Privacy Policy - Charac (2024)

Table of Contents
CHARAC – PRIVACY POLICY (last updated 12.4.2024) 1. Information about who we are 2. What information does Charac collect about me? 3. If you fail to provide personal information 4. Third party links 5. Information you provide to us 6. Information we receive from others 7. Online Account, Charac App and Platform: 8. Payment information: 9. Payment information: Charac Ltd The pharmacy The NHS 10. Why does Charac process my personal information and what is Charac’s legal basis for doing so? 11. Automated Decision Making 12. Who does Charac share your information with and why? Our service providers 13. Sharing personal information with your chosen pharmacy In corporate transactions When required by law To enforce legal rights 14. Marketing 15. How does Charac send information outside of my country? 16. What are my privacy rights? The right to be informed. Right of access. The right to rectification. The right to erasure. The right to restrict data. The right to data portability. The right to object. The right not to be subject to automated decision making and profiling. When you request to exercise your rights 17. How does Charac protect my personal information? 18. Cookies. What cookies and similar technologies does Charac use? 19. How long does Charac retain my personal information? 20. Can this Privacy Notice change? 21. How can Charac help you further? 22. Annex 1 – Privacy Notice example where the pharmacy acts as a controller of your personal information. How pharmacies use the personal information in connection with your use of Charac Patient’s Privacy Notice Welcome What information does your pharmacy collect about you? How does your pharmacy obtain your personal data? Why does your pharmacy process your personal data for and what are the legal bases on which they rely? How does your pharmacy keep your personal data safe? Who is your personal data disclosed to? What are your rights? How long will your pharmacy retain your personal data? Who do I contact to ask questions about this Privacy Notice? Can this Privacy Notice be updated?

CHARAC – PRIVACY POLICY (last updated 12.4.2024)

Welcome to Charac Limited.

Charac Limited values your privacy and is strongly committed to protecting your personal information.

Charac Limited’s app (the “Charac App”) and platform (“our Platform”) enables pharmacies to digitise their current processes by providing repeat prescriptions and consultations to customers via phone, video, desktop, or mobile.

The purpose of this Privacy Notice is to explain how Charac Limited handles personal information about you and to outline the rights that you have under applicable data protection legislation. We respect your privacy and want to be transparent about how your personal information will be processed, stored and used when you visit our website, use our online services, the Charac App or our Platform or otherwise engage with us as a customer, a pharmacy professional, a patient, a supplier, a retailer or have any other commercial contract with us.

Please read the following carefully to understand our practices regarding your personal information and how we will treat it. This Privacy Notice, together with our terms and conditions, as set out at https://charac.co.uk/terms-and-conditions and any additional terms of use, applies to your use of any of the services which are accessible through the website, the Charac App, our Platform or any other website of ours.

It is important that the personal information that we hold about you is accurate and current. Please keep us informed if your personal information changes during our relationship with you.

Compliance with Data Protection Legislation

All personal information that we collect or are provided with will only be held and stored in accordance with this Privacy Notice and the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and any other legislation relating to the protection of personal information (data protection laws).

This notice covers the following areas:

  1. Information about who we are
  2. What information does Charac collect about me?
  3. If you fail to provide personal information
  4. Third party links
  5. Information you provide to us
  6. Information we receive from others
  7. Online Account, the Charac App and our Platform
  8. Payment information
  9. How does Charac work? Who is responsible for my personal information?
  10. Why does Charac process my personal information and what is Charac’s legal basis for doing so?
  11. Automated decision making
  12. Who does Charac share your information with and why?
  13. Sharing personal information with your chosen pharmacy
  14. Marketing
  15. How does Charac send information outside of my country?
  16. What are my privacy rights?
  17. How does Charac protect my personal information?
  18. Cookies
  19. How long does Charac retain my personal information?
  20. Can this Privacy Notice change?
  21. How can Charac help you further?
  22. Annex 1 – example of a pharmacy’s privacy policy.

1. Information about who we are

We are Charac Limited (“we”, “us” or “our”) and are also known as Charac.
We are registered with the Information Commissioner’s Office (“ICO”) under reference: ZA774372
Charac will be the controller of your personal data unless otherwise stated.

