Privacy Policy
Last updated: 24 February 2026
Information We Collect
Damascus27 operates a comprehensive Laboratory Information Management System (LIMS) platform. We collect information you provide directly to us, such as when you:
- Create an account or use our multi-tenant LIMS platform
- Input laboratory data, sample information, and test results
- Configure laboratory workflows, user roles, and system settings
- Contact us for technical support, sales enquiries, or implementation guidance (including your name, email address, phone number, company name, and website)
- Submit information through the in-app support ticketing system, including descriptions of issues, screenshots, and any other data you choose to provide
- Subscribe to our newsletter or participate in platform feedback programmes
Automatically Collected Information
We also collect certain information automatically when you interact with our website and platform:
- IP Addresses: Your IP address is collected for security purposes, including rate limiting to prevent abuse of our contact form and platform services. Within the LIMS platform, IP addresses are recorded and retained in session records, in the security audit trail, and in report sign-off records, where they serve as an integrity and non-repudiation control evidencing who performed an action and from where. These records are retained for the audit-trail retention period set out under Data Retention below.
- Bot Protection Data: Our platform uses Cloudflare Turnstile for bot protection, which may automatically collect limited technical data such as browser type, device characteristics, and interaction patterns to distinguish legitimate users from automated traffic. This data is processed by Cloudflare, Inc. in accordance with their privacy policy.
Multi-Tenant Data Isolation
Our platform employs strict tenant isolation to ensure complete separation of laboratory data between different organisations. Each tenant's data is:
- Logically separated with database-level access controls
- Encrypted both in transit and at rest using industry-standard protocols
- Accessible only to authorised users within your organisation
- Subject to comprehensive tamper-proof audit trails
How We Use Your Information
We use the information we collect to provide and improve our LIMS platform services:
- Provide, maintain, and improve our LIMS platform and laboratory workflows
- Process laboratory data, generate reports, and maintain sample tracking
- Manage user accounts, roles, and access permissions
- Send technical notices, system updates, and security alerts
- Respond to support requests and provide implementation assistance
- Process support tickets to resolve technical issues and improve platform reliability
- Comply with laboratory regulations, ISO 17025, SANAS, and other compliance requirements
- Protect the security and integrity of our platform through rate limiting and bot protection
Third-Party Service Providers
We share personal information with the following third-party service providers who assist us in operating our platform and services:
- Zoho Corporation Pvt. Ltd. - We use Zoho CRM to manage sales enquiries submitted through our contact form. When you submit a contact form enquiry, your name, email address, phone number, company name, and website are transmitted to Zoho's servers, which may be located in India, the United States, or other jurisdictions. Zoho processes this data as a data processor on our behalf. For more information, see the Zoho Privacy Policy.
- Cloudflare, Inc. - Provides edge security, web application firewall, and bot protection (Turnstile). See the Cloudflare Privacy Policy.
Data Security & Compliance
We implement comprehensive security measures designed for enterprise laboratory environments. Our security controls are aligned to the AICPA SOC 2 Trust Service Criteria (self-attested). For full details, see our Security page.
- Tamper-proof audit trails for complete data integrity
- Advanced session management and security controls
- Role-based access control with granular permissions
- Regular security reviews and monitoring
- ISO 17025 and SANAS compliance support
- GDPR and POPIA (Protection of Personal Information Act) compliance
- Bot protection to prevent automated abuse of login and authentication pages
- Rate limiting on form submissions to prevent abuse
GDPR & POPIA Compliance
Damascus27 is committed to compliance with the General Data Protection Regulation (GDPR) and South Africa's Protection of Personal Information Act (POPIA). We ensure:
- Data minimisation - collecting only necessary information for laboratory operations
- Transparent privacy notices and clear consent mechanisms
- Data subject rights including access, rectification, erasure, and portability
- Regular privacy impact assessments for system enhancements
Breach Notification
Where we have reasonable grounds to believe that personal information under our control has been accessed or acquired by an unauthorised person, we will notify the affected client and, where required, the affected data subjects and the Information Regulator as soon as reasonably possible after becoming aware of the compromise and in any event without undue delay, as contemplated in section 22 of POPIA. Notification may only be delayed where a public body responsible for the prevention, detection, or investigation of offences, or the Information Regulator, determines that a delay is necessary.
