Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
These Terms are published in full, openly, before any commercial conversation. A hospital's counsel, an Authorised User and a prospective buyer read the same text. Nothing in these Terms is disclosed only after signature.
This document is the source of truth for: marketing:/legal/terms-of-service, marketing:/legal, marketing:/product/terms, trust:/legal/terms-of-service, trust:/documents/POL-GL-050, app:/legal/terms, app:/signup/terms-acceptance
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
POL-GL-050 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
These Terms are published in full, openly, before any commercial conversation. A hospital's counsel, an Authorised User and a prospective buyer read the same text. Nothing in these Terms is disclosed only after signature.
Where these Terms are inconsistent with a Master Services Agreement (MSA-IN-001) that
Edsol Edtech Pvt. Ltd. has executed with a Customer, the executed agreement prevails. See
2. This note does not form part of these Terms.
| Deployment model | Applies | Variation |
|---|---|---|
DM-1 Dedicated (Pensieve-hosted, isolated project) |
Yes | None. |
DM-2 Shared (Pensieve-hosted, multi-tenant) |
Yes | None. |
DM-3 Customer Cloud (Customer's own cloud project) |
Yes | 5.6 applies. Availability, infrastructure cost and infrastructure security sit with the Customer. |
DM-4 On-Premise (Customer-controlled infrastructure) |
Yes | 5.7 applies. Availability commitments in SLA-GL-001 do not apply to infrastructure Pensieve does not control. |
The deployment models are defined in Deployment Models Explained (WPR-GL-004). The model applying to a
given deployment is recorded on the Order Form as DM-1.
These Terms state the conditions on which Edsol Edtech Pvt. Ltd. makes the Pensieve platform
available, and the conduct required of every person who uses it. They serve three functions:
ADD-GL-013.They deliberately do not restate data protection, service levels, security controls or commercial terms.
Those live in DPA-GL-001, SLA-GL-001, ADD-GL-001 and the Order Form respectively, each of which
prevails over these Terms on its own subject matter.
1.1 In these Terms, capitalised expressions have the meanings given in MSA-IN-001 clause 1 unless
defined below. Where an expression is defined in both, the MSA definition governs.
**"Authorised User"** means an individual to whom the Customer grants access to the Platform, being an employee, contractor, consultant, visiting practitioner or agent of the Customer acting for the Customer's internal business purposes.
**"Customer"** means the organisation that has contracted for, or has been
granted, access to a Tenant, being Customer legal name where these Terms are rendered for a specific
deal.
**"Evaluation Access"** means access to the Platform granted without an executed Master Services Agreement, including a sandbox, a demonstration workspace, a trial tenant and any environment marked as non-production.
**"Platform"** means Pensieve, the software platform operated or
supplied by Edsol Edtech Pvt. Ltd., including its application-building surfaces, interfaces, application
programming interfaces, documentation and any capability made available through it.
**"Tenant"** means the logically or physically isolated instance of the Platform allocated to a single Customer.
**"Terms"** means this document, POL-GL-050, at the version stated in its
header, together with the policies it incorporates under 2.3.
**"you"** means the person reading and accepting these Terms: the Customer where the Customer accepts them, and the individual where an Authorised User accepts them.
1.2 Interpretation. Headings do not affect construction. "Including" means "including without
limitation". A reference to a document identified by a doc_id is a reference to the version of that
document published at https://trust.pensievelabs.org at the relevant time, except where a version has been
incorporated into an executed contract, in which case the incorporated version governs. Singular includes
plural. A reference to a statute includes subordinate legislation made under it, as amended.
2.1 The relationship these Terms have with a signed agreement. Where the Customer and Pensieve have executed a Master Services Agreement, that agreement and the documents incorporated into it govern the commercial relationship between the two organisations. These Terms then operate only as (a) the standing user-level rules binding each Authorised User individually, and (b) a policy incorporated into the MSA. They do not add, reduce or vary any obligation, warranty, indemnity, liability cap or payment term in an executed agreement.
2.2 Order of precedence. In the event of a conflict, the following order applies, the earlier prevailing over the later on the subject matter it addresses:
| Rank | Document |
|---|---|
| 1 | The Order Form or Statement of Work (ORD-GL-001, ORD-GL-002) |
| 2 | The Data Processing Agreement (DPA-GL-001) |
| 3 | The Security Addendum (ADD-GL-001) |
| 4 | The Service Level Agreement (SLA-GL-001) |
| 5 | Any other executed addendum, in the order stated in the Master Services Agreement |
| 6 | The Master Services Agreement (MSA-IN-001) |
| 7 | These Terms and the policies incorporated under 2.3 |
| 8 | Any other Pensieve documentation |
2.3 Policies incorporated into these Terms. The following are incorporated by reference and form part of these Terms:
| Document | Subject |
|---|---|
ADD-GL-004 Acceptable Use Policy |
Conduct required of every user of the Platform |
ADD-GL-005 Use Case Restrictions |
Purposes for which the Platform must not be used |
POL-GL-053 Privacy Policy |
Personal data Pensieve processes as a Data Fiduciary |
POL-GL-054 Cookie Policy & Consent Notice |
Cookies and similar technologies |
POL-GL-056 Support Policy & Escalation Matrix |
How support is requested and escalated |
POL-GL-057 Fair Use & Rate Limiting Policy |
Consumption limits and rate limits |
POL-GL-058 Beta / Early Access Terms |
Pre-release capability |
POL-GL-059 Vulnerability Disclosure Policy |
Reporting a security defect |
POL-GL-064 Product End-of-Life & Deprecation Policy |
Notice periods for withdrawal of capability |
POL-GL-066 Grievance Redressal Policy |
Complaints and the statutory grievance route |
POL-GL-067 Legal & Law Enforcement Request Policy |
Response to demands from public authorities |
2.4 Where there is no executed agreement. Where you access the Platform under Evaluation Access, these Terms, together with the documents in 2.3, are the whole of the agreement between you and Pensieve for that access, and 12 applies in place of any negotiated commercial terms.
