Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
If you are in the European Union or the European Economic Area, this policy does not apply to you. POL-EU-053 (Privacy Policy, GDPR Variant) does, and the two are not cumulative. The substantive processing is the same; the information duties, the legal bases and the rights are stated there as Articles 13, 14 and…
This document is the source of truth for: marketing:/legal/privacy, marketing:/privacy-policy, marketing:/footer/privacy, trust:/legal/privacy, trust:/documents/POL-GL-053, app:/legal/privacy, app:/grievance
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
POL-GL-053 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
If you are in the European Union or the European Economic Area, this policy does not apply to you.
POL-EU-053(Privacy Policy, GDPR Variant) does, and the two are not cumulative. The substantive processing is the same; the information duties, the legal bases and the rights are stated there as Articles 13, 14 and Chapter III of the General Data Protection Regulation require.
Edsol Edtech Pvt. Ltd. handles personal data in two entirely separate capacities, and confusing them
is the single most common error in reading a vendor privacy policy.
| If you are… | Then… | The document that governs |
|---|---|---|
| A patient, attendant, or a person whose record a hospital holds | Pensieve is not the organisation responsible to you. The hospital is. Pensieve processes that data only on the hospital's documented instructions, as its Data Processor. Your rights run against the hospital, and its own privacy notice tells you how to exercise them. | The hospital's notice; and, as between the hospital and Pensieve, DPA-GL-001 |
| A clinician, nurse, administrator or other staff member of a hospital using the Platform | Same as above for your record inside the hospital's tenant. But where you hold a Pensieve credential, Pensieve holds your business contact and access data in its own right. | The hospital's notice for your employment record; this Policy for your credential and access data |
| A visitor to our website, a Trust Center user, a prospect, a supplier, an applicant or anyone who contacts us | Pensieve determines why and how your data is processed. Pensieve is the Data Fiduciary. | This Policy |
This Policy covers what
Edsol Edtech Pvt. Ltd.does as a Data Fiduciary in its own right. It does not, and cannot, describe how any hospital handles its patients' records. No patient, clinical, diagnostic or demographic record of a Data Principal is ever processed by Pensieve as a Data Fiduciary, under any circumstance.
This Policy applies to personal data Edsol Edtech Pvt. Ltd. processes as a Data Fiduciary in connection
with:
https://pensievelabs.org;https://trust.pensievelabs.org;[TO BE SUPPLIED];Pensieve platform;It does not apply to: personal data inside a hospital's tenant, which is governed by DPA-GL-001 and
by that hospital's own notice; personal data a third-party site handles when you leave ours; or personal
data a hospital transmits to a third-party system using its own credentials under the bring-your-own-key
and bring-your-own-credential model (DIS-GL-025).
1.1 Edsol Edtech Pvt. Ltd. is a Private Limited Company incorporated in India,
bearing Corporate Identity Number [TO BE SUPPLIED], with its registered office at
28, Jamunather Bulandshahar Uttar Pradesh India. It trades as Pensieve Labs and operates the
Pensieve platform.
1.2 Contact points.
| Purpose | Contact |
|---|---|
| Privacy, this Policy, and rights requests | info@pensievelabs.org |
| Grievance Officer (statutory) | [TO BE SUPPLIED], info@pensievelabs.org |
| Data Protection Officer, where appointed | [TO BE SUPPLIED], [TO BE SUPPLIED] |
| Security incidents | info@pensievelabs.org |
| Legal | info@pensievelabs.org |
| EU / EEA representative, where appointed | Pensieve eu representative name, Pensieve eu representative email |
| UK representative, where appointed | Pensieve uk representative name, Pensieve uk representative email |
1.3 Where a representative is shown as [TO BE SUPPLIED], none has yet been appointed and Pensieve
says so rather than implying one exists. Contact info@pensievelabs.org directly.
2.1 Pensieve as Data Processor. For all personal data inside a hospital's tenant, patient records,
clinical documentation, diagnostic results, images, billing records, the hospital's own personnel records
and the audit logs of its operations, the hospital is the Data Fiduciary and Pensieve is a Data
Processor acting on the hospital's documented instructions. Pensieve does not determine the purposes of
that processing, does not use it for its own purposes, and does not decide what is collected or how long it
is kept. Section 8(1) of the Digital Personal Data Protection Act, 2023 places responsibility for that
processing on the Data Fiduciary. The full terms are in DPA-GL-001.
