Privacy policy

Last updated 5 October 2026 · NAIQ

This policy explains how NAIQ ("we") processes personal data in Lung26. Hospitals using Lung26 are the data fiduciary (controller) for patient data; NAIQ acts as their data processor under the Digital Personal Data Protection Act, 2023, and, where applicable, the GDPR.

What we do not collect

CT images (DICOM pixel data) are read and analysed inside the user's browser and are never transmitted to Lung26 servers.

What we store

Where and how

Data is stored in Cloudflare D1 (encrypted at rest) and served over TLS. Each hospital's records are isolated by tenant on every query. Access within a hospital is controlled by role.

Retention and deletion

Records are retained for the period configured by the hospital (default seven years, in line with medical-record practice). Archived records are hidden from use but kept for audit. On termination the hospital owner can export all data, after which we delete it within 30 days on written request, except where law requires retention.

Rights

Patients should direct access, correction and erasure requests to their hospital, which can action them in Lung26 or ask us to. Hospital owners can export all data at any time from Settings.

Sub-processors

Cloudflare, Inc. (hosting, database, network). jsDelivr CDN serves the open-source analysis libraries to the browser; no patient data is sent to it.

Contact

Grievance officer: support@naiq.in

← Back to Lung26 · Contact: support@naiq.in