This Privacy Policy describes how TestLedger LLC collects, uses, stores, discloses, and protects information in connection with the TestLedger™ Documentation Platform, TestLedger website, Record Check Portal, Identity Hash Comparison Tool, and related services.
Customer responsibility. TestLedger is a customer-controlled documentation platform provider. The customer is responsible for determining whether its data is PHI, ePHI, a medical record, laboratory record, quality record, regulated record, or otherwise subject to legal retention or privacy requirements. TestLedger does not determine the customer legal status, PHI classification, record-retention obligations, or whether the customer use of TestLedger is legally permissible.
1. Information We Collect
We may collect account information, contact information, organization information, subscription and billing information, support communications, device and usage data, security logs, audit logs, and platform metadata.
When enabled by a customer, the Services may process customer-entered workplace testing documentation, donor or employee identifiers, authorization and consent details, collection reference fields, result fields, customer-provided supporting files, photos, videos, notes, supporting-file metadata, hashes, timestamps, and export-comparison artifacts.
2. Sensitive Information, PHI, and Employment Records
Some customer-submitted information may be sensitive or legally regulated. Production use involving PHI or ePHI, where applicable, requires an active paid subscription, an active Business Associate Agreement, active organization membership, and backend account enablement before upload or processing. Trial accounts are for evaluation with fictitious, synthetic, or non-PHI data only and must not be used for PHI, ePHI, real employees, applicants, donors, customers, disputes, audits, employment decisions, production recordkeeping, lab reports, identity documents, photos, videos, or other sensitive personal data.
Customers must not submit Social Security Numbers, taxpayer identification numbers, driver's license numbers, passport numbers, financial account numbers, payment-card numbers, biometric identifiers, biometric templates, genetic information, account passwords, authentication secrets, or other prohibited identifiers unless expressly permitted under the applicable agreement and enabled configuration.
TestLedger does not determine whether customer data is PHI, ePHI, an employment record, consumer-report information, biometric information, or subject to any privacy, labor, employment, health-information, background-screening, cannabis, THC, drug-testing, alcohol-testing, DOT, or workplace-testing law.
3. How We Use Information
We use information to provide, secure, maintain, troubleshoot, improve, and support the Services; manage accounts and subscriptions; operate record-completion and export-comparison workflows; maintain audit and security logs; respond to customer requests; enforce applicable terms; comply with legal obligations; and protect the platform from misuse.
4. Customer Data and Supported Protection Architecture
Where configured, portions of customer data may be encrypted or protected by customer-controlled credentials. TestLedger does not store customer-controlled identity protection keys in the ordinary course of operations. TestLedger may still access encrypted customer data, metadata, audit logs, system records, support information, and customer-authorized access pathways as necessary to provide, secure, maintain, support, or comply with legal obligations relating to the Services.
5. Sharing and Disclosure
We may disclose information to service providers, subprocessors, payment processors, hosting providers, security providers, professional advisors, and other parties as needed to provide and protect the Services. We may disclose information when required by law, subpoena, court order, legal process, regulatory inquiry, security investigation, or to protect rights, safety, security, and platform integrity.
We do not sell customer-submitted workplace testing records. We do not provide laboratory testing, MRO review, background-screening reports, consumer reports, employment eligibility recommendations, legal advice, or employment-decision recommendations.
6. Business Associate Agreement
Where a customer uses the Services for PHI-related functionality and an applicable BAA is executed and active, PHI-related obligations are governed by that BAA. An eligible active paid customer may select its contracting role in the authenticated application and electronically execute the posted Standard Business Associate Agreement as a HIPAA Covered Entity or the posted Standard Subcontractor Business Associate Agreement as a Business Associate authorized to engage TestLedger downstream. Customers using TestLedger only for non-PHI information do not execute a BAA and PHI-capable fields remain blocked. Customers requesting different language, customer paper, riders, additional terms, or support for Part 2 records require separate review. PHI/ePHI workflows remain unavailable unless the customer has an active paid subscription, active organization membership, an active agreement appropriate to its contracting role, and the relevant server-side PHI entitlement. If this Privacy Policy conflicts with the applicable BAA regarding PHI, ePHI, security incidents, breach notification, access, return or destruction, deletion, backup remnants, infeasibility, or post-termination PHI obligations, the BAA controls.
7. Photos, Videos, and Supporting Files
Customers may upload photos, videos, laboratory reports, consent forms, collection references, and other customer-provided supporting materials only where the customer has determined that collection, upload, retention, disclosure, and use are lawful. TestLedger does not perform facial recognition, biometric template creation, biometric identification, or identity matching unless expressly agreed in a separate written order.
