Legal

Acceptable use policy

Reviewed with each platform release

This policy applies to everyone with access to a DocLab Solutions workspace, including administrators, staff and client-portal users.

Data you may store

DocLab Solutions is an operational system for accounts, sites, projects, equipment, reagent lots, tickets, documents and regulatory records.

Do not store patient-identifiable clinical results or diagnostic reports unless a signed Business Associate Agreement is in place for your workspace. Where no BAA exists, keep records at the practice and site level.

Access and credentials

Do not share accounts. Each person who needs access is invited individually and assigned a role by their workspace administrator.

Do not attempt to reach another workspace's data, probe row-level security, or escalate your own permissions.

AI and automation

The assistant only ever sees what your role can see, and never changes data without your explicit confirmation of the action and its consequences.

Do not use the assistant or automation flows to extract data in bulk beyond what your role is granted, or to generate regulatory documentation that a qualified person has not reviewed.

Integrity of the record

Audit entries, document version history and signatures are append-only by design. Do not attempt to alter or delete them.

Report suspected security issues to info@gpendatechnologies.com rather than testing them against live workspaces.

Enforcement

We may suspend an individual account, or a whole workspace, where continued use puts other customers or the integrity of the record at risk. Workspace administrators are notified whenever we do.