Privacy policy
At Foody's Pharmacy, we are committed to protecting and respecting your privacy. This Privacy Policy explains how www.foophar.com collects, uses, discloses, and safeguards your personal data when you use our services, make a purchase from www.foophar.com, or otherwise communicate with us for the provision of health-related services, including our flu vaccination service. For purposes of this Privacy Policy, "you" and "your" means you as the user of the services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
We are a data controller for the purposes of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Our contact details are provided at the end of this policy.
Please read this Privacy Policy carefully.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the website, update the "Last updated" date, and take any other steps required by applicable law.
How We Collect and Use Your Personal Information
To provide the services, we collect personal information about you from a variety of sources as set out below. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use the information we collect about you to communicate on how to improve the services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the services, our rights, and the rights of our users or others.
What Personal Information Do We Collect?
The types of personal information we obtain about you depend on how you interact with our site and use our services. When we use the term "personal information," we are referring to information that identifies, relates to, describes, or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Information that you directly submit to us through our services may include:
- Contact details: Your name, address, phone number, date of birth, and e-mail.
- Health-related data: Certain healthcare services and the law require us to share information with the Health Service Executive (HSE) as part of these services.
- Order information: Including your name, billing address, shipping address, payment confirmation, e-mail address, and phone number.
- Account information: Your username, password, security questions, and other information used for account security purposes.
- Customer support information: The information you choose to include in communications with us, for example, when sending a message through the services.
Some features of the services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
Information We Collect About Your Usage
We may also automatically collect certain information about your interaction with the services ("Usage Data"). To do this, we may use cookies, pixels, and similar technologies ("Cookies"). Usage Data may include information about how you access and use our site and your account, including device information, browser information, information about your network connection, your IP address, and other information regarding your interaction with the services.
Information We Obtain from Third Parties
We may obtain information about you from third parties, including vendors and service providers who may collect information on our behalf, such as:
- Companies that support our site and services, such as Shopify.
- Our payment processors, who collect payment information (e.g. bank account, credit or debit card information, billing address etc) to process your payment in order to fulfil your orders and provide you with products or services you have requested, in order to perform our contract with you.
- When you visit our site, open or click on e-mails we send you, or interact with our services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. Also see the section below, Third Party Websites and Links.
How We Use Your Personal Information
- Providing Products and Services: We use your personal information to provide you with the services in order to perform our contract with you. This includes processing your payments, fulfilling your orders, and sending notifications related to your account, purchases, returns, exchanges, or other transactions. We may also enhance your shopping experience by enabling Shopify to match your account with other Shopify services you may choose to use. In this case, Shopify will process your information as outlined in its Privacy Policy and Consumer Privacy Policy.
- Marketing and Advertising: We may use your personal information for marketing and promotional purposes, such as sending marketing, advertising, and promotional communications by e-mail, text message, or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the services and advertising on our site and other websites. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in selling our products, as per Art. 6 (1) (f) GDPR.
- Security and Fraud Prevention: We use your personal information to detect, investigate, or take action regarding possible fraudulent, illegal, or malicious activity. If you choose to use the services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone. If you believe your account has been compromised, please contact us immediately.
- Communicating with You and Service Improvement: We use your personal information to provide you with customer support and to improve our services. This is in our legitimate interest in order to be responsive to you, provide effective services, and maintain our business relationship with you, as per Art. 6 (1) (f) GDPR.
Your personal information will be used solely for providing health services, processing prescriptions, and ensuring legal compliance. If you are availing of a Health Service Executive (HSE) funded service, such as the flu vaccine, we may be required to share relevant information with the HSE to provide the service. Additionally, in circumstances where your General Practitioner (GP) needs to be informed of a particular service provided to you, we may share relevant information with your GP.
We only process your personal information where we have a valid "legal basis" for processing. The legal bases for processing your personal information are the following:
- We process your personal information based on the consent you have given.
- You can withdraw your consent at any time and exit this website prior to submitting your responses.
- Upon withdrawal of your consent, we will cease processing your data, but such withdrawal does not affect the processing of data already carried out under the consent.
- Our legal basis for processing your personal data is the performance of a contract with you (i.e. providing you with healthcare services), compliance with our legal obligations, and our legitimate interests (e.g. maintaining accurate records, communicating with you about our services).
In relation to special category data (i.e. health data), we process this data to provide you with healthcare services, and our lawful basis is the provision of health or social care (Article 9(2)(h) of the GDPR).
International Transfer of Personal Data
- We may transfer your personal data to a third party in countries outside the country in which it was originally collected for further processing, in accordance with the purposes set out in How We Disclose Your Personal Information
- In particular, your personal data may be transferred to outsourced service providers located outside the EEA states. In these circumstances, we will, as required by GDPR provisions, ensure that the receiving country provides adequate protection for individuals’ rights and freedoms for their personal data.
In accordance with Chapter V of the GDPR, we will only transfer your personal data to third countries or international organisations where:
- The European Commission has decided that the third country, a territory, or one or more specified sectors within that third country, or the international organisation in question, ensures an adequate level of protection (Article 45).