You may contact us at:
Email address: dataprotectiondesk@charac.co.uk
Postal address: March Studios, Peills Yard, Bromley, Kent BR2 9NS

2. What information does Charac collect about me?

Personal information or personal data means any information about an individual from which that person can be identified and is generally referred to throughout this Privacy Notice as “personal information”. It does not include data where the identity has been removed (anonymous data).

Personal information we may collect, use, store and transfer about you, are as follows:

  • Identity data, which includes your name, age/date of birth and gender, for pharmacy professionals and pharmacy administrators. We also collect your job title, professional qualifications, work experience, organisational or institutional affiliations, or publications;
  • Contact data, which includes postal address including billing and delivery addresses, your location, telephone numbers (including mobile numbers) and email address;
  • Special category data, also known as sensitive personal data, which includes information about your physical or mental health, health conditions, and other clinical metrics including environmental, socio-economic, and behavioural information pertinent to health and wellness;
  • Transaction data, which includes purchases and/or orders which are made by you and your payment card or bank transfer details;
  • Technical data, which includes your online browsing activities on our website, the Charac App and our Platform, profile and device information including IP address, browser type, version and language, identifiers associated with cookies or other technologies that may uniquely identify your device or browser;
  • Profile Data, which includes your account login details for website and/or our online account, including your username and password(s), your interests, preferences, feedback and survey responses;
  • Marketing and communications data, which includes your marketing preferences from us and our third parties, your communication preferences and your correspondence to and communications with us; and
  • other publicly available personal information, including any which you have shared via a public platform (such as a Twitter feed or public Facebook page ).

This list is not exhaustive and, in specific instances, we may need to collect additional data for the purposes set out in this Privacy Notice. Some of the above personal information is collected directly, for example when you set up an online account on our website or send an email to us or contact us via social media.

All your personal information will be processed in accordance with this Privacy Notice, and in compliance with all applicable confidentiality guidelines.

In some circ*mstances, we may anonymise your personal information (so that it can no longer be associated with you). This can be for research or statistical purposes; in which case we may use the anonymised information indefinitely without further notice to you. Anonymised information may also be used to develop insights and statistics as to the use of our services, and to identify trends within the pharmacy sector more broadly.

3. If you fail to provide personal information

Where we need to collect personal information by law, legitimate interest or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with the requested services). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.

4. Third party links

The Charac App and our Platform may include links to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third party websites and are not responsible for their privacy statements or policies.

When you leave the Charac App or our Platform, we encourage you to read the privacy policy or privacy notice of every website you visit.

5. Information you provide to us

Some information, including some of your personal information, is required when signing up for and using our services, our website, the Charac App and/or our Platform.

We collect personal information from you to manage and facilitate those services. When you provide us with your personal data, it is for the following reasons:

  • Account and contact details: When you create an account, you provide us with at least your login credentials, as well as some basic details necessary for the service to work and to set up your profile. These include your full name, email address, phone number, date of birth, gender, marketing preferences and profile picture.
  • Special category personal information: Some of the information you provide whilst using the Charac App and/or our Platform may be considered “special” or “sensitive” in certain jurisdictions. When you interact with your pharmacy on the Charac App or our Platform, for example when booking consultations and/or ordering prescriptions; or when notes are added to your account, the information provided may infer or identify information relating to your health.
  • Video consultations: if you book a video consultation through the Charac App or our Platform, our processing will be limited to facilitating the video interaction. We will not retain or record the video content of consultation, although both our users and pharmacy professionals will be able to add notes to the account, which will be retained.
  • Billing or bank details: When you make a payment, you provide us or our payment service provider with certain information which is necessary to process your payment, including your debit or credit card number, card holder name, card expiry, CVV and billing address. This information is held by our payment partner, Stripe. Please see Stripe’s privacy policy here: https://stripe.com/gb/privacy.
  • Customer service: You can contact our customer services team via the Charac App, our Platform, email or via the Chatbot. We collect the information that you give to us during the interaction. Sometimes, we monitor or record these interactions for training purposes and to ensure a high quality of service.

6. Information we receive from others

In addition to the information you provide us directly, we may receive information and personal information about you from others, including:

  • Pharmacy staff: Pharmacy staff may provide information about you as they use our services. For instance, the Charac App or our Platform may be used when you make an appointment, or order in store. Pharmacy staff are also able to add notes against your account, and individual consultations which may include personal information (and sensitive health information) about you. Pharmacy staff may also share your information with us in order to invite you to the Charac App or our Platform.
  • Other Partners: We may receive info about you from our partners. For instance, in relation to advertising, we may receive personal information and information where Charac ads are published on a partner’s websites and/or platforms (in which case, they may pass along details on a campaign’s success).

