Privacy Policy
This notice explains how your personal information is collected and used when you book through this portal.
1. Who Is Collecting Your Information
This portal is operated by Strixon Ltd, who is the Data Controller for the personal information you provide. The organisation is responsible for deciding how and why your data is used, and for keeping it safe.
If you have questions about how your data is handled, please speak to a member of staff or use the contact details shown at the organisation.
This portal is powered by RxTerminal, developed and operated by Strixon Ltd (company number 16475557, 3 Tamworth Road, Newcastle Upon Tyne, NE4 5AJ). Strixon Ltd acts as a Data Processor on behalf of the organisation, meaning it processes your data only as instructed by the organisation and does not use your data for its own purposes.
2. What Information Is Collected
When you use this portal to book an appointment, the following information is collected:
- Your first and last name
- Date of birth (used to identify you at the counter)
- Postcode (used to confirm you are registered at this facility)
- The service you are requesting (for example: prescription collection, consultation)
Your NHS number, full address, and payment information are not collected through this portal.
3. Why Your Information Is Collected (Lawful Basis)
Your information is processed under UK GDPR Article 6:
- Legitimate interests (Article 6(1)(f)): to manage the appointment queue efficiently and provide you with timely service.
- Performance of a task in the public interest (Article 6(1)(e)): where the service you are accessing is an NHS-funded service.
If your description of your query includes health-related information, the organisation also processes this under Article 9(2)(h): provision of health or social care, to prepare the appropriate support for you.
4. How Your Information Is Used
Your information is used to:
- Assign you a position in the queue and manage your waiting time
- Allow organisation staff to prepare for your service before you reach the counter
- Identify whether additional services may benefit you
- Maintain records required for NHS-funded service delivery
5. How Long Your Information Is Kept
Your personally identifiable information, including your name, date of birth, and postcode, is automatically anonymised after 90 days.
Anonymised records are irreversible and cannot be linked back to you.
Anonymised records of services provided may be retained for up to 7 years for regulatory and operational purposes.
6. Who Your Information Is Shared With
Your information is visible to organisation staff only. It is not shared with third parties for marketing purposes and is not sold to any organisation.
The following technology providers are used to operate this system. Each is bound by a Data Processing Agreement and processes your data only as instructed by the organisation:
| Provider | Role | Location |
|---|---|---|
| Strixon Ltd (RxTerminal) | Queue management software | United Kingdom |
| Hetzner Online GmbH | Application and secure database hosting | European Union, Germany |
7. Your Rights
Under UK GDPR you have the following rights:
- Right of access: request a copy of your personal data.
- Right to rectification: ask for inaccurate data to be corrected.
- Right to erasure: ask for your data to be deleted.
- Right to restriction: ask the organisation to limit how your data is used.
- Right to object: object to processing based on legitimate interests.
- Right to data portability: request your data in a portable format.
To exercise any of these rights, speak to a member of staff or contact the organisation directly. The organisation will respond within one calendar month.
If you are unhappy with how your data is handled, you can complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
8. Changes To This Notice
This notice is reviewed annually. The current version is always available at the organisation counter on request.