Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
This is the Australian Privacy Principle 1.3 privacy policy of Edsol Edtech Pvt. Ltd., trading as Pensieve Labs. It is available free of charge and in a downloadable form at https://trust.pensievelabs.org. If you would like it in another form, write to info@pensievelabs.org and we will provide it.
POL-AU-053 | Version 1.0.0 | Last Modified On 01 August 2026
This is the Australian Privacy Principle 1.3 privacy policy of Edsol Edtech Pvt. Ltd., trading as
Pensieve Labs. It is available free of charge and in a downloadable form at
https://trust.pensievelabs.org. If you would like it in another form, write to info@pensievelabs.org
and we will provide it.
It replaces Annexure B of the global Privacy Policy (POL-GL-053) for anyone in Australia. Where this
document and POL-GL-053 differ, this one applies to you.
| If you are | The policy that governs your information |
|---|---|
| A patient of a hospital that uses Pensieve | The hospital's privacy policy, not this one. The hospital decides what is collected about you, why, and who sees it. Pensieve holds that information on the hospital's behalf under DPA-AU-001. Ask the hospital's privacy officer, and see Section 3.1 below |
| A clinician, employee or contractor of a hospital that uses Pensieve | The hospital's policy for what is in your hospital record; this policy for the account credential Pensieve issues you |
| Someone who contacts Pensieve, visits the Trust Center, or works at a prospective customer | This policy |
| Someone applying for a role at Pensieve | This policy, Section 4.4 |
Edsol Edtech Pvt. Ltd. is a Private Limited Company incorporated in India,
with its registered office at 28, Jamunather Bulandshahar Uttar Pradesh India. It supplies Pensieve,
an operating system for hospitals, under the brand Pensieve Labs.
| Purpose | Contact |
|---|---|
| Privacy enquiries, access and correction requests | info@pensievelabs.org |
| Complaints | info@pensievelabs.org (Section 12) |
| Security reports | info@pensievelabs.org |
| Postal | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` |
We have no office, employee or agent in Australia unless the agreement with a particular customer records otherwise. That is stated because it is material to how you deal with us, and Section 2 explains why it does not put us outside the Privacy Act.
2.1 We treat ourselves as bound. Section 5B of the Privacy Act gives the Act extraterritorial operation where an organisation has an Australian link, and since the 2022 amendment carrying on business in Australia is sufficient: the information need not be collected or held in Australia. An organisation with paying Australian hospital customers, an Australian-facing website and an Australian support commitment carries on business in Australia on any sensible reading. We proceed on that basis.
2.2 We do not rely on the small business exemption. An entity with annual turnover at or below the
statutory threshold may be exempt from the Act. We supply software rather than health services, so on a
narrow reading we could argue the exemption applies to us. We do not make that argument, we do not
make it in a tender, and we contractually bind ourselves to the Australian Privacy Principles in
DPA-AU-001 Section 2.1 whatever our status under the Act.
2.3 Election under section 6EA. Section 6EA allows an entity that would otherwise be outside the Act
to elect to be treated as an organisation, becoming bound by the Principles and subject to the
Commissioner, and to be entered on a public register.
Our status: Pensieve au s6ea election status.
2.4 Every Australian hospital is bound regardless of size, because the small business exemption does not apply to a private sector health service provider.
3.1 Information inside a hospital's tenant. Patient records, clinical data, prescriptions, results,
images, billing records and the hospital's workforce records are the hospital's information. The
hospital decides what is collected, why, and who may see it. We handle that information only on the
hospital's documented instructions, under DPA-AU-001, and for no purpose of our own.
Australia has no controller and no processor. Both the hospital and Pensieve are APP entities in our own right for the information each of us handles. The agreement allocates responsibility between us; it does not transfer either party's obligations. If you are a patient, your rights of access and correction are exercised against the hospital, and we support the hospital in answering you.
