Privacy notice
Draft. This page is being reviewed by our legal and data-protection advisers and may change before PharmaOS launches. Details in [square brackets] are still to be confirmed. Last updated 29 September 2026.
The short version
- When you book, the pharmacy is responsible for your information; we process it for them.
- We collect what's needed to book and remind you: name, date of birth, contact details and appointments.
- Your data is stored in London. Card details stay with Stripe.
- We don't sell data, show adverts or use analytics cookies.
- You can ask for a copy of your data or for it to be deleted.
1.Who we are
PharmaOS is run by SiteGrowth [SiteGrowth Ltd, company number and registered address to be confirmed]. PharmaOS gives UK community pharmacies online booking: a booking page, a diary and payments.
When you book with a pharmacy, that pharmacy is responsible for your information (the data controller). We process it on the pharmacy's behalf, under a data processing agreement, and only to run the service for them.
We are the data controller for your PharmaOS sign-in account, for pharmacy staff accounts, for pharmacies' claims and subscriptions, and for messages sent through our website.
2.What we collect
Patients booking with a pharmacy:
- your name, date of birth, email address and phone number;
- your appointments: the pharmacy and branch, the service, the date and time, the price and whether you have paid, attended or cancelled;
- requests you make about your data, such as a request to delete it.
The service you book can reveal something about your health, which is special category data under UK GDPR, so it gets extra protection. PharmaOS is not a clinical record: your consultation notes and prescriptions stay in your pharmacy's own clinical systems.
Pharmacy staff: name, work email, role, the branches you work at, working hours, and for prescribers your GPhC registration number. For pharmacies that claim a listing: the GPhC premises number, the superintendent pharmacist's name and the claimant's contact details.
Everyone who signs in: your email address, the one-time codes we send you (kept for 10 minutes), and for staff an authenticator app secret. For security we record sign-ins and sensitive actions with the IP address and browser used.
Payments: card payments are made on Stripe. We never see or store card details; we keep the amount, status and Stripe's reference.
Our website's contact form: your name, email, optional pharmacy name and your message.
3.How we use it, and our legal reasons
- To book and manage appointments for the pharmacy you choose, send confirmations and a reminder the day before, and take payment. The pharmacy relies on providing you with health care (UK GDPR Articles 6(1)(b) and 9(2)(h)) [to be confirmed with each pharmacy's own notice].
- To run your account and keep it secure: sign-in codes, two-step sign-in for staff, rate limits and security logs (our legitimate interests in protecting the service, and our duty to keep data secure).
- To provide PharmaOS to pharmacies: accounts, checking pharmacies against the GPhC register, subscriptions and invoices (contract; legal obligations such as keeping tax records).
- To answer messages sent through our contact form (legitimate interests).
We don't sell personal data, show adverts, or use your information for marketing without asking. Booking emails leave out the name of the service, so a shared inbox doesn't reveal why you're visiting.
5.How long we keep it
- Booking records are kept for as long as the pharmacy needs them for its records, then deleted or anonymised [retention period to be agreed with pharmacies].
- Deletion requests: when a pharmacy approves one, your details are anonymised straight away.
- Sign-in codes expire after 10 minutes; staff are signed out after 30 minutes of inactivity and after 12 hours at most.
- Staff notifications are deleted after 90 days.
- Security logs and the audit log are kept to protect the service and show who changed what [retention period to be confirmed].
- Contact form messages are kept in our inbox while we help you [retention period to be confirmed].
6.Your rights
Under UK GDPR you can ask to:
- get a copy of your information;
- correct information that's wrong;
- have your information deleted;
- restrict or object to how it's used;
- receive it in a format you can take elsewhere.
For your bookings, ask the pharmacy: it is responsible for them, and you can ask for your data to be deleted from your bookings page on its site. The pharmacy must answer within one month. For your PharmaOS account, or if you're not sure who to ask, email info@pharmaos.co.uk.
8.How we protect it
Data is stored in London and encrypted in transit and at rest. There are no passwords to leak, staff use two-step sign-in, and every change to patient and appointment data is written to a tamper-evident audit log. Read more about security.
9.Complaints
If you're unhappy with how your information has been used, please tell us first at info@pharmaos.co.uk. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
10.Changes to this notice
We'll update this notice when how we use information changes, and change the date at the top. If a change affects you significantly, we'll tell you by email.
Email info@pharmaos.co.uk and we'll reply within one working day.