2.2 Pensieve as Data Fiduciary. Pensieve is a Data Fiduciary for exactly two categories, neither of which is data inside a hospital's tenant:
| Category | What it is |
|---|---|
| Business contact data | Name, work email, designation, work telephone, organisation, and the access and audit records of authorised users of the Platform, of the Trust Center, and of Pensieve's commercial, legal, finance and procurement contacts |
| Service operations data | Non-identifying operational telemetry about how the Platform runs, together with the administrative-user identities above, used to operate, secure, support and bill for the Platform |
2.3 What we never do. Pensieve does not: use hospital tenant data for its own purposes; sell, rent,
licence or trade personal data; use personal data for behavioural advertising; build a cross-hospital
profile of an individual; or use any customer data to train, fine-tune, validate or evaluate a
machine-learning model. That last commitment is unconditional and is repeated in POL-GL-050 clause 7.3
and DPA-GL-001.
2.4 De-identified statistics. Where Pensieve derives operational statistics, aggregation and
de-identification occur inside the tenant boundary before the data leaves it, no re-identification key is
retained, and no output permits identification of an individual, a clinician or a hospital. Personal data
under the Digital Personal Data Protection Act, 2023 is data about an identifiable individual;
genuinely de-identified aggregates fall outside it. The constraints are in DPA-GL-001 clause 3.4.
3.1 An itemised description. The following is the itemised description of personal data required by Rule 3(b)(i) of the Digital Personal Data Protection Rules, 2025, with the purpose for each, required by Rule 3(b)(ii).
| # | You are | Personal data | Source | Why we process it |
|---|---|---|---|---|
| 1 | A website visitor | IP address, browser and device type, pages viewed, referring page, session cookie identifiers | Your browser | To serve and secure the site, to prevent abuse, and to measure page-level usage in aggregate. See POL-GL-054. |
| 2 | Someone who submits an enquiry, demonstration request or contact form | Name, work email, telephone, organisation, role, the content of your message, and the bed count and location you tell us | You | To reply, to assess fit, to prepare a proposal, and to keep a record of the enquiry |
| 3 | A Trust Center access requester | Name, work email, organisation, role, stated reason for the request, approval decision and reason | You, and our administrator's decision | To decide the request, to provision or decline a credential, and to evidence what was released to whom |
| 4 | A Trust Center user | Credential identifier, authentication events, documents viewed and downloaded, timestamps, network address, click-through NDA acceptance record | Generated by your use | To operate and secure the Trust Center, to enforce access tiers, to evidence disclosure, and to trace an unauthorised disclosure. See POL-GL-052 clause 4. |
| 5 | An Authorised User of the Platform | Name, work email, designation, role assignment, credential and authentication events, access and action audit records | Your hospital, and generated by your use | To provision access, to operate and secure the Platform, to support you, and to maintain the audit trail the hospital and the law require |
| 6 | A commercial, legal or finance contact at a hospital | Name, work email, telephone, designation, authority evidence, correspondence, signature records, and the customer know-your-customer file | You, your organisation, public registers | To negotiate, execute and administer an agreement; to invoice and collect; and to meet our own statutory record-keeping duties |
| 7 | A supplier, adviser or partner contact | Name, work email, telephone, role, contract and payment records | You, your organisation | To manage the relationship, to pay, and to meet statutory record-keeping duties |
| 8 | Someone who contacts support | Name, work email, ticket content, and any screenshot or file you attach | You | To resolve the ticket and to improve the Platform |
| 9 | A security researcher | Name or handle, contact address, report content | You | To triage and fix the report, to communicate with you, and to credit you where you wish |
| 10 | A job applicant | Application, curriculum vitae, correspondence, interview notes, references and, where an offer is made, verification checks | You, your referees, verification providers | To assess the application, and to conduct pre-employment verification |
| 11 | An event or webinar attendee | Name, work email, organisation, attendance record | You, the event organiser | To run the event and to follow up where you asked us to |
3.2 Support artefacts are the practical risk, and how it is closed. A support ticket, a screenshot or a
log excerpt can inadvertently contain patient data. Pensieve's position is that it does not want to
receive it. Product telemetry and application logs are redacted of personal data by default; support
personnel are instructed not to request or retain patient data in a ticket; and where such data
nevertheless reaches a ticket, it is treated as Customer Personal Data under DPA-GL-001, not as data
Pensieve holds as a Data Fiduciary, and is removed. See DPA-GL-001 clause 3.5.
