We use cookies to make your experience better. To comply with the new e-Privacy directive, we need to ask for your consent to set the cookies. Learn more.
Data Protection & Privacy Policy
1. Introduction
Personal Homecare Pharmacy Ltd (“PHP”, “we”, “us”, “our”) is committed to protecting information through appropriate controls, being transparent about what data we hold and how we use it, and respecting your privacy. “You” (“your”) are our patient, client, or another individual to whom we provide services or with whom we are in contact about our services.
2. The law that applies to us
This policy is governed primarily by the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, enforced by the Information Commissioner’s Office (ICO). Where we process personal data of individuals resident in the European Economic Area, the EU GDPR may also apply. Terms such as “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Special Category Data” and “Processing” carry the meaning given to them in the UK GDPR.
3. Who we are
Personal Homecare Pharmacy Ltd is a company registered in England and Wales under company number 07158940. Our registered office is 11 High View Close, Hamilton Office Park, Leicester LE4 9LJ. Our trading address is 11 High View Close, Hamilton Office Park, Leicester LE4 9LJ. We operate from licensed pharmacy premises and are regulated by the General Pharmaceutical Council (GPhC). We are the Data Controller for the personal data described in this notice.
4. Personal data we collect
Depending on how you interact with us, the personal data we collect about you includes, but is not limited to:
Standard personal data
- Your full name.
- Your postal address and any delivery address you provide.
- Your email address and telephone numbers.
- Your date of birth (where used to confirm your identity).
- Customer account identifiers, order references and order history.
- Contact preferences and communication logs.
- Contact details of any next of kin or authorised recipient you nominate.
- Call data when you call us or we call you — caller line identity, date, time, duration and call content.
- Content of emails, postal correspondence and other communications between us.
- Information about medicines you are currently taking or will be taking, including name, dosage and dosing schedule (received from a third-party system, self-input or otherwise).
- Payment status, invoice references and transaction identifiers. Payments are processed by Opayo / Elavon, formerly Sage Pay, using a tokenised and PCI-DSS compliant payment process. PHP does not store your full card details.
- IP address and technical usage information when you use our website or patient portal (see Cookies section).
Additional data we process if you use the WhatsApp chatbot
- Your WhatsApp phone number.
- The content and metadata of your WhatsApp messages with us.
- Your recorded agreement to use the WhatsApp chatbot channel.
- Temporary one-time passcode verification data and related audit records, where this verification method is used.
- Your NHS number or registered patient number, where used to verify your identity.
- Session identifiers, authentication tokens and audit log entries created when you use the chatbot.
Special category data (health-related)
Because we provide pharmacy and homecare services, we also process information that the law treats as “special category” data because it concerns your health:
- Prescription and dispensing information received from NHS referring centres and held in our ordering platform.
- Medical needs and health notes required to dispense your medication safely.
- Diagnoses or other medical information that you disclose to us through the chatbot, on a call, or by other means.
- Adverse event, pharmacovigilance, product quality, technical issue and patient safety information you report to us, including the full conversation transcript where a chatbot conversation contains such information.
Source of your data
Your personal data may come from: (a) information you provide directly through our website, patient portal, WhatsApp chatbot, telephone, email or post; or (b) NHS Trust referring centres who refer you to PHP for homecare pharmacy services, under separate Information Sharing Agreements between the NHS and PHP.
5. Our lawful basis for processing your data
Under UK GDPR Article 6, we rely on the following lawful bases depending on the type of processing:
| Processing activity | Lawful basis |
|---|---|
| Delivering services directly to patients (orders, dispensing, fulfilment, customer service) | Article 6(1)(b) — Contract |
| Delivering services to patients referred from the NHS | Article 6(1)(c) — Legal obligation. The referring NHS organisation may rely on Article 6(1)(e) — Public task as a separate controller. |
| Adverse event, pharmacovigilance, product quality and patient safety handling | Article 6(1)(c) — Legal obligation |
| Authentication, fraud prevention, audit logging, security and operational assurance | Article 6(1)(f) — Legitimate interests |
| Sending proactive WhatsApp notifications about your orders | Article 6(1)(a) — Consent (you may withdraw at any time) |
Where we rely on legitimate interests, we only do this where the processing is necessary, proportionate, and does not override your rights and freedoms. This may include security monitoring, fraud prevention, audit logging, service protection, incident investigation and limited-service improvement activity.
