Privacy Policy

1. Our commitment
The protection of your personal data is a priority for us, which is why we are committed to only processing personal data that is strictly necessary for us to provide you with the best service, guaranteeing transparency in information and the application of best practices in the field of security and protection of personal data.
The data processing operation is based on the implementation of the SHEE software - Solutions 4 Healthcare Excellent Experience (hereinafter, "SHEE"), an integrated healthcare ecosystem designed and developed by Chee - Delivering Convenient & Affordable Healthcare, Lda (hereinafter, "Chee").
The SHEE software enables the aggregation of personal customer data from a set of 9 (nine) pharmacies: (I) Farmácia Central da Amora, (II) Farmácia Ronil, (III) Farmácia Largo do Rato, (IV) Farmácia Nova da Sobreda, (V) Farmácia Garantia, (VI) Farmácia Alcântara Terra; (VII) Farmácia A5 Oeiras; (VIII) Farmácia Estácio, (IX) Farmácia Estácio Xabregas, 1 (one) parafarmácia: (I) Shee and 1 (one) Clínica: (I) Clinica da Farma&cia, belonging to the Chee Group.

2. Who is responsible for processing your personal data?
Chee - Delivering Convenient & Affordable Healthcare, Lda., legal person no. 517050366, with registered office at Rua D. João V, N.º 29-C, 1250-089 Lisboa, determines the purposes and means of the processing in question, together with the following 9 (nine) pharmacies, 1 (one) parapharmacy and 1 (clinic) that make up the Chee Group, thus assuming the position of Joint Data Controllers:

  • Farmácia Central da Amora, with the corporate name Fan Farma, Lda., legal person no. 509045600, with headquarters at Rua Movimento das Forças Armadas, N.º 22 B, 2845-380 Lisboa;
  • Farmácia Ronil, with the corporate name Ilustre Descoberta U. Lda., legal person no. 509395856, with its registered office at Rua João de Freitas Branco, N.º20 A/B, 1500-359 Lisboa;
  • Farmácia Largo do Rato, with the corporate name Kool Koncept Farma, Lda., legal person no. 502403314, with headquarters at Avenida Álvares Cabral, N.º 1, 1250-015 Lisboa;
  • Farmácia Nova da Sobreda, with the corporate name Objetivo Dinâmico Lda., legal person no. 514096985, with headquarters at Rua João de Freitas Branco, N.º 20 A/B, 1500-359 Lisboa;
  • Farmácia Garantia, with the corporate name Farmácia Garantia, Lda. legal person no. 510673279, with its registered office at Rua João de Freitas Branco, N.º 20 A/B, 1500-359 Lisboa;
  • Farmácia Alcântara Terra, with the corporate name Farmácia Alcântara Terra, U. Lda., legal person no. 501137688, with its head office at Rua João de Freitas Branco, N.º 20 A/B, 1500-359 Lisboa;
  • Farmácia Estácio, with the company name A3I Serviços Integrados de Saúde Lda., legal person no. 506406415, with headquarters at Rua Bispo de Cochim, N.º 1, 1900-455 Lisboa;
  • Farmácia Estácio Xabregas, with the company name A3I Serviços Integrados de Saúde Lda., legal person no. 506406415, with headquarters at Rua Bispo de Cochim, N.º 1, 1900-455 Lisboa;
  • Farmácia A5 Oeiras, with the corporate name Farmácia A5 Oeiras, Lda., legal person no. 506248640, with its registered office at Rua João de Freitas Branco, N.º 20 A/B, 1500-359 Lisboa;
  • Shee, with the company name CHEE - Delivering Convenient & Affordable Healthcare, Lda., legal person 517050366, with registered office at Rua D. João V, nº 29 C, 1250-089 Lisboa.  
  • Clínica da Farma&cia, with the company name 4FClinic - Healthcare, Lda., legal person no. 514998822, with headquarters at Rua João de Freitas Branco, N.º 20 A/B, 1500-359 Lisboa;

