AssetLab
← AssetLab

Your data, export and deletion

What you can do yourself, what you have to ask us for, and how long each takes. No mechanism is described here that does not exist.

Last updated 2026-08-07

Getting a copy of everything

An admin can download the whole workspace as a single JSON file from Settings → Your data → Download everything. No request, no waiting. It contains every record your lab holds, with no row caps.

It is built from the same list of tables that a deletion sweeps, so what you can take away and what we would remove are the same set — an export that quietly covered less than the deletion is how a lab loses records it thought it had a copy of.

Three things are left out on purpose, and named in the file itself:

  • Password hashes
  • Live session tokens
  • Password-reset token hashes

Those are credentials rather than records. Putting them in a downloadable file would hand whoever ends up with the file a way into your accounts.

The per-module CSV exports under Reports are still there and any user can pull them. They are easier to open in a spreadsheet; the JSON bundle is the complete archive.

Correcting something

Most of it you can fix yourself — instrument details, your own name, your lab profile, and any record your role lets you edit. Corrections keep the previous value in the audit trail, because an equipment history that can be silently rewritten is not evidence of anything.

If the thing you need corrected should never have been recorded — a patient identifier typed into a breakdown note, say — editing it is not enough. The earlier text stays in the audit trail, and for most fields your colleagues can read it there. Write to us and we will remove it from the audit rows as well.

Erasing one person's details

Someone leaves and wants their personal details gone. There is a real tension here and we would rather set it out than pretend there is not.

Your equipment records are accreditation records. “Calibration performed by S. Kulkarni on 4 March” is the evidence that the work was done by a named, competent person — that is the point of it under ISO 15189. Erasing the name retroactively does not just remove personal data, it removes the traceability that made the record worth keeping.

What we do, on request:

WhatWhat happens
Contact details — email, phone, last sign-inErased.
The login itselfDeactivated so it cannot be used again.
Their name on work they didKept by default, because it is the traceability the record exists for. If your lab decides otherwise, we can replace it with a coded identifier your lab holds the key to — the record stays attributable, the name is no longer in our database. That is your lab's call to make, not ours.
Their name in our sales recordsErased on request, always, no argument.

If you were invited to a lab and never accepted, you have no account here — but your name may sit in our sales activity log, recorded when the invitation was sent. Write to us and we will remove it.

External people named in records — a calibration engineer, a supplier contact — can ask us directly. They never signed up and have no other route.

Deleting the whole workspace

Ask us and we will delete it. There is no self-service delete button; this is something we run for you.

Before you ask

Export first. We will ask whether you have, and we will wait until you say yes. Your equipment records may be records your laboratory is required to retain for accreditation — if you delete them here and hold no copy elsewhere, you may have destroyed evidence you needed. We would rather be the awkward supplier who asked twice.

What happens

The deletion runs as a single transaction. It works out its own scope from the live database rather than a hand-written list of tables, and it refuses to run at all if any table cannot be accounted for — a partial deletion reported as a complete one is the failure that matters here. It removes the lab, its users, instruments, all history, sessions, reset tokens, the sign-in telemetry keyed to your email addresses, and the sales lead record with it.

Two limits, stated plainly:

  • Backups. Your data is gone from the live system immediately, and stays in database backups for up to 14 days before those are overwritten. We do not edit backups — doing so would make them useless for the one job they have. If a backup is ever restored, we re-run the deletion.
  • It cannot be undone. Once it has run there is no restore for you. That is why the export step is not a formality.

Stopping sales contact

We only write to you about CrelioHealth if you ticked the box at signup. To withdraw, go to Settings → Your data and turn it off, or email us. It takes effect immediately and removes you from every future sales export.

What it cannot do is reach a spreadsheet already downloaded. Our sales exports only ever include labs that opted in and have not withdrawn — but once a file is on someone's laptop, no later switch reaches it. That is true of every company that exports a CRM, and it is worth saying rather than implying otherwise.

Withdrawing does not delete your lead record. If you want that erased too, ask — we will do it, and you can carry on using AssetLab exactly as before.

How to ask

Email privacy@creliohealth.comfrom the address on your AssetLab account, telling us which lab and what you want. If you cannot use that address, say so and we will find another way to confirm who you are — we will not act on a request to delete or export a lab's data without being reasonably sure it came from that lab.

RequestWhat to expect
Copy of your dataDo it yourself, instantly, in Settings.
CorrectionMostly yourself. Audit-trail removal: within 7 days.
Erase personal detailsWithin 30 days, usually much sooner.
Delete a workspaceWithin 7 days of you confirming you have exported.
Stop sales contactImmediately in Settings, or within 2 working days by email.

If we get it wrong

Write to our grievance officer: Mukund Malani, privacy@creliohealth.com. We will respond within 30 days.

India's Digital Personal Data Protection Act, 2023 is being brought into force in phases. The sections creating individual rights — access, correction, erasure, grievance redressal and nomination — are not yet in force; current expectation is 2027. What binds us today is the Information Technology Act, 2000 and the 2011 rules made under it. When those sections do commence you will also be able to complain to the Data Protection Board of India.

Privacy policy · Terms