Privacy Policy

Our Privacy Notice describes the categories of personal data we process and for what purposes. We are committed to colleting and using such data fairly and in accordance with the requirements of the General Data Protection Regulations (GDPR).

1. Introduction

1.1 We take your privacy seriously and you can find out more here about your privacy rights and how we gather, use and share your personal information – that includes the personal information we already hold about you now and the further personal information we might collect about you, either from you or from a third party. How we use your personal information will depend on the products and services we provide to you.

1.2 Our Data Protection Officer (DPO) provides help and guidance to make sure we apply the best standards to protecting your personal information. Our DPO can be reached by post at 20 Spelman street, London, E1 5LQ or by email on [email protected], if you have any questions about how we use your personal information.

1.3 This Privacy Notice provides up to date information about how we use your personal information and will update any previous information we have given you about using your personal information (also referred to as personal data). If we make any changes affecting how we use your personal information, we will update this web page with an updated date displayed at the top of this page, so please check back regularly for updates. Our website will always show our most up to date version of our Privacy Notice.

2. About Us

We are what is known as the ‘controller’ of personal information we gather and use. When we say ‘we’ or ‘us’ in this Privacy Notice, we mean the XRP health ltd, trading under the brands We are all registered with the data protection supervisory authority, the Information Commissioner’s Office (ICO), as data controllers.

3. Your Privacy Rights

3.1 You have the right to object to how we use your personal information. You also have the right to see what personal information we hold about you, to ask us to correct any inaccuracies and to ask for some of your personal information to be provided to someone else. In addition, when permitted by law, you can ask us to delete or restrict personal information we hold about you. To exercise your right to access your personal information please contact us by post at 20 Spelman street, London E1 5LQ or by email [email protected].

3.2 Right to object:
You can object to our processing of your personal information by providing details of your objection to us.

3.3 Access to your personal information
You can request access to a copy of your personal information that we hold, along with information on what personal information we use, why we use it, who we share it with, how long we keep it for and whether it has been used for any automated decision making. You can make a request for access free of charge by contacting us. Please make all requests for access in writing, and provide us with evidence of your identity. See Proof of identity checklist - GOV.UK for information on the documents you’ll need to provide.

3.4 Right to withdraw consent
If you have given us your consent to use personal information, you can withdraw your consent at any time.

3.5 Rectification
You can ask us to change or complete any inaccurate or incomplete personal information held about you.

3.6 Erasure
You can ask us to delete your personal information where it is no longer necessary for us to use it, you have withdrawn consent, or where we have no lawful basis for keeping it. We have the right to refuse to comply with a request for erasure where the personal data is processed for one of the following reasons:

  • we need to use the information to perform a task carried out in the public interest, to provide healthcare or treatment or it is necessary for the reasons of public health in the public health arena;
  • we need to use the information to comply with our legal obligations;
  • archiving purposes in the public interest, scientific research, historical research or statistical purposes; or
  • the exercise or defense of legal claims.

3.7 Portability
You can ask us to provide you or a third party with some of the personal information that we hold about you in a structured, commonly used, electronic form, so it can be easily transferred.

3.8 Restriction
You can ask us to restrict the personal information we use about you where you have asked for it to be erased or where you have objected to our use of it.

3.9 Make a complaint
You can make a complaint about how we have used your personal information to us, by contacting us at 20 Spelman Street, London, E1 5LQ or by email on [email protected]. You can also make a complaint to the data protection supervisory authority, the ICO, at We will not make any charge for responding to any request from you to exercise your privacy rights, and we will respond to your requests in accordance with our obligations under data protection law.

4. What Kinds Of Personal Information We Use

4.1 We use a variety of personal information depending on the products and services we deliver to you.

  • to provide most of our products and services we need to know your name, address, date of birth, contact details (phone and email address) and details of your GP/surgery;
  • to provide many of our products and services which are pharmacy or healthcare related we will need information about your health, your medication and your NHS number; and
  • to provide our products and services to you we may need to obtain your payment details.

4.2 Sometimes where we ask for your personal information it is needed to fulfill a contract with you or to meet a legal obligation (such as dispensing a prescription) and we will not be able to provide some of our products or services without that personal information.