Because we process health-related data, we also need to satisfy a condition under UK GDPR Article 9. We rely on the following:
| Processing activity | Special category condition |
|---|---|
| Core pharmacy services — dispensing, fulfilment, patient identification, care management | Article 9(2)(h) — Health or social care purposes |
| Adverse event, pharmacovigilance, product quality and patient safety handling | Article 9(2)(i) — Public health (quality and safety of medicinal products) |
Where we rely on Article 9(2)(h) or 9(2)(i), the processing is carried out by, or under the responsibility of, a registered health professional or another person who owes an equivalent duty of confidentiality. Our staff are trained, our systems use role-based access, and our processing is audited.
6. How we use your personal data
We use your personal data for purposes that include, but are not limited to:
- Responding to enquiries about our services.
- Verifying your identity when you use our services or contact us.
- Understanding and carrying out your instructions about the delivery of our services.
- Delivering your medication and the wider homecare pharmacy service.
- Maintaining appropriate pharmacovigilance. We may share limited information (such as your initials, date of birth and patient ID number) with pharmaceutical Marketing Authorisation Holders so that adverse events and medicine safety incidents can be monitored.
- Monitoring call traffic for service optimisation, training and problem-solving.
- Improving our services through internal analysis and patient surveys.
- Notifying you about changes to our services, terms or this privacy notice.
- Providing accurate billing and recovering money owed to us.
- Maintaining business records and meeting our obligations to HMRC.
- Preventing or detecting crime, fraud or misuse of our services.
- Meeting obligations under anti-money-laundering and other applicable legislation.
Further purposes where you use our additional services:
- Verifying your identity, using a combination of WhatsApp phone number matching and either (a) your NHS or registered patient number and date of birth, or (b) a one-time passcode (OTP) sent to the email address we hold on file.
- Providing self-service options including checking and amending eligible orders and delivery details, accessing approved Patient Information Leaflet content, submitting feedback, and reporting adverse events, product quality issues, technical issues or other patient safety concerns.
- Using AI-supported response generation (Google Gemini, managed through Botpress) to help interpret your messages and route your enquiry to the right service or information. See section 7 for the safeguards that apply.
- Sending you proactive notifications about your orders and deliveries through WhatsApp, where you have consented to receive them.
- To help us provide the best possible service, we partner with specialist digital providers for certain services and treatments to offer additional digital support and guidance to our patients.
7. The WhatsApp chatbot service
PHP offers an optional WhatsApp chatbot service for patients. You do not have to use it; you can continue to use the patient portal, telephone, SMS or email instead.
Before any protected information about you is accessed through the chatbot, you will be asked to verify your identity. The verification combines your WhatsApp phone number matching the number we hold for you with one of the following: (a) your NHS number or registered patient number and date of birth, or (b) a one-time passcode (OTP) sent to the email address we hold on file.
AI safeguards. The chatbot uses AI-supported response generation through Google Gemini, managed through Botpress. The AI element is used only to support patient interaction and to route you to relevant information or service actions. The chatbot does not have direct access to your health record or personal information that we may have. The AI element only interprets any free text (any text that the user of the system enters directly themselves). It is not used to make clinical decisions, does not provide medical advice beyond approved Patient Information Leaflet content, and does not replace review by trained PHP staff where escalation is required. Where you report a safety-related issue, the chatbot will flag the conversation for human review by qualified PHP staff. Your messages and patient data are not used to train or fine-tune AI models.
8. Automated decision-making
PHP does not make significant decisions about you based solely on automated processing. The WhatsApp chatbot may use AI-supported processing to help understand your message, route your enquiry, and provide information from approved sources, such as Patient Information Leaflets. It does not make clinical decisions, does not replace trained PHP staff, and does not make decisions that have a legal or similarly significant effect on you.
Where a safety concern, adverse event, product quality issue or urgent matter is raised, the chatbot flags the information for review by PHP staff. Decisions about your care, medication, delivery, service issue or safety concern are handled by trained staff where human review is required.
9. Who we share your data with
We share your personal data only where necessary to deliver our service, meet a legal obligation, or protect our legitimate interests. The following processors and third parties may receive your data:
Processors acting on our instructions under a Data Processing Agreement or equivalent contractual terms may include:
- Botpress Inc. (Canada) — operates the WhatsApp chatbot platform and processes chatbot messages, session data and workflow information.
- Google AI / Google Gemini (United States) — provides AI inference to support chatbot response generation.
- Meta Platforms / WhatsApp Business API (United States) — provides the WhatsApp messaging channel and processes message delivery data.
