FAQs

Personal information we collect about you  

We may collect and use the following personal information about you:  

  • your name and contact information, including postal address, email address and telephone number;   

  • information to enable us to check and verify your identity, e.g. your date of birth, scanned images of your exemption certificates, driving licence or passport;   

  • your gender information;  

  • your NHS number;  

  • information about your medicines, and the medicines you have been prescribed currently and in the past;  

  • your billing information, transaction and payment card information;   

  • your contact history, purchase history and saved items;   

  • information about how you use our website, information technology (IT), communication and other systems; and  

  • your responses to surveys, competitions and promotions.  

Personal information is required to provide our services to you. If you do not provide personal information we ask for, it may delay or prevent us from providing services to you.  

 

How your personal information is collected  

We collect most of this personal information directly from you—in person, by telephone, text or email and/or via our website and apps. However, we may also collect information:   

  • from a third party with your consent, e.g. your General Practitioner, NHS login or the NHS Spine system, which is the main database of your medical history with the NHS; 

  • from cookies on our website - for more information on our use of cookies, please see our https://www.codapharmacy.co.uk/cookie-policy  

  • via our IT systems, e.g. automated monitoring of our websites and other technical systems, such as our computer networks and connections

     

How and why we use your personal information  

 

In general, we only collect your information to provide you with our services – to help you order and keep track of your prescriptions and to dispense your prescriptions. We take our data protection responsibilities very seriously and will only process your information where we have a lawful basis for doing so. This will be the case if:

 

- You have given us your consent to process the data.

- We need to process the data to perform our contractual obligations or to take steps to enter a contract (for example, we need certain contact details and details of your prescription in order to provide the service to you).

- We have to process your information to meet our legal obligations as a data controller (such as VAT and tax accounting rules).

- We have a legitimate interest in processing your data (this includes things like improving our service by collecting behavioural information to see what actions are taken within the app, auditing and investigation of any issues).

 We collect and process your information for a variety of purposes, but our main purpose is to provide the services you request. These include:

 - Storing your data in databases so that we can create and maintain your account.

- Verifying your identity so that we can complete your registration

- Communicating with GP surgeries and internally so that your orders can be processed and your prescriptions dispensed.

- Auditing and analysis of your data, in particular to help us respond to issues and improve our services.

- Managing returns and confidential waste.

- Communicating to you via in-app messaging services and logging these communications to ensure we give you the best customer experience.

- Communicating to you via email, push alerts and in-app notifications so that you are fully updated with the progress of your order and any related communications.

- On the rare occasion, we may need to contact you; this would only be in relation to your order, a query you have raised.

- we process your data not only to provide you with our direct services but also to facilitate a cohesive and enhanced service experience across the pharmacy group. This involves working collaboratively within the group to improve prescription services, streamline our operations, and deliver a seamless patient experience in line with our unified brand strategy. This may include sharing your data within the group entities where necessary to fulfil our service commitments to you and to realise our goal of continuous service improvement. All such processing is grounded in our legitimate interest to optimise our service delivery and in some cases may be based on your consent or as part of our contractual obligation to you.

 By using our service, you acknowledge and agree to the terms outlined in our Privacy Notice. This agreement is effective from registration