Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
This Policy states the conduct required of every person who uses the Pensieve platform. It protects patients whose records the Platform holds, the Customer's own operations, other customers sharing the same infrastructure, and the Platform itself.
This document is the source of truth for: marketing:/legal/acceptable-use, trust:/legal/acceptable-use, trust:/documents/ADD-GL-004, app:/legal/acceptable-use
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
ADD-GL-004 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
| Deployment model | Applies | Note |
|---|---|---|
DM-1 Dedicated |
Yes | Enforcement under 14 is available in full. |
DM-2 Shared |
Yes | The obligations at 6 and 7 matter most here, because a shared platform is where one tenant's conduct can affect another. |
DM-3 Customer Cloud |
Yes | Pensieve's technical ability to detect a breach of this Policy is limited to the telemetry the Customer's environment exposes. See 14.6. |
DM-4 On-Premise |
Yes | Same limitation as DM-3, and more so. Enforcement is contractual rather than technical. |
This Policy states the conduct required of every person who uses the Pensieve platform. It
protects patients whose records the Platform holds, the Customer's own operations, other customers sharing
the same infrastructure, and the Platform itself.
It is a short list of testable rules. Each numbered statement is written so that a reader can design a check for it.
Who it binds. The Customer, every Authorised User, and every contractor, consultant, locum, visiting practitioner, auditor or other person to whom the Customer gives access.
How it binds. This Policy is incorporated into the Platform Terms of Service (POL-GL-050) clause 2.3
and into the Master Services Agreement (MSA-IN-001) clause 8.5.8. A breach of this Policy is a breach of
that agreement.
What it is not. This Policy governs conduct. The purposes for which the Platform must not be used
(including the clinical-safety boundary) are in the Use Case Restrictions (ADD-GL-005). Read both.
1.1 Use the Platform only for the Customer's own healthcare operations.
1.2 Open a patient's record only when your role gives you a reason to. The Platform records who viewed which record.
1.3 Do nothing that degrades the Platform's availability, integrity or security for anyone else.
1.4 Where a rule below and a patient's immediate safety conflict, act for the patient and tell someone afterwards. This Policy is never a reason to delay urgent care.
2.1 Each person uses a credential issued in their own name. Credentials must not be shared, delegated, borrowed or used by anyone other than the person to whom they were issued.
2.2 A generic, shared, departmental or ward-level login must not be created or used for clinical record access. Where a shared device is used, each user authenticates individually on it.
2.3 Multi-factor authentication is enabled and used on every administrative and privileged account.
2.4 A credential is revoked within one (1) Business Day of the holder ceasing to be entitled to it, including on resignation, transfer, end of locum engagement, end of a contractor's engagement or suspension from duty.
2.5 A suspected compromise of a credential is reported to the Customer's own security contact and to
info@pensievelabs.org without delay, and the credential is disabled immediately.
2.6 Authentication must not be circumvented, and a session must not be left unattended on an unlocked device.
3.1 Access a record only where your role and the care, administrative, billing or statutory task in front of you requires it. Curiosity, personal interest, a colleague's request without a clinical reason, and a family member's record are not reasons.
3.2 Use the least privilege necessary. A privileged role is used for privileged work and not as a convenience.
3.3 Do not attempt to access, extract or view data belonging to another customer's tenant, another department you are not entitled to, or any record above your assigned permissions.
3.4 Do not disable, bypass, alter or attempt to defeat an audit log, an access control or a masking rule.
3.5 Do not alter a record to conceal an act or omission. Corrections are made through the Platform's correction mechanism, which preserves the original entry and the reason.
3.6 The Customer reviews its own access rights at least quarterly and records the review. Pensieve supplies the access report needed to do it.
4.1 Export data only for a purpose the Customer has authorised, and only to a destination the Customer has approved.
4.2 Do not copy patient data to a personal device, a personal email account, a personal cloud storage account, a messaging application or removable media, except where the Customer's own written policy expressly permits it and the copy is encrypted.
4.3 Do not photograph a screen containing patient data, and do not share a screenshot of one outside the Customer's approved channels.
4.4 Do not paste patient data into a support ticket, a public forum, a chat channel outside the
Customer's control, or any third-party service, including a general-purpose artificial-intelligence
assistant. Pensieve does not want to receive patient data in a support ticket; see POL-GL-053
clause 3.2.
4.5 Print only what is needed, collect it from the printer immediately, and dispose of it under the Customer's confidential-waste procedure.