- GBG / Loqate (United Kingdom) — provides postcode and address validation.
- Opayo / Elavon, formerly Sage Pay (United Kingdom or other contracted processing location) — provides tokenised payment processing.
- Liquid Web or other approved hosting provider — provides hosting infrastructure for our ordering platform.
- ZenZero — provides managed IT services, including email and SMS support on our behalf.
- Magebit — provides support for our Magento ordering platform.
- Couriers and delivery sub-contractors — deliver medication and prescriptions.
- Clinical nursing sub-contractors — provide nursing services where these are commissioned alongside your medication.
Independent controllers and other recipients:
- NHS Trust commissioners and referring centres — act as independent controllers for their own purposes; our sharing with them is governed by Information Sharing Agreements.
- Pharmaceutical Marketing Authorisation Holders — receive limited adverse event information for pharmacovigilance purposes.
- Law enforcement agencies, regulators (including the ICO, MHRA, GPhC and CQC), and courts — where we are required to share data by law.
- Any successor to our business — as part of any sale or transfer of our business.
Where suppliers act as processors for PHP, we put appropriate contracts or Data Processing Agreements in place. These include requirements for security, confidentiality, breach reporting, sub-processor controls, and return or deletion of data at the end of the service.
10. International data transfers
Our core patient database, ordering platform and dispensing records remain hosted on UK infrastructure. However, where you use the WhatsApp chatbot, some of your personal data may be transferred outside the United Kingdom:
- Botpress Inc. (Canada) — covered by UK adequacy regulations under UK GDPR.
- Google AI / Google Gemini (United States) — covered by the UK Extension to the EU-US Data Privacy Framework where Google is certified for the relevant data; otherwise by the UK International Data Transfer Agreement, or by the UK Addendum to the EU Standard Contractual Clauses supported by a transfer risk assessment.
- Meta Platforms / WhatsApp Business API (United States) — covered by the same US transfer mechanisms as above.
We use appropriate safeguards for restricted transfers and keep evidence of the transfer mechanism used. This may include supplier contracts, Data Processing Agreements, sub-processor information, certification evidence, UK International Data Transfer Agreements, UK Addendums to EU Standard Contractual Clauses, and transfer risk assessments where required. The data transferred outside the UK is limited to the minimum needed to operate the chatbot service safely. You can ask us for a copy of the safeguards we have in place by contacting our DPO (see section 16).
We limit the data transferred outside the UK to what is needed for the chatbot service, message delivery, authentication, response generation, safety reporting or support activity. The full Magento patient record remains within PHP’s UK-controlled environment unless a specific transfer is necessary, documented and covered by an appropriate safeguard.
11. How long we keep your data
We keep personal data only for as long as we need it for the purposes for which we collected it, or as required by law, regulation, professional standards or our contractual commitments. Indicative retention periods are:
- Patient records and prescription records — retained in line with NHS, GPhC and applicable pharmacy record-keeping requirements.
- Adverse event and pharmacovigilance source records — retained for the lifetime of the medicinal product plus 10 years, in line with the European Medicines Agency Good Pharmacovigilance Practice (GVP) modules and corresponding UK requirements.
- WhatsApp chatbot conversation records containing adverse event, product quality, technical issue or patient safety information — retained in a PHP-controlled system for the required retention period.
- Other WhatsApp chatbot conversation records — retained for an operational period and then deleted, in line with our retention schedule.
- Audit logs and authentication records — retained in line with our Quality Management System retention schedule.
- Marketing preferences and consent records — retained for the duration of your relationship with us and for evidence purposes thereafter.
The exact retention period depends on the type of record, the purpose for which it is held, and any pharmacy, NHS, tax, contractual, complaint, incident, audit, legal or regulatory requirement that applies. PHP maintains its detailed retention schedule within its Quality Management System.
When the retention period ends, data is securely deleted or anonymised. Paper documents which we no longer need are destroyed by an ISO 27001 and NAID-accredited data destruction supplier.
12. Your rights
Under the UK GDPR you have the following rights in relation to your personal data:
- Right to be informed — through this privacy notice.
- Right of access — to a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure — to have your data deleted, subject to legal, regulatory or pharmacy retention requirements that may prevent us from deleting some information.
- Right to restriction of processing — to limit how we process your data while we consider a query about its accuracy or our lawful basis.
- Right to data portability — to receive a copy of certain personal data you have provided to us in a structured, commonly used, machine-readable format, and to ask us to transfer it to another controller where technically feasible.
