Search all 586 artefacts by title, document ID or content.
Statement | Family 3, Security, Privacy & Trust Disclosures
This Statement is written for four readers, in this order. A public authority preparing to serve process on Edsol Edtech Pvt. Ltd., who needs to know where to serve it, what it must contain, and who actually holds the records being sought. A hospital's data protection officer or board, deciding what a vendor can be…
This document is the source of truth for: trust:/legal/government-access, trust:/documents/STM-GL-037, marketing:/legal/government-access
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
STM-GL-037 | Version 1.2.0 | Effective 29 August 2026 | Last Modified On 29 August 2026
This Statement is written for four readers, in this order. A public authority preparing to serve process on
Edsol Edtech Pvt. Ltd., who needs to know where to serve it, what it must contain, and who actually holds
the records being sought. A hospital's data protection officer or board, deciding what a vendor can be
compelled to hand over before signing. A patient or a member of hospital staff, who is entitled to read the
same answer as everyone else. And a supervisory authority checking that a published disclosure required by
Regulation (EU) 2023/2854 Article 28(1) exists, is complete, and is current.
There are two documents on this subject and the division between them is deliberate. The Legal and Law
Enforcement Request Policy (POL-GL-067) is the handling policy: it governs the internal process by which
a demand is received, authenticated, reviewed, redirected, narrowed, challenged, answered and recorded, and
it is gated. This Statement carries the commitments Edsol Edtech Pvt. Ltd. is willing to be held to in
public. POL-GL-501 clause 1.4 provides that a publishable companion to a gated document is a separate
document with its own identifier, its own tier and its own review date, and is never a redacted serving of
one identifier; that is why this Statement exists rather than a shortened POL-GL-067. Where this
Statement and POL-GL-067 diverge on process, POL-GL-067 governs.
| Question | DM-1 Dedicated |
DM-2 Shared |
DM-3 Customer Cloud |
DM-4 On-Premise |
|---|---|---|---|---|
| Position | Pensieve Labs operates the environment and can be compelled in respect of it |
As DM-1, scoped to the single tenant |
The hospital owns the project and the account | The hospital owns the hardware and holds the only copy |
| Who owns the infrastructure | Edsol Edtech Pvt. Ltd., in its own cloud project in the deployment region recorded on the Order Form |
Edsol Edtech Pvt. Ltd., in the regional shared estate |
The hospital, in the hospital's own cloud account | The hospital, on its own premises |
| Who should be served | The hospital as Data Fiduciary first, then Edsol Edtech Pvt. Ltd. if the authority is entitled to proceed against it |
As DM-1 |
The hospital. It owns the project, the billing account and the data | The hospital. Edsol Edtech Pvt. Ltd. holds no copy to produce |
| Provider of a data processing service within Regulation (EU) 2023/2854 | Yes | Yes | Yes, in respect of the service Pensieve Labs operates inside the hospital's project |
No |
The disclosure at 7 is given for all four models, and in every market, whether or not the
Regulation reaches the deployment. Deployment model definitions are owned by WPR-GL-004 and are not
restated here. The reading order for the whole sovereignty estate is DIS-GL-038.
1.1 Address for service.
| Field | Detail |
|---|---|
| Entity | Edsol Edtech Pvt. Ltd. (Pensieve Labs) |
| Corporate Identity Number | [TO BE SUPPLIED] |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` | |
| E-mail for legal process | info@pensievelabs.org |
| Emergency requests involving a risk to life | info@pensievelabs.org with "EMERGENCY DISCLOSURE REQUEST" in the subject line. There is no telephone route: Edsol Edtech Pvt. Ltd. publishes no number for legal process, and POL-GL-067 clause 6.2 requires an emergency request to be in writing in any event. 1.1.2 states the position in full rather than printing an empty field in the one time-critical row of a public document |
| CERT-In Point of Contact filing | Filed under Direction (iii) of the CERT-In Directions of 2022; the acknowledgement is published in redacted form |
1.1.1 Two facts this Statement adds, outside the reproduced table. These are not part of POL-GL-067
clause 2.1 and are kept separate so that the table above stays a faithful reproduction of it.
Edsol Edtech Pvt. Ltd. does not transmit a production over an unencrypted
channel.Edsol Edtech Pvt. Ltd.. There is none to find. One named legal owner receives every
demand, and no other person may answer one (POL-GL-067 clause 4.1).1.1.2 There is no telephone route for legal process, and this Statement will not print a slot where a
number should be. Through version 1.1.0 the emergency row above offered info@pensievelabs.org and a
telephone number carried as a token. Edsol Edtech Pvt. Ltd. has not published a general or an emergency
telephone number, so that token had no value and the row rendered, to an authority reading this page, as an
address followed by nothing. A time-critical channel that resolves to an empty field is worse than a
channel that is honestly absent, so the row now states the written route alone.
Three things follow, and an authority is entitled to all three:
POL-GL-067 clause 6.2 requires an emergency
request to be in writing, from an official address, stating the nature of the emergency, identifying the
person at risk and identifying the specific data sought, before anything can be disclosed. A telephone
call could never have been the disclosure route; it could only ever have been a way of announcing an
e-mail. The Director signs off every emergency disclosure (POL-GL-067 clause 6.2).POL-GL-067 clause 4.1), which is the same fact recorded at 1.1.1 as the absence of an
escalation chain.DM-3 and DM-4 Edsol Edtech Pvt. Ltd. holds no copy to produce and the
hospital is the only holder, and in DM-1 and DM-2 the hospital should be served first. The
Applicability table at the head of this Statement states which applies. An authority facing a risk to life
in a DM-3 or DM-4 deployment reaches the records fastest by serving the hospital, not
Edsol Edtech Pvt. Ltd., whatever channel it uses.A telephone number for legal process is an open item, owned by the Founder. When one exists it is
seeded at entity.phone.general, this row carries it, and the change is recorded in the change history
below. This Statement does not assert a date for it, because no date has been decided, and Section 10.1
requires this page to move when the fact moves rather than when a claim is convenient.
1.2 What a demand must contain. Without each of these, Edsol Edtech Pvt. Ltd. cannot act and will say
so:
1.2.1 the issuing authority, the officer's name, designation and official contact details;
1.2.2 the legal power relied on, cited by statute and provision;
1.2.3 the specific data sought, identified by account, tenant, individual, date range and data type, and not by the words "all data relating to";
1.2.4 the purpose, and how the data sought is relevant and proportionate to it;
1.2.5 the date by which a response is required;
1.2.6 whether notification to the affected customer or individual is prohibited, and if so under which provision and for how long; and
1.2.7 a secure channel for delivery.
1.3 What this Statement reproduces from POL-GL-067, and why each one. POL-GL-067 is gated. The
test for reproducing any part of it here is narrow and is applied clause by clause: the passage must be
one a reader holding no credential has to be able to act on. On that test, and under POL-GL-501
clause 1.4, this Statement reproduces the following and no others.
