Data Protection

Home Data Protection

By : Lydia Hartley Comments: 0

Data Controller and Contact Details

Absolute Best Pharmacies (abpharmacies.com) is operated by Lydia Hartley, who acts as the data controller for personal data processed through this website.

Controller: Lydia Hartley

Postal Address: 2200 W Lawrence Ave, Chicago, IL 60625, United States of America

Email: [email protected]

Scope and Applicability

This notice describes how we collect, use, disclose, and protect personal data when you visit or interact with abpharmacies.com. It is intended to meet the transparency requirements of the EU/EEA General Data Protection Regulation (GDPR) for individuals located in the EU/EEA and to align with applicable United States privacy laws, including state privacy statutes. If any provision here conflicts with a mandatory law that applies to you, that law will govern.

Absolute Best Pharmacies is an informational resource and does not provide pharmacy dispensing services. We do not seek protected health information as defined by U.S. HIPAA. Please do not submit sensitive health information unless necessary for your inquiry.

Categories of Personal Data We Process

  • Identifiers and contact details: name, email address, and any information you provide via forms or email.
  • Internet or device information: IP address, device identifiers, browser type, operating system, referring URLs, and pages visited.
  • Usage and interaction data: time on page, clickstream, scrolls, and similar analytics events.
  • Preferences and communications: newsletter preferences, consent choices, and correspondence.
  • Approximate location data: derived from your IP address (city/region-level, where available).
  • User-generated content: questions, reviews, or feedback you submit.
  • Professional information: if you identify yourself as a healthcare professional in communications.
  • Sensitive data: only if you voluntarily provide health-related or other sensitive information in free‑text fields; we discourage submitting such data.

Sources of Personal Data

  • Directly from you when you contact us or provide information through forms or email.
  • Automatically from your device through cookies and similar technologies.
  • From service providers that support hosting, security, analytics, and communications, where permitted by law and contract.

Purposes and Legal Bases for Processing (GDPR)

  • Provide and operate the website: to deliver pages, content, and core functionality. Legal basis: legitimate interests (ensuring the site functions as intended).
  • Communications and support: to respond to inquiries, provide requested information, and manage subscriptions you request. Legal basis: consent (where required) and/or legitimate interests; performance of a contract if we provide a service you sign up for.
  • Analytics and improvement: to understand usage, measure performance, and enhance content and security. Legal basis: consent where required for non-essential cookies; legitimate interests for aggregated, privacy-preserving metrics.
  • Security and fraud prevention: to detect, investigate, and prevent malicious or illegal activities. Legal basis: legitimate interests and legal obligations.
  • Legal compliance: to comply with applicable laws, enforce our terms, and respond to lawful requests. Legal basis: legal obligations.
  • Recruitment or professional outreach: if you contact us regarding collaboration or opportunities. Legal basis: legitimate interests or steps prior to entering a contract.

Legitimate Interests Relied Upon

  • Operating a secure, reliable, and user-friendly informational website.
  • Measuring and improving content relevance and site performance.
  • Preventing misuse, ensuring integrity of systems, and protecting our users.

Recipients and Disclosure

We disclose personal data only as necessary for the purposes described above and subject to confidentiality and security obligations.

  • Hosting and infrastructure providers that enable our website to operate.
  • Security and fraud prevention partners that help protect users and systems.
  • Analytics and measurement service providers (where used) to understand site performance.
  • Communication and email service providers for sending messages you request.
  • Professional advisors (legal, accounting) under duties of confidentiality.
  • Authorities or other parties where required by law, legal process, or to protect rights and safety.

International Transfers

Our website infrastructure is located in the United States. If you are located in the EU/EEA, your personal data may be transferred to countries outside the EU/EEA, including the U.S. Where required, we rely on appropriate safeguards such as European Commission Standard Contractual Clauses and implement supplementary measures consistent with applicable guidance.

Retention of Personal Data

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, or reporting requirements. Retention periods are determined based on the nature of the data and our legal obligations.

  • Server logs and security records: typically up to 12 months, unless extended for security investigations.
  • Contact inquiries and correspondence: typically up to 24 months after resolution.
  • Newsletter or subscription data: retained until you unsubscribe or your account (if any) is closed.
  • Cookies: retained according to their specific lifespan as set on your device.

Cookies and Similar Technologies

We use cookies and similar technologies to operate the site, remember preferences, and, where applicable, perform analytics. Non-essential cookies are used only with your consent where required by law.

  • Strictly necessary cookies: essential for site functionality and security.
  • Analytics cookies: help us understand how the site is used so we can improve it.
  • Functionality cookies: remember your choices and preferences.

You can manage cookies through your browser settings (e.g., blocking or deleting cookies) and device-level controls. If you disable cookies, some features may not function as intended. At this time, we do not respond to browser Do Not Track signals due to the lack of a common industry standard.

Your Rights Under GDPR

If you are located in the EU/EEA, you have the following rights subject to applicable limitations:

  • Right of access to your personal data and information about processing.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure where grounds apply (for example, consent withdrawal or data no longer needed).
  • Right to restriction of processing in certain circumstances.
  • Right to object to processing based on legitimate interests, and to direct marketing at any time.
  • Right to data portability for data you provided, where processing is based on consent or contract and carried out by automated means.
  • Right to withdraw consent at any time without affecting prior lawful processing.
  • Right to lodge a complaint with a supervisory authority in your habitual residence, place of work, or place of alleged infringement.

To exercise your rights, contact us at [email protected] or write to the postal address above. We will respond without undue delay and within one month, extendable as permitted by law.

U.S. Privacy Rights

Depending on your state of residence, you may have rights similar to those described under the GDPR, including rights to know/access, delete, correct, receive a portable copy, and to opt out of certain processing. California residents, for example, have rights under the CCPA/CPRA, including the right to non-discrimination for exercising those rights.

  • Right to know/access: request details about categories and specific pieces of personal information we have collected about you.
  • Right to delete: request deletion of personal information, subject to exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to data portability: receive your information in a portable, readily usable format.
  • Right to opt out: opt out of the sale or sharing of personal information for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: where applicable by law.

We do not sell personal information and do not share personal information for cross-context behavioral advertising. If our practices change, we will update this notice and honor applicable opt-out rights.

To submit a U.S. privacy request, email [email protected] or write to the postal address above. We may need to verify your identity (for example, via your email address or additional information). You may designate an authorized agent as permitted by law by providing a signed authorization and sufficient verification. If we deny your request in whole or in part, you may appeal by replying to our decision email with the subject line “Appeal.”

Security Measures

We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures include access controls, encryption in transit, need-to-know access, and vendor due diligence. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Children’s Privacy

Our website is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us so we can take appropriate action.

Automated Decision-Making

We do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects on you. If this changes, we will provide information about the logic involved and the significance and envisaged consequences for you, and where required, obtain your consent.

How to Contact Us and Exercise Your Rights

For any questions about this notice or to exercise your rights, please contact:

Absolute Best Pharmacies
Attn: Data Protection
2200 W Lawrence Ave, Chicago, IL 60625, United States of America
Email: [email protected]

Please include sufficient information to verify your identity and describe your request in detail. We will respond within the timeframes required by applicable law.

Changes to This Notice

We may update this Data Protection notice from time to time to reflect changes in our practices or legal requirements. Material changes will be indicated by updating the effective date below.

Effective Date

August 22, 2025