Privacy Notice
Last updated:
Audience: pharmacy professionals and LPC administrators who use Community Pharmacy Connect ("CPC", "the Service").
1. Who we are (the controller)
Neuronet Dev Ltd is the data controller for the personal data described in this notice.
- Registered address: London, United Kingdom
- ICO registration number: Pending registration
- Contact for data-protection matters: Data Protection Officer (dpo@neuronet.dev)
- General contact: support@neuronet.dev
CPC is a free compliance tool for community pharmacy. It delivers drug-safety alerts (e.g. MHRA / National Patient Safety Alerts) and lets a verified pharmacy professional record that they have read and acted on an alert, producing a tamper-evident attestation record (an "acknowledgement") and, on request, a signed Inspection Pack of that history.
2. What personal data we collect
We collect and process the following personal data about you.
2.1 Identity and account data
- Name
- Email address
- Authentication factors (e.g. password and/or other sign-in factors)
These are held by our identity provider, Clerk (see §5).
2.2 Professional profile data
- GPhC registration number and its verification status
- Working site identified by ODS code, and your site history
2.3 Acknowledgement (attestation) evidence — WORM records
When you acknowledge a safety alert, we write an immutable, append-only evidence record ("WORM" = write-once, read-many). Each record can contain:
- your user identifier (Clerk user ID)
- the ODS code of the site you acted for
- the attestation / intent text you confirmed and the signed name
- whether you re-authenticated at the point of signing
- a content hash of the alert content you acknowledged
- your IP address
- device information
- timestamps
The IP address and device information are personal data. We collect them deliberately as part of the integrity and evidential value of the acknowledgement record — they help demonstrate who acted, from where, and when.
2.4 Professional development and operational data
- CPD reflections — free-text professional-development notes you author
- Shift pulses — operational signals about supply, staffing or service status (and any blocker note), used in aggregate for site- and estate-level views
2.5 Consent and audit records
- Consent events — a record of consents you give or withdraw
- Administrative action audit — where you act as an administrator, a log of administrative actions (including a reason / case reference)
2.6 Special-category data
CPC is not designed to collect special-category (e.g. health) data. The CPD reflection and shift-pulse blocker fields are free text. Please do not enter patient-identifiable or health data into these fields. We provide on-screen guidance to remind users not to enter patient-identifiable data.
3. Where your data comes from
Most data comes directly from you (when you sign in, complete your profile, acknowledge an alert, or write a reflection). Some is generated by the Service as you use it. Alert content itself comes from external safety sources (e.g. MHRA / NatPSA) and is not personal data about you.
4. Purposes and lawful basis
| # | Purpose | Personal data used | Lawful basis |
|---|---|---|---|
| 1 | Create and operate your account; authenticate you | Name, email, auth factors | Art. 6(1)(b) Contract |
| 2 | Verify your professional registration (GPhC) and associate you with a site | GPhC number + status, ODS code, site history | Art. 6(1)(f) Legitimate interests |
| 3 | Deliver safety alerts and record your acknowledgement as a tamper-evident professional/compliance record | Acknowledgement WORM records incl. IP/device | Art. 6(1)(f) Legitimate interests & Art. 6(1)(c) Legal obligation |
| 4 | Provide CPD recording | CPD reflections | Art. 6(1)(b) Contract |
| 5 | Provide operational situational awareness (aggregated) | Shift pulses | Art. 6(1)(f) Legitimate interests |
| 6 | Maintain a consent and administrative audit trail | Consent events, admin audit | Art. 6(1)(c) Legal obligation |
| 7 | Keep the Service secure, prevent abuse, and produce evidence integrity | IP/device, audit logs | Art. 6(1)(f) Legitimate interests |
5. Processors and sub-processors
We use the following processors to deliver CPC. Each is governed by a written Data Processing Agreement (DPA) under UK GDPR Article 28.
| Processor | Role | Data they process |
|---|---|---|
| Clerk | Authentication, identity, email delivery, session / re-verification | Name, email, auth factors, session metadata |
| Neon | PostgreSQL database hosting all application data | All application tables |
| Vercel | Application hosting and serverless functions | All in-transit data; log metadata |
6. International transfers and data residency
CPC commits to UK/EU data residency for personal data. All production databases, identity instances, and hosting functions operate within the EU/UK regions. Where any personal data is transferred outside the UK/EU, Neuronet Dev Ltd relies on an appropriate transfer mechanism (e.g. UK adequacy regulations or standard contractual clauses).
7. How long we keep your data (retention)
| Data | Retention | Notes |
|---|---|---|
| Acknowledgement WORM evidence | 7 years | Retained as a professional/regulatory evidence record, immutable by design. |
| Site-claim denials | 180 days | Pruned automatically. |
| Profile data, CPD reflections, shift pulses | Until account deletion | Retained while your account is active. |
| Consent events / administrative audit | 7 years | Retained for accountability and legal compliance. |
| Hosting / function logs | 30 days | Rolling automatic deletion. |
8. The acknowledgement record, IP/device, and why it is immutable
Because CPC produces evidence that a safety alert was read and acted upon, the acknowledgement record is intentionally write-once / immutable (WORM) and captures integrity signals including your IP address and device information. This gives the record evidential value in professional or regulatory inspections.
9. Who can see your data
- You can export your own acknowledgement history via the Inspection Pack.
- Administrators / LPC see compliance roll-ups, GPhC verification status, and aggregated shift-pulse pressure.
- Organisation owners see estate-level aggregates only.
- An organisation-wide WORM ledger export exists for accountability and is tightly access-controlled, logged, and securely audited by Neuronet Dev Ltd.
10. How we keep your data secure
Security measures include: authenticated access via Clerk with optional step-up re-authentication at the point of signing; fail-closed authorisation; an immutable evidence store; encryption at rest and in transit; and routine backups. We maintain a strict incident-response process and will notify the ICO within 72 hours of any notifiable breach.
11. Your rights
Under UK GDPR you have rights to: access your data; rectification; erasure ("right to be forgotten"); restriction; portability; and objection. There is no solely-automated decision-making producing legal or significant effects on you in the Service.
- Access / portability: You can export your own acknowledgement evidence via the Inspection Pack.
- Erasure: You can delete your account in the app at any time (see §11.1). However, erasure of acknowledgement WORM records may be refused where we are required to retain them as professional/regulatory evidence or to meet a legal obligation.
11.1 Deleting your account (in-app)
You can delete your account directly in the app: Profile → "Delete account".
What we erase:
- Your profile PII (name, phone, avatar, GPhC number).
- Your CPD reflections, shift pulses, site history, and active sessions.
- Your messages and forum posts are anonymised.
What we retain, and why (UK GDPR Art. 17(3) exceptions):
- Signed acknowledgement evidence (retained for 7 years as a professional/regulatory record).
- Professional-registration (GPhC) verification decisions.
- Consent events and audit logs (kept as accountability records).
12. How to exercise your rights, and complaints
To exercise a right or ask a question: contact dpo@neuronet.dev.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
13. Changes to this notice
We may update this notice. We will publish the updated version with a new "Last updated" date and, where changes are material, notify you via email and in-app alerts 30 days prior to changes taking effect.
