SignatureRX Website Privacy Policy
CONTENTS
____________________________________________________________
CLAUSE
1. Important information and who we are
2. The data we collect about you
3. How is your personal data collected?
4. How we use your personal data
5. Disclosures of your personal data
Welcome to the Signature Healthcare services Limited (“SignatureRX”) privacy policy.
Please also use the Glossary in this document understand the meaning of some of the terms used in this privacy policy.
1. IMPORTANT INFORMATION AND WHO WE ARE
2. THE DATA WE COLLECT ABOUT YOU
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. DISCLOSURES OF YOUR PERSONAL DATA
1. Important information and who we are
Purpose of this privacy policy
This website is not intended for children and we do not knowingly collect data relating to children.
Full name of legal entity: Signature Healthcare services Limited
Email address: [email protected]
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (https://www.ico.org.uk/), or the data protection regulator in the country where you usually live or work, or where the alleged data protection infringement has taken place We would, however, appreciate the chance to deal with your concerns before you approach the ICO or the applicable data protection regulator so please contact us in the first instance.
Changes to the privacy policy and your duty to inform us of changes
We keep our privacy policy under regular review. This version was last updated on 14 November 2021.
2. The data we collect about you
· Identity Data includes first name, maiden name, last name, or similar identifier, title, date of birth and gender.
· Contact Data includes email address and telephone number.
· Technical Data includes [internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
· Usage Data includes information about how you use our website.
· Prescriber Data, includes, Prescriber Full Name, Professional Registration Details, Biometric Identification Details, home and work address, Date of birth, Email Address, Telephone Number, CQC registration number, registered manager name & email address, medical speciality/fields of specialism, KYC registration check results, proof of registration with a registration authority, website usage data.
· Patient Data, Full name, Date of birth, Address, Telephone Number, Email Address, Prescriptions that have been prescribed including details of medicines and instruction from the medical doctor.
· Pharmacist data, Pharmacy name, pharmacy address, email address, Telephone number.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
We collect Special Categories of Personal Data about you (this can include details about sex life, sexual orientation, information about your health, and genetic and biometric data). We do not collect any information about criminal convictions and offences.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
· Direct interactions. This includes a prescriber using the services on our platform to create a prescription for a patient, a pharmacist retrieving the prescription, or using our platform inquire about our products or services;
· subscribe to our service or publications;
· make payments
· give us feedback or contact us.
· Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.
· Third parties or publicly available sources. We will receive personal data about you from various third parties as set out below from the following parties:
o Woody Labs Inc (Vouched.id) for verification of prescriber’s identification documents.
4. How we use your personal data
· Where we need to perform the contract, we are about to enter into or have entered into with you.
· Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
· Where we need to comply with a legal or regulatory compliance obligation.
· Where it is necessary to provide health treatment and the management of health of patients.
Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending third party direct marketing communications to you via email. You have the right to withdraw consent to any marketing at any time by contacting us at [email protected].
Purposes for which we will use your personal data
Purpose/Activity |
Type of data |
Lawful basis for processing including basis of legitimate interest |
To register you as a prescriber |
(a) Identity (b) Contact |
(a) Performance of a contract with you |
To provide our services to you |
(a) Identity (b) Contact (c) Health |
(a) Performance of a contract with you (b) Necessary to provide health treatment or the management of health |
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Asking you to leave a review or take a survey and provide feedback on our services |
(a) Identity (b) Contact (c) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
(a) Identity (b) Contact (c) Technical |
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences |
(a) Technical (b) Usage |
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
To retain data in accordance with regulatory and compliance obligations |
(a) Identity (b) Contact (c) Health |
(a) Necessary to provide health treatment or the management of health (b) Necessary to comply with a legal obligation |
You will receive marketing communications from us if you have requested information from us and you have not opted out of receiving that marketing.
SignatureRX does not share your personal data with any third party for marketing purposes. In the event, we wish to do so, we will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time at [email protected].
5. Disclosures of your personal data
· External Third Parties as set out in the Glossary.
· Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
Your personal data may be used, stored and/or accessed by staff operating outside the UK and EEA working for us, or our suppliers. If we transfer your personal data outside the UK or EEA, we will take appropriate security measures to ensure the respective receipt protects your personal data adequately in accordance with this privacy policy. These measures may include the following:
· To countries that have been deemed to provide an adequate level of protection for personal data by the UK and/or EU Commission
· To entities in countries based outside the UK and EEA, by entering into the European Commission approved Standard Contractual Clauses and/or the UK equivalent with them.
How long will you use my personal data for?
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. Insofar as the processing of personal data is based on your consent, we will delete this data if you withdraw your consent.
· Request access to your personal data.
· Request correction of your personal data.
· Request erasure of your personal data.
· Object to processing of your personal data.
· Request restriction of processing your personal data.
· Request transfer of your personal data.
· Right to withdraw consent.
If you wish to exercise any of the rights set out above, please contact us at [email protected].
10. Glossary
Health treatment or the management of health means processing your personal data where it is necessary for the management of your health.
· Service providers who provide IT and system administration services.
· Professional advisers including lawyers, bankers, auditors and insurers based who may provide consultancy, banking, legal, insurance and accounting services.
· HM Revenue & Customs, regulators and other applicable authorities who require reporting of processing activities in certain circumstances.
· If you want us to establish the data’s accuracy.
· Where our use of the data is unlawful but you do not want us to erase it.
· Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
· You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
How We Use Your Personal Data
This section sets out the purposes for which we collect this information, and the legal bases upon which we rely:
Purpose |
Lawful Basis |
To register you as a prescriber/customer |
(i) Performance of a contract |
To supply our services to you, such as enabling you to create and generate prescriptions |
(i) Performance of a contract |
To provide you with updates on your order |
(i) Legitimate interests |
To ensure that items on your prescription or your order are suitable for you, such as ensuring that the medication is age appropriate and that there are no interactions with any of your other medication or conditions |
(i) Providing health treatment or the management of health |
To solicit feedback on our services |
(i) Legitimate interests |
To administer and improve our products and services |
(i) Legitimate interests |
To retain your personal data in line with legal obligations |
(i) Legal obligation |
To communicate with you and provide information by email and post that you have opted-in-to |
(i) Legitimate interests |
The security of your information is important to us and we take measures, both electronically and physically, to ensure that you information is not passed to person(s) or companies who are not authorised to receive it.
Sharing and Disclosing Your Personal Information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. In certain scenarios we share your information with third parties to help us provide you with our services, and they too are bound by the same data protection regulations as we are. Below are the categories of third party with whom we share your personal data:
In the case of Vouched, your personal data will be transferred to the United States. As the United State is a third country, we use standard data protection clauses that have been adopted by the European Commission in order to safeguard the data transfer. These clauses have the effect of ensuring your personal data retains the same level of protection as the data would in the UK. Additionally, we have undertaken a risk assessment to obtain additional assurance that the necessary controls are in place to protect your data as part of this ID checking service. Finally, we will never share your data for marketing purposes.
Your Rights
You have a number of rights with regards to the personal data that we process about you. These include:
Should you wish to exercise any of these rights free-of-charge, please contact [email protected]. We may ask you to verify your identity before acting on the request so as to ensure that your data is protected and kept secure.
How Long We Keep Your Data
We retain your personal information for as long as is necessary to satisfy the purposes for which we collect it, as well as to satisfy our legal obligations. This means that different sets of data may be retained for different periods of time. For example, patient medical records are retained for 10 years after the death of the patient in line with NHS guidelines. Further information on these retention periods can be provided upon request.
Lodging A Complaint
We only process your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, please contact [email protected].
You also have the right to lodge a complaint with the Information Commissioner’s Office via their phone number 0303 123 1113 or via their online complaints form https://ico.org.uk/make-a-complaint/your-personal-information-concerns/.
Copyright © SignatureRx 2023 a trading name of Signature Healthcare services Limited