Privacy Policy
Effective Date: 18th February 2025
Welcome to SendScript. This Privacy Policy outlines how we collect, use, and safeguard your data when you use our services, ensuring compliance with applicable privacy laws and regulations. Whether you are a patient, healthcare provider, or pharmacy, we strive to maintain transparency in our data practices while delivering a secure and seamless prescription management experience. Please read this policy carefully to understand how your information is handled and your rights concerning your personal data. By accessing www.sendscript.com, you agree to the practices described in this policy.
1. Information We Collect
1.1 Personal Identification Information
We collect personal identification details to verify your identity and ensure accurate prescription processing for clinicians, prescribers, pharmacy professionals, pharmacy and clinic administrators. This includes:
- Full name for identification purposes. Job title, professional qualifications, organisational and institutional affiliations.
- Contact details (email, phone number) to communicate important updates about your prescriptions and account.
- Address to facilitate the delivery of medications where applicable and billing.
- Date of birth and gender to ensure proper identification and legal compliance.
- Sensitive personal data, includes details about your physical and mental health, medical conditions, and other clinical indicators. This may encompass environmental, socio-economic, and behavioral factors relevant to health and well-being.
1.2 Medical and Prescription Information
To provide safe and appropriate prescriptions, we collect:
- Medical history relevant to your prescriptions, ensuring drug compatibility and patient safety.
- Prescription details, including medication name, dosage, and prescribing physician.
- Healthcare provider details to coordinate with doctors and pharmacists.
1.3 Transactional, Technical and Usage Information
We collect technical data to enhance our website, SendScript App and SendScript Platform functionality and security:
- IP address to track usage trends and prevent fraudulent activity.
- Browser type and version and language for site optimisation.
- Operating system details for compatibility improvements.
- Cookies and tracking technologies to personalise user experience and provide analytics (see Cookie Policy).
- Other technologies that may uniquely identify your device or browser.
- Transactional data, which includes details of purchases and orders made by you, along with your payment card information or bank transfer details.
1.4 Payment Information
We process personal data to facilitate payments for services provided. This may include details necessary for identification and verification, such as your name, credit or debit card number, card expiration date, and CVV code.
Payment Partners
All payment transactions, whether processed directly by us or through our third-party payment providers, are encrypted and secured to the highest standards. Our current payment partners are:
- Ryft Pay
- Stripe(Stripe's services are gradually being phased out and will be fully replaced by Ryft Pay.)
1.5 Profile, Marketing, and Publicly Available Information
We collect the following information to ensure transparency:
- Profile Data: Includes login credentials for your online account, such as username and password, as well as your stated interests, preferences, feedback, and survey responses.
- Marketing and Communications Data: Covers your preferences regarding marketing communications from us and third parties, your preferred method of communication, and any correspondence you have had with us.
- Publicly Available Personal Information: Includes details you have shared on publicly accessible platforms, such as social media accounts (e.g., Twitter, Facebook, or other public forums).
1.6 Information We Receive from Others
In addition to the information you provide directly, we may receive personal data about you from third parties and publicly available sources, including:
- Healthcare Service Providers: Pharmacy staff, Clinicians and administrators may share information about you when using our services.
- Other Partners: We may receive personal data about you from our business partners.
- Third Parties or Publicly Available Sources: We may obtain personal data about you from various third parties and publicly accessible sources.
2. How We Use Your Personal Data
2.1 Lawful Basis for Processing
We only process your personal data where permitted by law. The most common circumstances in which we use your data include:
- Contractual necessity – When processing is required to fulfill a contract we have entered into with you or are about to enter into.
- Legitimate interests – When processing is necessary for our legitimate interests (or those of a third party), provided these do not override your fundamental rights and freedoms.
- Legal or regulatory obligations – When processing is required to comply with applicable laws or regulatory requirements.
2.2 Consent and Marketing Communications
We generally do not rely on consent as a legal basis for processing your personal data, except when sending direct marketing communications from third parties via email or SMS. You can withdraw consent for marketing at any time by contacting us.
2.3 Healthcare and Service Management
We process personal data to support healthcare services, including:
- Preventive or occupational medicine
- Assessing an employee's work capacity
- Medical diagnosis and treatment
- Managing health or social care systems and services
- Fulfilling healthcare-related contracts with professionals or institutions
3. Legal Basis for Processing
We process your personal data only when there is a valid legal reason to do so, in compliance with applicable regulations. When we collect your information, we will always be transparent about which details are necessary for the services you are accessing. Our legal justifications for processing your personal information typically include:
- Your consent – When you have explicitly agreed to the processing of your data.
