Privacy Policy

1. Introduction

This Privacy Policy explains how LabInflow (“we”, “our”, or “us”) collects, uses, stores, and protects personal and institutional data provided by users of our Order Management System (“LabInflow”). This applies to both:

  • Locally installed versions (e.g., Microsoft Access-based setups hosted on client networks)
  • Web-based versions (hosted platforms managed by LabInflow)

We are committed to ensuring that your privacy is protected and that your data is handled in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) if you are located in the European Union.

By using LabInflow, you agree to the practices described in this Privacy Policy.

2. What Information We Collect

Depending on the version and usage of LabInflow, we may collect the following types of information:

  • Personal Information:
    • Full name
    • Email address
    • Institution name
    • Role or designation
    • Contact number (optional)
  • System Usage Data:
    • Login timestamps (web version)
    • Order entries (items ordered, purpose, date, etc.)
    • Account/project-related data (as managed by your lab or admin)
  • Technical Data (Web Version only):
    • IP address
    • Browser/device type
    • Error logs (to help with debugging and support)

We do not collect sensitive personal data such as racial, political, or health information.

3. How We Use Your Information

We collect and use your data solely for the purpose of enabling and supporting the LabInflow system, including:

  • Managing user accounts and permissions
  • Tracking orders and lab-related activities
  • Providing technical support
  • Generating usage reports (for admins only)
  • Sending system-related notifications or alerts
  • Improving functionality and user experience

Your data will never be sold, used for marketing purposes, or shared without your consent, unless required by law.

4. Data Storage and Security

We take data protection seriously and implement appropriate technical and organizational measures to safeguard your information.

  • Web-based version:
    Data is stored on secure servers protected by firewalls, access control, and encryption where applicable. We may use trusted third-party hosting or database providers under strict data handling agreements.
  • Internal access to user data is restricted to authorized personnel who require it to provide support or manage the service.
  • No passwords are stored in plain text. Passwords (in web-based versions) are securely hashed.

5. Local Installations (MS Access-based version)

If you are using a locally installed version of LabInflow (Microsoft Access-based), please note:

  • All user data, order records, and account information are stored within your own institution’s infrastructure (e.g., shared drives, local networks).
  • LabInflow developers do not have access to your database, network, or user accounts unless explicitly granted for support purposes.
  • Clients are solely responsible for the security, maintenance, and backup of their own data.
  • It is your responsibility to implement appropriate IT policies, access restrictions, and backup procedures to ensure data safety and regulatory compliance.

6. Sharing of Information

We do not share, sell, rent, or trade your personal or institutional data to any third parties.

However, we may share information under the following circumstances:

  • With service providers (for web-hosted versions): such as cloud/database hosts and email service providers, under strict confidentiality and data processing agreements.
  • For legal reasons: If required by law, court order, or government request.
  • For support purposes: If you explicitly grant temporary access to assist with technical troubleshooting or system customization.

7. Your Data Rights

If you are a resident of the European Union (or under similar data protection jurisdictions), you have the following rights regarding your personal data:

  • Right to access – Request what data we hold about you.
  • Right to correction – Request correction of inaccurate data.
  • Right to deletion – Request removal of your personal data (unless legally required to retain it).
  • Right to data portability – Request a copy of your data in a machine-readable format.
  • Right to object/restrict – Restrict certain data uses (where applicable).

To exercise these rights, please contact us at info@labinflow.com. We will respond to your request within 30 days.

8. Cookies & Analytics (Web Version Only)

The web-based version of LabInflow may use cookies or browser storage for technical and functional purposes, such as:

  • Keeping you logged in
  • Remembering preferences (e.g., dark/light mode)
  • Improving user experience

We do not use third-party tracking cookies, advertising, or marketing analytics tools. All analytics (if enabled) are used strictly for system improvement and debugging.

You may disable cookies in your browser, though this may limit some functionality.

9. Data Retention

We retain personal and usage data only as long as it is necessary for the purposes stated in this policy:

  • Web-based users: Data is retained during the active account period and for a reasonable time after account deactivation (e.g., for reporting or legal compliance).
  • MS Access clients: Data retention is fully controlled by the client and governed by their internal policies.

We may retain anonymized system logs for longer periods to analyze trends or detect abuse.

10. Third-Party Links

LabInflow may contain links to external websites (e.g., documentation, support, or partner resources). We are not responsible for the privacy practices or content of third-party websites.

Users are advised to review the privacy policies of any external sites they visit.

11. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time. Changes will be posted on our official website:

🔗 https://labinflow.com/privacy

We encourage users to review the policy periodically. Continued use of LabInflow after changes are posted indicates your acceptance of those changes.

12. Contact Information

If you have questions about this Privacy Policy or wish to make a data request, please contact:

LabInflow Privacy Officer
📧 info@labinflow.com
🌐 https://labinflow.com