Search all 478 artefacts by title, document ID or content.
Form | Family 2, Legal & Contractual
Estimated completion time: about 5 minutes. Most of the fields are optional, and you never have to attach an identity document to begin. Submitting this form starts your statutory clock: you receive a reference number and an acknowledgement within 3 Business Days.
This document is the source of truth for: marketing:/legal/data-request, marketing:/privacy/your-rights, marketing:/privacy/request, trust:/privacy/request, trust:/documents/FRM-GL-505
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
FRM-GL-505 | Version 1.0.0 | Last Modified On 03 August 2026
Estimated completion time: about 5 minutes. Most of the fields are optional, and you never have to attach an identity document to begin. Submitting this form starts your statutory clock: you receive a reference number and an acknowledgement within 3 Business Days.
Most people who reach this page are looking for their hospital, not for Pensieve. Read these three lines first. The right one may save you the form.
If you only want the email address and website data this Trust Center holds about you removed: the fastest route is the self-serve tool at https://trust.pensievelabs.org/privacy/your-data. It needs no account. You enter your address, follow a link sent to it, and your identifiers are removed or pseudonymised across the site. That page also lists, in full, everything this site stores about you.
Everyone else uses the form below. If you are a website or Trust Center visitor, a prospective customer, a Trust Center credential holder, a subscriber, a supplier, a job applicant, or a member of hospital staff who holds a Pensieve credential, then over that data Edsol Edtech Pvt. Ltd. is the Data Fiduciary in its own right, and this form is how you exercise your rights against it.
You do not need to know the law to use this form. This table is here so you can see what you are entitled to before you ask for it.
| Right | What it does | Where it comes from |
|---|---|---|
| Access and a summary | A summary of the personal data being processed, the processing activities, and the identities of the Data Processors and other Data Fiduciaries it has been shared with | DPDP Act section 11; GDPR Article 15; Australia APP 12 |
| Correction | Correct personal data that is inaccurate or misleading | DPDP Act section 12; GDPR Article 16; APP 13 |
| Completion | Complete personal data that is incomplete | DPDP Act section 12 |
| Updating | Bring personal data up to date | DPDP Act section 12 |
| Erasure | Erase personal data, unless the law requires it to be kept | DPDP Act section 12; GDPR Article 17 |
| Withdrawal of consent | Withdraw consent as easily as you gave it, stopping consent-based processing | DPDP Act section 6(4); GDPR Article 7(3) |
| Nomination | Nominate a person to exercise your rights if you die or become incapacitated | DPDP Act section 14 |
| Grievance | Raise a grievance about how a right, or your personal data, was handled | DPDP Act section 13; POL-GL-066 |
| Additional GDPR rights | Restriction of processing, data portability, and an absolute right to object to direct marketing | GDPR Articles 18, 20 and 21(2) |
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 1 | Full name | text | Yes | The name we address the response to | 2 to 100 characters | We respond to a person, and for some records this is what we check the request against |
| 2 | Contact email | Yes | Where we send the acknowledgement and the response | Valid email address | It is how we reach you, and for a website record it is usually the identifier that ties the record to you | |
| 3 | Contact telephone | tel | No | Only if you would rather we call you | Valid telephone number, or leave blank | An alternative channel. It is never required and is not used to market to you (POL-GL-072) |
| 4 | Preferred language | select | Yes | English and Hindi are answered directly. Any other language in the Eighth Schedule to the Constitution is arranged, which may add a little time | One value | The DPDP Act (sections 5(3) and 6(3)) gives you the option to deal in English or an Eighth Schedule language |
| 5 | Preferred response format | select | No | Standard, large print, a screen-reader-friendly document, or a telephone call | One value | Accessibility (POL-GL-061). Ask and we provide it |
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 6 | Your relationship with Pensieve | select | Yes | Visitor; prospective customer; Trust Center credential holder; newsletter or bulletin subscriber; supplier contact; job applicant; hospital staff member with a Pensieve credential; a patient (or a patient's family) of a hospital that uses Pensieve; other | One value | It tells us which record to look in, and whether Pensieve or your hospital must answer. If you pick the patient option the form routes you to your hospital (DIS-GL-037) |
