Privacy Notice & Policy
PRIVACY NOTICE – MILTON ROAD PHARMACY
1. Who we are
Milton Road Pharmacy is operated by A Rossier Ltd. We are the data controller for the personal information described in this notice.
Milton Road Pharmacy
123 Milton Road
Cambridge
Cambridgeshire
CB4 1XE
United Kingdom
GPhC pharmacy registration: 1029231
Website: https://miltonroadpharmacy.co.uk
Privacy and data protection contact: Michal Sibilla.
You can contact us using the contact form at https://miltonroadpharmacy.co.uk/contact/ or by writing to the pharmacy at the address above.
This notice explains how we collect, use, share, store and protect personal information about patients, customers, carers or representatives, and visitors to our website. A separate privacy notice may apply to employees, workers and job applicants.
2. The information we collect
The information we collect depends on the service you use. It may include:
- Identity information, such as your name, title, date of birth and, where relevant, NHS number.
- Contact information, such as your address, postcode, telephone number and email address.
- Appointment information, including the service booked, appointment date and time, booking status, cancellation or rescheduling information, and appointment communications.
- Health and clinical information, including medical history, current medicines, allergies, pregnancy status where relevant, vaccination history, symptoms, weight or other measurements, answers to clinical questionnaires, treatment preferences and information needed to assess whether a service or treatment is suitable.
- Clinical service records, such as the medicine, vaccine or treatment supplied or administered, dose or strength, route and site of administration, batch or lot number, expiry date, clinical outcome, and the identity or professional registration details of the healthcare professional providing the service.
- Records of communications with us, including enquiries, complaints and messages sent through our website, by email, by telephone or in person.
- Payment and transaction information where a paid service or product is provided. Where a third-party payment provider is used, we do not normally store full payment-card details ourselves.
- Technical information about use of our website, such as IP address, browser or device information, security logs and cookie information where applicable.
Health information is special category personal data and receives additional protection under data protection law.
3. How we obtain your information
We may obtain personal information:
- directly from you when you book or receive a service, complete a questionnaire, contact us, buy a product or otherwise provide information to us;
- from a parent, carer, representative or person booking on your behalf;
- from your GP practice, another healthcare professional, NHS organisation or service system where this is relevant and lawful;
- from NHS or commissioned clinical systems used to provide a service;
- automatically from your use of our website, for example through security logs and cookies.
If information is provided to us by someone acting for you, we may need to confirm that they have authority to act on your behalf.
4. Why we use your information
We use personal information where necessary to:
- arrange, manage, confirm, reschedule or cancel appointments;
- provide pharmacy, vaccination, weight-management, contraception and other clinical or private services;
- assess suitability for treatment or supply and support safe clinical decision-making;
- maintain accurate clinical and service records;
- contact you about your appointment, including confirmations, secure completion links and appointment reminders;
- communicate with your GP practice or another healthcare professional where this is appropriate, required for the service, or requested by you;
- provide NHS-funded or commissioned services and meet the requirements of those services;
- process payments and maintain appropriate financial records;
- manage complaints, queries, safeguarding concerns, clinical governance, audit, quality assurance and service improvement;
- meet legal, regulatory, professional, contractual and insurance requirements;
- keep our website, booking system and other systems secure and prevent misuse or fraud.
We do not sell your personal information.
We do not use health or clinical information for advertising or unrelated marketing.
5. Our lawful bases
We only use personal information where we have a lawful basis under UK data protection law. The basis depends on the purpose and the service.
The lawful bases we may rely on include:
- Contract – where processing is necessary to provide a private service you have requested or to take steps at your request before providing that service.
- Legal obligation – where we must process information to comply with a legal or regulatory duty.
- Public task – where applicable to NHS-funded or commissioned services or another function carried out in the public interest with a basis in law.
- Legitimate interests – for appropriate business administration, service management, system security, fraud prevention, responding to enquiries and similar purposes, where those interests are not overridden by your rights and interests.
- Vital interests – in exceptional circumstances where processing is necessary to protect someone’s life.
- Consent – where consent is the appropriate lawful basis, for example for certain optional communications or non-essential website technologies.
For health and other special category information used to provide healthcare or treatment, we may rely on Article 9(2)(h) of the UK GDPR and the relevant condition in Schedule 1 of the Data Protection Act 2018, where processing is carried out by or under the responsibility of a professional subject to duties of confidentiality.