3.1 Acceptance. You accept these Terms by any of: clicking to accept them; being granted and then using a credential to the Platform; or executing an agreement that incorporates them. Continued use after a change made under 26 is acceptance of the changed version.
3.2 Authority. Where you accept these Terms on behalf of an organisation, you represent that you are authorised to bind that organisation, and "you" means that organisation. Where you are not so authorised, you must not accept them and must not use the Platform.
3.3 Eligibility. The Platform is made available to organisations for their internal business purposes. It is not offered to consumers, and it is not offered to individuals for personal use. An individual under the age of eighteen (18) years must not be granted an Authorised User credential. Patients, attendants and other Data Principals are not Authorised Users; their interaction with the Platform, where any, is through interfaces the Customer configures and controls.
3.4 One acceptance per person. Each Authorised User accepts these Terms in their own name at first
sign-in. The Customer remains responsible for its Authorised Users under MSA-IN-001 clause 8.3
irrespective of whether an individual acceptance has been recorded.
4.1 What it is. The Platform is an operating system for hospitals: a substrate on which a hospital's clinical documentation, administrative, financial, diagnostic, pharmacy, inventory, supply-chain, human-resource, quality and analytical operations are recorded, coordinated, reconciled and reported. It records, stores, retrieves, routes, presents and reports information that Authorised Users enter or that Third-Party Systems supply on the Customer's authority.
4.2 What it is not: the clinical safety boundary. The Platform is not a medical device and is not
software as a medical device. It is not registered, licensed or approved as a medical device under the
Medical Devices Rules, 2017 or under any comparable regime in any market in which it is supplied, and
Pensieve does not represent that it is. Its function is administrative and record-keeping, the category
that the Central Drugs Standard Control Organisation's draft guidance on medical device software places
outside medical-device scope, which expressly excludes administrative systems, hospital management
information systems and electronic medical records. 16, the Use Case Restrictions
(ADD-GL-005) and the Clinical Safety Boundary Statement (DIS-GL-028) state the boundary in full.
4.3 No certification is claimed. Pensieve holds no third-party certification of its information
security management system. Pensieve is not certified to ISO/IEC 27001, holds no SOC 2 report, holds no
HITRUST certification, and holds no medical-device or health-IT product certification. Pensieve's controls
are mapped to published control sets and to the statutory minima that apply in each market, and the mapping,
the supporting evidence and the gaps are published. Nothing in these Terms or in any Pensieve material may
be read as a claim to a certification Pensieve does not hold. See WPR-GL-005.
4.4 Pensieve is not the regulated participant in national digital health programmes, stated
affirmatively. Pensieve does not hold, and does not represent that it holds, certification, empanelment,
milestone accreditation or participant status in the Ayushman Bharat Digital Mission, the National Health
Claims Exchange, or any comparable national digital health programme in any market. This is a deliberate
architectural boundary, not a gap. The registered health facility is the Customer; the facility identity,
the practitioner identities and the claims-exchange participant credentials belong to the Customer;
Pensieve supplies the software through which the Customer uses them. See 10, the Integration
Boundary Statement (DIS-GL-024) and the responsibility matrix (DIS-GL-026).
4.5 The Platform is not the Customer's clinical governance. The Platform records what the Customer's personnel do. It does not supervise them, does not validate their clinical judgement, and does not discharge any professional, statutory or accreditation obligation owed by the Customer. See 16.
5.1 Grant. Subject to these Terms and, where one exists, to the executed agreement, Pensieve grants the Customer a non-exclusive, non-transferable, non-sublicensable right for its Authorised Users to access and use the Platform in the Tenant allocated to it, for the Customer's internal business purposes, during the term of that access.
5.2 Reservation. All rights not expressly granted are reserved. No right is granted to the Platform's source code, object code, architecture or underlying models.
5.3 Environments. Where an environment is designated as non-production, whether sandbox, evaluation, demonstration, training or user-acceptance testing, it is provided for that purpose only. Production personal data, and in particular patient records, must not be entered into a non-production environment except where the Order Form records that the environment is provisioned to production standard and the Data Processing Agreement covers it.
5.4 Credentials. Credentials are personal to the individual to whom they are issued. Sharing a credential, using another person's credential, or retaining a credential after ceasing to be entitled to it is a breach of these Terms by the individual concerned and by the Customer. The Customer must remove access within one (1) Business Day of a user ceasing to be entitled to it.
5.5 Multi-factor authentication. Administrative and privileged accounts must use multi-factor authentication. Pensieve may refuse to provision, or may withdraw, a privileged credential that is not so protected.
