NohaLims
Features Pricing Contact
ES | EN

Home · Privacy Policy

Privacy Policy

Version: 2.0 · Last updated: September 2026 · Previous version: v1.0

v2.0 This version completely restructures the previous policy: adds Legitimate Interests section, table of specific retention periods, dedicated section on roles (Controller vs Processor), automated decisions and a link to the previous version. See changelog summary.

Contents

  1. Introduction
  2. Who we are and our roles
  3. What information we collect
  4. How we use your information
  5. Legitimate Interests
  6. Who we share your information with
  7. International transfers
  8. How long we keep your information
  9. How we protect your information
  10. Personal Data Breaches
  11. Your rights as a data subject
  12. Your choices
  13. Children's privacy
  14. Automated decision-making
  15. Changes to this policy
  16. Previous versions
  17. How to contact us
  18. Changelog v1 → v2

1. Introduction

NohaLims takes privacy seriously. This Privacy Policy explains how NohaLims handles personal information when:

  • You visit our website (nohalims.com).
  • You purchase or use our LIMS Service.
  • You interact with us by email, WhatsApp, form or any other channel.

Please take a few minutes to read this policy. If you do not agree with any practice described, please do not use our Service or send us personal information.

2. Who we are and our roles

2.1 Data Controller

When we collect information directly from you — for example when you visit our website, complete a form, contract our Service or contact us through any channel — NohaLims acts as Data Controller of that information, in accordance with Colombian Law 1581 of 2012 and its regulatory decrees.

2.2 Data Processor

When our Customers (laboratories) upload Personal Data of their own clients, patients, employees or third parties into NohaLims, NohaLims acts as Data Processor on behalf of the Customer. In that case, the Customer is the Controller and NohaLims processes the data only according to the Customer's instructions and the terms of the Data Processing Agreement (DPA).

2.3 Controller contact details

  • Legal name: [Operator's legal name, pending incorporation]
  • Tax ID: [Pending]
  • Address: Bogotá D.C., Colombia
  • Privacy email: privacy@nohalims.com

3. What information we collect

3.1 When you visit our website

  • Technical data: IP address, browser type, operating system, pages visited, access time.
  • Cookies (see section 12.2).

3.2 When you contact us or complete a form

  • Full name.
  • Email.
  • WhatsApp (with country code).
  • Laboratory name.
  • Approximate laboratory size.
  • Message or inquiry (optional).

3.3 When you contract our Service

  • Legal name, tax ID, billing address.
  • Billing email.
  • Legal representative details.
  • Payment data (processed by our payment sub-processor; we never see card data).

3.4 When you use the NohaLims Service (as Customer)

  • Username, email, password (encrypted), assigned role.
  • Laboratory logo (for CoA certificates).
  • Laboratory configuration.
  • Activity audit trail within the system (part of the product, cannot be disabled).
  • Data the Customer uploads of its own clients, patients or third parties — in these cases NohaLims acts as Processor, not Controller.

3.5 Data we do NOT collect

  • Credit card data: processing is delegated to Wompi (Bancolombia); NohaLims never sees or stores this data.
  • Patient health data: except when a clinical laboratory uploads patient samples, in which case NohaLims acts as Processor.
  • Biometric data: except TOTP for 2FA (temporary code generated by an app; we do not store biometrics).

4. How we use your information

We use your personal information for the following purposes, each with its specific legal basis:

PurposeLegal basis
Provide the contracted ServiceContract execution
Billing and collectionsContract execution + legal obligation
Technical support and customer serviceContract execution
Transactional communications (payments, maintenance, alerts)Contract execution
Compliance with legal and tax obligationsLegal obligation
System security and fraud preventionLegitimate interest
Product improvement via aggregated and anonymized analysisLegitimate interest
Marketing and commercial communicationsConsent
Response to authority requestsLegal obligation
Exercise of legal rights (defense in lawsuits)Legitimate interest

5. Legitimate Interests

For some processing we rely on our legitimate interest, as permitted by Colombian Law 1581/2012 and, when applicable, GDPR. In each case we have assessed that our legitimate interest is not overridden by your fundamental rights and freedoms.

We use the "legitimate interest" legal basis for:

  • System security: preventing unauthorized access, attacks, fraud and abuse of the Service. Our legitimate interest is maintaining the integrity and availability of the Service for all Customers.
  • Product improvement: analyzing aggregated and anonymized usage patterns to identify higher-value features and possible improvements. We never use identifiable data for this.
  • Legal defense: retaining information necessary to exercise or defend against potential legal claims. Our legitimate interest is protecting ourselves against litigation.
  • Default prevention: managing collections and, eventually, transferring debt to specialized third parties. Our legitimate interest is recovering legitimate credits.

