gurdal Ltd, is the data controller responsible for your personal data. We are a registered pharmacy in Great Britain, premises number 1092508. Our Superintendent Pharmacist, Jeetender Singh Sahota (GPhC 2048691), is responsible for data protection here.
Questions about this policy? Email lyngpharmacy@gmail.com, call 0121 500 5756, or write to us at the address above.
This policy covers our website, our online shop, customer accounts and our mobile app. Our data protection policy gives the fuller detail on lawful bases, retention periods and your rights.
Identity and contact data — your name, date of birth, delivery address, phone number and email address.
Health data — your medications, prescriptions, conditions, allergies, consultation notes, vaccination records, and the answers you give to any eligibility or screening questionnaire, including the pharmacy medicine questions in our online shop.
Account data — if you create a shop account, your email address, a securely hashed password that we cannot read, your saved address, and your order history.
Order and payment data — what you ordered, delivery details and order status. We never see or store your card number. Card payments are handled entirely by Stripe; we receive only confirmation that a payment succeeded and the last few digits for reference.
Security data — sign-in attempts, including your IP address, so we can detect and block attacks on accounts.
Technical data — IP address, browser type, device type and the pages you visit.
Directly from you when you fill in a form, place an order, book an appointment, create an account or speak to us. From the NHS, your GP practice and the Electronic Prescription Service where you nominate us. And automatically from your device when you browse the site.
We rely on public task and provision of health care for NHS and clinical services, contract for shop orders, legal obligation for record keeping, legitimate interests for site security, and consent for optional marketing. Full detail is in our data protection policy.
We do not use automated decision-making that produces legal or similarly significant effects. A pharmacist — a person — reviews every pharmacy medicine questionnaire.
Our website can be installed to your home screen as an app. Push notifications are used only by pharmacy staff to receive new order alerts, and require you to opt in through your device. We do not send marketing notifications to patients. You can revoke permission at any time in your device settings.
NHS England, the NHS Business Services Authority and your Integrated Care Board, for payment and management of NHS services. Your GP and other healthcare professionals involved in your care. The MHRA, where we report a suspected side effect. Our delivery drivers, who see only what they need to deliver.
We also use technology suppliers who process data strictly on our instructions: Supabase (database, hosted in the EU), Netlify (website hosting), Stripe (payments), Resend (emails) and postcodes.io (checking whether a postcode is in our delivery area — we send only the postcode, nothing that identifies you).
We never sell your data, and we never share it for advertising.
Prescription and NHS service records for 2 years, or 11 years for children. Private consultation and vaccination records for 8 years. Shop orders and financial records for 6 years, as HMRC requires. Account details until you close your account. Security logs for 30 days.
Data is encrypted in transit and at rest, held in an access-controlled database in the EU. Admin access is limited to named authorised staff, protected by an allowlist, and every sign-in is logged and rate limited. Passwords are hashed and cannot be recovered by us or anyone else. Paper records are kept in the dispensary, away from public access.
If a breach occurs that risks your rights, we will report it to the ICO within 72 hours and tell you directly where the risk is high.
You can ask for a copy of your data, correct anything wrong, ask us to delete it, restrict or object to how we use it, ask for it in a portable format, or withdraw consent where consent is our basis. We normally respond within one month, free of charge. We may ask for identification first so that we don’t hand your records to someone else.
Some records we cannot delete because the law requires us to keep them — we’ll always explain if that applies.
You must be 16 or over to create a shop account. We provide NHS services to children where clinically appropriate, and hold their records in line with NHS retention rules. Where a child has capacity to make their own decisions, their confidentiality is respected.
We update this policy when our services change, and post the date at the top. If you’re unhappy with how we’ve handled your information, please tell us first — see our complaints policy. You can also complain to the Information Commissioner’s Office on 0303 123 1113 or at ico.org.uk.
See also: cookie policy · data protection policy · terms of use · shop terms.
We use essential cookies to make the site work — things like your basket, sign-in and secure checkout. With your permission we’d also like to use analytics cookies to understand how the site is used and improve it. See our cookie policy.