Privacy policy

Last updated: 26th Feb 2026

This Privacy Policy describes how Waterfall Group Ltd T/A Happy Pharmacy (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from happypharmacy.co.uk (the "Site") or otherwise communicate with us regarding the Site (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.

Please read this Privacy Policy carefully.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.

How We Collect and Use Your Personal Information

Under UK and EU data protection laws, personal information may only be used where one of the following applies: 

·      you have consented to the use

·      we need use it to achieve a legitimate interest, and our reasons for using it outweigh any prejudice to your data protection rights

·      it is necessary to enter into or perform a contract with you

·      we need to use it to comply with our legal obligations

·      the use is necessary for us to protect your vital interests (or another person’s)

·      we need to use it to perform a task in the public interest.

To provide the Services, we collect personal information about you. The information that we collect and use varies depending on how you interact with us.

In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

What Personal Information We Collect

If you visit our website

When someone visits our website we use a third party service, Google Analytics, to collect standard internet log information (your IP address, browser, and type of device) and details of visitor behaviour patterns (where you joined our site from, the path you take through our site and where you leave). We do this for the purpose of monitoring the number of visitors to the various parts of the site and engagement levels, which in turn enables us to make improvements. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website. The legal basis for the collection and processing of this information will be with your consent.

In addition to this, we use another third party service, Klaviyo, Inc., to provide marketing incentives to visitors to sign up to continue to be informed of future information and offers. The legal basis for collecting and processing of this information will be with your consent.

If you are a website customer

We collect the following Personal information from or about you as a Happy Pharmacy Limited customer:

When you register for an account, we will collect your full name and email address. The legal basis for the collection and processing of this information is the provision to you of the services purchased by you, or intended to be purchased by you.

When you proceed through the purchase process, we will use your details from your account to complete populate your full name and email, and additionally collect your phone number, billing address, delivery address, and marketing preferences for further communications not directly related to the purchase. The label basis for the collection and processing of this information is to fulfil our contract with you for your purchase.

For Prescription Medication and certain Over Counter medications additional medical history information is required in order to prescribe medications, along with details of your doctor. Our legal basis for the collection and processing of this data is the provision to you of the services purchased by you.

We will use the information collected to;

·      administer your purchases and to contact you about your purchase (for example to discuss medical history or request additional medical information).

·      assess whether it is safe to prescribe or supply the medication you have requested.

·      check your identity to ensure the medication is going to the correct person.

·      process your payment for items purchased.

·      contact you with marketing messages which you have requested or agreed to receive from us.

If you email us

Any email sent to us, including any attachments, may be monitored by us for cybersecurity reasons.  Email blocking software may also be used.  We have a legitimate business interest in using your email address, and any personal data included in your message, to resolve and respond to any issues raised.  Your email will be handled in line with our policies, depending on the nature of your enquiry.

How We Manage Your Personal Information

Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.

·       Right to Access: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.

·       Right to Erasure: You may have a right to request that we delete personal information we maintain about you.

·       Right to Rectification: You may have a right to request that we correct inaccurate personal information we maintain about you.

·       Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.

·       Restriction of Processing: You may have the right to ask us to restrict our processing of personal information.

·       Right to Object: You may have the right to ask us to stop our processing of your personal information.

·       Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.

You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.

Duration of Processing

We will maintain records of your Personal Information for as long as you remain:

·      a registered subscriber to our mailing list;

·      a registered user of any of our Sites;

·      have completed a purchase with Happy Pharmacy; or

·      for as long as is necessary to provide our services to you.

·      for as long as is necessary to meet the requirements of the Care Quality Commission (CQC), General Pharmaceutical Council (GPhC) and/or HMRC.

Where retention is necessary to enable us to enforce our legal rights, or to protect the rights, property or safety of our employees, or satisfy the regulatory requirements of the CQC, GPhC and HMRC, we might process your data indefinitely.

