Privacy Policy

The EU General Data Protection Regulation (GDPR) includes rules on giving privacy information to anyone using our online services. Further information about your rights under GDPR can be found at

Medicinechest Ltd provides websites and apps for NHS contracted pharmacies in the UK. If you use a site or app provided by us for your pharmacy, Medicinechest Ltd is the data processor for your Pharmacy and your Pharmacy is your data controller*.

You can contact our DPO by writing to Nigel Baker, Medicinechest Ltd, St. Mary’s Court, The Broadway, Amersham, Buckinghamshire HP7 0UT

    • Your personal information is stored encrypted on servers in the UK. Medicinechest Ltd may at times process or transfer encrypted personal information outside the UK (and possibly to places outside the European Economic Area) to deliver site and app services, for example to process email and push notification updates. Medicinechest Ltd shall take reasonable steps to ensure that any transfer of your personal information to a country or territory outside the European Economic Area, whose laws may provide for a lesser standard of protection for your personal information than that provided under European law, shall have adequate protection (such as model contractual arrangements as approved by the EU).
    • You may review, edit, or delete your information at any time via your profile.
    • Information you delete from your profile held in our systems may still be held by your data controller, which is your pharmacy, in other records held or systems used by your pharmacy for the purposes of patient safety, professional pharmacy regulations, NHS record keeping and business processing such as a your Patient Medical Record and VAT records.
    • If Example Pharmacy ceases to use the website/app service provided by Medicinechest Ltd, as the data controller, Example Pharmacy may request a download of the data stored on our systems and your data will be deleted from our systems
    • If you use the online nhs repeat prescription facility on the website provided by us for your pharmacy, you will receive email or sms updates on your prescription request and automated email or sms reminders if you request them. If you use The Bewell mobile app for Android or IOS provided by us for your pharmacy, in addition to email updates and reminders, you will receive push notification updates on your request and push notification re-order reminders.
    • Every effort has been made to make sure our databases are secure. All your personal information is stored in the UK. Your information can only be accessed by Medicinechest and trusted Medicinechest Ltd staff and IT contractors. Occasionally, information may be viewed by trusted third parties such as Doctors and IT personnel for the purpose of improving the website and app service provided to you by us for your pharmacy.
    • The site and app, our servers and third-party service providers wherever they are based, have appropriate technical and organisational measures in place to protect against unauthorised or unlawful use of your personal information as well as the accidental loss, destruction or damage of your personal information whilst under our control.
    • However, no data transmission over the internet can ever be guaranteed to be 100% secure and whilst we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us and you do so at your own risk.
    • Your Community Pharmacist may use the information you supply to help in improving your wellbeing by informing your health decisions through advice, diagnostic testing and the management of chronic conditions. The information you supply is important and will help your pharmacy and Medicinechest Ltd understand your health needs better and improve the service given to you. With your permission only, your pharmacy or, Medicinechest Ltd on your pharmacy’s instruction may in future use this information to:
      • Update you with information on services relevant to you provided by your pharmacy and the NHS.
      • Update you with relevant pharmacy and general health, diet and wellbeing retail offers available from your pharmacy.
      • Update you with any public health alerts, drug recalls and changes in treatment advice and also information relevant to your condition(s).

    • Medicinechest Ltd and your may disclose depersonalised data (such as aggregated statistics) in order to describe sales, prescription demand, customers, traffic patterns and other site information to prospective partners, suppliers, medical researchers, sponsors, investors and other reputable third parties and for other lawful purposes, but these statistics will include no personally identifying information.
    • Medicinechest Ltd may disclose depersonalised aggregated data to third parties in the event that we sell or buy any business or assets.
    • Medicinechest Ltd may disclose your personal data if all or substantially all of our assets are acquired by a third party, in which case personal data held by us about our customers may be one of the transferred assets.
    • Under certain circumstances we may occasionally be required by law, court order or governmental authority to disclose certain types of personal information and we reserve the right to comply with any such legally binding request. Examples of the type of situation where this would occur would be:


        • the administration of justice
        • where we have to defend ourselves legally
        • complying with the mandatory requirements of a government department collecting information
        • to protect or defend the rights or property of Medicinechest Ltd or users of our services.

*Using NHS Login

Please note that if you access your account on the website or app provided by us for your pharmacy using your NHS login details, the identity verification services are managed by NHS Digital. NHS Digital is the controller for any personal information you provided to NHS Digital to get an NHS login account and verify your identity and uses that personal information solely for that single purpose. For this personal information, our role is a “processor” only and we must act under the instructions provided by NHS Digital (as the “controller”) when verifying your identity. To see NHS Digital’s Privacy Notice and Terms and Conditions, please click here. This restriction does not apply to the personal information you provide to your pharmacy that we process separately.