3.2 Information we hold for our own purposes. We hold personal information in our own right for two categories only:
This policy governs 3.2. DPA-AU-001 and the hospital's own policy govern 3.1.
3.3 What we never do. We do not use a hospital's tenant information for our own purposes. We do not sell, rent, licence or trade personal information, and never have. We do not use tenant information to train, fine-tune, evaluate or ground a machine learning model. We do not combine one hospital's information with another's.
| Category | What it is | How it is collected |
|---|---|---|
| 4.1 Business contact information | Name, work e-mail, job title, employer, work telephone, correspondence | From you, when you contact us, request access to a document, complete a form, meet us, or are introduced to us. Sometimes from a public register, a professional network or a published tender document |
| 4.2 Trust Center account information | E-mail address, the organisation you belong to, the documents you opened and when, sign-in events, internet protocol address and device type | Automatically, when you request and use access |
| 4.3 Support correspondence | Ticket text, identifiers, error references and the times of the exchange | From you or from your hospital's nominated contacts |
| 4.4 Recruitment information | Curriculum vitae, contact details, work history, references, right-to-work information | From you, or from a recruiter you have authorised |
| 4.5 Website information | Pages viewed, referrer, approximate location derived from internet protocol address | Automatically. Our cookie position is in POL-GL-054 |
4.6 Information we do not want. Do not send us patient records, clinical documents, or any
individual's health information in an e-mail, a ticket, a screenshot or an attachment. Where we receive
personal information we did not ask for and could not lawfully have collected, we destroy it, record
that we did, and tell the sender, which is what APP 4 requires. The controls that keep this rare are in
DIS-AU-033 Section 5.
4.7 Anonymity. You may make a general enquiry without giving us your name. We cannot provide gated documents, a credential or support without identifying you.
We collect personal information only where it is reasonably necessary for our functions, and we use and disclose it only for the purpose it was collected for, for a directly related secondary purpose you would reasonably expect, with your consent, or where required or authorised by law.
| Category | Purpose |
|---|---|
| Business contact information | To respond to you, to run a sales or procurement process, to negotiate and administer a contract, and to send operational and security notices |
| Trust Center account information | To grant, control and audit access to gated documents; to secure the service; to comply with our own obligations |
| Support correspondence | To resolve the issue and to improve our own service quality |
| Recruitment information | To assess your application. Unsuccessful applications are retained for the period in Section 10 unless you ask us to delete them |
| Website information | To operate and secure the site |
We do not use your business contact information for automated profiling, behavioural advertising or scoring.
Health information is sensitive information under the Act. We do not collect sensitive information for
our own purposes. All clinical content we handle is inside a hospital's tenant under Section 3.1, and every
control in ADD-GL-001 and DPA-AU-001 is calibrated to the fact that it is sensitive information.
7.1 To whom we disclose. To the service providers that operate our own systems, listed with their
function and location in DIS-GL-009; to our professional advisers under a duty of confidence; to a
hospital, where you hold a credential issued at that hospital's request; and where required or authorised
by law, on the process in POL-GL-067.
7.2 Overseas recipients: the countries. We are likely to disclose personal information to recipients
outside Australia. The countries are listed and kept current in DIS-GL-009. As at the Last Modified
On date of this policy, personal information covered by this policy is handled in India, where our
engineering and support function is located, and in the countries in which our own service providers
operate.
7.3 What that means legally. Where an Australian entity discloses personal information overseas, it
generally remains accountable for the recipient's acts and practices as though they were its own. For
information a hospital gives us, we accept that consequence contractually: DPA-AU-001 Section 3 contains a
binding flow-down of the Australian Privacy Principles, disclosure of every access country, the access
controls in DIS-AU-033, and an indemnity. We do not argue that offshore access by our own staff is a
"use" rather than a "disclosure", and we do not ask a hospital to rely on that argument.
7.4 Where hospital data is held. Australian hospital tenant data is stored and processed in an
Australian region, with backups and logs held in that region. The per-deployment-model position, and the
components Pensieve has not yet verified, are in DIS-AU-008.