POL-GL-067 clause |
Reproduced at | Why a credential-less reader must be able to read it |
|---|---|---|
| 2.1 Address for service | 1.1 | An address for service that can only be read by the party being served is not an address for service |
| 2.2 What a request must contain | 1.2 | An authority cannot meet requirements it cannot see, and a demand that fails them is refused |
| 2.3 What Pensieve will not act on | 1.4 | The same reason, stated negatively |
| 3.1 The redirect rule | 3.1 | An authority is entitled to know before it serves that it will be told to serve the hospital |
| 3.3 What Pensieve does not do | 3.4 | Two falsifiable negative facts, worth nothing if only the customer can read them |
| 9.1 No back door | 8.1 | A negative commitment behind a gate reassures nobody it is addressed to |
| 9.2 No weakened cryptography | 8.3 | As above |
| 9.3 The honest limit | 5.2 | A candid limit that only a credentialed reader can see is worth nothing |
| 5.4 No voluntary non-disclosure undertaking | 8.6 | It is a commitment made to authorities, and authorities hold no credential |
| 5.5 A prohibition is stated, never reported as zero | 4.3 and 8.9 | It is the sentence that tells a reader what silence in 8 would and would not mean |
Separately, and not as reproduced text, the table at 4 publishes windows that POL-GL-067
owns, naming the owning clause in its own third column: clause 5.1 for notice before disclosure,
clause 5.3 for the reserved delay and clause 6.3 for notice after an emergency disclosure. Publishing a
window beside the clause that owns it is not the same as restating that clause, and the four windows in
that table that are new to this Statement are marked as such at 4.1.
Every other part of POL-GL-067 is cited and not reproduced, including its process at clause 4, its
reasons at clause 3.2, its preservation rule at clause 2.4, its notice mechanism at clause 5.2, its
architecture point at clause 9.4 and its records, retention and reporting at clause 10. POL-GL-067
governs if the two ever diverge on any reproduced passage, and any divergence is a defect in this
Statement, corrected under 10.
1.4 What Edsol Edtech Pvt. Ltd. will not act on. An oral request. A request from a non-official
address. A request that identifies no legal power. A request for bulk or indiscriminate access. Also, and
for completeness, a request from a foreign authority that has not proceeded through a lawful channel
(6) and a request to create data that does not exist. The closed list is POL-GL-067
clause 2.3.
This is the fact this Statement owns. POL-GL-067 clause 7 states what Edsol Edtech Pvt. Ltd. can produce
on a valid demand; this Section states whose law reaches each class of data and against whom process
should be served. On the production position POL-GL-067 clause 7 governs.
2.1 How to read the matrix. Each cell answers three things in a fixed order. Law: the legal system
that reaches the data. Serve: the entity that must be served to reach it. Plaintext: whether
Edsol Edtech Pvt. Ltd. is in a position to produce readable content.
| Data class | DM-1 |
DM-2 |
DM-3 |
DM-4 |
|---|---|---|---|---|
| Customer Data at rest | Law: the law of the deployment region recorded on the Order Form, market by market at 7.1, and Indian law as it reaches Edsol Edtech Pvt. Ltd.. Serve: the hospital first, then Edsol Edtech Pvt. Ltd.. Plaintext: Yes |
Law: as DM-1. Serve: as DM-1, and production is scoped to the single tenant. Plaintext: Yes |
Law: the law of the region the hospital selects in its own account. Serve: the hospital. Plaintext: Only while the hospital's delegated grant and its key remain enabled | Law: the law of the place where the hospital's premises are. Serve: the hospital. Plaintext: No. Edsol Edtech Pvt. Ltd. holds no copy |
| Backups | Law and serve: as the row above. Backups do not leave the deployment region. Plaintext: Yes | As DM-1. Plaintext: Yes |
Law: the hospital's project and its configured location. Serve: the hospital. Plaintext: As the row above | Law: wherever the hospital keeps its media. Serve: the hospital. Plaintext: No |
| System and audit logs | Law: the deployment region, with the Indian localisation duty in DIS-GL-034. Serve: Edsol Edtech Pvt. Ltd.. Plaintext: Yes |
As DM-1. Plaintext: Yes |
Law: the hospital's project. Serve: the hospital, which owns the logs. Plaintext: Only through the delegated grant | Law: the hospital's own log storage. Serve: the hospital. Plaintext: No |
| Encryption keys | Law: the key management service of the deployment region. Serve: Edsol Edtech Pvt. Ltd., which owns the key ring. Plaintext: Yes, and it can be ordered to use the keys |
As DM-1, on the per-tenant arrangement in DIS-GL-011. Plaintext: Yes |
Law: the hospital's own key management service. Serve: the hospital. Plaintext: No. Edsol Edtech Pvt. Ltd. never holds the key material |
Law: the hospital's on-premise key store. Serve: the hospital. Plaintext: No |
| Support correspondence and Ticket metadata | Law: the region of the tenancy the Ticket belongs to. Serve: Edsol Edtech Pvt. Ltd.. Plaintext: Yes. Patient data must never be placed in a Ticket |
As DM-1. Plaintext: Yes |
Law: as DM-1, because the Ticket sits in the Pensieve Labs-operated estate even though the Platform does not (DIS-GL-009 Section 5.2). Serve: Edsol Edtech Pvt. Ltd.. Plaintext: Yes |
As DM-3. Plaintext: Yes |
| Trust Center access records | Law: the jurisdictions of the Trust Center entities at DIS-GL-009 Section 3. Serve: Edsol Edtech Pvt. Ltd., or one of those entities directly (6.3). Plaintext: Yes. No patient record reaches this stack |
As DM-1 |
As DM-1 |
As DM-1 |
Edsol Edtech Pvt. Ltd.'s own business records |
Law: Indian law. Serve: Edsol Edtech Pvt. Ltd.. Plaintext: Yes |
As DM-1 |
As DM-1 |
As DM-1. This is the whole of what Edsol Edtech Pvt. Ltd. can produce under DM-4 |
2.2 The DM-3 answer, stated without flattery. Under DM-3 the encryption keys are the hospital's,
and if the hospital disables or destroys a key Edsol Edtech Pvt. Ltd. cannot decrypt (DIS-GL-011). That
is not the same as saying Edsol Edtech Pvt. Ltd. can produce nothing. While the hospital's delegated
administrative grant subsists, that access could be turned to a production, and an honest statement says
so. What limits it is that the hospital grants and revokes the access itself, immediately, unilaterally,
without notice and without Pensieve Labs's cooperation, and that every action Pensieve Labs takes
appears in the hospital's own audit logs, which Pensieve Labs cannot alter or delete (DIS-GL-033).
A hospital that wants the DM-3 answer to be absolute revokes the grant.
2.3 The honest ranking of compellability. If what can be compelled from Edsol Edtech Pvt. Ltd. is the
hospital's controlling concern, DM-4 answers it absolutely, DM-3 answers it structurally, and DM-1
and DM-2 answer it procedurally and contractually, because in those two models Pensieve Labs holds
the keys and can be ordered to use them. This ranks the same way, and for the same reasons, as the
residency ranking in DIS-GL-008, and WPR-GL-004 states what each model costs in schedule and money.
2.4 What this Section deliberately does not restate. What data exists and where it is held is
DIS-GL-008. The vocabulary in which residency and sovereignty are described is DIS-GL-038. The key
hierarchy is DIS-GL-011, the access model is DIS-GL-033, and the log localisation configuration is
DIS-GL-034. None of them is reproduced here.
3.1 The rule. Where a demand seeks records inside a hospital's tenant, Edsol Edtech Pvt. Ltd.'s first
action is to tell the authority that the hospital is the Data Fiduciary, that the hospital holds and
controls those records, and that the demand should be directed to the hospital.
