Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
This Policy applies to every deployment model (DM-1, DM-2, DM-3 and DM-4) without variation. A restriction that depended on who owned the infrastructure would not be a restriction. Where the Customer runs the Platform in its own cloud project or on its own hardware, Pensieve's ability to detect a prohibited use is…
This document is the source of truth for: marketing:/legal/use-restrictions, marketing:/legal/prohibited-uses, marketing:/product/clinical-safety, trust:/legal/use-restrictions, trust:/documents/ADD-GL-005, app:/legal/use-restrictions
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
ADD-GL-005 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
This Policy applies to every deployment model (DM-1, DM-2, DM-3 and DM-4) without variation.
A restriction that depended on who owned the infrastructure would not be a restriction. Where the
Customer runs the Platform in its own cloud project or on its own hardware, Pensieve's ability to detect
a prohibited use is limited (ADD-GL-004 clause 14.6), but the prohibition itself is identical and is
enforced contractually.
This Policy states the purposes for which the Pensieve platform must not be used. It is
the companion to the Acceptable Use Policy (ADD-GL-004), which governs conduct. Read both.
It exists for three reasons, stated plainly:
Incorporation. This Policy is incorporated into POL-GL-050 clause 2.3 and MSA-IN-001 clause 8.5.8.
A breach is a material breach of that agreement.
| Category | Meaning |
|---|---|
| Prohibited | Must not be done. No exception is available. Detection triggers 9. |
| Restricted | Permitted only on stated conditions recorded in writing on the Order Form or in an approved exception. |
| Declined | Pensieve will not build, enable, configure or support the capability, and will decline the engagement. Lawfulness is not the test. |
1.1 The rule. The Platform must not be used as a diagnostic device, a treatment-decision device, or any other medical device. It is an information-management system. It records, stores, retrieves, routes, presents, reconciles and reports information that qualified people enter or that third-party systems supply on the Customer's authority. It makes no clinical decision.
1.2 Why the boundary is where it is. In India, software is regulated as a medical device under the
Medical Devices Rules, 2017. The Central Drugs Standard Control Organisation's draft guidance on medical
device software, issued in October 2025 and clarificatory rather than new, expressly excludes
administrative systems, hospital management information systems, electronic medical records and general
health information software from medical-device scope. That exclusion is the Platform's position, and it
holds only while the Platform stays inside it. Equivalent boundaries apply in the other markets Pensieve
serves: the Therapeutic Goods Administration regime in Australia, the EU Medical Device Regulation in
Denmark and Norway, and the Ministry of Health and Prevention regime in the United Arab Emirates, and the
market-specific statements are published as jurisdiction variants of DIS-GL-028.
1.3 The test, in one sentence. If a competent clinician can see the input, the rule and the output, and would reach the same conclusion without the software, it is information management. If the software applies a clinically-derived or non-transparent model whose output the clinician is expected to rely on, it is a medical device. Transparency is the safe harbour: show the source, show the rule, let the clinician act.
1.4 Feature by feature. This table is a binding design and configuration constraint, not guidance.
| Capability | Permitted: information management | Prohibited: medical device |
|---|---|---|
| Allergy alert | Matching a prescribed drug against an allergy recorded in that patient's own chart and surfacing it | Computing an allergy risk score, inferring cross-reactivity across drug classes, or recommending an alternative agent |
| Drug interaction | Displaying a licensed third-party reference monograph verbatim, attributed, with no interpretation | Grading severity, ranking interactions, or permitting or blocking an order on a computed score |
| Dose checking | Range-checking against the manufacturer's labelled dose or a hospital-configured formulary limit, with the source shown | Computing a patient-specific dose from weight, age or renal function and recommending it |
| Vital signs | Charting values, arithmetic derivations, and threshold flags where the hospital sets the numbers | Early-warning or deterioration scores, sepsis prediction, arrhythmia detection |
| Laboratory results | Displaying results against the laboratory's own reference ranges and flagging out-of-range | Interpreting a result pattern into a suggested diagnosis |
| Imaging | Storage, routing, worklists, non-diagnostic display, report authoring | Automated detection, measurement for diagnosis, study triage or prioritisation, computer-aided detection |
| Order sets and protocols | Templates authored and approved by the hospital's own clinicians, applied by a clinician | Software that selects the protocol for a patient from that patient's data |
| Clinical documentation | Templates, structured forms, transcription, and coding assistance for billing | Auto-generating a diagnosis or a clinical impression |
| Analytics | Operational, financial, utilisation, quality-indicator and population dashboards | Individual patient risk stratification that drives a care decision |
| Triage | Recording the triage category a nurse assigns | Computing the triage category |
1.5 Prohibited configuration and extension. The Customer must not configure, extend, script, integrate or automate the Platform so as to produce any outcome in the right-hand column, and must not represent to any person that the Platform does so.
