Who we are
DiagnOS is a laboratory operating platform built and operated by Lead TAD ("Lead TAD", "we", "us"), a company registered in Nigeria. You can reach us at leadtad.com.
This policy explains what we do with personal information when you visit this website, when your laboratory uses DiagnOS, and when your test results are recorded, approved and delivered through the platform. It is written to meet the Nigeria Data Protection Act 2023 (the "NDPA") and the Nigeria Data Protection Regulation.
Our two roles
DiagnOS is used by laboratories, and almost everything sensitive in the platform belongs to a laboratory rather than to us. That gives us two distinct roles, and your rights depend on which one applies.
We are the controller
For information about the people we deal with directly: visitors to this website, people who request a demo, and the staff of a laboratory in their capacity as our customer's representatives — account details, billing records and support conversations.
We are the processor
For everything a laboratory records about its patients — visits, vitals, test requests, results, interpretive comments, payments and delivery records. The laboratory decides what is collected and why; we only act on its instructions.
If you are a patient, your laboratory is the data controller for your records. We hold that data on its behalf and cannot release, correct or delete it on our own initiative. Requests should go to the laboratory that tested you; we will support them in answering you.
Information we collect directly
Where we act as controller, we collect:
- Demo requests. Your name, laboratory name, work email, phone or WhatsApp number, preferred date and time, whether you want a virtual or physical session, and the laboratory address if you choose a physical visit.
- Account data. The name, email address, phone number, job role and access level of each person your laboratory invites into DiagnOS, together with authentication data such as password hashes and two-factor settings.
- Subscription and billing data. Your laboratory's plan, invoices, payment status and the reference numbers returned by our payment providers.
- Support and correspondence. Messages you send us by email or WhatsApp and our replies, including any screenshots or files you attach.
- Technical data. IP address, browser and device type, pages visited, and server and application logs recording the time of each request and any errors it produced.
Patient data we process for laboratories
Where we act as processor, the categories of data a laboratory may store in DiagnOS include:
- Patient identity. Name, age or date of birth, gender, phone number, email address and any patient identifier the laboratory assigns.
- Visit records. Arrival and discharge times, visit status, the staff member who attended, and the history of previous visits.
- Vitals. Blood pressure, pulse, temperature, weight, height and derived measures such as BMI.
- Clinical data. Tests requested, sample types, recorded values, reference ranges and abnormal flags, scientist comments, approvals and digital signatures, and the generated PDF report with its validation QR code.
- Financial records. Amounts charged, part-payments and balances, payment method, and transaction references from our payment partners.
- Delivery records. Whether a result was sent by WhatsApp or email, the destination address or number, and when it was sent.
- Laboratory staff records. Where a laboratory uses the payroll features, employee details, schedules and salary runs.
Health data is sensitive personal data under the NDPA. We treat every record in this category as confidential, restrict access to the staff and systems that need it, and never use it to build products, profiles or marketing of any kind.
How we use information
We use the information described above to:
- provide the platform — running visits, tests, results, payments and result delivery for your laboratory;
- authenticate users, enforce role-based permissions and keep an audit trail of who recorded, approved or sent each result;
- generate reports, receipts and the analytics your laboratory sees in its own dashboard;
- take payment for subscriptions and, where your laboratory uses online collection, for patient charges;
- respond to demo requests and support enquiries, and send service messages about outages, security or changes to the platform;
- keep the service secure and available — monitoring, backups, debugging and investigating misuse;
- meet our legal, tax and regulatory obligations.
We do not sell personal information, and we do not use patient or clinical data for advertising.
Lawful basis under the NDPA
Where we are the controller, we rely on the performance of a contract (running your laboratory's subscription), our legitimate interests (securing the platform, answering enquiries, improving our own service), your consent (for a demo request or marketing email, which you may withdraw at any time), and legal obligation (tax and record-keeping).
Where we are the processor, the laboratory determines the lawful basis. Laboratories using DiagnOS must have a valid basis under the NDPA for the patient data they record — normally the provision of healthcare services and, for sensitive data, the patient's consent or another applicable condition — and are responsible for giving their patients notice of it.
AI-drafted result summaries
DiagnOS can draft a plain-language summary of a finished result so a patient can understand it. This is worth describing precisely, because it is the one place where clinical content leaves our systems.
- When a scientist opens the approval dialog, we use AI to generate a short suggested comment.
- The suggestion is a draft. A qualified scientist reviews it, edits it freely, and it is only stored and sent to the patient once that person approves and signs the result.
- No automated decision with legal or similarly significant effect is made about any patient. Nothing is diagnosed, prioritised or refused by a model.
A laboratory that would rather not use this feature can ask us to disable it for its account, and results will then be approved with comments written entirely by its scientists.
How long we keep information
- Patient and clinical records are kept for as long as the laboratory's account is active, because a laboratory has its own record-keeping obligations. Deletion within an active account is the laboratory's decision.
- After termination we keep the account's data for 30 days so it can be exported, then delete it from live systems. Encrypted backups age out within 90 days.
- Demo requests are kept for 12 months from your last contact with us.
- Billing records are kept for six years to meet Nigerian tax and accounting requirements.
How we protect information
We take the measures you would expect of a platform holding health records: encryption in transit over TLS, encryption of stored backups, hashed passwords, role-based access so that each member of staff sees only what their role allows, an approval and signing step before any result leaves the laboratory, an audit trail on clinical actions, and access to production systems limited to the few Lead engineers who need it.
No system is perfectly secure. If a breach affects your data we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as the NDPA requires, and tell affected laboratories without undue delay so they can inform their patients.
Your rights
Under the NDPA you have the right to be informed about how your data is used, and to request access to it, correction of it, deletion of it, restriction of its processing, portability of it, and to object to processing based on legitimate interests. Where processing rests on consent, you can withdraw that consent at any time without affecting what was done before.
Where we are the controller, write to privacy@leadtad.com and we will respond within 30 days. Where we are the processor — which covers all patient records — please contact the laboratory that holds your records. If a request reaches us instead, we will forward it to the laboratory and help them respond.
Changes to this policy
We may update this policy as the platform changes. The date at the top always reflects the current version. If a change materially affects how we handle personal information, we will tell account administrators by email at least 14 days before it takes effect.
Contact and complaints
Privacy questions and data subject requests: privacy@leadtad.com. Everything else: legal@leadtad.com. By post: Lead TAD.
If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng.
Questions about this page? Write to legal@leadtad.com and we'll come back to you.