Privacy Policy
How BDxLMS collects, uses, stores, protects and shares personal and health information.
Contents 36 sections
- 1. Introduction
- 2. About BDxLMS
- 3. Who Is Responsible for Your Personal Data?
- 4. Personal Information We May Process
- 5. How We Obtain Personal Information
- 6. Why We Process Personal Information
- 7. Legal Bases for Processing
- 8. Sensitive Personal Data and Health Information
- 9. How We Share Information
- 10. Multi-Tenant Data Separation
- 11. User Accounts and Access Control
- 12. Security of Personal Information
- 13. Data Breaches and Security Incidents
- 14. Data Retention
- 15. Backups
- 16. Data Location and International Transfers
- 17. Third-Party Integrations
- 18. Email, SMS and Messaging Services
- 19. Cookies and Similar Technologies
- 20. Analytics
- 21. Artificial Intelligence and Automated Processing
- 22. Children's Information
- 23. Data Subject Rights
- 24. Requests Concerning Patient Records
- 25. Verification of Requests
- 26. Healthcare Facility Responsibilities
- 27. Direct Marketing
- 28. Sale of Personal Data
- 29. Confidentiality
- 30. Subprocessors
- 31. Links to External Websites
- 32. Changes to This Privacy Policy
- 33. Governing Privacy Framework
- 34. Complaints
- 35. Contact BDxLMS
- 36. Acceptance and Acknowledgement
1. Introduction
BDxLMS ("BDxLMS", "we", "us", or "our") is a cloud-based Laboratory Information Management System and diagnostics operations platform designed to help medical laboratories, diagnostic centres, healthcare facilities and related organisations manage their operations.
We recognise that information handled through BDxLMS may include personal, financial and sensitive health information. Protecting that information is fundamental to the design, operation and governance of our platform.
This Privacy Policy explains how BDxLMS collects, uses, stores, protects, shares and otherwise processes personal information when individuals or organisations use:
- the BDxLMS website;
- the BDxLMS web application;
- mobile or browser-based interfaces provided by BDxLMS;
- BDxLMS APIs and integrations;
- laboratory analyser connectivity services;
- communication and result-dispatch services;
- customer support services; and
- other products or services operated by BDxLMS.
This Privacy Policy also explains the rights available to individuals whose personal data is processed through our services.
BDxLMS processes personal data in accordance with applicable data-protection laws, including the Nigeria Data Protection Act 2023 and regulations, directives or guidance issued by the Nigeria Data Protection Commission ("NDPC"), where applicable.
2. About BDxLMS
BDxLMS provides technology that enables healthcare and diagnostic organisations to manage activities such as:
- patient registration;
- test and service requests;
- laboratory workflows;
- sample collection;
- analyser integration;
- laboratory result entry and validation;
- radiology workflows;
- billing and payments;
- stock and inventory management;
- referrals;
- appointment and booking management;
- report generation;
- result dispatch;
- email, SMS and messaging integrations;
- financial and operational reporting;
- staff and user management;
- audit trails;
- branch management;
- customer communications; and
- other diagnostic-facility operations.
Healthcare facilities that subscribe to BDxLMS remain independent organisations and are responsible for their own healthcare services, patients, staff, clinical decisions and regulatory obligations.
BDxLMS does not become the healthcare provider merely because information is processed using the BDxLMS platform.
3. Who Is Responsible for Your Personal Data?
The identity of the organisation responsible for your personal information depends on the circumstances in which the information is processed.
3.1 Information processed on behalf of healthcare facilities
When a laboratory, diagnostic centre, hospital, clinic or other organisation uses BDxLMS to manage information about its patients, customers, referring clinicians or personnel, that organisation will generally determine why and how the information is processed.
In such circumstances, the healthcare facility will generally act as the Data Controller, while BDxLMS will generally act as a Data Processor providing technology and related services on its behalf.
