Trusted family run Cheltenham community pharmacy serving you for 20+ years now. Offering NHS & Private Treatements

We believe that true healing happens in a space where you feel safe, heard and understood. We’ve created a caring and supportive environment where everyone feels comfortable, regardless of their background or health journey.

Talk with me now to update your NHS record

We care dearly about your personal information.

We update NHS preiodically

Why its important to update your NHS pharmacy record?


🇪🇺🇬🇧 Comprehensive Privacy Notice and Framework

This document serves as the combined Privacy Notice for Charlton Pharmacy & Cheltenham Clinic _ ("we," "us," or "our"), outlining how we handle your personal data. We are fully committed to complying with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (GDPR), and the ePrivacy Directive (PECR).

1. Introduction, Scope, and Contact Details

Data Controller

The data controller responsible for the processing of your personal data is Charlton Pharmacy & Cheltenham Clinic, registered at [Insert Full Registered Address].

Data Protection Officer (DPO)

If you have any questions or wish to exercise your legal rights, please contact our Data Protection Officer (DPO):

Email: [email protected]

Postal Address: 39 Lyefield Road West, Charlton Kings, Cheltenham England GL53 8EZ

Effective Date: 11th November 2025


2. The Data We Collect About You

We collect various categories of personal data, either directly from you or indirectly through automated technologies.

Categories of Data Collected:

Identity Data: First name, last name, title, and account identifiers.

Contact Data: Billing and delivery addresses, email address, and telephone numbers.

Financial Data: Payment details (processed securely by third-party processors) and banking details for transactions.

Technical Data (Indirectly Collected): IP address, login data, browser type and version, operating system, and geographic location.

Usage Data (Indirectly Collected): Information on how you interact with our website and services, including click paths and time spent on pages.

Conversational Data (Directly Collected): Transcripts of voice calls and text chats, including all interactions with our AI systems.

Marketing and Communications Data: Your preferences in receiving marketing and communications from us.


3. How and Why We Use Your Data (Purposes and Lawful Basis)

We must have a valid Lawful Basis under the GDPR for every activity where we process your personal data.

Lawful Processing Activities:

Service Provision & Order Fulfilment: Processed under the basis of Performance of a Contract with you (e.g., fulfilling orders, managing accounts).

Website Security & Maintenance: Processed under Legitimate Interests (for running our business, ensuring system security, and fraud prevention).

Legal Compliance: Processed under Legal Obligation (e.g., meeting tax or regulatory requirements).

Direct Marketing & Promotions: Processed under Consent (where required for non-essential communications) or Legitimate Interests (for existing customers).

AI System Training & Improvement: Processed under Legitimate Interests (for developing, auditing, and enhancing the accuracy and quality of our services and systems).


4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance user experience and analyse site usage.

Consent Requirement (ePrivacy Directive/PECR)

Non-essential cookies (e.g., analytics, marketing) will not be set without your prior, clear, and affirmative consent.

We use a Consent Management Platform (CMP) to manage and record your consent choices.

Policy and Withdrawal

For complete details on the cookies we use (including their name, purpose, and duration), please refer to our separate [

LINK TO SEPARATE COOKIE POLICY].

You can easily change or withdraw your consent at any time by clicking the Cookie Settings/Preference Centre [LINK TO CMP].


5. Use of Artificial Intelligence (AI) in Communications

We employ AI and automated systems in both inbound/outbound voice calls and online chat channels. Our commitment is to full transparency and human oversight.

Transparency and Notification

Immediate Notification: You will be informed immediately when you are interacting with an AI system. On calls, this will be a verbal notification (e.g., "You are now speaking with our AI Assistant"). In online chats, the interface will be clearly labelled.

Data Use for AI: We process your Conversational Data to answer your queries and to train the underlying AI models. This processing is based on our Legitimate Interests in improving service quality and, where applicable, the Performance of a Contract to resolve your service request.

Human Oversight and Accuracy Disclaimer

Right to Human Intervention: Our AI systems do not make final, legally significant decisions affecting you. You have the right to request immediate escalation to a human agent at any point during an interaction.

Right to Contest: If you believe a piece of information or a decision provided by the AI is incorrect, you have the right to contest it and request a review by a human supervisor.

Accuracy Disclaimer: Please be aware that AI systems are probabilistic and can occasionally produce inaccurate or incomplete information. We advise seeking human verification for critical decisions.


6. Data Sharing and International Transfers

Data Sharing (Third Parties)

We share your personal data with third parties only as necessary for our operations, including:

IT and system administration service providers (Cloud hosts).

Payment processors and logistics providers.

Professional advisers (e.g., lawyers, auditors).

Analytics and advertising partners.

We ensure all third-party processors are bound by written agreements (Data Processing Agreements) to protect your data in line with GDPR standards.

International Data Transfers

When we transfer your personal data outside the UK or the European Economic Area (EEA), we ensure appropriate legal safeguards are in place:

We rely on Adequacy Decisions where the receiving country has been deemed to provide an adequate level of protection.

We implement Standard Contractual Clauses (SCCs) approved by relevant authorities (UK or EU) to ensure protection equivalent to that offered within the UK/EEA.


7. Your Legal Rights (UK/EU Data Subject Rights)

You have the following rights over your personal data under the GDPR:

Right to Access (Art. 15): Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16): Request correction of incomplete or inaccurate data.

