Privacy Notice
Your privacy matters to us. This Privacy Notice explains how MedeCue collects, uses, stores, discloses and protects personal data when you use our website, products and laboratory management platform.
1. Introduction
MedeCue is a laboratory management software platform developed and operated by QAWebPrints Infocorp LLP (“QAWebPrints,” “MedeCue,” “we,” “us,” or “our”).
MedeCue provides subscription-based software and related services to clinical laboratories, diagnostic centres, hospitals, clinics, healthcare organisations, collection centres and other authorised customers.
This Privacy Notice explains how we collect, use, store, disclose and protect personal data when individuals:
- Visit the MedeCue website;
- Request a demonstration or contact us;
- Create or use a MedeCue account;
- Use MedeCue as an employee, administrator, laboratory professional, doctor, technician, authorised representative or other user;
- Receive support, implementation or training services;
- Interact with communications sent through MedeCue;
- Are registered as patients or service recipients by a laboratory using MedeCue; or
- Otherwise interact with MedeCue or QAWebPrints.
This Notice also explains the respective privacy responsibilities of MedeCue and our laboratory customers.
2. About MedeCue
MedeCue is operated by:
QAWebPrints Infocorp LLP
SBC-6, 1st Floor, Ashtamudi
Technopark Kollam Campus
Kundara, Kollam
Kerala 691501
India
Privacy and grievance contact: info@medecue.com
Telephone: +91 903 767 6068 / +91 860 687 6068
References to the “Services” include the MedeCue web application, mobile applications, websites, APIs, gateways, integrations, laboratory device interfaces, support services and associated products.
3. Scope of This Notice
This Privacy Notice applies to personal data processed through:
- MedeCue websites and web portals;
- The MedeCue SaaS application;
- MedeCue mobile applications;
- MedeCue Gateway applications;
- Laboratory analyser and medical-device integrations;
- APIs and third-party integrations;
- Customer support, implementation and training;
- Billing and subscription administration;
- Sales, demonstrations and marketing activities; and
- Communications sent through email, SMS, WhatsApp or other enabled channels.
This Notice does not replace the privacy notice that a laboratory, hospital, clinic or other MedeCue customer is required to provide to its patients, employees or other individuals.
4. Our Privacy Roles
Our privacy role depends on the context in which personal data is processed.
4.1 Customer-controlled data
When a laboratory or healthcare organisation enters patient information, laboratory results, employee information, billing records or similar data into MedeCue, the customer normally determines:
- Which information is collected;
- Why the information is collected;
- Who may access it;
- How long it should be retained;
- Which communications should be sent; and
- How the information should be used.
In this situation, the customer generally acts as the data controller, data fiduciary, business or equivalent responsible organisation under applicable privacy law.
MedeCue generally acts as a data processor, data processor on behalf of the data fiduciary, service provider, contractor or equivalent processing organisation.
We process this data according to:
- The customer’s documented instructions;
- The applicable subscription agreement;
- Any Data Processing Agreement;
- Customer-configured settings; and
- Applicable law.
Individuals seeking to exercise rights concerning customer-controlled patient, employee or laboratory data should ordinarily contact the relevant laboratory or healthcare organisation first.
4.2 Data controlled directly by MedeCue
MedeCue may act as the data controller or data fiduciary for information concerning:
- Customer account administrators;
- Subscription and billing contacts;
- Website visitors;
- Demo and sales enquiries;
- Support contacts;
- Security and access logs;
- Marketing contacts;
- Vendor and business-partner contacts; and
- Individuals communicating directly with MedeCue.
5. Personal Data We Collect
Depending on the Services used, we may process the following categories of information.
5.1 Customer and business information
This may include:
- Laboratory, organisation or business name;
- Registration and licensing information;
- Business address;
- Branch and collection-centre information;
- Contact-person name;
- Job title and department;
- Business telephone number;
- Email address;
- Tax information;
- Subscription details;
- Billing and payment information;
- Contract details; and
- Authorised representative information.
5.2 User account information
This may include:
- Name;
- Username;
- Email address;
- Telephone number;
- Employee identifier;
- Role and designation;
- Assigned branch;
- User permissions;
- Password or authentication credentials in protected form;
- Multi-factor authentication information;
- Account status;
- Sign-in history;
- Session information; and
- User activity and audit logs.
