Privacy Policy
Last updated: 26 May 2026
On this page
Who we are
The data controller is Medway Pharmacy, 465 Canterbury Street, Gillingham, Kent, ME7 5LJ. We are registered with the General Pharmaceutical Council (GPhC No. 1121209).
What data we collect
We collect information you provide when booking an appointment or contacting us, including your name, email address, phone number, date of birth, and travel health history relevant to your consultation. Vaccination records and health information are special category data under UK GDPR Article 9 and are handled with additional care.
Lawful basis for processing
We process your personal data on the following lawful bases:
- Contract — to manage your appointment and deliver the service you have requested (Article 6(1)(b)).
- Legal obligation — to comply with our regulatory duties as a GPhC-registered pharmacy (Article 6(1)(c)).
- Legitimate interests — to respond to enquiries and improve our services (Article 6(1)(f)).
- Health care provision — for special category health data, we rely on Article 9(2)(h) (provision of health care) and, where required, your explicit consent.
How we use it
Your data is used to manage your appointments, provide travel health advice, issue vaccination certificates, and comply with our legal and regulatory obligations as a registered pharmacy. We do not use your data for marketing without your explicit consent.
Third parties
We use the following third-party processors to operate our service:
- SimplyBook.me — appointment booking system. Data is processed in the EU under GDPR-compliant terms.
- Resend — transactional email delivery for form submissions.
- Vercel Web Analytics — anonymous, cookieless page analytics.
- Google Analytics— website analytics, if enabled in production. Governed by Google's Data Processing Agreement.
We do not sell your data to third parties or share it for advertising purposes.
Data retention
We retain health and vaccination records for a minimum of eight years from the date of last contact, in line with NHS and GPhC guidance. Non-clinical data (enquiries, contact messages) is deleted within 24 months of your last interaction.
Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate or incomplete data
- Request erasure of your data (where no legal obligation to retain it exists)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time where consent is the lawful basis
To exercise any of these rights, contact us using the details below.
Cookies
This website uses only essential cookies required for it to function correctly. See our Cookie Policy for full details.
Contact
For any privacy-related queries please contact our Data Protection lead at medwaypharmacy.gillingham@gmail.com or by post at 465 Canterbury Street, Gillingham, Kent, ME7 5LJ.