3.3 Data we do not want. Do not send us patient records, clinical documents or any individual's health
data through a website form, a general email address or a support ticket. POL-GL-051 clause 6.2 says the
same thing. Where a secure exchange is genuinely needed, ask and we will provide one.
3.4 Sources other than you. Where we obtain your business contact details from a public register, an industry directory, a conference list, a referral or a colleague at your organisation, we say so on first contact and tell you how to stop hearing from us.
4.1 India. Under the Digital Personal Data Protection Act, 2023, personal data may be processed for a lawful purpose either with the Data Principal's consent or for a certain legitimate use under section 7. Pensieve relies on:
| Processing | Basis |
|---|---|
| Replying to an enquiry you send us | Section 7(a): you have voluntarily provided the data for that purpose and have not indicated that you object |
| Provisioning and operating a credential you or your employer requested | Section 7(a), and performance of the agreement with your organisation |
| Operating, securing and auditing the Platform and the Trust Center | Section 7(a), and compliance with Pensieve's own obligations |
| Meeting a statutory obligation: tax, company law, incident reporting, subscriber records under the CERT-In Directions of 2022 | Section 7(b) and section 7(c) as applicable |
| Marketing communication to a business contact | Consent, withdrawable at any time with the same ease with which it was given |
| Recruitment | Section 7(a), and consent where required |
4.2 European Union, European Economic Area and the United Kingdom. Where the General Data Protection Regulation applies, our bases are Article 6(1)(b) (performance of a contract or steps before entering one), Article 6(1)(c) (legal obligation), Article 6(1)(f) (legitimate interests: operating, securing and developing our business, where those interests are not overridden by your rights) and Article 6(1)(a) (consent, for marketing and for non-essential cookies). See Annexure A.
4.3 Australia. See Annexure B. United Arab Emirates. See Annexure C.
4.4 Withdrawing consent. Where we rely on consent, you may withdraw it at any time by writing to
info@pensievelabs.org or by using the unsubscribe link in any marketing message. Withdrawal is as
easy as giving consent was. Withdrawal does not affect processing already carried out, and does not
affect processing we carry out on a different basis; for example, we will continue to hold contract and
invoice records that tax law requires us to keep.
Rule 3 of the Digital Personal Data Protection Rules, 2025 requires a notice to be understandable independently of any other information, to give an itemised description of the personal data and the purposes in clear and plain language, and to give the means to withdraw consent, to exercise rights and to complain to the Data Protection Board. This Policy meets those requirements as follows.
| Requirement | Where it is met |
|---|---|
| Presented and understandable independently of other information | This Policy is a standalone document with its own address, is not embedded in the Terms of Service, and is published at https://trust.pensievelabs.org and on the website |
| Itemised description of the personal data | 3.1 |
| Specified purpose for each item | 3.1 and 4.1 |
| Means to withdraw consent, with ease comparable to that with which it was given | 4.4 |
| Means to exercise rights under the Act | 6 |
| Means to make a complaint to the Data Protection Board | 6.8 |
| Contact of a person who can answer questions (section 8(9), Rule 9) | The statutory notice at the head of this Policy |
| Availability in a language in the Eighth Schedule to the Constitution | This Policy is published in English and in Hindi; further language versions are added on request to info@pensievelabs.org |
A note on timing, stated honestly. Sections 3 to 17 of the Digital Personal Data Protection Act, 2023, and Rules 3 and 5 to 16 of the Digital Personal Data Protection Rules, 2025, commence on 14 May 2027. Pensieve operates to that end state now rather than waiting for the commencement date. The Data Protection Board of India was constituted in the first tranche of commencement; where a step in this Policy depends on the Board being operational, this Policy says so.
