Privacy Policy
Last updated: August 4, 2026
1. Scope
This Privacy Policy describes how LabSuite ("we", "us") handles data in connection with the LabSuite platform - both data about the organizations and staff who use LabSuite directly ("Customers"), and the patient data Customers store within their own private workspace ("Customer Data").
2. Data isolation between organizations
Every organization on LabSuite is provisioned its own separate database. Patients, tests, payments, and staff accounts belonging to one organization are never stored alongside, or queryable from, another organization's data. Each organization reaches its workspace through its own private address (e.g. yourlab.thelabsuite.com).
3. What we collect
Depending on how the Service is used, this includes:
- Account data: staff name, email, phone, role, and a securely hashed password (we never store passwords in plain text).
- Organization data: organization name, subdomain, plan, subscription status, and branding details (logo, tagline, contact info) an admin chooses to add.
- Customer Data entered by an organization: patient demographics, test orders, results, clinical remarks, payments, and invoices - entered and controlled by that organization, not by us.
- Billing data: subscription plan, billing cycle, and payment confirmation records. Card details are handled entirely by Paystack, our payment processor - we never receive or store full card numbers.
- Activity logs:a record of significant actions (logins, records created/changed, invoices voided, etc.) within each organization, visible to that organization's own admins.
- Technical data: IP address and basic request metadata, used for security purposes such as rate-limiting repeated failed sign-in attempts.
4. How we use data
- To operate, maintain, and secure the Service.
- To authenticate sign-ins and enforce that each session only reaches its own organization's data.
- To process subscription payments and renewals through Paystack.
- To provide optional AI-assisted remark suggestions (see below).
- To respond to support requests sent to us directly.
- To detect and throttle abusive or malicious request patterns (e.g. repeated failed logins).
We do not sell Customer Data or patient data to third parties.
5. Third-party processors
We rely on the following third-party services to operate LabSuite:
- MongoDB Atlas- hosts every organization's database.
- Paystack - processes subscription payments; card details never reach our own servers.
- Cloudinary - stores uploaded logo and profile images.
- Anthropic (Claude) - powers the optional AI-assisted clinical remark suggestion feature, where enabled. Only the specific test result data needed to generate a suggestion is sent; nothing is sent unless a lab user explicitly requests a suggestion, and the AI is never given identifying patient information beyond what the requesting organization includes in the result itself.
- Vercel - hosts the application.
6. The public demo
Data entered into the public demo sandbox is not private, is periodically wiped, and should never include real patient information.
7. Data retention and deletion
Customer Data is retained for as long as the organization's account is active. If a platform administrator deletes an organization, every record in that organization's database - patients, tests, payments, staff accounts - is permanently removed; this action cannot be undone.
8. Cookies and sessions
We use a single, essential session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
9. Your rights
If you are a patient whose data is held by a LabSuite Customer (a lab), requests about your data should go to that lab directly, as they control their own records. If you are a Customer with questions about your organization's account data, or believe we hold data about you that needs to be corrected or removed, contact us at hello@thelabsuite.com.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated date at the top of this page.
11. Contact
Questions about this policy can be sent to hello@thelabsuite.com.