Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
POL-EU-053
v1.0.0 | 01 August 2026
POL-EU-053 v1.0.0, Last Modified On 01 August 2026, Tier: Public
If you are a patient of a hospital that uses Pensieve, this policy does not govern your
health records. Your hospital does.
The hospital is the controller of its patients' personal data. It decides what is recorded, who may see
it, how long it is kept and on what legal basis it is processed. Edsol Edtech Pvt. Ltd. is the
processor: it operates the platform on the hospital's documented instructions and does nothing with
patient data on its own account. A patient exercising a right under the GDPR should contact the
hospital, which will contact Pensieve Labs if it needs assistance. If a patient contacts
Pensieve Labs directly, Pensieve Labs will not answer the substance; it will pass the request to
the hospital within two business days, tell the patient it has done so, and identify the hospital if the
patient does not already know it.
This policy covers the personal data Edsol Edtech Pvt. Ltd. processes as a controller in its own
right: the personal data of people who visit its websites and Trust Center, who contact it, who work at
a customer or prospective customer and deal with it, who apply for a role, and who report a security
vulnerability.
| If you are | The controller is | The policy is |
|---|---|---|
| A patient of a hospital using the Platform | The hospital | The hospital's own privacy notice |
| A clinician or staff member of a hospital using the Platform, in respect of your clinical activity records | The hospital | The hospital's own privacy notice |
A hospital administrator whose account Pensieve Labs holds for contract administration and support |
Edsol Edtech Pvt. Ltd. |
This policy |
A visitor to https://trust.pensievelabs.org or the marketing site |
Edsol Edtech Pvt. Ltd. |
This policy |
A person who contacts Pensieve Labs by email, form or telephone |
Edsol Edtech Pvt. Ltd. |
This policy |
| A job applicant | Edsol Edtech Pvt. Ltd. |
This policy |
| A security researcher reporting a vulnerability | Edsol Edtech Pvt. Ltd. |
This policy and POL-GL-059 |
This is the EU/EEA fork of the global privacy policy POL-GL-053, which is written to Indian statutory
notice requirements. The two are not cumulative: if you are in the EEA, this policy applies to you and
POL-GL-053 does not. The substantive processing is the same; the information duties, the legal bases
and the rights are stated here as Articles 13, 14 and Chapter III of the GDPR require.
| Item | Detail |
|---|---|
| Controller | Edsol Edtech Pvt. Ltd., trading as Pensieve Labs |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` | |
| Privacy contact | info@pensievelabs.org |
| Data protection officer | [TO BE SUPPLIED], [TO BE SUPPLIED], where one is appointed. Where no appointment is required and none is made, this row says so rather than naming a role that does not exist |
| Representative in the Union under Article 27 | Where our processing is subject to the GDPR under Article 3(2) and Article 27 requires a representative, the representative's identity and contact details are published at https://trust.pensievelabs.org. Where Article 27 does not apply, no representative is designated and none is claimed |
| Security contact | info@pensievelabs.org |
Each row states the categories, the purpose, the Article 6 basis, the source if not you, and the retention. Where the basis is legitimate interests, the interest is named; a legal basis that does not say what the interest is has not been given.
| # | Who | Categories | Purpose | Article 6 basis | Retention |
|---|---|---|---|---|---|
| 1 | Website and Trust Center visitors | IP address, device and browser data, pages viewed, referrer, timestamps | Serving the site, security, abuse prevention, aggregate audience measurement | 6(1)(f): our legitimate interest in operating and securing a site we are responsible for | Server and security logs: 12 months. Aggregate statistics containing no personal data: indefinitely |
| 2 | Trust Center access requesters | Work email, name, organisation, role, the message you send | Deciding whether to grant access to gated documents, and administering the grant | 6(1)(b): steps at your request before entering a contract; and 6(1)(f): our interest in controlling access to confidential material | Access request record: 24 months from decision. Access grant and viewing log: for the life of the grant plus 24 months |
| 3 | Enquirers and prospective customers | Name, business contact details, employer, role, correspondence, meeting notes, proposal history | Responding to you, qualifying and progressing a sale, and keeping a record of what was agreed | 6(1)(b) where you are the counterparty; 6(1)(f) (our interest in business development and in an accurate record of dealings) where you act for an organisation | 36 months from last meaningful contact, unless a contract results |
| 4 | Customer administrative users | Name, work email, role, authentication events, support interactions | Provisioning and administering accounts, delivering support, contract administration, billing | 6(1)(b) and 6(1)(f): our interest in administering a contract with your employer | Term of the contract plus the statutory limitation period |
| 5 | Customer signatories and authorised persons | Name, designation, signature, evidence of authority, identifiers a counterparty requires for onboarding | Contract execution, vendor onboarding, statutory and tax records | 6(1)(b), and 6(1)(c): compliance with legal obligations to keep books and records | The statutory record-keeping period applicable to the contract |
| 6 | Persons named in a support request | Whatever the requester includes | Investigating and resolving the request | 6(1)(f): our interest, and the hospital's, in resolving a fault. Where the requester includes patient data, the hospital is the controller of that data and clause 3 of DPA-EU-001 governs |