4.3 No credit/debit card payment details are stored by us. For any repeat orders of products or services made by you online via our website or app or if you opt to have your details stored for future payments, our third-party Processing Agency securely holds your credit/debit card details and provides us with a unique token that represents that particular card; this token is only valid for payment to us.

Find out more about additional personal information we gather: For some products and services, we need to use additional personal information which we will gather about you, or we will not be able to provide any of these products and services to you.

5. How We Gather Your Personal Information

We obtain personal information:

  • directly from you, for example when you fill out a consent form to receive a product or service, when you have a prescription dispensed in one of our pharmacies, or when you use our online pharmacy services for dispensing prescriptions or providing products and services where we ask you to give us health related information online;
  • indirectly from you, for example when you use our website, or post comments on our Facebook page or other social media. We collect certain usage information when you utilize our website such as Internet Protocol (“IP”) addresses, log files, unique device identifiers, pages viewed, browser type, any links you click on to leave or interact with our website and the products and services we offer, and other usage information collected from cookies and other tracking technologies. For example, we collect IP addresses to track and aggregate non-personal information, such as using IP addresses to monitor the regions from which users navigate our website. We may also collect IP addresses from users when they log into our website as part of our log-in and security features. We may also, when you enable location based-services, collect Global Positioning System (GPS) location data and/or motion data;
  • from other organizations which hold commercially-available data such as the electoral roll and companies that collate and update data. This helps us to keep our records up to date and learn more about our customers so we can improve our products and services;
  • from NHS bodies such as your GP/surgery or hospital and, if we have your consent to do so, from viewing your Summary Care Record;
  • information provided by other people on your behalf, for example, if someone books an appointment on your behalf. We will need to ask them basic details about you, which may include health details such as family history of diseases. We will always check with you that any such details provided are accurate when you come to see us; and We also may obtain some personal information from monitoring or recording calls and when we use CCTV. We may record or monitor phone calls with you for regulatory purposes, for training and to ensure and improve quality of service delivery, to ensure safety of our staff and customers, and to resolve queries or issues. We may also use CCTV on our premises to ensure the safety and security of our staff and customers.

6. How We Use Your Personal Information

We use your personal information:

  • to provide our products and services, respond to queries and comments, to collaborate with others to improve our products and services and to provide you with the best possible level of customer service. We may use it to contact you about appointments you have booked or to send you reminders (e.g. about repeat prescriptions or notification that your prescriptions are ready for collection);
  • to learn more about you. We’ll consolidate the information we hold about you across the companies in our Group and the different channels you use to interact with us (e.g. in store, via our app, by phone and correspondence etc.). We do this to keep our records accurate and up to date, provide you with a seamless and consistent service and to build a clearer picture of our customers, both individually and as a group. By understanding you better we can offer you the best and most personalized service we can, but don’t worry – we will only send you marketing material if you have agreed that we can;
  • to protect our customers, our staff and our business. We may use your personal data to help prevent and detect crime. We use CCTV to record images in our stores and, if requested, we may pass it on to the police; and
  • to fulfill our contractual requirements with the NHS. We need to share your personal information with your GP and others in the wider NHS, such as the NHS Business Services Authority, and sometimes Local Authorities to provide you with NHS or Local Authority funded services, to negotiate and check the accuracy of our payments with the NHS or Local Authorities and to ensure that we maintain appropriate professional and service standards and that your declarations and ours are accurate.

7. Automated Decision Making

We do not use any automated decision-making processes.

8. Our legal basis for using your personal information

8.1 We only use your personal information where that is permitted by the laws that protect your privacy rights. We only use personal information where:

  • we have your consent (if consent is needed);
  • we need to use the information to perform a task carried out in the public interest, to provide health care or treatment or it is necessary for reasons of public health in the public health arena;
  • we need to use the information to comply with our legal obligations;
  • we need to use the information to perform a contract with you; or
  • it is fair to use the personal information either in our interests or someone else's interests, where there is no disadvantage to you – this can include where it is in our interests to contact you about appropriate products or services or collaborate with others to improve our products and services

Where we have your consent, you have the right to withdraw it. We will let you know how to do that at the time we gather your consent.