We do not generally rely on consent as the legal basis for providing ordinary clinical care where another lawful basis applies. Where our booking system asks you to tick a privacy acknowledgement, this normally confirms that you have been shown our privacy information; it does not necessarily mean that consent is the lawful basis for all processing connected with your care.
6. Appointments, online booking and reminders
Our website may allow you to book pharmacy services online. Depending on the service, the booking form may ask for contact information, date of birth, address, NHS number where relevant, and answers to service-specific clinical questions.
We use this information to manage your booking, assess service requirements and, where applicable, create or maintain a clinical record.
We may send appointment confirmations, secure links to complete information, cancellation or rescheduling messages, and appointment reminders to the email address you provide.
Routine appointment emails are designed to contain only the information reasonably necessary to manage the appointment. We do not intentionally include questionnaire answers or detailed medical information in routine booking or reminder emails.
If a member of staff makes a booking for you by telephone or in person, you may be sent a secure link so that you can complete any remaining information yourself.
7. Pharmacy services and clinical records
When you use a clinical pharmacy service, we may create a clinical record of the consultation or treatment.
This may include:
- the information you provided before or during the consultation;
- the clinical assessment and outcome;
- medicines or treatments supplied;
- vaccination details;
- weight-management treatment details;
- advice or referrals made;
- relevant communications with your GP or another healthcare professional;
- the identity of the healthcare professional providing the service.
Clinical decisions are made by appropriately trained healthcare professionals. Our appointment system does not make solely automated clinical decisions that have legal or similarly significant effects on you.
8. Sharing information with your GP and other healthcare professionals
Where appropriate, necessary for your care, required by the service, or requested by you, we may share relevant information with:
- your GP practice;
- NHS England
- another pharmacy, prescriber or healthcare professional involved in your care;
- NHS organisations, commissioners or service providers;
- NHS systems or approved/commissioned clinical service platforms;
- public health bodies where required or appropriate.
For example, if you ask us to notify your GP that you received a private vaccination, we may prepare and send relevant patient and vaccination information to your GP practice so that your medical record can be updated.
We only share information that is relevant to the purpose.
Where confidential clinical information is sent electronically to another healthcare organisation, we use an appropriately secure communication method, such as NHSmail or another service that meets applicable health and care secure-email standards. Staff are expected to verify the intended recipient before sending confidential information.
9. Other organisations we may share information with
Where necessary and lawful, we may also share information with:
- organisations providing IT, hosting, backup, email, cyber-security or technical support services to us;
- payment providers, where a payment service is used;
- professional advisers, insurers or indemnity providers;
- regulators or professional bodies, including the General Pharmaceutical Council, where appropriate;
- law-enforcement agencies, courts or other authorities where we are legally required or permitted to do so;
- safeguarding bodies or relevant organisations where necessary to protect a person at risk.
Service providers acting on our behalf are expected to process personal information only for agreed purposes and to protect it appropriately.
10. NHS and third-party clinical systems
Some NHS or commissioned services use third-party clinical systems or platforms specified or approved by the NHS, commissioner or service provider.
Where we use such a system, personal and clinical information may be entered into or exchanged through that system as necessary to deliver the service and meet contractual, clinical, payment, audit or reporting requirements.
Depending on the service and the parties involved, another organisation may act as our processor, a joint controller, or an independent controller. Where another organisation is an independent controller, its own privacy information may also apply.
11. Marketing
We do not use clinical or health information for marketing.
If we send optional marketing communications, we will do so only where permitted by law and, where required, with your consent. You can opt out of marketing at any time.
Appointment confirmations, service messages, safety communications and reminders are service communications rather than marketing.
12. Cookies and website information
Our website uses cookies and similar technologies where needed for security, essential functionality and, where configured, analytics or other optional features.
Strictly necessary cookies may be used without consent where permitted by law. Where consent is required for non-essential cookies or similar technologies, we will ask for it through our cookie controls.
You can manage cookies using the controls provided on the website and through your browser settings.
We may collect technical information such as IP address, browser type, device information and website-security logs to operate and protect the site and understand how it is used.
13. International transfers
Our website is hosted in the United Kingdom.
Some suppliers or service providers may process personal information outside the United Kingdom. Where personal information is transferred internationally, we take steps to ensure that an appropriate lawful transfer mechanism and safeguards are in place, such as applicable adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful safeguard.
We do not transfer clinical information internationally unless there is a lawful and appropriate reason to do so.
