Last updated: October 1, 2026 • Governing all clinical and patient data processing
All clinical data, patient records, laboratory results, and genomic data entered into LISDESK by a laboratory client belong exclusively to that laboratory client ("Data Owner"). LISDESK acts solely as a Data Processor and processes this data only under documented instructions from the Data Owner.
LISDESK does not claim any ownership, license, or commercial rights over your clinical or patient data. Upon contract termination, all data is returned to the client in industry-standard formats (HL7, CSV, JSON, FASTQ) within 30 days.
| Classification | Examples | Protection Level |
|---|---|---|
| Critical | Patient PHI, MRN, genomic sequences, HIV/STI results | AES-256 + field-level encryption, restricted role access |
| Sensitive | Diagnosis codes, instrument QC values, audit logs | AES-256 at rest, TLS 1.3 in transit, audit trail |
| Internal | Workflow configurations, user preferences, report templates | Standard encryption, role-based access |
| Public | Help documentation, API reference guides | Standard web security |
LISDESK processes data on infrastructure hosted in India (primary) with optional disaster recovery replication within India to comply with the DPDP Act 2023 data localisation provisions. Cross-border data transfer (e.g., for Illumina/DRAGEN genomic pipeline processing) is conducted only with explicit client consent and appropriate Standard Contractual Clauses (SCCs).
Every transaction in LISDESK — including specimen accession, result entry, QC action, report release, and user login — is recorded in an immutable, cryptographically signed audit log compliant with:
In the event of a confirmed data breach affecting personal or clinical data:
Upon contract termination or client request:
LISDESK Data Governance Team
Karak, Kalyanpur, Nandakumar, West Bengal, India
+91 99075 52631 • Alt: +91 89272 76802