This privacy policy covers (Bow Clinic) collection, use, and disclosure of information practices while on our website (www.b12clinics.co.uk). This privacy policy together with our terms and conditions and other agreements with you forms the basis on which we will collect and process your data. In this policy (Bow Clinic) is referred to as, we, us, our. The policy describes how we collect, store and process your data on this website.
What information we may collect from you (the user) when you use our website or services?
- Contact details such as name, email address, mailing address, phone number.
- For pharmacy services we collect information such as your medical history, medication history, gender, NHS number, date of birth, GP details.
- Your preferences information such as product wish lists, order history, marketing preferences, reviews.
- Information that you provide by filling in the forms on this website.
- Information you provide when you report a problem or query.
- Payment details
- We try to reduce the holding and use of sensitive information.
How we may use your data?
To process your EPS nominations and repeat prescription requests. This will involve send your request to your GP surgery with your personal details. We may provide some services on our website which are supplied by a third party, such as online doctor or travel clinic booking system. By using these services, the third party providers will have access to your personal details.
- Send you alerts about booked service such as vaccinations, medication review and other private services Respond to requests.
- Process your payments for such products and services
- Create and maintain your account
- Send you a newsletter if you have consented
- Respond to your questions and concerns
- Review and enhance the quality of our services and products
- Assist in the detection of fraud.
- To process your booking
Why do we collect, process and store your data?
Legal bases for processing data
Consent: When you register on our website, you agree and give us consent to process your data for the delivery of products and services to you by us.
Legitimate interests: To enable us to conduct our necessary business but not when our interests are overridden by your interests or rights.
Allowing us to fulfill a contract: We are required to process your personal information in order to provide you with one of our products or services.
Vital interests: When processing of your personal data is vital to protect you or someone else’s life.
Legal obligation: When we are required by law to process your personal information. We will always try to contact you unless we are restricted by law.
How long do we hold your data?
Data Security
Where is the user data stored and who has access?
How do we protect your data?
We take the security of your personal information seriously. When you enter sensitive information, we encrypt the transmission of that using secure socket layer technology (SSL). We do not store any credit or debit card information. Payments are processed via a third party payment provider that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. Any payment transactions are encrypted using SSL technology. We follow generally accepted standards to protect your personal information submitted to us. We take at least a monthly backup of the data stored on our system and is stored in UK based dedicated servers.
Commercial sale of your data?
Limitations of internet based systems
User Access and Choice
Right to be informed: we will explain to you in our privacy policy as to how we use your personal data.
Right to correction and completion: you have the right to ask us to correct any of your data which might be inaccurate and complete any data that is incomplete.
Right to restrict: In some cases you may request to restrict the processing of your personal data. We reserve the right to store enough data to respect your data restriction request in future.
Right to data portability: You have the right to request your data to be provided to you for your own use. This request applies to when processing is based on consent or performance of contract and where when processing is done through an automated system.
Right to object: you may object to the processing of your personal data.
Right to erasure: You may request to have your personal data erased where its not stopping us from complying with legal requirements.
Right to withdraw consent: you have the right to withdraw your consent at any point by contacting us through the details below. In some circumstances, this might not be always possible or you might have to wait for a period of time for this to take place. Contact us for if you would like to discuss this in detail.