Ticket retention per DIS-GL-034; patient data pasted into a ticket is removed on identification |
| 7 | Newsletter and update subscribers | Email address, subscription preferences, delivery and open events | Sending the updates you asked for | 6(1)(a): consent, withdrawable at any time by the link in every message | Until you unsubscribe, plus 12 months to evidence the withdrawal |
| 8 | Job applicants | Application, CV, correspondence, interview notes, references where you nominate them | Assessing your application | 6(1)(b): steps at your request before a contract; 6(1)(f): our interest in a documented, fair process | 6 months after the decision, or 24 months where you consent to being kept on file |
| 9 | Security researchers | Name or pseudonym, contact details, the report | Triaging and remediating, and crediting you if you want it | 6(1)(f): our interest, and the public interest, in the security of a health platform | 36 months from closure |
| 10 | Everyone | Records of data protection requests and our responses | Demonstrating accountability under Article 5(2) | 6(1)(c) and 6(1)(f) | 36 months from closure |
Special-category data. In its own controller processing Edsol Edtech Pvt. Ltd. does not seek, and asks
you not to send, data revealing racial or ethnic origin, political opinions, religious or philosophical
beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or
sexual orientation. Where such data reaches us unsolicited (most commonly in a support ticket), we treat
it under DPA-EU-001 if it is a customer's patient data, and otherwise delete it.
Children. Our sites and services are not directed to children and we do not knowingly collect children's personal data in our controller capacity. Where a hospital's deployment processes children's data, the hospital is the controller and the national conditions applicable to it govern.
Where we rely on Article 6(1)(f) we have carried out a balancing assessment. Its substance:
| Interest | Why processing is necessary | Impact on you | Safeguards | Your control |
|---|---|---|---|---|
| Operating and securing our sites | A site that is not logged cannot be defended | Low. Technical data, short retention, no profiling | 12-month retention, no advertising use, no sale, no cross-site tracking | Object under Article 21; use the cookie controls |
| Controlling access to gated documents | The documents contain security detail that should not be indexed | Low. Business contact data you supplied | Purpose-limited, not used for unrelated marketing | Object; ask us to revoke the grant and delete the record |
| Business development with organisations | We must be able to record who said what to whom | Low. Business-context data, no consumer profiling | No enrichment from data brokers, no automated scoring of individuals | Object at any time and we stop. Article 21(2) is absolute for direct marketing |
| Administering a contract with your employer | Someone must hold the account | Low | Least privilege, access logging | Ask your employer; we act on its instruction where it is the controller |
| Investigating support requests | We cannot fix what we cannot see | Depends on what the requester sends | Data minimisation, pseudonymised support views, patient data removed on identification | Object; ask us to purge the ticket |
| Security research handling | Vulnerabilities must be triaged | Low | Pseudonymous reporting accepted | Report anonymously if you prefer |
A copy of the full assessment for any row is available on request to info@pensievelabs.org. We
publish the substance rather than asserting that a balance was struck.
We do not sell personal data and we do not share it for another party's marketing.
| Recipient | Why | Safeguard |
|---|---|---|
| Sub-processors: hosting, email delivery, ticketing, monitoring, e-signature, analytics | To operate our own business | Each is named in DIS-GL-009 with its role, country and safeguard. Article 28 contracts in place |
| The hospital, where you are its administrator or its user | To administer the contract and support | The contract between us and the hospital |
| Professional advisers: legal, tax, audit, insurance | Advice and compliance | Professional confidentiality obligations |
| Public authorities | Where legally compelled | POL-GL-067. We assess the legality of every demand, challenge it where there are reasonable grounds, disclose no more than the minimum, and notify you where we lawfully can. As at 01 August 2026 we have received no government request for a customer's personal data |
| An acquirer, on a merger or sale | To transact | Confidentiality until completion; notice to you; this policy continues to apply until superseded |
Edsol Edtech Pvt. Ltd. is established in India, for which there is no adequacy decision under Article
45. We say so plainly rather than burying it.
| Data | Where it goes | Safeguard |
|---|---|---|
| Customer patient data processed under a hospital contract | Stored and processed in an EEA region. Remote access from India for support is a restricted transfer | Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, incorporated into DPA-EU-001, with the supplementary measures in its clause 12 and the assessment in REP-GL-021 |
| Personal data we process as controller under this policy | India, and the sub-processor locations in DIS-GL-009 |
Standard Contractual Clauses, Module One or Module Two as applicable, with equivalent supplementary measures |
REP-GL-021, our transfer impact assessment, concludes that Indian law does not, on its face, provide
protection essentially equivalent to that guaranteed within the Union. It then explains, measure by
measure, why a specific transfer is nonetheless lawful, and what would suspend it. We publish it because a
vendor willing to write that down is a vendor whose other statements can be believed. A copy of the
Clauses and of the assessment is available on request.
