Privacy policy
What we collect, what our sales team can see, and what you can do about it. Written to be read, not to be survived.
Last updated 2026-08-07
The short version
AssetLab is free because it is built by the company that sells CrelioHealth, a paid laboratory information system. When you sign up we create a sales lead record with your name, your work email and your lab's name, and we score that lead based on what your lab does inside the product. Our sales team can see that record and that score.
That is the trade. Four things worth knowing before you decide:
- We only email you about CrelioHealth if you tick the box. It is unticked by default, it is separate from creating your account, and leaving it unticked changes nothing about the product you get.
- Our sales console does not show your equipment records. It shows what is derived from them — how many instruments you have, which kinds of action your lab took and when. Not your breakdown notes, QC results or certificates.
- There is no delete button for your workspace. Deletion is something we run for you, by hand, when you ask. Section 9 explains exactly what happens and how long it takes.
- One shared key opens our internal console, and that key can also issue a password-reset link for any account. Section 6 is honest about what that means.
1. Who we are
AssetLab is operated by Creliant Software Private Limited, registered at 8th Floor, Baner Biz Bay, Laxman Nagar, Baner, Pune, Maharashtra 411045 (CIN U72900PN2017PTC173749).
“We” means that company. “You” means you personally. “Your lab” means the workspace you belong to. This policy covers AssetLab only — CrelioHealth's paid products have their own.
Two kinds of data, two different sets of rules
Data we control.Your signup details, your lead record, your lab's activity score, and the record of which landing page you were shown. We decided to collect this and we decided what it is for: finding labs to sell a LIMS to. For this we are the Controller (UAE) / Data User (Malaysia) and you deal with us directly.
Data your lab controls. Your instrument register, maintenance and calibration records, breakdown tickets, QC runs, suppliers, spares and staff accounts. Your lab decides what goes in and how long to keep it; we host it.
2. Why it is free, and what sales can see
Creating a workspace creates a sales lead. That happens whether or not you tick the contact box — the difference is whether anyone writes to you.
What is in the lead record
Your name, your work email, your lab's name, and how you arrived — if your link carried utm_source, utm_medium, utm_campaign or ref tags we save them, and we save which of two versions of our home page you were shown. None of that is asked for on screen, so we are telling you here.
The record has empty columns for phone, city, lab size, accreditation status and current LIMS. The signup form does not ask for any of these, so they stay empty unless you tell us later inside the product.
How the score works
Fourteen kinds of action add points: signing up, adding instruments, importing a register, exporting the equipment register, setting up and completing maintenance, recording calibration or QC, logging breakdowns, tracking contracts, adding spares, inviting a colleague, and opening the QR label sheet. Each kind is capped so one busy afternoon cannot fake a hot lead. A score of 60 or more flags your lab as worth a call.
Two of these are worth calling out because they are not obvious:
- The QR label points are added when the label page loads, not when you print. Opening it to look counts.
- Saving CrelioHealth LIMS connection details in Settings is our strongest buying signal and is scored accordingly. If you are only testing an integration, it still reads as interest.
Alongside each action we store a short note — which asset number, how many rows you imported. When you invite a colleague, that note contains their name. If they never accept, they have an entry in our sales database and no account; write to us and we will remove it.
What the console can do
Our internal sales console is switched off entirely unless a console key is set on the server. When it is on, anyone holding that one shared key can sign in and see every lab's contact details, score and activity timeline, and export the contactable ones to a spreadsheet. Once a spreadsheet is on someone's laptop we cannot recall it.
The export contains only labs that ticked the contact box and have not since withdrawn. Withdrawing takes you out of every future export; it cannot reach one already downloaded.
