LEGAL

Security & Data Protection

Effective date: August 25, 2026

1. Our security approach

LabCare uses a privacy- and security-focused approach designed to protect the confidentiality, integrity and availability of information processed through the Service. Measures include data minimization, authenticated access, restricted permissions, private storage, database row-level access controls, server-side secrets, encrypted network connections where appropriate, operational monitoring and ongoing security review. No Internet-connected service can guarantee absolute security.

2. Health data protection

Health-related information is treated as sensitive. Access is intended to be limited to systems, personnel, contractors and service providers that require it to operate, maintain, secure or provide the Service, subject to applicable legal and contractual requirements.

3. Account protection

Private LabCare functionality requires authenticated access. Security controls are designed to help prevent unauthorized users from accessing another user’s private information. Users are responsible for protecting account credentials.

4. Database access controls

LabCare uses database- and application-level controls that may include Row Level Security, role-based permissions, authenticated access boundaries, restricted service-level access and protected database functions.

5. File and laboratory report protection

Laboratory reports and other health-related documents are stored in private, access-controlled storage. Public access to sensitive user-uploaded health documents is not intended to be permitted.

6. Service providers

LabCare relies on selected providers for infrastructure, storage, authentication, server-side analysis, communications, cybersecurity and payment processing. Providers may process limited information as necessary to perform services on LabCare’s behalf and are not authorized by LabCare to independently use Consumer Health Data for unrelated advertising or marketing.

7. Advertising technologies

LabCare distinguishes public marketing functionality from authenticated health-data areas. Advertising technologies are not intended to receive laboratory reports, biomarker values, Health Scores, My Health Timeline information or personalized health reports from protected areas.

8. Payment security

Payments may be processed by Stripe or another independent payment processor. Complete card numbers and security codes entered directly into the processor’s secure payment environment do not need to be stored in the LabCare application database.

9. Access limitation and minimization

Access to Consumer Health Data is intended to be limited to persons and systems for which access is reasonably necessary to provide user-requested functionality, operate and secure the Service, provide support, investigate misuse or comply with law.

10. Retention and deletion

Health information used for longitudinal features may be retained while necessary to provide those features or until deleted under applicable account, retention or privacy procedures. Privacy and deletion requests may be sent to support@labcarehealth.com.

11. Security monitoring and incidents

LabCare may maintain operational health checks, security logs and integrity monitoring. If an incident affects information subject to legally mandated breach-notification requirements, LabCare will investigate and take notification and remediation actions required by applicable law.

12. Responsible security contact

If you believe you identified a security or privacy issue, contact support@labcarehealth.com. Please do not include unnecessary sensitive health information in an initial report.