Processor terms
This is the public shape of the schedule a lab accepts at onboarding. The signed copy in the app wins if they differ.
Roles. The lab is the data fiduciary (DPDP Act, 2023) and remains the clinical establishment. We are the processor for patient data, and a body corporate under CERT-In directions.
Purposes. Accession, testing, reporting, billing, quality records, and the consents the lab collected. No secondary use for our own marketing. Camp/marketing messages only under the lab’s separate promotional consent, never to a minor’s record.
Region. Primary storage in India. Subprocessors, when any, will be named in the signed schedule. Patient payloads do not go to error trackers.
Aadhaar. We do not receive, store, or log Aadhaar numbers, masked Aadhaar, eKYC XML, or Aadhaar PDFs.
HIV records. Restricted results are stored under the lab’s HIV Act duties. We do not auto-deliver them on WhatsApp, SMS, B2B portals, or ABDM unless a specific consent record exists.
Breach. We keep an incident record with an affected-patient list so the lab can meet the Board’s 72-hour clock. CERT-In’s 6-hour clock is our ops runbook.
End. Export, then delete, except where the lab placed a retention or legal hold, or where we must keep ICT logs under CERT-In.
Related: Privacy, Security, Terms, Compliance.