5.8 Capacity and fair use. Consumption limits, rate limits and the treatment of sustained excess
consumption are in the Fair Use & Rate Limiting Policy (POL-GL-057). Pensieve applies a rate limit before
it applies a suspension, and gives notice before it applies either, except where an immediate limit is
necessary to protect the Platform or another Customer's Tenant.
6.1 Each Authorised User must:
6.1.1 use the Platform only for the Customer's internal business purposes and only within the permissions assigned;
6.1.2 keep credentials confidential, use a distinct credential, and report a suspected compromise to
the Customer and to info@pensievelabs.org without delay;
6.1.3 enter information accurately, completely and in the correct patient, encounter or ledger context;
6.1.4 comply with the Acceptable Use Policy (ADD-GL-004) and the Use Case Restrictions
(ADD-GL-005);
6.1.5 access a record only where there is a legitimate need arising from that user's role, the Platform records who viewed which record, and unauthorised access is visible; and
6.1.6 comply with the Customer's own policies, its professional obligations and Applicable Law.
6.2 The Customer must additionally: maintain accurate user records; assign the least privilege necessary; obtain and maintain every notice, consent, authority and lawful basis required for the personal data it processes through the Platform; hold and maintain its own registrations, licences and accreditations; and maintain and be able to execute documented clinical downtime procedures under 16.5.
6.3 Prohibited conduct. You must not:
6.3.1 make the Platform available to any person who is not an Authorised User, or resell, sublicense, rent, lease, timeshare or operate it as a service bureau, except as an Order Form expressly records;
6.3.2 copy, modify, translate, adapt or create a derivative work of the Platform;
6.3.3 decompile, disassemble or reverse engineer the Platform, or attempt to derive its source code, except to the extent Applicable Law expressly permits notwithstanding this restriction and after written notice to Pensieve and a reasonable opportunity to supply the information sought;
6.3.4 remove, obscure or alter a proprietary notice;
6.3.5 use the Platform to build a competing product, or publish a benchmark of it without Pensieve's prior written consent, such consent not to be unreasonably withheld where the benchmark is factual, current and methodologically disclosed;
6.3.6 introduce malicious code, circumvent access controls, or interfere with the operation or security of the Platform or of another Customer's Tenant;
6.3.7 conduct penetration testing or automated scanning without Pensieve's prior written consent, which
Pensieve gives on reasonable conditions for the Customer's own Tenant, see DPA-GL-001 clause 15.6 and
the Vulnerability Disclosure Policy (POL-GL-059);
6.3.8 use the Platform for a purpose restricted under ADD-GL-005, including any use that would cause
the Platform to be a medical device; or
6.3.9 access, extract or use another Customer's data, or attempt to.
6.4 Automated access. Access through the Platform's application programming interfaces is permitted for the Customer's own integrations, within the published rate limits, using credentials issued for that purpose. Scraping the user interface, driving it with an automation tool to evade a rate limit, or extracting data at a volume or frequency that degrades the Platform for others is not permitted. A bulk export is available under 21 and does not need to be improvised.
7.1 Ownership. Customer Data belongs to the Customer. Pensieve claims no ownership of it, acquires no licence to it beyond what is necessary to provide the Platform and the Services, and does not sell, rent, licence, mine or trade it.
7.2 Licence to operate. The Customer grants Pensieve a non-exclusive licence to host, store, transmit,
process, back up, restore and display Customer Data solely to provide, secure, support and bill for the
Platform, and to perform the Customer's documented instructions under DPA-GL-001. That licence ends when
the data is deleted under 21.
7.3 No training on Customer Data. Pensieve does not use Customer Data to train, fine-tune, validate
or evaluate any machine-learning model, whether for Pensieve's own purposes, for another customer, or for
a third party. Where an artificial-intelligence capability is made available in the Platform, its
processing is disclosed in DIS-GL-027 and governed by ADD-GL-006. This commitment is unconditional and
is not varied by any Order Form.
7.4 Aggregated statistics. Pensieve may derive aggregated, de-identified operational statistics for
capacity planning, product improvement and security. The constraints on that derivation (aggregation and
de-identification inside the Tenant boundary before the data leaves it, no retained re-identification key,
and no output that permits identification of a Data Principal, an individual clinician or the Customer) are stated in DPA-GL-001 clause 3.4 and are not restated here.
7.5 Responsibility for content. The Customer is responsible for the accuracy, quality, integrity, legality and lawful collection of Customer Data. Pensieve does not review or verify Customer Data and is not responsible for clinical or commercial decisions taken on it.
7.6 Backups are not an archive service. Pensieve maintains backups for continuity as described in
DIS-GL-014. A backup is a continuity mechanism, not a record-keeping service, and does not discharge the
Customer's own statutory medical-record retention obligations. The retention position is in DPA-GL-001
clause 14 and DIS-GL-023.
8.1 The Data Processing Agreement governs. The processing of personal data through the Platform is
governed exclusively by the Data Processing Agreement (DPA-GL-001). The substance of the
data-protection obligations is not restated here, and where these Terms conflict with the DPA on the
processing of personal data, the DPA prevails.
8.2 Roles. The Customer is the Data Fiduciary. Pensieve is a Data Processor acting on the Customer's documented instructions. In markets where the General Data Protection Regulation applies, the equivalent roles are controller and processor.