Any data which is obtained from third parties will be kept in accordance with this Privacy Notice, and with any additional restrictions imposed by the third party that shared your personal information with us.

7. Online Account, Charac App and Platform:

Our website, the Charac App and our Platform have been designed to improve the online accessibility of independent pharmacies and their services. Charac enables independent pharmacies and their customers and patients to make their appointments, video consultations, manage prescriptions and other advice/services available to you from the comfort of your own home.

When you sign up to use our online services, the Charac App or our Platform, we require some of your personal information, including your name and contact details.

You are able to access your account and update your personal information within the Charac App or our Platform.

Where you have logged on via your NHS login, you can access and update your medical and/or NHS records by contacting the pharmacy directly.

We may collect additional information, for example, when you provide feedback, when you provide information about your personal circ*mstances, change email preference, respond to surveys and/or promotions, provide financial or credit card information, or communicate with us, the pharmacies, the patients or other support functions including customer services.

We also collect information from and about the device(s) used to access the Charac App or our Platform, including:

  • hardware and software information, such as IP address, device ID and type, device-specific and apps settings and characteristics, app crashes, advertising IDs (such as Google’s AAID and Apple’s IDFA, both of which are randomly generated numbers that you can reset by going into your device’s settings), browser type, version and language, operating system, time zones, identifiers associated with cookies or other technologies that may uniquely identify your device or browser (e.g., IMEI/UDID and MAC address);
  • information on your wireless and mobile network connection, like your service provider and signal strength; and
  • information on device sensors, such as accelerometers, gyroscopes and compasses.

We collect information about your activity on our website, the Charac App and our Platform, for instance how you use and interact with our website/application (e.g., date and time you logged in, features you have been using, searches, clicks and pages which have been shown to you, referring webpage address, advertising that you click on) and how you interact with pharmacy staff (e.g. interactions, time and date of your exchanges, number of messages you send and receive).

If you give us your consent, we can collect your precise geolocation (latitude and longitude) through various means, depending on the service and device you are using, including GPS, Bluetooth or Wi-Fi connections. The collection of your geolocation may occur in the background even when you are not using the services if the permission you gave us expressly permits such collection. If you decline permission for us to collect your geolocation, we will not collect it.

8. Payment information:

We may process your personal information to process any payments made for the provision of services. The information may include information for identification and verification, such as your name, credit, debit or other card number, card expiration date, and CVV code.

Any payment transactions carried out by us, or our chosen third party provider of payment processing services will be kept secure and encrypted where possible. Our payment partner is Stripe. Please see Stripe’s privacy policy here: https://stripe.com/gb/privacy.

9. Payment information:

How does Charac work? Who is responsible for my personal information?

Charac Ltd

We are the operator of the Charac App and our Platform, which has been designed to improve the digitisation of processes and services within community pharmacies. What this means for our users is that if your local or online pharmacy has signed up to Charac, then you will be able to book and manage instore and online appointments, consultations, manage prescriptions and repeat prescriptions with your local or online pharmacy, as well as providing information ahead of your visit, to improve your in store experience. If you or your pharmacy uses Charac to facilitate or coordinate your access to medicinal products or pharmaceutical services, then we will be the party responsible for the processing of your personal information within the Charac environment (the data controller).

The pharmacy

When your pharmacy signs up to use the services of Charac, it will be able to coordinate, manage and deliver certain medicinal products and pharmaceutical services that it will provide to you through the Charac App or our Platform.

The pharmacist and their administrative users will be able to access the Charac App and our Platform, as necessary to coordinate and deliver the pharmacy’s products and services. The pharmacy will be able to manage appointments, prescriptions and be able to add care notes to the account.

The pharmacy will be independently responsible (as a separate and independentdata controller) for the use of the Charac App and our Platform, and the pharmacy professionals’ use and collection of your personal data in connection with the delivery of the pharmacy’s services and supply of medicinal products.

For additional information about how the pharmacy processes the personal information that you provide through the Charac App and our Platform, please see the Patient’s Privacy Notice which is appended at the end of this Privacy Notice or see your pharmacy’s privacy notice or privacy policy.

