Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
DIS-GL-009
v1.0.0 | 31 July 2026
Register version 1.0.0 | Position as at 31 July 2026 | Next scheduled review
31 October 2026 | Total entries: 5
DM-1 Dedicated |
DM-2 Shared |
DM-3 Customer Cloud |
DM-4 On-Premise |
|---|---|---|---|
| Full register applies | Full register applies | Section 2 does not apply because the hospital owns the cloud account | Section 2 does not apply because there is no cloud infrastructure provider |
Section 3 (Trust Center and corporate) applies in all four models, because every hospital that buys
Pensieve also uses the Trust Center to receive documents, and no deployment model changes that.
This register names every third party that Edsol Edtech Pvt. Ltd. engages which processes data belonging
to, or relating to, a hospital customer. It exists so that a hospital's IT head, privacy officer or
lawyer can answer the question "who else touches our data?" without sending an e-mail and waiting three
days.
It is the source of truth. Annexure III of the Data Processing Agreement (DPA-GL-001) records the
position a Customer accepted on signature; this register records who is engaged today. Where the two
differ, this register is current and the Annexure is historical. Notification and objection rights are
governed by DPA-GL-001 clause 8.4 and the running record of changes is the Sub-Processor Change Log
(DIS-GL-010).
The register is deliberately falsifiable. Every entry names a real legal entity, a real service, a real
processing location and a publicly retrievable data processing agreement. Each of those can be checked
without trusting Pensieve Labs. A register that cannot be checked is a marketing page.
Three tiers of entry are used, and the distinction is material:
| Tier | Meaning | Notification right |
|---|---|---|
| Section 2 Platform Sub-processors | Process Customer Personal Data, including patient records | Full: 30 days' advance notice and an objection right under DPA-GL-001 clause 8.4 |
| Section 3 Trust Center and corporate Sub-processors | Process business contact data only: the names, work e-mail addresses and document access records of the hospital's authorised users. No patient record reaches any of them. | Notified in DIS-GL-010; no objection right, because no Customer Personal Data is processed |
| Section 5 Not Sub-processors | Systems the hospital connects using its own credentials on its own authority | Not applicable: they are the hospital's suppliers, not Pensieve Labs's |
In DM-1 and DM-2, exactly one sub-processor processes hospital patient data: the cloud infrastructure
provider named in Section 2. In DM-3 and DM-4 there is none, because the hospital owns the infrastructure.
Everything else in this register handles business contact data for the Trust Center and for corporate
administration. Pensieve Labs does not use a third-party hosted error-tracking, session-replay,
product-analytics, customer-messaging, data-warehouse or artificial-intelligence service that receives
Customer Personal Data. If that changes it changes under the notice procedure in Section 6, and this register is
republished on the day it changes.
| Field | Value |
|---|---|
| Legal entity | Google Cloud India Private Limited for Customers contracting in India; Google Cloud EMEA Limited or the applicable Google entity for Customers contracting elsewhere, as recorded on the Order Form |
| Group parent | Google LLC |
| Service provided | Infrastructure hosting. Specifically: managed container compute (Cloud Run), managed relational database (Cloud SQL for PostgreSQL), object storage (Cloud Storage), key management (Cloud KMS), secret storage (Secret Manager), log storage (Cloud Logging log buckets), edge load balancing and web application firewall (Cloud Load Balancing, Cloud Armor), and container image storage (Artifact Registry) |
| Categories of data processed | All categories listed in DPA-GL-001 Annexure I Section I-3, including patient identification data, health data, financial and billing data, and system logs. All are encrypted at rest under the key hierarchy in DIS-GL-011 |
| Processing location | The region recorded as Deal data region on the Order Form. For Indian deployments this is a Google Cloud India region and no Customer Personal Data leaves Indian jurisdiction. See DIS-GL-008 for the position in every market |
| Sub-processing by this entity | Google may engage its own sub-processors; its published list is maintained at cloud.google.com/terms/subprocessors |
| Transfer mechanism | For India, no cross-border transfer occurs. Where a transfer occurs in another market, the mechanism is stated in DPA-GL-001 clause 12 and in DIS-GL-008 |
| Data processing agreement | Google Cloud Data Processing Addendum (Customers), published at cloud.google.com/terms/data-processing-addendum, incorporating the European Commission Standard Contractual Clauses where applicable |
| Applies to | DM-1, DM-2. Under DM-3 the cloud provider is the hospital's own supplier, contracted directly by the hospital (see Section 5.2). Under DM-4 there is no cloud provider |
| Entry status | Initial entry, added at first publication of this register (v1.0.0, 31 July 2026) |
There is no second platform sub-processor. Pensieve Labs does not engage a separate provider for
monitoring, alerting, search, backup, e-mail delivery, document rendering or machine learning that receives
Customer Personal Data. Every one of those functions runs on the infrastructure above, inside the
deployment's own cloud project, under the same encryption keys and the same access controls.
