Privacy Policy
How TestGo collects, uses, discloses, and protects information within the TestGo Client app for authorized healthcare, laboratory, and diagnostic staff.
Introduction
This Privacy Policy explains how TestGo ("we", "us", or "our") collects, uses, discloses, stores, and protects information when you use the TestGo Client mobile application (the "App").
TestGo Client is a business/professional application used by authorized staff of healthcare, laboratory, and diagnostic organizations to manage test orders, sample pickups, patient results, facilities, supplies, and related workflows.
The App is not intended for the general public and requires a valid account issued by your organization to sign in.
By downloading, accessing, or using the App, you agree to this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.
Who This Policy Applies To
This Privacy Policy applies to:
- Authorized users and employees of subscribing organizations, including laboratory staff, physicians, facility administrators, phlebotomists, and couriers.
The App is provisioned solely through organization-issued accounts and is not available for public sign-up. Consistent with this closed, employer-issued access model, we do not knowingly permit use of the App by anyone under 18 years of age.
The App may process information relating to patients and physicians as part of the diagnostic workflow. In this context:
- Your organization is the data controller / covered entity.
- TestGo acts as a data processor / business associate and processes such information on behalf of your organization and according to its instructions.
Information We Collect
We collect only the information reasonably necessary to operate the App and provide its services.
3.1 Account and Profile Information
Depending on your organization's configuration and your role, we may collect:
- First name and last name
- Username and email address
- Phone number and fax number
- Designation, job role, and user type
- Profile photo or avatar, if provided
- Date of birth and gender, if provided by your organization
- City and state associated with your work address
- NPI number and provider or card identifiers for physician users
- Authentication tokens required to keep you securely signed in
3.2 Operational and Health-Related Workflow Data
Because the App supports laboratory and diagnostic operations, it may process information including:
- Test orders and order details
- Sample pickup and courier tracking information
- Patient results and result inbox items
- Test menu information
- Supply information
- Facility information
- E-signatures, including typed or drawn signatures
- Documents and images uploaded to authorize E-Requests
Some of this information may constitute Protected Health Information (PHI) under U.S. law or sensitive personal data under applicable Indian law. We handle such information in accordance with applicable legal and contractual requirements, as described in Sections 8 and 9.
3.3 Device Permissions and Related Data
The App requests device permissions only when required for a specific feature.
- Camera — Capture a photo of your signature or upload documents for E-Requests.
- Photos / Media / Storage — Select images or documents from your device for upload.
- Bluetooth (Connect / Scan) — Connect to compatible thermal printers to print barcode labels.
- Location (Fine) — Required by Android to enable Bluetooth device scanning for printers. We do not use location to track your movements or for advertising.
- Microphone — Declared for an optional video-recording feature; not currently used.
- Internet / Network — Communicate securely with our servers and provide App functionality.
You may grant or revoke these permissions at any time through your device settings. Some App features may not function correctly if a required permission is denied.
3.4 Technical and Log Data
We may automatically collect limited technical information, including:
- App version
- Device model
- Operating system and version
- Language settings
- Diagnostic logs
- Error reports
This information is used to maintain reliability, troubleshoot issues, improve performance, and protect the security of the App. We do not use third-party advertising SDKs, and we do not sell your personal information.
How We Use Your Information
We may use collected information to:
- Authenticate users and provide role-based access
- Operate core workflows, including orders, sample pickups, results, facilities, and supplies
- Enable document and signature uploads
- Enable barcode label printing
- Send in-app notifications relevant to your work
- Maintain security and prevent fraud or unauthorized access
- Diagnose technical issues and improve App performance
- Provide customer and technical support
- Comply with applicable legal, regulatory, and contractual obligations
Depending on the circumstances, we process personal information based on:
- Your consent
- Performance of a contract with your organization
- Legitimate business interests
- Compliance with applicable legal obligations
Data Storage, Transfer, and Retention
6.1 Data Transmission
Data transmitted between the App and our servers is protected using encrypted connections, including HTTPS/TLS.
6.2 Secure Storage
Authentication tokens and other sensitive values stored on your device are protected using the device's secure storage mechanisms, including:
- Android Keystore
- iOS Keychain
6.3 International Data Transfers
Data may be stored and processed on servers located in:
- India
- United States
- Other countries or regions where our service providers operate
Where personal information is transferred across borders, we apply appropriate safeguards as required by applicable law.