The NHS

The Charac App and our Platform is an NHS integrated app.

When you access the Charac App or our Platform using your NHS login details, the identity verification services are managed by NHS England.

NHS England is the controller for any personal information that you provide to NHS England to get an NHS login account and to verify your identity and uses that personal information solely for that single purpose.

For this personal information, our role is a “processor” only and we must act under the instructions provided by NHS England (as the “controller”) when verifying your identity. To see NHS England’s Privacy Notice and Terms and Conditions follow this link https://www.nhs.uk/our-policies. This restriction does not apply to the personal information you provide to us separately.

10. Why does Charac process my personal information and what is Charac’s legal basis for doing so?

We will only use your personal information if we have a proper reason to process it and the law allows us to do so.

When collecting your personal information, we will always make it clear to you which information is necessary in connection with the particular activity.

Most commonly, we will use your personal information in the following circ*mstances:

  • Where you have consented before the processing.
  • Where we need to perform a contract, we are about to enter or have entered with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where it is necessary to protect your vital interests where you are physically or legally incapable of giving consent, for example in an emergency if you are incapacitated.
  • For reasons of substantial public interest or the management of health or social care systems and services.
  • Where we need to comply with a legal or regulatory obligation.

Whenever you have given us your consent to use your personal information, you have the right to change your mind at any time and withdraw that consent. However, this will not affect the lawfulness of any processing which is carried out before you withdraw your consent. Also, if we are not relying on consent as the lawful basis for processing your personal information, then we may still continue to process it.

The table below sets out all the ways in which we plan to use your personal information, which are the legal bases on which we rely to do so and, where relevant, what the legitimate business interests are. (There may be more than one lawful basis depending on the specific purpose for which we are using your data.)

To provide our services:
The personal information we collectWhy we use this personal informationThe lawful basis relied upon:
• Account and contact details;• NHS details;
• Information relating to your health (to the extent such information is provided by you, or your pharmacy professional);
• Billing details;
Customer service information;
Name;
Email;
Address; and
Phone number
• Making our website, the Charac App and our Platform available to you;
• Creating and managing your account;
• Sharing your information with your chosen pharmacy;
• Tailoring our services and advice to you;
• Customer support;
• Communicating with you about our services, including order management and billing;
• Delivery services; and
• NHS login
We rely on to process your personal information is article 6(1)(b) and (f) of the UK GDPR, which allows us to process personal information when this is necessary for the performance of a contract with you and where the processing is necessary for the purposes of a legitimate interest pursued by us.Where the information contains health information the lawful basis, we rely on to process it is article 9(2)(h) or (i) of the UK GDPR, which is for the purposes of preventative or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services or pursuant to contract with a health professionals.Where we process information for the NHS the lawful basis we rely on article 6(1)(e) of the UK GDPR, which allows us to process personal information when this is necessary to perform public tasks. Where the information contains health information the lawful basis we rely on to process it is article 9(2)(g) of the UK GDPR, which also relates to public tasks.
To manage our relationship with you
Account and contact details; andCustomer service information• Notifying you of changes in our terms and conditions or privacy notice; and
• Asking you to leave a review or take part in a survey
We rely on to process your personal information is article 6(1)(b) and (f) of the UK GDPR, which allows us to process personal information when this is necessary for the performance of a contract with you and where the processing is necessary for the purposes of a legitimate interest pursued by us.Where the information contains health information the lawful basis, we rely on to process it is article 9(2)(h) or (i) of the UK GDPR, which is for the purposes of preventative or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services or pursuant to contract with a health professionals.

11. Automated Decision Making

We may use automated decision making and profiling to provide some services and to tailor the information we provide to you to your specific circ*mstances.

In order to comply with our legal obligations and industry best practice, we use our user’s date of birth to determine their eligibility for features and content on the Charac App or our Platform. If you would like further information about this assessment, including asking for a person to review a decision, please contact us atdataprotectiondesk@charac.co.uk. Please note you also have a right to object to profiling, and solely automated decision making as detailed below.

12. Who does Charac share your information with and why?

We sometimes share your personal information with trusted third parties.

The reasons we may share your information with third parties are:

  • to provide you with our services;
  • if we are under a legal or regulatory duty to do so;
  • if it is necessary to do so to enforce our terms of use or other contractual rights;
  • to lawfully assist the police or security services with the prevention and detection of crime or terrorist activity;
  • where such disclosure is necessary to protect the safety or security of any persons; and/or
  • otherwise as permitted under applicable law.