6.1 The rights. In respect of personal data Pensieve holds as a Data Fiduciary, you have the following rights under the Digital Personal Data Protection Act, 2023. Equivalent and additional rights under other laws are in the Annexures.
| Right | Section | What you get |
|---|---|---|
| Access | 11 | A summary of the personal data we process about you, a summary of the processing activities, and the identities of the Data Fiduciaries and Data Processors with whom we have shared it |
| Correction, completion and updating | 12 | Correction of inaccurate or misleading data, completion of incomplete data, and updating of data that has changed |
| Erasure | 12 | Erasure of your personal data, unless retention is necessary for a specified purpose or for compliance with a law in force |
| Grievance redressal | 13 | A response from our Grievance Officer, on the timelines in the statutory notice above, before you need to approach the Board |
| Nomination | 14 | The right to nominate one or more individuals to exercise your rights on your death or incapacity |
6.2 How to make a request. Write to info@pensievelabs.org, or use the rights request form
published at https://trust.pensievelabs.org/privacy/request. Requests are accepted in English or Hindi.
6.3 The identifier we need. Rule 14(5) of the Digital Personal Data Protection Rules, 2025 requires a Data Fiduciary to publish the identifier by which a request is made. Ours is the work email address you gave us, or, where you hold a Pensieve credential, that credential's registered email address. Where you write from a different address we will ask you to verify control of the registered address; we do this to protect you, and we will not ask for a government identity document to process a routine request.
6.4 Our timelines.
| Step | Timeline |
|---|---|
| Acknowledgement | Within 3 Business Days |
| Substantive response | Within 30 days |
| Extended response, where the request is complex or voluminous | Within 60 days, with reasons given inside the first 30 |
| Absolute outer limit for a grievance | 90 days, the statutory maximum in Rule 14(3) |
6.5 No charge. We make no charge for a rights request. Where a request is manifestly unfounded or repetitive we may say so and decline it, with reasons and with the escalation route in 6.8.
6.6 What we will tell you when we refuse. Where we refuse a request in whole or in part we will tell you which part, the reason, the provision relied on, and how to escalate. We will not refuse silently.
6.7 Erasure against a retention obligation. Where you ask us to erase data we are required to keep, we will erase what we can, retain what we must, and tell you exactly which records were retained and under which obligation. That record is an Erasure Decision Record and you may have a copy.
6.8 Escalation. If you are not satisfied with our response:
6.8.1 escalate within Pensieve under the Grievance Redressal Policy (POL-GL-066), which names the
escalation ladder and the response times at each rung;
6.8.2 India: complain to the Data Protection Board of India, once it is operational, by the means the Board publishes. Pensieve will not require you to exhaust its internal process before you approach the Board, although the Act contemplates that you do;
6.8.3 European Union / European Economic Area: complain to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement, including Datatilsynet in Denmark and Datatilsynet in Norway;
6.8.4 Australia: complain to the Office of the Australian Information Commissioner; and
6.8.5 United Arab Emirates: complain to the UAE Data Office, or to the applicable free-zone authority where the free-zone regime applies.
6.9 Data Principals of a hospital. If you are a patient or another individual whose record a hospital holds, your rights run against the hospital, not against Pensieve. Where you contact us, we will tell you so, route your contact to the hospital where you ask us to, and take no decision on the merits. Pensieve's contact details are not published to patients as a route for exercising rights, because doing so would misdirect them.
7.1 The principle. We keep personal data for as long as the purpose it was collected for is being served, and then for as long as a law requires, and then we delete it.
7.2 Retention periods.
| Category | Period | Trigger |
|---|---|---|
| Website server and security logs | 12 months | From the date of the log entry |
| Enquiry and demonstration-request records where no relationship follows | 24 months | From last contact |
| Trust Center access request records (approved and declined) | 36 months | From decision |
| Trust Center access, view and download logs | 12 months minimum, extended where an investigation is open | From the event |
| Platform administrative-user records and access audit logs | Minimum 12 months, and longer where the customer's own retention configuration or a legal obligation requires | From the event |
| Contract, order, invoice, tax and statutory accounting records | 8 financial years | From the end of the relevant financial year |
| Customer know-your-customer records under Direction (v) of the CERT-In Directions of 2022 | 5 years | From cancellation or withdrawal of the service |
| Supplier and adviser records | 8 financial years | From the end of the relationship |
| Recruitment records (unsuccessful applicants) | 12 months | From the decision, or longer with your consent |
| Marketing consent and withdrawal records | For as long as the consent is relied on, and 3 years after withdrawal | To evidence that the withdrawal was honoured |
| Grievance records | 3 years | From closure |
| Security incident records | 5 years | From closure |
7.3 Log retention floor. The minimum log-retention figures above reflect a deliberate choice to take the
longest applicable floor rather than track several: Rule 6(1)(e) and Rule 8(3) of the Digital Personal Data
Protection Rules, 2025 each set a one-year minimum, and Direction (iv) of the CERT-In Directions of 2022
requires 180 days of ICT system logs held within Indian jurisdiction. The applied configuration is stated
in DIS-GL-034.