For example, if you undergo a laboratory test at a diagnostic facility that uses BDxLMS, questions regarding:
- why the test was ordered;
- why your information was collected;
- correction of your medical information;
- access to your clinical records;
- deletion of records;
- release of results; or
- the facility's clinical retention requirements
should ordinarily be directed first to the healthcare facility concerned.
BDxLMS will assist our customers in responding to valid data-protection requests where required.
3.2 Information collected directly by BDxLMS
BDxLMS may act as a Data Controller for information we collect for our own purposes, including information relating to:
- BDxLMS customer accounts;
- subscriptions;
- facility administrators;
- billing contacts;
- prospective customers;
- website visitors;
- support enquiries;
- platform security;
- system logs;
- contractual relationships;
- BDxLMS marketing communications; and
- compliance with our legal obligations.
In some situations, BDxLMS may therefore be both a Data Controller and a Data Processor in relation to different categories of information.
4. Personal Information We May Process
Depending on how BDxLMS is used, the platform may process the following categories of information.
4.1 Patient information
Information entered by healthcare facilities may include:
- name;
- patient identification number;
- age;
- date of birth where applicable;
- sex;
- telephone number;
- email address;
- residential or contact information;
- branch or facility identifiers;
- emergency or next-of-kin information;
- referring clinician details;
- appointment information;
- payment information;
- service and test history; and
- other patient-registration information.
4.2 Health and medical information
BDxLMS may process health-related information including:
- laboratory test requests;
- laboratory results;
- specimen information;
- sample collection information;
- clinical notes;
- diagnostic findings;
- radiology information;
- vaccination information;
- medical reports;
- pathology information;
- reference ranges;
- test interpretation data;
- result validation information;
- diagnostic images or links to images where supported;
- referring-clinician information; and
- other information relating to healthcare or diagnostic services.
Health information may constitute sensitive personal data and is subject to enhanced protections.
4.3 Payment and billing information
Information may include:
- invoices;
- amount due;
- amount paid;
- discounts;
- payment status;
- payment method;
- transaction references;
- payment dates;
- receipts;
- payer information; and
- financial reconciliation information.
BDxLMS may integrate with third-party payment providers. Where payment-card information is processed directly by an external payment provider, BDxLMS may not receive or store the complete card information.
4.4 Healthcare professional and referring-clinician information
We may process:
- names;
- professional titles;
- contact details;
- facility or practice information;
- referral relationships;
- referral activity;
- portal credentials;
- professional registration information where applicable; and
- communications with healthcare facilities.
4.5 Facility and staff information
For personnel using BDxLMS, information may include:
- names;
- email addresses;
- telephone numbers;
- job roles;
- branch assignments;
- facility affiliations;
- usernames;
- account status;
- authentication information;
- access permissions;
- actions performed within the platform; and
- audit logs.
4.6 Technical information
When BDxLMS is accessed, we may automatically collect information such as:
- IP address;
- browser type;
- operating system;
- device information;
- login date and time;
- session information;
- security events;
- error logs;
- pages or modules accessed;
- activity logs;
- approximate geographic information derived from IP addresses where necessary;
- API activity; and
- other technical information required to operate and secure the service.
4.7 Laboratory analyser and integration data
Where a facility connects laboratory analysers or other medical equipment to BDxLMS, information exchanged may include:
- patient or sample identifiers;
- test codes;
- analyser identifiers;
- result values;
- units;
- timestamps;
- flags;
- device communication information; and
- information necessary to match analyser results to laboratory orders.
The exact information exchanged depends on the analyser, integration method and configuration selected by the healthcare facility.
5. How We Obtain Personal Information
We may obtain information:
- directly from users;
- from healthcare facilities using BDxLMS;
- from authorised employees of those facilities;
- from patients completing forms or bookings;
- from referring clinicians;
- from laboratory analysers and connected devices;
- through integrations and APIs;
- from authorised third-party applications;
- from payment processors;
- through customer-support communications; and
- automatically through use of our website or platform.
