For full information on how we process and protect your data, see our full Privacy Notice here: https://www.lifepharmacy.ie/cookie-policy 


 

PRIVACY POLICY FOR THE LIFE PHARMACY APP

INTRODUCTION

Your personal data is collected by Our pharmacy, for the purpose of allowing you to use this app. This app has been designed to enable you to send your prescriptions in advance to the pharmacy in which you have registered with the aim of reducing your waiting time in store.

We are committed to protecting your personal data and this privacy policy sets out why we require your personal data, how we process it in compliance with data protection legislation and what your rights are under the legislation. You may contact us at any time to exercise your rights as a data subject or where you require further clarification on the information provided in this policy by emailing us at service@lifepharmacy.ie.

 

CATEGORIES OF PERSONAL DATA COLLECTED

When you register in store to use this app, we your name and date of birth for the purpose of verifying your identity when you download the app and to accurately register you on our database to keep a record of prescriptions you purchase for the purpose of patient safety. We store your email address and password for authentication process only.

We use your location data with your permission to show nearby pharmacies, however we do not store your location on our servers.

We access the camera and the photo gallery on your phone to scan the QR registration code and to also send a photo of your prescription to the pharmacy.

We store details of your name or the patient you are collecting the prescription on behalf of, and you may choose to change this if you wish.

In respect of information collected on your medication, we store drug name, strength, and directions from your registered pharmacy in order for you to view the information within the app.

We do not use information that you have provided us with through the app for marketing purposes other than where you may have opted in separately to receive marketing communications.

 

LEGAL BASIS FOR COLLECTING PERSONAL DATA

We do not require information on your health status to use the app, however, from the prescriptions that you order from us, it may be possible to gather information relating to your health from this data, and therefore we may collect information classified as special categories of data as defined under Article 9 of the General Data Protection Regulation (GDPR) and by using this app and uploading prescriptions to it you provide us with your explicit consent to process this category of data on you. We rely on your consent to contact you through the app where the pharmacist may have a query in relation to the prescription you have submitted through the app.

 

You are free to withdraw your consent at any time by deleting your account which removes all data from our servers.

 

We also rely on Article 6(f) of the GDPR to process your personal data for the purpose of running analytics on our sales and website to determine how we can optimise and improve the app for the benefit of its users.

 

RETENTION OF PERSONAL DATA

Where you upload prescriptions to the app, weather on an ad hoc or repeated basis, we retain the information on the app for the purpose that we accurately dispense the repeated dosages and for the purpose of ensuring your safety and wellbeing as a patient.

We have a statutory basis for retaining this information in the interest of patient safety for a period of 3 years ( 5 years in the case of unlicensed medication) as we are obliged to under Regulation 10 of the Medical Products ( prescription and Control of Supply) Regulation 2003 (as amended) to retain prescriptions or duplicate copies of the prescriptions on the pharmacy premises from the date of dispensing or in the case of repeat prescriptions from the last date of dispensing. We will therefore take a copy of the prescription when you arrive to collect the medicine and will retain this on our premises for the purposes specified.

 

DISCLOSURE OF PERSONAL DATA

Your data will not be shared with any third parties and will only be accessed in limited circumstances by the developers of the app with prior approval from Our Pharmacy and your explicit consent where their assistance is required with troubleshooting issues with the app. A data processing agreement has been put in place with this third party in their capacity, as data processers of data to ensure they adequately protect your data and keep if confidential, safe, and secure.

Where required by law to disclose this data to law enforcement authorities we are under a legal basis to do so.

 

SECURITY

We have implemented appropriate security measures to protect your personal data against unauthorised access, destruction, or disclosure including encryption using industry standard techniques and tokenisation to mask patient details stored on our server. The QR code used to register customer on the app expires after 7 days to ensure it is not misused by third parties. Access to and management of data is limited to those staff members who have appropriate authorisation. Where data is stored in hard copy format, we have procedures in place and staff training to ensure that paper records are stored securely.

Unfortunately, no data transition over the internet or electronic storage system can be guaranteed as secure, however we will ensure that the technical and organisational measures in place are up -to -date and functioning effectively.

 

YOUR RIGHTS

You have a number of rights as a data subject which you may choose to exercise at any time by contacting us

  1. Access to personal data

Where you wish to access a copy of your personal data held by us, you may do so by contacting us in writing and we will respond to this request in 30 days

 

  1. Rectification or Erasure of Personal Data

Where you wish the data that we hold on you to be rectified, you have the right to request this in writing. Where you wish to exercise the right to have your personal data erased, we will do so without undue delay, subject to the exemptions provided for in Article 17(3) of the GDPR.

 

  1. Restriction of processing

You have the right to obtain restriction of processing of your personal data where you contest the accuracy for a period allowing us to verify the accuracy of the data; where the processing is unlawful and you oppose the erasure of your data and request the restrictions of its use instead; where we no longer need the data for the purposes for which it was collected but is required by you for legal purposes; where you have objected to the processing pursuant to article 21(1).

 

  1. Right to data portability

You have the right to receive your personal data in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.

 

  1. Right to object

You have the right to object to the processing of your personal data where your data is processed on the basis of our legitimate interests 

  1. Right to complain

You also have the right to complain to the Data Protection Commissioner where you believe your personal data has not been processed in compliance with this legislation.

 

NOTIFICATIONS

By downloading this app, you will receive push notifications from our pharmacy specifically related to your prescriptions such as when we have received your order or when it is ready for collection or similar. Also, from time to time we will send marketing messages for offers and promotions available at our Pharmacy.  You may turn off these notifications from your handset settings or uninstall the app to opt out.