If you wish to object to a processing based on legitimate interest, you can write to us at privacy@nohalims.com and we will evaluate your case.

6. Who we share your information with

We do not sell or rent your personal information. We only share it with:

6.1 Within NohaLims

Our authorized personnel, who have assumed confidentiality commitments and only access the data necessary for their function.

6.2 Sub-processors (service providers)

Third parties that process data on our behalf, all under data processing agreements with obligations equivalent to ours:

Sub-processorServiceData processed
Google Cloud PlatformApplication and DB hostingService data
CloudflareCDN and DDoS protectionAccess logs
ResendTransactional emailEmail and name
Wompi (Bancolombia)Payment processingBilling data (no card)

Complete and updated list in Annex III of the DPA.

6.3 Legal obligations

When a competent authority (SIC, DIAN, courts) requires it per law, or when necessary to protect our legal rights.

6.4 Business transfers

If NohaLims is acquired, merged or sells assets, Customer data may be transferred as part of the transaction. We will notify the Customer at least 30 days in advance.

6.5 With your consent

In any other case, we will only share data with third parties if you have given us your express consent.

7. International transfers

By default, Service data is stored and processed on Google Cloud Platform, southamerica-east1 region (São Paulo, Brazil). This location meets data residency requirements for LATAM clients and keeps data within a geographically close block.

For transactional email data, we may transfer email and name to Resend (United States). This provider operates under the Standard Contractual Clauses (SCCs) 2021/914 to guarantee an adequate level of protection.

If in the future we transfer data to other countries, we will notify you 30 days in advance and, if required by applicable law, request your consent.

8. How long we keep your information

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, unless the law or a legitimate interest justifies a longer period.

Data categoryRetention periodJustification
Leads and prospects (form, WhatsApp)Up to 2 years from last contactCommercial legitimate interest; while they may convert to Customer
Active Customer data (account, billing)During contractual relationship + 6 yearsTax (DIAN) and accounting obligations
Payment transaction data7 yearsLaw 1231 of 2008 + Tax Statute
Support portal access logs6 years from last loginLegitimate interest in security and legal defense
Data uploaded by Customer in Service (when we are Processor)Per Customer instructions; deleted upon termination + 60 daysContract execution + DPA
Marketing email (subscribers)Until you withdraw consentConsent
Internal audit data (compliance)5 yearsLegal defense and legitimate interest
Social media contact info (comments, messages)Per each platform's termsConsent by using the platform
Service automated backups30 days normal rotationOperational continuity

Once the retention period is fulfilled, data is securely deleted or irreversibly anonymized for statistical purposes.

9. How we protect your information

We implement technical and organizational measures aligned with industry best practices. Complete detail in Annex II (TOMs) of the DPA. Summary:

  • Encryption in transit (TLS 1.2+) and password hashing (bcrypt + salt).
  • Access control with JWT + 2FA TOTP available.
  • Immutable audit trail with PKI RSA-2048 digital signatures.
  • Physical single-tenant (1 Customer = 1 PostgreSQL database).
  • Daily automated backups with end-to-end validated restore.
  • Personnel with signed confidentiality commitments.
  • Least privilege access (36 granular permissions, 4 roles).

10. Personal Data Breaches

In case of an incident affecting the confidentiality, integrity or availability of Personal Data:

  • We will notify affected Customers without undue delay, within 72 hours of becoming aware, aligned with GDPR Art. 33.
  • We will notify the Supervisory Authority (SIC in Colombia) when required by law.
  • Notification to the final data subject (e.g., patients, Customer clients) is the Customer's responsibility (as Controller), not NohaLims'.
  • If you are our Customer and experienced an incident involving us, contact us at security@nohalims.com.