7.5 My Health Record. We do not hold, receive, process or handle My Health Record system records or
information relating to them, and we are not a registered contracted service provider under the My
Health Records Act 2012. DIS-AU-033 Section 4 explains why this is an exclusion rather than a control.
8.1 Our own decisions about you. We do not use a computer program to make, or substantially and directly to assist in making, any decision about you that could reasonably be expected to significantly affect your rights or interests. Access to gated documents is approved by a person.
8.2 Inside a hospital's tenant. The Platform can be configured by a hospital to automate or assist administrative decisions, for example eligibility and benefit determination, financial hardship assessment, payment-plan decisions, appointment or waitlist ordering, or rostering. Those are the hospital's decisions, made under the hospital's configuration and disclosed in the hospital's own privacy policy.
8.3 What we supply so the hospital can disclose them. From before 10 December 2026, when the
automated decision-making transparency requirement commences, we maintain for each hospital a register
of every automated or substantially-assisted decision point configured in its tenant: the inputs, the
effect, and whether a person reviews the outcome, and we generate from it the disclosure text the
hospital needs for its own policy. DPA-AU-001 Section 10.3 is the contractual commitment.
8.4 The obligation is transparency, not consent. Australian law requires disclosure of this kind of processing. It does not require consent and does not confer a right to human review. We say so because the position differs from the European one and the difference is often assumed away.
The controls we implement are in the Security Addendum (ADD-GL-001), with the specifics in
DIS-GL-011 (encryption), DIS-GL-012 (authentication and access control) and DIS-GL-013 (audit
logging). Access to production is not standing, is separately approved, is time-bound and is logged, per
DIS-AU-033 Section 3.
We do not represent that our systems are immune from attack, and we hold no security certification.
What we publish instead (a self-assessed control position, a penetration test attestation, a software
bill of materials and the control set itself) is listed in REG-AU-002 Section 4. Saying that plainly is
worth more than a claim we cannot evidence.
10.1 The principle. We keep personal information only while the purpose it was collected for is being served, or while a law requires us to keep it. APP 11.2 requires destruction or de-identification when it is no longer needed, and we treat that as an obligation rather than good practice.
| Category | Retention |
|---|---|
| Business contact information | While the relationship is live, and for the period in POL-GL-111 afterwards |
| Trust Center account and access records | For the period in POL-GL-111, then deleted |
| Support correspondence | For the period in POL-GL-111 |
| Recruitment information | Twelve months after the decision, unless you ask us to delete it sooner |
| Audit logs | The floor in DIS-GL-034 |
10.2 Hospital tenant data. Retention inside a hospital's tenant is configured by the hospital, per
record class, because Australian retention minimums differ by State, by record type and by the patient's
age at collection. We do not set the number. DPA-AU-001 Section 7.5 and Schedule AU-B.
10.3 Deletion evidence. When tenant data is deleted we issue a certificate identifying what was
deleted, when, from which stores, and what remains under a legal hold (DIS-GL-023).
11.1 Your right. You may ask us for the personal information we hold about you, and you may ask us to correct it.
11.2 How. Write to info@pensievelabs.org. Tell us enough to let us find the information and
verify who you are. We do not charge for a request.
11.3 Our timeframe. We respond within 30 calendar days, and we aim to respond within 10 business days.
11.4 If we refuse. We give you written reasons, tell you which exception we rely on, and tell you how to complain. Where we refuse correction, you may ask us to attach a statement to the information noting that you consider it inaccurate, and we will do so.
11.5 If you are a patient of a hospital. Your access and correction rights are exercised against the hospital (Section 3.1). In New South Wales, Victoria and the Australian Capital Territory you may also have a direct statutory right of access to your health record, with its own timeframes, and the hospital will tell you how to use it.