 

DATA CONTROLLER AND OWNER

TYPES OF DATA COLLECTED

Among the types of personal data that this application collects, by itself or through third parties are: Geographic positions, Cookie and Usage data. Other personal data collected may be described in other sections of the privacy policy or by dedicated explanatory text contextually with the Data Collection. The Personal Data may be freely provided by the user or collected automatically when using this Application. Any use of Cookies – or other tracking tools , by this Application of the owners of a third party services used by the Application, unless stated otherwise serves to identify Users and remember their preferences, for the sole purpose of providing the service required by the User. Failure to provide certain Personal Data may make it impossible for this Application to provide its services. The User assumes responsibility for the personal data of third parties published or shared through this Application and declares to have the right to communicate or broadcast them, thus relieving the Data Controller of all responsibility

 

MODE AND PLACE OF PROCESSING THE DATA

METHODS OF PROCESSING

The Data Controller processes the Data of Users in a proper manner and shall take appropriate security measures to prevent unauthorised access, disclosure, modification or unauthorised destruction of Data. The Data processing is carried out using computer and or / IT enabled tools, following organisational procedures and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of people in charge, involved in the operation of the site (administration , sales marketing ,legal and system administration) or  external parities such as ( third party technical service providers, mail carriers, hosting providers, IT companies and communication agencies) appointed, if necessary, as Data Processors by the owner. The updated list of these parties may be requested from the Data Controller at any time.

 

PLACE

The Data is processed at the Data Controllers operating offices and in other places where the parties involved in the processing are located. For further information please contact the Data Controller.

 

RETENTION TIME

The Data is kept for the time necessary to provide the service requested by the User, or stated by the purpose outlined in this document, and the User can always request that the Data Controller suspend or remove the data.

 

THE USE OF COLLECTED DATA

The data concerning the user is collected to allow the Application to provide its services, as well as for the following purposes: Access to third party service account, Location based interactions, Content commenting and Interaction with external social networks and platforms. The Personal Data used for each purpose is outlined in the specific sections of this document.

 

DETAILED INFORMATION ON THE PROCESSING OF PERSONAL DATA

Personal data is collected for the following purposes and uses the following services

 

ACCESS TO THIRD PARTY SERVICE ACCOUNTS

These services allow applications to access data from your account on a third-party service and preform actions with it. These services are not activated automatically but require explicit authorization by the User.

 

LOCATION BASED INTERACTIONS

GEOLOCATION (THIS APPLICATION)
This Application may collect, use, and share User location Data in order to provide location-based services. Most browsers and devices provide tools to opt out from this feature by default. If explicit authorisation has been provided, the User’s location data may be tracked by this Application. Personal Data collected: Geographic position.

 

ADDITIONAL INFORMATION ABOUT DATA COLLECTION AND PROCESSING

LEGAL ACTION

The User's Personal Data may be used for legal purposes by the Data Controller, in Court or in the stages leading to possible legal action arising from improper use of this Application or the related services.
The User is aware of the fact that the Data Controller may be required to reveal personal data upon request of public authorities.

 

ADDITIONAL INFORMATION ABOUT USER’S PERSONAL DATA

In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular services or the collection and processing of Personal Data upon request.

 

SYSTEM LOGS AND MAINTENANCE

For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System Logs) or use for this purpose other Personal Data (such as IP Address).

 

INFORMATION NOT CONTAINED IN THIS POLICY

More details concerning the collection or processing of Personal Data may be requested from the Data Controller at any time. Please see the contact information at the beginning of this document.

 

 

 

THE RIGHTS OF THE USER

Users have the right, at any time, to know whether their Personal Data has been stored and can consult the Data Controller to learn about their contents and origin, to verify their accuracy or to ask for them to be supplemented, cancelled, updated or corrected, or for their transformation into anonymous format or to block any data held in violation of the law, as well as to oppose their treatment for any and all legitimate reasons. Requests should be sent to the Data Controller at the contact information set out above.
This Application does not support “Do Not Track” requests.
To determine whether any of the third party services it uses honour the “Do Not Track” requests, please read their privacy policies.

 

CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to make changes to this privacy policy at any time by giving notice to its Users on this page. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom. If a User objects to any of the changes to the Policy, the User must cease using this Application and can request that the Data Controller erase the Personal Data. Unless stated otherwise, the then-current privacy policy applies to all Personal Data the Data Controller has about Users.

 

DEFINITIONS AND LEGAL REFERENCES

PERSONAL DATA (OR DATA)

Any information regarding a natural person, a legal person, an institution or an association, which is, or can be, identified, even indirectly, by reference to any other information, including a personal identification number.

 

USAGE DATA

Information collected automatically from this Application (or third party services employed in this Application ), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.

 

USER

The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refer.

 

DATA SUBJECT

The legal or natural person to whom the Personal Data refers to.

 

DATA PROCESSOR (OR DATA SUPERVISOR)

The natural person, legal person, public administration or any other body, association or organization authorized by the Data Controller to process the Personal Data in compliance with this privacy policy.

 

 

 

DATA CONTROLLER (OR OWNER)

The natural person, legal person, public administration or any other body, association or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.

 

THIS APPLICATION

The hardware or software tool by which the Personal Data of the User is collected.

 

COOKIE

Small piece of data stored in the User's device.

 

LEGAL INFORMATION

Notice to European Users: this privacy statement has been prepared in fulfilment of the obligations under Art. 10 of EC Directive n. 95/46/EC, and under the provisions of Directive 2002/58/EC, as revised by Directive 2009/136/EC, on the subject of Cookies. This privacy policy relates solely to this Application.