Call us on 01 619 0229
| Mon - Fri 8am to 7pm, Sat 9am to 5pm, Sun 10am to 4pm

Privacy and Cookie Policy

Superdrug Online Doctor is a website and service operated by HEALTH BRIDGE LIMITED ("We"/"Us"). We are registered in England and Wales under company number 07392646 and have our registered office and trading address at Superdrug Online Doctor, Health Bridge Limited, 46 Essex Road,  London, N1 8LN, United Kingdom.. We are committed to protecting and respecting your privacy.

This Privacy and Cookie Policy (the “Policy”) (together with our Terms & Conditions and any other documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. By using our online properties including our site located at and purchasing our products and services you agree to the use we make in accordance with this Policy of all personal data you provide to us or we collect from you. If you do not agree with any term in this Policy, please do not use our online properties.

For the purpose of the Data Protection Act 2018 (the “Act”), the data controller is Health Bridge Limited.

Our nominated representative for the purpose of the Act is David Meinertz.

This Policy explains:

  • What information we may collect from you.
  • The types of cookies we use and how you can reject these cookies.
  • Where we store your personal data.
  • How we keep your information secure.
  • What we do with your data.
  • Uses we make of your data.
  • To whom we may disclose your data.
  • Your rights.

Information we may collect from you
In this Policy your "data" means information or pieces of information relating to you or that could allow you to be directly or indirectly identified.

We may collect and process the following data about you:

Information you voluntarily provide
  • Information that you provide by filling in forms and medical questionnaires on our online properties. This includes information provided at the time of accessing our online properties, subscribing to our services, posting material or requesting further services. We may also ask you for information when you enter a competition or promotion sponsored by Health Bridge Limited and when you report a problem with our online properties.
  • If you contact us, we may keep a record of that correspondence.
  • We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
  • Details of transactions you carry out through our online properties and of the fulfilment of your orders.
Information we collect from the device you use to access our online properties
When you visit our online properties or interact with our services, we (and our advertisers and/or other service providers) may use a variety of technologies that automatically or passively collect information about how our services are accessed and used including:

Technical device information

  • the type of device you use (e.g are you using an Apple or a Samsung device);
  • a unique device identifier (for example, your device's IMEI number or the MAC address of the device's wireless network interface);
  • network information (e.g are you on the 3 network or BT Broadband);
  • your operating system;
  • your IP address and HTTP referrer information;
  • your login information;
  • the browser you are using and what version it is (e.g. are you using the Chrome or Safari browser?);
  • time zone setting (e.g. GMT, EST?).

Other information about your visit

  • the full Uniform Resource Locators (URL) clickstream to, through and from our online properties (including date and time);
  • services you viewed or searched for;
  • page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page;
  • any phone number used to call our customer service number.

Information we receive from other sources

We work closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them.

Cookies, pixels and other similar technologies
Cookies are small pieces of data that are stored on your computer, mobile phone or other device. Pixels are small blocks of code on web pages that do things like allow another server to measure viewing of a webpage and often are used in connection with cookies.

We use the following cookies:

Strictly necessary cookies. These are cookies that are required for the operation of our online properties. They include, for example, cookies that enable you to log into secure areas of our online properties or make use of e-billing services.

Analytical/performance cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our online properties when they are using it. This helps us to improve the way our online properties work, for example, by ensuring that users are finding what they are looking for easily.

Functionality cookies. These are used to recognise you when you return to our online properties. This enables us to personalise our content for you, greet you by name and remember your preferences.

Targeting cookies. These cookies record your visit to our online properties, the pages you have visited and the links you have followed. We will use this information to make our online properties more relevant to your interests. We may also share this information with third parties for this purpose.

Cookies do lots of different jobs designed to help us improve our online properties and to deliver a better and more personalised service.

They enable us:
  • To estimate our audience size and usage pattern.
  • To store information about your preferences, and so allow us to customise our site according to your individual interests.
  • To speed up your searches.
  • To recognise you when you return to our site.
  • We have outlined below the individual cookies we use and why we use them:

Name of Cookie Expiry Period Purpose Other Information
PHPSESSID Session Your account login
dr_session Session Your account login
dred_pid Session Your account login
PREF 2 years User experience
id 2 years User experience
mc 1 year User experience
_dc_gtm_UA-24605896-1 session User experience
_ga 2 years User experience
_gali session User experience
_gat_UA-24605896-1 session User experience
is_returning 5 years User experience
uid session User experience
test_cookie session User experience
optimizelyBuckets 10 years User experience
optimizelyEndUserId 10 years User experience
optimizelyPendingLogEvents 10 years User experience
optimizelySegments 10 years User experience
__qca 18 months User experience
ki_r 5 years User experience
ki_t 5 years User experience

You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of our online properties. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our online properties.

For more information about cookies or if you would like to learn how to remove cookies set on your device, visit:

Where we store your personal data

The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"), including to countries that do not offer the same level of protection with respect to personal data as required in the EEA. It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff maybe engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of services. By submitting your personal data, you acknowledge and consent to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

We are aware of the recent ruling from the European Court of Justice regarding transfers to the USA. We are monitoring the guidance from the ICO carefully and will follow their new guidance once issued.

Information security
We take appropriate security measures to protect against unauthorised access to or unauthorised alteration, disclosure or destruction of data. These include internal reviews of our data collection, storage and processing practices and security measures, including appropriate encryption and physical security measures to guard against unauthorised access to systems where we store personal data. All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology.