5.3 Patient and clinical information
Where entered by an authorised customer, MedeCue may process:
- Patient name;
- Patient identifier or medical record number;
- Date of birth or age;
- Sex or gender information where required;
- Address and contact details;
- Referring doctor information;
- Corporate or insurance information;
- Visit and registration information;
- Test orders;
- Specimen and sample information;
- Laboratory analyser data;
- Test results;
- Reference ranges;
- Clinical observations;
- Comments and remarks;
- Diagnostic or clinical reports;
- Report approval information;
- Billing and payment information;
- Report-delivery preferences;
- Communication records; and
- Other information entered by the customer.
Patient and clinical data may be considered health data, sensitive personal information or special-category personal data under applicable law.
5.4 Employee and human-resource information
If a customer uses MedeCue HR features, the Services may process:
- Employee name and identifier;
- Contact information;
- Designation and department;
- Branch assignment;
- Shift information;
- Attendance records;
- Leave information;
- Payroll-related information;
- Earnings and deductions;
- Overtime information;
- User roles and access permissions; and
- Employment-related documents uploaded by the customer.
5.5 Biometric and facial-attendance information
Where the customer enables a facial-attendance or biometric feature, MedeCue may process facial images, facial templates, biometric identifiers or associated check-in and check-out information.
The customer is responsible for ensuring that:
- The feature is lawful in the relevant jurisdiction;
- Required consent or another lawful basis exists;
- Appropriate notices are provided;
- Collection is proportionate and necessary;
- Retention periods are configured appropriately; and
- Individuals are provided with any legally required alternative attendance method.
MedeCue will not use biometric information for advertising or unrelated identification purposes.
6. Sources of Personal Data
We may receive personal data:
- Directly from the individual;
- From a MedeCue customer;
- From an account administrator;
- From a laboratory analyser or connected device;
- From a hospital information system, laboratory information system or third-party API;
- From a payment processor;
- From an implementation or support partner;
- From publicly available business sources;
- Through cookies and technical logs; or
- From authorised communication providers.
7. How We Use Personal Data
We may process personal data for the following purposes.
7.1 Providing the Services
We use information to:
- Create and administer accounts;
- Process patient registrations;
- Manage test orders and samples;
- Receive analyser results;
- Generate laboratory reports;
- Support billing and payment workflows;
- Manage stock, accounts, HR and reporting modules;
- Deliver reports and notifications;
- Provide dashboards and analytics;
- Maintain audit trails; and
- Provide other customer-configured functions.
7.2 Performing contracts
We process information to:
- Provide subscriptions;
- Manage customer onboarding;
- Configure the Services;
- Provide implementation and training;
- Process invoices and payments;
- Provide customer support;
- Manage renewals;
- Enforce contractual terms; and
- Communicate about the customer relationship.
7.3 Security and fraud prevention
We use information to:
- Authenticate users;
- Detect unauthorised access;
- Investigate suspicious activity;
- Prevent fraud and abuse;
- Maintain backups;
- Monitor service security;
- Protect system availability;
- Respond to incidents; and
- Enforce access restrictions.
7.4 Legal and regulatory compliance
We may process information to:
- Comply with legal obligations;
- Respond to lawful government requests;
- Maintain financial and tax records;
- Establish, exercise or defend legal claims;
- Investigate complaints;
- Meet data-protection obligations; and
- Support customers in meeting applicable regulatory requirements.
7.5 Product administration and improvement
We may use technical, support and usage information to:
- Diagnose errors;
- Improve system performance;
- Develop new functionality;
- Evaluate feature adoption;
- Maintain compatibility;
- Improve usability;
- Conduct quality assurance;
- Test security controls; and
- Generate aggregated or de-identified statistics.
Patient or clinical data will not be used to train a general-purpose artificial-intelligence model unless this is expressly agreed in writing with the customer and a valid legal basis has been established.
7.6 Communications and marketing
We may use business-contact information to:
- Respond to enquiries;
- Arrange demonstrations;
- Provide service announcements;
- Send product updates;
- Invite customers to training;
- Communicate about relevant MedeCue services; and
- Conduct lawful business-to-business marketing.