3.2 Why. Because the hospital determines the purposes and means of that processing and is better
placed than Edsol Edtech Pvt. Ltd. to judge privilege, statutory confidentiality, medico-legal status and
whether a narrower production would satisfy the demand. The reasons are set out at POL-GL-067 clause 3.2
and are not restated here.
3.3 What follows if the authority declines. Where the authority declines to redirect, or is legally
entitled to proceed against Edsol Edtech Pvt. Ltd., the handling process at POL-GL-067 clause 4 runs.
The redirect rule and its consequences are owned by POL-GL-067 clause 3.
3.4 Two negative facts. Edsol Edtech Pvt. Ltd. does not volunteer a hospital's records to an authority
that has not asked the hospital. And a demand addressed to Edsol Edtech Pvt. Ltd. is not permission to
search a tenant.
| Event | Window | Owner of the commitment |
|---|---|---|
| Notice to the affected customer before disclosure | The default in every case. Enough detail and enough time for the customer to take its own advice and challenge the demand itself | POL-GL-067 clause 5.1 |
| Notice after an emergency disclosure | Within 5 Business Days of the disclosure, unless prohibited | POL-GL-067 clause 6.3 |
Notice delayed by Edsol Edtech Pvt. Ltd., without a prohibition |
Reserved, and narrow: where notifying would create a risk of death or serious harm, or would defeat an investigation into a risk to a child. The reason is recorded, and notice is given as soon as the risk passes | POL-GL-067 clause 5.3 |
| Notice after a prohibition on notice lapses | Within 5 Business Days of the prohibition ending or expiring, without Edsol Edtech Pvt. Ltd. being asked |
This Statement, mirrored into POL-GL-067 clause 5.2.3 |
| A preservation request acted on | Within 1 Business Day of receipt | This Statement, mirrored into POL-GL-067 clause 2.4 |
| A preservation held | For no longer than 90 days | This Statement, mirrored into POL-GL-067 clause 2.4 |
| A preservation extended | Once only, on a further written request that meets 1.2 | This Statement, mirrored into POL-GL-067 clause 2.4 |
| Customer told a preservation has lapsed without a production order | On lapse, unless prohibited | This Statement, mirrored into POL-GL-067 clause 2.4 |
4.1 Four of these were new in version 1.0.0, and the amendment that mirrors them has landed. The
preservation figures and the five-day gag-lapse window are commitments this Statement introduced.
POL-GL-067 clause 2.4 previously recorded that a preservation is time-limited, recorded and not itself an
authority to disclose, without publishing a number, and its clause 5.2.3 committed to notice on the ending
of a prohibition without publishing a window. Both are now mirrored: POL-GL-067 version 1.1.0 carries
the four preservation figures at its new clause 2.4.1 and the five Business Day gag-lapse window at its
clause 5.2.3. Those are rows A-2 and A-3 at 10.3, both landed. The Policy and this Statement
state the same windows, and if they ever diverge POL-GL-067 governs.
4.2 Preservation is not disclosure. That a preservation is acted on without waiting for a production
order, is time-limited and recorded, and does not itself authorise disclosure of anything, is
POL-GL-067 clause 2.4. This Statement adds only the figures in the table above.
4.3 The gag rule. Where notice is prohibited, Edsol Edtech Pvt. Ltd. complies with the prohibition
and then works to lift it. What it does, in what order, is POL-GL-067 clause 5.2, which owns the
mechanism and is not restated here; the published window on the lapse of a prohibition is the row above.
It gives no voluntary non-disclosure undertaking (8.6). Where a prohibition reaches even an
aggregate figure, POL-GL-067 clause 5.5 requires Edsol Edtech Pvt. Ltd. to state that a prohibition
applies rather than report zero.
5.1 The closed list. Edsol Edtech Pvt. Ltd. challenges a demand in every case on any of these six
grounds, and does not treat a challenge as discretionary where one applies:
5.1.1 the issuing authority is not competent to make the demand;
5.1.2 the demand cites no legal power, or cites one that does not reach the data sought;
5.1.3 the scope is broader than is necessary and proportionate to the stated purpose;
5.1.4 the data sought belongs to, or would necessarily include, another hospital's tenant;
5.1.5 the demand carries a prohibition on notice with no statutory basis; or
5.1.6 the demand is from a foreign authority and has not proceeded through a lawful channel (6.1).
Narrowing precedes disclosure in every case, and disclosure is of the minimum the demand covers after
narrowing. The sequence is POL-GL-067 clause 4, steps 5 to 8.
This closed list was stricter than the Policy when version 1.0.0 published it, because clause 4 step 6
then required a challenge "where there is a reasonable basis" and left the grounds unenumerated.
POL-GL-067 version 1.1.0 now carries the same six grounds at clause 4 step 6, as a closed list on which a
challenge is mandatory, keeping the reasonable-basis limit on pursuing an appeal so that 5.4 is
not contradicted. That is row A-6 at 10.3, landed. The Policy and this Statement now state one
list, and POL-GL-067 governs on process.
5.2 The honest limit, published rather than gated. Edsol Edtech Pvt. Ltd. cannot undertake to defeat
a lawful order of a court or authority of competent jurisdiction, and does not undertake it here. Indian
law contains compulsion powers, including under section 69 of the Information Technology Act, 2000 and the
rules made under it, section 5(2) of the Indian Telegraph Act, 1885, the production powers of the criminal
procedure statute, and section 70B(6) of the Information Technology Act, 2000 in relation to CERT-In
directions. Comparable powers exist in every market Pensieve Labs serves. This limit is stated in
POL-GL-067 clause 9.3, and it is repeated in public because a candid limit that only a credentialed
reader can see is worth nothing. A vendor that claims a contractual promise can defeat a lawful order is
not describing something that exists.
5.3 What actually determines the exposure. The architecture rather than the promise, for the reasons
POL-GL-067 clause 9.4 gives. That is why 2 is the load-bearing section of this Statement and
this one is not. The assessment of Indian compulsion powers instrument by instrument is REP-GL-021
Sections 4.1 and 4.2, and is not reproduced here.
5.4 No promise of unlimited litigation. Edsol Edtech Pvt. Ltd. commits to the six grounds above, to
narrowing, and to pursuing an available appeal where there is a reasonable basis. It does not promise to
litigate every demand to exhaustion at its own cost regardless of merit, because that is a promise no
company of its size could keep and a reader is entitled to the version that is true.
Edsol Edtech Pvt. Ltd. does not disclose data to a foreign authority on the strength of that
authority's own domestic process alone. A foreign demand must proceed through a mutual legal assistance
treaty, a letter rogatory, or another route that produces a demand enforceable against
Edsol Edtech Pvt. Ltd. in the jurisdiction where it holds the data.
The reasons are three, and each is external to Pensieve Labs. Complying outside a lawful channel would
breach Edsol Edtech Pvt. Ltd.'s obligations to its customer. Article 48 of the General Data Protection
Regulation provides that a judgment or decision of a third-country authority requiring a transfer or
disclosure is recognisable or enforceable only on the basis of an international agreement in force. Rule 15
of the Digital Personal Data Protection Rules, 2025 addresses making personal data available to a foreign
State, or to a person or entity under the control of or an agency of such a State, and
Edsol Edtech Pvt. Ltd. treats a foreign authority demand as engaging that rule. The full rule is
POL-GL-067 clause 8.