1.6 If you need a device. A capability in the right-hand column must be supplied by a separately licensed medical device of the appropriate risk class, integrated by interface, operating under its own regulatory approval and its own manufacturer's responsibility. It is not part of the Platform and Pensieve does not take responsibility for it.
1.7 Artificial intelligence. Any AI capability in the Platform is limited to non-clinical functions:
documentation drafting under clinician review, coding suggestions for billing, natural-language search over
the record, operational forecasting, and anomaly detection on financial and operational data. No AI
capability in the Platform predicts, diagnoses, triages, scores or recommends treatment. See
DIS-GL-027, ADD-GL-006 and POL-GL-060. Prohibited: using an AI capability, or connecting an
external model to the Platform, to produce or appear to produce a clinical decision.
1.8 The consequence of crossing the line. A use that crosses into the right-hand column exposes the Customer to operating an unlicensed medical device, and exposes Pensieve to supplying one. Pensieve will require it to stop, will suspend the capability if it does not, and will treat continued use as a material breach.
2.1 Pensieve is not a certified or empanelled participant in the Ayushman Bharat Digital Mission,
the National Health Claims Exchange, or any comparable national digital health programme in any market, and
does not represent that it is. This is a deliberate architectural boundary. See DIS-GL-024 and
DIS-GL-026.
2.2 Prohibited. The Customer must not represent to a patient, an insurer, a regulator, an accreditation body or any other person that Pensieve holds a certification, empanelment, milestone accreditation or participant status that it does not hold.
2.3 Prohibited. The Customer must not use Pensieve's software to hold itself out as compliant with a programme for which the Customer itself is not registered. The registered facility identity, the practitioner identities and the claims-exchange participant credentials are the Customer's, and the obligations attaching to them are the Customer's.
2.4 Restricted. Use of a third-party system through the Platform is permitted only where the Customer
holds valid credentials for it, complies with the operator's terms, and has recorded the integration on the
Order Form. See ADD-GL-007.
These are criminal or penal matters. They are named specifically because a general "comply with law" clause does not put anyone on notice.
3.1 Prenatal sex determination: absolutely prohibited. The Platform must not be used to record, store, transmit, communicate, infer, report or disclose the sex of a foetus, in any field, in any form, in any module, by any means. The Pre-conception and Pre-natal Diagnostic Techniques (Prohibition of Sex Selection) Act, 1994 prohibits communication of the sex of a foetus, and the prohibition is criminal. Pensieve does not provide a field for it and will not build one on request. Where the Customer performs regulated diagnostic procedures, the Platform supports the statutory registers, records and Form-based reporting that the Act and its Rules require. That is the permitted use, and it is the opposite of the prohibited one.
3.2 Narcotic and psychotropic substances. The Platform supports the statutory registers, records and reconciliation the narcotic-drugs regime requires. Prohibited: using the Platform to conceal, falsify or reconcile away a discrepancy in a narcotic or psychotropic stock register.
3.3 Scheduled drugs and pharmacy records. The Platform supports the prescription and register records the drugs regime requires. Prohibited: using the Platform to record a dispensing that did not occur, or to omit one that did.
3.4 Organ and tissue. Prohibited: using the Platform to facilitate, record or conceal any commercial dealing in a human organ or tissue, or to falsify a donor authorisation.
3.5 Termination of pregnancy. Records relating to termination of pregnancy carry a statutory duty of confidentiality. Prohibited: configuring the Platform to expose the identity of a person who has undergone a termination to any person not entitled to it, or to include such records in any report, extract, campaign or analytic output that identifies the individual.
3.6 Medico-legal records. Prohibited: altering, deleting, backdating or suppressing a medico-legal record, or configuring retention so as to destroy one that must be retained. The Platform preserves the original entry and the reason on every correction, and that mechanism must not be circumvented.
3.7 Birth and death records. Prohibited: using the Platform to generate, alter or suppress a record of a birth or a death otherwise than in accordance with the statutory reporting duty.
3.8 Radiation and imaging. The Platform supports the records the radiation regulator requires. Prohibited: using it to record an examination as performed on equipment not authorised for it.
3.9 Equivalent provisions elsewhere. Where the Customer operates in Australia, Denmark, Norway or the United Arab Emirates, the equivalent statutory prohibitions of that market apply, and this clause is to be read as extending to them.
