Skip to content

Legal

Privacy policy

What Labnize collects, why it collects it, where it is kept and what you can ask us to do with it.

Last updated 3 September 2026

Who we are

Labnize provides a hosted laboratory inventory, procurement and traceability platform. Where your organisation uses Labnize, your organisation is the data controller for the laboratory data it enters, and Labnize is the processor acting on its instructions.

For personal data we collect directly, such as an enquiry from this website, Labnize is the controller.

What we collect

We collect information you give us and information the service generates while you use it.

  • Account information: name, work email, role and the organisation you belong to.
  • Laboratory data your organisation enters: chemicals, batches, suppliers, analyzes, devices and the movements between them.
  • Files you upload, such as certificates of analysis and safety data sheets.
  • Service records: audit log entries, stock movement entries and technical logs needed to run and debug the platform.
  • Correspondence when you contact us for support or through the form on this site.

Why we use it

Each purpose below is limited to what running the service requires.

  • To provide the platform and keep your organisation data separate from every other organisation.
  • To authenticate users and enforce the role each account holds.
  • To send operational messages: stock alerts, approval notifications and security notices.
  • To diagnose faults and improve reliability, using technical logs and error reports.
  • To answer enquiries and provide support.
  • To meet legal obligations that apply to us.

Where your data is kept

All customer data is stored in the European Union, in data centres in Nuremberg, Falkenstein and Helsinki, on infrastructure certified to ISO/IEC 27001:2022. Data is not transferred outside the European Union.

Backups are taken every four hours, retained for the last six cycles, and stored encrypted in separate EU object storage.

How it is protected

Traffic runs over TLS. Passwords are stored as one-way cryptographic hashes. Every query is scoped to the organisation it belongs to, and each of the seven roles reaches only the data its job needs.

Uploaded files are served through short-lived private links rather than public URLs. Significant actions are written to an audit log, and every stock movement is written to the movement ledger.

How long we keep it

Laboratory data is kept for as long as your organisation holds an account, because traceability is the point of the record. On termination, data is deleted or returned according to the agreement with your organisation.

Enquiry correspondence is kept only as long as it is useful for answering you and for any resulting contract.

Who else touches it

We use a small number of processors to run the service: the EU hosting and object storage provider, an email provider for transactional messages, and an error monitoring service. Each is bound by a data processing agreement.

We do not sell personal data, and we do not share it for advertising.

Your rights

Under the GDPR you can exercise the rights below. Where your organisation is the controller, we will pass your request to it and support it in answering.

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted, where no legal obligation requires us to keep it.
  • Object to or restrict processing.
  • Receive your data in a portable format.
  • Complain to your national data protection authority.

Changes to this policy

If this policy changes materially, the date at the top of the page changes with it, and account holders are notified before the change takes effect.

Questions about this policy

Write to us and a human answers.

[email protected]