Southampton Travel Vaccines

Privacy Policy

This policy explains how Southampton Travel Vaccines collects, uses, shares and protects personal information, including health information.

Effective 3 September 2026 Version 2026-09-03

Who we are

Southampton Travel Vaccines is the controller of personal information used to provide this website and our travel-health services. You can contact us at [email protected] or through the contact page.

Information we collect

We collect identity and contact details, date of birth, sex at birth, account and security information, appointment details, orders, payments and communications.

To assess and provide care, we collect health information such as medical history, medicines, allergies, vaccination history, pregnancy or breastfeeding information, travel itinerary and clinical notes. Health information is special category data.

We may also collect technical and security information associated with use of the website, such as IP address, device or browser information, authentication events and necessary cookies.

Where information comes from

Most information comes directly from you. Information may also be added by authorised staff and clinicians during care, received from somebody authorised to act for you, or generated through appointments, orders, payments and communications with the service.

Why we use information

We use personal information to create and secure accounts, arrange appointments, assess clinical suitability, provide and document care, manage orders and payments, communicate with you, answer enquiries, prevent misuse, meet regulatory duties and improve service operation.

Our Article 6 lawful bases may include performance of a contract, compliance with legal obligations and our legitimate interests in operating and securing the service and providing effective administration. Where we process health information for care, we rely on the applicable Article 9 condition for health or social care delivered by or under the responsibility of a health professional. Where consent is the appropriate basis for a separate optional activity, you may withdraw it.

Who we share information with

We share information only where necessary with authorised clinicians and staff, participating pharmacy locations, payment providers, website and database hosting providers, email and communications providers, professional advisers, regulators and public authorities, or emergency services where required.

Current service providers include Railway for application hosting, Supabase for database infrastructure, Resend for email delivery and Trust Payments for payment processing. Each receives only the information needed for its role.

International transfers

Some technology suppliers may process information outside the United Kingdom. Where this occurs, we use an applicable adequacy regulation or appropriate safeguards such as contractual protections, and assess the protection available for the information.

How long we keep information

We keep clinical records for the period required by applicable healthcare, professional, indemnity and legal requirements. Account, appointment, order, payment and communication records are retained for as long as needed for the service, legal obligations, dispute handling, fraud prevention and establishment or defence of legal claims.

When information is no longer required, it is deleted or anonymised securely. Retention may differ where a legal hold, safeguarding concern or regulatory requirement applies.

Your rights

Depending on the circumstances, you may have rights to access your information, correct it, request erasure or restriction, object to processing, receive portable data and withdraw consent where consent is the lawful basis. Some rights are limited where records must be retained or processing is required for care or by law.

To exercise a right, contact [email protected]. We may need to verify your identity before acting.

You may complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the opportunity to address your concern first.

Automated recommendations

The website may use answers and itinerary details to organise or highlight possible travel-health recommendations. These outputs support, but do not replace, clinician review and are not used alone to make a legal or similarly significant decision about you.

Security and account protection

We use technical and organisational safeguards designed to protect information, including access controls, authentication, encryption and monitoring. No internet service can guarantee absolute security, so tell us promptly if you suspect unauthorised account access.

Cookies

We use cookies and similar storage that are necessary for authentication, security and core website functions. If optional analytics or marketing technologies are introduced, they will require the appropriate notice and choice before use.

Children

Online patient account registration is restricted to people aged 18 or over. Information about a child may only be handled through an appropriate adult and clinical process where the service permits it.

Policy changes

We may update this policy as services, suppliers or legal requirements change. The current version and effective date will be published here, and material changes will be brought to users' attention where appropriate.