The PDF render service is not a sub-processor. Documents are rendered to PDF by a containerised service
that Edsol Edtech Pvt. Ltd. builds and operates itself, running on Cloud Run inside Pensieve Labs's
own cloud organisation. It is Pensieve Labs's own software on Pensieve Labs's own infrastructure,
so the sub-processor for it is the cloud provider already named above, and nothing further. This is stated
explicitly because "we use a document rendering service" is exactly the kind of phrase that hides a
third-party vendor, and here it does not.
These process the business contact data described in DPA-GL-001 clause 3.6: the names, work e-mail
addresses, and document access records of the hospital's authorised users, plus the contract and disclosure
documents exchanged during a deal. No patient record, no clinical record and no Data Principal record is
processed by any entity in this section. The Trust Center is a separate application from the Platform and
is not connected to any hospital's Platform instance (WPR-GL-001 Section 5.7).
| # | Sub-processor | Legal entity | Service | Data processed | Processing location | Data processing agreement |
|---|---|---|---|---|---|---|
| 3.1 | Vercel | Vercel, Inc. | Hosting and edge delivery of the Trust Center application at https://trust.pensievelabs.org |
Business contact data; document access events; request logs including IP address and user agent | United States, with edge delivery from the network region nearest the visitor | vercel.com/legal/dpa, incorporating Standard Contractual Clauses |
| 3.2 | Neon | Neon, Inc. | Managed PostgreSQL database for the Trust Center: the token registry, document templates and instances, access requests, and access records | Business contact data; document instances and their resolved token values; access grant and access event records | The region selected for the Trust Center database project, recorded in the deployment record | neon.com/dpa, incorporating Standard Contractual Clauses |
| 3.3 | Resend | Plus Five Five, Inc., trading as Resend | Transactional e-mail delivery: access approvals and denials, document issue notices, signature requests, sub-processor change notifications and breach notifications | Recipient work e-mail address, sender address, subject and message body, delivery and open telemetry | United States | resend.com/legal/dpa, incorporating Standard Contractual Clauses |
Why these three and no more. The Trust Center is deliberately a small stack. It holds
Pensieve Labs's document library and the deal lifecycle record. It does not hold patient data, it does
not connect to a Platform instance, and it does not need an analytics vendor, a chat widget, a session
replay tool or a marketing automation platform, none of which is used.
A hospital's realistic exposure through this section is that its authorised users' work e-mail addresses
and the record of which documents they opened are processed in the United States. That is stated plainly
rather than buried. A hospital that objects to this can receive its documents by e-mail attachment or on
physical media instead of through the Trust Center, at the cost of the speed the Trust Center exists to
provide; the request goes to info@pensievelabs.org.
Publishing an empty row is more useful than publishing nothing, because it tells a reviewer where the register will grow.
| Function | Status as at 31 July 2026 |
What triggers an entry |
|---|---|---|
| Electronic signature provider | Provider [TO BE SUPPLIED], selection pending. Contracts are currently executed by the methods recorded on each instrument | First execution through a hosted e-signature platform. The entry will record signatory name, work e-mail and signature evidence as the data categories |
| Electronic stamping provider | Provider [TO BE SUPPLIED], selection pending | First stamp purchased through a hosted provider on a Customer's behalf |
| Accounting, payroll and banking providers | Engaged for Edsol Edtech Pvt. Ltd.'s own statutory finance and payroll functions, in India. They process Pensieve Labs's personnel data and the hospital's finance contact and invoice data, not Customer Personal Data. Named entities are [TO BE SUPPLIED] |
These are listed for completeness of disclosure; they are not sub-processors of Customer Personal Data |
| Artificial intelligence or machine learning model provider | None engaged. No third-party model provider receives Customer Personal Data. See DIS-GL-027 |
Engagement of any hosted model provider. This would be a Section 2 entry with a full 30-day notice and objection right |
| Independent security testing firm | None engaged. Status and target dates are in WPR-GL-005 Section 5 |
Appointment of a testing firm with access to a production environment |
| Support ticketing or customer messaging platform | None engaged. Support runs through the channels in SLA-GL-001 |
Adoption of a hosted platform that would receive hospital correspondence |
[TO BE SUPPLIED] here means exactly what it says: Pensieve Labs has not selected a provider. It does
not mean a provider exists and is being withheld.