Recipients may opt out of promotional communications at any time. Service, billing, security and transactional messages may still be sent where necessary.
8. Legal Bases for Processing
Depending on the applicable law and context, we rely on one or more of the following:
- Performance of a contract;
- Steps requested before entering a contract;
- Compliance with legal obligations;
- Consent;
- Legitimate business interests;
- Protection of legal rights;
- Prevention of fraud and security incidents;
- Processing instructed by a customer that has established a lawful basis;
- Protection of vital interests where recognised by law; or
- Another lawful basis permitted by applicable legislation.
Where consent is the legal basis, the individual may withdraw consent. Withdrawal does not affect processing that was lawful before withdrawal.
For customer-controlled patient or employee data, the customer is generally responsible for identifying and documenting the lawful basis.
9. Patient and Clinical Data
MedeCue does not independently decide which laboratory tests should be ordered, which results are clinically valid or how a patient should be diagnosed or treated.
The relevant laboratory, healthcare organisation and authorised professionals remain responsible for:
- Obtaining required patient notices and permissions;
- Verifying patient identity;
- Ensuring data accuracy;
- Selecting appropriate tests;
- Validating analyser mappings;
- Reviewing results;
- Approving reports;
- Interpreting clinical information;
- Maintaining legally required records; and
- Responding to patient privacy requests.
MedeCue personnel may access patient or clinical data only where reasonably necessary for authorised support, implementation, security, troubleshooting or legal compliance.
Access is subject to confidentiality and access-control requirements.
10. Artificial-Intelligence-Assisted Features
MedeCue may offer optional AI-assisted features, such as:
- Suggested observations;
- Draft remarks;
- Data-quality checks;
- Workflow recommendations;
- Report-formatting assistance;
- Anomaly indicators; or
- Operational analytics.
Where such features are enabled:
- AI output is provided as an aid and not as a final medical conclusion;
- Output may be incomplete, inaccurate or unsuitable;
- A qualified and authorised professional must review the output;
- Customers must not rely on AI output as the sole basis for diagnosis or treatment;
- The customer remains responsible for the final report and clinical decision;
- Access to AI features may be controlled through customer settings;
- Data will be transmitted to an external AI provider only where contractually authorised and appropriately protected; and
- MedeCue will not use identifiable patient data to train general-purpose models unless expressly agreed and legally permitted.
Where required by law, individuals will be informed about significant automated processing.
11. Cookies and Similar Technologies
MedeCue websites and applications may use:
- Strictly necessary cookies;
- Authentication cookies;
- Security cookies;
- Preference cookies;
- Performance cookies;
- Analytics cookies; and
- Similar local-storage or session technologies.
Strictly necessary cookies support login, security and essential functionality.
Non-essential cookies will be used subject to consent where required by applicable law. Users may manage cookies through browser settings or an available consent-management tool.
Disabling essential cookies may prevent parts of the Services from operating correctly.
12. How We Disclose Personal Data
We may disclose personal data to the following categories of recipients.
12.1 Customer-authorised users
Information may be available to laboratory administrators, authorised staff, doctors, technicians, accountants, HR personnel or other users according to roles and permissions configured by the customer.
12.2 Service providers and subprocessors
We may use service providers for:
- Cloud hosting;
- Data storage;
- Backup and disaster recovery;
- Email delivery;
- SMS or WhatsApp communication;
- Payment processing;
- Authentication;
- Security monitoring;
- Analytics;
- Error tracking;
- Customer support;
- Remote support;
- Document generation;
- AI processing where enabled; and
- Other infrastructure services.
Providers may process information only for authorised purposes and subject to contractual confidentiality, security and data-protection requirements.
A current subprocessor list may be made available to customers on request or through a designated MedeCue page.
12.3 Integrations selected by customers
Data may be shared with third-party systems selected or enabled by the customer, including:
- Laboratory analysers;
- Hospital information systems;
- Accounting systems;
- Payment providers;
- Messaging providers;
- Government portals;
- Insurance or corporate systems; and
- Other customer-authorised APIs.
The customer is responsible for evaluating and authorising third-party integrations.
