← Back to sign in

Privacy Policy

Effective date: September 8, 2026

1. About this policy

PathOS is an operations platform for diagnostic-laboratory collection centres and their franchise networks. It connects a laboratory to its information systems and lets the laboratory's staff manage bookings, deliver reports, reconcile finances and communicate with patients over WhatsApp from a single dashboard.

The PathOS platform is operated by PathOS Labs("PathOS", "we", "us"). PathOS is used by more than one laboratory. For the personal data of patients, the laboratory or franchise operator that serves you(the "Lab") decides why and how that data is processed and is the Data Fiduciary; PathOS processes that data as a Data Processor on the Lab's instructions. For the accounts of the Lab's own staff and operators, PathOS acts as the Data Fiduciary.

This policy explains what personal data is processed through PathOS, why, who it is shared with, how long it is kept, and the rights available to you. It should be read together with the privacy notice of the Lab you interact with.

2. Key terms

  • Data Principal — the individual the personal data is about (a patient, or a member of Lab staff).
  • Data Fiduciary — the party that determines the purpose and means of processing personal data.
  • Data Processor — a party that processes personal data on behalf of a Data Fiduciary.

These terms are used as defined in India's Digital Personal Data Protection Act, 2023.

3. Personal data we process

Patient data(received from you, from the Lab, or from the Lab's information system):

  • Identity and contact details — name, mobile number, email address, postal address.
  • Demographics — age and gender, and a lab-assigned health identifier (UHID / patient code).
  • Health-related data — the tests booked or performed for you, sample-collection details, and the lab report documents delivered to you.
  • Transaction data — bill and receipt numbers, amounts, discounts, payment mode and payment status.
  • Communications — the content of WhatsApp messages you exchange with the Lab through PathOS, including voice notes and any images or documents you send, together with message timestamps and delivery status.

Staff and operator data (for people who log in to PathOS): name, work email address, phone number, Google profile basics used for sign-in, assigned role and access scope, and a record of significant actions taken in the application (audit log).

4. How data is collected

  • Directly from you when you message the Lab on WhatsApp or provide details for a booking.
  • From the Lab's laboratory information system, which PathOS accesses from the Lab's management systems to retrieve reports, bills and test records.
  • From Lab staff who enter or update records on your behalf.
  • From Sign-in with Google when a staff member authenticates.

5. Why we process it, and our lawful basis

  • To take and manage test bookings and sample collections.
  • To deliver lab reports and receipts to you.
  • To answer your questions and provide support, including in Telugu and Hindi.
  • To process billing, payments, settlements and reconciliation for the Lab.
  • To operate, secure, debug and improve the platform.
  • To meet legal, tax and regulatory obligations of the Lab.

Processing is carried out on the basis of the consent you give to the Lab, for the performance of the service you have requested, and for other legitimate uses permitted under applicable law.

6. Who we share data with

We do not sell personal data. It is shared with the Lab that serves you, and with the service providers below, only to the extent needed to run the service:

Meta Platforms (WhatsApp Business / Cloud API)
Delivering and receiving patient messages, sending lab reports and receipts, template broadcasts, and syncing the test catalogue.
Processing location: United States / global
Sarvam AI
Transcribing WhatsApp voice notes and translating messages between English, Telugu and Hindi.
Processing location: India
OpenRouter, with Anthropic (Claude) as the model provider
Classifying the intent of patient messages and drafting assistant replies and financial summaries.
Processing location: United States / global
Google (Sign-in with Google, Google Cloud)
Authenticating staff and operator accounts; hosting the application and storing encrypted database backups.
Processing location: India / global
The laboratory's LIMS provider
The source lab information system from which reports, bills and test data are retrieved on the lab’s instruction.
Processing location: India

We may also disclose personal data where required by law, court order or a lawful request from a public authority, or to protect the rights, safety and property of patients, the Lab or PathOS.