7.4 Legal hold. Where data is relevant to an actual or anticipated legal proceeding, an investigation or a regulatory request, we suspend deletion for as long as necessary and record the reason.
7.5 Deletion. On expiry, records are deleted from production systems and then from backups within the
backup rotation period stated in DIS-GL-023.
8.1 We do not sell personal data. We have never sold, rented, licensed or traded personal data, and we do not do so.
8.2 Service providers. We share personal data with the service providers that operate our own systems.
The current list, with each provider's role, the data it touches and the country of processing, is the
Subprocessor Register (DIS-GL-009), which is published, dated and maintained. The register is the
single source of truth; this Policy does not restate it, because a list restated in two places goes
stale in one of them.
8.3 Changes to service providers. Changes are notified through the Sub-Processor Change Log
(DIS-GL-010) and the notification and objection terms in POL-GL-055.
8.4 Other recipients. We may also disclose personal data to: our professional advisers under a duty of
confidence; an insurer where a claim arises; a bank or payment processor to receive payment; a regulator,
court or public authority where legally required, under POL-GL-067; and an acquirer or successor of our
business, under the same protections as this Policy, with notice.
8.5 Hospitals. Where you hold a credential issued at a hospital's request, we tell that hospital about your credential, your access rights and your access activity. That is the point of the credential and the audit trail, and the hospital is entitled to it.
8.6 Aggregate reporting. We publish aggregate figures, for example in the Transparency Report
(POL-GL-068), that contain no personal data.
9.1 The default. Pensieve's default position is that customer personal data and system logs are
stored and processed in India, in the Google Cloud India regions, with regional rather than global log
storage. The full residency position, per deployment model and per market, is the Data Residency Statement
(DIS-GL-008).
9.2 Data covered by this Policy. Business contact data and service operations data covered by this
Policy are held in the systems listed in DIS-GL-009. Some of those systems process data outside India.
The register states which, and where.
9.3 India: the legal position. Section 16(1) of the Digital Personal Data Protection Act, 2023 allows the Central Government to restrict transfer to a notified country. This is a negative-list model: transfer is lawful unless the destination is notified. As at the Last Modified On date of this Policy, no country has been notified. Rule 15 adds a condition directed at making personal data available to a foreign State or to a person or entity under its control, not at commercial cloud vendors. Section 16(2) preserves stricter sectoral rules, and health-sector localisation expectations and the CERT-In log localisation requirement are the constraints that actually bind, which is why the default at 9.1 is India.
9.4 If a country is notified. If the Central Government notifies a restricted country, Pensieve will
comply and will move or cease the affected processing. That commitment is contractual in DPA-GL-001
clause 12.
9.5 Transfers out of the EU and EEA. Where the General Data Protection Regulation applies and personal data is transferred to India, there is no adequacy decision for India. Transfers are made on the European Commission's Standard Contractual Clauses with a transfer impact assessment. See Annexure A.
9.6 Government access. Pensieve's position on demands from public authorities, including the process
it follows and the honest limits of that process, is in the Legal & Law Enforcement Request Policy
(POL-GL-067) and DPA-GL-001 clause 17. Pensieve grants no public authority direct, standing or
back-door access to any system, and has created no mechanism by which such access could be given.
10.1 We do not knowingly process children's data as a Data Fiduciary. The Platform is a business system. A Pensieve credential is not issued to a person under the age of eighteen (18) years, our website and Trust Center are directed at organisations, and we do not knowingly collect personal data of a child in our own capacity.
10.2 If we learn that we have. If we discover that we hold a child's personal data as a Data Fiduciary, we delete it, unless a law requires us to keep it, and we record the decision.
10.3 No tracking or profiling of children. Section 9(3) of the Digital Personal Data Protection Act,
2023 prohibits tracking, behavioural monitoring and targeted advertising directed at children. Pensieve
does none of those things for anyone, of any age, in any capacity: there is no behavioural advertising
in any Pensieve property and no third-party tracker in the Trust Center (POL-GL-052 clause 8.2).
