NEW RELEASE LISDESK 2026 Engine — Integrated Illumina NovaSeq & DRAGEN Bioinformatic Pipelines Explore Genomic Module →
+91 99075 52631 • Admin Portal

Data Policy

Last updated: October 1, 2026 • Governing all clinical and patient data processing

1. Data Ownership

All clinical data, patient records, laboratory results, and genomic data entered into LISDESK by a laboratory client belong exclusively to that laboratory client ("Data Owner"). LISDESK acts solely as a Data Processor and processes this data only under documented instructions from the Data Owner.

LISDESK does not claim any ownership, license, or commercial rights over your clinical or patient data. Upon contract termination, all data is returned to the client in industry-standard formats (HL7, CSV, JSON, FASTQ) within 30 days.

2. Data Classification

Classification Examples Protection Level
Critical Patient PHI, MRN, genomic sequences, HIV/STI results AES-256 + field-level encryption, restricted role access
Sensitive Diagnosis codes, instrument QC values, audit logs AES-256 at rest, TLS 1.3 in transit, audit trail
Internal Workflow configurations, user preferences, report templates Standard encryption, role-based access
Public Help documentation, API reference guides Standard web security

3. Data Processing Locations

LISDESK processes data on infrastructure hosted in India (primary) with optional disaster recovery replication within India to comply with the DPDP Act 2023 data localisation provisions. Cross-border data transfer (e.g., for Illumina/DRAGEN genomic pipeline processing) is conducted only with explicit client consent and appropriate Standard Contractual Clauses (SCCs).

  • Primary datacenter: India (Mumbai / Hyderabad region)
  • Backup/DR: India (secondary region)
  • Cross-border transfers: Only with client consent + DPA amendment

4. Data Backup & Recovery

  • Automated encrypted backups every 6 hours for critical clinical data
  • Full daily snapshots retained for 30 days
  • Monthly archives retained for 12 months
  • Recovery Time Objective (RTO): < 4 hours
  • Recovery Point Objective (RPO): < 6 hours
  • Annual disaster recovery drill conducted and results shared with clients

5. Audit Trails & Regulatory Compliance

Every transaction in LISDESK — including specimen accession, result entry, QC action, report release, and user login — is recorded in an immutable, cryptographically signed audit log compliant with:

  • FDA 21 CFR Part 11 (Electronic Records and Signatures)
  • CAP Laboratory Accreditation Program checklist requirements
  • CLIA 1988 regulations
  • ISO 15189:2022 Medical Laboratories standard
  • India IT Act 2000 and DPDP Act 2023

6. Data Breach Notification

In the event of a confirmed data breach affecting personal or clinical data:

  • Affected clients will be notified within 72 hours of discovery
  • CERT-In will be notified per Indian IT Rules 2022 (within 6 hours for critical breaches)
  • A detailed incident report will be provided within 30 days
  • Forensic investigation will be conducted and remediation plan communicated

7. Data Portability & Deletion

Upon contract termination or client request:

  • Full data export provided in HL7 FHIR, CSV, JSON, or PDF formats within 30 days
  • Secure data destruction using NIST 800-88 wiping standards upon confirmed export
  • Written certificate of data destruction provided upon request

8. Contact

LISDESK Data Governance Team

Karak, Kalyanpur, Nandakumar, West Bengal, India

+91 99075 52631 • Alt: +91 89272 76802

data@lisdesk.com