3. What we hold about you personally
| What | When it is collected | Notes |
|---|---|---|
| Name and work email | You sign up, or an admin adds you | Shown to your colleagues on the Team screen. |
| Password | You set or reset it | Stored as a scrypt hash. We cannot read your password. |
| Phone number | Only if an admin types one in | No screen currently displays it back. It sits unused. |
| Last sign-in time | Every sign-in | Visible to your lab's admins. |
| Everything you enter in the product | As you work | Instruments, tickets, notes, QC — your lab's records. |
| Your name against your work | As you work | The audit trail records who changed what, and when. |
Sign-in and reset attempts
To stop password guessing we keep short-lived counters keyed by email address and by the network address the request appears to come from — for sign-ins and for reset requests, four counters in total. The address is whatever our server is told by the connection; we do not independently verify it, and where we cannot determine it we store the word unknown. A successful sign-in clears the counter for that email address; the address-based counters age out on their own.
4. Patient data — please do not
AssetLab is for instruments, not patients. Nothing in it is designed for patient data and no screen asks for any. But free-text boxes accept whatever is typed into them, and a breakdown note saying which sample was affected is an easy thing to write.
5. Cookies
We set three, all first-party. No analytics, no advertising, no third-party trackers.
| Cookie | What it does | How long |
|---|---|---|
| Session | Keeps you signed in. Strictly necessary. | Until you sign out or it expires |
| Console key | Signs in our own staff to the internal console. Strictly necessary, and never set on your browser unless you are our staff. | 12 hours |
| Landing version | Records which of two versions of our home page you were shown, so you see the same one if you come back, and so we can tell which works better. This one is measurement, not strictly necessary — we are not going to call it essential when it is not. It holds a single letter and nothing that identifies you. | 180 days |
We found no instrument in either the UAE or Malaysia requiring a cookie consent banner, and we have not put one up for a single letter that identifies nobody. If you would rather not have it, clearing cookies removes it and the site works normally.
6. Security, described accurately
Every table carrying your data has a lab ID, and every query filters on it. That filter is in our application code, not in the database. All labs share one database file; SQLite has no row-level security, so there is no second net underneath us. We test for it, but it depends on us writing every query correctly.
Also true, and worth your knowing:
- Passwords are stored as scrypt hashes. Reset links are stored hashed, expire in an hour, work once, and end every existing session when used.
- One shared key opens the internal console, and the same key can issue a password-reset link for any account in any lab. It exists so a locked-out sole admin can be helped, it requires a written note of how the caller's identity was confirmed, and that note is written into your lab's own audit trail so you can see it happened. It is still a key that opens your lab.
- We do not currently log who viewed or exported a lead in the console. If personal data were exposed there, we would not be able to reconstruct exactly who saw what.
- We hold no certification for any of this. We are not ISO 27001 certified and we have not had a third-party security audit.
7. How long we keep things
| What | How long |
|---|---|
| Your lab's records | Until your lab deletes them or asks us to delete the workspace. |
| Audit trail | For the life of the workspace. Nothing prunes it — it is the record that makes the equipment file trustworthy. |
| Lead record and activity | Until you ask us to erase it, which we do on request without argument. |
| Sign-in and reset counters | Days, not months. They age out automatically. |
| Database backups | 14 days, then overwritten. The most recent copy is always kept. |
8. Your rights
Two regimes apply to the markets we serve, and they are at different stages. Malaysia's Personal Data Protection Act 2010, as amended in 2024, is in force with prescribed deadlines and penalties. The UAE's Federal Decree-Law No. 45 of 2021 has been in force since 2 January 2022, but its Executive Regulations have still not been issued — so the federal breach-notification period, the data protection officer thresholds and the penalty schedule do not yet exist as prescribed numbers, and the transition period the law allows has not started running.
We are offering these rights now anyway, ahead of the requirement, because waiting would be a strange way to treat people. What we will not do is claim a legal obligation that has not commenced.
9. Contacting us
Privacy questions: privacy@creliohealth.com.
Grievance officer: Mukund Malani, privacy@creliohealth.com. If you are unhappy with how we handled something, this is the person to write to, and we will respond within 30 days.
10. Changes
If we change this materially we will update the date at the top and post a notice inside the product. We will also email your lab's admins where an email channel is configured — but the product does not send bulk email today, so the in-product notice is the channel to rely on.