Data protection and privacy policy

How Fertility2U collects, uses and protects your personal and health information when you use our pharmacy service and website.

1. Introduction

Personal Homecare Pharmacy Ltd, trading as Fertility2U (“Fertility2U”, “we”, “us”, “our”), is committed to protecting information through appropriate controls, being transparent about what data we hold and how we use it, and respecting your privacy. “You” (“your”) are our patient, client, or another individual to whom we provide services or with whom we are in contact about our services.

2. The law that applies to us

This policy is governed primarily by the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, enforced by the Information Commissioner’s Office (ICO). Where we process personal data of individuals resident in the European Economic Area, the EU GDPR may also apply. Terms such as “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Special Category Data” and “Processing” carry the meaning given to them in the UK GDPR.

3. Who we are

Fertility2U is a trading name of Personal Homecare Pharmacy Ltd, a company registered in England and Wales under company number 07158940. Our registered office is 11 High View Close, Hamilton Office Park, Leicester LE4 9LJ. Our trading address is 11 High View Close, Hamilton Office Park, Leicester LE4 9LJ. We operate from licensed pharmacy premises and are regulated by the General Pharmaceutical Council (GPhC). We are the Data Controller for the personal data described in this notice.

4. Personal data we collect

Depending on how you interact with us, the personal data we collect about you includes, but is not limited to:

Standard personal data

  • Your full name.
  • Your postal address and any delivery address you provide.
  • Your email address and telephone numbers.
  • Your date of birth (where used to confirm your identity).
  • Customer account identifiers, order references and order history.
  • Contact preferences and communication logs.
  • Contact details of any next of kin or authorised recipient you nominate.
  • Call data when you call us or we call you — caller line identity, date, time, duration and call content.
  • Content of emails, postal correspondence and other communications between us.
  • Information about medicines you are currently taking or will be taking, including name, dosage and dosing schedule (received from a third-party system, self-input or otherwise).
  • Payment status, invoice references and transaction identifiers. Payments are processed by Opayo / Elavon, formerly Sage Pay, using a tokenised and PCI-DSS compliant payment process. Fertility2U does not store your full card details.
  • IP address and technical usage information when you use our website or your online account (see the Cookies section).

Special category data (health-related)

Because we provide pharmacy and homecare services, we also process information that the law treats as “special category” data because it concerns your health:

  • Prescription and dispensing information received from NHS referring centres and held in our ordering platform.
  • Medical needs and health notes required to dispense your medication safely.
  • Diagnoses or other medical information that you disclose to us on a call or by other means.
  • Adverse event, pharmacovigilance, product quality, technical issue and patient safety information you report to us.

Source of your data

Your personal data may come from: (a) information you provide directly through our website, your online account, telephone, email or post; or (b) NHS Trust referring centres who refer you to Fertility2U for homecare pharmacy services, under separate Information Sharing Agreements between the NHS and Personal Homecare Pharmacy Ltd.

5. Our lawful basis for processing your data

Under UK GDPR Article 6, we rely on the following lawful bases depending on the type of processing:

Processing activity Lawful basis
Delivering services directly to patients (orders, dispensing, fulfilment, customer service) Article 6(1)(b) — Contract
Delivering services to patients referred from the NHS Article 6(1)(c) — Legal obligation. The referring NHS organisation may rely on Article 6(1)(e) — Public task as a separate controller.
Adverse event, pharmacovigilance, product quality and patient safety handling Article 6(1)(c) — Legal obligation
Authentication, fraud prevention, audit logging, security and operational assurance Article 6(1)(f) — Legitimate interests

Where we rely on legitimate interests, we only do this where the processing is necessary, proportionate, and does not override your rights and freedoms. This may include security monitoring, fraud prevention, audit logging, service protection, incident investigation and limited service improvement activity.

Because we process health-related data, we also need to satisfy a condition under UK GDPR Article 9. We rely on the following:

Processing activity Special category condition
Core pharmacy services — dispensing, fulfilment, patient identification, care management Article 9(2)(h) — Health or social care purposes
Adverse event, pharmacovigilance, product quality and patient safety handling Article 9(2)(i) — Public health (quality and safety of medicinal products)

Where we rely on Article 9(2)(h) or 9(2)(i), the processing is carried out by, or under the responsibility of, a registered health professional or another person who owes an equivalent duty of confidentiality. Our staff are trained, our systems use role-based access, and our processing is audited.