10.4 Children's data inside a hospital's tenant. Paediatric records inside a hospital's tenant are the hospital's, and the hospital is the Data Fiduciary. Rule 12 read with Part A of the Fourth Schedule to the Digital Personal Data Protection Rules, 2025 exempts a clinical establishment, a mental health establishment, a healthcare professional and an allied healthcare professional from section 9(1) and section 9(3) where the processing is restricted to the provision of health services to the child, to the extent necessary for the protection of her health. Section 9(2), no processing likely to have a detrimental effect on a child's well-being, is not exempted and continues to apply.
10.5 The product boundary that follows from that. The exemption is conditional on necessity for health
protection. Marketing, campaign, loyalty and engagement use of paediatric data falls outside it. The
Platform therefore prevents a marketing, campaign or outreach selection from including records flagged as
belonging to a person under 18. This is a hard product boundary, not a configuration option, and it is
stated so that a hospital can rely on it. See DPA-GL-001 clause 9.8.
10.6 Guardianship. Rule 11 makes equivalent provision for a person with a disability who has a lawful guardian. The Platform supports the recording of a guardian and a nominee; the verification of guardianship is the hospital's.
11.1 What we implement. The controls Pensieve applies are stated in the Security Addendum
(ADD-GL-001) and in the disclosures it references: encryption (DIS-GL-011), authentication and access
control (DIS-GL-012), audit logging (DIS-GL-013), backup and recovery (DIS-GL-014), vulnerability
management (DIS-GL-017) and personnel security (DIS-GL-020). They are not restated here.
11.2 The statutory minimum, met item by item. Rule 6(1) of the Digital Personal Data Protection Rules, 2025 sets a closed list of seven minimum safeguards. Pensieve publishes a clause-by-clause mapping of that list to implemented controls, with evidence. It is the shortest honest answer to "is this vendor secure enough under Indian law".
11.3 No absolute claim, and no certification. Pensieve does not represent that its systems are immune from compromise, and holds no certification of its information security management system. It states what is implemented, publishes the evidence and the gaps, and commits to defined notification timelines.
11.4 If there is a breach. Where a personal data breach affects data Pensieve holds as a Data Fiduciary,
Pensieve will notify each affected individual without delay, with the description, likely consequences,
mitigation taken, the safety measures you may take, and a contact who can answer your questions; and will
notify the Data Protection Board without delay and in detail within 72 hours of becoming aware, in each
case as Rule 7 of the Digital Personal Data Protection Rules, 2025 requires. Where a breach is a reportable
cyber incident, Pensieve reports it to CERT-In within 6 hours of noticing it, under Direction (ii) of
the CERT-In Directions of 2022. The commitments and the three-clock model are in DIS-GL-016. Where the
breach affects a hospital's tenant data, DPA-GL-001 clause 10 governs and Pensieve notifies the hospital,
not the Data Principal.
Cookies, local storage and similar technologies are described in the Cookie Policy & Consent Notice
(POL-GL-054), which names every cookie set on each Pensieve property, its purpose, its duration and
whether it is strictly necessary. That policy also records that the Trust Center uses no third-party
analytics, advertising or tracking technology at all. This Policy does not restate it.
13.1 No automated decision with legal or similar effect. Pensieve does not make a decision about you, as a Data Fiduciary, based solely on automated processing that produces a legal effect or similarly significantly affects you. A Trust Center access request is decided by a person, except where the hospital has asked us to configure automatic approval for a verified domain, which grants access rather than refusing it.
13.2 AI in the Platform. Where an artificial-intelligence capability is made available in the Platform,
what it does, what it does not do, what data it processes, the human oversight applied and how to turn it
off are disclosed in DIS-GL-027 and governed by ADD-GL-006 and POL-GL-060. No such capability
produces a clinical decision.
13.3 No training on customer data. Restated because it is the question most often asked: Pensieve does not use customer data, including any hospital's tenant data and including the personal data covered by this Policy, to train, fine-tune, validate or evaluate any machine-learning model. Using patient data to develop or validate a model would also be biomedical research under the Indian Council of Medical Research's ethical guidelines of 2023, requiring institutional ethics committee review. Pensieve does not do it.