12.1 Complain to us first. Write to info@pensievelabs.org, or to
28, Jamunather, Bulandshahar, Uttar Pradesh, India. Tell us what happened and what you would like us to do.
12.2 What we do. We acknowledge within 5 business days, investigate, and give you a written
response within 30 calendar days with our findings, what we have done, and what you can do next. The
full process is POL-GL-066.
12.3 If you are not satisfied. You may complain to the Office of the Australian Information Commissioner. In New South Wales, Victoria and the Australian Capital Territory you may instead be able to complain to the State or Territory privacy regulator about health information handled in that jurisdiction. We will tell you which regulator we think applies, and we will not obstruct a complaint to either.
Where we suspect a data breach affecting personal information we hold, we start assessing immediately and target completion within 5 business days, taking all reasonable steps to complete it within the statutory maximum of 30 calendar days. Where the breach is an eligible data breach we notify as soon as practicable.
Where the information is inside a hospital's tenant, the hospital notifies and we support, with the
forensic timeline, the affected-record extract, the affected-individual list and a draft statement, on the
committed clock in DPA-AU-001 Section 4. Only one entity needs to notify, and we settle which one in the
contract rather than during the incident.
We do not pay ransoms. We do not make ransomware or extortion payments and will not make one on a customer's behalf.
The Trust Center, the site serving this document, runs on the stack in DIS-GL-009 Section 3. It is not
hosted in Australia, is not connected to any hospital's Platform instance, and holds no patient data.
What it holds about you is in Section 4.2. Our cookie position is POL-GL-054; we do not use advertising or
cross-site tracking cookies.
Health information handled in New South Wales, Victoria and the Australian Capital Territory is also
subject to a State or Territory health records statute that binds private providers. Where a hospital is
in one of those jurisdictions, DPA-AU-001 Schedule AU-B is attached and extends our undertaking to the
applicable Health Privacy Principles. In Queensland, Western Australia, South Australia, Tasmania and
the Northern Territory the Commonwealth Privacy Act is the whole of the regime for a private hospital,
and we say so rather than making a blanket claim to comply with "Australian privacy law".
We do not knowingly collect personal information about a child for our own purposes; the Platform is a business system and the Trust Center is for people acting in a professional capacity. Paediatric records inside a hospital's tenant are the hospital's information under Section 3.1 and are handled as sensitive information.
The Children's Online Privacy Code does not apply to us, because it applies to designated online
services and expressly excludes health services.
[UNVERIFIED: the exclusion wording is from the exposure draft of the Code; we will confirm it on registration and update this section if it changes.]
We review this policy at least annually and whenever the law or our practices change. The Last Modified
On date at the top is the date of the current version, and every superseded version is retained and
retrievable at https://trust.pensievelabs.org. Where a change is material to how we handle your
information, we notify the contacts we hold.
We keep this policy current deliberately. A missing or out-of-date privacy policy is directly penalisable in Australia under the infringement-notice tier introduced in 2024, and the currency of this document is monitored rather than assumed.
| Document | For |
|---|---|
POL-GL-053 |
The global privacy policy. This document replaces its Annexure B for Australia |
DPA-AU-001 |
What we agree with a hospital about the information in its tenant |
DIS-AU-008, DIS-AU-033 |
Where the data is, and who can reach it from where |
DIS-GL-009 |
Our service providers, their function and their location |
POL-GL-066 |
The complaints process |
POL-GL-054 |
Cookies |
POL-GL-067 |
How we respond to a demand from a public authority |
POL-GL-111, DIS-GL-034 |
Retention and log retention |
REG-AU-002 |
The Australian assurance evidence set referenced in Section 9 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Legal | First issue. Standalone Australian Privacy Principle 1.3 policy: section 5B position, express non-reliance on the small business exemption, section 6EA election status, the two-role distinction, overseas recipients and countries, automated decision-making disclosure ahead of the December 2026 commencement, the Notifiable Data Breaches position, and the State health records applicability statement. |