8.3 Where Pensieve is a Data Fiduciary in its own right. Pensieve is a Data Fiduciary only for business
contact data and service operations data relating to Authorised Users, Trust Center users and the
Customer's commercial contacts. That processing is described in the Privacy Policy (POL-GL-053).
Patient, clinician and other Data Principal records are never processed by Pensieve as a Data
Fiduciary.
8.4 Precondition to use. Where the Customer processes personal data through the Platform in production, an executed Data Processing Agreement is a precondition. Under section 8(2) of the Digital Personal Data Protection Act, 2023, a Data Fiduciary may engage a Data Processor only under a valid contract; the DPA is that contract. Pensieve publishes the DPA in advance and signs its counterpart first so that this is never the item that delays a go-live.
8.5 Grievances and rights. A Data Principal's rights run against the Customer as Data Fiduciary. Where
a Data Principal contacts Pensieve directly, Pensieve routes the contact to the Customer and does not
respond on the merits. Pensieve's own grievance mechanism, for the data described at 8.3, is
in POL-GL-066.
9.1 What Pensieve implements. The security measures Pensieve implements are stated in the Security
Addendum (ADD-GL-001) and in the disclosures it references, including encryption (DIS-GL-011),
authentication and access control (DIS-GL-012), audit logging (DIS-GL-013), backup and recovery
(DIS-GL-014) and vulnerability management (DIS-GL-017). They are not restated here.
9.2 No absolute claim. Pensieve does not represent that the Platform is immune from compromise. It
states what it implements, publishes the evidence, and commits to defined notification timelines in
DPA-GL-001 clause 10 and DIS-GL-016.
9.3 Shared responsibility. Security of the Platform is divided between Pensieve and the Customer. The
division is set out per deployment model in ADD-GL-001. Customer-side controls (device security, network
controls, user lifecycle, credential hygiene, multi-factor authentication on administrative accounts) are
the Customer's, and no Pensieve control substitutes for them.
9.4 Reporting a vulnerability. A suspected vulnerability in the Platform is reported under the
Vulnerability Disclosure Policy (POL-GL-059) to info@pensievelabs.org. Pensieve does not
pursue a good-faith researcher who complies with that policy.
10.1 Bring your own key and credential. The Platform integrates with third-party systems on a
bring-your-own-key and bring-your-own-credential basis. The Customer holds its own registrations,
participant identities, client identifiers, secrets, certificates and licences. Pensieve stores them
encrypted in a per-tenant key vault and uses them to exchange data as the Customer, on the Customer's own
authority, and only for the purposes the Customer instructs. The custody, encryption, rotation, revocation
and offboarding terms are in ADD-GL-007 and DIS-GL-025.
10.2 Allocation of responsibility. The Customer is responsible for the existence, validity, scope and lawfulness of each credential, for compliance with the operator's terms, and for the consequences of acts performed through the Platform using its credentials in accordance with its instructions and configuration. Pensieve is responsible for using credentials only within the instructed scope, for the security controls applied to their custody, and for technical faults in the Platform's own construction of a call.
10.3 No warranty for third-party systems. Pensieve does not control and does not warrant the availability, accuracy, continuity, performance, security or lawfulness of any third-party system. Downtime, latency, schema change, deprecation, rate limiting, rejection of a transaction or withdrawal of a third-party system is not a Pensieve breach and is excluded from the service levels.
10.4 Withdrawal. If a third-party system ceases to be available, or the Customer's credentials for it are revoked, Pensieve disables the corresponding integration. Charges are not reduced on that account.
11.1 Pensieve's property. Pensieve and its licensors own the Platform, its source and object code, its architecture, its interfaces, its documentation, and every improvement to it, including improvements arising from work performed for the Customer other than a Commissioned Module recorded as the Customer's on an Order Form.
11.2 The Customer's property. The Customer owns Customer Data, its Configuration and any Customer
Application it builds on the Platform, on the terms in MSA-IN-001 clause 13. Pensieve does not assert
ownership over a workflow, form, report or data model the Customer designs.
11.3 Feedback. Where you give Pensieve a suggestion, defect report, enhancement request or other feedback, Pensieve may use it without restriction, obligation or payment. Feedback must not contain Customer Data, patient information or the Customer's confidential information; where it does, Pensieve treats it under 8 and 23 and this sub-clause does not apply to it.
11.4 Open-source components. The Platform includes third-party open-source components. They are listed,
with their licences, in DIS-GL-019, and a software bill of materials in CycloneDX format is published
there. An open-source component is supplied under its own licence, which prevails over these Terms for that
component.
11.5 Trade marks. No right is granted to use Pensieve's name, marks or logos. Permitted use is governed
by the Trademark & Brand Usage Policy (POL-GL-062).
12.1 Where an Order Form exists. Charges, currency, taxes, payment terms, invoicing, price change and
renewal are governed by the Order Form and by MSA-IN-001 clauses 6 and 7, POL-GL-063 and POL-GL-065.
These Terms do not set a price and do not vary one.
12.2 Evaluation Access. Evaluation Access is provided at no charge unless an Order Form states otherwise. For Evaluation Access:
12.2.1 the Platform is provided as is, and 17 applies in full;
12.2.2 no service level applies, and SLA-GL-001 is not incorporated;
12.2.3 Pensieve's total aggregate liability is limited under 18.4;
12.2.4 Pensieve may withdraw the access on seven (7) days' written notice, or immediately for a breach of 6.3; and
12.2.5 the export right at 21 applies without qualification, so that nothing entered during an evaluation is stranded.
