Last updated 3 September 2026
Data processing
The terms on which we handle patient records for you. This is the document to hand an accreditation assessor who asks who touches your data.
The short version. Your laboratory decides what happens to patient records. We only act on your instructions, we list every supplier that touches the data, we tell you quickly if something goes wrong, and we give it all back and delete our copies when you leave.
1. Roles
For patient records held in LabDiGi, your laboratory is the controller: you decide what is collected and why. To be confirmed is the processor: we act only on your documented instructions. Your instructions are these terms, your subscription agreement, and the configuration choices you make in the product.
If we ever believe an instruction from you would breach applicable law, we will tell you rather than carry it out silently.
2. What we process
| Item | Detail |
|---|---|
| Subject matter | Providing a laboratory information system to your laboratory. |
| Duration | For as long as your subscription runs, plus the deletion window in section 7. |
| Categories of person | Your patients, your staff, and referring doctors you record. |
| Categories of data | Identity and contact details, age and sex, referring clinician, test requests, results and reference ranges, report content including clinical remarks, invoices and payments, and audit records of who did what and when. |
| Special category data | Yes. Test results are health data and are treated as the most sensitive material in the system. |
3. Our undertakings
- We process laboratory data only on your instructions, and for no purpose of our own.
- We do not sell it, share it for advertising, or use it to train machine learning models.
- We do not use one laboratory’s data to serve another. Tenant isolation is enforced at the database, not in the interface.
- Everyone with access is bound by confidentiality obligations that survive the end of their engagement.
- Access by our staff is limited to those who need it to run or support the service, is granted for a specific purpose, and is logged.
4. Security measures
- Encryption in transit and at rest.
- Role-based access control enforced on the server: reception registers, technicians enter, pathologists verify, administrators configure.
- An append-only amendment history. A released result is never overwritten; an amendment creates a new version, retains the previous one, and records who made it and why.
- An exportable audit trail covering creation, amendment and release, for any date range.
- Daily backups, with restoration tested periodically.
- Multi-factor authentication available on all accounts.
5. Sub-processors
We use a small number of suppliers to deliver the service. Each is bound by written terms no less protective than these, and each may process data only to deliver its part of the service.
| Purpose | What it touches |
|---|---|
| Cloud hosting and database | All laboratory data, at rest and in transit. |
| Transactional email and messaging | Report delivery and system notifications you trigger. |
| Payment processing | Your billing details only. No patient data. |
| Error and performance monitoring | Technical diagnostics. Configured to exclude patient identifiers. |
We will give you at least 30 days’ notice before adding or replacing a sub-processor that handles laboratory data. If you reasonably object on data protection grounds, you may terminate without penalty and export everything.
6. Incidents
If we become aware of a breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware. We will tell you what happened, what data was involved, what we are doing about it, and what we recommend you do. We will give you the information you need to meet your own notification obligations, and we will not wait for a complete investigation before telling you something has happened.
7. Return and deletion
- You can export your full laboratory to open formats at any time during the subscription, without charge and without asking us.
- After termination we keep the data for 30 days so you can export it. On request we will delete it sooner.
- After that window we delete it from live systems, and from backups within a further 90 days as backup cycles expire.
- We will confirm deletion in writing if you ask.
8. Audit and assistance
We will give you the information you reasonably need to demonstrate compliance, including for a laboratory accreditation assessment. Where you receive a request from a patient exercising their rights, we will help you respond. If a patient approaches us directly, we will refer them to you rather than act on it ourselves.
9. International transfers
Some sub-processors operate outside Sri Lanka. Where laboratory data is handled outside the country, we rely on the supplier’s contractual data protection commitments. Tell us if your accreditation or your own policy requires data residency in a particular jurisdiction, and we will tell you honestly whether we can meet it.
Who we are
Not ready to publish. The registration details below are placeholders. Fill them in at src/lib/company.ts before this page goes live.
| Registered name | To be confirmed |
| Registration number | To be confirmed |
| Registered address | To be confirmedSri Lanka |
| Data protection contact | To be confirmed |
| Reach us | +94 77 549 1905on WhatsApp, or by telephone |