Last updated: April 2026
1. Who We Are
Holborn Clinic is operated by MNS Pharmaceuticals Limited (trading as Boutalls Pharmacy), registered at 60 Lamb's Conduit Street, London WC1N 3LW. GPhC Registration: 1041552. Superintendent Pharmacist: Mohammed Sharifi (GPhC 2231852). We are the data controller for the personal data described in this policy.
Contact: [email protected] / 0207 405 1039.
2. Data We Collect
We collect personal data when you:
- Book an appointment: name, email, phone, date of birth, selected service, preferred date/time, UTM tracking parameters.
- Use the patient portal: email address for magic-link authentication, booking history.
- Register for pharmacy delivery: name, date of birth, NHS number, address, GP surgery, phone, email.
- Contact us: name, email, phone, message content.
- Browse the website: analytics data via Google Analytics 4 (anonymised IP), cookies (see our Cookie Policy).
- Meta Pixel: browsing activity for advertising retargeting and conversion tracking, subject to your cookie consent.
3. Lawful Basis for Processing
- Contract: processing necessary to provide the services you’ve booked (appointments, prescriptions, deliveries).
- Legitimate interest: appointment reminders, service improvement, fraud prevention.
- Consent: marketing cookies, Meta Pixel tracking, promotional emails (you can withdraw consent at any time).
- Legal obligation: pharmacy record-keeping as required by GPhC regulations and NHS standards.
4. How We Use Your Data
- To provide and manage your appointments, vaccinations, and prescriptions.
- To send appointment confirmations, reminders, and follow-up communications.
- To process pharmacy delivery registrations and arrange deliveries.
- To improve our website and services using anonymised analytics.
- To serve relevant advertising (with your consent) via Meta Pixel and Google Ads.
5. Third-Party Processors
We share data with the following processors, all of whom are GDPR-compliant:
- MongoDB Atlas: database hosting (patient records, bookings).
- Vercel / Railway: website hosting.
- Google (GA4, Google Ads): analytics and advertising (with consent).
- Meta (Facebook Pixel, Conversions API): advertising (with consent).
- Google (Gmail SMTP): transactional emails (booking confirmations, reminders).
- Twilio: SMS appointment reminders.
6. Data Retention
- Patient and pharmacy records: retained as required by GPhC regulations (typically 8 years for adults).
- Booking records: 3 years after the appointment date.
- Analytics data: 26 months (Google Analytics default).
- Contact form submissions: 12 months.
7. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data (Subject Access Request).
- Rectify inaccurate data.
- Request deletion (where not overridden by legal retention requirements).
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time.
To exercise any right, email [email protected] or write to us at the address above.
8. Complaints
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
9. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page will be revised accordingly. Significant changes will be communicated via email where we hold your contact details.