8. Drug, Alcohol, Cannabis, and THC-Related Records
Drug, alcohol, cannabis, THC, controlled-substance, prescription-medication, workplace-testing, privacy, accommodation, and employment-use requirements may vary by jurisdiction and may change over time. TestLedger records customer-entered information only and does not determine whether any test is permitted, whether a test method is lawful, whether a result indicates current impairment, whether cannabis or prescription-medication use is protected, whether accommodation review is required, whether a role is safety-sensitive, whether notice or consent was sufficient, or whether any disclosure, retention practice, or employment action is lawful or appropriate.
9. Cookies, Analytics, and Similar Technologies
The website and Services may use cookies, local storage, browser storage, log files, and similar technologies for session management, security, preferences, analytics, troubleshooting, and platform operation. Customers should configure their browsers and organization policies as appropriate for their environment.
10. Retention and Deletion
We retain information for as long as needed to provide the Services, comply with legal obligations, maintain security, enforce agreements, support audit and operational records, and satisfy applicable retention or deletion settings. After subscription access ends, customer content is ordinarily available in export-only mode for 30 days. Production customer content is then targeted for deletion or de-identification by approximately day 60, and routine backup remnants are targeted to become unrecoverable by approximately day 95, subject to applicable law, legal hold, security incident preservation, disaster recovery, or documented technical infeasibility. If a BAA applies, retained PHI remains protected, may be used or disclosed only for the purpose justifying retention, and must be returned or destroyed when that reason ends. A payment dispute alone does not authorize denial of legally required PHI access or retention of PHI contrary to the BAA. Compliance documentation, including BAA execution evidence, may be retained for at least six years without authorizing broader retention of customer PHI.
11. Security
We maintain a risk-based information security program using administrative, physical, and technical safeguards designed to protect account data. For ePHI handled under an active BAA, TestLedger is obligated to comply with the HIPAA Security Rule provisions applicable to a business associate. Safeguards for enabled PHI workflows include access and authentication controls, security-relevant audit controls, incident-response procedures, workforce and subcontractor controls, and encryption controls for ePHI in transit and at rest consistent with risk analysis and applicable requirements. Implementations may vary by service and documented risk, but that variation does not reduce obligations stated in an applicable BAA or law. No system is perfectly secure, and cryptographic hashes do not by themselves establish HIPAA compliance or the accuracy of underlying content.
11A. Security Incidents and Breach Notices
For customers operating under an active BAA, reportable uses or disclosures, Security Incidents affecting PHI, and Breaches of Unsecured PHI are handled under the applicable agreement. The posted standard agreements require notice without unreasonable delay and no later than 30 calendar days after discovery for a Use or Disclosure not provided for by the agreement, and no later than 10 business days after discovery for a Breach of Unsecured PHI, with required information supplemented as it becomes available. This public summary does not replace the executed agreement. Do not send PHI through ordinary email when reporting a suspected incident; use the designated security or legal contact and an approved secure transmission method.
12. Record Check Portal
The Record Check Portal compares supported exported data to a recorded reference state. A match does not prove the underlying test occurred, donor identity, specimen handling, consent validity, laboratory accuracy, legal sufficiency, admissibility, confidentiality status, lawful access, regulatory compliance, or lawful employment use.
13. FCRA and Employment Use
TestLedger is not marketed or configured to furnish consumer reports, background-check reports, employment eligibility recommendations, or adverse-action notices. Customers are responsible for determining whether their use of drug-testing, background-screening, employment, or third-party information triggers FCRA, state background-check laws, adverse-action procedures, notice requirements, authorization requirements, dispute procedures, equal-employment obligations, or other legal requirements.
14. International and State Privacy Rights
Depending on location, role, and applicable law, individuals may have rights to request access, correction, deletion, portability, restriction, objection, or information about certain data practices. Many workplace records are controlled by the customer, not TestLedger. Requests relating to customer-controlled records should usually be directed to the customer organization first.
15. Children
The Services are intended for business and organizational use and are not directed to children. Customers are responsible for determining whether any minor-related workplace testing documentation is lawful and properly authorized.
16. Changes to This Privacy Policy
TestLedger may update this Privacy Policy from time to time. Material changes will be communicated through the Services, by email, or through a notice on the website. The effective date at the top of this Privacy Policy will reflect the most recent revision date.
Continued use of the Services after the effective date of any modifications constitutes acceptance of the updated Privacy Policy.
17. Contact Information
Questions, concerns, or requests regarding this Privacy Policy may be directed to:
TestLedger LLC
Attention: Privacy Officer
Email: privacy@testledger.io
Legal inquiries: legal@testledger.io
Do not send PHI or ePHI through ordinary support, email, contact forms, chat, or billing support. Use approved in-app workflows only after your account has an active paid subscription, active BAA, and backend account enablement.
For PHI-related inquiries from customers operating under a BAA, contact requirements may be specified in the applicable BAA or Order Form.