Regulation (EU) 2023/2854 Article 32 sets conditions on a provider of data processing services before it
may act on a third-country decision requiring transfer of, or access to, non-personal data held in the
Union. Edsol Edtech Pvt. Ltd. applies those conditions in every market it serves and not only in the
Union, because a company that would apply a lower standard to an Indian, Australian or Emirati hospital
than to a Danish one has not adopted a standard at all. POL-GL-067 version 1.1.0 records the same
global application at its new clause 8.6, which names this Section as the owner of the four recognition
conditions, the minimum-permissible-amount rule and the notification duty. That is row A-7 at
10.3, landed.
6.2.1 The recognition test, in four conditions. A third-country decision is recognised or acted on only where:
(a) it is based on an international agreement in force between the requesting third country and the Union, or between that third country and the relevant Member State, which is the condition at Article 32(1); or, in the absence of such an agreement, where each of the following is true:
(b) the third-country system requires the reasons and the proportionality of the decision to be set out, and requires the decision to be specific in character, for instance by establishing a sufficient link to certain suspected persons or infringements (Article 32(2)(a));
(c) the reasoned objection of the addressee is subject to review by a competent third-country court or tribunal (Article 32(2)(b)); and
(d) that court or tribunal is empowered under the law of that third country to take duly into account the legal interests of the provider of the data protected by Union law or the national law of the relevant Member State (Article 32(2)(c)).
6.2.2 The minimum permissible amount. Where a demand is acted on, Edsol Edtech Pvt. Ltd. provides the
minimum amount of data permissible in response, on a reasonable interpretation of the request
(Article 32(4)). This is the same discipline as POL-GL-067 clause 4 step 8, applied to a foreign demand.
6.2.3 The notification duty. Edsol Edtech Pvt. Ltd. informs the data holder of the existence of a
third-country authority's request to access its data, except where the request serves law enforcement
purposes and for as long as that is necessary to preserve the effectiveness of the law enforcement activity
(Article 32(3)). Where that exception applies, 4 governs when notice is given instead.
6.2.4 Where the conditions are not met. Edsol Edtech Pvt. Ltd. does not transfer or give access, and
challenges the decision on ground 5.1.6.
A demand need not be served on Edsol Edtech Pvt. Ltd. to reach data associated with a hospital. It can be
served on a sub-processor, and in that case Edsol Edtech Pvt. Ltd. may never be told it happened. That
is stated here because it is the exposure a reader is most likely to miss, and because a statement that
described only the demands Pensieve Labs receives would be describing half the risk.
6.3.1 The entities. DIS-GL-009 is the register of record. As at the date on the face of this
document, the entities incorporated in the United States that appear in it are: Vercel, Inc., which
hosts the Trust Center application; Neon, Inc., which operates the Trust Center database; Plus Five
Five, Inc., trading as Resend, which delivers transactional e-mail; and Upstash, Inc., which operates
the Trust Center rate limiter. Those four are the Trust Center and corporate sub-processors at DIS-GL-009
Section 3. The platform sub-processor at DIS-GL-009 Section
2.1 contracts through an entity incorporated in the market of the deployment, and its group parent, Google
LLC, is incorporated in the United States.
6.3.2 The mitigation, stated as a fact and not as a promise. The Trust Center stack holds no patient
data. It processes the names, work e-mail addresses and document access records of a hospital's
authorised users, the contract and disclosure documents exchanged during a deal, and, on the rate-limiting
path, a per-window counter keyed by the caller's network address or account identifier and holding no
document content (DIS-GL-009 Section 3.4). It is a separate
application from the Platform and is not connected to any hospital's Platform instance. That is the
position recorded in DIS-GL-009 Section 3, and it is what bounds this exposure.
6.3.3 The contractual answer, and the part of it that is not yet in force. The minimum terms every
sub-processor contract must contain are POL-GL-135 Section 4.3.2, which now requires the government
access term at that Policy's Section 4.3.5. POL-GL-135 version 1.1.0 carries it: the sub-processor must
notify Edsol Edtech Pvt. Ltd. before disclosing unless notification is prohibited by law, must ask the
authority to lift or narrow a prohibition and notify as soon as it ends, must challenge the demand where
there is a reasonable basis and pursue an available appeal, and must disclose only the minimum the demand
compels after narrowing. That is row A-4 at 10.3, landed. Two limits are stated rather than
left to be found. First, the term binds a sub-processor to challenge where there is a reasonable basis,
which is weaker than the closed list 5.1 binds Edsol Edtech Pvt. Ltd. to, because a term
negotiated with a third party is not a commitment about Pensieve Labs's own conduct. Second, the term
reaches only sub-processor contracts entered into, renewed or varied on or after the date on the face of
POL-GL-135 version 1.1.0: each contract in force before that date is brought into line at its next
renewal or at the next quarterly review, whichever is earlier, and until it is, that sub-processor is an
open contractual gap recorded in REG-GL-202 under POL-GL-135 Section 4.3.3, with the population still
outstanding reported at each management review (POL-GL-135 Section 4.3.6). An unamended contract is not
evidence that the term is in force, and this Statement does not present it as one. What the term is worth
against a sub-processor under a non-disclosure order is assessed at REP-GL-032 Section 4.1.3.
6.3.4 The assessment. The transfer impact assessment for the infrastructure and sub-processor leg is
REP-GL-032, and it is the document that assesses this exposure. The assessment of the EEA to India leg,
covering Pensieve Labs's own personnel access, is REP-GL-021. Neither is restated here.
This Section is the disclosure required by Regulation (EU) 2023/2854 Article 28. It is sub-headed so that a regulator can find each limb without reading the rest of the document.
