To register you as a new customer | - (a) Identity
- (b) Contact
- (c) Professional
| Performance of a contract with you | For the duration of the contract and 7 years thereafter for regulatory compliance |
To verify professional credentials and regulatory status | - (a) Identity
- (b) Professional
- (c) Contact
| - (a) Performance of a contract with you
- (b) Legal obligation (GPhC, GMC, NMC requirements)
- (c) Public interest in healthcare safety
| For the duration of the contract and 7 years thereafter |
To process and deliver Clinical Services including: - (a) NHS Pharmacy First consultations
- (b) Private consultations
- (c) PGD utilisation
- (d) Prescription management
- (e) NHS claims and reporting
- (f) Consultation review
| - (a) Identity
- (b) Contact
- (c) Patient Data
- (d) Clinical Data
- (e) NHS Data
- (f) Transaction Data
- (g) Clinical Review Data
| - (a) Performance of a contract with you
- (b) Legal obligation (NHS compliance, regulatory reporting, NHSBSA/PPV)
- (c) Public interest in healthcare provision (Article 9(2)(h) UK GDPR)
- (d) Vital interests (patient safety)
- (e) Consent (where required)
| Clinical records: 10 years (adults)/25 years (paediatrics) as per NHS Records Management Code; NHS claims and reporting data as per NHSBSA/contract requirements |
To facilitate consultation review by independent clinicians | - (a) Patient Data
- (b) Clinical Data
- (c) PSQ responses
- (d) Identity (anonymised)
- (e) Clinical Review Data
| - (a) Performance of a contract with you
- (b) Public interest in healthcare provision
- (c) Consent (where required)
- (d) Vital interests (patient safety)
| 12 months from review completion for audit purposes |
To obtain and manage patient consents including: - (a) GP practice information sharing
- (b) NHS reporting
- (c) Third party presence
- (d) Pharmacy referrals
- (e) NHSBSA/PPV sharing
| - (a) Consent Records
- (b) Identity
- (c) Contact
- (d) Clinical Data
| - (a) Legal obligation (NHS requirements)
- (b) Performance of a contract
- (c) Public interest in healthcare provision
| 7 years from consent withdrawal or contract termination |
To manage payments, fees and charges including: - (a) Base Plan subscriptions
- (b) Consultation fees
- (c) Module charges
- (d) SMS and API fees
- (e) Collection of debts
| - (a) Identity
- (b) Contact
- (c) Transaction Data
- (d) Usage Data
| - (a) Performance of a contract with you
- (b) Necessary for our legitimate interests (to recover debts due to us and manage our business finances)
| Transaction data: 7 years from end of financial year for HMRC compliance |
To manage our relationship with you which will include: - (a) Notifying you about changes to our terms or privacy policy
- (b) Asking you to leave a review or take a survey
- (c) Account management
- (d) Account management
| - (a) Identity
- (b) Contact
- (c) Professional Data
- (d) Usage Data
- (e) Marketing and Communications
| - (a) Performance of a contract with you
- (b) Necessary to comply with a legal obligation
- (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
| For the duration of the contract and 2 years thereafter |
To enable you to partake in surveys, feedback, or quality improvement initiatives | - (a) Identity
- (b) Contact
- (c) Usage Data
- (d) Clinical Data (anonymised)
- (e) Marketing and Communications
| - (a) Performance of a contract with you
- (b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
- (c) Consent
| Until consent withdrawal or 3 years after participation |
To administer and protect our business including: - (a) NHS DSPT compliance
- (b) Clinical governance
- (c) Regulatory audits
- (d) System security
- (e) Fraud prevention
| - (a) Identity
- (b) Contact
- (c) Technical
- (d) Professional
- (e) Audit and Compliance
| - (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud)
- (b) Necessary to comply with a legal obligation
| For the duration of the contract and 7 years thereafter for audit purposes |
To deliver relevant platform content and improve user experience | - (a) Identity
- (b) Contact
- (c) Professional Data
- (d) Usage Data
- (e) Technical
| Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our service strategy) | For the duration of the contract (anonymised thereafter for analytics) |
To conduct data analytics for service improvement and NHS reporting | - (a) Technical
- (b) Usage
- (c) Clinical Data (anonymised)
- (d) Transaction
| - (a) Necessary for our legitimate interests (to understand service usage patterns, improve clinical outcomes, inform business strategy)
- (b) Public interest (population health improvement)
- (c) Legal obligation (NHS reporting)
| Anonymised data retained indefinitely for research and development |
To provide marketing communications and educational content | - (a) Identity
- (b) Contact
- (c) Professional Data
- (d) Marketing and Communications
- (e) Usage
| - (a) Consent (for promotional marketing)
- (b) Necessary for our legitimate interests (to promote our services to healthcare professionals, share clinical updates)
- (c) Legal obligation (mandatory clinical updates)
| Until consent withdrawal or 24 months after last engagement |
To make recommendations about services and clinical best practice | - (a) Identity
- (b) Contact
- (c) Identity
- (d) Usage
- (e) Professional Data
| Necessary for our legitimate interests (to develop our products/services, support clinical practice improvement, and grow our business) | For the duration of the contract and 12 months thereafter |
To comply with legal, regulatory, safeguarding, and public interest obligations | - (a) All data categories as required
| - (a) Legal obligation
- (b) Public interest
- (c) Vital interests
- (d) Regulatory requirement
| As required by law or regulatory body |