Search all 478 artefacts by title, document ID or content.
Disclosure | Family 3, Security, Privacy & Trust Disclosures
Applies to DM-1, DM-2, DM-3 and DM-4. The log records changes to the Subprocessor Register (DIS-GL-009); which entries are relevant to a given hospital depends on its deployment model, and each log entry states which models it affects.
This document is the source of truth for: subprocessor-change-history, subprocessor-notification-feed, trust-center-subprocessor-updates, marketing:/trust/subprocessor-changes
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
Applies to DM-1, DM-2, DM-3 and DM-4. The log records changes to the Subprocessor Register
(DIS-GL-009); which entries are relevant to a given hospital depends on its deployment model, and each
log entry states which models it affects.
DIS-GL-009 tells you who is engaged today. This document tells you what changed, when, why, and
whether you were notified in time. The two together are what makes the register checkable rather than
merely current: a register with no history can be quietly rewritten.
This is also the notification feed. Publication here is one of the two channels by which
Edsol Edtech Pvt. Ltd. gives the notice required by DPA-GL-001 clause 8.4; the other is direct e-mail to
each Customer's notified privacy contact. Both are used for every change affecting Customer Personal Data.
| Channel | How | Who should use it |
|---|---|---|
| E-mail notification | Automatic for every Customer's notified privacy contact. Set or change the contact by writing to info@pensievelabs.org |
Every hospital under contract. This is not optional and requires no action |
| This page | Published at https://trust.pensievelabs.org and dated on every change |
Prospects, and anyone doing diligence before contracting |
| Feed | An RSS/Atom feed of this log is published at https://trust.pensievelabs.org |
IT teams that want the change in their own tooling |
A hospital that has not received an e-mail notification but sees an entry here should treat that as a
notification failure and report it to info@pensievelabs.org. Pensieve Labs will treat it as an
incident in its own process, because a notification obligation that silently fails is worse than one that
does not exist.
| Change | Entry required | Advance notice | Objection right |
|---|---|---|---|
| Adding a sub-processor that will process Customer Personal Data | Yes | 30 days | Yes (DPA-GL-001 clause 8.4) |
| Replacing a sub-processor that processes Customer Personal Data | Yes | 30 days | Yes |
| Removing a sub-processor | Yes | None required; published on effect | No: removal reduces the chain |
| Change of processing location for an existing sub-processor | Yes | 30 days where the change moves data to a new country | Yes, where a country changes |
| Change of legal entity or corporate control of an existing sub-processor | Yes | As soon as Pensieve Labs becomes aware |
Yes, if the change moves processing to a new country or materially changes the terms |
| Material change to a sub-processor's data processing agreement | Yes | 30 days where the change reduces protection | Yes, where protection is reduced |
| Adding or changing a Trust Center or corporate sub-processor that handles business contact data only | Yes | Published on effect | No, because no Customer Personal Data is processed. See DIS-GL-009 Section 3 |
| Urgent replacement to preserve security or availability | Yes, marked URGENT: retrospective notice | Notice as soon as practicable after the change, per DPA-GL-001 clause 8.5 |
Yes, preserved and exercisable after the fact |
| A new market-specific infrastructure provider for a deployment in a market the default infrastructure cannot serve | Yes | 30 days, or at contracting for a new deployment in that market | Yes |
Not a trigger. Changes to the hospital's own connected systems (DIS-GL-024), changes to the cloud
provider's own downstream sub-processors, and internal changes at Edsol Edtech Pvt. Ltd. that do not
introduce a third party are not logged here. The cloud provider maintains its own sub-processor list and its
own notification mechanism; a hospital that wants that notification should subscribe to it directly, and
DIS-GL-009 Section 9.1 states this limitation.
Every entry carries the same nine fields, so that a hospital's own change-control process can consume them without reading prose:
Log ID SP-CHG-nnn
Published on the date this entry was published
Effective on the date the change takes or took effect
Type ADD | REPLACE | REMOVE | LOCATION | ENTITY | TERMS | URGENT
Sub-processor legal entity name
Function what it does
Data categories what it will process
Applies to DM-1 | DM-2 | DM-3 | DM-4, and the markets affected
Notice advance notice given, in days, and the objection deadline
| Log ID | Published | Effective | Type | Sub-processor | Change | Applies to | Notice given |
|---|---|---|---|---|---|---|---|
SP-CHG-001 |
31 July 2026 |
31 July 2026 |
BASELINE | Not applicable | First publication of the Subprocessor Register (DIS-GL-009) v1.0.0. Five entries recorded as the opening position: one platform sub-processor applying to DM-1 and DM-2, three Trust Center sub-processors handling business contact data only, and the corporate finance function. No change to any existing engagement. |
All models, all markets | Not applicable: baseline publication, not a change |
There has been no change to the sub-processor chain since first publication. This log will not be padded. An empty log with a visible baseline date is an honest statement; a log filled with cosmetic entries is not.
The procedure is in DPA-GL-001 clause 8.4 and is summarised here because a hospital reading this feed is
the person who would use it.
| Step | Timing | What happens |
|---|---|---|
| 1 | Within the 30-day notice period | The Customer objects in writing to info@pensievelabs.org, stating the grounds |
| 2 | Within 5 business days | Pensieve Labs explains the sub-processor's role, the data it would process, and the safeguards applied |
| 3 | By agreement | Pensieve Labs offers, where one exists, a commercially reasonable alternative that avoids the sub-processor processing that Customer's data |
| 4 | If unresolved | The Customer may terminate the affected Services without penalty, and DIS-GL-023 governs the return and deletion of its data |
Pensieve Labs does not treat an objection as an obstacle. A hospital that objects is doing exactly what
the clause is for, and the answer is either a genuine alternative or an exit that does not cost it money.
Entries are never deleted or edited. A correction is published as a new entry that references the entry it corrects. The log is retained for the period in this document's frontmatter and remains available after an entry is superseded, because a hospital investigating a historical incident needs to know who was in the chain at the time, not who is in it now.
7.1 This log is self-maintained. No third party verifies that every change has been logged. The control
that makes it reliable is contractual: failing to notify is a breach of DPA-GL-001 clause 8.4.
7.2 Downstream changes are not visible here. A change made by the cloud provider to its own sub-processors does not appear in this log (Section 2). This is a real gap and it is stated rather than glossed.
7.3 Notification depends on the Customer keeping its privacy contact current. If the notified contact
has left the hospital and has not been replaced, the e-mail notification will fail silently. Hospitals
should confirm the contact at each renewal; Pensieve Labs prompts for it, but cannot maintain it.
| Question | Document |
|---|---|
| Who is engaged today | DIS-GL-009 Subprocessor Register |
| The contractual notice and objection terms | DPA-GL-001 clause 8 |
| What happens to data if a hospital terminates over an objection | DIS-GL-023 Data Deletion & Return Disclosure |
| Where data is processed | DIS-GL-008 Data Residency Statement |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Pensieve Labs Security |
First publication. Baseline entry SP-CHG-001 recorded. Entry format, trigger table and objection procedure published. |
| 1.0.1 | 31 July 2026 |
Pensieve Labs Security |
Log-entry identifier re-formatted from CHG-SP-nnn to SP-CHG-nnn. The former collided with the corpus doc_id grammar (three-letter kind, two-letter jurisdiction, three digits) and was reported as a dangling artefact reference by the reference checker. No substantive change; no change to any entry. |