12.3 No set-off against the export. No amount owed by the Customer, and no dispute about any amount, entitles Pensieve to withhold, delay, condition or charge for a data export. See 21.3.
13.1 Availability. Where SLA-GL-001 is incorporated, availability, measurement method, exclusions,
support hours, severity definitions, response and restoration targets and service credits are stated there
and are not restated here. Where it is not incorporated, no availability commitment applies.
13.2 Planned maintenance. Pensieve performs planned maintenance within the windows and on the notice
stated in SLA-GL-001. Emergency maintenance to address a security or integrity risk may be performed
without that notice; Pensieve notifies as soon as it is practical and records the reason.
13.3 Changes to the Platform. Pensieve develops the Platform continuously. Pensieve may add, modify or
improve capability at any time. Pensieve will not remove or materially degrade a capability the Customer
is using except under the Product End-of-Life & Deprecation Policy (POL-GL-064), which sets the notice
periods, the migration support and the Customer's rights where a removal is material and adverse. Change
and release practice is disclosed in DIS-GL-031.
13.4 Beta and early-access capability. Capability marked as beta, preview, early access or experimental
is governed by POL-GL-058. It is provided as is, may be changed or withdrawn without the notice periods
in POL-GL-064, carries no service level, and must not be used to process production patient data unless
the Order Form expressly permits it.
13.5 Status and incident communication. Operational status, incident notices and maintenance notices are
published at Pensieve status page URL and communicated through the channels in SLA-GL-001.
14.1 How support works. Support hours, severity definitions, response targets, escalation path and
named escalation contacts are in SLA-GL-001 and the Support Policy (POL-GL-056). Help articles,
how-to guidance and product documentation are published in the Pensieve Support Center at
[TO BE SUPPLIED]. The Trust Center is not the Support Center, and neither duplicates the
other.
14.2 Support access to Customer Data. Where Pensieve personnel need access to Customer Data to resolve
a ticket, the conditions on that access (authorisation, scope, duration, logging and the Customer's
visibility of it) are in DPA-GL-001 clause 6.4 and DIS-GL-033.
14.3 Out of scope. Support does not include the Customer's own hardware, network, devices, third-party systems, or the correctness of the Customer's Configuration, clinical content or master data.
15.1 Grounds. Pensieve may suspend access, in whole or in part, where:
15.1.1 continued access presents a material and immediate risk to the security or integrity of the Platform, of Customer Data, or of another Customer's Tenant;
15.1.2 a use breaches 6.3, ADD-GL-004 or ADD-GL-005 and the breach is material or is
not cured after notice;
15.1.3 Pensieve is required to suspend by Applicable Law or by a binding order; or
15.1.4 an undisputed amount is overdue and remains unpaid after the notice period stated in
MSA-IN-001 clause 20.
15.2 Proportionality. Suspension is applied at the narrowest scope that addresses the cause: a single credential, a single integration or a single capability before a Tenant. Pensieve gives prior notice except where 15.1.1 or 15.1.3 makes prior notice impossible or unlawful.
15.3 Patient safety carve-out. Pensieve will not exercise a suspension for non-payment in a manner that Pensieve knows would prevent the Customer from accessing a clinical record needed for the immediate care of a patient. Where a suspension for non-payment is applied, Pensieve maintains a read-only clinical record path for the duration, and says so at the time. This carve-out does not apply to a suspension under 15.1.1 or 15.1.3, where the risk or the order determines the scope.
15.4 Restoration. Access is restored promptly once the cause is removed. Suspension does not extend the term and does not suspend the Customer's payment obligation, except where the suspension was wrongful.
15.5 Suspension is not termination. A suspension does not affect the export rights at 21, which continue to operate throughout.
16.1 No clinical decision. The Platform does not, and is not designed, offered or permitted to: diagnose; screen for or predict disease; compute a patient-specific dose; grade, score or rank a clinical finding; triage; select a protocol for a patient; interpret an image or a result into a clinical conclusion; or recommend, initiate, withhold or discontinue any treatment. Pensieve makes no clinical decision. Where the Platform presents an alert, a flag, a range or a reference, it presents information from a source the Customer has configured or a third party has supplied, with that source shown, for a qualified person to consider.
16.2 The Customer retains full clinical responsibility. Every clinical decision is made by a qualified, registered healthcare professional exercising independent professional judgement, and the Customer is solely and completely responsible for it. Use of the Platform does not transfer, share, dilute or reduce that responsibility in any degree.
16.3 Configured clinical content. Order sets, protocols, formularies, reference ranges, alert thresholds and templates configured or approved by the Customer are the Customer's clinical content. Pensieve provides the mechanism, does not validate the clinical correctness of that content, and is not responsible for it.
16.4 Restriction on use. You must not use, configure, extend or integrate the Platform in a manner that
would cause it to perform a medical-device function, and must not represent to any person that it does. The
feature-level boundary is stated in ADD-GL-005 and DIS-GL-028. A capability that performs a
medical-device function must be provided by a separately licensed product of the appropriate risk class,
integrated by interface, and is not part of the Platform.