| 7 | Which jurisdiction should decide your request | select | Yes | India (DPDP Act, 2023); the EU or EEA (GDPR); the United Kingdom (UK GDPR); Australia (Privacy Act 1988); other or not sure | One value | It sets which Privacy Policy governs: POL-GL-053 for India and the rest of the world, POL-EU-053 for the EU, EEA and UK, POL-AU-053 for Australia. The GDPR variant carries additional rights, shown in the table above |
| 8 | Account identifier | text | No | The email, credential ID, support ticket number, application reference or subscription address already tied to your record | Free text, or leave blank | The DPDP Rules (Rule 14(1)(b) and 14(5)) point to the identifier you already have. Giving it is the fastest and least intrusive way for us to find you, so we ask for it rather than for fresh identity documents |
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 9 | Are you making this request for yourself, or for someone else | radio | Yes | Myself; as a nominee under section 14 of the DPDP Act; as a parent or lawful guardian; as an authorised representative or agent | One value | We can disclose personal data only to the person entitled to it, or to someone with authority to act for them |
| 10 | Evidence of authority | file upload | Conditional | Required only where you are acting for someone else. A nomination, a guardianship record, or a signed authority is enough | PDF, JPG or PNG up to 10 MB | Where the outcome would disclose personal data, we confirm the authority first (POL-GL-066 Section 1). We do not ask for it otherwise |
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 11 | Which right or rights are you exercising | multi-select | Yes | Choose from the rights in the table above: access and a summary, correction, completion, updating, erasure, withdrawal of consent, nomination, grievance, and, under the GDPR, restriction, portability and objection to marketing. You may choose more than one | One or more values | It tells us what you want done, and which statutory clock and process to run |
| 12 | Describe your request | textarea | Yes | In your own words, what you would like us to do. You do not have to cite the law. The table has done that | 10 to 4,000 characters | It is the substance of the request, and a specific description lets us answer it once, correctly |
| 13 | The specific data, document, message or account this concerns | textarea | No | For example a particular email you received, a form you filled in, or a document you accessed | Up to 2,000 characters, or leave blank | It narrows the search, which usually gets you a faster and more complete answer |
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 14 | Identity check | file upload | No | Usually not needed. Leave this blank. We ask only if the request needs it, and we say exactly what and why | PDF, JPG or PNG up to 10 MB, or leave blank | We verify proportionately, as set out below, and never demand more identity data than the request needs |
| 15 | Declaration of accuracy | checkbox | Yes | I confirm the information I have given is accurate to the best of my knowledge | Must be ticked | A knowingly false or frivolous request falls outside the protection Pensieve gives a good-faith one (DPDP section 15; POL-GL-066) |
| 16 | Consent to handle this request | checkbox | Yes | I agree that Pensieve may use the personal data in this form only to handle and answer this request | Must be ticked | It is the lawful basis for processing the request itself, described in the Privacy Policy (POL-GL-053) |
How Pensieve verifies you, proportionately. Pensieve verifies enough to be confident you are who you say you are, and no more. If you give an identifier it already holds (field 8), it confirms by sending a link to the email on that record, as the self-serve erasure tool does. It does not ask a known or logged-in person for a government identity document. It asks for an additional check only where the request would disclose a body of personal data, or where you are acting for someone else. Any identity data you give is used only to verify this request, never for anything else, and is deleted when the request closes. This follows the DPDP Rules (Rule 14(1)(b) and 14(5)), which point to the identifier you already have, and regulator guidance on proportionate verification.
| Step | Commitment |
|---|---|
| Acknowledgement, with a reference number and the name of the person handling it | 3 Business Days |
| Substantive response: the decision, the reasoning, and what Pensieve will do | 30 days |
| India, absolute outer limit | 90 days, the statutory maximum in Rule 14(3) of the Digital Personal Data Protection Rules, 2025 |
| EU, EEA and UK (GDPR) | Within one month of receipt, extendable by two further months for a complex or repeated request, with the extension and its reason told to you inside the first month (Article 12(3)) |
| Australia (APP 12) | Within a reasonable period, and no more than 30 days |
| Where Rule 5(9) of the SPDI Rules, 2011 applies (in force today) | 1 month. Pensieve applies the shorter period where both could apply |
Step by step.
