Data Protection
How PharmGrowth processes personal and health-related data, as controller for its own site and processor for pharmacy clients.
Last updated · 29 August 2026
PharmGrowth supplies digital services to NHS community pharmacies, so the systems we build handle health-related data. This statement explains how personal data is processed across our own website and the websites, apps and software we run for pharmacies, under UK GDPR and the Data Protection Act 2018. It is written to agree with our privacy policy and cookie policy; where a client pharmacy has signed our data processing agreement in the client portal, that agreement governs.
1. Who we are and the roles we play
PharmGrowth (“we”, “us”) is a UK business that builds and hosts pharmacy websites, the White Label App, the Routly delivery management platform and Ledgerly invoice capture. Contact: support@pharmgrowth.co.
- We are the data controller for data about visitors to pharmgrowth.co.uk, people who enquire or request a demo, users of our free tools, and our client pharmacies and their staff.
- We are a data processor for data submitted by patients and customers through websites, apps and software we run on a pharmacy’s behalf. The pharmacy is the controller of that data and we act only on its documented instructions, under a data processing agreement (Article 28 UK GDPR) that every client signs in the client portal before using the admin dashboard.
2. What data is processed
As controller (our own website and business):
- Enquiry and demo request data: name, email, phone, pharmacy name, postcode, ODS code where given, product of interest, current website address, message
- Free-tool requests: name and email where you ask for a result to be sent; the website address, pharmacy name or postcode you enter for the website, Google profile and competition checks
- Client account data: pharmacy details, contact names, GPhC and company details supplied for the website, branding, portal login, plan and billing history, signed agreements
- Payment confirmation and Stripe customer references (card details are held by Stripe only)
- Server logs kept by our hosting provider for security
As processor (on pharmacy websites, apps and software we run):
- EPS nomination requests: name, date of birth, postcode, contact details, GP practice if given, consent record
- Repeat prescription requests: name, date of birth, contact details, the items requested, collection or delivery choice
- Service bookings and minor ailment or Pharmacy First requests: name, contact details, date of birth, eligibility answers and symptom information
- Private service enquiries (weight management, vaccinations, clinics): name, contact details, eligibility answers
- Online shop accounts and orders: name, address, contact details, order history, and the pharmacist’s questions and decision on P medicine orders
- Routly: patient names, addresses, delivery instructions, delivery flags, proof-of-delivery records, driver location during a round, driver shift and pay records
- Ledgerly: supplier invoices and the business data on them
- Dashboard and driver logins for pharmacy staff
Much of the processor data is special category (health) data. The pharmacy, as a healthcare provider, relies on Article 9(2)(h) UK GDPR (provision of health care) with the conditions in Schedule 1 of the Data Protection Act 2018; we do not decide the purpose or legal basis for that data.
3. Legal bases for our own processing
- Contract — delivering and billing the service to client pharmacies, and taking steps you ask for before a contract (building a demo)
- Legitimate interests — responding to enquiries, keeping the service secure, and sending existing clients service information
- Consent — the free email course and free-tool follow-ups; withdraw at any time by emailing us or using the unsubscribe link
- Legal obligation — keeping financial records
4. Where data is processed and by whom
- Netlify — hosts this website and runs the serverless functions that handle forms, checkout and the free tools.
- Supabase — the database and authentication service that stores enquiries, demo requests, client accounts, portal logins and the form submissions made on pharmacy websites we build.
- Stripe — card payments and subscriptions for PharmGrowth plans, and for online shops on pharmacy websites we build. Card details are entered on Stripe’s hosted pages and are never stored by us.
- Resend — sends transactional email: confirmations, lead notifications to our team, the free email course, and service messages.
- Google — when you use the free website check, Google Business Profile check or competition checker, the website address, pharmacy name or postcode you enter is sent to Google’s PageSpeed Insights and Places APIs to produce the result. Google Fonts are loaded from Google’s servers on every page.
Each processor operates on cloud infrastructure it manages. Data may be stored or processed outside the UK by these providers under their standard contractual terms and UK GDPR transfer safeguards; we can confirm the current hosting region of each service on request. We do not sell, rent or share personal data with third parties for marketing purposes.
Within PharmGrowth, patient data submitted to a pharmacy’s website is accessible only to that pharmacy’s authorised users through its admin dashboard. Our own staff access it only for technical support and maintenance, on the pharmacy’s instruction or with its knowledge, and never for any purpose of our own.
5. Security
- All connections use HTTPS (TLS)
- Database access is controlled by row-level security so each pharmacy can only see its own data
- Admin dashboards, the client portal and the Routly driver and staff portals require authenticated sign-in; admin access is limited to named, allow-listed accounts
- Secret keys are held as server-side environment variables and never shipped in website code
- Card data never touches our systems; payments are completed on Stripe’s hosted pages
- Access to production systems is limited to the PharmGrowth team and reviewed when staff change
6. Retention
- Enquiries, demo requests and free-tool lead data — kept for up to two years from our last contact with you, then deleted.
- Client account and billing records — kept for the life of the subscription and then for as long as UK tax and accounting law requires us to keep financial records (up to seven years after the relevant financial year).
- Websites, dashboards and the data submitted through them — kept for as long as the pharmacy’s subscription runs and the pharmacy instructs us to keep it. Thirty days after a subscription ends, the website and its stored submissions are deleted unless the pharmacy has requested an export or transfer within that period.
- Portal and dashboard login records — kept while the account is active and deleted with it.
- Email course subscriptions — kept until you unsubscribe or the course ends, then treated as enquiry data above.
These periods are the same wherever they appear on this site. Where a client pharmacy has its own retention policy for patient submissions, we act on its instructions.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and to withdraw consent where consent is the basis. Email support@pharmgrowth.co. We aim to acknowledge within five working days and to complete requests within one month. If you are a patient of one of our client pharmacies, please contact the pharmacy, which controls your data; we will support it in responding.
8. Responsibilities of client pharmacies
- The pharmacy is the controller for patient and customer data collected through its website, app, shop and Routly, and is responsible for its own privacy notice, retention policy and any registration or fee it owes to the Information Commissioner’s Office.
- Our data processing agreement, signed in the client portal, sets out our obligations as processor: acting on instructions, confidentiality, security, sub-processors, assistance with rights requests and breaches, and deletion or return of data at the end of the contract.
- We will notify the pharmacy without undue delay if we become aware of a personal data breach affecting its data.
9. Complaints
Please raise any concern with us first at support@pharmgrowth.co. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
10. Changes to this statement
We update this statement when our services or processors change; the date at the top changes with it. Active clients are told of material changes by email.