Last updated 3 September 2026
Privacy
What we collect, why, and what we will never do with a patient record. Written to be read by a lab owner, not only by a lawyer.
The short version. Patient records belong to your laboratory, not to us. We hold them so the software can work, we never sell them, we never use them to train anything, and we never look at them except when you ask us to help with a specific problem. You can export everything and leave at any time.
Two kinds of data
It matters which is which, because our obligations differ. Throughout this document, you means the laboratory that subscribes to LabDiGi.
| Kind | Examples | Our role |
|---|---|---|
| Account data | Your lab’s name and address, staff names and email addresses, billing details, support conversations, enquiries made through this website. | We decide how this is used. We are the controller. |
| Laboratory data | Patient names and identifiers, ages, referring doctors, test results, reports, invoices. | You decide how this is used. You are the controller and we act only on your instructions. See the data processing policy. |
Account data we collect
- What you give us. Contact details when you enquire or sign up, the names and roles of staff you create accounts for, and anything you send us in support requests.
- What the service records. Sign-in times, IP address, browser and device type, and an audit record of actions taken in the system. The audit trail exists because laboratory accreditation requires it, and because you need to know who released a report.
- What this website records. Basic request logs. We do not run advertising trackers or third-party analytics that profile visitors across other sites.
Why we use it
- To provide the service, authenticate users, and enforce role permissions.
- To bill you, which for metered plans means counting reports you release.
- To answer your support requests and to notify you about outages or material changes.
- To keep the service secure and to investigate misuse.
- To meet legal obligations that apply to us.
What we do not do
- We do not sell personal data, and we do not share it with advertisers or data brokers.
- We do not use patient records to train machine learning models, our own or anyone else’s.
- We do not access your laboratory data except where you ask us to help with a specific issue, or where we must to prevent an active security or data-loss incident. Such access is logged.
- We do not use one lab’s data to build features shown to another lab.
Who else is involved
Running the service means using a small number of suppliers. Each one is bound to confidentiality and may only process data to deliver its part of the service. We use suppliers for cloud hosting and databases, transactional email and messaging, payment processing, and error monitoring. We will tell you before adding a supplier that materially changes how or where your data is handled.
We may also disclose data where a Sri Lankan court or regulator lawfully compels us to. If that happens and we are permitted to tell you, we will.
Where data is held, and for how long
Data is held on managed cloud infrastructure and is encrypted in transit and at rest, with daily backups. Some suppliers operate outside Sri Lanka; where that is the case, we rely on their contractual data protection commitments.
We keep account data for as long as you are a customer and for a limited period afterwards for tax and accounting purposes. Laboratory data is kept for as long as you instruct, and is deleted after termination in line with the data processing policy. Medical records carry statutory retention obligations that fall on your laboratory, not on us. Decide your retention period deliberately.
Your rights, and your patients’ rights
You may ask us for a copy of the account data we hold about you, ask us to correct it, or ask us to delete it where we have no ongoing need or legal obligation to keep it. You can export your full laboratory data yourself at any time, without charge.
If a patient contacts us directly about their records, we will not act on that request ourselves. We will refer them to your laboratory, because those records are yours and only you can verify the person’s identity and their clinical context.
Security
Each laboratory’s data sits behind its own boundary, enforced at the database rather than in the interface. Permissions are checked on the server, so no browser can talk its way past them. Released results are never silently edited: an amendment creates a new version, keeps the old one, and records the reason.
No system is perfect. If a breach affects your data, we will tell you without undue delay, describe what happened and what we are doing about it, and give you what you need to meet your own notification obligations.
Changes
If we change this policy in a way that materially affects you, we will tell you before it takes effect. The date at the top always reflects the current version.
We aim to answer privacy questions within five working days. This policy is issued by To be confirmed, trading as LabDiGi.
Who we are
Not ready to publish. The registration details below are placeholders. Fill them in at src/lib/company.ts before this page goes live.
| Registered name | To be confirmed |
| Registration number | To be confirmed |
| Registered address | To be confirmedSri Lanka |
| Data protection contact | To be confirmed |
| Reach us | +94 77 549 1905on WhatsApp, or by telephone |