BDxLMS does not require healthcare facilities to provide information unrelated to legitimate use of the platform.
6. Why We Process Personal Information
Personal information may be processed to:
Provide the BDxLMS service
This includes operating patient registration, laboratory workflows, billing, result management, stock management, reporting and other platform functions.
Process laboratory and diagnostic workflows
This may include handling test requests, samples, analyser results, result validation and diagnostic reports.
Maintain patient records
Healthcare facilities may use BDxLMS to maintain historical records of services provided to patients.
Generate and deliver reports
Information may be processed to generate laboratory or diagnostic reports and deliver them through authorised channels.
Process payments and billing
Information may be used to prepare invoices, record payments, issue receipts, calculate balances and perform financial reporting.
Manage users and permissions
We process account and access-control information to ensure users can access only the areas and information they are authorised to use.
Maintain security
Information may be processed to:
- authenticate users;
- detect unauthorised access;
- investigate suspected misuse;
- prevent fraud;
- protect patient information;
- maintain security logs; and
- respond to cybersecurity incidents.
Provide customer support
We may use account and technical information to investigate errors, provide technical assistance and resolve customer requests.
Improve the platform
We may analyse appropriately protected usage and technical information to improve reliability, performance, usability and functionality.
Where possible, aggregated or de-identified information will be used for analytics and product improvement.
Meet legal and regulatory requirements
Information may be processed when necessary to comply with applicable laws, court orders, regulatory requirements, audit obligations or lawful requests from authorised public authorities.
7. Legal Bases for Processing
Depending on the circumstances and applicable law, personal information may be processed on one or more of the following grounds:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- legitimate interests recognised by applicable law;
- performance of a task carried out in the public interest or under official authority where applicable; and
- other lawful grounds permitted for processing sensitive personal data, including health information.
Healthcare facilities using BDxLMS are responsible for establishing an appropriate lawful basis for the patient and health information they collect and process through the platform.
8. Sensitive Personal Data and Health Information
BDxLMS recognises health and medical information as particularly sensitive.
We therefore apply enhanced safeguards to health information processed through the platform.
Healthcare facilities must ensure that health information uploaded to BDxLMS is collected and processed lawfully.
BDxLMS will not intentionally use patient health information submitted by a healthcare facility for unrelated advertising or sell such information to advertisers.
9. How We Share Information
We do not sell patient health records.
Personal information may, however, be disclosed when necessary for the provision, protection or lawful operation of the service.
Recipients may include:
9.1 The healthcare facility
Information is accessible to authorised personnel of the healthcare facility that created or manages the relevant records.
9.2 Authorised branches
Where a healthcare organisation operates multiple branches, information may be available across authorised branches depending on the organisation's configuration and access policies.
9.3 Healthcare professionals
Patient information may be shared with authorised laboratory professionals, radiographers, doctors, referring clinicians or other healthcare personnel where authorised by the relevant healthcare facility.
9.4 Service providers and subprocessors
BDxLMS may use carefully selected service providers to provide services such as:
- cloud hosting;
- email delivery;
- SMS delivery;
- messaging;
- payment processing;
- data backup;
- cybersecurity;
- monitoring;
- analytics;
- technical support; and
- infrastructure services.
These providers are permitted to access personal information only to the extent necessary to provide their services and are expected to protect that information appropriately.
9.5 Government and regulatory authorities
We may disclose information where required by applicable law, regulation, court order or other lawful governmental request.
Where legally permitted, BDxLMS will assess such requests before disclosing information.
9.6 Corporate transactions
If BDxLMS undergoes a merger, acquisition, financing, restructuring or sale of some or all of its business or assets, information may be transferred as part of that transaction subject to applicable data-protection requirements.
10. Multi-Tenant Data Separation
BDxLMS is designed as a multi-tenant platform.
Different healthcare facilities may use the same underlying platform infrastructure while remaining separate customers.
BDxLMS implements technical and organisational controls intended to prevent one facility from accessing another facility's information except where access has been expressly authorised or is required by law.
