PRIVACY POLICY
Welcome to Medicinex - Your Trusted Online Pharmacy
Privacy policy
Last updated: August 2025
At Medicinex, we are committed to protecting your privacy and handling your personal data with transparency, care and in compliance with UK data protection law including the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
This Privacy Policy explains how we collect, use, store and protect your personal data when you use our website and services.
1. Who we are
Medicinex is a UK-based online pharmacy registered with the General Pharmaceutical Council (GPhC) and complies fully with all UK legal and professional standards.
Data Controller:
WebPharmaHub Limited
1 Canute Road, Southampton, SO14 3FH, United Kingdom
ICO Registration Number:
Email: support@medicinex.co.uk
2. What information we collect
When using our website or pharmacy services, we may collect and process the following information:
Personal Information
- Name
- Date of birth
- Gender
- Delivery and billing address
- Email address
- Phone number
Health and Medical Information
- Responses to online consultation questionnaires
- Medical history, allergies, current medications
- Consultation records (via form, phone, video)
- National Care Records: Information accessed via the National Care Records Service (NCRS), including your Summary Care Record (SCR), medication history and any clinical flags or alerts.
Technical Data
- IP address
- Device type and browser
- Cookies and usage data
Payment Information
- Cardholder details (processed securely via PCI-DSS compliant third parties)
- Billing address
We collect this information when you:
- Register an account
- Complete a medical questionnaire
- Place an order
- Contact our support team
- Visit or browse our website (via cookies)
3. How we use your information
Your data is used solely to provide a safe, secure and effective pharmacy service.
We may use your information to:
- Process and deliver your orders
- Conduct clinical assessments: Our prescribing pharmacists use your provided data and the National Care Records Service (NCRS) to make informed clinical decisions. Accessing these records allows us to safeguard your health by verifying your medical history and ensuring our care is tailored to your specific needs.
- Conduct clinical assessments and consultations
- Maintain and update medical records
- Communicate about your treatment or orders
- Verify your identity
- Comply with UK legal, regulatory and pharmaceutical obligations
- Improve website functionality and customer experience
We do not use your data for marketing without your explicit consent
4. Legal basis for processing
Under UK GDPR, we rely on the following lawful bases:
- Consent - for marketing communications and data sharing
- Contract - to deliver goods and services you request
- Legal Obligation - to meet our responsibilities as a registered pharmacy
- Vital Interests - to protect your health in emergencies
- Legitimate Interests - for fraud prevention, business operations
- Public Task/Healthcare- For the provision of direct healthcare and the management of social care systems (specifically regarding NCRS access)
5. Who we share your data with
We may share your data with trusted third parties, only when necessary:
- NHS England & NCRS: We access and share summary information via the National Care Records Service to ensure clinical safety
- GPhC, MHRA or NHS bodies for regulatory compliance and audits
- Registered prescribers involved in your care
- Couriers to fulfil delivery (Royal Mail, DPD)
- Payment processors (e.g. Stripe, PayPal)
- IT providers for secure system management¸
6. Data retention
We retain your personal and medical records for at least 8 years after the date of your last interaction, in accordance with professional and legal standards (e.g. GPhC, NHS guidance).
7. How we protect your data
We use strong physical, technical, and organisational safeguards, including:
- SSL encryption on all website traffic
- Encrypted data storage
- Secure NHS CIS2 Authentication for accessing national records
- Password-protected systems
- Staff training in data protection and information governance
- Secure consultation forms
- Regular IT audits and risk assessments
8. Your rights
Under UK GDPR, you have the following rights:
- Access your personal data
- Correct inaccurate or incomplete data
- Request data deletion (where lawful)
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time
To exercise any of your rights, contact our Data Protection Officer:
- Data Protection Officer
- WebPharmaHub Limited
- Email: support@medicinex.co.uk
- Phone: 02382515648
9. Cookies
We use cookies to enhance your browsing experience and collect anonymised analytics. You can manage your cookie preferences via your browser settings.
Please refer to our separate Cookie Policy for more details.
10. External links
Our website may contain links to third-party websites. We are not responsible for their content or privacy practices. Please review their privacy policies if you choose to visit them.
11. Changes to this Privacy Policy
We may update this policy from time to time to reflect changes in law or our services. All changes will be posted on this page with the latest revision date.
12. Contact us
If you have any questions, complaints, or concerns about this Privacy Policy or how we handle your data, please contact:
- Data Protection Officer
- WebPharmaHub Limited
- Email: support@medicinex.co.uk
- Phone: 02382515648
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
🔗 www.ico.org.uk