7. Automated processing by AI services

To understand and respond to patient messages, the text of a message (which may first be translated to English) is sent to the AI providers listed above for intent classification and for drafting a reply. Draft replies may be reviewed by Lab staff before being sent. We instruct these providers not to use the content to train their models. Decisions that affect you (such as report release or booking confirmation) are made by the Lab, not by an automated system alone.

8. Transfers outside India

Some of the service providers above process data on infrastructure located outside India. Where this happens, the transfer is made subject to contractual data-protection commitments with the provider and only to countries not restricted for such transfers under applicable law.

9. How long we keep data

  • Report and receipt documents generated for delivery are retained for 3-7days, after which they are deleted from our platform, but will be retained by the Lab.
  • Booking, transaction, patient and message records are retained for as long as the Lab requires them for service, accounting and legal purposes, and are then deleted or anonymised.
  • Encrypted database backups are retained for 14 days on a rolling basis.
  • Audit-log entries are retained for 2years.
  • When you delete a conversation in the dashboard it is hidden from view; the underlying message records are removed on the schedule above.

10. How we protect data

  • Encryption of data in transit (HTTPS/TLS) between your device, PathOS and its providers.
  • Encryption at rest of sensitive credentials and secrets.
  • Role-based access control, so staff can only reach the centres and screens their role allows.
  • A messaging allow-list that restricts which numbers the platform may contact during testing and rollout.
  • Logging of actions that create, change or delete patient, report and financial records.
  • Regular, retained backups of the database.

No system is perfectly secure. If a personal-data breach occurs, we will notify the affected Lab and support notification to the Data Protection Board and to affected individuals as required by law.

11. Your rights

Subject to applicable law, you may ask to:

  • access a summary of the personal data processed about you and how it is processed;
  • correct, complete or update inaccurate data;
  • erase data that is no longer needed for the purpose it was collected;
  • withdraw a consent you have given (this does not affect processing already done);
  • nominate another person to exercise your rights in the event of death or incapacity;
  • raise a grievance about how your data is handled.

Because the Lab is the Data Fiduciary for patient data, requests about patient data are usually best made to the Lab that served you. You may also contact PathOS using the details in section 13 and we will act on the request or route it to the relevant Lab.

12. Children's data

Where tests are booked for a child or for a person under guardianship, the platform is used by the parent or lawful guardian, who provides the child's details and consent. We do not knowingly use children's data for any purpose other than delivering the requested diagnostic service.

13. Contact and grievances

For questions about this policy or to exercise a right, contact the PathOS Grievance Officer:

  • Aditya Teja Vemuri
  • lupin.lmpcc.hydernagar@gmail.com
  • PathOS Labs
  • #14, Brindavan Colony, Hydernagar, Hyderabad, Telangana, 500090, India

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

14. How to delete your data

You can ask for the personal data held about you on the PathOS platform to be deleted:

  • Ask the Lab — tell the collection centre that served you, in person, by phone, or by replying on the same WhatsApp number, that you want your data deleted.
  • Email us — write to lupin.lmpcc.hydernagar@gmail.com with the mobile number used for your visits and a request to delete your data. We will verify your identity and act on the request, or route it to the relevant Lab.

Authorised Lab staff can carry out the deletion directly from the PathOS dashboard. When a record is erased:

  • your patient record, the WhatsApp conversation messages linked to it, and the lab-report files held on the platform are permanently removed;
  • booking and billing entries that must be kept for accounting, tax and audit are retained with your identifying details (name, address) removed;
  • if a mobile number is shared by a family, only the record of the named person is erased — other family members' records are not affected;
  • copies already held by the Lab in its own laboratory systems, and routine encrypted backups, are outside the platform and age out on their own schedules (backups within 14 days).

We aim to complete a verified deletion request within 30 days and will confirm once it is done. This does not remove data the Lab or PathOS is required by law to keep.

15. Changes to this policy

We may update this policy as the platform, our providers or the law change. The updated version takes effect when posted here, and the effective date above is revised. Material changes will be communicated through the Lab or in the application.