Search all 478 artefacts by title, document ID or content.
Printed on the legal letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Edsol Edtech Pvt. Ltd.
Pensieve Labs | Pensieve
POL-GL-067
v1.0.0 | 31 July 2026
POL-GL-067 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
This Policy states how Edsol Edtech Pvt. Ltd. responds when a court, a regulator, a police authority, a
tax authority or any other public body demands access to data held in or through the Pensieve
platform, or held by Pensieve about its customers and their people.
It is published so that a hospital knows, before it signs, exactly what Pensieve will do, and what Pensieve cannot do, when someone in authority asks.
1. The hospital is the Data Fiduciary. Pensieve is a Data Processor. For records inside a hospital's tenant, the demand should go to the hospital, and Pensieve will say so.
2. Pensieve requires valid legal process. No informal request, no telephone call, no email from a personal address, and no request that does not identify a legal power will be acted on.
3. Pensieve challenges what is challengeable, discloses the minimum, and notifies the customer. In that order.
4. Pensieve does not pretend it can defeat a lawful order. It cannot, it says so at 9, and the technical measures it takes are what actually determine how much there is to compel.
1.1 This Policy applies to a demand for:
POL-GL-053 clause 2.2).1.2 It covers demands from: a court or tribunal; a police or investigating authority; a regulator; a tax authority; a data protection authority; a health authority; a national computer emergency response team; and a foreign authority proceeding through a lawful channel.
1.3 It does not cover: a civil discovery request between private parties, which is answered under
MSA-IN-001 clause 27 and referred to the customer; a request from a patient or a Data Principal, which is
POL-GL-053 and POL-GL-066; or a request from a hospital about its own tenant, which is ordinary
support.
1.4 Pensieve's own regulatory reporting (CERT-In incident reporting under Direction (ii) of the CERT-In
Directions of 2022, and personal data breach reporting) is not a law enforcement request. It is
DIS-GL-016 and it happens on Pensieve's own initiative.
2.1 Address for service.
| Field | Detail |
|---|---|
| Entity | Edsol Edtech Pvt. Ltd. (Pensieve Labs) |
| Corporate Identity Number | [TO BE SUPPLIED] |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` | |
| Email for legal process | info@pensievelabs.org |
| Emergency requests involving a risk to life | info@pensievelabs.org with "EMERGENCY DISCLOSURE REQUEST" in the subject line, and [TO BE SUPPLIED] |
| CERT-In Point of Contact filing | Filed under Direction (iii) of the CERT-In Directions of 2022; the acknowledgement is published in redacted form |
2.2 What a request must contain. Without these, Pensieve cannot act and will say so:
2.2.1 the issuing authority, the officer's name, designation and official contact details;
2.2.2 the legal power relied on, cited by statute and provision;
2.2.3 the specific data sought, identified by account, tenant, individual, date range and data type, not "all data relating to";
2.2.4 the purpose, and how the data sought is relevant and proportionate to it;
2.2.5 the date by which a response is required;
2.2.6 whether notification to the affected customer or individual is prohibited, and if so under which provision and for how long; and
2.2.7 a secure channel for delivery.
2.3 What Pensieve will not act on. An oral request; an email from a non-official address; a request with no identified legal power; a request from a foreign authority that has not proceeded through a mutual legal assistance channel or another lawful route (8); a request for bulk or indiscriminate access; and a request to create data that does not exist.
2.4 Preservation. Pensieve will act on a lawful preservation request without waiting for the production order, because preserving is less intrusive than disclosing. A preservation is time-limited, recorded, and does not itself authorise disclosure.
3.1 The rule. Where a demand seeks records inside a hospital's tenant, Pensieve's first action is to tell the authority that the hospital is the Data Fiduciary, that the hospital holds and controls those records, and that the authority should direct the demand to the hospital.
3.2 Why. The hospital determines the purposes and means of that processing. It holds the clinical context, knows what is privileged or statutorily protected, and is the party the law places the obligation on. It is also better placed than Pensieve to judge whether a record is a medico-legal record, whether a statutory confidentiality applies, and whether a narrower production would satisfy the demand.
3.3 What Pensieve does not do. Pensieve does not volunteer a hospital's records to an authority that has not asked the hospital, and does not treat a demand addressed to Pensieve as permission to search a tenant.
