The table below sets out each purpose and its lawful basis under Article 6 UK GDPR.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and operating your account, including sending one-time sign-in links and messages about your account | Account data, technical data | Performance of a contract (Article 6(1)(b)) |
| Sending new-article emails and occasional communications about the products and services of our publisher, including Dataforge PMR | Subscription data | Consent (Article 6(1)(a)), which you may withdraw at any time; every email carries a one-click unsubscribe |
| Editorial planning, using aggregated answers to "what brings you here" | Account data | Legitimate interests (Article 6(1)(f)): understanding our readership to decide what to publish |
| Handling correspondence, corrections and complaints | Correspondence | Legitimate interests: running an accurate, accountable publication |
| Securing the Site, preventing abuse and rate-limiting sign-in links | Technical data | Legitimate interests: network and information security |
| Establishing, exercising or defending legal claims and complying with legal obligations | Any of the above, as relevant | Legitimate interests; legal obligation (Article 6(1)(c)) |
Marketing, stated plainly.The email list you join through the Site is used for new-article notifications and for occasional marketing of our publisher products and services, including Dataforge PMR. We do not sell, rent or share your email address with any third party for that third party’s own marketing, and no one else’s products are marketed to the list. You can unsubscribe at any time, with immediate effect, using the link in any email or by writing to us.
Where we rely on legitimate interests we have carried out the balancing required by law and concluded that the processing is necessary and does not override your interests, rights and freedoms. You may object at any time under section 8 below.
We use a small number of service providers who process personal data on our behalf under written contracts meeting the requirements of Article 28 UK GDPR: our hosting provider, our email service provider [name the ESP] and our analytics provider [name the analytics tool, if any]. They act only on our instructions.
Support of the Site through Patreon takes place on Patreon’s own platform under Patreon’s own terms and privacy notice; Patreon is an independent controller of the data you give it, and we receive from Patreon only the information it provides to creators. We do not otherwise disclose personal data except where the law requires or permits it, including to professional advisers, regulators, law enforcement, or a purchaser or reorganised entity in the event of a sale or restructuring of our business, in which case this policy will continue to apply to your data.
We aim to keep personal data in the United Kingdom or the European Economic Area. Where a provider processes data outside those territories we transfer it only under safeguards recognised by UK law: UK adequacy regulations, or the International Data Transfer Agreement or Addendum, applying the data protection test in the transfer provisions of UK data protection legislation as amended in 2025. Details of the safeguards in place for any given transfer are available on request.
Account data is kept for as long as your account exists and is deleted within 30 days of account deletion. Subscription data is kept while your subscription is active; on unsubscribing we retain the minimal suppression record needed to honour your choice. Consent records are kept for as long as we rely on the consent and for a reasonable period afterwards to demonstrate compliance. Correspondence is kept for up to 24 months after the matter closes, or longer where a correction record, complaint or legal matter requires it. Server logs are kept for no more than 12 months. Where data is needed for legal claims it may be retained until the matter and any limitation periods conclude.
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls on a need-to-know basis, single-use time-limited sign-in links in place of stored passwords, and rate limiting. No transmission over the internet is entirely secure, and we cannot guarantee absolute security, but we will notify you and the Information Commissioner of any personal data breach where the law requires it.
Subject to the conditions and exemptions in UK data protection legislation, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests and to any direct marketing, which we will stop without exception; and withdraw consent at any time without affecting prior processing. We do not carry out automated decision-making producing legal or similarly significant effects.
To exercise any right, email hello@pharma.wiki. We respond within one month, extendable where the law allows for complex requests, and we may need to verify your identity, which for account holders is done through your account email. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Complaints. You are entitled to complain to us directly, and we ask that you do so first: we will acknowledge your complaint promptly, investigate it and respond without undue delay. You also have the right to complain at any time to the Information Commissioner at ico.org.uk.
The Site is a professional resource and is not directed at children. We do not knowingly collect personal data from anyone under 18, and accounts may only be created by people aged 18 or over. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy from time to time. Material changes will be signposted on the Site and, for account holders and subscribers, notified by email where the change affects how we use your data. The version number and date above always identify the current policy.