Legal

Privacy Policy

Last updated: [date]

Draft outline

This page lists what the final policy will cover. The final text is being written by legal counsel for the United States, Canada and the United Kingdom.

1. Who we are

[Legal company name and state of incorporation], how to contact us, and our privacy contact.

2. Our two roles

We are the controller for website and account data, and a processor for the patient data we handle on behalf of labs.

3. What we collect

Lab account details, website usage, and patient data entered by labs.

4. How and why we use it

The purposes for each type of data, with the legal bases under UK GDPR.

5. AI processing

What Lab Desk's AI does, and our commitment that patient data is never used to train AI models.

6. Sub-processors

Amazon Web Services for hosting, AI and email, Stripe for payments, and any analytics provider.

7. Where data is stored

US and Canadian labs are hosted in the United States, with safeguards for Canadian data. UK labs are hosted in the United Kingdom.

8. Retention and deletion

How long each type of data is kept and how it is deleted.

9. Security

The technical and organizational measures that protect data.

10. Your rights

Rights by region (US, Canada, UK). Patients should contact their lab first, since the lab controls their records.

11. Cookies

How we use cookies. See our Cookie Policy.

12. Changes

How we tell you about changes, and the effective date.