14. How long we keep information
We keep personal information only for as long as it is needed for the purpose for which it was collected and to meet relevant legal, professional, contractual and records-management requirements.
Different types of information may therefore have different retention periods.
Clinical pharmacy records
As a general rule, pharmacy-held clinical records, including records of vaccinations and other clinical interactions, are retained for 8 years after the last interaction with the patient, unless:
- a different retention period applies to the particular service or type of record;
- a longer period is required by law, contract, commissioner or professional requirement; or
- there is a justified, documented and approved reason to retain the record for longer.
Where justified, some pharmacy clinical records may be retained for longer, including up to 20 years in accordance with applicable records-management guidance.
Where ordinary booking information forms part of a clinical record, the clinical-record retention period takes priority over a shorter administrative booking-retention setting.
Booking and administrative information
Non-clinical booking and contact information is retained only for as long as necessary to administer the appointment, respond to queries or complaints, maintain appropriate audit records and meet legal or business requirements.
Our systems may identify older non-clinical booking information that is eligible for erasure. Nothing is erased automatically unless we have deliberately configured an approved retention process.
Cancellation of an appointment does not automatically mean that the associated information is immediately erased.
Financial, complaints and other records
Financial, tax, complaint, regulatory, insurance and legal records are retained for the periods required or reasonably necessary for those purposes.
We periodically review our retention arrangements.
15. Keeping information accurate
Please tell us if information we hold about you is incorrect or changes.
You may be able to update some information when completing an appointment form. For other corrections, please contact the pharmacy.
16. Security and confidentiality
We take reasonable technical and organisational measures to protect personal and clinical information.
These measures include, where appropriate:
- encryption in transit using HTTPS/TLS;
- access controls and role-based permissions;
- secure authentication;
- audit and activity records;
- database and system backups;
- controlled access to clinical information;
- secure communication methods for confidential healthcare information;
- staff confidentiality and data-protection procedures.
No internet or electronic system can be guaranteed to be completely secure. We regularly review our arrangements and respond to security risks as they are identified.
17. Your data protection rights
Depending on the circumstances and the lawful basis we rely on, you may have rights including:
- the right to be informed about how we use your information;
- the right to access personal information we hold about you;
- the right to have inaccurate information corrected;
- the right to request erasure of information in certain circumstances;
- the right to request restriction of processing in certain circumstances;
- the right to object to certain processing;
- the right to data portability in certain circumstances;
- rights relating to certain types of automated decision-making;
- the right to withdraw consent where processing is based on consent.
These rights are not absolute. For example, we may need to retain clinical records or other information where we have a legal, professional or other lawful reason to do so.
We will normally provide a copy of personal information in response to a valid subject access request without charge. A reasonable fee may be permitted in limited circumstances provided for by law, such as where a request is manifestly unfounded or excessive or where additional copies are requested.
We may need to verify your identity before responding to a rights request.
To exercise your rights, please contact us using the details in section 1.
18. Data protection complaints
If you are concerned about how we have used your personal information, please contact us so that we can investigate.
You may make a data protection complaint using our website contact form, by writing to the pharmacy, or by another reasonable method.
We will acknowledge a data protection complaint within 30 days of receiving it, investigate it without undue delay, keep you appropriately informed and explain the outcome.
You also have the right to complain to the Information Commissioner’s Office (ICO).
Information Commissioner’s Office:
https://ico.org.uk/make-a-complaint/
We would appreciate the opportunity to address your concerns directly where possible, but this does not affect your right to contact the ICO.
19. Children and people represented by others
Some pharmacy services may involve children or people who are assisted or represented by a parent, carer, attorney or other authorised person.
We will only collect and use information that is appropriate for the service and will take reasonable steps to confirm authority where necessary.
Privacy information should be provided in a way that is appropriate to the person receiving the service and the circumstances.
20. Links to other websites
Our website may contain links to third-party websites or services.
We are not responsible for the privacy practices of independent third parties. If you follow a link to another organisation, please read its privacy information.
21. Changes to this notice
We review this notice regularly and will update it when our services, systems, legal obligations or data-sharing arrangements change.
The current version will be published on our website.
22. Legal framework and guidance
This notice is intended to reflect the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and amendments introduced by the Data (Use and Access) Act 2025, together with relevant healthcare records-management and secure-communications guidance.
Last reviewed: 23 September 2026.








