Privacy Policy
Effective Date: July 12, 2026
Where we are, plainly: Lablytics is pre-launch. This policy covers this website โ the forms you can submit and what happens to that information. Before the platform launches, this policy will be expanded to cover the product itself, and every customer lab will receive a Business Associate Agreement covering patient-related data.
1. Company Information
Lablytics is a healthcare operations software platform owned and operated by SAAS for Healthcare LLC.
Privacy inquiries: policies@lablytics.org
2. Scope of This Policy
The Lablytics platform is designed to support laboratory operational workflows, including activities such as:
- Operational tracking.
- Workflow coordination.
- Inventory management.
- Documentation management.
- Training and competency tracking.
- Communication.
- Reporting and analytics.
- Laboratory process visibility.
The platform may process information provided by customer organizations and authorized users in connection with their use of the service.
This policy applies to information processed through the Lablytics application environment. It does not apply to the public-facing Lablytics website, which is governed by the Terms of Use.
3. Customer Data Ownership
Customers retain ownership and control of their data. Lablytics does not sell, rent, or claim ownership rights over customer data submitted to the platform.
Customer data may include:
- Laboratory operational information.
- Workflow information.
- Inventory information.
- Documentation records.
- User account information.
- Training records.
- Configuration information.
- Other information entered by authorized users.
Customers remain responsible for:
- Determining what information is entered into the platform.
- Ensuring appropriate authorization exists for submitted information.
- Maintaining compliance with applicable healthcare, privacy, and regulatory requirements.
4. Roles and Responsibilities
Depending on the nature of the information processed, customers and Lablytics may have different responsibilities. Generally:
Customer Responsibilities
Customers are responsible for:
- Establishing lawful purposes for using the platform.
- Managing authorized users.
- Controlling user permissions.
- Ensuring submitted information is accurate.
- Maintaining compliance with applicable laboratory regulations.
- Determining whether a Business Associate Agreement is required.
Lablytics Responsibilities
Lablytics is responsible for:
- Providing the software platform.
- Maintaining reasonable security practices.
- Protecting customer information from unauthorized access.
- Processing information according to customer instructions and contractual agreements.
- Maintaining platform availability and functionality.
5. Information We Process
Depending on customer configuration and use, Lablytics may process categories of information including:
User Account Information
Examples include:
- Name.
- Work email address.
- Username.
- Role or position.
- Organization affiliation.
- Authentication information.
- Access permissions.
Laboratory Operational Information
Examples include:
- Inventory records.
- Reagent information.
- Equipment-related information.
- Workflow records.
- Documentation tracking.
- Training records.
- Operational metrics.
- Quality-related information.
Technical Information
The platform may collect technical information including:
- IP addresses.
- Device information.
- Browser information.
- Login activity.
- Security logs.
- System usage information.
- Error reports.
- Performance information.
6. Protected Health Information (PHI)
Lablytics is designed primarily as a laboratory operations platform.
Customers should not submit Protected Health Information (PHI) unless such processing is expressly permitted through applicable agreements between the customer and SAAS for Healthcare LLC.
Where Lablytics processes PHI on behalf of a covered entity or business associate, such processing will be governed by applicable contractual agreements, including a Business Associate Agreement where required.
Lablytics does not determine:
- Whether information constitutes PHI.
- Whether a customer may submit specific information.
- Whether a customer's use complies with healthcare regulations.
Customers remain responsible for determining appropriate use of the platform within their regulatory obligations.
7. How We Use Customer Information
Lablytics may process customer information to:
- Provide platform functionality.
- Authenticate users.
- Manage accounts.
- Maintain security.
- Monitor system performance.
- Provide customer support.
- Troubleshoot technical issues.
- Improve platform reliability.
- Develop product improvements.
- Maintain backups.
- Prevent fraud, abuse, or unauthorized activity.
- Meet contractual and legal obligations.
We process customer information only for legitimate business purposes and according to applicable agreements.
8. Data Security
Lablytics implements administrative, technical, and organizational safeguards designed to protect customer information.
Security measures may include:
- Encryption during transmission.
- Secure hosting environments.
- Authentication controls.
- Role-based access controls.
- Access monitoring.
- Security logging.
- Vulnerability management practices.
- Backup procedures.
- System monitoring.
- Least-privilege access principles.
Security practices may evolve as technology, threats, and industry standards change.
9. Employee and User Access
Access to customer information is limited to authorized personnel who require access for legitimate business purposes.
Personnel may access customer information only when necessary for:
- Customer support.
- System maintenance.
- Security investigations.
- Technical troubleshooting.
- Platform operations.
Access is subject to confidentiality obligations and appropriate safeguards.
10. Subprocessors and Service Providers
Lablytics may use trusted third-party service providers to support platform operations.
These providers may assist with:
- Cloud infrastructure.
- Hosting.
- Security monitoring.
- Database services.
- Communication services.
- Customer support tools.
Lablytics evaluates service providers and requires appropriate contractual and security obligations where applicable. A current list of subprocessors may be made available upon request.
11. Data Retention
Lablytics retains customer information only as necessary to:
- Provide services.
- Maintain platform functionality.
- Meet contractual obligations.
- Maintain security.
- Comply with legal requirements.
Retention periods may depend on:
- Customer agreements.
- Service requirements.
- Legal obligations.
- Security considerations.
12. Customer Data Export and Deletion
Customers may request assistance with exporting or deleting customer data subject to applicable agreements.
Upon termination of services:
- Customer access may be disabled.
- Customer data may be retained for limited periods for backup, legal, or operational purposes.
- Data may be securely deleted according to applicable retention requirements.
Specific deletion procedures may be governed by customer agreements.
13. Security Incidents
Lablytics maintains procedures designed to identify, investigate, respond to, and address security incidents.
If an incident affects customer information, notification obligations will be handled according to:
- Applicable law.
- Customer agreements.
- Data Processing Agreements.
- Business Associate Agreements where applicable.
14. Healthcare Compliance
Lablytics is designed to support laboratory operational workflows.
Customers remain responsible for maintaining compliance with applicable requirements, including where applicable:
- HIPAA.
- CLIA.
- CAP requirements.
- State regulations.
- Organizational policies.
Use of Lablytics does not independently establish compliance with any healthcare regulation or accreditation standard.
15. International Data Processing
Lablytics operates primarily within the United States.
Customers accessing the platform from other jurisdictions acknowledge that information may be processed in locations where Lablytics or its service providers operate. Additional data transfer requirements may apply depending on customer location and applicable law.
16. Changes to This Policy
SAAS for Healthcare LLC may update this Platform Privacy Policy periodically to reflect:
- Changes to platform functionality.
- Changes in technology.
- Changes in security practices.
- Changes in legal requirements.
- Changes in regulatory expectations.
When updates occur, the Effective Date will be revised.
Customers are encouraged to review this policy periodically to remain informed about current privacy practices. Continued use of the Lablytics platform after updates become effective indicates acceptance of the revised policy.
17. Contact Us
Questions regarding this Platform Privacy Policy may be directed to:
SAAS for Healthcare LLC
Email: policies@lablytics.org