| Service | Contracting provider entity | Jurisdiction of the deployment region | Jurisdiction of incorporation of that entity | Ultimate parent | Parent's jurisdiction |
|---|---|---|---|---|---|
Platform, DM-1 |
Google Cloud India Private Limited for Customers contracting in India; Google Cloud EMEA Limited or the applicable Google entity elsewhere, as recorded on the Order Form | The deployment region recorded on the Order Form. India: an Indian region, and no Customer Personal Data leaves India (DIS-GL-008 Section 4). Australia: an Australian region (Section 5). Denmark and Norway: a European Union region (Section 7, with DIS-EU-008). United Arab Emirates: a region physically inside the UAE, on the separate architecture at Section 6 and DIS-AE-008 |
India; Ireland respectively | Alphabet Inc. Group parent: Google LLC | United States |
Platform, DM-2 |
As DM-1, per regional estate |
As DM-1, on the regional shared estate for that market |
India; Ireland respectively | Alphabet Inc. Group parent: Google LLC | United States |
Platform, DM-3 |
The hospital's own cloud provider, contracted directly by the hospital. Edsol Edtech Pvt. Ltd. is not a party to that contract |
The region the hospital selects in its own account | Recorded in the hospital's own agreement, not in Pensieve Labs's |
Recorded in the hospital's own agreement | Recorded in the hospital's own agreement |
Platform, DM-4 |
None. There is no cloud provider | The place where the hospital's premises are | Not applicable | Not applicable | Not applicable |
| Trust Center, application hosting | Vercel, Inc. | United States, with edge delivery from the network region nearest the visitor | United States. The State of incorporation is not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
| Trust Center, database | Neon, Inc. | Singapore. The Trust Center database project is in the provider's Singapore region, recorded in the deployment record, and the project's region configuration is shown to any Customer that asks for it (DIS-GL-009 Section 3.2) |
United States. The State of incorporation is not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
| Trust Center, rate limiting | Upstash, Inc. | The region selected for the Trust Center rate-limit database, recorded in the deployment record. DIS-GL-009 Section 3.4 does not name the country. Entered in that register on 21 August 2026, the date the rate limiter was configured in production |
United States. The State of incorporation is not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
| Scaffold, the Support Center | The Section 2.1 entity above | The region of the tenancy the Ticket belongs to | India; Ireland respectively | Alphabet Inc. Group parent: Google LLC | United States |
| Transactional e-mail | Plus Five Five, Inc., trading as Resend | United States | United States. The State of incorporation is not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
Not yet verified in DIS-GL-009 |
7.1.1 DIS-GL-009 is the register of record. Every value in the table above is derived from
DIS-GL-009 Sections 2.1 and 3 and from DIS-GL-008. Where the two differ, DIS-GL-009 is current and
this table is the defect. The Ultimate parent column reproduces two different fields and says which is
which, because DIS-GL-009 Section 2.1 distinguishes them: the group parent of the contracting entity
is Google LLC, and the ultimate parent of the group is Alphabet Inc., a United States company. Article
28(1)(a) asks which jurisdiction the infrastructure is subject to, and the answer runs to the top of the
ownership chain, so the column carries the ultimate parent and names the group parent beside it rather than
stopping one level short. Where a cell in that column reads that the parent is not yet verified, it is
reproducing an unverified field from DIS-GL-009 Section 3 and not withholding a known answer. This table is updated within 5 Business Days of the DIS-GL-010 notice being
issued, not within 5 Business Days of the change landing. Customers receive thirty (30) days' prior
notice of an addition, replacement or change of processing location under DPA-GL-001 clause 8.4, and a
public page that moved only after the change would lag the notice by a month. Moving with the notice is
what keeping the page up to date means here and what 10.1 commits. A change that is made
without a DIS-GL-010 notice, because none is required, is picked up on the DIS-GL-009 trigger at
10.1.1.
7.1.2 Two limits of this disclosure, stated rather than hidden, and one that has closed. First,
DIS-GL-009 records a group parent and a State of incorporation for the platform sub-processor and records
neither for the four Trust Center and corporate entities. Those cells read not yet verified, which
DIS-GL-009 Section 3 defines as a field recorded but not yet read off a public corporate record, owned by
Security and due at that register's own review date. Edsol Edtech Pvt. Ltd. does not assert a corporate
parent it has not verified, so this table carries the same answer rather than a name. Second, and on the
limb the Article actually mandates, one row names no jurisdiction of processing: DIS-GL-009 Section 3.4
records the rate-limit database's location as the region selected for that project in the deployment record
and does not name the country. Edsol Edtech Pvt. Ltd. will not invent one for a public disclosure. The
Trust Center database row no longer carries that limit, which version 1.0.0 recorded as open:
DIS-GL-009 Section 3.2 now names Singapore, and this table names it too. Both open cells are review
actions at 10.1, and until they are completed a reader should treat the Article 28(1)(a)
answer for those rows as the jurisdiction of incorporation column only, which is answered in full.
7.1.3 The United Arab Emirates. The default infrastructure cannot be used for a UAE deployment and the
provider is selected per deal and recorded as a separate entry in DIS-GL-009. The reason, and the
architecture that replaces it, are DIS-GL-008 Section 6. Until a UAE deployment exists, no such entry and
no such row exists.
A general description, as the Article requires, of the technical, organisational and contractual measures adopted to prevent international governmental access to or transfer of non-personal data held in the Union where that access or transfer would conflict with Union law or the national law of the relevant Member State. Each measure names the artefact that owns it; none of them is configured or specified here.
7.2.1 Technical. The first, fourth, fifth and sixth measures below are true in all four deployment
models. The second and third describe infrastructure and are DM-1 and DM-2 statements: under
DM-3 the log storage and the key ring sit in the hospital's own project and are the hospital's, and under
DM-4 both are the hospital's own, as 2 states. They are marked rather than left to be
assumed.
DIS-GL-008 Section 2).DM-1 and DM-2: log buckets are regional and not global, so log data cannot come to rest outside
the deployment region (DIS-GL-034). Under DM-3 the log bucket is in the hospital's project and under
DM-4 it is the hospital's own storage.DM-1 and DM-2: encryption at rest and in transit, with the key ring held in the key management
service of the deployment region (DIS-GL-011). Under DM-3 the key ring is in the hospital's own key
management service and under DM-4 in its on-premise key store; encryption at rest and in transit
applies in every model.DM-3 and DM-4, where the key ring is the hospital's
own (DIS-GL-011). In a Pensieve Labs-operated deployment it is not available today, and this
Statement will not describe as a measure something that cannot be elected: DIS-GL-039 publishes it as
Sovereignty Tier S2, ADD-GL-025 clause 5.2.5 records that the control has not shipped and that no
Order Form may record that Tier against DM-1 or DM-2, and its clause 4.2 records the Tier as not
available under DM-3 or DM-4, custody being the hospital's in those two in any event. Where custody
is the hospital's, it removes the key material from Edsol Edtech Pvt. Ltd.'s hands; whether it also
removes the ability to obtain plaintext depends on the model and on whether a delegated grant subsists,
which 8.4 states per model.DPA-GL-001 clause 12.5, DIS-GL-033).DPA-GL-001 clause 12.5, with Annexure II and the
applicable jurisdiction Annexure stating which markets and which models each measure applies to).7.2.2 Organisational. Each of these is a documented control operated under POL-GL-067, which owns
the steps, the roles, the timings and the sign-off rule. They are named here and not reproduced.
POL-GL-067 clause 4 and clause 11).POL-GL-067
clause 4).POL-GL-067 clause 3).POL-GL-067
clause 4).POL-GL-067 clause 10.2, and available to the
affected customer at any time at no charge (POL-GL-067 clause 10.3).POL-GL-068 clause 2 metrics M-1 to M-3, in REP-GL-033.7.2.3 Contractual.
DPA-GL-001 clause 17 makes the review, challenge, minimisation, documented-channel and notification
commitments contractual, and clause 17.3 makes the no-standing-access commitment contractual.DPA-GL-001 clause 12.5 implements the supplementary measures as controls rather than undertakings, and
clause 12.6 applies Clauses 14 and 15 of the Standard Contractual Clauses where they are incorporated,
which prevail.DPA-GL-001 Annexure V Section V-5 states the transfer impact assessment conclusion for India on its
face rather than burying it.MSA-EU-001 and DPA-EU-001 carry these terms for European Union and EEA contracts, in
controller and processor vocabulary.POL-GL-135 clause 4.3.2 flows the minimum data protection terms down to every sub-processor before any
customer personal data reaches it, subject to 6.3.3.DPA-GL-001 clause 8.4 and
POL-GL-135.7.2.4 What none of these measures does. None of them defeats a lawful order of a competent authority in
the jurisdiction where the data is held. They reduce what is available to be compelled, which is a
different and more honest claim. 5.2 states the limit and REP-GL-021 Section 4.5 records
Edsol Edtech Pvt. Ltd.'s practical position.
