GDPR Compliance
Last updated: June 1, 2026
Mithla Lab is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page explains our approach to data protection and the rights available to EU/EEA residents.
Our Role
When you use the Mithla Lab website or submit inquiries, we act as the Data Controller. When our platform processes patient data on behalf of our laboratory clients, we act as a Data Processor under their instructions.
Legal Basis for Processing
- Contract — processing necessary to fulfill our service agreement with you
- Legitimate Interests — operating and improving our services, security
- Consent — marketing emails and non-essential cookies (you can withdraw at any time)
- Legal Obligation — compliance with applicable laws
Data Transfers
We may transfer data outside the EEA. All such transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
Your Rights Under GDPR
To exercise any of these rights, email privacy@mithlalab.com. We respond within 30 days.
Technical & Organisational Measures
- AES-256 encryption at rest, TLS 1.3 in transit
- Data processing agreements with all sub-processors
- Privacy by design and by default in all product development
- Regular Data Protection Impact Assessments (DPIAs)
- Strict access controls and employee training
- 72-hour breach notification to supervisory authorities
- Data minimization — we only collect what we need
Data Processing Agreement (DPA)
If you use Mithla Lab as a data processor for your lab's patient data, a DPA is available. Contact us to execute one.
Request a DPAContact our Data Protection Officer
Email: dpo@mithlalab.com
Address: Dhaka, Bangladesh
You also have the right to lodge a complaint with your local data protection supervisory authority.