Back to Dashboard

Master Terms of Service

Enterprise Software & Master Services Agreement (MSA)

HIPAA / HITECH
GDPR / UK GDPR
India DPDP Act 2023
256-Bit TLS & AES

Effective Date: January 1, 2026 | Last Updated: | Version: 2.4.0 Enterprise

Notice for Enterprise Healthcare Tenants: This Master Terms of Service Agreement governs access to and usage of the MyPathoLabs Diagnostic Laboratory Information System (LIS). If you are using the platform on behalf of a Covered Entity, Business Associate, or Healthcare Provider, your usage is subject to the executing Business Associate Agreement (BAA) and Data Processing Addendum (DPA) as incorporated herein.

Welcome to MyPathoLabs. These Enterprise Terms of Service ("Terms", "Agreement") constitute a legally binding agreement executed between MyPathoLabs Inc. / MyPathoLabs Technologies Private Limited ("MyPathoLabs", "Company", "We", "Us", or "Our") and the subscribing diagnostic laboratory, healthcare organization, clinic, hospital, or enterprise client ("Subscriber", "Customer", "You", or "User").

1. Acceptance of Terms & Legal Authority

By registering for an account, accessing, deploying, or utilizing the MyPathoLabs software platform, APIs, databases, microservices, or mobile interfaces (collectively, the "Platform"), you explicitly acknowledge that you have read, understood, and agreed to be bound by these Terms and our Privacy Policy.

If you are entering into this Agreement on behalf of a legal entity (such as a diagnostic laboratory network, hospital chain, or corporate healthcare provider), you represent and warrant that you possess the full legal authority to bind such entity to these Terms.

2. Description of Platform & Clinical Disclaimer

2.1 Scope of Service

MyPathoLabs provides a multi-tenant, enterprise-grade cloud Laboratory Information System (LIS) designed to automate diagnostic lab operations, patient record management, sample tracking, test order workflows, billing, integration with diagnostic machinery, and report generation.

2.2 Medical & Clinical Disclaimer

MYPATHOLABS IS A WORKFLOW MANAGEMENT AND DATA MANAGEMENT SOFTWARE TOOL ONLY. IT DOES NOT PROVIDE MEDICAL ADVICE, DIAGNOSTIC INTERPRETATIONS, OR CLINICAL DECISIONS.

  • All diagnostic reports, lab results, Reference Ranges, critical values, and medical test interpretations generated or stored on the Platform must be reviewed, verified, and signed off by a qualified, licensed Pathologist, Medical Practitioner, or Laboratory Director in accordance with local healthcare laws.
  • Subscribers retain full clinical responsibility for patient diagnosis, treatment plans, and medical care outcomes.

3. Global Regulatory Compliance Standards

MyPathoLabs is engineered to satisfy stringent global regulatory frameworks governing healthcare data privacy, security, and medical software compliance.

3.1 United States: HIPAA & HITECH Compliance

For Subscribers subject to the U.S. Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"):

  • MyPathoLabs acts as a Business Associate to Covered Entities.
  • Subscribers processing Protected Health Information (PHI) must request and execute our standard Business Associate Agreement (BAA) prior to transmitting PHI through the Platform.
  • MyPathoLabs maintains administrative, physical, and technical safeguards complying with 45 CFR Part 160 and Part 164 (Subparts A and C).

3.2 European Union & United Kingdom: GDPR / UK GDPR

For data subjects residing in the European Economic Area (EEA) or United Kingdom under the General Data Protection Regulation ("GDPR"):

  • The Subscriber acts as the Data Controller, and MyPathoLabs acts as the Data Processor.
  • Data transfers outside the EEA/UK are governed by standard EU Model Clauses (Standard Contractual Clauses / SCCs) and UK International Data Transfer Addendums (IDTA).

3.3 India: Digital Personal Data Protection (DPDP) Act 2023 & IT Act

For operations located in or serving data subjects in India:

  • The Subscriber acts as the Data Fiduciary, and MyPathoLabs acts as the Data Processor under Section 6 of the DPDP Act 2023.
  • Platform architecture complies with the Information Technology Act, 2000, IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, and guidelines of the National Medical Commission (NMC) and DISHA (Digital Information Security in Healthcare Act).

3.4 Other Worldwide Jurisdictions

The Platform provides compliance-ready infrastructure supporting California CCPA/CPRA (US), PIPEDA (Canada), LGPD (Brazil), and Privacy Act (Australia).