7.3.1 The address. This Statement is published at
https://trust.pensievelabs.org/legal/government-access, at the Public tier, requiring no account and no
e-mail address, and is retrievable at the same tier from the document register at
https://trust.pensievelabs.org/documents under STM-GL-037. It is the website referred to in
Regulation (EU) 2023/2854 Article 28(1), and this Section is the disclosure Article 28(2) requires a
contract to refer to.
7.3.2 The citation in contracts. That address is cited in every European Union and EEA contract for a
data processing service Edsol Edtech Pvt. Ltd. offers. MSA-EU-001 version 1.1.0 clause 12.5 and
DPA-EU-001 version 1.1.0 clause 14.7 both list it, and DPA-EU-001 cites it again at supplementary
measure S10. That is row A-5 at 10.3, landed. Each instrument refers to this Statement and does
not incorporate it, so no term of it varies either agreement, and an EEA contract that omits the reference
is in breach of the Article.
Regulation (EU) 2023/2854 does not reach a deployment in India, Australia or the United Arab Emirates, and
DM-4 is not a data processing service within it in any market. This disclosure is given for all four
deployment models and in every market anyway. An Indian hospital's board is entitled to the same answer
about jurisdiction and ownership as a Danish one, and the answer does not change depending on who is
asking.
Each is numbered so that it can be falsified separately.
8.1 No back door. Edsol Edtech Pvt. Ltd. grants no public authority direct, indirect, blanket, bulk or
standing access to Customer Data or to the systems on which it is processed, has not been asked to, and
has built no mechanism by which such access could be given without the process at POL-GL-067 clause 4.
8.2 No bulk, blanket or standing access, and no request for it will be acted on. A demand for bulk or
indiscriminate access is on the closed list of things Edsol Edtech Pvt. Ltd. will not act on
(1.4) and is a ground of challenge (5.1.3).
8.3 No weakened cryptography. Edsol Edtech Pvt. Ltd. has not weakened, and will not weaken, any
cryptographic control to facilitate access, and has not been asked to.
8.4 Customer-held keys, stated per model rather than absolutely.
Edsol Edtech Pvt. Ltd. never holds the key material where the key is the hospital's, and it cannot be
ordered to hand over a key it does not hold. What follows from that differs by model, and the absolute
form is true of one model only.
8.4.1 DM-4 in every case, and DM-3 once the hospital has disabled or destroyed the key or revoked
the delegated administrative grant. Edsol Edtech Pvt. Ltd. cannot produce plaintext at all, and will say
so to the authority. Under DM-4 there is in any event no copy to decrypt (2).
8.4.2 DM-3 while the hospital's delegated administrative grant and its key both remain enabled.
Edsol Edtech Pvt. Ltd. holds no key material, but it is in a position to invoke the hospital's key through
the grant, and it would say that to an authority rather than claim an inability it does not have.
2.2 states the same answer at length, and a hospital that wants the DM-3 answer to be
absolute revokes the grant. Not holding key material and being unable to obtain plaintext are two different
facts, and this Statement does not merge them.
8.4.3 The election recorded under DIS-GL-039, and the fact that it cannot be made today.
Customer-held key custody on an otherwise Pensieve Labs-operated deployment is Sovereignty Tier S2 in
DIS-GL-039. It is not electable in any deployment model today, and Edsol Edtech Pvt. Ltd. does not
represent to a hospital, a tender or an authority that it is: ADD-GL-025 clause 5.2.5 records that the
control has not shipped and provides that no Order Form may record that Tier against DM-1 or DM-2,
which are the only two models that could carry it, and its clause 4.2 records the Tier as not available
under DM-3 or DM-4. When the control ships, the position on such a deployment is 8.4.1 or 8.4.2
according to whether Pensieve Labs retains any means of invoking the key, and which it is, is recorded
on the election.
8.5 No voluntary intelligence-sharing arrangement. Edsol Edtech Pvt. Ltd. is party to no voluntary
information-sharing, intelligence-sharing or direct-access arrangement with any government, agency or
authority under which customer data or its metadata is made available outside the process at POL-GL-067
clause 4. It operates no licensed telecommunications service and is not subject to a systematic-access
obligation of that character (REP-GL-021 Section 4.5).
8.6 No non-statutory gag is accepted. Edsol Edtech Pvt. Ltd. gives no voluntary non-disclosure
undertaking to an authority and does not accept a request not to tell the customer that has no legal basis
(POL-GL-067 clause 5.4).
8.7 No warrant canary. Edsol Edtech Pvt. Ltd. operates no warrant canary and does not intend to. The
reason is published at POL-GL-068 clause 4.6: a canary is a device for signalling by omission, its legal
effectiveness is unsettled in Edsol Edtech Pvt. Ltd.'s home jurisdiction, and a device that may not work is
worse than an honest statement of what is reported and what is not.
8.8 The standing fact. Edsol Edtech Pvt. Ltd. has received no government or law enforcement demand
for customer data as at the date on the face of this document. This is the position recorded in
REP-GL-021 Section 4.5 and it is repeated here so that it carries a date.
8.9 Why 8.8 is not a canary. A canary works by being removed. This sentence works the other way round:
when it stops being true, it is affirmatively changed, in this document and in REP-GL-033, to the extent
the law permits, and where a prohibition prevents the change, POL-GL-067 clause 5.5 requires
Edsol Edtech Pvt. Ltd. to state that a prohibition applies rather than to report zero or to fall silent.
A reader should therefore draw no inference from the wording of this Section other than what it says.
8.10 The periodic counts live in one place, and this Statement is not it. The number of demands
received, redirected, challenged, complied with in whole or in part, refused, and the number where notice
was prohibited, are published each period in REP-GL-033 under POL-GL-068 clause 2 metrics M-1 to M-3,
on that document's counting rules, including the rule at POL-GL-068 clause 3.4 that a count between one
and four is published as a band rather than an exact figure. This Statement publishes no periodic figure,
for any period. The standing nil position at 8.8 is the single exception and is stated
plainly as one: a nil count is a count, POL-GL-068 clause 1.4 requires zero to be reported as "Zero"
rather than omitted, and the position is carried here only because it must carry a date. A reader who wants
a figure for a period should read REP-GL-033.
8.11 Where the published edition of the Transparency Report actually lives, and why it is gated. REP-GL-033 is the published edition. POL-GL-068 remains the policy, the counting rules
and the template. REP-GL-033 is itself served at the NDA-gated tier today, because POL-GL-501
clause 1.5 does not name it: until it does, a reader without a credential obtains it on the one-click
route at POL-GL-501 clause 1.1, decided on the service level at POL-GL-500 clause 1.6, and not from
the public estate. That is a gap this Statement names rather than leaves a reader to find at the gate.