Every external system Pensieve talks to is reached using credentials the hospital holds and
supplies: ABDM registries and the health information exchange, NHCX, insurers and third-party
administrators, payment gateways, SMS, WhatsApp, voice and e-mail providers, laboratories and analyser
vendors, PACS providers, accounting systems and government reporting portals.
Pensieve calls those systems as the hospital, on the hospital's authority.
Edsol Edtech Pvt. Ltd. does not contract with them, does not pay them, cannot obtain credentials for them
in its own name, and is not their customer. They are therefore the hospital's processors or independent
controllers, not Pensieve Labs's sub-processors. The reasoning, and the full list of what this covers,
is in the Integration Boundary Statement (DIS-GL-024); the custody rules for the credentials themselves
are in DIS-GL-025 and ADD-GL-007; the responsibility split for ABDM and NHCX is in DIS-GL-026.
This is not a technicality invented to shorten a register. It is the reason the hospital, not
Pensieve Labs, is the regulated participant in those systems, and it is stated affirmatively in
00-BRIEF.md Section 5 and throughout the contract stack.
DM-3 and DM-4Under DM-3 the hospital owns and pays for the cloud project, contracts with the cloud provider directly,
and holds its own agreement with it. The cloud provider is the hospital's supplier.
Edsol Edtech Pvt. Ltd. operates inside that project under the Delegated Cloud Access & Administration
Agreement (ADD-GL-009) and is not in a position to sub-contract infrastructure it does not buy.
Under DM-4 there is no cloud provider at all. The hardware is the hospital's.
Consequence, stated so nobody has to work it out: a hospital on DM-3 or DM-4 has zero
Pensieve Labs sub-processors touching its patient data. That is one of the two legitimate reasons to
choose those models, and it is a stronger answer than any assurance Pensieve Labs could give about a
provider it selects.
Pensieve Labs personnel and contractorsIndividuals engaged by Edsol Edtech Pvt. Ltd. (employees and contractors) act under
Pensieve Labs's direction and are not separately listed as sub-processors. They are subject to the
controls in DIS-GL-020 and the access path in DIS-GL-033. The countries from which they work, and the
constraints on that, are stated in DIS-GL-033 Section 2, including the Australian constraint that makes
offshore support impermissible for certain data.
The default infrastructure in Section 2 does not satisfy every market's law, and this register says so rather than implying a single global answer.
| Market | Position | Register consequence |
|---|---|---|
| India | Default infrastructure. Google Cloud India region recorded as Deal data region |
Section 2 entry applies unchanged |
| Australia | Default infrastructure in an Australian region. Where My Health Record connectivity is in scope, offshore support access is separately constrained (DIS-GL-033 Section 4) |
Section 2 entry applies; the constraint is on personnel, not on the sub-processor |
| Denmark, Norway | Default infrastructure in a European Union region | Section 2 entry applies unchanged |
| United Arab Emirates | The default infrastructure cannot be used. Federal Law No. 2 of 2019 Article 13 prohibits health data related to health services provided in the UAE from being stored, processed, generated or transferred outside the UAE, and the default cloud provider has no UAE region. The infrastructure provider for a UAE deployment is therefore a different entity, selected per deal and recorded on the Order Form | A separate Section 2 entry is created for each UAE deployment, naming the actual provider and the UAE region. Until a UAE deal is signed, no such entry exists. See DIS-GL-008 Section 6 |
The register is the output. The process behind it is:
| Step | What happens | Owner |
|---|---|---|
| 1 | A business need is identified that cannot be met on existing infrastructure | Engineering |
| 2 | Due diligence: legal entity verified; security documentation and audit reports reviewed; data processing terms reviewed; processing location confirmed; the provider's own sub-processor list reviewed; termination and data return terms reviewed | Security |
| 3 | A written data processing agreement is executed imposing obligations no less protective than those Edsol Edtech Pvt. Ltd. owes the hospital under DPA-GL-001, including confidentiality, security, breach notification, audit and deletion on termination |
Legal |
| 4 | Where a cross-border transfer arises, the applicable transfer mechanism is put in place: Standard Contractual Clauses or an adequacy basis, per DPA-GL-001 clause 12 |
Legal |
| 5 | Thirty days' advance notice is given to every affected Customer for any Section 2 engagement, by e-mail to the Customer's notified privacy contact and by publication in DIS-GL-010 |
Security |
| 6 | The objection procedure in DPA-GL-001 clause 8.4 runs. Pensieve Labs explains the role and safeguards within five business days, and if the objection is not resolved the Customer may terminate the affected Services without penalty |
Legal |
| 7 | This register is republished with the new entry on the day the engagement takes effect, and DIS-GL-010 records the change |
Security |
| 8 | Every Section 2 sub-processor is reviewed annually against the same criteria as step 2. The review date is recorded | Security |
Edsol Edtech Pvt. Ltd. remains fully liable to the hospital for each sub-processor's performance of its
data protection obligations, as if their acts and omissions were Pensieve Labs's own
(DPA-GL-001 clause 8.3). Engaging a sub-processor moves work, not responsibility.
