Legal
Acceptable use policy
Reviewed with each platform release
This policy applies to everyone with access to a DocLab Solutions workspace, including administrators, staff and client-portal users.
Data you may store
DocLab Solutions is an operational system for accounts, sites, projects, equipment, reagent lots, tickets, documents and regulatory records.
Do not store patient-identifiable clinical results or diagnostic reports unless a signed Business Associate Agreement is in place for your workspace. Where no BAA exists, keep records at the practice and site level.
Access and credentials
Do not share accounts. Each person who needs access is invited individually and assigned a role by their workspace administrator.
Do not attempt to reach another workspace's data, probe row-level security, or escalate your own permissions.
AI and automation
The assistant only ever sees what your role can see, and never changes data without your explicit confirmation of the action and its consequences.
Do not use the assistant or automation flows to extract data in bulk beyond what your role is granted, or to generate regulatory documentation that a qualified person has not reviewed.
Integrity of the record
Audit entries, document version history and signatures are append-only by design. Do not attempt to alter or delete them.
Report suspected security issues to info@gpendatechnologies.com rather than testing them against live workspaces.
Enforcement
We may suspend an individual account, or a whole workspace, where continued use puts other customers or the integrity of the record at risk. Workspace administrators are notified whenever we do.