Data Policy

Effective date: April 13, 2026

1. Data Architecture

Hope Consultation LLC uses a multi-tenant architecture where each laboratory's data is logically isolated. Every database query is scoped to the authenticated user's lab ID. Cross-lab data access is technically prevented at the API layer and tested automatically with each deployment.

2. Data Storage

  • Structured data (compliance records, QC results, CAPA, personnel) is stored in a managed relational database with daily automated backups.
  • Files and documents (SOPs, inspection photos, competency forms) are stored in S3-compatible object storage with server-side encryption (AES-256).
  • Audit logs are append-only and cannot be modified or deleted by lab users.

3. File Access Security

All file downloads are served via presigned URLs with a 1-hour expiry. Direct S3 bucket access is not permitted. Before generating a presigned URL, the platform verifies that the requesting user is a member of the lab that owns the file. Unauthorized download attempts are logged and rejected.

4. Backup and Recovery

  • Automated daily database backups retained for 30 days
  • On-demand backups available to system administrators at any time
  • Recovery point objective (RPO): 24 hours
  • Recovery time objective (RTO): 4 hours
  • Backup files are encrypted and stored in a geographically separate region

5. Data Export

Lab Directors and Quality Managers can export all compliance data at any time in CSV format. Available exports include: competency records, QC logs, PT events, CAPA cases, SOP lists, and inspection reports. Exports are logged in the audit trail.

6. Data Deletion

Upon account termination, lab data is soft-deleted immediately (no longer accessible through the platform) and permanently deleted after 90 days. Audit logs are retained for 10 years per regulatory requirements. You may request expedited deletion by contacting support.

7. Sub-processors

We use the following sub-processors to deliver the service:

ProviderPurposeLocation
Cloud Database ProviderRelational data storageUnited States
S3-Compatible StorageFile and document storageUnited States
LLM API ProviderAI-assisted compliance analysisUnited States

8. Regulatory Compliance

Hope Consultation LLC's data practices are designed to support laboratories operating under CLIA, CAP, ISO 15189, and Joint Commission standards. The platform's audit trail, document control, and access management features are specifically designed to meet the documentation requirements of these accreditation bodies.

9. Contact

For data-related inquiries: [email protected]

We use cookies

LabComply uses essential cookies to keep you signed in and functional cookies to improve your experience. We do not sell your data. Learn more