Data Processing Agreement (DPA)
Last Updated: September 2026 | Framework: UK GDPR Article 28 / Data Protection Act 2018
This Data Processing Agreement ("DPA") governs the processing of personal data in connection with digital services provided through the Queensway Chemist website (queenswaychemist.co.uk). It supplements our Privacy Policy and Terms of Service.
1. Scope & Core Architectural Principles
Queensway Chemist Ltd operates this website under a strict privacy-by-design architecture:
- Zero Patient Health Records on Web Infrastructure: The public website does not store electronic health records, NHS numbers, prescription histories, or clinical consultation notes.
- Zero Financial Data Processing: The website contains no payment processing gateways, takes no deposits, and stores no cardholder or banking details.
- Isolated Clinical Records: All dispensing and clinical records are maintained exclusively within secure, accredited NHS pharmacy clinical systems (PMR) accessible only within our physical pharmacy premises via NHS Smartcard authentication.
2. Controller and Processor Designations
Data Controller: Queensway Chemist Ltd, 14 Manchester Road, Chorlton-cum-Hardy, Manchester M21 9PN (GPhC Premises #9014227, ODS Code FQP88).
Data Protection Lead: Meera Patel MPharm, Superintendent Pharmacist (privacy@queenswaychemist.co.uk).
3. Authorised Third-Party Sub-Processors
To deliver website availability and consultation appointment scheduling, Queensway Chemist engages vetted third-party data processors bound by written agreements complying with Article 28(3) of the UK GDPR:
| Processor | Purpose | Data Handled | Hosting Location |
|---|---|---|---|
| Cal.com, Inc. | Clinic appointment scheduling widget | Name, phone number, email address, selected appointment slot | EU/UK Data Centre (SOC 2 / GDPR compliant) |
| Cloud Hosting / CDN | Static asset delivery & security firewall | IP address (anonymised server logs), browser telemetry | United Kingdom / EEA |
4. Security & Technical Safeguards
Processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Enforced TLS 1.3 encryption for all data in transit.
- Encryption of contact and appointment records at rest using AES-256.
- Role-based access controls limiting data view to designated dispensary staff only.
- Zero secondary sharing, profiling, or commercial exploitation of patient data.
5. Incident Notification & Breach Management
In the event of a confirmed or suspected personal data breach affecting website users, processors are obligated to notify Queensway Chemist within 24 hours of discovery. Queensway Chemist will notify the UK Information Commissioner's Office (ICO) within 72 hours where required by Article 33 of the UK GDPR.
6. Data Subject Rights & Deletion
Users have the right to request access, rectification, or erasure of contact information held by our web processors. Such requests can be submitted to privacy@queenswaychemist.co.uk and will be actioned within one calendar month without charge.