3.4 Where the authority insists. If the authority declines to redirect, or is legally entitled to proceed against Pensieve, 4 applies.
| Step | What happens | Time |
|---|---|---|
| 1. Intake | Logged on receipt with date, time, authority, power cited and scope. Handled by the named legal owner. No one else responds | Same Business Day |
| 2. Authenticate | Verify that the demand is genuine and that the officer holds the office claimed, by contacting the issuing office through a channel Pensieve establishes independently, not a telephone number printed on the demand | 1 Business Day |
| 3. Legality review | Competent authority? Valid power? Territorial reach? Proportionate scope? Required formalities? Any statutory confidentiality engaged? | 2 Business Days |
| 4. Redirect | Where 3 applies | Immediately |
| 5. Narrow | Ask the authority to reduce the scope to what is relevant and proportionate. Pensieve does this in every case where the demand is broader than necessary | Before any disclosure |
| 6. Challenge | Where there is a reasonable basis, formally object, seek to have the demand set aside or narrowed, and pursue an available appeal | Within the period the demand allows |
| 7. Notify the customer | Before disclosure, unless prohibited (see 5) | Before disclosure |
| 8. Disclose the minimum | Only the data the demand covers after narrowing, in a documented format, through the channel agreed with the authority, with a delivery record | On the required date |
| 9. Record | What was demanded, what was challenged, what was disclosed, to whom, when, and under what authority | Same day as disclosure |
| 10. Report | Counted in the Transparency Report (POL-GL-068) |
Next reporting cycle |
4.1 One owner. Every demand is handled by the named legal owner. A Pensieve engineer, support agent
or salesperson who receives a demand must route it to info@pensievelabs.org immediately and must not
respond, must not confirm whether an account exists, and must not run a query. This is a disciplinary
matter, and it is trained.
4.2 No production without sign-off. A disclosure requires the written sign-off of the Director. There is no self-service path by which any Pensieve person can extract and hand over customer data.
5.1 The default is notice. Pensieve notifies the affected customer before disclosing, with enough detail and enough time for the customer to seek its own legal advice and to challenge the demand itself.
5.2 Where notice is prohibited. Where a court order or a statute prohibits notification, Pensieve:
5.2.1 complies with the prohibition;
5.2.2 asks the authority to lift or narrow it, and records the request and the answer;
5.2.3 notifies the customer as soon as the prohibition ends or expires, without needing to be asked; and
5.2.4 counts the demand in the Transparency Report in the aggregate figures, where the law permits.
5.3 Where notice would create a risk. Pensieve may delay notice where notifying would create a risk of death or serious harm, or would defeat an investigation into a risk to a child. It records the reason and notifies as soon as the risk passes.
5.4 What Pensieve will not do. Pensieve will not agree to a voluntary non-disclosure undertaking that is not compelled by law, and will not accept a request "not to tell the customer" that has no legal basis.
5.5 Where a prohibition applies to the report itself. Where Pensieve is prohibited from reporting even an aggregate number, it states that a prohibition applies rather than reporting zero. A silent zero is a misleading statement.
6.1 The narrow path. Where an authority states that there is an imminent risk of death or serious physical harm to a person, and that the delay of ordinary process would create that risk, Pensieve may disclose the minimum data necessary to address the emergency without the full process at 4.
6.2 Conditions. The request must be in writing, from an official address, state the nature of the emergency, identify the person at risk, and identify the specific data sought. Pensieve authenticates the requesting office before disclosing. The Director signs off.
6.3 Afterwards. Pensieve records the disclosure, notifies the affected customer within 5 Business Days unless prohibited, asks the authority to follow up with ordinary legal process, and counts the disclosure separately in the Transparency Report.
6.4 Not a route around 4. An emergency is an imminent risk to life, not urgency, not convenience, and not an approaching deadline in an investigation.
An authority is entitled to know, and a hospital is entitled to know, that the answer differs.
| Deployment model | What Pensieve can produce |
|---|---|
DM-1 Dedicated |
Pensieve operates the environment and can, on a valid demand, produce data from that hospital's isolated project |
DM-2 Shared |
As DM-1, and production is scoped to the single tenant. Pensieve will not produce data belonging to any other tenant, and will resist a demand whose scope would require it |
DM-3 Customer Cloud |
The environment belongs to the hospital. Pensieve holds delegated administrative access under ADD-GL-009. A demand served on Pensieve should be served on the hospital, which owns the project, the billing account and the data. Pensieve will say so and will notify the hospital |
DM-4 On-Premise |
Pensieve holds no copy of the hospital's clinical data at all. There is nothing for Pensieve to produce beyond its own business records. A demand for patient records must go to the hospital |
7.1 What Pensieve holds in every model. Business contact data, contract and billing records, the customer know-your-customer file, Trust Center access records, and support correspondence. Those are Pensieve's own records and a valid demand can reach them.
7.2 Encryption and key custody. Where customer data is encrypted with keys the hospital controls,
Pensieve cannot produce plaintext and will say so. Key custody by model is in DIS-GL-011.
7.3 Log localisation. ICT system logs are retained within Indian jurisdiction as Direction (iv) of the
CERT-In Directions of 2022 requires, and are producible to CERT-In on a valid direction. The configuration
is in DIS-GL-034.
8.1 The rule. Pensieve does not disclose data to a foreign authority on the strength of that authority's own domestic process alone. A foreign demand must proceed through a mutual legal assistance treaty, a letter rogatory, or another route that produces a demand enforceable against Pensieve in the jurisdiction where it holds the data.