Each facility is responsible for appropriately managing its own authorised users, branches, roles and permissions.
11. User Accounts and Access Control
Users must keep their login credentials confidential.
Healthcare facilities are responsible for:
- creating accounts only for authorised personnel;
- assigning appropriate user roles;
- removing access when personnel leave or change roles;
- reviewing account permissions periodically;
- protecting authentication credentials; and
- notifying BDxLMS promptly of suspected unauthorised access.
BDxLMS may maintain audit records showing actions carried out by users for security, accountability and regulatory purposes.
12. Security of Personal Information
BDxLMS uses reasonable technical and organisational measures designed to protect information against:
- unauthorised access;
- unlawful disclosure;
- accidental loss;
- alteration;
- misuse;
- destruction; and
- other forms of unauthorised processing.
Depending on the service and environment, safeguards may include:
- encrypted communications;
- access controls;
- authentication controls;
- role-based permissions;
- facility-level data isolation;
- session management;
- activity and audit logging;
- database security;
- backups;
- monitoring;
- vulnerability management;
- infrastructure security;
- secure software-development practices; and
- incident-response procedures.
No electronic system can guarantee absolute security. We therefore continually review and improve our safeguards in light of evolving risks, technologies and regulatory requirements.
13. Data Breaches and Security Incidents
Where BDxLMS becomes aware of a personal-data breach, we will assess the nature and potential impact of the incident.
Where BDxLMS acts as a processor on behalf of a healthcare facility, we will notify the relevant facility in accordance with applicable law and our contractual obligations.
Where BDxLMS is required to notify the Nigeria Data Protection Commission, affected individuals or another competent authority, we will do so in accordance with applicable legal requirements.
14. Data Retention
BDxLMS retains personal information only for as long as reasonably necessary for the purposes for which it was collected, contractual requirements, legitimate business needs or applicable legal and regulatory obligations.
Different categories of information may therefore have different retention periods.
Clinical information processed on behalf of healthcare facilities may be retained according to:
- instructions from the healthcare facility;
- applicable healthcare record-retention requirements;
- laboratory or professional requirements;
- contractual requirements; and
- applicable law.
Security logs, audit records, financial information and transaction records may be retained for periods necessary for fraud prevention, accounting, regulatory compliance, dispute resolution and security.
When information is no longer required, BDxLMS may securely delete, anonymise or otherwise dispose of it in accordance with applicable requirements.
15. Backups
BDxLMS may maintain backups for disaster recovery, business continuity and security.
Deletion of information from the live system may not result in immediate deletion from all backup copies.
Information contained in backups will normally be removed through the ordinary backup-retention lifecycle and will remain protected while retained.
16. Data Location and International Transfers
BDxLMS or its service providers may operate infrastructure or provide services from jurisdictions outside Nigeria.
Where personal information is transferred internationally, BDxLMS will take reasonable steps to ensure that the transfer is permitted under applicable data-protection law and that appropriate safeguards are implemented where required.
Such safeguards may include:
- contractual protections;
- assessments of the receiving jurisdiction;
- approved transfer mechanisms;
- technical safeguards;
- encryption; and
- other measures recognised by applicable law.
17. Third-Party Integrations
BDxLMS may integrate with third-party services such as:
- payment providers;
- email services;
- SMS providers;
- messaging platforms;
- laboratory analysers;
- healthcare systems;
- websites;
- APIs; and
- other software selected or authorised by a healthcare facility.
Third-party services may process information under their own privacy policies and terms.
BDxLMS is not responsible for independent processing carried out by third-party services outside BDxLMS's control.
Healthcare facilities should review third-party services before enabling integrations involving personal information.
18. Email, SMS and Messaging Services
Healthcare facilities may use BDxLMS to send:
- appointment messages;
- payment notifications;
- laboratory reports;
- result notifications;
- operational communications;
- reminders; and
- other authorised messages.