Chee also maintains partnership relationships with entities known as 1st and 2nd level subcontractors or other business partners.
The 1st level subcontractor is Magicode, Lda., legal person no. 507695615, with headquarters at Rua da Fonte nº 5, Venda-Nova 6120-035 Envendos, which processes personal data on behalf of the Joint Data Controllers listed above.
Chee also provides access to the personal data processed in the Shee software to the Pharmaceutical Industry, healthcare professionals and partners, by signing protocols to this effect, as 2nd level subcontractors.
Personal data is subject to anonymization techniques which ensure that it is not attributed to an identified or identifiable natural person. Only anonymized data is transferred to the Pharmaceutical Industry.
Whenever your personal data is processed by third parties, we will require them to provide the same level of security and privacy guarantees in terms of personal data protection.
We want to earn your trust and make you feel that your personal data is safe with us, as we will always be committed to protecting your privacy.
How do I contact the Data Protection Officer?
If you have any questions about the processing of your personal data, we will be happy to answer them at the following email address: falecomigo@shee.pt or by contacting us directly on 21 150 54 76 (national landline).

3. What personal data is processed?
The personal data processed is as follows:

- Identification data: name; preferred name (how you like to be addressed); gender; ID card number; passport number; date of birth; voice;
- Contact details: address; telephone; e-mail;
- Billing data: tax identification number (TIN);
- Other categories of non-sensitive personal data: National Health System (SNS) number; products and services purchased; average price spent; frequency;
- Family life data: household;
- Work life data: employer;
- Health data: results of biochemical parameters; biophysical parameters; prescription; clinical history; anamnesis;
- Traffic and location data: logs.

4. How do we collect your personal data?
Personal data is provided directly by data subjects, or through healthcare professionals, in the following contexts:

- In pharmacies, by filling in the Client File and the Clinical Record;
- In the service channel (API - Contactcenter), through a telephone call between the client (data subject) and a health professional;
- In the Shee software, through registration on the platform by the data subject themselves, which requires filling in an identification form and the automatic extraction of transaction data by the Shee software through Sifarma.
- On the e-commerce platform www.farmaciashee.pt, by filling in the forms made available online to identify the customer/owner.

5. Why do we need your personal data?
The registration of personal data in the Shee software provides the user with a more appropriate, efficient, effective and rapid provision of health care and treatment, insofar as it allows easier access to information about their health and, at the same time, makes it possible to share their personal data with health professionals.
On the other hand, access to certain categories of personal data, organized in the Shee software, by authorized third parties, including Shee's back-office, the Pharmaceutical Industry and partners (through the signing of protocols), contributes to the continuous improvement and personalization of the health care/treatment provided by the units that make up the Chee Group.
The development of the Shee software is the result of the digital transformation phenomenon that has had a transversal impact on the health sector, boosting a set of valuable functionalities that are in the interest of those involved - users, health professionals, the pharmaceutical industry and partners.
Consequently, the project to implement the Shee software follows the three main aims assumed by the Portuguese legal system in the field of health data protection, guaranteeing the integrity of this information, the holder's right of access to the information that concerns them, and protection against undue access and/or disclosure of this information to unauthorized third parties.
The data collected and processed by the Joint Data Controllers is aimed at and limited to the purposes of (i) automated processing of personal data, purchase and consumption history and data related to transactions carried out through the Shee computer system, (ii) sharing personal data, and/or purchase and consumption history and/or data related to transactions with healthcare professionals, the Pharmaceutical Industry and partners, (iii) personalization of services and campaigns based on customer interests, (iv) marketing communications, and (v) alarming consumption of products or services, covering the following categories of personal data:  

