Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
The Trust Center at https://trust.pensievelabs.org uses no third-party analytics, no advertising technology, no session-replay tool, no marketing pixel and no cross-site tracker. It sets only the cookies strictly necessary to keep you signed in and to protect the session. There is no consent banner on the Trust Center…
This document is the source of truth for: marketing:/legal/cookies, marketing:/cookie-policy, marketing:/footer/cookies, marketing:/consent-banner, trust:/legal/cookies, trust:/documents/POL-GL-054
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
POL-GL-054 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
This Policy explains what cookies and similar technologies Edsol Edtech Pvt. Ltd. uses on each of its
properties, why, for how long, and how you control them. It is part of, and should be read with, the
Privacy Policy (POL-GL-053).
It covers the public website at https://pensievelabs.org, the Trust Center at https://trust.pensievelabs.org,
the Support Center at [TO BE SUPPLIED] and the Pensieve platform. It does not
cover a third-party site you reach by leaving ours, or a hospital's own patient-facing interfaces, which
the hospital configures and controls.
1.1 Cookie. A small text file a site asks your browser to store and return on later requests. A first-party cookie is set by the site you are visiting. A third-party cookie is set by another organisation whose code the site loads.
1.2 Similar technologies. Local storage and session storage (data held by the browser for the site), and pixels or beacons (a request for a tiny resource used to record that a page or message was opened). Where this Policy says "cookie" it includes these.
1.3 Session and persistent. A session cookie is deleted when you close the browser. A persistent cookie survives until its stated expiry or until you delete it.
| Category | What it does | Consent needed? | Do we use it? |
|---|---|---|---|
| Strictly necessary | Authentication, session integrity, load balancing, protection against cross-site request forgery, and remembering your consent choice | No: it is required to deliver the service you asked for | Yes, on every property |
| Functional | Remembering a preference you set, such as language or a display setting | Yes, where it is not strictly necessary | Yes, on the website and the Platform |
| Analytics | Measuring how pages are used | Yes | On the public website only, first-party and aggregated. Never on the Trust Center. |
| Advertising and cross-site tracking | Building a profile across sites for targeted advertising | Yes | No. Nowhere. On any property. In any market. |
| Session replay | Recording your keystrokes, mouse movements and screen | Yes | No. |
| Social media plug-ins | Third-party widgets that set their own cookies | Yes | No. Where we link to a social platform, it is a plain link that sets nothing until you click it. |
3.1 Trust Center: https://trust.pensievelabs.org
| Cookie | Party | Category | Purpose | Duration |
|---|---|---|---|---|
Pensieve cookie prefix_session |
First | Strictly necessary | Keeps you signed in after authentication | Session, or the configured idle timeout |
Pensieve cookie prefix_csrf |
First | Strictly necessary | Protects form submissions against cross-site request forgery | Session |
Pensieve cookie prefix_nda |
First | Strictly necessary | Records that you have accepted the click-through mutual NDA (NDA-GL-002) so that you are not asked again in the same session |
Session |
That is the complete list. No analytics cookie, no advertising cookie, no third-party cookie, no pixel and no external script that sets storage is served on the Trust Center. Public-tier documents are readable with no cookie at all, because no authentication is required for them.
3.2 Public website: https://pensievelabs.org
| Cookie | Party | Category | Purpose | Duration |
|---|---|---|---|---|
Pensieve cookie prefix_consent |
First | Strictly necessary | Records your consent choice so that we do not ask again and so that we can evidence what you chose | 12 months |
Pensieve cookie prefix_csrf |
First | Strictly necessary | Protects form submissions | Session |
Pensieve cookie prefix_pref |
First | Functional | Remembers a display or language preference you set | 12 months |
Pensieve cookie prefix_an |
First | Analytics | Aggregate page-level usage measurement, using a first-party identifier that is not shared with any third party and is not used to build a cross-site profile | 90 days |
Analytics on the website is set only after you consent, and declining it changes nothing about what the site shows you.
3.3 Support Center: [TO BE SUPPLIED]
Strictly necessary session and forgery-protection cookies, and a functional cookie recording an article
preference. Where the Support Center is delivered through a third-party help-desk platform, that platform
appears in the Subprocessor Register (DIS-GL-009) and the cookies it sets are listed at
[TO BE SUPPLIED]/cookies. [TO BE SUPPLIED: confirm the delivery platform before first publication and complete this sub-clause with its cookie table.]
