Privacy Policy

Last updated: 12/07/2025

At Be Online Pharmacy, we are fully committed to safeguarding your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you interact with our services, website, and pharmacy operations. We comply with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and all relevant healthcare and pharmacy regulations under the General Pharmaceutical Council (GPhC).

1. Who We Are

Be Online Pharmacy is a registered UK online pharmacy. We are authorised and regulated by the General Pharmaceutical Council (GPhC) and our services comply with all UK standards for the safe dispensing of prescription medicines. We are registered with the Information Commissioner’s Office (ICO) as a data controller.

2. What Information We Collect

We collect the following categories of personal data when you use our website or services:

  • Identity Information: Full name, date of birth, gender.
  • Contact Information: Email address, phone number, residential address.
  • Health Information: Medical history, prescriptions, GP details, medication preferences.
  • Transaction Data: Payment method, billing history.
  • Technical Data: IP address, browser type, device identifiers, usage logs, cookies.

We only collect health and sensitive data where it is necessary for the provision of healthcare and pharmaceutical services, and we apply strict confidentiality protocols in line with NHS and GPhC guidelines.

3. How We Use Your Information

We process your data under lawful bases including consentcontractlegal obligation, and legitimate interests. Specifically, we use your data to:

  • Verify your identity and eligibility for pharmacy services.
  • Process and deliver your prescriptions and orders.
  • Conduct clinical assessments where required.
  • Provide customer support and respond to inquiries.
  • Comply with legal, regulatory, and professional obligations.
  • Improve user experience and secure our website.

We do not use your medical data for marketing without your explicit consent.

4. Legal Basis for Processing

We process your personal data under one or more of the following lawful grounds:

  • Consent (e.g., marketing communications).
  • Performance of a contract (e.g., prescription fulfilment).
  • Legal obligation (e.g., pharmacy record keeping).
  • Vital interests (e.g., in emergencies).
  • Legitimate interests (e.g., fraud prevention, service optimisation).

Health data is processed in accordance with Article 9(2)(h) of the UK GDPR: for the purposes of healthcare and treatment.

5. Data Sharing

We may share your personal data with:

  • Registered healthcare professionals for clinical evaluation.
  • Our pharmacy partners and couriers to ensure correct delivery.
  • Payment processors for secure transaction handling.
  • Regulatory authorities (e.g., GPhC, MHRA, NHS) where required by law.
  • IT service providers under strict data protection agreements.

We never sell or lease your personal information to third parties.

6. International Data Transfers

All data is stored and processed within the UK or the European Economic Area (EEA). If we ever transfer data outside the EEA, we ensure it is subject to equivalent protection by using approved adequacy decisions or Standard Contractual Clauses (SCCs).

7. How We Protect Your Data

We implement robust technical and organizational security measures, including:

  • Data encryption (in transit and at rest)
  • Firewalls and access controls
  • Regular security audits and penetration testing
  • Employee confidentiality training and NDAs
  • Secure data storage and disposal procedures

8. How Long We Keep Your Data

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, accounting, or reporting requirements. For healthcare data, we follow NHS and GPhC retention periods, typically 8 years post-treatment or consultation.

9. Your Rights

Under UK GDPR, you have the following rights:

  • Right to access – Request a copy of the data we hold.
  • Right to rectification – Correct inaccurate or incomplete data.
  • Right to erasure – Request deletion of your data in certain circumstances.
  • Right to restrict processing – Limit how we use your data.
  • Right to data portability – Request transfer to another provider.
  • Right to object – Oppose certain types of processing (e.g., direct marketing).
  • Right to lodge a complaint – With the ICO if you believe your data rights are infringed.

To exercise any of these rights, please contact us via the details below.

10. Cookies and Tracking

Our website uses cookies to enhance user experience, analyse site traffic, and deliver relevant content. You can manage or disable cookies at any time through your browser settings.

11. Third-Party Links

Our website may include links to external websites. We are not responsible for the privacy policies or practices of those third-party sites.

12. Contact Us

If you have any questions or concerns about this Privacy Policy or your personal data, you can reach us at:

Be Online Pharmacy
Email:
Phone: 02071755104
Address:
82 Harley St, London W1G 7HN
ICO Registration Number:
GPhC Pharmacy Number:

13. Updates to This Policy

We may revise this Privacy Policy from time to time. All updates will be posted on this page, and where necessary, we will notify you directly. We encourage you to check this page regularly to stay informed.