Legal
Privacy Policy
Last updated 30 July 2026
Template notice. This document is a drafting starting point prepared alongside the platform. It is not legal advice and has not been reviewed by counsel. Have a qualified lawyer in your operating jurisdiction review and adapt it before this site accepts real clients.
1. Information we collect
When you submit samples or create an account we collect the contact and billing information you provide: name, company or organisation, email address, telephone number, and shipping and billing addresses. We collect the sample metadata you enter, including product names, batch numbers and requested analyses.
When you use the certificate verification facility we record the fact of the lookup, a truncated fragment of the reference queried, whether it succeeded, a keyed one-way hash of your IP address, and your browser's user-agent string. We do not store your raw IP address.
We do not use advertising cookies, third-party analytics trackers, or cross-site tracking of any kind.
2. Why we collect it
Contact and sample information is used to perform the analytical services you request, to issue and verify your certificates, to invoice you, and to notify you about the progress of your orders. These are transactional communications necessary to deliver the service and are not marketing.
Verification lookup records exist to detect and prevent abuse of the verification endpoint, in particular attempts to enumerate certificates. This is a legitimate-interests basis: without it, the confidentiality of our clients' certificates could not be protected.
We send service and product announcements only to recipients who have explicitly opted in, and every such message carries an unsubscribe link.
3. Certificates and confidentiality
Certificate documents are stored in private object storage that is not publicly accessible. A certificate document is served only after a successful verification, and only for the certificate that was verified.
We never publish a list of certificates, and we do not permit search engines to index certificate pages. Anyone you give a certificate number or QR code to will be able to view that certificate, so treat those references as confidential to the extent you wish the results to remain so.
4. Sharing
We do not sell personal information. We share it only with service providers who process it on our behalf under contract - our hosting provider, database provider, object-storage provider and transactional email provider - and only to the extent necessary to operate the service.
We disclose information where required by law, and we will notify you of any such request unless legally prohibited from doing so.
5. Retention
Analytical records and certificates are retained for a minimum of seven years, as required for the traceability of a laboratory record. Verification lookup logs are retained for twelve months. Account information is retained while your account is active and for seven years thereafter for accounting purposes.
6. Your rights
You may request access to, correction of, or deletion of your personal information by contacting support@lavadiagnostics.com. Note that we cannot delete an issued analytical record within its mandatory retention period, as doing so would compromise the integrity of the certificate register that third parties rely on.
Depending on your location you may have additional rights, including the right to data portability, the right to object to processing, and the right to lodge a complaint with your supervisory authority.