4.6 A disclosure of a patient's record to a third party is made only on the authority the law and the Customer's own release procedure require, and is logged.
5.1 Enter information into the correct patient, encounter, ledger and location context. A record filed against the wrong patient is a patient-safety event, not a data-entry error.
5.2 Do not create a duplicate patient record where an existing record can be found. Use the Platform's search and merge functions.
5.3 Do not enter test, dummy, placeholder or training data into a production environment, and do not
enter production patient data into a non-production environment. See POL-GL-050 clause 5.3.
5.4 Record entries contemporaneously, and record the time an event occurred where it differs from the time of entry.
6.1 Do not introduce malicious code, or upload a file you have reason to believe contains it.
6.2 Do not attempt to gain unauthorised access to the Platform, its infrastructure, its administrative interfaces, another tenant, or any account.
6.3 Do not probe, scan, penetration-test, fuzz or stress-test the Platform without Pensieve's prior
written consent. Consent is given on reasonable conditions for the Customer's own tenant; see
DPA-GL-001 clause 15.6.
6.4 Do not reverse engineer, decompile or disassemble the Platform, or attempt to derive its source code, except to the extent Applicable Law permits notwithstanding the restriction and after notice to Pensieve.
6.5 Do not circumvent, disable or interfere with a security control, a rate limit, a quota, a licence control or a monitoring function.
6.6 Do not modify the Platform's code, its container images, its database schema or its infrastructure configuration directly, outside the interfaces Pensieve provides for the purpose.
6.7 Report a suspected vulnerability under the Vulnerability Disclosure Policy (POL-GL-059) rather
than exploiting it. Pensieve does not pursue a good-faith reporter.
7.1 Do not consume resources at a level that degrades the Platform for other users or, on a shared
deployment, for another tenant. The applicable limits are in the Fair Use & Rate Limiting Policy
(POL-GL-057).
7.2 Use the published application programming interfaces for integration, with credentials issued for that purpose, within the published rate limits.
7.3 Do not drive the user interface with an automation tool to evade a rate limit, and do not scrape
the interface for bulk extraction. A bulk export is available at no charge under WPR-GL-400 and does
not need to be improvised.
7.4 Do not use the Platform for cryptocurrency mining, distributed computing unrelated to the Customer's operations, file distribution, or as a general-purpose file store, mail server or content delivery network.
7.5 Do not run a load test against a production environment without Pensieve's prior written agreement on timing and scope.
8.1 Do not upload or store content that is unlawful, that infringes a third party's intellectual property, that is obscene, or that the Customer has no right to hold.
8.2 Do not use the Platform to harass, threaten, defame or discriminate against any person.
8.3 Do not store, in the Platform, credentials for another system outside the credential vault provided
for that purpose. Third-party credentials are supplied to Pensieve by the secure method in ADD-GL-007,
not pasted into a notes field.
8.4 Do not store payment card data in a free-text field. Where the Customer takes card payments, they are taken through the payment integration the Order Form records.
9.1 Who is responsible. Where the Platform sends a message, appointment reminder, result
notification, invoice, campaign, using the Customer's own messaging, e-mail or telephony credentials, the
message is the Customer's, sent on the Customer's authority. Pensieve supplies the mechanism. See the
bring-your-own-credential model at DIS-GL-025.
9.2 The Customer is responsible for having a lawful basis and any required consent for every message, for honouring withdrawal of consent, and for complying with the telecommunications and commercial communication rules of the market it operates in: in India, the registration, header, template, consent and preference requirements applicable to commercial communications, and the National Customer Preference Register.
9.3 Do not use the Platform to send unsolicited bulk commercial messages.
9.4 Do not include a person's clinical information in a message sent over an unencrypted channel beyond what that person has agreed to receive that way. A reminder that an appointment exists is not the same as a diagnosis sent by text message.
9.5 Do not select a recipient list on a criterion the law forbids, and do not include a record
flagged as belonging to a person under 18 in a marketing, campaign or outreach selection. The Platform
prevents this; do not attempt to work around it. See POL-GL-053 clause 10.5.
10.1 Where an artificial-intelligence capability is available in the Platform, use it only within the
scope disclosed in DIS-GL-027 and governed by ADD-GL-006.
10.2 Review every output before relying on it. An AI-drafted note, summary or code suggestion is a draft until a qualified person has checked it and taken responsibility for it.
10.3 Do not use an AI capability to produce, or to appear to produce, a clinical decision. See
ADD-GL-005 and DIS-GL-028.