Such communications may be transmitted through external email, SMS or messaging providers.
Healthcare facilities are responsible for ensuring that recipients, telephone numbers, email addresses and communication methods used are appropriate and lawful.
Highly sensitive information should only be transmitted through channels appropriate to the nature and sensitivity of the information.
19. Cookies and Similar Technologies
The BDxLMS website or application may use cookies and similar technologies.
These may be used for:
- authentication;
- session management;
- security;
- remembering user preferences;
- preventing fraud;
- analysing website performance; and
- improving user experience.
Where required by applicable law, users will be provided with appropriate information and choices regarding non-essential cookies.
Essential cookies required for security, authentication or operation of the platform may not be capable of being disabled through the platform.
20. Analytics
BDxLMS may collect information regarding how the service is used in order to:
- diagnose technical issues;
- understand platform performance;
- identify frequently used features;
- improve user experience;
- prevent abuse; and
- develop new functionality.
Where practical, aggregated or de-identified information will be used instead of directly identifiable patient information.
21. Artificial Intelligence and Automated Processing
BDxLMS may introduce automated or artificial-intelligence-assisted features.
Where such functionality is provided, BDxLMS will implement appropriate safeguards based on the nature and risk of the processing.
Unless expressly stated otherwise, automated tools provided through BDxLMS should not be treated as a substitute for qualified professional medical judgement.
Healthcare facilities and authorised healthcare professionals remain responsible for clinical decisions.
Where applicable law grants rights relating to decisions based solely on automated processing that produce legal or similarly significant effects, those rights will be respected.
22. Children's Information
BDxLMS may process information relating to children where a healthcare facility provides healthcare or diagnostic services to a child.
Such information is processed on behalf of the healthcare facility and should be collected and handled in accordance with applicable law, including requirements relating to parental or guardian authority where applicable.
BDxLMS does not knowingly use children's medical information for behavioural advertising.
23. Data Subject Rights
Subject to applicable law and any relevant exemptions, individuals may have rights regarding their personal data, including the right to:
- obtain information about how their personal data is processed;
- request access to their personal data;
- request correction of inaccurate or incomplete information;
- request deletion of personal information in appropriate circumstances;
- request restriction of processing;
- object to certain processing;
- withdraw consent where processing is based on consent;
- request data portability where applicable;
- object to certain direct-marketing activities;
- obtain information regarding certain automated decision-making activities; and
- lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.
These rights are not absolute and may be restricted where continued processing is required by law or justified under an applicable lawful basis.
24. Requests Concerning Patient Records
Where BDxLMS holds information solely on behalf of a healthcare facility, patients should ordinarily contact the facility where they received care.
For example, requests relating to a laboratory result held within a diagnostic facility's BDxLMS account should normally be submitted to that facility.
If BDxLMS receives such a request directly, we may:
- identify the relevant healthcare facility;
- refer the request to that facility;
- request additional information necessary to verify the request; and
- assist the facility in responding where required.
BDxLMS will not independently alter clinical records controlled by a healthcare facility unless authorised or legally required to do so.
25. Verification of Requests
Because BDxLMS may hold sensitive medical information, we may require reasonable identity verification before responding to a data-protection request.
This is intended to prevent information from being disclosed to unauthorised persons.
We may also request information necessary to identify the healthcare facility or account associated with the records.
26. Healthcare Facility Responsibilities
Healthcare facilities using BDxLMS are responsible for ensuring that their use of the platform complies with applicable privacy, healthcare and professional requirements.
Facilities should, among other things:
- collect personal information lawfully;
- provide appropriate privacy notices to patients;
- obtain consent where consent is legally required;
- restrict platform access to authorised personnel;
- maintain appropriate internal confidentiality policies;
- promptly disable accounts belonging to former personnel;
- respond appropriately to data-subject requests;
- maintain appropriate legal bases for processing;
- comply with healthcare record-retention requirements;
- ensure that information entered into BDxLMS is accurate where required;
- use secure devices and networks;
- avoid sharing user credentials; and
- report suspected security incidents promptly.
