Farmeci is registered with the Information Commissioner's Office(ICO - who uphold data privacy laws).
Taking your privacy seriously
By using our website and services, you confirm that you agree to the terms of this Policy. If you do not agree to this Policy, do not use our website or services. You will be asked for explicit consent to this Policy when creating an account on this website.
Who controls the data you provide?
Farmeci is owned and operated by My Health Stop Ltd (Company Reg. 13900569) (we, us).
You can contact us by telephone on 01750 491 172; by e-mailing to firstname.lastname@example.org. We may contact you by e-mail, or by post to the billing address in your order.
For the purposes of the Data Protection Act 2018, My Health Stop Ltd is the 'controller' of your personal data, that is the company which is responsible for and controls the processing of your personal data.
We may change or update this Policy from time to time. You should check this Policy occasionally to ensure you are aware of the most recent version that will apply each time you access this Website.
Information we may collect from you
We collect the following types of information about you:
- Contact Data includes data such as your email address, telephone number, geographical address, delivery address and billing address
- Identity Data includes data such as first name, last name, username or similar identifier, date of birth, passport number, driving licence number;
- Health Data includes GP address, patient notes, consultation notes, and any other information relating to your health and medical status;
- Financial Data includes details you provide to us so that we can process your payments through our third party payment provider;
- Transaction Data includes details of products you have purchased and payments made;
- Technical Data includes data such as internet protocol (IP) address, your login data, browser type and version, cookies, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website and any communications we may send to you.
- Usage Data includes information about how you use our website such as information about your visit to our website, including the full Uniform Resource Locators (URL) clickstream to and through, pages you viewed or searches you made, page response times, download errors, length of visit, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
- Marketing Data includes your preferences in receiving marketing from us.
We do not knowingly collect personal data of children. Please do not provide personal data to us unless you are at least 18 years old.
As we are unable to verify the identity of an individual or obtain patient consent for treatment or data processing, please do not provide to us information about other people.
We may monitor and record communications with you such as telephone conversations and emails for the purpose of training, quality assurance, fraud prevention and compliance.
Information you voluntarily provide
You may provide information to us in a number of ways, including the following:
- You access and interact with our website or with us by telephone, including by filling in forms and medical questionnaires;
- You create an account on our website;
- You purchase products on our website;
- You apply to work with us as an employee or a consultant;
- You provide feedback or reviews to us;
- You respond to a survey or questionnaire although you do not have to respond to them.
- You sign up for our newsletter;
- You otherwise contact us including with queries, comments or complaints.
We shall process all such personal data in accordance with this Policy. Certain information is mandatory to be provided to us in order that we can fulfil your request, for example to purchase products from us, and we shall make this clear to you at the point of collection of the personal data.
All information that you provide to us must be true, complete and accurate. If you provide us with inaccurate or false data, and we suspect or identify fraud, we will record this and we may also report this to the appropriate authorities.
When you contact us by email or post, we may keep a record of the correspondence and we may also record any telephone call we have with you.
Information we collect from the device you use to access our website
When you visit our website or interact with our services, we (and our advertisers and/or other service providers) may use a variety of technologies that automatically or passively collect information about how our site is accessed and used.
Some of this information is collected using cookies and similar tracking technologies. If you want to find out more about the types of cookies we use, why, and how you can control them, please see our Cookies Policy.
Information we receive from other sources
We work closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, ID verification organisations and credit reference agencies) and may receive information about you from them. We may also receive your information from other organisations who sell products on our behalf.
To enable the pharmacists and clinicians to make medical or clinical decisions about you and for fraud prevention purposes, we use identity verification agents to search the files of credit reference and fraud prevention agencies (who will record the search).
If you provide false or inaccurate information and/or we suspect fraud, we will record this and we will be unable to fulfil your order.
Where we store your personal data
We ensure that all of the data that we hold about you is stored within the UK. However, the data that we collect from you may be transferred to, and stored at, a third party in a destination outside the United Kingdom. This will always be the minimum required information to carry out the task required and the data is anonymised. An example of this includes anonymous website browsing data that is aggregated within Google Analytics.
Where your personal data is transferred outside the United Kingdom or the EEA, it will only be transferred to countries that have been identified as providing adequate protection for personal data or to a third party where we have approved transfer mechanisms in place to protect your personal data.
