mdcrDr Green

Privacy Policy

Who We Are

Madchester Medical Cannabis Clinic (“Madchester,” “we,” “us,” or “our”) is a medical cannabis referral and consultation service operating under Harbour Medical & Wellbeing's Care Quality Commission (CQC) registration. We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What Data We Collect

We may collect and process the following personal data:

Personal Information

  • Full name, date of birth, and gender
  • Contact details including email address, phone number, and postal address
  • Proof of identity and age verification

Medical Information

  • Medical history and current conditions
  • Previous and current medications and treatments
  • Consultation records and clinical notes
  • Prescription history

Technical Information

  • IP address and browser type
  • Pages visited and time spent on our website
  • Cookies and similar tracking technologies

How We Use Your Data

We use your personal data to:

  • Provide medical consultation and referral services
  • Process and manage your prescriptions
  • Contact you regarding your appointments and treatment
  • Comply with legal and regulatory obligations
  • Improve our services and website experience
  • Respond to your enquiries and provide customer support

Legal Basis for Processing

We process your personal data on the following legal grounds:

  • Consent: Where you have given explicit consent for us to process your data for specific purposes, including marketing communications.
  • Legitimate Interest: Where processing is necessary for our legitimate business interests, such as improving our services and ensuring security.
  • Legal Obligation: Where processing is necessary to comply with legal or regulatory requirements, including CQC regulations and NHS reporting obligations.
  • Vital Interests / Medical Purposes: Where processing of special category data (health data) is necessary for the provision of healthcare services.

Data Sharing

We may share your personal data with:

  • Licensed pharmacy partners for prescription fulfilment
  • GMC-registered specialist prescribers involved in your care
  • The NHS or your GP, where required by law or with your consent
  • Regulatory bodies such as the CQC where legally required

We will never sell your personal data to third parties.

Your Rights Under GDPR

Under the UK GDPR, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data where there is no compelling reason for continued processing.
  • Right to Data Portability: Request transfer of your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request limitation of how we use your data.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please contact our Data Protection Officer at the details below.

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Medical records are retained in accordance with NHS guidelines (typically 10 years for adult records). Non-medical data such as enquiry forms is retained for up to 2 years after your last interaction with us.

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption, access controls, secure data storage, and regular security assessments.

Cookies

Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and personalise content. You can manage your cookie preferences through your browser settings. Essential cookies required for the website to function cannot be disabled.

Contact Our Data Protection Officer

If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us:

  • Email: dpo@madchester.clinic
  • Phone: 0161 XXX XXXX
  • Post: Data Protection Officer, Madchester Medical Cannabis Clinic, Manchester, UK

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Last updated: February 2025