Your personal data is collected by Our Pharmacy, for the purposes of allowing you to use this app. This app has been designed to enable you to send your prescriptions in advance to the pharmacy in which you have registered with the aim of reducing your waiting time in store.
Categories of Personal Data Collected
When you register in store to use this app, we require information on you such as your name, and date of birth for the purposes of verifying your identity when you download the app and to accurately register you on our database to keep a record of the prescriptions you purchase for the purposes of patient safety. We store your email address and password for authentication purposes only.
We use your location data with your permission to show nearby pharmacies, however, we do not store your location on our servers.
We access the camera and the photo gallery on your phone to scan the QR registration code and to also send a photo of your prescription to the pharmacy.
We store details of your name or the patient who you are collecting the prescription on behalf of, and you may choose to change this if you wish.
In respect of information collected on your medication, we store the drug name, strength and directions from you registered pharmacy in order for you to view this information from within the app.
We do not use information that you have provided us with through the app for marketing purposes other than where you may have opted-in separately to receive marketing communications.
Legal Basis for Collecting Personal Data
We do not require information on your health status to use the app, however, from the prescriptions that you order from us, it may be possible to infer information relating to your health from this data, and therefore we may collect information classified as special categories of data as defined under Article 9 of the General Data Protection Regulation (GDPR) and by using this app and uploading prescriptions to it you provide us with your explicit consent to process this category of data on you. We rely on your consent to contact you through the app where the pharmacist may have a query in relation to the prescription you have submitted through the app.
You are free to withdraw your consent at any time by deleting your account which removes all data from our servers.
We also rely on Article 6(f) of the GDPR to process your personal data for the purpose of running analytics on our sales and website to determine how we can optimise and improve the app for the benefit of its users.
Retention of Personal Data
Where you upload prescriptions to the app, whether on an ad hoc or repeated basis, we retain this information on the app for the purposes of ensuring we accurately dispense the repeat dosages and for the purposes of ensuring your safety and wellbeing as a patient.
We have a statutory basis for retaining this information in the interests of patient safety for a period of three years (five years in the case of unlicensed medicines) as we are obliged under Regulation 10 of the Medicinal Products (prescription and Control of Supply) Regulations 2003 (as amended) to retain prescriptions or duplicate copies of prescriptions on the pharmacy premises from the date of dispensing or in the case of repeat prescriptions from the last date of dispensing. We will therefore take a copy of the prescription when you arrive to collect the medicine and will retain this on our premises for the purposes specified.
Disclosure of Personal Data
Your data will not be shared with any third parties and will only be accessed in limited circumstances by the developers of the app with prior approval from Our Pharmacy and your explicit consent where their assistance is required with troubleshooting issues with the app. A data processing agreement has been put in place with this third party in their capacity as data processor of this data to ensure that they adequately protect your data and keep it confidential, safe and secure.
Where required by law to disclose this data to law enforcement authorities we are under a legal basis to do so.
We have implemented appropriate security measures to protect your personal data against unauthorised access, alteration, destruction or disclosure including encryption using industry standard techniques and tokenisation to mask patient details stored on our servers. The QR code used to register patients on the app also expires after 7 days to ensure that it is not misused by a third party. Access to and management of data is limited to those staff members who have appropriate authorisation. Where data is stored in hard copy format, we have procedures in place and staff training to ensure that paper records are stored securely.
Unfortunately, no data transmission over the Internet or electronic storage system can be guaranteed as secure, however, we will ensure that the technical and organisational measures in place are regularly reviewed to ensure that they are up-to-date and functioning effectively.
You have a number of rights as a data subject which you may choose to exercise at any time by contacting us
Access to Personal Data
Where you wish to access a copy of your personal data held by us, you may do so by contacting us in writing and we will respond to this request in 30 days.
Rectification or Erasure of Personal Data
Where you wish the data that we hold on you to be rectified, you have the right to request this in writing. â€¨Where you wish to exercise your right to have your personal data erased, we will do so without undue delay, subject to the exemptions provided for in Article 17(3) of the GDPR.
Restriction of processing
You have the right to obtain restriction of processing of your personal data where you contest the accuracy of the data for a period allowing us to verify the accuracy of the data; where the processing is unlawful and you oppose the erasure of your data and request the restriction of its use instead; where we no longer need the data for the purposes for which it was collected but it is required by you for legal purposes; where you have objected to the processing pursuant to Article 21(1).
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.
Right to Object
You have the right to object to the processing of your personal data where your data is processed on the basis of our legitimate interests.
Right to Complain
You also have the right to complain to the Data Protection Commission where you believe that your personal data has not been processed in compliance with this legislation.
By downloading this app you will receive push notification from our pharmacy specifically related to your prescriptions such as when we have received your order or when it is ready for collection or similar.Â Also we will from time to time send marketing messages for offers and promotions available at our Pharmacy.Â You may turn off these notifications from your handset setting or uninstall app to opt out.Â
Data Controller and Owner
Types of Data collected
Mode and place of processing the Data
Methods of processing
The Data Controller processes the Data of Users in a proper manner and shall take appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of the site (administration, sales, marketing, legal, system administration) or external parties (such as third party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Data Controller at any time.
The Data is processed at the Data Controller's operating offices and in any other places where the parties involved with the processing are located. For further information, please contact the Data Controller.
The Data is kept for the time necessary to provide the service requested by the User, or stated by the purposes outlined in this document, and the User can always request that the Data Controller suspend or remove the data.
The use of the collected Data
The Data concerning the User is collected to allow the Application to provide its services, as well as for the following purposes: Access to third party services' accounts, Location-based interactions, Content commenting and Interaction with external social networks and platforms. The Personal Data used for each purpose is outlined in the specific sections of this document.
