Legal

Privacy Notice

How TheraTrack collects, uses, and protects information about visitors, prospects, and pilot users.

Last updated: May 2026.

Who we are

TheraTrack ("we", "us") is a digital workflow product and service for NHS aseptic pharmacy, operating from Plymouth, United Kingdom. You can reach us at info@theratrack.co.uk.

Information we collect

  • Contact enquiries: if you submit our contact form or email us, we receive your name, email, organisation, and message.
  • Pilot and trial usage: within the TheraTrack desktop application, organisations control their own data. Where we host or assist with a pilot, we may process operator and prescription data as a processor on behalf of that NHS organisation, under a written agreement.
  • Website analytics: we keep website analytics minimal and avoid third-party tracking where possible.

How we use it

  • To respond to your enquiry or request a follow-up.
  • To provide and improve the TheraTrack platform under our agreements.
  • To meet legal and regulatory obligations, including audit and clinical safety requirements where applicable.

Lawful basis

We rely on legitimate interests for responding to enquiries, contract performance for delivering services to NHS organisations, and consent where required (for example, marketing communications).

Sharing

We do not sell personal data. We share information only with trusted infrastructure providers necessary to run the service, all under appropriate data processing terms.

Retention

We retain enquiry data only as long as needed to respond and follow up. Pilot/service data is retained according to the agreement with the relevant NHS organisation and applicable record-keeping requirements.

Your rights

Under UK GDPR you have rights to access, correction, deletion, restriction, portability, and objection. To exercise any of these, email info@theratrack.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO).

Security

We follow good-practice technical and organisational measures appropriate to our maturity stage. As we move toward production deployment with NHS organisations, we will progress to NHS-grade authentication, encryption, and secrets management.

Changes

We will update this notice when our practices change. Material changes will be communicated to active pilot organisations directly.