We may share your personal information to help us provide our services, including via the Charac App, our Platform and our website. We have contracts with companies which provide us with services such as IT support, data storage, payment processing, delivery services and email automation services.

Our service providers

We use third parties to help us operate and improve our services. These third parties assist us with various tasks, including personal information hosting and maintenance, analytics, customer care, marketing, advertising, payment processing, delivery and security operations.

We also use these service providers:

Royal Mail: If you opt in for delivery services with Royal Mail through the Charac App or our Platform, we will then pass your name, email, address and phone number to Royal Mail so that Royal Mail can create an account in its system on your behalf further information can be found here https://www.royalmail.com/privacy-notice.

Stripe: If you opt in for any services requiring payment through the Charac platform the payments may be taken by our payments partner Stripe. We will pass your name, email, address and phone number on to Stripe for the purposes of taking the payment. Stripe will collect further information from you such as account or card details. Please see Stripe’s Privacy Notice here https://stripe.com/gb/legal/privacy-center.

Ryft Pay: If you opt in for any services requiring payment through the Charac platform the payments may be taken by our payments partner Ryft Pay. We will pass your name, email, address and phone number on to Ryft Pay for the purposes of taking the payment. Ryft Pay will collect further information from you such as account or card details. Please see the Ryft Pay Privacy Notice here https://ryftpay.com/privacy-policy.

WorldPay: If you opt in for any services requiring payment through the Charac platform the payments may be taken by our payments partner Ryft Pay. We will pass your name, email, address and phone number on to WorldPay for the purposes of taking the payment. WorldPay will collect further information from you such as account or card details. Please see the WorldPay Privacy Notice here https://www.worldpay.com/en-gb/privacy.

Zoho: We use Zoho for our helpdesk, Chat and other tools to assist you with any issues you may have when using Charac or to contact you for platform notifications or email campaigns. Information stored in Zoho Desk is provided by you when opening and responding on any tickets within the Zoho System. Other information will be collected through your usage of the Charac platform. Please see Zoho’s privacy policy here https://www.zoho.com/en-uk/privacy.html.

GMail: We use Google Gmail as our email system, any emails you send to Charac will be processed and stored by Google. Please see Google Gmail’s privacy policy here: https://policies.google.com/privacy?hl=en-GB.

MOXO: We use MOXO for secure communications with your nominated Pharmacy. Your details may be sent by your pharmacy to Charac and vice versa to provide you with better service or to assist in correcting any issues that may arise from you use of the Charac Platform. Please see MOXO’s privacy policy here: https://www.moxo.com/legal/privacy-policy.

13. Sharing personal information with your chosen pharmacy

We share your personal information with the pharmacy chosen by you.

We provide a platform through which you are able to access medicinal products and pharmaceutical services which are provided to you by local and online pharmacies which have signed up to our services.

When you use the Charac App or our Platform, you will be asked to nominate a preferred pharmacy. The selections you make in relation to their services, will be shared with the pharmacy as necessary for their coordination, management, and delivery of such pharmaceutical services and medicinal products requested by you.

Please see the privacy notice available through your pharmacy’s website for additional information.

In corporate transactions

We may transfer your personal information if we are involved, whether in whole or in part, in a merger, sale, acquisition, divestiture, restructuring, reorganisation, dissolution, bankruptcy or other change of ownership or control.

When required by law

We may disclose your personal data if reasonably necessary:

(i) to comply with a legal process, such as a court order, subpoena or search warrant, government / law enforcement investigation or other legal requirements;
(ii) to assist in the prevention or detection of crime (subject in each case to applicable law); or
(iii) to protect the safety of any person.

To enforce legal rights

We may also share information:

(i) if disclosure would mitigate our liability in an actual or threatened lawsuit;
(ii) as necessary to protect our legal rights and legal rights of our users, business partners or other interested parties;
(iii) to enforce our agreements with you; and
(iv) to investigate, prevent, or take other action regarding illegal activity, suspected fraud or other wrongdoing.

14. Marketing

We strive to provide you with choices regarding certain personal information uses, particularly around marketing and advertising.

If you have given your consent to receive marketing emails, you can withdraw this at any time, or if we are relying on our legitimate interests to send you marketing, you can object.