Pensieve's process on receiving a demand from a court, a regulator or a law-enforcement authority (legality
review, challenge where there is a basis, minimum necessary disclosure, notice to the affected customer
where lawful, and the record kept) is the Legal & Law Enforcement Request Policy (POL-GL-067). The
aggregate numbers are published in the Transparency Report (POL-GL-068). Neither is restated here.
15.1 We may change this Policy. Every version carries a version number, an effective date and a Last
Modified On date, and superseded versions remain retrievable at https://trust.pensievelabs.org.
15.2 Where a change materially affects how we process personal data about you, we will notify you by email to the address we hold, at least thirty (30) days before it takes effect, and will tell you what changed. A clarifying change takes effect on publication and is recorded in the change history.
15.3 We will not use a change to this Policy to begin processing on a basis you have not been told about, or to reduce a commitment at 2.3.
A.1 When this Annexure applies. Where Pensieve processes personal data of individuals in the European Union or the European Economic Area (including Denmark and Norway) or in the United Kingdom, and that processing is within the territorial scope of the General Data Protection Regulation or the UK GDPR. Norway applies the GDPR through the European Economic Area Agreement.
A.2 Terminology. In this Annexure, controller means Data Fiduciary, processor means Data Processor, and data subject means Data Principal. Pensieve is a controller for the data described at 2.2 and a processor for hospital tenant data.
A.3 Lawful bases. Article 6(1)(b) contract; Article 6(1)(c) legal obligation; Article 6(1)(f) legitimate interests, being the operation, security, support, development and lawful promotion of our business, balanced against your rights and recorded in a legitimate interests assessment available on request; and Article 6(1)(a) consent for marketing and non-essential cookies.
A.4 Special category data. Pensieve does not process special category data under Article 9 in its capacity as a controller. Health data inside a hospital's tenant is processed as a processor, on the controller's instructions, under Article 28 and the Data Processing Agreement.
A.5 Your additional rights. Access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); data portability (Art. 20) in a structured, commonly used and machine-readable format; objection to processing based on legitimate interests, including an absolute right to object to direct marketing (Art. 21); withdrawal of consent (Art. 7(3)); and the right not to be subject to a decision based solely on automated processing (Art. 22), which Pensieve does not make. Requests are answered within one month, extendable by two further months for complexity with reasons given inside the first month.
A.6 Transfers to India. There is no adequacy decision for India under Article 45. Transfers rely on
Standard Contractual Clauses adopted by the European Commission, Module Two or Module Three as
applicable, supported by a documented transfer impact assessment that addresses Indian compulsion
powers directly rather than asserting they do not exist, and by the technical measures described in
DPA-GL-001 clauses 12.5 and 17. A copy of the executed clauses and the assessment is available to a
customer on request. For the United Kingdom, the UK International Data Transfer Addendum to those clauses
applies.
A.7 Representative. Where Article 27 requires the appointment of a representative in the Union,
Pensieve's representative is Pensieve eu representative name, Pensieve eu representative email.
Where the value is [TO BE SUPPLIED], no appointment has been made and Pensieve says so rather than
implying one.
A.8 Supervisory authorities. You may complain to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement: in Denmark and in Norway, Datatilsynet; in the United Kingdom, the Information Commissioner's Office.
A.9 Breach notification. Where Pensieve is controller, it notifies the competent supervisory authority
without undue delay and where feasible within 72 hours of becoming aware, under Article 33, and notifies
affected data subjects without undue delay where Article 34 requires. Where Pensieve is processor, it
notifies the controller without undue delay under Article 33(2); the timing commitment is in DPA-GL-001
clause 10.2.
B.1 When this Annexure applies. Where Pensieve handles personal information about individuals in Australia and the Privacy Act 1988 (Cth) applies to that handling.
B.2 Terminology. In Australia the statutory term is personal information, and the entity handling it is an APP entity. Health information is sensitive information.
B.3 APP 1: open and transparent management. This Policy, together with DPA-GL-001, ADD-GL-001 and
the disclosures they reference, is Pensieve's APP 1 privacy policy. It is available free of charge, in a
form that can be downloaded, at https://trust.pensievelabs.org.
B.4 APP 3 and APP 6: collection and use. Pensieve collects personal information only where it is reasonably necessary for its functions, and uses or discloses it only for the purpose of collection, for a directly related secondary purpose you would reasonably expect, with consent, or where required or authorised by law.