Data Processors

We use third party processors to collect, export, process and store Personal information on our behalf. The processors we use currently are the following:

·      Website Provider: Shopify, https://www.shopify.com/uk/legal/privacy

·      Payment Processor: PayPal, https://www.paypal.com/uk/legalhub/paypal/privacy-full

·      Cloud Hosting Provider: DigitalOcean, https://www.digitalocean.com/legal/privacy-policy

·      Email service provider: Microsoft, https://www.microsoft.com/en-gb/privacy/privacystatement

·      Email Marketing Tool: Klaviyo,  https://www.klaviyo.com/privacy

·      Customer & Product Reviews: Trustpilot, https://uk.legal.trustpilot.com/for-businesses/business-privacy-policy

·      CRM Tool: RxWeb, https://rxweb.co.uk/privacy-policy/

·      Consultation Booking System: Calendly, https://calendly.com/legal/privacy-notice

·      Google Analytics, located in the U.S. Privacy Shield Certified. https://www.google.com/policies/privacy/

·      ID Verification: OneID, https://oneid.uk/oneid-privacy-notice

·      Affiliate Programme: UpPromote, https://docs.uppromote.com/privacy-policy/privacy-policy

·      File transfer and storage: Dropbox. https://www.dropbox.com/en_GB/privacy

·      Link Pharmacy Limited. 88A King Street, MAIDSTONE, Kent, ME14 1BH ( Data Processor for Summary Care Records )

·      Payment Processing. WorldPay https://privacy.worldpay.com/policies

·      Payment Processing. Stripe https://stripe.com/gb/privacy

·      Apple App Store: https://www.apple.com/uk/legal/privacy/data/en/app-store/

·      Google Play Store: https://policies.google.com/privacy?hl=en-US

International Data Transfers

We use data processors located outside the European Economic Area only after taking such steps as are required to ensure that Personal Data they process on our behalf receives protection equivalent to that provided in the EEA. Our processors are either certified as compliant with the EU-U.S. Data Privacy Framework where they are located in the USA or have entered into an agreement with us containing the model clauses approved by the European Commission as providing contractual protection equivalent to that provided by the data protection regulations applicable in the EEA.

Do We Share Your Personal Information?

Other than as outlined above (for example where we use third party service providers), we will not usually disclose personal data. However we may disclose your information to third parties in the following circumstances:

·       if we are under a legal or regulatory obligation to do so;

·       if we believe your use of our websites has or may violate any law, regulation or our Terms of Use,

·       if we believe you are or may be a threat to safety, security, property, our rights or the rights of others; or

·       in a merger, acquisition, change of control, joint venture or other business combination involving us.

Children's Data

The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.

As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.

Information Security

We maintain technical and physical safeguards that are designed to protect the security and integrity of your Personal Information, and to guard it against accidental or unauthorised access, use, alteration or disclosure to unauthorised third parties. These measures include device encryption, firewalls and virus checking procedures.

Where we keep Personal Data files on local devices these devices are protected and accessible only to authorised Happy Pharmacy employees.

We regularly review our security systems to ensure that your Personal Data remains safe and secure.

Cookies

Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

How You Can Make A Complaint About Our Use Of Information

We make every effort to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures.

Any complaints should be addressed to the Data Protection Officer using the contact details below. If we fail to resolve your complaint to your satisfaction, you have the right to contact the UK Information Commissioner.  For further information on how to do that, please go to the following webpage: https://ico.org.uk/concerns.   

How You Can Contact Us

This privacy policy was drafted with brevity and clarity in mind. It does not provide exhaustive detail of all aspects of our collection and use of personal information. However, we are happy to provide any additional information or explanation needed. Any requests for this should be sent to the address below.

The Data Protection Officer is Barry Last. If you want to request information about our privacy policy, make requests concerning your data or make a complaint, you can email us at help@happypharmacy.co.uk or write to:

FAO Data Protection Officer

Waterfall Group Ltd, 

Eurolink 4, Bingham Road,

Unit 18, Precision 2 Business Park,

Sittingbourne ME10 3TR