4. Account Management, RBAC & Security Obligations

  • Role-Based Access Control (RBAC): Subscribers are responsible for establishing granular access permissions for staff, lab technicians, phlebotomists, and administrative personnel.
  • Credential Protection & Multi-Factor Authentication (MFA): Subscribers must enforce strong passwords and MFA across all user accounts. Sharing credentials or using generic shared logins is strictly prohibited.
  • Audit Logging: The Platform automatically maintains immutable audit logs tracking user authentication, record views, edits, report downloads, and administrative actions for security compliance.

5. Data Ownership & Intellectual Property

5.1 Subscriber Data Ownership

Subscriber retains exclusive ownership, title, and all intellectual property rights in and to all patient records, test results, lab metrics, and operational data ("Subscriber Data") uploaded or generated on the Platform.

5.2 Platform Proprietary Rights

MyPathoLabs retains all rights, title, and interest (including patents, copyrights, trade secrets, and trademarks) in the software architecture, algorithms, UI/UX designs, APIs, and underlying source code of the Platform. Subscriber receives a limited, non-exclusive, non-transferable, non-sublicensable license during the active subscription term.

6. Enterprise Service Level Agreement (SLA) & Uptime

  • Target Uptime SLA: MyPathoLabs guarantees a Monthly Uptime Percentage of 99.9% for core Platform infrastructure, excluding scheduled maintenance windows.
  • Scheduled Maintenance: Maintenance windows are scheduled during off-peak hours (between 01:00 AM and 04:00 AM UTC) with a minimum of 48 hours advance notification provided to administrators.
  • Data Redundancy & Backups: Automated encrypted backups (AES-256) are performed hourly, with geo-redundant storage across isolated availability zones.

7. Acceptable Use Policy & Prohibited Conduct

Subscribers and authorized users strictly agree NOT to:

  • Decompile, reverse engineer, disassemble, or attempt to derive source code from the Platform.
  • Exceed API rate limits, conduct automated unauthorized scraping, or attempt penetration testing without explicit prior written authorization.
  • Process or store unlawful, malicious, or deceptive payloads, including software viruses or ransomware.
  • Bypass or attempt to exploit access control mechanics, cryptographic tokens, or role scopes.

8. Subscription, Fees & Enterprise Invoicing

Platform access is billed on a monthly or annual subscription tier based on active laboratory count, monthly report volumes, and enterprise module add-ons. Fees are non-refundable once billed. Failure to settle invoices within thirty (30) days of the due date may result in temporary account suspension, subject to data preservation guarantees under Section 10.

9. Limitation of Liability & Mutual Indemnification

9.1 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL MYPATHOLABS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, DATA LOSS, OR BUSINESS INTERRUPTION, ARISING OUT OF OR IN CONNECTION WITH THE PLATFORM.

MyPathoLabs' total aggregate liability under this Agreement shall not exceed the total fees paid by Subscriber to MyPathoLabs during the twelve (12) calendar months preceding the incident giving rise to liability.

9.2 Mutual Indemnification

Subscriber agrees to defend, indemnify, and hold harmless MyPathoLabs against any third-party claims arising from Subscriber's clinical operations, medical misdiagnosis, or breach of applicable data protection laws. MyPathoLabs agrees to defend Subscriber against third-party claims alleging that the Platform infringes valid registered intellectual property rights.

10. Data Retention, Account Termination & Offboarding

  • Termination for Convenience: Subscriber may terminate their subscription by providing thirty (30) days written notice prior to the end of the current billing cycle.
  • Data Export Grace Period: Upon account termination, Subscriber will be granted a 30-day grace period to export all Subscriber Data in standard machine-readable formats (XLSX, with additional formats planned in future releases).
  • Data Erasure: Following the 30-day grace period, MyPathoLabs will perform secure deletion of Subscriber Data from active and backup storage in accordance with platform infrastructure data sanitization capabilities, unless statutory medical retention mandates apply.

11. Governing Law & Dispute Resolution

This Agreement shall be governed by and construed under the laws of the jurisdiction of incorporation of MyPathoLabs, without regard to conflict of law principles. Any dispute arising out of or relating to this Agreement shall be resolved through binding arbitration under the rules of the International Chamber of Commerce (ICC) or relevant national arbitration body, with proceedings conducted in English.

12. Contact & Compliance Officer Details

For questions regarding these Terms, enterprise contract execution, BAA requests, or legal notices, please reach out to our legal and compliance department:

MyPathoLabs Legal & Compliance Division

Legal & Compliance: legal@mypatholabs.com

Data Protection Officer: pranshuvramani@gmail.com

Corporate Headquarters: Enterprise Tech Park, Financial District, India / USA

© 2026 MyPathoLabs Technologies Inc. All rights reserved. Enterprise LIS System v2.4.0.