16.5 Downtime procedures. The Customer must maintain, test and be able to execute documented clinical downtime procedures, and must train its personnel in them, so that patient care continues safely if the Platform is unavailable for any reason. A record system that is unavailable must never become a clinical risk, and the only party able to prevent that is the Customer. This obligation is independent of any service level and is not reduced by one.
16.6 Artificial intelligence. Any artificial-intelligence capability made available in the Platform is
limited to non-clinical functions, is disclosed in DIS-GL-027, and is governed by ADD-GL-006 and
POL-GL-060. No such capability produces a clinical decision, and each remains subject to human review.
16.7 Nothing excludes liability for personal injury. Nothing in these Terms excludes or limits either party's liability for death or personal injury caused by its own negligence.
17.1 Pensieve's warranties. Pensieve warrants that: it has the right to grant the rights it grants; it will provide the Platform and the Services with the reasonable skill and care of a competent supplier of comparable platforms; the Platform will perform materially in accordance with its published documentation; and it will not knowingly introduce malicious code into the Platform.
17.2 Remedy for a defect. Where the Platform does not perform materially in accordance with its documentation, Pensieve will correct the defect, provide a workaround, or, where it can do neither within a reasonable period, permit termination of the affected capability with a pro-rata refund of prepaid Charges attributable to it. This is the Customer's exclusive remedy for that warranty, without prejudice to 16.7.
17.3 What Pensieve does not warrant. Pensieve does not warrant that: the Platform will be uninterrupted or error-free; it will meet a requirement the Customer has not recorded on an Order Form or a Statement of Work; it will operate with a third-party system Pensieve has not agreed to integrate; the results of any report, analysis or reconciliation will be accurate where the underlying Customer Data is not; or that the Customer will achieve any commercial, clinical, operational or financial outcome.
17.4 Disclaimer. To the fullest extent Applicable Law permits, and except as 17.1 states, all warranties, conditions, terms and representations, whether express, implied or statutory, are excluded, including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, title and non-infringement.
17.5 Evaluation and beta. Evaluation Access and beta capability are provided as is and as available, with no warranty of any kind, and 17.1 does not apply to them.
17.6 Statutory rights. Nothing in this clause excludes a right or remedy that Applicable Law does not permit to be excluded.
18.1 What is never limited. Nothing in these Terms limits or excludes liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; a party's wilful misconduct; a breach of 7.3 (no training on Customer Data); a breach of 21.3 (no conditions on data export); or any liability that Applicable Law does not permit to be limited.
18.2 Excluded losses. Subject to 18.1, neither party is liable for loss of profit, loss of revenue, loss of anticipated savings, loss of goodwill, loss of business opportunity, or any indirect or consequential loss, in each case whether or not foreseeable.
18.3 Where an executed agreement exists. Where a Master Services Agreement is in force, the liability
regime in that agreement governs and this clause does not apply to the Customer's claims. MSA-IN-001
clause 18 is the source of truth for the liability cap structure.
18.4 Where no executed agreement exists. For Evaluation Access and for any access not covered by an
executed agreement, Pensieve's total aggregate liability, in contract, tort (including negligence),
statute or otherwise, is limited to the total Charges paid for that access in the twelve (12) months before
the event giving rise to the claim, or, where no Charges have been paid, to Legal nominal liability cap.
18.5 Individual Authorised Users. Pensieve does not assert a claim under these Terms against an individual Authorised User for a breach of 6.1 committed in the course of that individual's employment or engagement by the Customer, and looks to the Customer instead. This does not affect a claim against an individual for fraud, wilful misconduct or an act done outside that engagement, and does not affect any claim by a third party or by a public authority.
18.6 Allocation of risk. The Charges have been set on the basis of this clause. Each party acknowledges the allocation is reasonable given the nature of the Platform, the Customer's retained clinical responsibility under 16, and the Customer's own obligations under 6.2.
19.1 Where an executed agreement exists. The indemnities in MSA-IN-001 clause 17 govern, and this
clause does not apply.
19.2 Where no executed agreement exists. The Customer will indemnify Pensieve against any claim,
penalty, fine or loss arising from: the Customer's breach of 6.3, ADD-GL-004 or
ADD-GL-005; the entry of production personal data into a non-production environment contrary to
5.3; a claim by a Data Principal, a regulator or a third party arising from the Customer's own
processing, disclosure, consent practice or clinical decision; and the Customer's use of a third-party
system under 10.
19.3 Conduct. The indemnified party must notify the indemnifying party promptly, not admit liability, allow the indemnifying party to control the defence and settlement of a claim that is solely for money, and give reasonable assistance at the indemnifying party's cost. A settlement that imposes a non-monetary obligation on the indemnified party requires its consent, not to be unreasonably withheld.
20.1 Term. These Terms apply from acceptance until access ends. Where an executed agreement exists, the term of that agreement governs the Customer's access, and these Terms run with it.
20.2 Termination of Evaluation Access. Either party may terminate Evaluation Access at any time on
seven (7) days' written notice. Pensieve may terminate it immediately for a breach of 6.3, for
a use restricted under ADD-GL-005, or where required by Applicable Law.
