This platform is being built with trusted users and we invite you to join and leave feedback.
Privacy & Data Standards

Patient Confidentiality Policy

At MCRx, we treat medical and personal data with absolute confidentiality. Learn how we safeguard patient privacy while ensuring clinical compliance with UK regulations.

Our Core Privacy Commitments

MCRx is a directory and patient utility platform for verified UK medical cannabis patients. Because our users interact with information concerning Prescription-Only Medicines (POMs) and personal health tracking, we maintain strict technical boundaries to prevent surveillance, data harvesting, and unauthorized exposure.

Gated Medical Details

Under Chapter 6 of the MHRA Blue Guide, public advertising of POMs is prohibited. Sensitive specifications (THC/CBD percentages, pricing, stock levels, and laboratory Certificates of Analysis) are strictly gated behind patient-verified logins.

Minimal Data Collection

We do not require full clinical dossiers to use MCRx. We only collect details essential to verify your status as a legal UK medical cannabis patient (such as name, email, and redacted prescription receipts which are deleted post-verification).

Local-First Therapeutic Logs

Your personal Therapeutic Dosage Journal, including symptom ratings and product feedback, is stored securely. Individual dosage histories are never shared or made visible to clinics without your explicit request.

100% Anonymized Datasets

B2B market intelligence features (such as regional demand, terpene efficacy tracking, and strain popularity) are compiled using aggregated, macro-level data. Individual user identifiers are stripped entirely to protect patient anonymity.

How We Handle Specific Data Streams

Patient Verification Documents

When you upload a receipt, clinic letter, or prescription photo to verify your status, it is routed to a secure, private queue. Once our compliance team approves or denies your application, the uploaded file is permanently purged from our active storage.

UK GDPR Rights

You hold complete rights under UK GDPR regulations. You can request a full copy of the data associated with your profile, ask for correcting errors, or request immediate deletion of your account. Contact AHM Labs Ltd at [email protected] to exercise your rights.

Client-Side & Zero-PII Patient Tools

All interactive patient utilities (such as the GP Subject Access Request Generator, Emergency Rights Card Creator, and Dosage & Titration Calculator) operate 100% client-side inside your local browser memory. Personal patient details (e.g. NHS numbers, GP surgery names, home addresses, dosage quantities) are never transmitted to, logged by, or stored on MCRx servers.

No Third-Party Advertising Trackers

We do not permit commercial third-party trackers (like Meta Pixel or Google remarketing tags) to monitor patient behavior on MCRx. We do not display ad network banners for pharmacy products.

Read our full Comprehensive Privacy Policy

Full legal, regulatory disclosures under UK GDPR & Data Protection Act 2018.

1. Introduction & Data Controller

MCRx is built, maintained, and operated by AHM Labs Ltd, a private limited company registered in England and Wales. AHM Labs Ltd acts as the "Data Controller" for the personal data processed through our application. For any enquiries regarding your data, privacy, or this policy, you can contact our Data Protection Officer at [email protected].

2. Lawful Basis for Processing (UK GDPR)

We process your personal data under the following lawful bases set out in the UK General Data Protection Regulation (UK GDPR):

  • Article 6(1)(b) Contract: To set up your account, process login sessions, and provide the patient directory services you register to use.
  • Article 6(1)(f) Legitimate Interests: To verify your legal UK patient status, prevent portal abuse, secure our infrastructure, and comply with the UK MHRA Blue Guide guidelines prohibiting the public promotion of POMs.
  • Article 9(2)(a) Explicit Consent (Special Category Data): Because medical cannabis is a controlled drug and prescription medicine, logs in your Therapeutic Dosage Journal, symptom severity ratings, and treatment notes constitute health data ("Special Category Data"). We process this data only after obtaining your explicit consent when you write or edit your journal. You can withdraw this consent at any time by deleting your journal entries or account.

3. Data Retention & Deletion Schedules

We enforce strict retention limits to ensure we do not store your data longer than necessary:

  • Account Profile Data: Maintained until you request deletion. Upon a verified request, your profile is flagged and permanently deleted from our primary databases within 30 days.
  • Verification Uploads (Prescriptions/Letters): Receipts or clinic documents uploaded to verify your patient status are temporarily held in an encrypted container. They are permanently purged from active storage immediately upon approval or denial. Backups of these transient files are fully overwritten and cleared within 14 days.
  • Local-First Logs: Local journal records stored inside your browser's SQLite WASM storage exist solely on your client device and can be cleared instantly by clicking "Reset Local Database" in your dashboard or clearing browser storage.

4. Sub-processors & Infrastructure Partners

We keep patient data localized, but rely on secure infrastructure partners to run our application:

  • IONOS Cloud Host: Our primary application servers, PM2 processes, and PostgreSQL database are hosted on secure, virtual private servers located in UK/EU datacenters managed by IONOS.
  • Local MailServer Gateway: Transactional registration and verification emails are routed through our self-hosted mailServer container mapping to authorized relays.

5. Your Data Subject Rights

Under the UK GDPR and Data Protection Act 2018, you possess the following rights:

  • Right of Access: Request a complete, structured copy of all personal data we store about you.
  • Right to Rectification: Ask us to correct inaccurate or incomplete details.
  • Right to Erasure (Right to be Forgotten): Request the permanent deletion of your account and verification history.
  • Right to Restrict Processing: Request that we suspend processing your data while keeping it stored.
  • Right to Data Portability: Obtain your data in a portable, machine-readable format.
  • Right to Object: Object to our processing based on legitimate interests.

To exercise any of these rights, email us at [email protected].

6. Complaints to the ICO

If you believe we have processed your data unlawfully, please contact us first so we can resolve the concern. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK data protection supervisory authority:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: https://ico.org.uk

MHRA Compliance Standard • UK GDPR Compliant Framework • Updated June 2026
Menu
Theme
Notifications