6. How we use your personal data

We use your personal data for purposes that include, but are not limited to:

  • Responding to enquiries about our services.
  • Verifying your identity when you use our services or contact us.
  • Understanding and carrying out your instructions about the delivery of our services.
  • Delivering your medication and the wider homecare pharmacy service.
  • Maintaining appropriate pharmacovigilance. We may share limited information (such as your initials, date of birth and patient ID number) with pharmaceutical Marketing Authorisation Holders so that adverse events and medicine safety incidents can be monitored.
  • Monitoring call traffic for service optimisation, training and problem-solving.
  • Improving our services through internal analysis and patient surveys.
  • Notifying you about changes to our services, terms or this privacy notice.
  • Providing accurate billing and recovering money owed to us.
  • Maintaining business records and meeting our obligations to HMRC.
  • Preventing or detecting crime, fraud or misuse of our services.
  • Meeting obligations under anti-money-laundering and other applicable legislation.

7. Automated decision-making

Fertility2U does not make significant decisions about you based solely on automated processing. Decisions about your care, medication, delivery, service issue or safety concern are handled by trained staff.

8. Who we share your data with

We share your personal data only where necessary to deliver our service, meet a legal obligation, or protect our legitimate interests. The following processors and third parties may receive your data.

Processors acting on our instructions under a Data Processing Agreement or equivalent contractual terms

  • GBG / Loqate (United Kingdom) — provides postcode and address validation.
  • Opayo / Elavon, formerly Sage Pay (United Kingdom or other contracted processing location) — provides tokenised payment processing.
  • Liquid Web or other approved hosting provider — provides hosting infrastructure for our ordering platform.
  • ZenZero — provides managed IT services, including email and SMS support on our behalf.
  • Magebit — provides support for our Magento ordering platform.
  • Couriers and delivery sub-contractors — deliver medication and prescriptions.
  • Clinical nursing sub-contractors — provide nursing services where these are commissioned alongside your medication.

Independent controllers and other recipients

  • NHS Trust commissioners and referring centres — act as independent controllers for their own purposes; our sharing with them is governed by Information Sharing Agreements.
  • Pharmaceutical Marketing Authorisation Holders — receive limited adverse event information for pharmacovigilance purposes.
  • Law enforcement agencies, regulators (including the ICO, MHRA, GPhC and CQC), and courts — where we are required to share data by law.
  • Any successor to our business — as part of any sale or transfer of our business.

Where suppliers act as processors for Fertility2U, we put appropriate contracts or Data Processing Agreements in place. These include requirements for security, confidentiality, breach reporting, sub-processor controls, and return or deletion of data at the end of the service.

9. International data transfers

Our core patient database, ordering platform and dispensing records are hosted on UK infrastructure.

Where personal data is transferred outside the United Kingdom, we use appropriate safeguards for restricted transfers and keep evidence of the transfer mechanism used. This may include supplier contracts, Data Processing Agreements, sub-processor information, certification evidence, UK International Data Transfer Agreements, UK Addendums to EU Standard Contractual Clauses, and transfer risk assessments where required. You can ask us for a copy of the safeguards we have in place by contacting our DPO (see section 14).

10. How long we keep your data

We keep personal data only for as long as we need it for the purposes for which we collected it, or as required by law, regulation, professional standards or our contractual commitments. Indicative retention periods are:

  • Patient records and prescription records — retained in line with NHS, GPhC and applicable pharmacy record-keeping requirements.
  • Adverse event and pharmacovigilance source records — retained for the lifetime of the medicinal product plus 10 years, in line with the European Medicines Agency Good Pharmacovigilance Practice (GVP) modules and corresponding UK requirements.
  • Audit logs and authentication records — retained in line with our Quality Management System retention schedule.
  • Marketing preferences and consent records — retained for the duration of your relationship with us and for evidence purposes thereafter.

