Privacy policy
Last updated 1 October 2026 · Applies to PathLab Software by AvanceZone
What this policy covers
This policy explains what AvanceZone ("we") processes when pathology and diagnostic labs use PathLab Software (the "Service"), why, for how long, and who helps us. It covers the public website and the lab application. In short: the lab decides what patient data is collected and why; we process it only to run the Service for that lab, host it in India, and never sell it.
Who is responsible for what
For patient, referring-doctor and test data, the lab is the data fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and we act as its data processor, following the lab's instructions. For lab staff accounts, billing and website enquiries, AvanceZone is responsible. Patients who want to access, correct or erase their data should contact their lab first; we help the lab respond.
Data categories we process
- Patient records (entered by the lab): name, age or date of birth, sex, phone number, area or address, preferred language, ABHA number if given, and WhatsApp consent.
- Orders, samples and results: tests ordered, barcodes, collection and receipt times, results, reference ranges, flags, delta checks, validation and signing records, signed reports and their verification codes.
- Analyzer messages: result messages sent by the lab's analyzers through the connector (sample ID, test codes, values, units).
- Critical-value records: alert details, call and WhatsApp attempts, failures, escalations and acknowledgements with names, channels and times.
- Home-collection records: scheduled address, collection time, geo-location at collection (when the phlebotomist allows the browser to share it), temperature note and tube photo.
- Referring doctors and clients: name, phone/WhatsApp, registration number, speciality, rate lists and monthly referred-patient statements.
- Messages: WhatsApp and SMS messages sent or received by the lab through the Service, with delivery status.
- Billing: the lab's GST invoices to patients and clients, payments and dues; our subscription invoices to the lab.
- Lab staff accounts: name, email, phone, role, password hash, and activity in the audit trail (user, time, IP address).
- Website enquiries: name, lab name, city, phone, email and message from the setup form.
- Report verification: when someone opens a /verify page, we count the view and keep the time; we rate-limit by IP address to stop guessing.
Why we process it
- To run the lab workflow the lab uses: registration, results, validation, signed reports, delivery to the patient and referring doctor, critical-value alerts, reminders the patient agreed to, billing and audit records.
- To secure the Service, keep the audit trail, prevent misuse and support the lab.
- To bill our subscription and answer enquiries. With consent, to send product updates; you can opt out at any time.
- To meet legal obligations, including the DPDP Act 2023. We do not use patient data for advertising, profiling or training AI models, and we never sell personal data.
Retention
| Data | How long |
|---|---|
| Lab workspace data (patients, orders, results, reports, messages, alerts, home-collection records, statements) | While the workspace is active, as the lab decides. After cancellation, 30 days for export, then deleted. The lab is responsible for any longer legal retention of medical records and should export before closing. |
| Encrypted backups | Rolling 30 days, then overwritten. |
| Audit trail entries | For the life of the workspace (they are part of the lab's quality records), deleted with it. |
| Security logs (login attempts, rate limits, server logs) | 12 months. |
| Our subscription invoices to labs | As long as Indian tax law requires. |
| Website enquiries | 24 months, or sooner on request. |
Where data is hosted and who helps us (sub-processors)
| Category | Sub-processor | What they receive |
|---|---|---|
| Hosting and backups | Amazon Web Services, ap-south-1 (Mumbai, India) | All Service data, encrypted at rest |
| WhatsApp, SMS and voice | AvanceZone messaging gateway, using the Meta WhatsApp Business Platform and Indian telecom operators | Recipient number and message or call content (reports links, alerts, reminders) |
| Email delivery | Our transactional email provider (name on request) | Staff email addresses and account emails |
| Payments | The UPI app or payment gateway the lab or patient chooses | Payment amount and reference; we do not store card details |
Meta and telecom operators process message content to deliver it and apply their own policies. We notify workspace owners before adding a sub-processor that receives patient data.
Your rights
You may ask to access, correct, export or erase your personal data, or withdraw consent, by emailing info@radiatus.com. Patients: please contact your lab first; withdrawing WhatsApp consent at the lab stops report messages. You may also complain to the Data Protection Board of India.
Cookies
We use a strictly necessary session cookie for logged-in users and, if enabled, privacy-friendly analytics with IP anonymisation on the public website. No advertising cookies.
Security
TLS in transit, encryption at rest, Argon2id password hashing, role-based access, two-level validation, rate limiting, an audit trail and daily encrypted backups. Details on the Security page.
Changes and contact
We post changes here and email workspace owners about material changes. Questions: info@radiatus.com, +91-9585160363, AvanceZone, Coimbatore, Tamil Nadu.
Related: Privacy policy · Terms of service · Refund policy · Security and compliance · PathLab Software pricing · Contact us