The Platform must not be used to:
4.1 deny, delay or withdraw clinical care on the basis of an automated determination, a credit score, a payment status or a risk classification produced by or through the Platform;
4.2 falsify a clinical record, an invoice, a claim, a register, a consent or an audit trail;
4.3 submit or support a fraudulent insurance claim, an upcoded procedure, a service not rendered, or a duplicate claim;
4.4 conceal an adverse event, a never event, a medication error or a mortality from a person or body entitled to know of it;
4.5 discriminate against a patient, an employee or an applicant on the basis of caste, religion, race, sex, gender identity, sexual orientation, disability, HIV status, pregnancy, age or any other protected characteristic, including by using any of those attributes as a selection criterion in an admission, triage, pricing, campaign or staffing rule;
4.6 monitor employees beyond what employment law permits and what the Customer's own published policy discloses: the Platform's audit logs exist to protect patients and to evidence access, not to run a productivity surveillance programme;
4.7 conduct debt collection in a manner that harasses a patient, discloses their clinical information to a third party, or withholds a clinical record from them;
4.8 withhold from a patient a copy of their own record where they are entitled to it;
4.9 aggregate, sell, licence, broker or otherwise commercialise patient data, whether identified or purportedly de-identified, to a pharmaceutical company, an insurer, a data broker, an advertiser or any other third party;
4.10 re-identify data that has been de-identified, or attempt to;
4.11 conduct biometric identification of the public, mass surveillance, or population monitoring unconnected to the care of the individuals concerned;
4.12 operate a social-scoring, credit-scoring or citizen-rating system;
4.13 perform immigration status enforcement, or disclose a patient's immigration status to an
enforcement authority other than under a lawful, specific and binding demand handled through POL-GL-067;
4.14 support the practice of medicine by a person not registered to practise it;
4.15 operate a clinical establishment that is not registered where registration is required;
4.16 train, fine-tune, validate or evaluate a machine-learning model on patient data, whether by the Customer, by Pensieve or by any third party, except under 6;
4.17 provide services to a person or entity subject to applicable sanctions, or in a manner that breaches applicable export control law; or
4.18 do anything prohibited by the Acceptable Use Policy (ADD-GL-004).
5.1 The position. There are engagements Pensieve will decline, and capabilities Pensieve will not build, even where they are lawful in the market concerned. Publishing that list costs Pensieve some addressable market. It is published anyway, because a hospital handing over its entire operation is entitled to know what its supplier will refuse to do, and because a boundary that only exists in a private conversation is not a boundary.
5.2 Pensieve declines to build, enable, configure or support:
5.2.1 any capability that scores, ranks or classifies an individual patient in a way that determines whether they receive care, other than a clinical triage decision made by a qualified person;
5.2.2 any capability whose purpose is to identify, track or profile a person by a protected characteristic, or to enable a third party to do so;
5.2.3 any capability supporting so-called conversion practices directed at a person's sexual orientation or gender identity;
5.2.4 any capability supporting detention, restraint or involuntary treatment other than the records a lawful mental-healthcare regime requires, with the safeguards that regime imposes;
5.2.5 any capability whose purpose is to conceal a clinical outcome from a regulator, an accreditation body, a coroner or a patient;
5.2.6 any capability designed to obstruct a patient's access to their own record or to a second opinion;
5.2.7 any capability whose purpose is to identify individuals for law-enforcement, military, immigration or intelligence targeting;
5.2.8 any capability that makes the continuation of clinical care conditional on the patient consenting to a secondary commercial use of their data; and
5.2.9 any capability whose principal purpose is to extract a commercial advantage from a patient's lack of information about their own condition.
5.3 How a decline works. Where a request falls in 5.2, Pensieve says so in writing, gives the reason, and does not treat the decision as negotiable on price. Where the request is close to a line rather than over it, Pensieve says that too and proposes what it can do instead.
5.4 No silent refusal. Pensieve does not accept an engagement and then quietly fail to deliver a capability it has decided not to build. It declines at the point the request is made.
6.1 Research on patient data is Restricted. The Customer may use its own data for research where it has the lawful basis, the consent where consent is required, and the approval of a properly constituted institutional ethics committee. The Platform provides an export and a de-identification capability; the approvals are the Customer's.
6.2 Prohibited. Using patient data for research, model development or model validation without that ethics approval. In India, the Indian Council of Medical Research's ethical guidelines of 2023 treat the development or validation of an artificial-intelligence model using patient data as biomedical research requiring ethics-committee review. Pensieve treats it the same way.
6.3 Pensieve's own position, restated. Pensieve does not use customer data to train, fine-tune,
validate or evaluate any machine-learning model, for its own purposes, for another customer, or for a
third party. This is unconditional, is not varied by any Order Form, and is within the never-limited
category at POL-GL-050 clause 18.1.
6.4 De-identified aggregates. Where the Platform produces cross-tenant operational statistics,
aggregation and de-identification occur inside the tenant boundary before the data leaves it, no
re-identification key is retained, and the output cannot identify a Data Principal, a clinician or a
hospital. The constraints are in DPA-GL-001 clause 3.4. Prohibited: any attempt by any party to
reverse that process.