8.2 Special protection is given to certain kinds of personal information that is particularly sensitive. This is information about your health status, medication, racial or ethnic origin, religious or similar beliefs, and sex life or sexual orientation. We will only use this kind of personal information where:

  • required to deliver pharmacy and healthcare products and services to you;
  • we have a legal obligation to do so (for example to protect vulnerable people);
  • it is necessary for us to do so to protect your vital interests (for example if you have a severe and immediate medical need whilst on our premises);
  • it is in the substantial public interest; or
  • you have specifically given us explicit consent to use the information.

Find out more about how we use special categories of personal information for the following purposes:

Health and Medication information

We will use your health and medication information provided to dispense and deliver to you your prescriptions or provide other healthcare products and services you have requested. We will never use information about your prescriptions for marketing, although we may use it to advise you of other health services/products that might be useful or relevant to you, such as our new medicine service or medicines use review; and if we need to provide you with urgent medical assistance when you are on our premises.


Sometimes prescriptions we dispense for you will reveal special categories of information (such as your health status, religious beliefs and sex life or sexual orientation). This information may be processed by us to dispense your prescriptions to you and will not be used for any other purpose.

9. Sharing Your Personal Information With Or Getting Your Personal Information From Others

9.1 We will share personal information within with other organizations where we need to do that to make our products and services available to you, to contact you about appropriate products and services, to meet or enforce a legal obligation or where it is fair and reasonable for us to do so. See section 6 How we use your personal information for more information about how we do this. We will only share your personal information to the extent needed for those purposes.

9.2 Who we share your personal information with depends on the products and services we provide to you and the purposes we use your personal information for. For most products and services, we will share your personal information with our own service providers such as our IT Suppliers, couriers, mailing houses, manufacturers and suppliers. See section 6 How we use your personal information for more information on who we share your personal information with and why.

9.3 Most of the time the personal information we have about you is information you have given to us, or is gathered by us in the course of providing products and services to you. We also sometimes gather personal information from and send personal information to third parties (such as NHS bodies) where necessary so we can fulfill our legal obligations as a provider of pharmacy and healthcare products and services. See section 6 How we use your personal information for more information on who we get your personal information from and why.

10. Transfers Outside The UK

10.1 We may need to transfer your information outside the UK to service providers, agents and subcontractors in countries where data protection laws may not provide the same level of protection as those in the European Economic Area, such as the USA.

Find out more about how we transfer your data outside of the UK

We may need to transfer your personal information to territories that are outside the EEA. We will only transfer your personal information outside the EEA where either the transfer is to a country which the EU Commission has decided ensures an adequate level of protection for your personal information, or we have put in place our own measures to ensure adequate security as required by data protection law. These measures include ensuring that your personal information is kept safe by carrying out strict security checks on our overseas partners and suppliers, backed by strong contractual undertakings approved by the relevant regulators such as the EU style model clauses

You can find out more information about standard contractual clauses as detailed by the ICO. Visit their website at and search for ‘International transfers’.

11. How Long We Keep Your Personal Information For

We need your personal information for as long as we have a legal or business reason to do so, which generally means as long as you remain a customer of or as requested to meet our legal obligations, resolve disputes or enforce our agreements. To fulfil our obligations to NHS, regulatory or similar bodies, health related personal information may need to be retained for a period of time after you cease to be a customer. We will always store it securely and not use it for any other purpose.

12. Keeping you up to date

12.1 We will communicate with you about products and services we are delivering using any contact preferences you have given to us - for example by post, email, text message, social media, and notifications on our app or website

12.2 Where you have given us consent to receive marketing, you can withdraw consent or update your details by contacting us by post at 20 Spelman Street, London, E1 5LQ or by email [email protected].

13. Your Online Activities

13.1 We use cookies and other tracking technologies to track your use of our website and our other online services.

13.2 Find out more about cookies and other tracking technologies

A cookie is a small file which is sent to your browser and stored on your computer's hard disc and helps us understand and track your use of our website and other online services and where we can improve the information and services provided. We use cookies solely to gather information on IP addresses, to analyze trends, administer our website and other online services, track your movements on the website and on our other online services and gather broad demographic information for aggregate use. For information about blocking the use of cookies, please refer to the instructions/help screen on your internet browser. Please note that you may not be able to use or access certain parts of the website or our online services if you block the use of all cookies.