11. Your rights as a data subject

Pursuant to Article 8 of Colombian Law 1581/2012 and GDPR (when applicable), you have the following rights:

RightWhat it meansHow to exercise it
Know Know what data we hold about you and what we use it for. Email to privacy@nohalims.com
Update and rectify Correct inaccurate or incomplete data. Email or from your account
Erase (right to be forgotten) Request deletion of your data when no longer necessary. Email, unless we have legal obligation to retain
Restrict processing Request temporary suspension of processing in certain circumstances (e.g., while accuracy is verified). Email
Portability Receive your data in structured, commonly used format, or request transfer to another operator. Email (PostgreSQL dump + CSV)
Object Refuse a specific processing, including marketing or automated decisions. Email or "unsubscribe" link in each communication
Withdraw consent Withdraw your authorization when processing is based on it (e.g., marketing). Email or link in each email
Lodge a complaint with the authority If you believe we did not address your rights, you can complain to the SIC. www.sic.gov.co

Response time: we respond to your request within a maximum of 15 business days from receipt. If we need more time, we will notify you with the corresponding justification.

12. Your choices

12.1 Marketing communications

You can opt out of our commercial communications at any time:

  • Click "unsubscribe" at the bottom of any email.
  • Reply "STOP" to WhatsApp messages.
  • Write to privacy@nohalims.com.

12.2 Cookies and similar technologies

We use cookies for the following purposes:

TypePurposeRequired?
SessionKeep your session logged inYes
PreferencesRemember language and visual themeNo (can be rejected)
AnalyticsUnderstand site usage (Hostinger built-in + optional Microsoft Clarity)No (can be rejected)

You can configure your browser to reject all cookies or notify you before accepting them. If you reject them, some features may not be available.

12.3 Account closure

You can close your NohaLims account at any time:

  1. Request closure in writing to soporte@nohalims.com.
  2. We will send you a copy of your data in standard format within 30 days.
  3. After 60 days from closure, we delete the data from our servers and backups.
  4. You will receive a signed deletion certificate.

13. Children's privacy

NohaLims is a B2B service for laboratories and companies. We do not intentionally collect data from minors under 18. If a Customer uploads data of minors into the system (e.g., a clinical laboratory analyzing pediatric samples), it is the Customer's responsibility to obtain parental authorizations per applicable law and Colombian Law 1581/2012.

14. Automated decision-making

NohaLims does not make automated decisions that produce legal or similarly significant effects on data subjects (as defined by GDPR Art. 22).

The Service may perform automated calculations (e.g., mean, standard deviation, CV, specification compliance) as part of its operational functionality, but those calculations are technical, do not produce legal effects on natural persons, and are always reviewed and digitally signed by laboratory personnel before generating a certificate.

If in the future we incorporate features with significant automated decisions, we will update this policy and request consent when required.

15. Changes to this policy

We may modify this policy to reflect legal, technical or operational changes. We will notify you by email of any material change at least 30 days in advance of its effective date.

The date of the last update is always visible at the top of this document. Previous versions remain archived and accessible (see next section).

16. Previous versions

Previous versions of this policy remain archived and may be consulted:

  • v1.0 — September 2026 (initial version, archived after migration to v2.0).

When we publish future versions, the previous ones will remain available with their effective date clearly indicated.

17. How to contact us

For any privacy inquiry, write to us:

  • Main privacy email: privacy@nohalims.com
  • Security incidents email: security@nohalims.com
  • Legal email: legal@nohalims.com
  • General support email: soporte@nohalims.com
  • WhatsApp: +57 321 726 5727
  • Postal address: Bogotá D.C., Colombia

Supervisory authority (Colombia)

If you believe we did not adequately address your rights, you may file a complaint with Colombia's Superintendencia de Industria y Comercio (SIC):

  • Web: www.sic.gov.co
  • Address: Carrera 13 No. 27-00, Bogotá D.C.
  • Phone: +57 601 587 0000

Changelog v1 → v2

Main changes incorporated in this version 2.0 relative to v1.0:

Aspectv1 (previous)v2 (current)
Structure13 named sections17 numbered sections
Roles Controller vs ProcessorMentioned but confusingOwn §2 with clear explanation
Legitimate InterestsAbsentOwn §5 with list of uses
Retention periodsGenericTable with 9 categories and specific periods
Automated decisionsBriefly mentionedOwn §14 with explanation
Previous versionsNot mentioned§16 with version archive
Your choicesMarketing onlyMarketing + cookies + account closure
Your rightsGeneric tableExpanded table with right to restriction and portability
Breach timeline"Notification to customer"72h aligned with GDPR Art. 33
How to contact us3 emails5 emails + WhatsApp + address + SIC
LanguageES + ENES + EN (maintained)

This policy is governed by Colombian Law 1581 of 2012 and Decree 1377 of 2013. For information on how we process data when acting as Data Processor on behalf of our Customers, see our DPA.

← Back to home · Terms and Conditions · DPA