The four instruments that named POL-GL-068 as the document in which the report is published now name
REP-GL-033: POL-GL-067 version 1.1.0 at clause 10.4 and at clause 4 step 10, DPA-GL-001
version 1.1.0 at clause 17.4, and POL-GL-068 version 1.2.0 at its new clause 1.2.1, which records that
the published edition at the clause 1.2 address is issued as REP-GL-033 while that Policy remains in
force. Those are rows A-8, A-9 and A-10 at 10.3, all landed. A reader who looks for the
published edition under the Policy identifier is still answered, because POL-GL-068 clause 1.2.1 names
the edition on its face.
| Question a reader may have arrived with | The document that answers it |
|---|---|
| What data exists, where it is stored, processed, logged and backed up, and in which market | DIS-GL-008, with the vocabulary and reading order in DIS-GL-038 |
| Whether a transfer from the EEA to India is defensible, and the assessment of Indian compulsion powers instrument by instrument | REP-GL-021 Sections 4.1, 4.2 and 4.5 |
| Whether the infrastructure and sub-processor leg is defensible, including a demand served on a United States entity | REP-GL-032 |
| How many demands were received, challenged, complied with or refused in a period | REP-GL-033, on the counting rules in POL-GL-068 |
How a demand is actually handled inside Edsol Edtech Pvt. Ltd., step by step, by whom, and in what time |
POL-GL-067, which governs on any question of process |
9.1 This Statement restrains nobody from reporting. Nothing in it prevents, delays or conditions a report by a hospital, a patient, a member of staff or any other person to a court, a regulator, a supervisory authority, the Data Protection Board or a law enforcement agency. Where any provision of this Statement would have that effect, the report prevails and the provision is read down.
This Statement is reviewed every six months, and the next review is due 28 February 2027. It is
additionally updated within 5 Business Days of each of the following:
10.1.1 any change to DIS-GL-009, whether an addition, a replacement, a removal or a change of legal
entity;
10.1.2 any change of deployment region for a market;
10.1.3 any change of contracting provider entity for any service in 7.1; and
10.1.4 any relevant change of law in a market Pensieve Labs serves, including a change to the
compulsion powers named at 5.2.
Three review actions are carried forward from this edition, and two are closed. Carried: completing the
parent-company and State-of-incorporation cells at 7.1.2, which DIS-GL-009 Section 3 owns
and Security closes; naming the jurisdiction of the Trust Center rate-limit region, or recording that
DIS-GL-009 Section 3.4 still does not, also at 7.1.2; and recording the population of
sub-processor contracts not yet carrying the POL-GL-135 Section 4.3.5 government access term, which
6.3.3 discloses and POL-GL-135 Section 4.3.6 owns. Closed at this version: the jurisdiction
of the Trust Center database region, which DIS-GL-009 Section 3.2 now names, and the confirmation that
each amendment at 10.3 has been made, which this version records row by row against the
current text of each instrument.
Every published edition carries the identification and verification marks POL-GL-501 clause 2.2
requires, which are not restated here. A change of substance is a new version with a change-history row and
is never a silent edit of the published page, under POL-GL-501 clause 2.3; a superseded edition remains
retrievable. Were this Statement ever withdrawn rather than superseded, POL-GL-501 clause 2.4 governs: it
keeps its doc_id, is marked Withdrawn with the date and the reason, remains retrievable, and its
successor is named. Edsol Edtech Pvt. Ltd. does not silently change a published statement about government
access.
A statement that quietly relies on amendments nobody can see is worse than one that names them. Ten were
named in version 1.0.0, each a condition of a commitment above. All ten have landed. The Status column
was added at version 1.1.0 and every row in it was set by opening the instrument named in that row and
reading its current text, not by carrying forward what this table previously said about itself. Where this
Statement is stricter than POL-GL-067, or moves where something is published, the amendment is named here
rather than left for a reader to discover:
| # | Instrument | The amendment | What it carries | Status, checked against the instrument's current text |
|---|---|---|---|---|
| A-1 | POL-GL-501 clause 1.5 |
Admit STM-GL-037 to the closed public list, by an amendment to that clause approved by the Founder and recorded under POL-GL-501 Section 2 |
The Public tier of this Statement. The classification finding is recorded in its frontmatter and is the first finding in the classification table at the head of POL-GL-501 Section 1, with the second finding satisfied as well |
Landed. POL-GL-501 version 2.1.0, 29 August 2026. The clause 1.5 list names this Statement, on the Article 28(1) and 28(2) ground |
| A-2 | POL-GL-067 clause 2.4 |
Insert the preservation figures published at 4 | The 1 Business Day, 90 day, extended-once and lapse-notice commitments | Landed. POL-GL-067 version 1.1.0, new clause 2.4.1, which carries all four figures and names 4 as their published source |
| A-3 | POL-GL-067 clause 5.2.3 |
Insert the 5 Business Day window on the lapse of a prohibition | The gag-lapse notice window at 4 | Landed. POL-GL-067 version 1.1.0, clause 5.2.3 |
| A-4 | POL-GL-135 Section 4.3.2 |
Add the notify-and-challenge minimum term for sub-processor contracts | The contractual answer at 6.3.3 | Landed. POL-GL-135 version 1.1.0, as new Section 4.3.5, which Section 4.3.2 now requires. Section 4.3.6 phases it in across contracts already in force, and 6.3.3 states that limit rather than treating the term as universally in force |
| A-5 | MSA-EU-001 and DPA-EU-001 |
Cite the address at 7.3.1 | Compliance with Regulation (EU) 2023/2854 Article 28(2) | Landed. MSA-EU-001 version 1.1.0 clause 12.5 and DPA-EU-001 version 1.1.0 clause 14.7, with the same address cited at DPA-EU-001 supplementary measure S10 |
| A-6 | POL-GL-067 clause 4 step 6 |
Insert the six grounds at 5.1 as a closed list on which a challenge is mandatory, in place of the discretionary formulation "where there is a reasonable basis" that step 6 then carried | The closed list at 5.1 | Landed. POL-GL-067 version 1.1.0, clause 4 step 6, which now states the six grounds as a closed list and makes a challenge mandatory on any of them, keeping the reasonable-basis limit on pursuing an appeal |
| A-7 | POL-GL-067 clause 8 |
Record that the Regulation (EU) 2023/2854 Article 32 conditions are applied in every market and not only in the Union | The global application at 6.2 | Landed. POL-GL-067 version 1.1.0, new clause 8.6, which names 6.2 as the owner of the conditions |
| A-8 | POL-GL-067 clause 10.4 and clause 4 step 10 |
Redirect the published edition of the Transparency Report from POL-GL-068 to REP-GL-033, leaving POL-GL-068 as the policy, the counting rules and the template |
The counts at 8.10 and 8.11 | Landed. POL-GL-067 version 1.1.0, clause 10.4 and clause 4 step 10, with clause 5.5 naming the same edition |
| A-9 | DPA-GL-001 clause 17.4 |
The same redirection in the contractual clause, which then named POL-GL-068 |
The contractual form of the transparency commitment | Landed. DPA-GL-001 version 1.1.0, clause 17.4 |
| A-10 | POL-GL-068 clause 1.2 |
Record that the published edition at that address is issued as REP-GL-033, the Policy remaining in force |
The publication address and cadence relied on at 8.11 | Landed. POL-GL-068 version 1.2.0, new clause 1.2.1 |
Every commitment in this table was operative from the moment it was published here, and each is now carried
by the instrument beside it as well. The table is kept rather than deleted so that a reader can check each
row against the instrument it names and see when the gap closed. One gap remains, and it is not a row of
this table: POL-GL-501 clause 1.5 does not name REP-GL-033, which is why 8.11 records
that the published edition of the Transparency Report is served at the gated tier. Two register cells also
remain open and are carried as review actions at 10.1 rather than as amendments, because they
are fields DIS-GL-009 has yet to verify and not instruments anyone has yet to amend. This table is
reviewed again under 10.1.
Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2, HITRUST, CE or ARTG certification. Nothing in this
Statement is a certification, an attestation, or an independently audited finding. Every statement in it is
self-reported, and the mechanism for checking each one is named beside it. WPR-GL-005 states the assurance
position in full.
| Subject | Document that owns it |
|---|---|
| The handling process, roles, timings and register for every demand | POL-GL-067 |
| Contractual form of these commitments | DPA-GL-001 clause 17, with clause 12.5 and clause 12.6 |
| Reading order and vocabulary for the whole sovereignty estate | DIS-GL-038 |
| Sovereignty tiers and the customer-held key election | DIS-GL-039 |
| Where data is stored, processed, logged and backed up, per market and per model | DIS-GL-008 |
| Who else touches the data, their legal entities and their locations | DIS-GL-009, with the change feed at DIS-GL-010 |
| Encryption and key custody per model | DIS-GL-011 |
| Which countries a human being can reach the data from | DIS-GL-033 |
| Log retention and localisation configuration | DIS-GL-034 |
| Transfer impact assessment, EEA to India personnel leg | REP-GL-021 |
| Transfer impact assessment, infrastructure and sub-processor leg | REP-GL-032 |
| Published counts of demands received, challenged and answered | REP-GL-033, on the rules in POL-GL-068 |
| Sub-processor contractual minimums and flow-down | POL-GL-135 |
| Deployment model definitions and what each costs | WPR-GL-004 |
| What a Data Principal is told, and the rights channel | POL-GL-053, and POL-EU-053 for the EEA |
| Publication tier, the closed public list and the verification requirements | POL-GL-501 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.2.0 | 29 August 2026 | Legal | Two published facts corrected, one of them the only time-critical channel in this Statement. The emergency row at 1.1 routed a risk-to-life request through info@pensievelabs.org and [TO BE SUPPLIED]. That token is unseeded, so the row rendered to a public authority as an address followed by an empty slot. Edsol Edtech Pvt. Ltd. publishes no telephone number for legal process, so the row now states the written route alone and new 1.1.2 gives the three facts an authority needs in its place: that POL-GL-067 clause 6.2 requires an emergency request to be in writing in any event so the written route was always the operative one, that one named legal owner receives every demand, and that in DM-3 and DM-4 the hospital is the only holder of the records and is reached faster than Edsol Edtech Pvt. Ltd.. A published telephone number is recorded there as an open item owned by the Founder, with no date asserted. In the Article 28(1)(a) table at 7.1 the two Platform rows and the Scaffold row recorded the Ultimate parent as Google LLC; DIS-GL-009 Section 2.1, which is the register of record, distinguishes the group parent, Google LLC, from the ultimate parent, Alphabet Inc., a United States company. All three rows now carry Alphabet Inc. with the group parent named beside it, and 7.1.1 states why the column runs to the top of the ownership chain. The parent's jurisdiction is unchanged in every row, so no Article 28 disclosure of jurisdiction is altered by the correction. No commitment, window or handling process changes. |
| 1.1.0 | 29 August 2026 | Legal | Clears the dependency ledger at Section 10.3 against the current text of every instrument it names, and corrects the Article 28(1)(a) table against DIS-GL-009. All ten amendments have landed and the table gains a Status column naming the version that carries each: A-1 at POL-GL-501 version 2.1.0 clause 1.5; A-2, A-3, A-6, A-7 and A-8 at POL-GL-067 version 1.1.0, at new clause 2.4.1, clause 5.2.3, clause 4 step 6, new clause 8.6 and clause 10.4 with step 10; A-4 at POL-GL-135 version 1.1.0, as new Section 4.3.5; A-5 at MSA-EU-001 version 1.1.0 clause 12.5 and DPA-EU-001 version 1.1.0 clause 14.7; A-9 at DPA-GL-001 version 1.1.0 clause 17.4; and A-10 at POL-GL-068 version 1.2.0 clause 1.2.1. Every sentence that was conditioned on one of those amendments being outstanding is rewritten: Section 4.1, Section 5.1, Section 6.2, Section 6.3.3, Section 7.3.2 and Section 8.11 no longer tell a reader that a window, a closed list, a global standard, a sub-processor term, a contract citation or a report address is published here but not yet carried by the instrument that owns it. Section 6.3.3 keeps an honest residual rather than declaring the sub-processor gap closed: the term at POL-GL-135 Section 4.3.5 binds a sub-processor to challenge on a reasonable basis and not on the closed list at Section 5.1, and reaches only contracts entered into, renewed or varied on or after that Policy's version 1.1.0, the unamended population remaining an open gap in REG-GL-202 under Section 4.3.6. In the Article 28(1)(a) table, the Trust Center database row now names Singapore as DIS-GL-009 Section 3.2 does; a fourth Trust Center row is added for Upstash, Inc., the rate limiter entered in that register on 21 August 2026; and the parent and State-of-incorporation cells are aligned to the register's own wording, "not yet verified", which carries an owner and a due date, in place of "not recorded", which carried neither. Section 6.3.1 names four United States entities in place of three and Section 6.3.2 records what the rate-limit counter holds. Section 7.1.2 is rewritten accordingly and records the database-region limit as closed. Section 7.3.1 additionally names the document register address at which this Statement is retrievable at the same tier, so that the Article 28(1) website is reachable by more than one path. The carried review actions at Section 10.1 are restated: two close, and the population of sub-processor contracts not yet carrying the government access term is added. The document control line's literal tier is replaced with the document tier token, so that the line and the frontmatter cannot diverge. No commitment in this Statement is varied, withdrawn or weakened. |
| 1.0.0 | 29 August 2026 | Legal | First published edition, issued as the public companion to POL-GL-067 under POL-GL-501 clause 1.4, and admitted to the closed public list by the amendment to POL-GL-501 clause 1.5 recorded in the same pass. Publishes the address for service and the seven required elements of a demand for readers who can hold no credential; a per-deployment-model compellability matrix stating whose law reaches each data class, who must be served, and whether plaintext can be produced, with the honest ranking that DM-4 answers compellability absolutely and DM-1 and DM-2 answer it procedurally; the redirect-to-the-hospital rule; published notice and preservation windows, four of which are new commitments introduced here and named for mirroring into POL-GL-067; a closed list of six challenge grounds and the honest limit that no lawful order can be undertaken to be defeated; the mutual legal assistance rule; Regulation (EU) 2023/2854 Article 32 applied as a global standard; the sub-processor route on which Pensieve Labs may never be told, with the contractual gap disclosed; the Article 28(1)(a) jurisdiction table, the Article 28(1)(b) measures description and the Article 28(2) address; eleven numbered negative commitments including the customer-held key position stated per deployment model rather than absolutely, and the absence of a warrant canary and the reason; and the amendments this Statement depends on, named in full rather than assumed. |
STM-GL-037 v1.2.0 | Last Modified On 29 August 2026 | Review due
28 February 2027 | Tier: PUB | Applies to DM-1, DM-2, DM-3, DM-4 | Published at
https://trust.pensievelabs.org/legal/government-access