6.4 Data Retention
We retain personal information only for as long as reasonably necessary to:
- Provide and maintain the service
- Fulfill contractual obligations
- Meet legal and regulatory requirements
- Resolve disputes
- Protect our rights and security
As a general rule, account and profile information is retained for the duration of your organization's subscription plus 90 days after account deactivation, and operational/health-related workflow data (orders, results, e-signatures, uploaded documents) is retained for 6 years, or the period specified in your organization's agreement with TestGo, consistent with applicable healthcare recordkeeping requirements.
When information is no longer required, we take reasonable steps to delete, securely dispose of, or anonymize it, subject to applicable legal and contractual requirements.
Security
We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction. These safeguards may include:
- Encryption of data in transit
- Secure credential and token storage
- Role-based access controls
- Access logging
- Authentication and authorization controls
- Security monitoring and vulnerability management
However, no method of transmission or electronic storage is completely secure.
While we continuously work to protect information and address security vulnerabilities, we cannot guarantee absolute security of information transmitted to or stored by the App.
Your Rights — India (DPDP Act, 2023)
If you are located in India, you may have rights under the Digital Personal Data Protection Act, 2023, including the right to:
- Access a summary of your personal data and information about its processing
- Request correction, completion, or updating of inaccurate or incomplete data
- Request erasure of personal data, subject to applicable legal and contractual retention requirements
- Withdraw consent where processing is based on consent — you may withdraw consent at any time using the same ease with which it was given, either through the in-app settings (where available) or by contacting our Grievance Officer / Data Protection Officer as described in Section 11. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and certain processing may continue where required for legitimate purposes such as legal or contractual obligations.
- Nominate another individual to exercise your rights in the event of death or incapacity
- Seek grievance redressal through the contact channel provided in Section 11
To exercise applicable rights, please contact our Grievance Officer / Data Protection Officer using the contact information provided in Section 11.
Your Rights — United States (HIPAA & CCPA/CPRA)
9.1 HIPAA
Where the App processes Protected Health Information (PHI) on behalf of a HIPAA-covered entity, TestGo acts as a Business Associate.
TestGo handles PHI in accordance with the applicable Business Associate Agreement (BAA) and applicable requirements of the Health Insurance Portability and Accountability Act (HIPAA). Where required by an applicable BAA or by HIPAA's documentation requirements, TestGo retains designated PHI-related records (such as audit logs and disclosure accountings) for a minimum of six (6) years, or such other period specified in the applicable BAA, whichever is longer.
Patient rights concerning PHI are generally exercised through the applicable covered entity, such as your healthcare provider, laboratory, or organization.
9.2 California — CCPA/CPRA
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Depending on applicable law, these rights may include:
- The right to know what personal information is collected and how it is used
- The right to request access to personal information
- The right to request deletion of personal information, subject to applicable exceptions
- The right to correction of inaccurate personal information
- The right to opt out of certain forms of data sharing or sale where applicable
- The right not to receive discriminatory treatment for exercising applicable privacy rights
TestGo does not sell or share personal information for cross-context behavioral advertising. Because TestGo does not sell or share personal information as defined under the CCPA/CPRA, a "Do Not Sell or Share My Personal Information" link is not applicable to the App or its associated properties.
To exercise applicable rights, please use the contact information provided in Section 11.
Children's Privacy
The App is intended exclusively for authorized adult professional users.
We do not knowingly collect personal information directly from children under the age of 18.
If you believe that a minor has provided personal information directly to us, please contact us using the information provided in Section 11. We will take appropriate steps to investigate and address the situation in accordance with applicable law.
Contact Us
For questions, privacy requests, complaints, or other concerns regarding this Privacy Policy or the handling of personal information, please contact:
Company: TestGo
Email: info@testgo.com
We will review and respond to privacy requests within the timeframes required by applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, practices, legal requirements, or other operational needs.
When we make changes, we will:
- Update the "Last Updated" date at the beginning of this Privacy Policy.
- Provide additional notice through the App or other appropriate means where required or appropriate.
Your continued use of the App after an updated Privacy Policy becomes effective constitutes your acknowledgment of the updated Policy, to the extent permitted by applicable law.