1. IMPORTANT INFORMATION AND WHO WE ARE
PURPOSE OF THIS POLICY
This Policy aims to give you information on how Ashtons collects and processes your personal data, including through your use of our websites (https://orders.ashtons.com/)or (https://ashtons.com/), or place an order via our pharmacy services, including our online Live View or e-Works services, or when you contact us or take part in a survey.
Our websites and services are not intended for use by children and we do not knowingly collect data relating to children unless it is with the consent of a guardian or adult.
CHANGES TO THE POLICY AND YOUR DUTY TO INFORM US OF CHANGES
This version was last updated in October 2023 and may be subject to further revisions.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Our website or online services may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website or online services, we encourage you to read the privacy notice of every website you visit.
2.THE DATA WE COLLECT ABOUT YOU
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes: first name, last name, maiden name, username or similar identifier used by our pharmacy or online services, title, passport or national insurance or NHS number, photos or other images.
- Contact Data includes: address, email address and telephone numbers, any social media accounts used to contact us or submitted used via our websites or our online services.
- Technical Data includes: device ID, internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
- Profile Data includes: any username and password to access our pharmacy or online services, preferences, feedback and survey responses.
- Usage Data includes: information about how you use our services and websites.
- Special Category Data includes: health, biometric or genetic data, as well as the contact details of healthcare professionals and healthcare providers you are registered with or in contact with for any diagnostics, care or treatments, or the details of which you provide to us or explicitly allow us to share, including:
- records of medicines you have been prescribed by your doctor or another qualified prescriber, and which have been supplied by Ashtons Hospital Pharmacy Services;
- details of medicines purchased from Ashtons without a prescription (over the counter medicines);
- other details and notes about your health and medical treatment;
- Information relevant to your continued care provided by relatives, carers and healthcare professionals, and any other services we provide to you, for example, a flu vaccination.
We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where we need to collect personal data by law, or under the terms of a contract (i.e. online service end user licence) we have with you, or we have legitimate interest in collecting because of a service offered, and you fail to provide that data when requested, we may not be able to perform the contract or service we have or are trying to enter into with you. In this case, we may have to cancel a registration or service you have with us but we will endeavour to notify you if this is the case at the time.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
We use different methods to collect data from and about you including through:
- Direct interactions. You may give us your Identity, Contact, Profile and Special Category data by using our website or registering to use our pharmacy or online services, or by corresponding with us by post, phone, email, social media or otherwise. This includes personal data you provide when you:
- make a general enquiry about our services; or
- register or activate an account registered with one of our pharmacy or online services;
- give us feedback.
- Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources as set out below:
- Technical or Contact Data from the following parties:
- (a) analytics providers such as Google based inside or outside the UK;
- (b) website or online service hosting platforms such as Iomart or CNC.
- Special Category data provided from permitted and authorised carers, healthcare professionals or healthcare providers (including in the UK via the NHS).
- Technology providers we use based inside or outside the UK.
- Identity and Contact Data from publicly available
- Technical or Contact Data from the following parties:
4. HOW WE USE YOUR PERSONAL DATA
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you, one of our clients or one of our providers.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation or where we are acting in the vital interests of a person, if the processing needs to be done to protect someone’s life, for instance.
Click here to find out more about the types of lawful basis that we will rely on to process your personal data.
It is important that you read this Policy together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Policy supplements the other notices and is not intended to override them.
Ashtons Hospital Pharmacy Services Limited is the controller and responsible for this website and is the controller and responsible for your personal data (collectively referred to as “Ashtons”, “we”, “us” or “our” in this Policy).
Our Data Protection Officer (DPO) is responsible for overseeing questions in relation to this Policy. If you have any questions, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
Our full details are: Ashtons, Units 2-10, 74 Dyke Road Mews, Brighton, BN1 3JD.