If you have received a direct marketing email from us and no longer wish to receive these marketing emails, the easiest way to let us know is to click on the unsubscribe link at the bottom of our marketing emails. We provide opt out or unsubscribe links at the bottom of these emails to allow you to opt out at any time.

15. How does Charac send information outside of my country?

Your personal information will be stored on systems with technical and organisational security measures and controls located within the UK. For example, all personal information which is processed as part of the services is held securely by our information hosting provider AWS on servers in the UK.

Sometimes, we will need to share your personal information with third parties and suppliers outside the UK, such as Europe and the USA.

In the event we need to transfer your personal information outside the UK, for instance to our third party service providers, we will ensure we have in place adequate safeguards to do so. Our safeguards ensure that your personal information receives the same protection as if it were being processed inside the UK. For example, our contracts with third parties stipulate the standards they must follow at all times.

Any transfer of your personal information will follow applicable laws and we will follow the guiding principles of this Privacy Notice.

16. What are my privacy rights?

You are also able to exercise your rights over the personal information which we process which include:

The right to be informed.

We aim to be transparent within our Privacy Notice and provide you with information about how we use your personal information.

Right of access.

You have the right to request a copy of any information that we hold about you. We try to be as open as possible as we can be in terms of giving people access to their personal data.

You can find out if we hold any personal information by making a subject access request.

The right to rectification.

You have the right to request the correction of your personal data when it is incorrect, out of date or incomplete. You can contact us, and we can amend inaccurate personal data, however, please note that in some circ*mstances we may ask for documentary proof that the amendment is necessary.

The right to erasure.

You can request the erasure of your personal data when it is no longer necessary, you withdraw consent, or you object to its processing. Some information held by us is required by law to be held for a period of time. You can contact us if you wish to make a request.

The right to restrict data.

You can request that we restrict the processing of your personal data. This can be done in circ*mstances where we need to verify the accuracy of personal data, if you do not wish to have personal data erased or you object to the processing and we are considering this request.

The right to data portability.

Under some circ*mstances, you can request a copy of the personal data you provided to us in a machine-readable format or ask that this data be transferred to another third party.

The right to object.

In some circ*mstances, you can stop the processing of your personal data for reasons connected to your individual situation. We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data. Where your details are used for marketing, you can opt out at any time.

The right not to be subject to automated decision making and profiling.

You have the right to not be subject to solely automatic decisions (i.e. decisions that are made about you by computer without any human input) in relation to your treatments, care or other processes that have a legal or similarly significant effect on you.

Please see the section on Automated decision making for details about when we may make automated decisions.

When you request to exercise your rights

You will not have to pay a fee to exercise any of the rights listed above. However, we may charge a reasonable fee if your request is clearly unfounded or excessive, including where requests are repetitive. Alternatively, we could refuse to comply with your request in these circ*mstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information or to exercise any of your other rights. This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

17. How does Charac protect my personal information?

We have implemented, and will maintain current, reasonable physical, technical, and organisational security measures to protect your personal information from loss, misuse, and unauthorised access, disclosure, alteration, or destruction.

We use encryption to add an extra layer of protection to your data while it is stored on the Charac App or our Platform and for personal information which is transmitted by the Charac App or our Platform.

Where we have given you (or where you have chosen) a password which enables you to access certain parts of our service, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we have security measures in place to protect your personal information, we cannot guarantee the security of your data transmitted to our sites; any transmission is at your own risk.

18. Cookies. What cookies and similar technologies does Charac use?

We use and may allow others to use cookies and similar technologies (e.g. web beacons, pixels) to recognize you and/or your device(s).

Some of these cookies are essential to our service, for example they ensure that the Charac App or our Platform loads properly, they remember your cookie preferences, enable you to use payment functionalities, and enable Charac administrative users to login to the Charac App and our Platform. Others are of an analytical nature allowing us to better understand how you use our website, the Charac App and our Platform.

You can find more information about the individual cookies we use, the purposes for which we use them, and how you can better control their use in our Cookie Notice.

You can also set your browser to accept or reject all specific cookies. You can set your browser to alert you each time a cookie is presented to your device or opt out of Google Analytics by installing Google’s opt-out browser add-on. You can delete cookies that have been stored on your device, but if you prevent us from placing cookies on your device, or if you subsequently delete a cookie, it may not be possible for you to use our website, the Charac App and our Platform effectively. Please see our Cookie Notice for additional information https://charac.co.uk/cookie-policy.