20.3 Termination of an individual credential. The Customer may withdraw an Authorised User's credential
at any time. Pensieve may withdraw an individual credential where that individual's conduct breaches
6.1 or ADD-GL-004, after notice to the Customer except where immediate action is necessary
to protect the Platform, Customer Data or another Tenant.
20.4 Effect. On termination, the right to access the Platform ends, subject to 21. Accrued rights and liabilities are unaffected.
20.5 Survival. 1, 7, 8, 11, 16, 17, 18, 19, 21, 22, 23, 27, 28 and 29 survive, together with any provision that by its nature is intended to survive.
21.0 The principle. A hospital cannot run on a system it is afraid it cannot leave. The Customer's data is the Customer's, at all times, in a form it can use, at no charge, however access ends, including where it ends because the Customer did not pay.
21.1 The commitment. The full commitment (what is exported, in which formats, how quickly, with what
documentation and integrity evidence, and what happens to the data afterwards) is the Exit & Data
Portability Commitment (WPR-GL-400), which is published, is incorporated into these Terms, and is
contractually binding through MSA-IN-001 clause 22. It is not restated here.
21.2 Self-service. The Platform provides a self-service export of the Customer's own data. The Customer does not need Pensieve's permission, cooperation or availability to obtain a copy of its data during normal operation.
21.3 No conditions, no charge, no lien. Pensieve makes no charge for a data export, at any time, for any reason. The export is not conditional on payment of any amount, on the resolution of any dispute, on the signing of any release or waiver, or on the return of any equipment. Pensieve waives any lien, right of retention or right of set-off it might otherwise assert over Customer Data. A term anywhere purporting to permit a charge for, or a condition on, a data export is of no effect. This sub-clause is within 18.1 and cannot be limited.
21.4 Deletion. After export and the verification window, Pensieve deletes Customer Data on the timetable
in DPA-GL-001 clause 14 and DIS-GL-023, and issues a Certificate of Data Deletion & Destruction
(CRT-GL-011).
22.1 The question this clause answers. "What happens if you shut down?" Pensieve is a young company with no certifications and no long trading history. The answer is a mechanism, not a reassurance.
22.2 The mechanism. Source-code escrow, the events on which the deposit is released, the licence granted
on release, the notice period before Pensieve would cease operating the Platform, the run-out commitment
during that period and the assumptions on which it rests are stated in the Business Failure Continuity
Plan (DIS-GL-407), in POL-GL-064 and, contractually, in MSA-IN-001 clause 23 and ADD-GL-011.
They are published and are not restated here.
22.3 The headline commitments. Pensieve commits that, if it resolves to cease operating the Platform as a business, it will give at least one hundred and eighty (180) days' written notice, continue to operate and support the Platform for that period at the Charges then applying, not increase those Charges during it, provide the export at 21 on request at no charge without waiting for termination, keep the escrow deposit current, and use reasonable efforts to identify a successor supplier or migration path.
22.4 No warranty of solvency. DIS-GL-407 describes an arrangement and its limitations. It does not
warrant that Pensieve will remain solvent, and it does not pretend to.
23.1 Where an executed agreement exists. MSA-IN-001 clause 12 governs, and this clause does not
apply.
23.2 Otherwise. Each party will keep the other's confidential information confidential, use it only for the purpose for which it was disclosed, disclose it only to those who need it and who are bound by equivalent obligations, and return or destroy it on request. The obligation does not apply to information that is public other than through a breach, was already lawfully held, is independently developed, or must be disclosed by law or by a competent authority, and where disclosure is compelled, the disclosing party gives notice where it lawfully may.
23.3 Customer Data. Customer Data is the Customer's confidential information and is additionally
governed by 8 and DPA-GL-001.
23.4 Trust Center material. Material obtained from the Trust Center is governed by the Trust Center
Terms of Use (POL-GL-052) and, where it was released under an accepted non-disclosure agreement, by that
agreement.
24.1 No use without consent. Neither party may use the other's name, marks or logo, or describe the
relationship publicly, without the other's prior written consent. Consent is given, where it is given,
through the Reference & Publicity Consent (ADD-GL-020).
24.2 Withdrawal. A consent given under ADD-GL-020 may be withdrawn on thirty (30) days' written
notice, after which Pensieve removes the reference from material it controls at its next publication cycle.
25.1 Complaints. A complaint about the Platform, about Pensieve's conduct, or about these Terms is made
under the Grievance Redressal Policy (POL-GL-066) to info@pensievelabs.org. That policy
states the acknowledgement and resolution timelines and the escalation path, and is not restated here.
25.2 Data protection grievances. A grievance about personal data Pensieve processes as a Data Fiduciary
is handled under POL-GL-066 and the Privacy Policy (POL-GL-053). A grievance about personal data
processed through the Platform on the Customer's instructions is directed to the Customer, which is the
Data Fiduciary.
25.3 Commercial disputes. A dispute under an executed agreement follows the dispute resolution clause
in that agreement (MSA-IN-001 clause 25). 27 applies only where no executed agreement
covers the dispute.
26.1 Right to change. Pensieve may change these Terms and the policies incorporated under
2.3. Every version is published at https://trust.pensievelabs.org with a version number, a
Last Modified On date and a change history, and superseded versions remain retrievable.
26.2 Notice. Pensieve gives thirty (30) days' notice of a change that is material and adverse to the Customer, by email to the Customer's notified contacts and by publication. A change that is clarificatory, that is required by Applicable Law, or that is favourable to the Customer takes effect on publication, and Pensieve says which it is.
