Community Pharmacy Connect logo Pharmacy Connect
Private pilot · by invitation Sign in

Privacy Notice

Last updated:

Audience: pharmacy professionals and LPC administrators who use Community Pharmacy Connect ("CPC", "the Service").


1. Who we are (the controller)

Neuronet Dev Ltd is the data controller for the personal data described in this notice.

CPC is a free compliance tool for community pharmacy. It delivers drug-safety alerts (e.g. MHRA / National Patient Safety Alerts) and lets a verified pharmacy professional record that they have read and acted on an alert, producing a tamper-evident attestation record (an "acknowledgement") and, on request, a signed Inspection Pack of that history.

2. What personal data we collect

We collect and process the following personal data about you.

2.1 Identity and account data

These are held by our identity provider, Clerk (see §5).

2.2 Professional profile data

2.3 Acknowledgement (attestation) evidence — WORM records

When you acknowledge a safety alert, we write an immutable, append-only evidence record ("WORM" = write-once, read-many). Each record can contain:

The IP address and device information are personal data. We collect them deliberately as part of the integrity and evidential value of the acknowledgement record — they help demonstrate who acted, from where, and when.

2.4 Professional development and operational data

2.5 Consent and audit records

2.6 Special-category data

CPC is not designed to collect special-category (e.g. health) data. The CPD reflection and shift-pulse blocker fields are free text. Please do not enter patient-identifiable or health data into these fields. We provide on-screen guidance to remind users not to enter patient-identifiable data.

3. Where your data comes from

Most data comes directly from you (when you sign in, complete your profile, acknowledge an alert, or write a reflection). Some is generated by the Service as you use it. Alert content itself comes from external safety sources (e.g. MHRA / NatPSA) and is not personal data about you.

4. Purposes and lawful basis

#PurposePersonal data usedLawful basis
1Create and operate your account; authenticate youName, email, auth factorsArt. 6(1)(b) Contract
2Verify your professional registration (GPhC) and associate you with a siteGPhC number + status, ODS code, site historyArt. 6(1)(f) Legitimate interests
3Deliver safety alerts and record your acknowledgement as a tamper-evident professional/compliance recordAcknowledgement WORM records incl. IP/deviceArt. 6(1)(f) Legitimate interests & Art. 6(1)(c) Legal obligation
4Provide CPD recordingCPD reflectionsArt. 6(1)(b) Contract
5Provide operational situational awareness (aggregated)Shift pulsesArt. 6(1)(f) Legitimate interests
6Maintain a consent and administrative audit trailConsent events, admin auditArt. 6(1)(c) Legal obligation
7Keep the Service secure, prevent abuse, and produce evidence integrityIP/device, audit logsArt. 6(1)(f) Legitimate interests

5. Processors and sub-processors

We use the following processors to deliver CPC. Each is governed by a written Data Processing Agreement (DPA) under UK GDPR Article 28.

ProcessorRoleData they process
ClerkAuthentication, identity, email delivery, session / re-verificationName, email, auth factors, session metadata
NeonPostgreSQL database hosting all application dataAll application tables
VercelApplication hosting and serverless functionsAll in-transit data; log metadata

6. International transfers and data residency

CPC commits to UK/EU data residency for personal data. All production databases, identity instances, and hosting functions operate within the EU/UK regions. Where any personal data is transferred outside the UK/EU, Neuronet Dev Ltd relies on an appropriate transfer mechanism (e.g. UK adequacy regulations or standard contractual clauses).

7. How long we keep your data (retention)

DataRetentionNotes
Acknowledgement WORM evidence7 yearsRetained as a professional/regulatory evidence record, immutable by design.
Site-claim denials180 daysPruned automatically.
Profile data, CPD reflections, shift pulsesUntil account deletionRetained while your account is active.
Consent events / administrative audit7 yearsRetained for accountability and legal compliance.
Hosting / function logs30 daysRolling automatic deletion.

8. The acknowledgement record, IP/device, and why it is immutable

Because CPC produces evidence that a safety alert was read and acted upon, the acknowledgement record is intentionally write-once / immutable (WORM) and captures integrity signals including your IP address and device information. This gives the record evidential value in professional or regulatory inspections.

9. Who can see your data

10. How we keep your data secure

Security measures include: authenticated access via Clerk with optional step-up re-authentication at the point of signing; fail-closed authorisation; an immutable evidence store; encryption at rest and in transit; and routine backups. We maintain a strict incident-response process and will notify the ICO within 72 hours of any notifiable breach.

11. Your rights

Under UK GDPR you have rights to: access your data; rectification; erasure ("right to be forgotten"); restriction; portability; and objection. There is no solely-automated decision-making producing legal or significant effects on you in the Service.

11.1 Deleting your account (in-app)

You can delete your account directly in the app: Profile → "Delete account".

What we erase:

What we retain, and why (UK GDPR Art. 17(3) exceptions):

12. How to exercise your rights, and complaints

To exercise a right or ask a question: contact dpo@neuronet.dev.

If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.

13. Changes to this notice

We may update this notice. We will publish the updated version with a new "Last updated" date and, where changes are material, notify you via email and in-app alerts 30 days prior to changes taking effect.