10.4 Do not paste patient data into an external AI service. See 4.4.
11.1 The Customer may give access to a contractor, consultant, auditor or incoming supplier, provided that person holds a credential in their own name, is bound by confidentiality obligations at least as protective as the Customer's own, and is subject to this Policy.
11.2 The Customer remains responsible for everything done under a credential it has caused to be issued, whoever holds it.
11.3 Access granted for a defined engagement is time-limited to that engagement and is revoked at its end.
| Role | Responsibility |
|---|---|
| Authorised User | Comply with this Policy. Report a suspected breach or compromise. |
| Customer: nominated project owner | Maintain accurate user records, assign least privilege, run the quarterly access review at 3.6, and enforce this Policy internally. |
| Customer: security contact | Receive and act on Pensieve's notifications; notify Pensieve of a suspected compromise. |
| Pensieve: Security | Monitor for the conduct at 6 and 7 within the limits of the deployment model, notify the Customer, and act under 14. |
| Pensieve: Legal | Own this Policy, decide exceptions under 13, and authorise enforcement above a warning. |
13.1 A Customer may request an exception to a rule in this Policy by writing to info@pensievelabs.org
with the rule, the reason, the compensating control and the period requested.
13.2 An exception is granted, if at all, in writing, for a stated period, with a stated compensating
control, and is recorded in the Exception & Waiver Register (REG-GL-210). An undocumented exception
does not exist.
13.3 No exception is available to 1.2, 3.4, 3.5, 6.1 or 9.5.
14.1 Reporting a breach of this Policy. Report to info@pensievelabs.org for a security matter,
info@pensievelabs.org for anything else, or through the Customer's own escalation route. A report may be
made in confidence.
14.2 The ladder. Pensieve's response is proportionate and, wherever the risk allows, escalates:
| Step | Action |
|---|---|
| 1 | Notify the Customer's project owner and security contact, with the evidence |
| 2 | Require a remediation plan within a stated period |
| 3 | Apply a technical limit: rate limit, feature restriction, or suspension of the individual credential |
| 4 | Suspend a wider scope under POL-GL-050 clause 15 and MSA-IN-001 clause 20 |
| 5 | Terminate for material breach under MSA-IN-001 clause 21 |
14.3 Immediate action. Pensieve may act at step 3 or 4 without prior notice where the conduct presents a material and immediate risk to the Platform, to Customer Data or to another tenant. Pensieve notifies as soon as it is practical, with the reason.
14.4 The patient-safety carve-out applies to enforcement too. Pensieve will not enforce this Policy in
a manner that it knows would prevent access to a clinical record needed for the immediate care of a
patient. See POL-GL-050 clause 15.3.
14.5 Individuals. Pensieve enforces against the Customer, not against the Customer's staff, and looks to the Customer to address individual conduct under its own disciplinary procedure. A serious misuse of patient data by an individual may also be a criminal offence: in India, section 72A of the Information Technology Act, 2000 reaches an individual who discloses personal information in breach of a lawful contract, and Pensieve will cooperate with a lawful investigation.
14.6 What Pensieve can actually detect, by deployment model. On DM-1 and DM-2, Pensieve operates
the infrastructure and can detect the conduct at 6 and 7 directly. On DM-3 and
DM-4, Pensieve sees only what the Customer's environment exposes to it, and enforcement is contractual
rather than technical. This is stated plainly rather than implied.
This Policy is reviewed annually, and on any material change to the Platform, to the deployment models
or to Applicable Law. The review date is 31 July 2027. A change that materially and adversely
affects the Customer is notified thirty (30) days in advance under POL-GL-050 clause 26.
| Subject | Document that owns it |
|---|---|
| Purposes for which the Platform must not be used | ADD-GL-005 |
| Clinical safety boundary, feature by feature | DIS-GL-028 |
| Rate limits and quotas | POL-GL-057 |
| Credential custody for third-party systems | ADD-GL-007, DIS-GL-025 |
| Reporting a vulnerability | POL-GL-059 |
| Suspension and termination | MSA-IN-001 clauses 20 and 21 |
| Security controls and the shared-responsibility split | ADD-GL-001 |
| Exception register | REG-GL-210 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. Testable conduct rules with named owners, the patient-safety override at 1.4 and 14.4, the paediatric marketing prohibition, the documented-exception rule, and an honest statement of what Pensieve can detect under each deployment model. |
ADD-GL-004 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 July 2027 | Published at https://trust.pensievelabs.org