- The transfer is subject to appropriate safeguards, such as standard data protection clauses adopted by the European Commission (Article 46).
- One of the derogations for specific situations applies, such as your explicit consent or the performance of a contract between you and us (Article 49).
Data Sharing
Personal information will be accessible to authorised Foody's Pharmacy staff, relevant third-party service providers, and, where applicable, the HSE and your GP. Personal information will not be made accessible or transferred otherwise.
Data Retention
Your personal information will be retained in accordance with legal and professional requirements, and only for as long as necessary for the purposes for which it was collected.
Security
We apply technical and organisational security measures to protect your personal information against unauthorised access, alteration, or loss.
Your Rights
Under GDPR, you have the right to access, rectify, or erase your personal information, and to restrict or object to processing. You may also withdraw your consent at any time, where consent is the lawful basis for processing.
Cookies
Like many websites, we use cookies on our site. For specific information about the cookies that we use related to powering our store with Shopify, see here. We use cookies to power and improve our site and services (including to remember your actions and preferences), to run analytics, and to better understand user interaction with the services (in our legitimate interest to administer, improve, and optimise the services). We may also permit third parties and service providers to use cookies on our site to better tailor the services, products, and advertising on our site and other websites.
Most browsers automatically accept cookies by default, but you can choose to set your browser to remove or reject cookies through your browser controls. Please keep in mind that removing or blocking cookies can negatively impact your user experience and may cause some of the services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking cookies may not completely prevent how we share information with third parties, such as our advertising partners.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for contract fulfilment purposes, legitimate purposes, and other reasons subject to this Privacy Policy. Such circumstances may include:
- With vendors or other third parties who perform services on our behalf (e.g. IT management, payment processing, data analytics, customer support, cloud storage, fulfilment, and shipping).
- To the HSE, where you have asked us to register you on a scheme or service, such as the Drugs Payments Scheme, and to ensure prescription claims can be made and reimbursements processed as part of the Primary Care Reimbursement Service (PCRS). We may provide you with a HSE-funded service, such as the flu vaccine, and are required to share this information with the HSE to provide you with the service.
- To your GP in circumstances where we need to inform your GP that we have provided you with a particular service.
- With business and marketing partners to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
- When you direct us, request us, or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations with your consent.
- With our affiliates or otherwise, in our legitimate interests to run a successful business.
- In connection with a business transaction, such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants, and similar requests), to enforce any applicable terms of service, and to protect or defend the services, our rights, and the rights of our users or others.
We may disclose the following categories of personal information and sensitive personal information about users for the purposes set out above in How We Collect and Use Your Personal Information and How We Disclose Personal Information:
We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you. With your consent, we share personal information for the purpose of engaging in advertising and marketing activities as follows.
Third Party Websites and Links
Our site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated with or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms, may also be viewable by other users of the services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the services.
Children's Data
The services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted. As of the effective date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
Security and Retention of Your Information
We implement technical and organisational measures to protect your personal information. However, please be aware that no security system is impenetrable. While we strive to protect your data, we cannot guarantee absolute security.
Information transmitted over the internet may not be fully secure. We use encryption protocols (such as HTTPS) for our website, but we cannot ensure the security of data in transit. We strongly advise against sending sensitive or confidential information through unsecured channels.
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including maintaining your account, providing our services, complying with legal and regulatory obligations, resolving disputes, and enforcing our terms and policies.
>When personal information is no longer needed, we securely delete or anonymise it in accordance with our data retention policies and applicable laws.
For more information about our security practices or data retention periods for specific types of information, please contact our Data Protection Officer using the details provided at the end of this policy
Your Rights
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances, and in certain cases, we may decline your request as permitted by law.
- Right to Access / Know: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
- Right to Delete: You may have a right to request that we delete personal information we maintain about you.
- Right to Correct: You may have a right to request that we correct the inaccurate personal information we maintain about you.
- Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
- Right to Opt-Out of Sale or Sharing or Targeted Advertising: You may have a right to direct us not to "sell" or "share" your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising" as defined in applicable privacy laws. Please note that if you visit our site with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will automatically treat this as a request to opt out of the "sale" or "sharing" of information for the device and browser that you use to visit the site.
- Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
- Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
- Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
- Managing Communication Preferences: We may send you promotional e-mails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our e-mails to you. If you opt out, we may still send you non-promotional e-mails such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on our site or by contacting us using the contact details provided below. We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your e-mail address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorised agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorised them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live, you may have the right to appeal our decision by contacting us using the contact details set out below or lodge your complaint with your local data protection authority. For the EEA, you can find a list of the responsible data protection supervisory authorities here.
Contact and Questions
If you have any queries regarding your personal information or wish to make a complaint, you can contact our Data Protection Officer (Olivia O’Regan • olivia@foodyspharmacy.com • +353 96 77998). You also have the right to lodge a complaint with the Data Protection Commission.