The urgent-replacement exception. Where a sub-processor must be replaced without notice to preserve the
security or availability of the Platform, DPA-GL-001 clause 8.5 permits it and requires notice as soon
as practicable afterwards, with the objection right preserved. That exception has not been used. If it is
ever used, DIS-GL-010 will record it as such, including the fact that notice was retrospective.
A hospital should not take this document on trust. Five checks, none of which requires
Pensieve Labs's cooperation:
DIS-GL-034 states what should be there and
Pensieve Labs will show it.DIS-GL-010 and check that it produces an entry when
this register changes. A change log that never changes and a register that never dates itself are the
two symptoms of a register maintained for show.9.1 The cloud provider has its own sub-processors. Edsol Edtech Pvt. Ltd. does not control, audit, or
individually approve the entities the cloud provider engages beneath it. Pensieve Labs relies on that
provider's published sub-processor list and its own contractual flow-down. No vendor of
Pensieve Labs's size audits a hyperscale cloud provider, and this register does not imply otherwise.
9.2 This register is self-published and not independently audited. No third party verifies that it is
complete. What makes it credible is that every entry is checkable (Section 8) and that omitting an entry would be
a breach of DPA-GL-001 clause 8, which is contractually actionable, not that anyone has certified it.
9.3 It is accurate as at its date, not continuously. The register is republished on the day an engagement changes. Between changes it carries the date at the top of this page. If that date is old, the register is old, and that is visible rather than hidden.
9.4 Section 4 entries are genuinely undecided. Where a provider is marked [TO BE SUPPLIED],
Pensieve Labs has not selected one. A hospital signing today should read Section 4 as a list of engagements
that will trigger a notification later, and should note that the e-signature and stamping providers, when
selected, will handle signatory identity data.
9.5 Business contact data in Section 3 is processed outside India. For an Indian hospital this is not
Customer Personal Data under DPA-GL-001 and is not patient data, but it is personal data about the
hospital's own staff. The opt-out in Section 3 exists for hospitals that will not accept it.
| Question | Document |
|---|---|
| What changed in this register, and when | DIS-GL-010 Sub-Processor Change Log & Notification Feed |
| The contractual sub-processor terms, notice period and objection right | DPA-GL-001 clause 8 and Annexure III |
| Where data is stored, per market and per model | DIS-GL-008 Data Residency Statement |
| How data is encrypted and who holds the keys | DIS-GL-011 Encryption Disclosure |
| Why the hospital's connected systems are not sub-processors | DIS-GL-024 Integration Boundary Statement |
| How hospital-supplied credentials are held | DIS-GL-025 BYOK/BYOC Credential Handling Disclosure |
| Who can access hospital data, from where | DIS-GL-033 Remote Access & Support Model Disclosure |
| What each deployment model changes | WPR-GL-004 Deployment Models Explained |
| Whether any machine learning provider is engaged | DIS-GL-027 AI/ML Feature Disclosure |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Pensieve Labs Security |
First published register. Five entries: one platform sub-processor (DM-1/DM-2 only), three Trust Center sub-processors handling business contact data only, and the corporate finance function. Not-yet-engaged functions published as empty rows. |