Privacy Policy
Who We Are
Madchester Medical Cannabis Clinic (“Madchester,” “we,” “us,” or “our”) is a medical cannabis referral and consultation service operating under Harbour Medical & Wellbeing's Care Quality Commission (CQC) registration. We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What Data We Collect
We may collect and process the following personal data:
Personal Information
- Full name, date of birth, and gender
- Contact details including email address, phone number, and postal address
- Proof of identity and age verification
Medical Information
- Medical history and current conditions
- Previous and current medications and treatments
- Consultation records and clinical notes
- Prescription history
Technical Information
- IP address and browser type
- Pages visited and time spent on our website
- Cookies and similar tracking technologies
How We Use Your Data
We use your personal data to:
- Provide medical consultation and referral services
- Process and manage your prescriptions
- Contact you regarding your appointments and treatment
- Comply with legal and regulatory obligations
- Improve our services and website experience
- Respond to your enquiries and provide customer support
Legal Basis for Processing
We process your personal data on the following legal grounds:
- Consent: Where you have given explicit consent for us to process your data for specific purposes, including marketing communications.
- Legitimate Interest: Where processing is necessary for our legitimate business interests, such as improving our services and ensuring security.
- Legal Obligation: Where processing is necessary to comply with legal or regulatory requirements, including CQC regulations and NHS reporting obligations.
- Vital Interests / Medical Purposes: Where processing of special category data (health data) is necessary for the provision of healthcare services.
Data Sharing
We may share your personal data with:
- Licensed pharmacy partners for prescription fulfilment
- GMC-registered specialist prescribers involved in your care
- The NHS or your GP, where required by law or with your consent
- Regulatory bodies such as the CQC where legally required
We will never sell your personal data to third parties.
Your Rights Under GDPR
Under the UK GDPR, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data where there is no compelling reason for continued processing.
- Right to Data Portability: Request transfer of your data in a structured, machine-readable format.
- Right to Restrict Processing: Request limitation of how we use your data.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, please contact our Data Protection Officer at the details below.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Medical records are retained in accordance with NHS guidelines (typically 10 years for adult records). Non-medical data such as enquiry forms is retained for up to 2 years after your last interaction with us.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption, access controls, secure data storage, and regular security assessments.
Cookies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and personalise content. You can manage your cookie preferences through your browser settings. Essential cookies required for the website to function cannot be disabled.
Contact Our Data Protection Officer
If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us:
- Email: dpo@madchester.clinic
- Phone: 0161 XXX XXXX
- Post: Data Protection Officer, Madchester Medical Cannabis Clinic, Manchester, UK
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Last updated: February 2025