We shall process your personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Where you have chosen a password which enables you to access certain parts of our website, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Uses made of your data
|PURPOSE/ACTIVITY||TYPE OF DATA||LAWFUL BASIS FOR |
BASIS OF LEGITIMATE
|To register you as a customer and/or |
create your account
|(a) Contact |
|Performance of a contract with you|
|To manage your account and orders for products including considering prescriptions and managing payments, cancellations, returns and refunds||(a) Contact |
|Performance of a contract with you Legitimate interests (fraud-checking)|
|Performance of a contract with you Necessary to comply with a legal obligation Necessary for our legitimate interests|
|To administer and protect our business and this website (including improving and fixing our service, analysis, testing, system maintenance, support, reporting)||(c) Technical||Necessary for our legitimate interests (for running our business and site securely, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) Necessary to comply with a legal obligation|
|To deliver relevant website content and advertisements to you and measure and understand the effectiveness of the advertising we serve to you||(a) Contact |
|Necessary for our legitimate interests (to analyse how customers use our website and manage our business accordingly)|
|To use data analytics to improve our website, products/services, marketing, customer relationships and experiences||(a) Technical |
|Necessary for our legitimate interests (to define types of customers for our products and services, to keep our site updated and relevant, to develop our business and to inform our marketing strategy)|
For our legitimate business interests, if you have purchased goods from us or you otherwise request or consent to marketing communications from us, we may use your personal data to send to you marketing communications about our goods and services that are relevant to you. You can choose to no longer receive marketing communications from us by clicking unsubscribe from an email or notifying us at email@example.com. We shall therefore retain your personal data in our records for marketing purposes until you unsubscribe from marketing communications. Please note, even if you do unsubscribe from marketing communications, we will still contact you for our legitimate interests in relation to your account and any products you order from us. We will also retain your personal data in our systems to ensure that we do not send you marketing communications. You acknowledge that it may take a few days for us to update your preferences on our system if you do unsubscribe.
Disclosure of your information
For our legitimate interests, we may share your personal data with our prescribers and pharmacies that use the Farmeci platform to perform prescribing and dispensing services, as well as our IT service providers, payment providers, accountants, auditors and lawyers. We may also ask third parties to contact you to ask you to review our services and/or provide feedback.
We check that all of our third-party suppliers are GDPR compliant before we engage their services to ensure any data is handled responsibly. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy. In addition, we shall provide our sub-contractors and agents only with such of your personal data as they need to provide the service for us and if we stop using their services, we shall request that they delete your personal data or make it anonymous within their systems.
For our legitimate interests if we choose to merge, sell assets, consolidate or restructure, finance, or sell all or a portion of our business into another company then the new owners may use your personal data in the same way that we do as set out in this Policy.
We may also disclose or share your personal data if we are under a duty to do so in order to comply with any legal obligation, or in order to enforce or apply our Terms & Conditions and other agreements; or to protect the rights, property, or safety of My Health Stop Limited, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection, security issues, technical risks and credit risk reduction.
For ID verification purposes, we share your personal data with our ID verification partner. This is only done the first time you order or if you update your personal details. This check may appear on your credit record, however, will not affect your credit score. If you are alerted that a check has been performed by a credit agency, please contact us and we will be happy to help.
You have a number of rights under applicable data protection legislation. Some of these rights are complex, and not all of the details have been included below.
- Right of access: You have the right to obtain from us a copy of the personal data that we hold for you.
- Right to rectification: You can require us to correct errors in the personal data that we process for you if it is inaccurate, incomplete or out of date.
- Right to portability: You can request that we transfer your personal data to another service provider if you initially provided consent for us to use the personal data or where we used the personal data to perform a contract with you.
- Right to restrict or object to processing: In certain circumstances, you have the right to require that we restrict the processing of your personal information. If you believe our processing impacts on your fundamental rights and freedoms. However, we may demonstrate that we have legitimate grounds to process your personal data not withstanding your rights and freedoms.
- Right to be forgotten: If you would like to discontinue being a patient you can email us and we will suspend your account. Your account will become inactive with immediate effect and you will not be able to access your account. This action cannot be undone. You acknowledge and agree that we are required by law to archive electronic patient records including your personal information, communication and treatments for a minimum of 10 years.
- Right to stop receiving marketing information: You can ask us to stop sending you information about our services, but please note we shall continue to contact you in relation to any matters relating to your account, if you have one.