19. How long does Charac retain my personal information?

Your personal information will be stored in accordance with applicable laws and kept for as long as needed to carry out the purposes described in this policy or as otherwise required by applicable law or NHS mandate.

20. Can this Privacy Notice change?

This Privacy Notice may be amended from time to time. We will post any changes we may make on this page and, where appropriate, notify you via email.

21. How can Charac help you further?

If you have any questions or comments, please contact us atdataprotectiondesk@charac.co.uk.

For further information on data protection, please visit the Information Commissioner’s Office (ICO) website.

The Information Commissioner’s Office regulates data protection. If you feel that your information has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal information, you have the right to lodge a complaint with the Information Commissioner’s Office.

You can contact them by calling 0303 123 1113 or visit the website.

22. Annex 1 – Privacy Notice example where the pharmacy acts as a controller of your personal information.

How pharmacies use the personal information in connection with your use of Charac

The following information provides information about how we expect pharmacies to use the information and personal information which is provided and associated with your use of the Charac App and our Platform.

The pharmacies are independently responsible for their compliance with their obligation under data protection laws and for providing any additional information associated with their use of your personal data.

Please contact your chosen pharmacy if you have any questions, queries or rights you wish to exercise in respect of their use of your information and personal data.

Patient’s Privacy Notice

Welcome

This Privacy Notice (“Notice”) has been prepared by Charac Limited for the benefit of its customers, such as pharmacies, and in connection with the pharmaceutical services and medicinal products which are provided to you by the pharmacies through the Charac App and our Platform.

The purpose of this Notice is to explain how pharmacies that are using the Charac App and our Platform, engage with Charac Limited and typically handle personal information about you and to outline the rights that you have under the applicable data protection laws.

Note that “you” and “your” include any users or patients that may be registered to the Charac App or our Platform.

Your pharmacy may be referred to in this Privacy Notice as “they” or “them”.

Your pharmacy will be the controller of your personal information in connection with the pharmaceutical services and medicinal products which are provided to you by the pharmacies through the Charac App and our Platform.

Please note that you can access the medicinal products and pharmaceutical services which are provided to you by your pharmacy via online (including booking appointments and video consultation, among others) through the Charac App and / or our Platform. You can consult the Charac Limited privacy notice at https://charac.co.uk/privacy-policy.

What information does your pharmacy collect about you?

Your pharmacy may collect and process your personal data in accordance with applicable laws to pursue its business activities. Your pharmacy may collect and process information about you including:

  • Contact detailssuch as your name, address, telephone number and email address, gender.
  • Health datasuch as the information related to any disease you may be suffering, any specific diagnosis or medical treatment you may receive.

You may decide not to provide your personal data to your pharmacy. However, if you do not provide it, your pharmacy may not be able to provide you with their medicinal products or pharmaceutical services.

How does your pharmacy obtain your personal data?

Your pharmacy may collect your information:

  • Directly from youthrough your interactions with them, such as when you book an appointment with them or when they have video consultations with you; or
  • From third party sources, such as Charac Limited, as the owner of the Charac App and our Platform in which you are registered and where you upload your personal data, as well as from your relatives, where you cannot provide your personal data directly.

Why does your pharmacy process your personal data for and what are the legal bases on which they rely?

Your pharmacy may process your personal data for the purposes below and based on the following legal bases:

i. They can rely on the compliance with applicable laws and regulations for the following purposes:

  • To establish, exercise or defend legal claims in suspected or actual legal proceedings or to exercise or perform any right or obligation which is conferred or imposed by law on them.
  • Where they are legally required to process personal data in connection with health and safety legislation and other legal or tax related obligations.

ii. They can rely on the performance of their obligations arising from the service contract or arrangement in place with you for the following purposes:

  • Performance of service, which includes making appointments, video consultations, prescriptions and other advice/services, available to you.

iii. They can also rely on your explicit consent, for the following purposes:

  • Where you have consented to us using your information for marketing purposes.

They shall notify you of any material changes to personal data they collect or to the purposes for which they collect and process it.

How does your pharmacy keep your personal data safe?

Your pharmacy implements appropriate technical, physical, and organisational measures which are intended to safeguard any information you provide to them, and to protect it from unauthorised access, loss, misuse, alteration or destruction.