Right to Erasure ('Right to be Forgotten') (Art. 17): Request the deletion of your data where there is no good reason for us to continue processing it.

Right to Restriction of Processing (Art. 18): Request the suspension of processing in certain circumstances.

Right to Data Portability (Art. 20): Request the transfer of your data to you or a third party.

Right to Object (Art. 21): Object to processing based on Legitimate Interests or for Direct Marketing.

Rights related to Automated Decision Making (Art. 22): Object to a decision based solely on automated processing.

Right to Withdraw Consent: Withdraw consent at any time where we rely on it for processing.

To exercise any of these rights, please contact our DPO using the details provided in Section 1.


8. Data Retention and Complaints

Data Retention Policy

We will retain your personal data only for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying any legal, regulatory, or reporting requirements. Our retention periods are determined by the nature of the data and the necessity to meet legal obligations.

Right to Complain to the Supervisory Authority

You have the right to lodge a complaint with your relevant data protection authority:

UK Residents: The Information Commissioner’s Office (ICO). [Insert ICO Website Link].

EU Residents: The Data Protection Authority in your specific EU Member State.


🍪 Separate Cookie Policy for _

This Cookie Policy explains what cookies are, how _ ("we," "us," or "our") uses them on our website, and how you can manage your preferences. This policy should be read alongside our main Privacy Notice.

1. What are Cookies and Tracking Technologies?

Cookies are small text files that are placed on your computer, tablet, or mobile phone when you browse our website. They are widely used to make websites work efficiently and to provide information to the site owners.

We use two main types of cookies:

Session Cookies: These are temporary and are deleted once you close your browser. They are typically used for essential functionalities, like keeping you logged in.

Persistent Cookies: These remain on your device for a set period (which may be days, months, or years) and are used to remember your preferences or track usage across multiple sessions.

We also use First-Party Cookies (set by our domain) and Third-Party Cookies (set by external services like analytics or advertising partners).

2. Your Consent and Control (PEC-R Compliance)

Under UK/EU law, we are required to obtain your informed, prior consent for all cookies and tracking technologies that are not Strictly Necessary for the operation of the website.

Consent Management Platform (CMP)

When you first visit our site, a consent banner appears, powered by our Consent Management Platform (CMP).

Default Setting: All non-essential cookie categories (Functional, Analytics, Marketing) are OFF by default.

Affirmative Action: We only set non-essential cookies if you provide a clear, affirmative action, such as clicking "Accept All" or enabling categories within the settings.

Withdrawal of Consent

You have the right to withdraw or change your consent at any time.

You can easily access and adjust your current preferences by clicking the Cookie Settings/Preference Centre link, which is located in [Specify Location, e.g., the footer of every page].

3. Categories of Cookies We Use

We classify the cookies we use into the following categories to help you make an informed decision regarding consent:

1. Strictly Necessary Cookies (Consent Not Required)

These cookies are essential for you to browse the website and use core functions, such as accessing secure areas, using a shopping cart, or ensuring security. Without these cookies, the website cannot function properly.

Example Purpose: Security, network management, and basic accessibility functions.

2. Functional Cookies (Consent Required)

These cookies allow the website to remember choices you make (such as your user name, language, or region) and provide enhanced, more personal features.

Example Purpose: Remembering your login details, site language selection, or saving accessibility settings.

3. Analytics and Performance Cookies (Consent Required)

These cookies collect information about how visitors use the website, such as which pages are visited most often and if they get error messages. They are used to measure and improve the performance of our website.

Example Purpose: Measuring website traffic, identifying popular content, and optimising user journeys (e.g., Google Analytics, provided you have consented).

4. Marketing and Targeting Cookies (Consent Required)

These cookies are used to track your browsing habits across different websites. They are used to deliver advertisements that are more relevant to you and your interests. They also limit the number of times you see an advertisement and help measure the effectiveness of the advertising campaigns.

Example Purpose: Delivering targeted advertising, tracking effectiveness of ad campaigns, and social media integration.

4. Full Cookie Details (Cookie Table)

To ensure full transparency, the following information is provided for every cookie used on our site within the

[LINK TO CMP/COOKIE TABLE PAGE]:

Cookie Name: The technical identifier (e.g., _ga , session_id ).

Provider: The entity setting the cookie (e.g., _ for first-party, or Google, Facebook for third-party).

Purpose: A clear explanation of the cookie's function (e.g., "Registers a unique ID to generate statistical data on how the visitor uses the website").

Expiration/Duration: How long the cookie remains on your device (e.g., "30 minutes," "2 years," or "Session").

Type: Whether it is a First-Party or Third-Party cookie.

We strongly recommend reviewing the live Cookie Settings/Preference Centre [LINK TO CMP] for the most accurate and up-to-date list, as this list changes dynamically based on the third-party tools we use.

5. Other Tracking Technologies

In addition to cookies, we may use similar technologies such as web beacons, pixels, and local storage to collect information about your interactions with our website and emails for the same purposes outlined above. Your cookie consent choices apply equally to these technologies.

Services we offer

Blood Tests

prescriptions

Ear wax Removal

Weight loss clinic

Vaccines & Travel Clinic

Minor illnes

Longevity & Wellness

Hormones

CLIENT

TESTIMONIALS

Client

COMPANY

CUSTOMER CARE

FOLLOW US

Copyright 2025. Cheltenham Clinic & Pharmacy . All Rights Reserved.