NTC-GL-019), and repeats the business contact for questions about the processing, which Rule 9 of the DPDP Rules requires in every response. That contact is the Grievance Officer named in POL-GL-066.POL-GL-066 Section 5; DPA-GL-001).DIS-GL-023.No fee. There is no charge to make a request, in any market. The Digital Personal Data Protection Act and its Rules prescribe none. Under the GDPR (Article 12(5)) a request that is manifestly unfounded or excessive, in particular a repeated one, may attract a reasonable fee or be refused. Pensieve carries the burden of showing that, and will give its reasons and the appeal route rather than a bare refusal. In Australia there is no charge to make a request, though a not-excessive charge for giving access may apply (APP 12).
Appeal and escalation. Tell Pensieve within 30 days and the decision is reviewed by someone who was not involved in it. You may also go straight to the external route. Pensieve does not require you to exhaust its process first. The Grievance Officer (POL-GL-066) is the internal appeal. After that, the external authority is the Data Protection Board of India, or, for a GDPR request, your supervisory authority, which in the United Kingdom is the Information Commissioner's Office, or, in Australia, the Office of the Australian Information Commissioner. POL-GL-066 Section 6 lists these by market.
Pensieve operates this form to the full Digital Personal Data Protection framework now, and none of the commitments above is conditional on a commencement date. For completeness: the operational Rule on rights handling (Rule 14) commences on or about 14 May 2027, while the one-month Grievance Officer duty under Rule 5(9) of the SPDI Rules, 2011 is in force today, and Pensieve applies the shorter period where both could apply. [UNVERIFIED: one-day discrepancy in the Rules' publication date, 13 or 14 November 2025, which shifts the derived commencement dates by one day. Pensieve treats the earlier date as the conservative one.]
| Document ID | Title | What it carries that this one does not |
|---|---|---|
POL-GL-053 |
Privacy Policy | The full description of the personal data Pensieve holds as a Data Fiduciary, the purposes, the retention, and the complete statement of your rights |
POL-EU-053 |
Privacy Policy: GDPR Variant (EU/EEA) | The EU, EEA and UK rights in full, including restriction, portability and the absolute objection to marketing |
POL-AU-053 |
Privacy Policy: Australia | The Australian Privacy Principles position, including the access-charge rule |
POL-GL-066 |
Grievance Redressal Policy and Grievance Officer Notice | The Grievance Officer's details, the full grievance mechanism, the routing rule for a hospital's records, and external escalation by market |
NTC-GL-023 |
Notice to the Data Principal at the Point of Collection | The itemised collection notice, and what a consent record contains |
NTC-GL-019 |
Data Principal Request Notice | The exact acknowledgement and response Pensieve sends you |
DIS-GL-023 |
Data Deletion & Return Disclosure | The erasure process, and what is retained because the law requires it |
DIS-GL-037 |
A Notice for Patients and Hospital Staff | Who holds a patient's medical record, in plain language, for the patient route |
POL-GL-072 |
Marketing Communications and Consent Policy | How Pensieve contacts non-customers, and how to withdraw |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-03 | Legal | First issue. Public, multi-market Data Principal rights-request intake: routing rule sending patients to the hospital and website data to the self-serve tool; a reader-facing rights table with the statutory basis for each right; sixteen concretely renderable form fields in five groups; proportionate identity verification with a no-reuse and deletion commitment; the response timelines committed on the form's face; the no-fee position with the narrow GDPR exception; and the appeal route to the Grievance Officer and then the Data Protection Board of India or the relevant supervisory authority. |
FRM-GL-505 v1.0.0 | Last Modified On 03 August 2026 | Review due 03 February 2027 | Published at https://trust.pensievelabs.org