In short
We collect only what we need to dispense your medicines, run your appointments and meet our NHS and GPhC obligations. We never sell your data. Your health records are held under strict professional confidentiality.
1. Who we are
St Matthew's Pharmacy ("we", "us", "our") is the data controller for the personal data described in this notice.
- Address: 44 Malabar Road, Leicester, LE1 2PD
- Email: info@stmatthewspharmacy.co.uk
- Telephone: 0116 360 2000
- Registered company name: St Matthew's Pharmacy Ltd
- Company registration number: 16919271
- GPhC premises registration number: 1034117
- Superintendent Pharmacist: Muhammad Shafire Rashid, GPhC No. 2237265
- ICO registration number: [ICO NUMBER — ADD WHEN REGISTERED]
2. What personal data we collect
Depending on how you use our services, we may collect:
- Identity and contact details — your name, date of birth, postal address, email address and telephone number.
- Health information — your medical history, current and past medication, allergies, symptoms, consultation notes, test results and details of any treatment we supply. This is special category data under UK GDPR.
- Appointment details — the service booked, the date and time, and any information you give us when booking (for example your destination country for travel vaccinations, or a brief description of your symptoms).
- NHS information — your NHS number, GP surgery, and prescription exemption status where relevant.
- Technical data — your IP address, browser type and device information, and data collected by cookies when you use this website. See our Cookie Policy.
- Correspondence — records of emails, messages and calls between you and us.
3. Why we use your data, and our lawful basis
Under UK GDPR we must have a lawful basis under Article 6 for all personal data, and an additional condition under Article 9 for health data. Ours are set out below.
| What we do | Article 6 basis | Article 9 condition (health data) |
|---|---|---|
| Dispensing medicines and providing pharmacy services, clinical consultations and treatment | Legal obligation, and public task for NHS services | Article 9(2)(h) — provision of health care and treatment, and management of health care systems. DPA 2018 Schedule 1, Part 1, paragraph 2. |
| Managing appointments, confirmations and reminders | Contract, and legitimate interests in running the pharmacy efficiently | Article 9(2)(h) where the booking discloses health information |
| Meeting NHS, GPhC and medicines legislation requirements, including record keeping and audit | Legal obligation | Article 9(2)(h) and, where applicable, Article 9(2)(i) — public interest in public health |
| Responding to enquiries sent through this website or by email | Legitimate interests in answering the people who contact us | Article 9(2)(h) if you choose to include health information |
| Emergency care where you are physically or legally incapable of giving consent | Vital interests | Article 9(2)(c) — vital interests. This applies only in genuine emergencies. |
| Keeping this website secure and working properly | Legitimate interests in the security and integrity of our systems | Not applicable |
All health professionals also owe you a separate common law duty of confidentiality, which applies alongside data protection law.
4. Who we share your data with
We do not sell your personal data, and we never use it for advertising. We share it only where we need to:
- NHS England and NHS bodies — for the NHS services we provide, including the Electronic Prescription Service, Pharmacy First and payment for NHS services.
- Your GP and other healthcare professionals — where it is necessary for your care, for example sending a consultation record to your surgery.
- Cal.com — our online appointment booking provider, which processes the details you enter when booking.
- Resend — the email delivery service that sends us your EPS nomination form when you submit it on this website.
- Microsoft 365 — our email provider, which processes correspondence between us.
- Netlify — our website hosting provider, which processes technical data such as IP addresses in server logs, and any enquiry form submissions.
- Regulators and authorities — such as the GPhC, the Care Quality Commission, NHS counter-fraud bodies, the police or the courts, where we are legally required or permitted to disclose.
- Our professional advisers and insurers — where necessary, for example to defend a legal claim.
Where a supplier processes data on our behalf they act as our processor under a written contract, and may only use your data on our instructions.
5. Transfers outside the UK
Some of our suppliers, including Cal.com, Microsoft and Netlify, may process data outside the United Kingdom. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, so that your data keeps essentially the same protection it has in the UK. You can ask us for details of the safeguards that apply.
6. How long we keep your data
| Record | Retention period |
|---|---|
| Health and clinical records, including consultations and treatment supplied | 8 years from the date of the last entry, in line with GPhC and NHS records management guidance. For patients under 18, until their 25th birthday. |
| Booking and appointment records | 2 years |
| Email and written correspondence | 2 years |
| Private prescriptions and controlled drug registers | As required by medicines legislation, generally 2 to 7 years depending on the record |
| Website server logs and cookie data | See our Cookie Policy |
When a retention period ends we securely delete or destroy the records.
7. Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data — which is what this notice is for.
- Access your data and receive a copy, usually within one month and free of charge.
- Rectification — have inaccurate data corrected or incomplete data completed.
- Erasure — ask us to delete your data. This right is limited where we must keep clinical records to meet legal and professional obligations.
- Restrict processing in certain circumstances.
- Object to processing carried out on the basis of legitimate interests.
- Data portability — receive data you gave us in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, where we rely on consent.
- Not be subject to automated decision making. We do not make decisions about you by automated means.
To exercise any of these rights, contact us at info@stmatthewspharmacy.co.uk or write to us at the address above. We may ask you to verify your identity before we release health information.
8. How we protect your data
We use appropriate technical and organisational measures to keep your data safe, including access controls, secure NHS-approved systems, encrypted connections on this website, staff confidentiality training, and restricting access to health records to those who need it for your care.
9. Children
Some of our services, including NHS Pharmacy First, are available to children. Where we treat a child we hold their records with the same protection as any other patient. A person with parental responsibility may exercise data protection rights on behalf of a child who is not able to do so themselves.
10. Complaints
If you are unhappy with how we have handled your data, please contact us first at info@stmatthewspharmacy.co.uk so we can try to put it right.
You also have the right to complain to the Information Commissioner's Office at any time:
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline: 0303 123 1113
- ico.org.uk/make-a-complaint
11. Changes to this notice
We review this notice regularly and will update this page whenever it changes. Please check back from time to time.
Last updated: July 2026