a) Automated processing of personal data, purchase and consumption history and data related to transactions carried out through the Shee computer system: name; preferred name (how you like to be addressed); gender; ID card number; passport number; date of birth; voice; address; telephone number; e-mail address; tax identification number (TIN); household name; employer; results of biochemical parameters; biochemical parameters; average price spent; frequency; address; products and services purchased.Tax identification number (NIF); National Health System (SNS) number; products and services purchased; average price spent; frequency; household; employer; biochemical parameter results; biophysical parameters; prescription; clinical history; anamnesis; logs;
b) Sharing personal data, and/or purchase and consumption history and/or data related to transactions with healthcare professionals, the pharmaceutical industry and partners: name; preferred name (how you like to be addressed); gender; ID card number; passport number; date of birth; voice; address; telephone number; e-mail address; tax identification number (NIF).Tax identification number (NIF); National Health System (SNS) number; products and services purchased; average price spent; frequency; household; employer; results; biochemical parameters; biophysical parameters; prescription; clinical history; anamnesis;
c) Marketing communications based on customer interests: name, e-mail address, telephone number, products and services purchased, average price spent, frequency of purchases, categories, campaigns, services, brands, frequency of visits;
d) Product or service consumption alarms: name, telephone number, e-mail address, medical history, products and services purchased, frequency.
The basis for the lawfulness of the processing of the logs corresponds to the need to comply with the legal obligation (pursuant to Article 9(2)(b) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, "GDPR") to electronically record the accesses and health data accessed, which falls to the Joint Data Controllers, set out in Article 29(7)(c) of Law 58/2019 of August 8.

The basis for the lawfulness of the processing of the other personal data listed above lies in the explicit consent of the data subject, under the terms of Article 9(2)(a) of the GDPR. The constant accuracy and updating of personal data is guaranteed through the possibility of alteration or correction by the data subject (client/user) through direct access to the Shee software, as well as at their request, via the pharmacy operator

6. How do we guarantee data processing security?
The Joint Controllers guarantee that the data is housed in systems equipped with protection measures aimed at ensuring a level of trust appropriate to the risk, in accordance with Article 32 of the GDPR.
The personal data is organized by Magicode, Lda , 1st level subcontractor, according to the following categories: (i) Customers; (ii) Logins; (iii) Log activities; (iv) Sales docs; (v) Newsletter; (vi) E-commerce; (vii) Dictionaries; (viii) Reference Tables; (ix) Forms Data; (x) Business; (xi) Actions.
In addition to the Controllers, in some cases the data may be accessed internally by 2nd level subcontractors appointed, where necessary, as data processors by the Joint Controllers. The updated list of these parties can be requested from any of the Joint Controllers at any time.
The creation of access is guaranteed by Shee's back-office, through the creation of access credentials, with three (3) profiles that differ according to the categories of personal data that the user can access (Administrator, Creator and Query).
Personal data is loaded into the Shee software and stored on the AWS cloud server subscribed to by SHEE in an ORACLE database.
The automated processing of personal data is carried out within the server.

7. How long do we keep your personal data?
Personal data will only be kept for the period strictly necessary for the purposes for which it was processed, in accordance with Article 5(1)(e) of the GDPR.
Since the processing of personal data is based on the lawfulness of the data subject's consent, as set out in Article 6(1)(a) and Article 9(2)(a) of the GDPR, the retention period corresponds to the moment of withdrawal of consent by the data subject.
The Joint Data Controllers ensure that consent is renewed after 3 years from the time it was given, by submitting a request to the data subject to this effect.
Access logs are kept for a maximum of 2 years. The deletion of personal data is guaranteed automatically by Shee's server and complies with the various applicable retention periods. When the processing of personal data depends on the consent of the data subject, the retention period corresponds to the time of withdrawal of consent.