- Fulfilling a contract – When processing is essential to provide a service you have requested or to carry out contractual obligations.
- Legitimate business interests – When processing supports our operations or those of a third party, provided it does not infringe on your fundamental rights.
- Vital interests – When necessary to protect your health or safety, particularly if you are unable to provide consent (e.g., in an emergency situation).
- Public health and service management – When processing is required for healthcare system administration, medical diagnosis, or health-related services.
- Legal or regulatory compliance – When the law mandates data processing for specific obligations.
4. How We Share Your Data
We share your personal information with trusted third parties in specific circumstances to ensure the effective operation of our services.
Why We Share Your Data
We may share your data with third parties in the following cases:
- To deliver the services you request.
- To meet legal or regulatory requirements.
- To enforce agreements and protect our contractual rights.
- To assist law enforcement in crime or fraud prevention.
- To protect public safety or security where necessary.
- As permitted or required under applicable laws.
Our Third-Party Service Providers
To maintain a seamless and secure experience, we work with external partners who support various operational aspects of our platform, such as:
- IT infrastructure and security – Ensuring stability, hosting, and data protection.
- Payment processing – Managing transactions securely.
- Customer communication and support – Handling inquiries, complaints, and notifications.
- Delivery and logistics – Enabling prescription fulfillment and product dispatch.
5. Data Accuracy and Compliance
Ensuring that the personal information we maintain about you is accurate and up to date is crucial. Please notify us as soon as possible if any of your personal information changes during our relationship. Compliance with Data Protection Laws: Any personal information we collect or receive will be securely managed and stored in line with this Privacy Policy and in adherence to the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and all other applicable data protection laws, as well as any other legislation relating to the protection of personal information (data protection laws).
6. Data Security
We employ stringent security measures to safeguard your personal data:
- Encryption of sensitive data to protect against unauthorized access.
- Secure access controls ensuring only authorized personnel handle your data.
- Regular security audits and compliance checks.
- Compliance with GDPR, HIPAA, and other relevant healthcare data protection regulations.
7. Data Retention
We retain your data only as long as necessary to fulfill our services and meet legal obligations. Data retention periods depend on:
- Legal requirements for healthcare data retention.
- Business needs for service continuity and security.
- Your request to delete personal data, where applicable.
8. Your Privacy Rights and How to Exercise Them
You have several rights under data protection laws that give you control over how your personal data is collected, stored, processed, and shared. These rights ensure that you can access, correct, limit, or even erase your data in certain circumstances. Below, we outline your key rights and what they mean for you.
Your Rights Explained
- Right to Be Informed: You have the right to know how your personal data is being used. We are committed to transparency and provide clear details about the collection, use, storage, and sharing of your information through this Privacy Notice and other relevant policies.
- Right to Access (Subject Access Request - SAR): You can request a copy of the personal data we hold about you at any time. This allows you to verify what information we have and ensure we are processing it lawfully. If you would like to access your data, you may submit a Subject Access Request (SAR).
- Right to Rectification (Correction of Data): If your personal information is incorrect, outdated, or incomplete, you can request that we update or correct it.
- Right to Erasure (Right to Be Forgotten): You can request the deletion of your personal data in certain situations, such as when the data is no longer needed for the purpose for which it was originally collected.
- Right to Restrict Processing: You may ask us to limit how your data is processed in certain cases.
- Right to Data Portability: You have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON).
- Right to Object: You can object to the processing of your personal data in certain cases, such as when processing is based on legitimate interests, and you believe it affects your fundamental rights.
- Right to Avoid Automated Decision-Making and Profiling: You have the right not to be subject to fully automated decisions (i.e., decisions made solely by computers without human involvement) that significantly impact you.
How to Exercise Your Rights
If you wish to exercise any of the rights listed above, please contact us directly with your request. Important Points to Note:
- Free of charge – You do not have to pay to exercise your rights, but if a request is excessive, repetitive, or clearly unfounded, we may charge a reasonable fee or refuse the request.
- Identity verification – To protect your data, we may ask for proof of identity before processing your request. This ensures that personal information is only disclosed to the correct individual.
- Clarification requests – If needed, we may ask for more details to better understand and process your request efficiently.
9. Cookies and Tracking Technologies
We, along with certain third parties, use cookies and similar tracking technologies (such as web beacons and pixels) to recognise your device and enhance your experience.
Types of Cookies We Use:
- Essential Cookies – These are necessary for the functionality of the SendScript App, website, and platform. They help ensure the platform loads properly, store your cookie preferences, enable secure login for administrative users, and support payment processing features.