6.5 Secondary commercial use. Prohibited: the Customer using the Platform to make patient data available to a commercial third party for that third party's own purposes, unless the Customer has the lawful basis and the consent required and has recorded the arrangement in writing with Pensieve so that the sub-processing position is correct.
| Use | Conditions |
|---|---|
| Telemedicine and remote consultation | The Customer's practitioners comply with the telemedicine practice guidelines applicable to them, including identification, consent, prescription limits and record-keeping. The Platform records the consultation; it does not authorise the practice. |
| Patient-facing portals and applications | The Customer is the Data Fiduciary for the portal, publishes its own notice and consent, and configures identity verification. Records of a person under 18 are handled under POL-GL-053 clause 10. |
| Third-party analytics on tenant data | Permitted only through an export the Customer controls, to a recipient the Customer has contracted with, recorded in writing. Pensieve does not connect a third-party analytics tool to a tenant on request. |
| Multi-entity or group deployment | Requires ADD-GL-010, so that the Data Fiduciary for each entity, and the lawful basis for any sharing between them, is recorded. |
| Non-production environments | Production patient data must not be entered unless the Order Form records the environment as production-grade and DPA-GL-001 covers it. See POL-GL-050 clause 5.3. |
| Beta and early-access capability | Must not process production patient data unless the Order Form expressly permits it. See POL-GL-058. |
| Penetration testing by the Customer | Prior written consent, agreed scope and window, own tenant only. See DPA-GL-001 clause 15.6. |
| Use by an unregistered establishment | Not permitted. The Customer must hold the registration its jurisdiction requires. |
| Government or public-health reporting | Permitted and supported, on the Customer's authority and using the Customer's own credentials. |
8.1 Where the Customer wants to do something this Policy does not clearly permit, ask before building
it. Write to info@pensievelabs.org with: what the capability would do; who would use it; what data it
would touch; what decision, if any, it would influence; and who would be responsible for that decision.
8.2 Pensieve answers within ten (10) Business Days with one of: permitted; permitted on
stated conditions, which are recorded on the Order Form or in the Exception & Waiver Register
(REG-GL-210); prohibited, with the reason and the boundary relied on; or declined, with the
ground in 5.2.
8.3 Where the answer is prohibited or declined, Pensieve states what it can do instead where anything can be done.
8.4 A permission given under this clause is specific to the use case described, is recorded in writing, and does not generalise.
9.1 A breach of 1, 3 or 4 is a material breach of the agreement between the parties, and is not subject to the ordinary cure period where the breach is continuing and presents a risk to a patient, to a Data Principal or to either party's regulatory standing.
9.2 Pensieve will require the use to stop, may suspend the affected capability or the deployment under
POL-GL-050 clause 15 and MSA-IN-001 clause 20, and may terminate for material breach under
MSA-IN-001 clause 21.
9.3 The patient-safety carve-out applies. Pensieve will not exercise a suspension in a manner it knows
would prevent access to a clinical record needed for the immediate care of a patient. See POL-GL-050
clause 15.3.
9.4 The export right is unaffected. A breach of this Policy does not entitle Pensieve to withhold,
delay, condition or charge for a data export. See WPR-GL-400 and POL-GL-050 clause 21.3. Pensieve
will not hold a hospital's records hostage, for any reason, including this one.
9.5 Reporting obligations. Where Pensieve becomes aware of a use that appears to be a criminal offence, it will take its own legal advice and may be obliged to report it. It will tell the Customer that it is doing so unless the law prevents it.
This Policy is reviewed annually, at every product feature gate that touches clinical function, and on
any change to the medical-device regime in a market Pensieve serves. The review date is
31 July 2027. A new feature is assessed against 1.4 before it is built, not after
it ships.
| Subject | Document that owns it |
|---|---|
| Clinical safety boundary, in full, feature by feature and market by market | DIS-GL-028 |
| Conduct rules for users | ADD-GL-004 |
| AI capability disclosure | DIS-GL-027 |
| AI and automated processing addendum | ADD-GL-006 |
| Responsible AI use | POL-GL-060 |
| Integration boundary and the ABDM/NHCX position | DIS-GL-024, DIS-GL-026 |
| Children's data and the paediatric marketing boundary | POL-GL-053 clause 10 |
| Exit and data portability | WPR-GL-400 |
| Exception register | REG-GL-210 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. States the clinical-safety boundary as a binding feature-level table, names the Indian statutory prohibitions specifically including prenatal sex determination, lists the general prohibited uses, publishes the uses Pensieve declines on ethical grounds with reasons, and confirms that no breach of this Policy affects the Customer's right to export its data. |
ADD-GL-005 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 July 2027 | Published at https://trust.pensievelabs.org