- Right to object — to processing based on legitimate interests, and to direct marketing at any time.
- Right not to be subject to solely automated decision-making — including profiling that produces legal or similarly significant effects on you (UK GDPR Article 22).
- Right to withdraw consent — at any time, where consent is the lawful basis for processing (for example, proactive WhatsApp notifications).
- Right to complain — to PHP and to the ICO if you believe we have not handled your data correctly (see section 17).
Where we rely on legitimate interests, you have the right to object to the processing of your personal data. This may apply to certain security, fraud prevention, audit, service improvement or operational assurance activities. If you object, we will consider your request and explain whether we can stop the processing or whether we need to continue it for a lawful reason.
We will respond to rights requests within one calendar month of receipt. For complex or numerous requests, this period may be extended by up to two further months; if we need to extend, we will explain the reason within the initial one-month period. We may ask you to provide proof of identity before we release information.
Where your request relates to data held across PHP systems and supplier systems, we will coordinate the request with the relevant supplier where this is required under our contract or Data Processing Agreement. We may need to keep some information where this is required for pharmacy, legal, regulatory, adverse event, pharmacovigilance, complaint, audit or patient safety reasons.
13. Your consent choices for WhatsApp
If you use WhatsApp with PHP, there are two separate consent points you should be aware of:
(1) Using the WhatsApp chatbot. Interacting with PHP through WhatsApp is your choice. Before any protected patient information is shared, you will see a privacy summary and be asked to complete identity verification. Your agreement to continue is recorded. You can stop using the chatbot at any time and contact PHP through other channels.
(2) Proactive WhatsApp notifications. These are messages we send to you about order and delivery updates. We will only send these if you have given clear consent to receive them. You can withdraw consent at any time by contacting us. If you choose not to receive WhatsApp notifications, you will still receive the service through other approved channels such as the Patient App, SMS or email, depending on your preferences.
These two consent points are separate from the lawful basis we rely on to deliver core pharmacy services to you (see section 5).
14. Security and storage of your data
We use appropriate technical and organisational measures to keep personal data secure and to prevent it from being accidentally lost, accessed or used in an unauthorised way, altered or disclosed. These measures include role-based access controls, encryption, audit logging, supplier due diligence, staff training, and incident response procedures.
We may monitor and record telephone conversations for training and quality purposes, to confirm verbal instructions, to investigate complaints, and to meet our legal and regulatory obligations. Recordings are encrypted and securely stored, with access controlled and monitored.
If we identify a personal data breach that affects information we hold about you, we will take urgent action in line with the UK GDPR and ICO guidance. No internet-based service can be guaranteed 100% secure; if you become aware of any unauthorised access affecting data we have shared with you, please contact us as soon as possible using the details in section 16.
15. Cookies
Our website uses cookies and similar technologies. Cookies are small files stored on your device by your web browser. Some cookies are strictly necessary for the website or patient portal to work properly. For example, our patient portal uses a security cookie that contains a session security token only and lasts for the duration of your browsing session.
We may also use analytics and tracking cookies, including services provided by Google and Microsoft/Bing, to understand how visitors use our website, count visitors, improve pages and measure the effectiveness of our online content. These cookies may collect information such as your device type, browser, IP address, pages visited, visit time and visit duration.
Non-essential cookies are only used where you have given consent through our cookie banner. You can refuse non-essential cookies or change your preferences at any time using the cookie settings on our website.
16. Contact us
If you have any questions about this notice, want to update your preferences, or exercise any of your rights, please contact us:
- Data Protection Officer: dpo@homecare-pharmacy.co.uk
- General enquiries: info@homecare-pharmacy.co.uk
- Telephone: 01827 438 775
- Post: Personal Homecare Pharmacy Ltd, 11 High View Close, Hamilton Office Park, Leicester LE4 9LJ
17. Complaints
If you are unhappy with how we have handled your personal data, please contact us first using the details in section 16 so that we can investigate your concern. You can make a data protection complaint by email, post or telephone.
We will acknowledge your complaint within 3 days of receiving it. We will provide a response to your complaint within 30 days of receiving it. We will review the complaint, make appropriate enquiries, and keep you informed where needed.
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO): https://www.ico.org.uk/concerns or telephone 0303 123 1113. We are registered with the ICO under Register Entry Z2749263.
18. Changes to this notice
We review this notice regularly and may update it from time to time. Where changes are material, we will let you know by email or another appropriate route. The version date below shows when this notice was last updated.
Version: 2 — Date: 19 June 2026