12.4 Professional advisers
We may disclose information to auditors, lawyers, accountants, insurers and professional advisers where reasonably necessary.
12.5 Government and legal authorities
We may disclose information where required to:
- Comply with law;
- Respond to a valid legal process;
- Protect rights or safety;
- Investigate fraud or security incidents; or
- Establish or defend legal claims.
Where legally permitted, we will attempt to notify the affected customer before disclosing customer-controlled data.
12.6 Business transactions
Information may be transferred as part of a merger, acquisition, financing, restructuring or sale of all or part of the business, subject to appropriate confidentiality and privacy protections.
13. No Sale of Patient or Clinical Data
MedeCue does not sell patient or clinical data.
MedeCue does not use patient or clinical data for cross-context behavioural advertising.
We do not allow third parties to use identifiable patient or clinical data for their independent advertising purposes.
14. International Data Transfers
MedeCue is operated from India and may use service providers located in India or other countries.
Where personal data is transferred across national borders, we will use safeguards required by applicable law. These may include:
- Contractual data-protection obligations;
- Data Processing Agreements;
- Standard Contractual Clauses;
- United Kingdom international-transfer mechanisms;
- Transfer-risk assessments;
- Adequacy decisions;
- Data-localisation arrangements;
- Encryption and access controls; or
- Consent where legally appropriate.
Customers requiring specific hosting locations or data-residency arrangements must ensure that these requirements are included in the applicable Order Form or enterprise agreement.
15. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to contractual and legal obligations.
Retention is determined using factors such as:
- Customer instructions;
- Subscription duration;
- Customer-configured retention settings;
- Laboratory and healthcare recordkeeping requirements;
- Tax, accounting and corporate requirements;
- Legal limitation periods;
- Security and fraud-prevention needs;
- Backup schedules;
- Pending disputes or investigations; and
- Applicable local law.
15.1 Customer-controlled data
Patient, clinical, employee and operational data is retained according to:
- Customer instructions;
- The Customer Agreement;
- The Data Processing Agreement;
- Configured retention settings; and
- Applicable legal requirements.
Following termination, customers will normally be provided a limited period to export their data, as described in the applicable agreement.
Data will then be deleted or anonymised, subject to legal retention requirements and normal backup-deletion cycles.
15.2 Account and contract records
Account, billing, contract and transaction records may be retained for the duration of the commercial relationship and for the period required for accounting, taxation, dispute resolution and legal compliance.
15.3 Security and audit logs
Security, audit and access logs may be retained for a period appropriate to security monitoring, incident investigation, compliance and customer requirements.
15.4 Marketing information
Marketing information is retained until consent is withdrawn, an objection is received or the information is no longer needed for legitimate business communications.
16. Security Measures
MedeCue uses reasonable technical and organisational safeguards appropriate to the nature of the information and associated risks.
Measures may include:
- Role-based access controls;
- Unique user accounts;
- Password protection;
- Multi-factor authentication where enabled;
- Encryption in transit;
- Encryption at rest where supported;
- Secure development practices;
- Audit logs;
- Backup controls;
- Network protections;
- Vulnerability management;
- Security monitoring;
- Employee confidentiality obligations;
- Restricted support access;
- Incident-response procedures; and
- Business-continuity measures.
No electronic system is completely secure. Customers must also maintain appropriate security practices, including protecting credentials, removing inactive users, assigning minimum necessary permissions and securing connected devices and networks.
17. Personal-Data Breaches
MedeCue maintains procedures for identifying, investigating and responding to suspected personal-data breaches.
Where MedeCue is processing data on behalf of a customer, we will notify the affected customer in accordance with:
- Applicable law;
- The Data Processing Agreement;
- The Customer Agreement; and
- The circumstances of the incident.
The customer remains responsible for notifying patients, employees, regulators or other affected parties where the customer is the relevant controller or data fiduciary.
18. Individual Privacy Rights
Privacy rights vary by jurisdiction and may be subject to exemptions.
18.1 India
Where applicable under Indian data-protection law, individuals may have rights to:
- Obtain information about processing;
- Request correction of inaccurate or incomplete personal data;
- Request erasure where legally permitted;
- Withdraw consent;
- Submit a grievance;
- Nominate another individual to exercise rights in the event of death or incapacity; and
- Use other remedies available under applicable law.