Who is your personal data disclosed to?

Your pharmacy will only disclose your personal data in accordance with the applicable laws and for the above-stated purposes, to the following parties:

  • Third party service providers for the provision of services to your pharmacy, such as third parties supporting them with their IT systems and third parties providing external legal advice or litigation support. Your pharmacy has appropriate contracts in place that define the legitimate use and sharing of personal data in accordance with this Notice and oblige such service providers to only process personal data that is necessary for the performance of the contract or are required by applicable laws.
  • Regulatory authorities and other public bodies, for the purposes of, including but without limitation, responding to official requests or inquiries, complying with a court order, administrative or judicial process, or when the disclosure is otherwise required by applicable laws and regulations.
  • Parties including prospective or actual buyers or sellers in the event of a merger, acquisition, or other reorganisation or sale or disposition of all or any portion of your pharmacy business and/or assets.

Some of these third parties may be located in a country outside the United Kingdom (UK) where the applicable laws may not afford your personal data the same level of protection as your own country. Where your personal data is transferred outside of the UK, your pharmacy will ensure that adequate safeguards are in place (e.g. for residents of the UK this includes transfers to countries which have equivalent levels of data protection laws or the use of approved standard contractual clauses) and that all applicable laws and regulations are complied with. You may contact your pharmacy for a copy of the safeguards which they have put in place to protect your personal data in these circ*mstances.

What are your rights?

You have rights in relation to your personal data arising from the applicable data protection legislation. These include the right to:

  • Access, rectify and erase your personal data:You may have the right to request access to information that your pharmacy holds about you; request corrections or updates to your personal data; or, in some cases, ask your pharmacy to erase your personal data except to the extent that they are required or permitted to retain it by law.
  • Restriction of processing:You may have the right to request the restriction of processing of your personal data, in which case, your personal data will only be processed for certain purposes.
  • Data portability:You may you have the right to receive the personal data which you have provided to your pharmacy in a structured, commonly used and machine-readable format and you may have the right to transmit the personal data to another entity without hindrance from them.
  • Object:Where your pharmacy relies on legitimate interests as a legal basis for processing personal data, you have the right to object, on grounds relating to your situation, at any time to the processing of your personal data by them and they are required to no longer process your personal data. If you exercise this right, your personal data will no longer be processed for such purposes unless otherwise authorised by law.
  • Consent withdrawal: You have the right to withdraw any consent you may have provided at any time without being penalised.

If you wish to exercise one of the above-mentioned rights, please refer to “Who do I contact to ask questions about this Privacy Notice” below. Any request to exercise one of these rights will be assessed by your pharmacy on a case-by-case basis. There may be circ*mstances in which your pharmacy is not legally required to comply with your request or because of relevant legal exemptions provided for in applicable data protection legislation.

How long will your pharmacy retain your personal data?

Your pharmacy generally retains personal data for as long as needed for the specific purpose(s) for which it was collected. In some cases, they may be required to retain your personal data for a longer period where applicable laws or regulations require or allow them to do so.

Where possible, your pharmacy aims to anonymise the information or remove unnecessary identifiers from records that they may need to keep for longer periods beyond the specified retention period.

Who do I contact to ask questions about this Privacy Notice?

If you have any queries or concerns about this Notice or you wish to exercise your rights and/or make complaints concerning the handling of your personal data, please contact your pharmacy.

If you are still dissatisfied, you have the right to complain to the Information Commissioner’s Office.

Can this Privacy Notice be updated?

This Privacy Notice is kept under regular review in order to reflect changes in the law, regulatory guidance or data privacy practices in compliance with the law. When this happens and where required by law, you shall be provided with a new or an updated Privacy Notice detailing how the use of your personal data is changing.

Privacy Policy - Charac (2024)
Top Articles
Latest Posts
Article information

Author: Arielle Torp

Last Updated:

Views: 6332

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Arielle Torp

Birthday: 1997-09-20

Address: 87313 Erdman Vista, North Dustinborough, WA 37563

Phone: +97216742823598

Job: Central Technology Officer

Hobby: Taekwondo, Macrame, Foreign language learning, Kite flying, Cooking, Skiing, Computer programming

Introduction: My name is Arielle Torp, I am a comfortable, kind, zealous, lovely, jolly, colorful, adventurous person who loves writing and wants to share my knowledge and understanding with you.