27. Direct Marketing
BDxLMS may send information about its products, services, updates or offers to customers or prospective customers where legally permitted.
Individuals may opt out of direct marketing communications using the unsubscribe mechanism provided or by contacting us.
Opting out of marketing communications will not prevent BDxLMS from sending essential service-related communications such as security notices, account notifications or contractual information.
Patient health information entered by healthcare facilities will not be used by BDxLMS for unrelated direct marketing to patients without an appropriate legal basis.
28. Sale of Personal Data
BDxLMS does not sell patient medical records or laboratory results to data brokers or advertisers.
If BDxLMS's business model changes in a way that materially affects how personal information is used, this Privacy Policy will be updated and any additional consent or notice required by law will be provided.
29. Confidentiality
BDxLMS personnel and contractors who may have access to confidential customer or patient information are expected to comply with confidentiality and security obligations appropriate to their roles.
Access to production information should be limited to individuals who require access for legitimate operational, technical, security or support purposes.
30. Subprocessors
BDxLMS may engage third-party subprocessors to assist in providing its services.
Where required, BDxLMS will impose appropriate contractual privacy and security obligations on subprocessors that process personal information on our behalf.
Customers may contact BDxLMS for information regarding relevant categories of subprocessors used in delivering the service.
31. Links to External Websites
BDxLMS websites or communications may contain links to third-party websites.
BDxLMS is not responsible for the privacy practices or content of independent third-party websites.
Users should review the privacy policies of those services before providing personal information.
32. Changes to This Privacy Policy
BDxLMS may update this Privacy Policy periodically to reflect:
- changes to the platform;
- new features;
- changes in applicable law;
- regulatory guidance;
- changes in our service providers; or
- improvements to our privacy and security practices.
The updated version will display a revised "Last Updated" date.
Where changes materially affect the rights of users or how personal information is processed, we may provide additional notice through the platform, email or another appropriate channel.
33. Governing Privacy Framework
This Privacy Policy is intended to operate in accordance with applicable Nigerian data-protection requirements, including the Nigeria Data Protection Act 2023 and regulatory requirements issued by the Nigeria Data Protection Commission.
Where BDxLMS provides services to organisations or individuals subject to additional data-protection laws, additional contractual or privacy provisions may apply.
34. Complaints
Individuals who have concerns about how their personal information has been handled may contact BDxLMS using the contact information below.
Where the information is controlled by a healthcare facility, the complaint may be referred to that facility for investigation.
Individuals may also have the right to lodge a complaint with the Nigeria Data Protection Commission or another competent regulatory authority.
Nigeria Data Protection Commission
Abuja, Nigeria
Official information regarding data-protection complaints and regulatory procedures is available through the Nigeria Data Protection Commission.
35. Contact BDxLMS
Questions, complaints and privacy requests may be directed to:
BDxLMS
Operated by: BDx Technologies
Registered Address: Yaba, Lagos, Nigeria
Website: https://bdxlms.cloud
General Email: info@bdxlms.cloud
Privacy Email: [Insert Privacy/DPO Email Address]
Telephone: +234 904 446 3614
Data Protection Officer / Privacy Contact:
[Insert Name or Position, if applicable]
Email: [Insert DPO/Privacy Email]
When contacting us regarding information maintained by a healthcare facility, please include the name of the relevant facility where appropriate. Do not send unnecessary medical information by unsecured email.
36. Acceptance and Acknowledgement
Use of BDxLMS is subject to this Privacy Policy together with any applicable Terms of Service, subscription agreement, Data Processing Agreement and other contractual terms between BDxLMS and the subscribing organisation.
Healthcare facilities using BDxLMS acknowledge that they remain responsible for their own obligations as healthcare providers and Data Controllers where applicable.
BDxLMS remains responsible for its obligations regarding personal information that it processes as a Data Controller or Data Processor.