Get 10% off on orders above ₹500 · Use code BIODNA10 at checkout
How BIO DNA LAB collects, uses and protects your personal and health data.
Last updated 01 Aug 2026
This policy applies to BIO DNA LAB (“we”, “us”), our website biodnalab.com, our mobile experiences and our home sample collection services. It is issued in line with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices) Rules, 2011.
Identity and contact data: name, date of birth, sex, phone number, email and collection address.
Health data: tests ordered, samples collected, laboratory results, reports and any prescription you upload. Health data is “sensitive personal data” and is handled with additional safeguards.
Transaction data: order history, invoices and payment status. Card and UPI details are processed by our payment partner and never stored on our systems.
Technical data: device, browser, IP address and usage analytics needed to keep the service secure and reliable.
To schedule and perform sample collection, transport samples to NABL accredited partner labs, generate and deliver reports, and issue invoices.
To contact you about your order, critical results, rescheduling and support requests.
To improve our services through aggregated, de-identified analytics. We do not sell personal data and we do not use health data for advertising.
Partner laboratories that perform your tests receive only the information needed to process the sample (a barcode, age, sex and clinical notes where relevant).
Doctors or family members you explicitly choose to share a report with.
Service providers under contract for payments, messaging (WhatsApp, SMS, email) and secure hosting, bound by confidentiality and data-processing terms.
Authorities where required by law, for example notifiable disease reporting under public-health regulations.
Reports and results are retained for a minimum of 5 years in line with laboratory record-keeping norms, and are available in your account for that period.
Account and transaction data are retained while your account is active and for 8 years thereafter to satisfy tax and audit obligations. You may request earlier deletion of data that we are not legally required to keep.
Under the DPDP Act you may access, correct and request erasure of your personal data, withdraw consent, nominate a person to exercise your rights, and raise a grievance.
Write to our Grievance Officer at [email protected] or No 47, Lakshmi Venkateshwara Road, Nanjappa Reddy Layout, 8th Block, Koramangala, Bengaluru (Urban) – 560095, Karnataka. We respond within 30 days.
Data is encrypted in transit (TLS 1.2+) and at rest. Access to health data is role-based and logged. Phlebotomists see only the details needed for the visit and lose access once the order is complete.
We use strictly necessary cookies for sign-in and cart, and privacy-respecting analytics cookies. You can disable analytics cookies in your browser without affecting core functionality.
We will notify you by email or in-app notice before material changes take effect. Continued use after the effective date constitutes acceptance.