Our notification will describe, to the extent then known, the nature of the incident, the categories of information affected, the likely consequences, the remedial steps taken, and the measures we recommend affected parties take to mitigate potential harm.
Lawful Bases for Processing (POPIA s11 / GDPR Art 6)
We process personal information on the following lawful bases:
- Consent: Contact form enquiries are processed on the basis of your explicit consent, provided via the consent checkbox on our contact form.
- Contractual Necessity: Platform and LIMS data is processed as necessary for the performance of our service agreement with your organisation. Support ticket data submitted through our in-app ticketing system is also processed on this basis as part of the service agreement.
- Legitimate Interest: Security measures such as rate limiting and bot protection are implemented on the basis of our legitimate interest in protecting our platform and users from abuse.
Data Retention
We retain laboratory data in accordance with regulatory requirements and industry best practices. Retention periods are determined by:
- Laboratory regulatory requirements (typically 5 to 10 years for analytical data)
- ISO 17025 and accreditation body requirements
- Legal obligations under South African and international law
- Customer-specific retention policies configured within the platform
- Business continuity and quality assurance needs
Platform-Generated Personal Information
In addition to laboratory data, the platform generates records containing personal information as a by-product of operation. These are retained as follows:
- Session and access logs (including IP address and device information): retained for 12 months, then deleted.
- Security audit trail and report sign-off records (including IP address as a non-repudiation control): retained for the record-retention period applicable to the associated laboratory records, aligned to SANAS and ISO 17025 expectations and typically 5 to 10 years. Audit trail entries are tamper-evident and cannot be edited or deleted during that period.
- Support tickets and associated correspondence: retained for 24 months from closure, then deleted or anonymised.
- Contact form enquiries held in our sales CRM: retained for 24 months from last contact, unless you request earlier deletion.
Following termination of a client's subscription, platform data remains available for export for 30 calendar days and is then permanently deleted, save where a longer retention period is required by law. Full details are set out in our Terms of Service.
Your Rights
Under GDPR and POPIA, you have the following rights regarding your personal information:
- Access to your personal information and data processing activities
- Correction of inaccurate or incomplete information
- Deletion of personal information (subject to regulatory retention requirements)
- Data portability for laboratory data export
- Objection to processing for specific purposes
- Restriction of processing in certain circumstances
- The right to lodge a complaint with the Information Regulator of South Africa
Please note that some rights may be limited by regulatory requirements for laboratory data retention and audit trail integrity.
International Data Transfers
Where personal information is transferred internationally (including to Zoho Corporation), we ensure appropriate safeguards including:
- Adequacy decisions and standard contractual clauses
- Data processing agreements with third-party service providers
- Encryption and secure transmission protocols
- Regular compliance monitoring and auditing
- Compliance with POPIA section 72 cross-border transfer requirements
Information Officer
In terms of section 55 of the Protection of Personal Information Act, 2013 (POPIA), the designated Information Officer of Damascus27 (Pty) Ltd is:
Information Officer: Jacques Pretorius, Chief Executive Officer, Damascus27 (Pty) Ltd
Email: information.officer@damascus27.co.za
Address: 18 Three Fountains Road, Cape Farms, Western Cape, South Africa
Damascus27 (Pty) Ltd's Information Officer is registered with the Information Regulator of South Africa in accordance with the requirements of POPIA. You may also contact the Information Regulator directly at inforegulator.org.za.
Cookies and Local Storage
We use a minimal amount of browser storage, limited to recording your consent preference and to essential bot protection on our contact form. We do not use analytics, performance, or advertising cookies. For full details of what is stored, why, and how to manage it, see our Cookie Policy.
Contact Us
For privacy-related enquiries, data subject requests, or compliance questions, please contact us at:
Information Officer: information.officer@damascus27.co.za
Data Protection Queries: office@damascus27.co.za
Address: 18 Three Fountains Road, Cape Farms, Western Cape, South Africa