Facebook permissions asked by this Application
By default, this includes certain Userâ€™s Data such as id, name, picture, gender, and their locale. Certain connections of the User, such as the Friends, are also available. If the user has made more of their data public, more information will be available.
Provides read access to the authorized user's check-ins
Provides access to the user's primary email address
Provides access to the list of all of the pages the user has liked.
Provides access to the photos the user has uploaded, and photos the user has been tagged in.
Publish App Activity
Allows the app to publish to the Open Graph using Built-in Actions, Achievements, Scores, or Custom Actions. The app can also publish other activity which is detailed in the Facebook's Publishing Permissions document.
Detailed information on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Access to third party services' accounts
These services allow this Application to access Data from your account on a third party service and perform actions with it. These services are not activated automatically, but require explicit authorization by the User.
Access to the Facebook account (This Application)
Content commenting services allow Users to make and publish their comments on the contents of this Application. Depending on the settings chosen by the Owner, Users may also leave anonymous comments. If there is an email address among the Personal Data provided by the User, it may be used to send notifications of comments on the same content. Users are responsible for the content of their own comments. If a content commenting service provided by third parties is installed, it may still collect web traffic data for the pages where the comment service is installed, even when users do not use the content commenting service.
Facebook Comments (Facebook)
Interaction with external social networks and platforms
These services allow interaction with social networks or other external platforms directly from the pages of this Application. The interaction and information obtained by this Application are always subject to the Userâ€™s privacy settings for each social network. If a service enabling interaction with social networks is installed it may still collect traffic data for the pages where the service is installed, even when Users do not use it.
Facebook Like button and social widgets (Facebook)
Geolocation (This Application)
This Application may collect, use, and share User location Data in order to provide location-based services. Most browsers and devices provide tools to opt out from this feature by default. If explicit authorization has been provided, the Userâ€™s location data may be tracked by this Application. Personal Data collected: Geographic position.
Additional information about Data collection and processing
The User's Personal Data may be used for legal purposes by the Data Controller, in Court or in the stages leading to possible legal action arising from improper use of this Application or the related services.
The User is aware of the fact that the Data Controller may be required to reveal personal data upon request of public authorities.
Additional information about User's Personal Data
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third party services may collect files that record interaction with this Application (System Logs) or use for this purpose other Personal Data (such as IP Address).
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Data Controller at any time. Please see the contact information at the beginning of this document.
The rights of Users
Users have the right, at any time, to know whether their Personal Data has been stored and can consult the Data Controller to learn about their contents and origin, to verify their accuracy or to ask for them to be supplemented, cancelled, updated or corrected, or for their transformation into anonymous format or to block any data held in violation of the law, as well as to oppose their treatment for any and all legitimate reasons. Requests should be sent to the Data Controller at the contact information set out above.
This Application does not support â€œDo Not Trackâ€ requests.
To determine whether any of the third party services it uses honor the â€œDo Not Trackâ€ requests, please read their privacy policies.
Definitions and legal references
Personal Data (or Data)
Any information regarding a natural person, a legal person, an institution or an association, which is, or can be, identified, even indirectly, by reference to any other information, including a personal identification number.
Information collected automatically from this Application (or third party services employed in this Application ), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refer.
The legal or natural person to whom the Personal Data refers to.
Data Processor (or Data Supervisor)
Data Controller (or Owner)
The natural person, legal person, public administration or any other body, association or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
The hardware or software tool by which the Personal Data of the User is collected.
Small piece of data stored in the User's device.
Extended policy concerning the application of the European GDPR.
In accordance with the obligations of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
Quantum Touch Limited does not own any of the client data stored or processed via the service App Content Manager.
Quantum Touch Limited is not responsible for the content of the personal data contained in the client data or other information stored on its servers.
At the discretion of the client or user nor is Quantum Touch Limited responsible for the manner in which the client or user collects, handles disclosure, distributes or otherwise processes such information.
Contact to access, correct, delete any data information
Quantum Touch Limited
Smart Fit Apps, Dublin, Ireland
Contact e-mail: email@example.com
Access, Correction, Deletion
We respect your privacy rights and provide you with reasonable access to the Personal Data that you may have provided through your use of the Services.
If you wish to access or amend any other Personal Data we hold about you or to request that we delete any information about you that we have obtained from an Integrated Service, you may contact us.
At your request we will have any reference to you deleted or blocked in our database.
You may update, correct, or delete your Account information and preferences at any time by accessing your Account settings page on the Service.
Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytic, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so
You may decline to share certain personal data with us, in which case we may not be able to provide to you some of the features and functionality of the Service.
At any time, you may object to the processing of your personal data, on legitimate grounds except if otherwise permitted by applicable law.
Intended use of personal data
Unless you want to use advanced features in applications, we do not require any form of registration, allowing you to use the application without telling us who you are.
However some services do require you to provide us with personal data.
In these situations, if you choose to withhold any personal data request by us, it may not not be possible for you to gain access to certain parts of the application and for us to respond to your query.
How we use the information we collect
We use the information that we collect in a variety of ways in providing the service and operating our business.
Including the following operations:
- Maintain, enhance and provide all features of the service, to provide the services and information that you request,
to respond to comments and questions and to provide support to users of the service we process client data solely in accordance with the directions provided by the applicable client or user improvements.
- We may use a visitor or user email address or other information other than client data to contact that visitor or user for administrative purposes such as customer service,
to address intellectual property infringement, right of privacy violations or defamation issues related to the client data or personal data posted on the service.
Latest update: April 24, 2018.