8.2 Why. Complying with a foreign demand outside a lawful channel would breach Pensieve's obligations to its customer, may breach Indian law, and, where the General Data Protection Regulation applies, engages Article 48, which provides that a judgment or decision of a third-country authority is enforceable only on the basis of an international agreement.
8.3 Rule 15 and foreign States. Rule 15 of the Digital Personal Data Protection Rules, 2025 addresses making personal data available to a foreign State, or to a person or entity under the control of or an agency of such a State. Pensieve treats a foreign authority demand as engaging that rule and applies 8.1.
8.4 Where a customer is in another market. A demand from the authority of the market in which the customer operates (Australia, Denmark, Norway or the United Arab Emirates) is handled under this Policy with that market's process substituted, and the customer is notified under 5.
9.1 No back door. Pensieve grants no public authority direct, indirect, blanket, bulk or standing access to Customer Data or to the systems on which it is processed, and has not been asked to. Pensieve has built no mechanism by which such access could be given without the process at 4.
9.2 No weakened cryptography. Pensieve has not weakened, and will not weaken, any cryptographic control to facilitate access, and has not been asked to.
9.3 The honest limit. Pensieve cannot undertake to defeat a lawful order of a court or authority of competent jurisdiction, and does not undertake it here. Indian law contains compulsion powers, including under section 69 of the Information Technology Act, 2000 and the rules made under it, section 5(2) of the Indian Telegraph Act, 1885, the production powers of the criminal procedure statute, and section 70B(6) of the Information Technology Act, 2000 in relation to CERT-In directions. Comparable powers exist in every market Pensieve serves. A vendor that claims otherwise is not being straight with you.
9.4 What actually determines the exposure. Not the promise, but the architecture: what data exists,
where it is held, who holds the keys, how narrowly access is scoped, and how much is logged. That is why
Pensieve's answer to this question is a deployment-model conversation (see WPR-GL-004), and why the
technical measures in DPA-GL-001 clause 12.5 and DIS-GL-033 matter more than this clause does.
9.5 If Pensieve is ever compelled to change this position, the change will appear in this document and in the Transparency Report to the extent the law permits, and where it does not permit it, 5.5 applies.
10.1 Costs. Pensieve does not charge a customer for responding to a demand about that customer's data. Where the law entitles Pensieve to recover the cost of production from the requesting authority, it may.
10.2 Records. Every demand is recorded, received, authenticated, reviewed, redirected, narrowed, challenged, disclosed or refused, with the authority, the power, the scope, the decision, the reasoning and the outcome. Records are retained for 8 years.
10.3 Customer access to the record. A customer may request the record of demands relating to its own tenant at any time, at no charge, subject only to a prohibition under 5.2.
10.4 Transparency Report. Pensieve publishes, in POL-GL-068, at the level of aggregation the law
permits: the number of demands received, by type and by authority category; the number redirected to the
customer; the number challenged, and the outcome; the number complied with in whole or in part; the number
refused; the number of customers affected; and the number of emergency disclosures. Where a prohibition
prevents reporting a figure, the report says a prohibition applies.
10.5 Zero is reported as zero, with a denominator. Where Pensieve has received no demands in a period, it says so, states the period, and states the date the statement was made. A trust centre that never updates this figure is not reporting it.
| Role | Responsibility |
|---|---|
| Legal owner | Sole point of receipt and response. Runs 4. Maintains the register. |
| Director | Signs off every disclosure and every emergency disclosure. |
| Every Pensieve person | Routes a demand to info@pensievelabs.org immediately; does not respond, confirm or query. Trained annually. |
| Security | Provides the technical scoping so that a production is the minimum technically possible. |
Review. This Policy is reviewed annually, on any change to the compulsion powers in a market
Pensieve serves, and after any demand that reveals a gap. The review date is 31 January 2027.
| Subject | Document that owns it |
|---|---|
| Contractual form of these commitments | DPA-GL-001 clause 17 |
| Aggregate demand statistics | POL-GL-068 |
| Personal data Pensieve holds as a Data Fiduciary | POL-GL-053 |
| Grievances | POL-GL-066 |
| Incident reporting Pensieve initiates itself | DIS-GL-016 |
| Remote and support access to customer data | DIS-GL-033 |
| Encryption and key custody | DIS-GL-011 |
| Log retention and localisation | DIS-GL-034 |
| Data residency by model and market | DIS-GL-008 |
| Deployment models | WPR-GL-004 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Legal | First published version. Establishes the redirect-to-the-hospital default, the ten-step handling process with independent authentication of the requesting officer, notice to the customer as the default with an obligation to seek the lifting of a gag, a narrow emergency path, a per-deployment-model statement of what Pensieve can actually produce, the foreign-authority rule, and an explicit statement of the honest limit rather than a claim that lawful orders can be defeated. |
POL-GL-067 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org