This Privacy Policy explains how PharmaDesk collects, uses, shares and protects personal data when you use our website and platform, and sets out your rights under UK data protection law.
Contents
1. Who we are
PharmaDesk provides a cloud-based operations platform for UK pharmacy businesses, covering point of sale, inventory, daily cashing-up, HR and annual leave, locum cover and reporting. This policy applies to our marketing website and to the PharmaDesk platform.
2. Personal data we collect
Depending on how you interact with us, we may collect:
- Account & contact data — name, business name, email address, telephone number, job role, and login credentials.
- Enquiry & communications data — messages you send us by email, WhatsApp, telephone or web form, and our correspondence with you.
- Billing data — billing contact, subscription and invoice details. Card payments are handled by our payment provider; we do not store full card numbers.
- Usage & technical data — IP address, browser and device type, pages viewed, and actions taken, collected through cookies and server logs.
3. How and why we use it
We use personal data to:
- provide, operate, secure and support the platform;
- set up and administer accounts, subscriptions and billing;
- respond to enquiries and provide customer support;
- improve and develop our services and website;
- send service messages and, where permitted, relevant updates;
- detect, prevent and investigate fraud, misuse and security incidents; and
- comply with our legal and regulatory obligations.
4. Lawful bases for processing
Under the UK GDPR we rely on the following lawful bases:
- Contract — to provide the services you or your organisation have signed up for.
- Legitimate interests — to run, secure, improve and market our business, provided your rights do not override those interests.
- Consent — for non-essential cookies and certain marketing communications, which you may withdraw at any time.
- Legal obligation — to meet our accounting, tax and other legal duties.
5. Cookies
Our website uses cookies and similar technologies. Essential (strictly necessary) cookies are needed for the site and platform to function (for example, to keep you signed in and to remember your preferences); these do not require consent. Any non-essential cookies (such as analytics) are only set with your consent, which you can give or refuse using our cookie banner and change at any time by clearing your browser’s stored data. You can also control cookies through your browser settings.
6. Sharing your data
We do not sell your personal data. We may share it with:
- Service providers (processors) who host, support or help us operate the platform (for example, cloud hosting, email delivery, payment processing and messaging providers), under contracts that require them to protect your data;
- Professional advisers such as accountants and lawyers where necessary;
- Authorities or third parties where required by law, to enforce our terms, or to protect our rights, users or the public; and
- A buyer or successor in the event of a merger, acquisition or business reorganisation.
7. Data we process on behalf of customers
When a pharmacy business uses the platform, it may enter personal data relating to its staff, locums and operations (for example, employee records, hours, leave and locum details). For that data, the customer is the controller and PharmaDesk acts as a processor, processing the data only on the customer’s documented instructions and in accordance with our agreement and applicable data protection law.
8. International transfers
We aim to store and process data in the UK or European Economic Area. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as UK adequacy regulations or the International Data Transfer Agreement (or UK Addendum to the EU Standard Contractual Clauses).
9. How long we keep data
We keep personal data only for as long as necessary for the purposes set out in this policy, including to meet legal, accounting or reporting requirements. Account and billing records are typically retained for the duration of the relationship and for a reasonable period afterwards as required by law.
10. Security
We use appropriate technical and organisational measures to protect personal data, including access controls, role- and store-based permissions, encryption in transit, and safeguards on financial and stock records. No system can be guaranteed to be completely secure, but we work to protect your information and to respond appropriately to any incident.
11. Your rights
Subject to conditions under UK data protection law, you have the right to: access your personal data; have it corrected; have it erased; restrict or object to its processing; data portability; and to withdraw consent where we rely on it. To exercise any of these rights, contact us using the details below.
You also have the right to complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk, although we ask that you contact us first so we can try to resolve the matter.
12. Children
Our website and platform are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Significant changes will be notified where appropriate.
14. Contact us
For any questions about this policy or your personal data, contact us at:
- Email: support@pharmadesk.cloud
- Telephone: +966 50 090 0558
- Post: [Registered Company Name], [Registered Address]
