Launching 30 September 2026. Early access from 15 August 2026.

Legal

Privacy Policy

Effective 26 September 2026 · Aynstyn Technologies Private Limited

This policy explains what personal data Labgen collects, why, who it is shared with, how long it is kept, and the rights you have under Indian law. Questions? Write to [email protected].

1. Who we are and what this policy covers

Labgen is a cloud laboratory information and management platform operated by Aynstyn Technologies Private Limited, a company incorporated in India with its office in Hyderabad, Telangana (“Labgen”, “we”, “us”).

This policy applies to labgen.online and all of its subdomains (including app., docs. and demo.), the patient, consultant and corporate portals, and the Labgen Bridge agent installed in laboratories (together, the “Services”).

It is published under section 5 of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025, and rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) under the Information Technology Act, 2000.

2. Our two roles: Data Fiduciary and Data Processor

Where we are the Data Fiduciary

We decide why and how we process the personal data of visitors to our website, people who join our waitlist or contact us, the owners and staff of laboratories who hold Labgen accounts, and individuals who create their own patient, consultant or corporate portal account. For this data we are the Data Fiduciary under the DPDP Act.

Where we are a Data Processor for a laboratory

Laboratories use Labgen to register patients, record test orders and results, and issue reports and invoices. That patient data belongs to the laboratory, which is the Data Fiduciary for it. We process it only on the laboratory’s behalf and instructions, under our Terms & Conditions with that laboratory.

If you are a patient and want to see, correct or delete records a laboratory holds about you, please contact that laboratory first. If you contact us instead, we will pass your request to the laboratory and help it respond.

3. Personal data we collect

  • Website visitors: IP address, browser and device type, pages visited and your cookie choices. Optional analytics or marketing cookies are used only with your consent — see the Cookie Policy.
  • Enquiries and waitlist: name, email, phone number, laboratory name and city, and anything you write to us.
  • Laboratory accounts: the owner’s and staff members’ names, email addresses, mobile numbers, roles and login credentials (passwords are stored only as one-way hashes); laboratory name, address, GSTIN and registration details; and the documents uploaded during Lab Authentication, such as licences and registration certificates.
  • Payments: plan, amount, invoice and transaction references. Card, UPI and bank details are entered directly with our payment gateway, Razorpay, and are never stored by us.
  • Patient portal accounts: name, email, a mobile number verified by one-time password, and any reports or documents you choose to upload.
  • Consultant and corporate portals: name, professional and organisation details, contact information, and for corporate accounts the company’s GSTIN and CIN.
  • Patient data processed for laboratories: name, age, gender, contact details, referring doctor, test orders, samples, results, reports and invoices. Health and medical records are “sensitive personal data” under rule 3 of the SPDI Rules and are handled with the additional care described below.
  • Technical and security data: sign-in times, IP addresses, audit logs of changes to results and records, and data sent by laboratory analyzers through the Bridge agent.

4. Why we use it and on what basis

We process personal data only for the purposes below:

  • To create and secure accounts, and to provide, maintain and support the Services.
  • To process subscriptions, onboarding fees and campaign credits, and to issue GST invoices.
  • To verify laboratories before activating them (Lab Authentication).
  • To send service messages — sign-in codes, report-ready alerts, billing notices and security alerts — by SMS or email.
  • To answer enquiries and waitlist sign-ups and, where you have agreed, send product news. You can unsubscribe at any time.
  • To detect, prevent and investigate fraud, abuse, tampering with results and security incidents.
  • To comply with Indian law, including tax, accounting and lawful requests from authorities.

Our legal basis is either your consent under section 6 of the DPDP Act, given freely and for a specific purpose, or a legitimate use under section 7 — for example, data you voluntarily give us for a stated purpose, compliance with law or a court order, or responding to a medical emergency. Where we rely on consent you may withdraw it at any time; withdrawal does not affect processing already carried out.

We do not sell personal data, and we do not use patient data for advertising.

5. AI features

Some features — reading uploaded reports, and plain-language summaries in the patient portal — send the relevant report content to OpenAI to generate a result. This happens only when the feature is used. It is sent under OpenAI’s API terms, which do not allow it to be used to train OpenAI’s models.

