Privacy and data handling
LabTatva Privacy Notice
Effective 20 August 2026. This notice explains how LabTatva by CoreTatva handles information used for the public directory, accounts, laboratory claims, reviews, enquiries, RFQs, quotations, lead unlocks and payments.
Who is responsible and how to contact us
LabTatva by CoreTatva determines how information submitted to this service is used. For privacy questions, correction requests or complaints, email support@coretatva.com. Laboratory listing and claim questions may also be sent to labs@coretatva.com.
01
Information we handle
We handle account identity and security records; contact-form details; buyer RFQ contact and technical requirements; selected laboratory recipients; laboratory claims, memberships and profile submissions; saved listings; moderated reviews; quotations and lead-unlock decisions; and payment order, event, refund, fee and settlement references when payments are enabled. We also retain security, delivery and audit metadata.
02
Why we use it
We use information to provide and secure accounts, verify email and laboratory claims, route a buyer's RFQ only to laboratories the buyer selected, support quotations and contact unlocks, moderate reviews and claims, process and reconcile payments, prevent abuse, meet legal and accounting duties, and maintain an explainable audit history.
03
Who receives it
Selected laboratories receive the technical RFQ and initially masked buyer contact. Full buyer contact is released only through the recorded unlock workflow. Approved infrastructure, email, identity, security and payment providers process the minimum information needed for their service. Public laboratory pages expose only approved public fields; private notification addresses are never returned by public directory APIs.
04
Public and official-source data
Official-source facts, platform-normalized interpretations, laboratory-claimed information and platform-verified operating information are kept structurally separate. Laboratory users cannot directly alter official-source facts. Published reviews do not establish accreditation eligibility.
05
Security
LabTatva uses restricted database roles, encryption for buyer contact records, server-side session controls, CSRF protection, rate limits, signed payment callbacks and append-only audit controls where applicable. No internet service can promise absolute security; report a suspected incident to support@coretatva.com.
06
Your choices and requests
You may ask to access, correct or update information linked to you, object to an inaccurate public claim, or raise a privacy complaint. Requests are verified before action. Some records cannot be erased where transaction, evidence, security, accounting or legal obligations require retention; they may instead be corrected, cancelled, withdrawn, archived or access-restricted.
India data residency
Production application, accreditation, profile, RFQ, quotation and audit data is required to remain in India on E2E Networks or another explicitly approved Indian service. A web delivery layer may use an approved India-region hosting or CDN provider, but it must not become the system of record for transactional data. Payment providers and banks process payment information under their own notices and regulated infrastructure; provider approval must include a documented residency and subprocessors review before activation.
Retention and immutable records
We retain information only while needed for the purposes above and for security, dispute, accounting, legal and audit obligations. Submitted RFQs and quotations are cancelled, withdrawn, archived or superseded rather than hard-deleted. Published evidence, capability publication records and audit records are not application-deletable. Payment and settlement history, when enabled, is retained as an auditable ledger. Temporary challenges and operational logs are retained for operational and security purposes under the applicable deployment settings.
Payments and UPI
When payments are enabled, checkout is provided by the named payment provider and settlement is made to the approved business current account. LabTatva does not ask for or store a UPI PIN, card CVV or online-banking password. Do not treat a screenshot or client-side success message as proof of payment; only a server-verified provider event updates the LabTatva ledger.
Updates
We may update this notice when workflows, providers or law change. Material updates will be published here with a revised effective date. See also the Terms & Conditions.