26.3 The Customer's right where a change is material and adverse. Where a change is material and adverse and the Customer objects in writing within the notice period, the parties will discuss it. If it is not resolved within thirty (30) days, the Customer may terminate the affected part of the agreement on notice, with a pro-rata refund of prepaid Charges for the terminated part, and 21 applies. The Customer is not required to accept a material adverse change as the price of keeping access to its own data.
26.4 What cannot be changed unilaterally. Pensieve will not use this clause to reduce the commitments
at 7.3 (no training on Customer Data), 21.3 (no charge and no conditions on
export), 22.3 (run-out notice period) or WPR-GL-400. A change to any of those requires the
Customer's written agreement.
26.5 Executed agreements are unaffected. A change to these Terms does not amend an executed Master Services Agreement, Data Processing Agreement, Order Form or addendum. Those are amended only in writing signed by both parties.
27.1 Governing law. These Terms, and any non-contractual obligation arising out of or in connection
with them, are governed by the laws of the laws of India.
27.2 Jurisdiction. The courts at Legal jurisdiction have exclusive jurisdiction, save that either
party may apply for urgent interim relief in any court of competent jurisdiction.
27.3 Where an executed agreement exists. The governing law and dispute resolution provisions of that agreement govern and displace this clause.
| Purpose | Contact |
|---|---|
| Legal notices | info@pensievelabs.org |
| Privacy and data protection | info@pensievelabs.org |
| Grievance Officer (statutory) | [TO BE SUPPLIED], info@pensievelabs.org |
| Security incidents and vulnerability reports | info@pensievelabs.org |
| Support | info@pensievelabs.org, [TO BE SUPPLIED] |
| Billing | info@pensievelabs.org |
| General | info@pensievelabs.org, [TO BE SUPPLIED] |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` | |
| Trust Center | https://trust.pensievelabs.org |
A notice to Pensieve under these Terms is given in writing to info@pensievelabs.org. Electronic mail is
a valid method of service, and a requirement of writing is satisfied by it under section 4 of the
Information Technology Act, 2000 where Indian law applies.
29.1 Assignment. You may not assign or transfer your rights under these Terms without Pensieve's written consent. Pensieve may assign to an Affiliate or to a successor of its business on written notice, provided the assignee assumes its obligations.
29.2 Entire agreement. Together with the documents in 2.3 and, where one exists, the executed agreement, these Terms are the entire agreement on their subject matter and supersede any prior statement, except that nothing excludes liability for fraudulent misrepresentation.
29.3 Severability. If a provision is held invalid or unenforceable, it is modified to the minimum extent necessary to make it enforceable, or, if that is not possible, severed. The rest continues in effect.
29.4 Waiver. A failure or delay in exercising a right is not a waiver of it. A waiver is effective only in writing and only for the instance given.
29.5 No partnership or agency. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship.
29.6 Third-party rights. A person who is not a party has no right to enforce these Terms, except that an Affiliate of Pensieve that provides part of the Platform may rely on 17 and 18.
29.7 Force majeure. Neither party is liable for a failure to perform caused by an event beyond its reasonable control which makes performance impossible or unlawful despite its best efforts, provided it notifies the other and mitigates. A party's inability to pay is never a force majeure event, and 21 continues to operate during one.
29.8 Electronic execution and records. Where acceptance is recorded electronically, the record of acceptance (including the accepted version identifier, the timestamp, the accepting identity and the network address) is evidence of acceptance. Neither party will contend that acceptance is invalid solely because electronic means were used.
29.9 Language. These Terms are written in English. Where Pensieve supplies a translation, the English version governs in the event of a conflict, except where Applicable Law requires otherwise.
| Subject | Document that owns it |
|---|---|
| Commercial relationship, liability caps, indemnities, exit assistance | MSA-IN-001 |
| Processing of personal data, breach notification, sub-processors, audit | DPA-GL-001 |
| Availability, support hours, severities, service credits | SLA-GL-001 |
| Security controls and the shared-responsibility split | ADD-GL-001 |
| Conduct required of users | ADD-GL-004 |
| Purposes for which the Platform must not be used | ADD-GL-005 |
| Credential custody for third-party systems | ADD-GL-007, DIS-GL-025 |
| Deployment model definitions | WPR-GL-004 |
| Clinical safety boundary, feature by feature | DIS-GL-028 |
| Subprocessor list | DIS-GL-009 |
| Deletion and return | DIS-GL-023 |
| Exit and data portability | WPR-GL-400 |
| End-of-life and deprecation notice periods | POL-GL-064 |
| What happens if Pensieve fails | DIS-GL-407 |
| Personal data Pensieve holds as Data Fiduciary | POL-GL-053 |
| Complaints and the statutory grievance route | POL-GL-066 |
| Demands from public authorities | POL-GL-067 |
| Trust Center access conditions | POL-GL-052 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. Establishes the three functions of these Terms, the order of precedence against MSA-IN-001, the user-level obligations, the clinical safety boundary, the no-training-on-Customer-Data commitment, the unconditional export right, and the change-notice regime with a protected core that cannot be varied unilaterally. |
POL-GL-050 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 July 2027 | Published at https://trust.pensievelabs.org | Classification
PUBLIC