Where we have given you (or where you have chosen) a password which enables you to access certain parts of our online properties, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

Uses made of your data
We use information held about you in the following ways:
  • To ensure that content from our online properties is presented in the most effective manner for you and for your computer.
  • To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes including responding to your queries or comments.
  • To carry out our obligations arising from any contracts entered into between you and us. You understand that in order to provide our services to you we need to share your personal data (including sensitive medical data) with doctors and non-medical staff working at or with Health Bridge Limited as well as with pharmacies (including but not limited to pharmacies operated by Superdrug Stores plc), hospitals and laboratories working with us to deliver medical services to you. We ensure that any personal data we disclose in accordance with our Policy is kept to the minimum required to allow the safe and effective delivery of services to you.
  • You also understand and agree, that we will use third party delivery companies, such as Royal Mail and other delivery service companies (“Delivery Providers”), to deliver medicines to you.  We do not and cannot take responsibility for the errors of Delivery Providers.  For example, we are not responsible if your medicine is accidentally delivered to your neighbour.
  • To allow you to participate in interactive features of our services, when you choose to do so.
  • To notify you about changes to our services.
By using our service you consent to Health Bridge Limited using 3rd party products and services to collect & analyse information about your use of the services. By doing this we aim to provide a better and more personalised and a continuous service for each of our customers and to use this information for marketing & administration purposes, as follows:

  • Analysing individual and aggregate customer data
  • Carrying out market research
  • Identifying and executing improvements to our services
  • Providing marketing communications to you about Health Bridge Limited & partner products, services & offers
  • Informing you of changes to our services.

We will never sell your data! You understand that third party services that Health Bridge Limited uses change from time-to-time and may not always be reflected concurrently in this Privacy and Cookie Policy. From time to time we may also use your data, or permit selected third parties to use your data, to receive feedback about our services or to provide you with information about our goods and services which may be of interest to you. We or they may contact you about these by SMS, Email, post or telephone. Health Bridge Limited reserves the right to change third party service providers and will use best endeavours to notify you as soon as reasonably practicable each time Health Bridge Limited adds or removes a third party service provider.
Currently, Health Bridge Limited works with the following third party service providers:

  • Superdrug - to fulfil our services; where customers opt-in to collect Health & Beauty card points some data is sent to Superdrug to enable them to process the points (customer ID, transaction ID, purchase amount, loyalty card number and transaction date/time) and for marketing, research & analysis purposes;
  • Ometria - to help Health Bridge Limited analyse customers' behaviour and help Health Bridge Limited implement improved marketing communications (;
  • Inspectlet - to help Health Bridge Limited analyse customers’ use of its websites and identify improvements (;
  • Mailchimp & Mandrill  - to send email communications to customers ( and;
  • Trustpilot - to solicit, collate & display reviews of products & services (

If you do not want us to use your data in this way, or to pass your details on to third parties to collect & analyse information about your use of the services, please change your preferences in your patient record. Please untick the ‘Newsletter’ or ‘Email’ box in the ‘Settings’ tab of your patient record or click the the unsubscribe link that you will find at the bottom of every email we send to you.

Disclosure of your information
We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.

Also, if you order a product or service from us, we may share your personal data with our suppliers (including pharmacies operated by Superdrug Stores plc) and other third parties to allow delivery of the products and services you have ordered. Any such suppliers or third parties are not authorised by us to use your personal data in any other way and will be required by us to implement measures to protect your personal data.

We may disclose your personal information to third parties:
  • In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
  • If Health Bridge Limited or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
  • If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our Terms & Conditions and other agreements; or to protect the rights, property, or safety of Health Bridge Limited, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
  • In order to detect, prevent or otherwise address fraud, security or technical issues.
Your rights
You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by ticking the box in your Patient Record tab or by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at Superdrug Online Doctor, Health Bridge Limited, 46 Essex Road, London N1 8LN, UK or by emailing [email protected] Likewise you can contact us if you wish to report any violations of the privacy Policy.

Our online properties may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

When you use our services, we make good faith efforts to provide you with access to your personal information and either to correct this data if it is inaccurate or to delete such data at your request, if it is not otherwise required to be retained by law or for legitimate business purposes. You can ask us to suspend the account you created on our online properties by following the instructions on our online properties regarding suspension of accounts currently located in your electronic patient record.

If you would like to discontinue visiting Superdrug Online Doctor as a patient you can click on the suspend button in your electronic patient record. Your account will become inactive with immediate effect and you will not be able to access your electronic patient record. This action cannot be undone. You acknowledge and agree that Superdrug Online Doctor is required by law to archive electronic patient records including your personal information, communication and treatments for a minimum of 10 years.

Access to information
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act. You can exercise this right at any time by contacting us using the contact details below.

Changes to our Policy
Any changes we may make to our Policy in the future will be posted on this page and, where appropriate, notified to you by e-mail.

Questions, comments and requests regarding this Policy are welcomed and should be addressed to Superdrug Online Doctor, Health Bridge Limited, 46 Essex Road, London, N1 8LN, UK or emailed to [email protected].

The latest CQC inspection found this service to be "safe, effective, caring, responsive, and well-led" with a Good rating. This inspection was conducted on 18th April 2019 and the results were published on the 7th June 2019. To find out more about this inspection, please see here.