Privacy Policy
Effective 2 January 2027
Last updated 2 January 2027
This policy explains what Ariqon Tech Private Limited ("we", "us") collects when a diagnostic laboratory uses the Noline Lab platform, why we collect it, and what rights you have. It applies to the Noline Lab web console, mobile app and related services.
1. Our two roles, and why the distinction matters
We handle two different kinds of information under two different responsibilities, and your rights depend on which one applies:
- Lab and staff account data — we are the Data Fiduciary. We decide why this data is processed, and you exercise your rights directly with us.
- Patient data — we are a Data Processor acting only on the instructions of the laboratory that holds the data. The laboratory is the Data Fiduciary. We do not decide the purposes for which patient data is processed, we do not use it for our own purposes, and we do not sell it.
If you are a patient and want to access, correct or erase your information, contact the laboratory that performed your test. They are the party who can act on that request. We will support them in doing so, but we cannot act on patient data without their instruction.
2. What we collect
Laboratory registration details, gathered during onboarding: registered legal name, laboratory type, year established, full address and PIN code, city, state, map location, GST number and registration number.
Registered pathologist details: name, qualification, medical council, registration number, and the registration certificate you upload.
Account and team member details: first and last name, email address, mobile number, gender, address, profile photograph, assigned role and permissions.
Service configuration: opening and closing times, whether you offer home collection and in-lab testing, and your service radius.
Patient data, processed for the laboratory: patient name, age and gender, the tests ordered, the referring clinic or doctor, order status, and the report files uploaded and released by the laboratory.
Transaction data: Noline Coin balance, purchases and the deduction ledger.
Technical data: IP address, browser and device information, session cookies, a per-request identifier used to trace a request through our logs, and diagnostic information captured when something goes wrong.
3. Why we process it
- To create and operate your laboratory account, and to verify that a registering laboratory is genuine.
- To deliver the service: receiving orders from clinics and doctors, tracking samples, and delivering reports.
- To authenticate users and enforce the role-based permissions you configure for your team.
- To operate the Noline Coin balance, process purchases and maintain the ledger.
- To keep the service secure, diagnose faults and prevent abuse.
- To notify you about orders and account activity through the channels you enable in Notification Settings.
- To meet legal and regulatory obligations.
4. Consent, and withdrawing it
We process lab and staff account data on the basis of the consent you give when you register, and where processing is necessary to provide the service you have asked for. You may withdraw consent at any time by writing to contact@noline.in. Withdrawing consent does not affect processing already carried out, and it may mean we can no longer provide the service.
Consent for patient data is obtained by the laboratory, not by us.
5. Cookies
The lab console uses strictly necessary cookies only. Your session is held in HttpOnly cookies set by our servers, which the browser sends with each request and which JavaScript cannot read. We do not store authentication tokens in local storage.
We do not run advertising or behavioural tracking on any signed-in page. Advertising scripts, where enabled at all, appear only on the public marketing pages and never on pages that display patient information.
6. Who else is involved
We do not sell personal data. We share it only with the service providers needed to run the platform:
- Google Cloud Platform — hosts our application programming interfaces and stores laboratory and patient data, in an India region.
- Vercel — hosts and serves the web front end. See section 7 for an important limitation.
- Google Maps — used on the onboarding and profile screens so you can place your laboratory on a map. Loading the map sends your approximate coordinates and our API key to Google.
- Error monitoring — diagnostic reports about failures are sent to an error-monitoring service we operate. Session recording and request tracing are disabled, so these reports do not carry patient data.
- Razorpay — processes coin purchases. Your card, UPI or net banking credentials are entered with Razorpay and are never received, seen or stored by us. We receive only the outcome of the payment and a reference for it.
- Google AdSense — on public marketing pages only, and only where enabled. It is never loaded on a signed-in page.
We may also disclose information where we are required to by law, or to establish or defend a legal claim.
7. Where your data is processed
Patient data does not leave India. Your browser communicates directly with our application programming interfaces hosted in India. Our web servers render page shells only; they do not fetch, receive or store patient information.
Some technical data is currently processed outside India. Our web front end is served through a hosting provider whose server-side rendering for this deployment currently executes in the United States. As a result, your session cookie, request headers and the page addresses you visit — which can include order and team identifiers — pass through, and are logged on, infrastructure in the United States. This does not include patient names, test results or report files.
We are moving this processing to an India region. This section will be updated when that change takes effect, and it should not be removed before then.
8. How long we keep it
We retain laboratory and account data for as long as your account is active. After your account is closed we retain it for a further six months, and then delete or anonymise it.
We keep data beyond that period only where we are required to by law — for example tax and accounting records — or where it is needed to establish or defend a legal claim that is already under way. In those cases we keep only what the obligation or the claim requires, and for no longer than it requires.
Patient data is retained on the instructions of the laboratory that holds it, and subject to the record-keeping periods that apply to diagnostic laboratories in India. If those periods are longer than six months, they prevail — we will not delete records your laboratory is legally required to keep. Export your data before closing your account if you need it.
9. How we protect it
- Data is encrypted in transit using TLS, and encrypted at rest in storage.
- Sessions use HttpOnly cookies; authentication tokens are never placed in browser storage.
- Access is role-based — each team member is granted only the permissions their role requires.
- Request and response payloads are excluded from our application logs, and diagnostic data is redacted before it is recorded.
- Report uploads are validated for size and file type.
No system is perfectly secure, and we do not claim otherwise. We are not certified under HIPAA, which is United States legislation and does not govern diagnostic data in India.
10. Your rights
Under the Digital Personal Data Protection Act 2023, in relation to the data for which we are the Data Fiduciary, you may:
- Ask for a summary of the personal data we process about you and how we process it.
- Ask us to correct inaccurate or incomplete data, or to complete it.
- Ask us to erase data we no longer need for the purpose it was collected for.
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
- Withdraw consent, as described in section 4.
- Raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied.
Write to contact@noline.in to exercise any of these. We may need to verify your identity before we act.
11. Children
The Noline Lab console is for laboratory staff and is not directed at children. Where a laboratory processes the data of a patient under 18 through the platform, obtaining verifiable parental or guardian consent is the responsibility of that laboratory as the Data Fiduciary.
12. Grievance redressal
If you have a complaint about how we handle personal data, contact our Grievance Officer:
- Name: Shamshad
- Email: contact@noline.in
- Address: 603-604, 6th Floor, Tower B, Bhutani Alphathum, Sector 90, Noida, Uttar Pradesh 201305
We will acknowledge your complaint and respond within the period required by law. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13. Changes to this policy
We may update this policy. When we make a material change we will update the effective date above and, where the change significantly affects how we handle your data, notify you through the platform or by email.
14. Contact
Ariqon Tech Private Limited, 603-604, 6th Floor, Tower B, Bhutani Alphathum, Sector 90, Noida, Uttar Pradesh 201305. Privacy enquiries: contact@noline.in. General enquiries: contact@noline.in.