- Analytical Cookies – These help us understand how users interact with our platform, allowing us to improve performance and optimise user experience.
Managing Your Cookie Preferences
You can control how cookies are stored and used by:
- Adjusting your browser settings to accept, reject, or block cookies.
- Setting your browser to notify you when a cookie is placed on your device.
- Opting out of Google Analytics tracking by installing Google's opt-out browser add-on.
10. Third-Party Links
Our website may contain links to external sites. While we strive to include reputable sources, we are not responsible for the privacy practices of these third parties. We encourage reviewing their policies before sharing personal information.
Opting Out
You may request that we or third parties stop sending you marketing communications at any time by contacting us. Opting out of marketing messages does not affect the personal data we have collected in connection with a product or service purchase, interactions with a medical practitioner (which may need to be retained for future reference), service experiences, or other transactions.
11. Updates to This Policy
We may periodically update this Privacy Policy to reflect changes in regulations, services, or security measures. Any changes will be posted on this page with an updated effective date. Users are encouraged to review the policy periodically to stay informed.
12. Contact Information
For any inquiries regarding this Privacy Policy or your personal data, please reach out to us at:
13. Information About Who We Are
We are MSMB Healthcare Limited, trading as SendScript ("we", "us", or "our") and also known as SendScript. SendScript will be the controller of your personal data unless otherwise stated. For any inquiries regarding this Privacy Policy or your personal data, please reach out to us at:
14. Information You Provide to Us
Some information, including personal data, is required when signing up for and using our services, website, SendScript App, and SendScript Platform. We collect this information to manage and facilitate these services effectively. When you provide us with your personal data, it is for the following purposes:
- Account and Contact Details: When creating an account, you provide login credentials, including your username and password, along with necessary profile details such as full name, email address, phone number, date of birth, gender, marketing preferences, and profile picture.
- Special Category Personal Information: Some of the data you provide while using the SendScript App or Platform may be considered "special" or "sensitive" in certain jurisdictions. This includes interactions with pharmacies when booking consultations, ordering prescriptions, or when notes are added to your account that may relate to your health.
- Video Consultations: If you book a video consultation through the SendScript App or Platform, we only process the data necessary to facilitate the video interaction. The video content itself is not recorded or retained. However, both users and pharmacy professionals may add notes to the account, which will be stored.
- Billing or Bank Details: When making a payment, you provide details necessary for processing transactions, including debit or credit card number, cardholder name, card expiry, CVV, and billing address. This payment information is securely handled by our payment partner, Stripe. You can review Stripe's privacy policy here: https://stripe.com/gb/privacy.
- Customer Service: When you contact our customer service team via the SendScript App, Platform, email, or chatbot, we collect the information you provide during the interaction. This may include your name, contact details, and any other personal data you choose to share.
15. Online Account, SendScript App, and Platform
The SendScript App, website, and platform are designed to streamline access to independent pharmacy services, offering a seamless way to manage prescriptions, schedule appointments, and conduct virtual consultations. Our goal is to enhance convenience by enabling patients to engage with pharmacy services anytime, anywhere.
- To use our online services, including the SendScript App and Platform, we require basic personal details such as your name and contact information.
- You can manage and update your personal data directly through the app or platform.
- If you log in via your NHS account, you may need to contact your pharmacy to review or update medical records linked to your profile.
- Additionally, we may collect information when you: Submit feedback, update preferences, or participate in surveys and promotions,Complete transactions involving payment details,Engage with pharmacy staff, customer support, or other service channels.
- Customer Service: When you contact our customer service team via the SendScript App, Platform, email, or chatbot, we collect the information you provide during the interaction. This may include your name, contact details, and any other personal data you choose to share.
16.Data Controller
We operate the SendScript App and Platform, designed to digitize and streamline pharmacy services, enhancing accessibility for patients. If your local or online pharmacy is registered with SendScript, you can use our platform to:
- The SendScript App and Platform will be integrated with NHS services.
- If you access the platform using your NHS login, the identity verification process is managed by NHS England, which acts as the data controller for any personal data used to verify your identity
- You can manage and update your personal data directly through the app or platform.
- SendScript acts only as a data processor in this regard and operates under NHS England's instructions when verifying your NHS identity.
- To review NHS England's Privacy Notice and Terms & Conditions, visit: NHS Policies.
- This restriction applies only to data used for NHS login verification. Any personal data you provide directly to SendScript outside of NHS verification is processed under our standard privacy terms.
By using www.sendscript.com, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.