AI output is informational only. It is not a diagnosis or medical advice and does not replace a report authorised by the laboratory or advice from a qualified doctor.

6. Who we share it with

We share personal data only with service providers who process it for us under contract, confidentiality and security obligations:

  • Neon (managed PostgreSQL database) and Sevalla (application hosting)
  • Google Firebase / Google Cloud Storage (report PDFs and uploaded documents) and Google sign-in
  • Twilio (SMS and one-time passwords) and Resend (transactional email)
  • Razorpay (payment processing)
  • OpenAI (AI features, as described above)

We may also disclose personal data:

  • to the laboratory whose patient you are, or to a doctor or organisation that laboratory authorises;
  • to government or law-enforcement agencies, courts or regulators when required by law;
  • to a buyer or successor in a merger, acquisition or restructuring, under the same protections.

7. Where your data is stored

Some of our service providers store or process data outside India. Section 16 of the DPDP Act permits such transfers, except to countries the Central Government has restricted, and we will stop any transfer to a restricted country. We require providers to protect data to a standard at least equal to Indian law.

8. How long we keep it

  • Account data is kept while the account is active. After closure it is deleted or anonymised within 90 days, except what we must keep by law.
  • Laboratory and patient records are kept for as long as the laboratory instructs and applicable medical-records rules require. When a laboratory leaves, it can export its data within 30 days; the data is then deleted, apart from backups, which expire on their normal cycle.
  • Invoices and payment records are kept for eight years, as required by the Companies Act, 2013 and the GST law.
  • Cookie-consent records are kept for as long as needed to show that consent was given.
  • Security and audit logs are kept for up to one year, or longer if needed for an investigation.

In line with the DPDP Act, we erase personal data once its purpose is served and no law requires us to keep it.

9. How we protect it

We maintain reasonable security practices and procedures under section 43A of the IT Act and rule 8 of the SPDI Rules, and the safeguards required by section 8(5) of the DPDP Act, including:

  • encryption of data in transit (HTTPS/TLS) and encrypted managed storage;
  • per-laboratory isolation of data enforced in the database;
  • role-based access, hashed passwords and one-time-password verification;
  • tamper-evident audit trails for changes to test results;
  • restricted staff access on a need-to-know basis, under confidentiality obligations.

If a personal data breach occurs, we will inform the Data Protection Board of India and the affected people as the DPDP Act and Rules require. Where we act as processor, we will inform the laboratory without delay.

10. Your rights

Under sections 11 to 14 of the DPDP Act you have the right to:

  • get a summary of the personal data we hold about you and how we process it, and the identities of those we have shared it with;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your data erased when it is no longer needed, unless the law requires us to keep it;
  • withdraw consent at any time, as easily as you gave it;
  • have grievances resolved by our Grievance Officer;
  • nominate someone to exercise these rights for you in the event of death or incapacity.

To use any of these rights, write to [email protected] from the email address on your account, or ask us to verify you another way. We will respond within 30 days. Please remember your own duties under section 15 of the Act, including giving accurate information and not filing false complaints.

11. Children

Our own accounts are for adults. We do not knowingly create accounts for anyone under 18 without verifiable consent from a parent or lawful guardian, as section 9 of the DPDP Act requires. We do not track, monitor the behaviour of, or target advertising at children. Laboratories that register minors as patients are responsible for obtaining a guardian’s consent.

12. Cookies

We use strictly necessary cookies to run the Services and, only with your consent, analytics and marketing cookies. The Cookie Policy lists them, and you can change your choice at any time from “Cookie Settings” in the footer.

13. Grievance Officer

Under rule 5(9) of the SPDI Rules and section 8(10) of the DPDP Act, questions and complaints about how we handle personal data may be sent to:

Sai Kiran Reddy

Grievance Officer, Aynstyn Technologies Private Limited

Hyderabad, Telangana, India

Email: [email protected]

Phone: +91 80971 34410

We acknowledge complaints within 48 hours and resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India under section 13 of the DPDP Act.

14. Changes to this policy

We may update this policy as the Services or the law change. The effective date at the top shows the latest version. For material changes we will notify account holders by email or in the product before the change takes effect and, where the law requires it, ask for fresh consent.