8.    Quais os seus direitos e como poderá exercê-los?
No âmbito do cumprimento do direito de informação, consagrado no artigo 13.º do RGPD, as farmácias que compõem o Grupo Chee, enquanto Responsáveis Conjuntos pelo Tratamento, garantem a disponibilização das respetivas Política de Privacidade, no email dos titulares dos dados, para reconhecerem o seu consentimento.  
Simultaneamente, as farmácias e a Chee, publicitam de forma permanente a Política de Privacidade do software Shee no respetivo website, para consulta dos utilizadores.
Por outro lado, a Declaração de Consentimento que é disponibilizada aos titulares dos dados enfatiza as seguintes informações: (i) a identidade e os contactos dos Responsáveis Conjuntos pelo Tratamento; (ii) as finalidades do tratamento a que os dados pessoais se destinam, bem como a circunstância de o consentimento corresponder ao fundamento jurídico para o tratamento; (iii) a existência do direito de retirar o consentimento em qualquer momento, sem comprometer a licitude do tratamento efetuado com base no consentimento prestado; (iv) o direito de apresentar reclamação a uma autoridade de controlo; (v) a existência do direito de solicitar o exercício dos direitos de consulta, acesso, retificação, atualização, eliminação, oposição ou portabilidade dos dados pessoais; (vi) a existência de decisões automatizadas, incluindo a definição de perfis.
Os titulares de dados podem exercer os seus direitos de acesso e portabilidade perante qualquer um dos Responsáveis Conjuntos pelo Tratamento, mediante o envio de pedido escrito para o endereço eletrónico falecomigo@shee.pt ou entrando em contacto direto através do 21 150 54 76 (chamada para a rede fixa nacional), ou apresentado presencialmente junto dos operadores de qualquer uma das farmácias que integram o Grupo Chee.
Quando exista solicitação por parte do titular dos dados, o Responsável Conjunto pelo Tratamento que recebe o pedido fornece uma cópia dos dados pessoais em fase de tratamento. Se o titular dos dados apresentar o pedido por meios eletrónicos, e salvo pedido em contrário do titular dos dados, a informação é fornecida num formato eletrónico de uso corrente.
Os titulares dos dados podem exercer o direito de retificação mediante a apresentação de um requerimento escrito para o  falecomigo@shee.pt, ou um contacto telefónico para o 21 150 54 76 (chamada para a rede fixa nacional), no qual expõe os dados pessoais que devem ser completados/alterados e de que forma. Podem também fazê-lo presencialmente junto dos operadores das farmácias que integram o Grupo Chee.
Os titulares dos dados têm, ainda, o direito de obter de qualquer um dos Responsáveis Conjuntos pelo Tratamento o apagamento dos seus dados pessoais, mediante o exercício do direito de retirar o consentimento que corresponde à base de licitude do tratamento. 
O consentimento pode ser retirado através da mesma forma que foi dado: (i) Nas farmácias, através dos pads; (ii) No software Shee, através do acesso ao separador “Gestão de Consentimentos”; (iii) No canal de atendimento (API – Contactcenter), mediante declaração oral; (iv) Nas plataformas e-commerce www.farmaciashee.pt, através do acesso ao separador “Gestão de Consentimentos”.
Sem prejuízo, o titular dos dados pode exercer o direito de apagamento através do envio de requerimento expresso, por escrito, via correio eletrónico, para o endereço falecomigo@shee.pt.
O pedido de exercício do direito de apagamento também pode ser realizado oralmente, presencialmente junto da Chee ou dos operadores das farmácias que integram o Grupo Chee, bem como através de chamada telefónica para o 21 150 54 76 (chamada para a rede fixa nacional).
O Responsável Conjunto pelo Tratamento que recebe o pedido de exercício dos direitos, garante quer o apagamento dos dados pessoais, quer a sua retificação, num prazo máximo de um mês após a receção do pedido, enviando respetivo comprovativo ao titular dos dados através do mesmo meio em que o pedido de exercício dos direitos foi apresentado.
O titular dos dados tem o direito de se opor a qualquer momento, por motivos relacionados com a sua situação particular, ao tratamento dos dados pessoais que lhe digam respeito, incluindo, a definição de perfis. 
Nesses casos, o titular dos dados pode apresentar requerimento expresso, por escrito, através do envio de e-mail para o falecomigo@shee.pt. O pedido de exercício do direito de oposição também pode ser realizado oralmente, presencialmente junto da Chee ou dos operadores das farmácias que integram o Grupo Chee, bem como através de chamada telefónica para o 21 150 54 76 (chamada para a rede fixa nacional).
O Responsável Conjunto pelo Tratamento que recebe o pedido garante a conclusão do tratamento dos dados pessoais referente ao titular requerente num prazo máximo de um mês, sendo dessa operação notificada o titular, pelo mesmo meio em que o requerimento foi apresentado. 
O direito à limitação do tratamento é exercido nos mesmos termos que o direito de oposição, mediante a apresentação de um requerimento escrito, por e-mail, ou presencialmente junto da Chee ou dos operadores das farmácias que integram o Grupo Chee, bem como através de chamada telefónica para o 21 150 54 76 (chamada para a rede fixa nacional). 
Caso necessário, o titular de dados pessoais poderá, ainda, apresentar reclamação junto da Comissão Nacional de Proteção de Dados (CNPD).