DIS-EU-008 states where data is stored and how the plaintext boundary works.
Under Chapter III of the GDPR you have the right to:
| Right | Article | What it means here |
|---|---|---|
| Access | 15 | A copy of your personal data and the information in this policy, specific to you |
| Rectification | 16 | Correction of inaccurate data and completion of incomplete data |
| Erasure | 17 | Deletion, where one of the Article 17(1) grounds applies and no exception does |
| Restriction | 18 | We hold but do not otherwise process, in the listed circumstances |
| Portability | 20 | For data you provided, processed on consent or contract and by automated means, in a structured, commonly used, machine-readable format |
| Object | 21 | To processing based on legitimate interests. For direct marketing the right is absolute and we stop on request, without a balancing test |
| Withdraw consent | 7(3) | At any time, for row 7 in Section 3. Withdrawal does not affect the lawfulness of processing before it |
| Not be subject to solely automated decisions with legal or similarly significant effects | 22 | We make none. See Section 8 |
| Complain to a supervisory authority | 77 | Section 9 |
How to exercise. Email info@pensievelabs.org. We respond without undue delay and in any event
within one month, extendable by two further months for complex or numerous requests, in which case we
tell you within the first month and explain why. There is no charge unless a request is manifestly
unfounded or excessive, in which case we may charge a reasonable fee or refuse and explain why.
Verification. We verify identity proportionately. We do not demand an identity document where an existing account or a reply from a known address is sufficient, and we do not use verification as a delay tactic.
If you are a patient, see the box at the top: the hospital is the controller and your rights are exercised against it. We assist the hospital within seven business days.
Edsol Edtech Pvt. Ltd. does not make decisions about you based solely on automated processing that
produce legal effects concerning you or similarly significantly affect you. Trust Center access requests
may be routed by a domain rule, but a refusal is reviewed by a person before it takes effect, and you can
ask for that review.
Inside the Platform, any automated processing is the hospital's, configured by the hospital, and is
disclosed in DIS-GL-027. Pensieve Labs does not use customer data to train a model that serves
another customer.
If you think we have processed your personal data unlawfully, please tell us first at
info@pensievelabs.org. We would rather fix it than be told about it by a regulator. You are entitled
to complain regardless, to the supervisory authority of the EEA State in which you live, work, or where the
alleged infringement took place. In Denmark that authority is Datatilsynet; in Norway it is
Datatilsynet. You also have the right to an effective judicial remedy under Article 79 and to compensation
under Article 82.
POL-GL-054 is the cookie policy and it is the source of truth. In summary, on our EEA-facing properties:
We describe our security controls publicly rather than asserting that data is "secure": WPR-GL-001,
DIS-GL-011 (encryption), DIS-GL-012 (access control), DIS-GL-013 (audit logging) and DIS-GL-017
(vulnerability management). Edsol Edtech Pvt. Ltd. holds no security certification of any kind;
WPR-GL-005 says what compensates for that and what a hospital should verify instead.
If a personal data breach affecting you occurs and it is likely to result in a high risk to your rights and
freedoms, we will communicate it to you without undue delay under Article 34, unless one of the Article
34(3) exceptions applies. DIS-EU-016 states the commitments in full.
We version this policy, date it, and keep the previous versions retrievable at
https://trust.pensievelabs.org. Where a change materially affects how we process your personal data we
notify you before it takes effect, by email where we have your address, and by a notice on the site
otherwise. We do not make a material change effective retrospectively.
| ID | Artefact |
|---|---|
POL-GL-053 |
Privacy Policy: global master (India) |
POL-GL-054 |
Cookie Policy & Consent Notice |
DPA-EU-001 |
Data Processing Agreement (EU/EEA) |
REP-GL-021 |
Transfer Impact Assessment: EU/EEA to India |
DIS-EU-008 |
Data Residency Statement (EEA) |
DIS-EU-016 |
Breach Notification Commitment (GDPR) |
DIS-GL-009 |
Subprocessor Register |
POL-GL-067 |
Legal and Law Enforcement Request Policy |
POL-GL-052 |
Trust Center Terms of Use |
POL-GL-059 |
Vulnerability Disclosure Policy |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Privacy | First issue. EEA fork of POL-GL-053 written to Articles 13, 14 and Chapter III: controller/processor boundary stated first, per-row legal bases with named legitimate interests, the published balancing substance, the transfer position stated without evasion, and opt-in cookie consent. |