3.4 The Pensieve platform
The Platform sets strictly necessary cookies only: authentication, session integrity, forgery protection and tenant routing. No analytics, advertising or third-party cookie is set inside a hospital's tenant. Where a hospital configures a patient-facing interface on the Platform, the hospital is the Data Fiduciary for it and is responsible for its own cookie notice and consent; the Platform provides the mechanism to render one.
4.1 Where a banner appears. A consent banner appears on the public website only. It does not appear on the Trust Center, because the Trust Center sets nothing that requires consent.
4.2 How the banner behaves.
4.2.1 Nothing beyond strictly necessary cookies is set before you choose.
4.2.2 "Reject all" is presented with the same prominence, in the same style and with the same number of clicks as "Accept all". There is no dark pattern, no pre-ticked box, no colour weighting and no buried second layer.
4.2.3 You may accept or reject each non-essential category separately.
4.2.4 There is no cookie wall. Declining costs you no content and no functionality. Every document that is public remains public.
4.2.5 Your choice is recorded with a version identifier and a timestamp so that we can evidence what you were shown and what you chose.
4.3 Withdrawing or changing consent. Use the Cookie settings link in the footer of every page of the public website. You may change your choice at any time, and withdrawal is as easy as consent was. You may also delete cookies in your browser at any time; deleting the consent cookie means we will ask again.
4.4 Browser signals. Where your browser sends a Global Privacy Control signal, we treat it as a
rejection of non-essential cookies and do not show the banner. [UNVERIFIED: confirm implementation before first publication.] We do not act on the legacy "Do Not Track" header, which has no agreed meaning.
4.5 Consent is not consent to everything. A cookie consent is not consent to any other processing.
Consent to marketing communications is separate and is described in POL-GL-053 clause 4.
5.1 India. Where consent is the basis, section 6 of the Digital Personal Data Protection Act, 2023 requires it to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, limited to the personal data necessary for the specified purpose, and withdrawable with a comparable ease to that with which it was given. Rule 3 of the Digital Personal Data Protection Rules, 2025 requires the notice to be understandable independently of other information and to give the means of withdrawal. This Policy and the banner are built to that standard.
5.2 European Union, European Economic Area and the United Kingdom. Article 5(3) of the ePrivacy Directive, as transposed in each member state and applied in Denmark and Norway, requires prior informed consent before storing or accessing information on a user's device, except where the storage is strictly necessary to provide a service the user has explicitly requested. Consent must meet the General Data Protection Regulation standard. Where analytics or functional cookies are set, they are set only after consent under 4.2.
5.3 Australia. Cookies that carry personal information are handled under the Australian Privacy Principles; the notification and choice described here meet APP 1, APP 3 and APP 5.
5.4 United Arab Emirates. Consent under Federal Decree-Law No. 45 of 2021 must be specific, clear and unambiguous and must be withdrawable. The mechanism at 4 is applied.
5.5 One mechanism, everywhere. Pensieve does not vary the banner by country to obtain a better consent rate. The strictest standard is applied to every visitor. It is simpler to operate, and it is the only version of this that is defensible to a hospital.
6.1 Children. None of these properties is directed at children, and no cookie is used to profile,
track or advertise to any person, of any age. See POL-GL-053 clause 10.
6.2 Cookie security. Session cookies are set with the Secure, HttpOnly and SameSite attributes
and, where the platform supports it, the __Host- prefix. They are transmitted only over TLS.
6.3 Changes. We may change this Policy. Every version carries a version number and a Last Modified On
date, and superseded versions remain retrievable at https://trust.pensievelabs.org. If we add a cookie
category, we ask for consent again before setting it. We do not treat a prior consent as covering a new
purpose.
6.4 If you find a cookie we have not listed. Tell us at info@pensievelabs.org. We will either add
it to this Policy or remove it, and we will tell you which. A cookie policy that does not match the site is
worse than no cookie policy.
| Purpose | Contact |
|---|---|
| Cookies, this Policy, and privacy generally | info@pensievelabs.org |
| Grievance Officer | [TO BE SUPPLIED], info@pensievelabs.org |
| Legal | info@pensievelabs.org |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` |
| Subject | Document that owns it |
|---|---|
| What personal data we hold and why | POL-GL-053 |
| Trust Center access, watermarking and logging | POL-GL-052 |
| Website use | POL-GL-051 |
| Service providers and where they process | DIS-GL-009 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. Records the no-third-party-trackers position on the Trust Center as a deliberate trust signal, the complete per-property cookie inventory, symmetrical accept and reject controls with no cookie wall, and a single strictest-standard consent mechanism applied in every market. |
POL-GL-054 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org