Legal
Privacy Policy
Last updated: [date]
Draft outline
This page lists what the final policy will cover. The final text is being written by legal counsel for the United States, Canada and the United Kingdom.
1. Who we are
[Legal company name and state of incorporation], how to contact us, and our privacy contact.
2. Our two roles
We are the controller for website and account data, and a processor for the patient data we handle on behalf of labs.
3. What we collect
Lab account details, website usage, and patient data entered by labs.
4. How and why we use it
The purposes for each type of data, with the legal bases under UK GDPR.
5. AI processing
What Lab Desk's AI does, and our commitment that patient data is never used to train AI models.
6. Sub-processors
Amazon Web Services for hosting, AI and email, Stripe for payments, and any analytics provider.
7. Where data is stored
US and Canadian labs are hosted in the United States, with safeguards for Canadian data. UK labs are hosted in the United Kingdom.
8. Retention and deletion
How long each type of data is kept and how it is deleted.
9. Security
The technical and organizational measures that protect data.
10. Your rights
Rights by region (US, Canada, UK). Patients should contact their lab first, since the lab controls their records.
11. Cookies
How we use cookies. See our Cookie Policy.
12. Changes
How we tell you about changes, and the effective date.