18.2 European Economic Area and United Kingdom
Individuals may have rights to:
- Access personal data;
- Correct inaccurate personal data;
- Request deletion;
- Restrict processing;
- Object to processing;
- Receive portable data;
- Withdraw consent;
- Object to direct marketing;
- Request safeguards relating to significant automated decisions; and
- Submit a complaint to the relevant supervisory authority.
18.3 California and similar United States laws
Where applicable, individuals may have rights to:
- Know which categories of personal information are collected;
- Request access to specific information;
- Request deletion;
- Request correction;
- Opt out of sale or sharing;
- Limit certain uses of sensitive personal information;
- Receive information about disclosures; and
- Exercise rights without unlawful discrimination.
MedeCue does not sell patient or clinical data.
18.4 Exercising rights
For data entered by a laboratory or healthcare organisation, individuals should ordinarily contact that organisation directly.
MedeCue may forward a request to the relevant customer or assist the customer in responding.
For data controlled directly by MedeCue, requests may be sent to:
Email: info@medecue.com
Subject: Privacy Rights Request
We may need to verify the requester’s identity and authority before completing a request.
19. Children and Minors
MedeCue is intended for use by authorised organisations and professional users.
Patient information concerning children or minors may be entered by authorised laboratories where lawful and necessary for healthcare or laboratory services.
The customer is responsible for:
- Obtaining parental or guardian consent where required;
- Providing legally required notices;
- Restricting access appropriately; and
- Applying appropriate retention and security measures.
MedeCue does not knowingly market subscriptions directly to children.
20. Automated Decision-Making
MedeCue may automate operational activities such as:
- Workflow routing;
- Reference-range selection based on configured rules;
- Billing calculations;
- Alerts;
- Sample status updates;
- Result flags;
- Stock calculations; and
- Suggested observations.
Unless expressly stated otherwise, MedeCue is not intended to make final decisions that independently determine medical diagnosis, treatment or an individual’s legal rights.
Customers must ensure appropriate human review of clinically or legally significant decisions.
21. Communication Services
Customers may use MedeCue to send reports, reminders, invoices or other communications through email, SMS, WhatsApp or similar services.
The customer is responsible for:
- Obtaining valid contact details;
- Establishing a lawful basis for the communication;
- Obtaining consent where required;
- Ensuring the recipient is correct;
- Avoiding unnecessary sensitive information in message previews;
- Complying with messaging-provider policies; and
- Responding to opt-out requests.
Messages may be processed by the selected communication provider under that provider’s terms and privacy policy.
22. Third-Party Links and Services
The Services may contain links to or integrations with third-party services.
MedeCue is not responsible for the independent privacy practices of third parties. Customers and users should review the privacy terms of any third-party service they enable or access.
23. Changes to This Privacy Notice
We may update this Privacy Notice to reflect:
- Service changes;
- New functionality;
- Legal or regulatory developments;
- Changes to subprocessors;
- Security improvements; or
- Business changes.
The updated Notice will display a revised “Last Updated” date.
Where required, we will provide additional notice through the application, email or another appropriate channel.
24. Complaints and Grievances
Individuals may submit privacy concerns to:
Grievance Officer / Data Protection Contact
MedeCue – QAWebPrints Infocorp LLP
SBC-6, 1st Floor, Ashtamudi
Technopark Kollam Campus
Kundara, Kollam
Kerala 691501
India
Email: info@medecue.com
Please include sufficient information to identify the relevant account, laboratory or interaction.
We will acknowledge and address grievances within the period required by applicable law.
Individuals may also submit a complaint to the applicable data-protection or supervisory authority.
25. Customer Data Processing Agreements
Customers processing patient, health, biometric or other regulated information should enter into a Data Processing Agreement with MedeCue.
Where a customer is subject to specialised requirements, such as healthcare privacy, localisation or regulated hosting requirements, those obligations must be documented in the applicable agreement.
Use of MedeCue does not, by itself, guarantee that a customer has complied with every law applicable to its organisation, laboratory, patients, employees or jurisdiction.