Privacy Policy
Last updated: 6 August 2026
1. Who we are
SortScript is a prescription workflow platform for UK private pharmacies, operated by Quasol Ltd, registered in England and Wales (company number 15792740) at 20 Upton Lodge Close, Bushey, England, WD23 1AG. For any privacy query, contact us at support@sortscript.co.uk.
2. What data we process
2.1 Pharmacy account data (we are the controller)
- Pharmacy name, address, GPhC registration number, superintendent pharmacist name, company/VAT registration details
- Staff account details: name, email, role, login activity, IP address at login
- Billing details for your SortScript subscription (processed by our payment provider — we do not store full card numbers)
- Support correspondence
2.2 Patient data (the pharmacy is the controller; we process it on their behalf)
When a pharmacy imports a prescription batch or creates an order, the following may be processed:
- Patient name, date of birth, contact details (email, phone), delivery address
- Prescription and health data (special category data under UK GDPR Article 9): medication name, strength, dosage, prescribing clinic and prescriber name, prescription date, NHS number where provided
- Order and payment status, invoice and delivery records
We process this data strictly under the instructions of the pharmacy that controls it, for the purpose of running their prescription workflow — never for our own marketing or analytics purposes.
3. Legal basis for processing
| Data | Legal basis |
|---|---|
| Pharmacy account & billing | Performance of contract (our Terms of Service) |
| Patient contact & order data | Processed on the pharmacy's instructions — their legal basis (typically contract with the patient / legitimate interest in fulfilling a private prescription) |
| Patient health/prescription data | Processed on the pharmacy's instructions under UK GDPR Art. 9(2)(h) — provision of health/pharmaceutical care |
| Security & fraud prevention (audit logs, login IPs) | Legitimate interest in keeping the platform secure |
4. Who we share data with
We use the following sub-processors to operate SortScript. Each is bound by a data processing agreement:
- Payment processing: SumUp — patient card payments. Card details are entered directly with SumUp; we never see or store full card numbers.
- Shipping: Royal Mail (Click & Drop), ShipEngine, and/or Shippo, depending on which the pharmacy configures — used to generate labels and share the delivery address and patient name needed to dispatch an order.
- Email delivery: Resend, or the pharmacy's own SMTP server if configured — used to send order, payment, and account emails.
- SMS delivery (optional, per pharmacy): Twilio, if a pharmacy enables SMS notifications.
- Database & hosting: Neon (PostgreSQL, EU region) and Railway — infrastructure providers who store and run the platform.
We do not sell personal data, and we do not share patient data with any third party for marketing purposes.
5. Where data is stored
All data is stored in EU data centres and is not transferred outside the UK/EEA except where a sub-processor listed above operates internationally under an approved transfer mechanism (e.g. Standard Contractual Clauses).
6. How we protect data
- Encryption in transit (TLS) and at rest for sensitive fields, including third-party API credentials
- Two-factor authentication available on every staff account, with role-based access control (super admin, admin, dispenser, clinic)
- Full audit logging of actions taken on patient orders and account settings
- Rate limiting and IP allowlisting options on sensitive endpoints
- Regular automated backups with point-in-time recovery
7. How long we keep data
- Patient orders, dispensing records, and invoices: retained for as long as the pharmacy's account is active, in line with GPhC record-keeping obligations. Pharmacies are responsible for determining their own statutory retention period.
- Technical/diagnostic logs (unrelated to dispensing records): purged automatically after 90 days.
- Account data: retained while the pharmacy's subscription is active, and for a limited period afterwards to meet accounting obligations.
8. Your rights
If you are a pharmacy customer, contact us at support@sortscript.co.uk to access, correct, or delete your account data.
If you are a patient whose data has been processed through SortScript by a pharmacy, your data rights request should first go to that pharmacy, as they are the data controller. SortScript provides pharmacies with built-in tools to export or anonymise a patient's data on request. If you're unable to reach the pharmacy, contact us and we'll help direct your request.
Your rights under UK GDPR include the right to: access your data, correct inaccurate data, request erasure, restrict or object to processing, and data portability.
9. Cookies
See our Cookie Policy for details on the cookies used by this website and the SortScript application.
10. Changes to this policy
We may update this policy as SortScript evolves. Material changes will be notified to pharmacy account holders by email.
11. Complaints
If you have a concern about how your data is handled, contact us first at support@sortscript.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).