B.5 APP 5: notification. 3.1 and 4.1 give the matters APP 5 requires, including who we are, why we collect, to whom we disclose, and how to access, correct and complain.
B.6 APP 8 and section 16C: cross-border disclosure. Personal information handled by Pensieve is
processed in India and in the countries listed in DIS-GL-009. An Australian entity disclosing personal
information overseas remains accountable for the recipient's acts and practices, which are treated as its
own. Pensieve therefore offers Australian customers, in the Australia variant of the Data Processing
Agreement, a contractual flow-down of the Australian Privacy Principles binding Pensieve as recipient, and
where onshore processing is required it is arranged through the deployment model rather than asserted in
the policy.
B.7 APP 11: security. See 11.
B.8 APP 12 and APP 13: access and correction. A request is made to info@pensievelabs.org.
Pensieve responds within 30 days. Where access is refused, Pensieve gives written reasons and the
complaint mechanism.
B.9 Notifiable Data Breaches scheme. Where Pensieve suspects an eligible data breach, it assesses expeditiously and, in any event, takes all reasonable steps to complete the assessment within 30 calendar days, targeting 5 Business Days. Where the breach is an eligible data breach, Pensieve notifies the Office of the Australian Information Commissioner and affected individuals as soon as practicable.
B.10 Complaints. Complain first to info@pensievelabs.org, then to the Office of the
Australian Information Commissioner.
C.1 When this Annexure applies. Where Pensieve processes personal data subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, administered by the UAE Data Office.
C.2 Status. [UNVERIFIED] The Executive Regulations to the PDPL had not been issued as at the Last
Modified On date of this Policy, and commentary is divided on the point. Pensieve therefore operates a
single programme built to the General Data Protection Regulation standard and maps it to the PDPL, rather
than building a separate PDPL programme. Where the Executive Regulations impose a requirement not met by
that mapping, Pensieve will meet it and will update this Annexure.
C.3 Your rights. The PDPL provides rights of access, correction, erasure, restriction of processing,
objection, portability and withdrawal of consent, broadly equivalent to those in Annexure A. Requests are
made to info@pensievelabs.org and handled on the timelines at 6.4.
C.4 Health data and localisation: the point that actually matters. UAE health-sector rules, including
those governing health information systems and the applicable emirate-level health data platforms, impose
health-data localisation obligations that are stricter than the PDPL's general transfer rules. Where
Pensieve serves a UAE health provider, the deployment is architected to meet those obligations, and the
position is stated in the Data Residency Statement (DIS-GL-008) and the UAE localisation supplement
rather than being asserted here.
C.5 Cross-border transfer. The PDPL permits transfer to a jurisdiction with an adequate level of protection, or on appropriate safeguards including contractual clauses, or with the data subject's explicit consent, subject to the sectoral rules at C.4.
C.6 Complaints. Complain first to info@pensievelabs.org, then to the UAE Data
Office, or to the applicable free-zone data protection authority where the deployment sits within a free
zone with its own regime.
| Subject | Document that owns it |
|---|---|
| Processing of hospital tenant data | DPA-GL-001 |
| Subprocessor list | DIS-GL-009 |
| Sub-processor change notification and objection | DIS-GL-010, POL-GL-055 |
| Data residency, per model and market | DIS-GL-008 |
| Encryption and key management | DIS-GL-011 |
| Breach notification commitments and the three-clock model | DIS-GL-016 |
| Deletion and return | DIS-GL-023 |
| Log retention and localisation | DIS-GL-034 |
| AI capability disclosure | DIS-GL-027 |
| Cookies | POL-GL-054 |
| Grievance mechanism and the Grievance Officer | POL-GL-066 |
| Demands from public authorities | POL-GL-067 |
| Aggregate demand statistics | POL-GL-068 |
| Records of processing activities | REG-GL-206 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. DPDP-primary, with the two-role split stated first; statutory Grievance Officer notice; itemised data description and purposes meeting Rule 3; rights, identifier and timelines meeting Rule 14; retention matrix; negative-list transfer position; children's data including the Fourth Schedule Part A healthcare carve-out and the paediatric marketing product boundary. Annexures for GDPR (EU/EEA/UK), the Australian Privacy Principles and the UAE PDPL. |
POL-GL-053 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org