9. Can the privacy policy be changed?
The Joint Data Controllers reserve the right to make changes to this privacy policy at any time by communicating it to their users via e-mail or directly on the website, to the extent that it is technically and legally feasible - by sending a notice to users via the contact information provided to the Joint Data Controller.
It is highly recommended that the website be consulted several times in relation to the latest modification described at the bottom.
If the changes affect processing activities carried out on the basis of the user's consent, the Joint Controller will collect new consent from the user where required.

10. Breach of Personal Data
The Chee Group will notify data subjects when a breach occurs that involves a high risk to their rights and freedoms, and is obliged to do so within 72 hours of the incident.
Pursuant to Article 34(3) of the GDPR, communication to the data subject is not required in the following cases:

- If the Chee Group has applied appropriate protection measures, both technical and organizational, and such measures have been applied to the personal data affected by the personal data breach, in particular measures that render the personal data unintelligible to any person not authorized to access such data, such as encryption;
- If the Chee Group has taken subsequent measures to ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialize; or
- If communication to the data subject would involve a disproportionate effort for the Chee Group, in which case it will make a public announcement or take a similar measure through which the data subject will be informed.

Any breach of personal data, the processing of which is the responsibility of the Chee Group, can be reported via the following e-mail address: falecomigo@shee.pt.

11. Cookie Policy
The Shee software uses cookies.
To find out more about cookies, the data subject can consult our Cookie Policy.
If you prefer not to allow cookies, you can disable cookies in the browser you use, but please note that this may prevent some web pages from being displayed correctly.

12. Data Protection Officer
Pursuant to Article 37(1)(a) and (2) of the GDPR, the Chee Group appoints a Data Protection Officer, who ensures the compliance of processing activities and the protection of data under the responsibility of the Chee Group, exercising at least the following functions:

- Informing and advising the Chee Group and its employees of their obligations;
- Monitoring compliance with applicable and relevant legislation and this Privacy Policy;
- Carrying out awareness-raising and training actions for employees involved in data processing operations;
- Acting as a point of contact for the CNPD.

Any questions relating to privacy and data protection should be addressed to the Data Protection Officer at the following e-mail address: falecomigo@shee.pt.

13. Definitions and legal references

(1) "personal data" means information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
(2) 'processing' means any operation or set of operations which is performed upon personal data or on sets of personal data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
(3) "profiling" means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects of a natural person, in particular to analyze or predict aspects relating to that person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements;
(4) 'controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria applicable to its appointment may be provided for by Union or Member State law
(5) "joint controller" means that where two or more controllers jointly determine the purposes and means of such processing, they are joint controllers. They determine, by agreement between themselves and in a transparent manner, their respective responsibilities for compliance with the GDPR;
(6) "Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
(7) "Recipient" means a natural or legal person, public authority, agency or other body that receives communications of personal data, regardless of whether or not it is a third party. However, public authorities that may receive personal data in the context of specific investigations under Union or Member State law are not considered recipients; the processing of such data by such public authorities must comply with the applicable data protection rules depending on the purposes of the processing;
(8) 'third party' means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data
9. the data subject's "consent" means a freely given, specific, informed and explicit indication of his or her wishes by which the data subject, by a statement or by an unambiguous affirmative action, signifies agreement to the processing of personal data relating to him or her;
(10) "User" means the person using this website who, unless otherwise specified, is the same as the data subject;
11."Data Subject" means the natural person to whom the personal data relates;
12. "Cookie", small units of data stored on the user's device.