The exact retention period depends on the type of record, the purpose for which it is held, and any pharmacy, NHS, tax, contractual, complaint, incident, audit, legal or regulatory requirement that applies. We maintain our detailed retention schedule within our Quality Management System.

When the retention period ends, data is securely deleted or anonymised. Paper documents which we no longer need are destroyed by an ISO 27001 and NAID-accredited data destruction supplier.

11. Your rights

Under the UK GDPR you have the following rights in relation to your personal data:

  • Right to be informed — through this privacy notice.
  • Right of access — to a copy of the personal data we hold about you.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to have your data deleted, subject to legal, regulatory or pharmacy retention requirements that may prevent us from deleting some information.
  • Right to restriction of processing — to limit how we process your data while we consider a query about its accuracy or our lawful basis.
  • Right to data portability — to receive a copy of certain personal data you have provided to us in a structured, commonly used, machine-readable format, and to ask us to transfer it to another controller where technically feasible.
  • Right to object — to processing based on legitimate interests, and to direct marketing at any time.
  • Right not to be subject to solely automated decision-making — including profiling that produces legal or similarly significant effects on you (UK GDPR Article 22).
  • Right to withdraw consent — at any time, where consent is the lawful basis for processing.
  • Right to complain — to Fertility2U and to the ICO if you believe we have not handled your data correctly (see section 15).

Where we rely on legitimate interests, you have the right to object to the processing of your personal data. This may apply to certain security, fraud prevention, audit, service improvement or operational assurance activities. If you object, we will consider your request and explain whether we can stop the processing or whether we need to continue it for a lawful reason.

We will respond to rights requests within one calendar month of receipt. For complex or numerous requests, this period may be extended by up to two further months; if we need to extend, we will explain the reason within the initial one-month period. We may ask you to provide proof of identity before we release information.

Where your request relates to data held across our systems and supplier systems, we will coordinate the request with the relevant supplier where this is required under our contract or Data Processing Agreement. We may need to keep some information where this is required for pharmacy, legal, regulatory, adverse event, pharmacovigilance, complaint, audit or patient safety reasons.

12. Security and storage of your data

We use appropriate technical and organisational measures to keep personal data secure and to prevent it from being accidentally lost, accessed or used in an unauthorised way, altered or disclosed. These measures include role-based access controls, encryption, audit logging, supplier due diligence, staff training, and incident response procedures.

We may monitor and record telephone conversations for training and quality purposes, to confirm verbal instructions, to investigate complaints, and to meet our legal and regulatory obligations. Recordings are encrypted and securely stored, with access controlled and monitored.

If we identify a personal data breach that affects information we hold about you, we will take urgent action in line with the UK GDPR and ICO guidance. No internet-based service can be guaranteed 100% secure; if you become aware of any unauthorised access affecting data we have shared with you, please contact us as soon as possible using the details in section 14.

13. Cookies

Our website uses cookies and similar technologies. Cookies are small files stored on your device by your web browser. Some cookies are strictly necessary for the website and your online account to work properly.

We may also use analytics and tracking cookies, including services provided by Google and Microsoft/Bing, to understand how visitors use our website, count visitors, improve pages and measure the effectiveness of our online content. These cookies may collect information such as your device type, browser, IP address, pages visited, visit time and visit duration.

Non-essential cookies are only used where you have given consent through our cookie banner. You can refuse non-essential cookies or change your preferences at any time using the cookie settings on our website.

14. Contact us

If you have any questions about this notice, want to update your preferences, or exercise any of your rights, please contact us:

15. Complaints

If you are unhappy with how we have handled your personal data, please contact us first using the details in section 14 so that we can investigate your concern. You can make a data protection complaint by email, post or telephone.

We will acknowledge your complaint within 3 days of receiving it. We will provide a response to your complaint within 30 days of receiving it. We will review the complaint, make appropriate enquiries, and keep you informed where needed.

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO): www.ico.org.uk/concerns or telephone 0303 123 1113. We are registered with the ICO under Register Entry Z2749263.

16. Changes to this notice

We review this notice regularly and may update it from time to time. Where changes are material, we will let you know by email or another appropriate route. The version date below shows when this notice was last updated.

Version: 2 — Date: 19 June 2026

Feedback