This page explains how Lenava handles personal information, sessions, tenant-aware data, and privacy-related requests across hosted and customer-managed deployments.
This Privacy Policy explains how Lenava Group Inc. accesses, collects, stores, uses, shares, retains, and protects personal information when you interact with Lenava LIMS, related customer portals, support channels, product websites, and other business communications connected to the service.
This notice is intended to work across Lenava-hosted environments, customer subdomains, and on-premise deployments. The exact categories of data processed may vary depending on the modules, integrations, deployment model, and customer instructions that apply to a specific tenant environment.
This Privacy Policy applies to Lenava Group Inc. and to the online services we provide, including Lenava LIMS, customer portals, user accounts, support communications, and product-related interactions provided by Lenava. It applies to public visitors, authenticated users, customer users, tenant administrators, and other persons whose personal information is processed in connection with those services.
The policy covers both hosted and customer-managed environments. In multi-tenant deployments, the relevant business tenant remains responsible for the lawfulness, accuracy, and instruction set of the data it stores or processes through the platform. Where Lenava acts as a service provider, processor, or technology platform, the tenant may remain responsible for additional customer-facing disclosures required in its jurisdiction or industry.
We may collect personal information depending on how you use the service and which product modules are enabled. This may include account details, user profile information, login credentials or authentication metadata, business and tenant profile data, support communications, billing or contractual contact information, IP addresses, browser and device metadata, audit logs, and cookie preference records.
Within Lenava LIMS, customer tenants may also store or process operational records such as sample information, workflow history, equipment records, document metadata, report delivery history, internal notes, assignments, or communication records. The exact content of those records is determined by the tenant’s business process and deployment model.
We may also collect data you provide when you contact us, request support, participate in a demo or onboarding process, respond to product communications, or exercise privacy rights.
We process personal information to provide, operate, administer, secure, and improve Lenava LIMS and related services. This includes authenticating users, maintaining tenant isolation, preserving session continuity, generating reports, responding to support requests, administering accounts, communicating with customers, maintaining audit trails, protecting against fraud or misuse, and complying with contractual and legal obligations.
We may also use information to troubleshoot incidents, monitor service reliability, improve workflows and product quality, manage changes, and maintain internal records relevant to security, compliance, billing, and support.
Depending on the jurisdiction and deployment model, we may process information because it is necessary to perform a contract, operate the requested service, comply with law, protect legitimate business and security interests, or act on instructions from the relevant tenant or customer organization. In some cases, we may also rely on consent, especially for non-essential cookies or similar optional technologies.
When we process information on behalf of a tenant, that tenant may act as the controller or primary decision-maker for certain categories of customer or laboratory data, while Lenava provides the technical means to host, manage, secure, or transmit that information.
We do not sell personal information. We may share information only where necessary to provide the service, support customers, operate infrastructure, enforce agreements, comply with law, or protect rights, security, and service integrity.
Depending on the deployment, this may include sharing with hosting providers, cloud or infrastructure providers, email or messaging providers, support or implementation partners, affiliated entities involved in service delivery, or other subprocessors and vendors acting under appropriate contractual or operational controls. We may also disclose information where required by valid legal process, regulatory obligations, fraud-prevention needs, or corporate restructuring events.
Lenava LIMS uses cookies and similar browser storage to maintain secure sessions, remember interface settings, store consent decisions, and improve usability. Essential cookies for login, session handling, CSRF protection, tenant isolation, and security remain active because the application cannot operate safely without them.
Non-essential categories, such as preferences or analytics, are controlled through the in-product consent experience. You can review the Cookie Policy for more information and reopen cookie preferences from the product where available.
Lenava LIMS may be deployed across subdomains, private networks, managed cloud environments, and on-premise customer infrastructure. As a result, personal information may be processed in different jurisdictions depending on customer hosting choices, infrastructure providers, support arrangements, and contractual terms.
Where cross-border data handling occurs, we seek to use appropriate technical, organizational, and contractual measures consistent with the applicable deployment and legal context.
We retain information for as long as needed to provide the service, preserve business and security records, maintain auditability, meet contractual commitments, resolve disputes, enforce rights, and comply with applicable law or regulation. Retention periods can differ by data category, deployment type, feature set, customer agreement, and legal environment.
When retention is no longer required, information may be deleted, anonymized, archived, or otherwise handled in accordance with the relevant customer arrangement, technical capability, and legal obligations.
Lenava uses administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of the service and the information processed through it. These controls may include authentication mechanisms, session controls, access restrictions, audit logging, change management, and security monitoring.
However, no system, network, transmission method, or storage platform can be guaranteed to be completely secure. You should also use appropriate security practices within your organization, including credential management, access review, device security, and tenant-level permission control.
Lenava LIMS is a business and laboratory operations platform and is not intended for direct use by minors. We do not knowingly collect personal information directly from children for consumer-facing purposes through this product. If you believe information relating to a minor has been provided inappropriately, contact us so we can review the matter.
Depending on where you are located and the role Lenava or the relevant tenant plays in processing your data, you may have rights to request access, correction, deletion, restriction, objection, export, or other forms of review regarding your personal information. In some situations, these rights must be exercised through the business tenant or customer organization that controls the relevant records.
You may also have the ability to change optional cookie settings, withdraw consent for non-essential categories, or contact us regarding privacy-related questions. For cookie-specific choices, see the Cookie Policy. For general platform rules, see the Terms and Conditions.
Residents of certain US states may have specific privacy rights under applicable law, such as rights to know what categories of personal information are processed, request access or deletion, correct inaccurate information, appeal a denied request, or limit certain processing activities where the law provides that option.
If you submit a privacy request, we may need to verify your identity and the authority under which the request is made before taking action. Where the request relates to tenant-controlled operational data, we may direct you to the appropriate tenant or service administrator.
We may update this Privacy Policy from time to time to reflect legal, operational, technical, or product changes. When updates are made, the revised version will be published on this page and reflected by the updated version or effective date shown above. We encourage periodic review of this page.
If you have questions, concerns, or requests relating to this Privacy Policy, you may contact Lenava Group Inc. by email at privacy@lenava.ca.
Mailing address:
Lenava Group Inc.
481 Davisville Ave
Toronto, Ontario M4S 1J2
Canada