Search all 478 artefacts by title, document ID or content.
Printed on the legal letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Edsol Edtech Pvt. Ltd.
Pensieve Labs | Pensieve
POL-GL-069
v1.0.0 | 03 August 2026
POL-GL-069 | Version 1.0.0 | Effective 03 August 2026 | Last Modified On 03 August 2026
This Policy states how Edsol Edtech Pvt. Ltd. (Pensieve Labs) respects human rights in what it builds, how it operates, whom it sells to, and whom it buys from. It is the policy commitment required by Guiding Principle 16 of the United Nations Guiding Principles on Business and Human Rights (2011), and it is published so that a hospital, a regulator, a patient or a member of the public can read Pensieve's position and hold Pensieve to it.
Pensieve is a small company building an operating system for hospitals. Its most severe potential human rights impacts do not arise from a factory or a workforce in a high-risk sector. They arise from the data it processes and the software it operates inside a clinical setting, and from the parts of its value chain it cannot directly control. This Policy is written to that reality. It commits Pensieve to a proportionate process, not to an enterprise-scale programme it does not run, and it says plainly where the difference lies.
This Policy binds Edsol Edtech Pvt. Ltd. and every director, officer, employee, contractor, and person acting on Pensieve's behalf. It also states what Pensieve expects of its business partners; those expectations are made contractual through the Supplier Code of Conduct (POL-GL-071) and are not restated here.
This Policy is the human rights commitment for the group. It does not restate matters that other artefacts own:
| Matter | Owning artefact |
|---|---|
| Modern slavery, forced labour, child labour and ethical sourcing | STM-GL-031 |
| Anti-bribery and anti-corruption | STM-GL-030 |
| What Pensieve requires of its suppliers | POL-GL-071 |
| Anti-discrimination and equal opportunity in employment | POL-IN-307 |
| Whistleblowing and the internal speak-up route | POL-IN-308 |
| The prohibition on child and forced labour in Pensieve's own workforce | POL-IN-315 |
| The grievance mechanism and Grievance Officer | POL-GL-066 |
| Prohibited and restricted uses of the Platform | ADD-GL-005 |
1.1 The commitment. Pensieve shall respect internationally recognised human rights across its own activities and its business relationships. Respect means Pensieve avoids causing or contributing to adverse human rights impacts, addresses impacts it is involved in, and seeks to prevent or mitigate impacts directly linked to its operations, products or services, even where it has not contributed to them. This is the corporate responsibility to respect in Pillar II of the Guiding Principles (Guiding Principles 11 to 24). Pensieve commits to respect these rights; it does not represent that it can guarantee their enjoyment by every person its value chain touches, and it distinguishes the two deliberately.
1.2 The frameworks. Pensieve aligns its conduct with, and draws its standard from:
Pensieve aligns with these frameworks and commits to respect the rights they protect. It does not claim to be certified, accredited, or a filing participant under any of them, and it does not represent that it has submitted a UN Global Compact Communication on Progress.
1.3 The ILO fundamental principles, stated honestly. The five fundamental principles are: freedom of association and the effective recognition of the right to collective bargaining; the elimination of forced or compulsory labour; the effective abolition of child labour; the elimination of discrimination in employment and occupation; and a safe and healthy working environment (added in 2022). These principles bind every ILO member State by virtue of membership, whether or not the underlying Convention has been ratified. India has not ratified ILO Convention 87 (Freedom of Association) or Convention 98 (Right to Organise and Collective Bargaining). Pensieve therefore commits to respect the fundamental principles, including freedom of association, and does not claim that its home jurisdiction has ratified every fundamental Convention. Overstating the ratification position would be a misrepresentation, and Pensieve does not make it.
1.4 Approval and availability. This Policy is approved at the most senior level of Edsol Edtech Pvt. Ltd., as Guiding Principle 16 requires, and is published at https://trust.pensievelabs.org. It is communicated to personnel and made available to business partners. It is owned by Legal and reviewed under 10.
2.1 Why a salient-risk set, not a claim of full coverage. A credible policy for a company of Pensieve's size identifies the small number of rights where its potential impact is most severe, rather than asserting that it manages every right equally. The set below is drawn from the B-Tech Project's technology-sector risks and narrowed to a health-software company that processes clinical data on behalf of hospitals.
| Salient right and its source | Where the risk arises for Pensieve | How Pensieve constrains it |
|---|---|---|
| Privacy and protection of personal data (Universal Declaration Article 12; ICCPR Article 17) | The most probable severe impact Pensieve can cause or contribute to. Health data is sensitive personal data under India's Digital Personal Data Protection Act, 2023 and special-category data under GDPR Article 9. A breach, or a secondary use beyond the hospital's instruction, is the core risk | Pensieve acts as a Data Processor on the hospital's documented instruction, never as a Data Fiduciary for a patient record. See the Privacy Policy (POL-GL-053), the Encryption Disclosure (DIS-GL-011) and the Incident Response and Breach Notification Commitment (DIS-GL-016) |
| The right to health and access to care (ICESCR Article 12) | Software downtime, defect or degraded operation can impede a hospital's ability to deliver care. Availability is a human rights matter, not only a service level | Pensieve is not a medical device and takes no clinical decision: see the Clinical Safety Boundary Statement (DIS-GL-028). Availability and recovery commitments are stated in the Service Level Agreement (SLA-GL-001) |
| Non-discrimination in algorithmic features (Universal Declaration Article 7; ICCPR Article 26) | Any prioritisation, scoring, ranking or decision-support feature can encode bias against a protected group, made acute in a multilingual, mixed-literacy Indian clinical setting | Human accountability for every output that touches a person, and the principles that govern it, are stated in the Responsible AI Principles (STM-GL-034), the Responsible AI Use Policy (POL-GL-060), the AI Governance and Model Risk Policy (POL-GL-132) and the AI / ML Feature Disclosure (DIS-GL-027) |
| Freedom from arbitrary or disproportionate surveillance (ICCPR Article 17) | Analytics, audit logging of patients or staff, and monitoring features can enable surveillance beyond a legitimate purpose if not constrained | Purpose limitation and the hospital's control over its own configuration. Logging is bounded to security and traceability, not behavioural monitoring on Pensieve's initiative |
| Labour rights in Pensieve's operations and value chain (ILO fundamental principles) | Pensieve's own workforce, and the smaller vendors and facilities services in its supply chain | Owned by the internal labour policies (see 5), the Modern Slavery and Ethical Sourcing Statement (STM-GL-031) and the Supplier Code of Conduct (POL-GL-071) |
| The right to an effective remedy (Universal Declaration Article 8; ICCPR Article 2(3); Guiding Principles 22, 29 to 31) | Patients, staff and others affected by a Pensieve act need a route to raise a concern and obtain redress | The Grievance Redressal Policy and Grievance Officer Notice (POL-GL-066), and remediation under 7 |
2.2 Where Pensieve sits in the chain of responsibility. The Guiding Principles distinguish impacts a company causes, impacts it contributes to, and impacts directly linked to its operations, products or services through a business relationship. The distinction governs what Pensieve must do:
2.2.1 where Pensieve causes or contributes to an adverse impact, it provides for or cooperates in remediation under 7;
2.2.2 where an impact is directly linked to Pensieve through a business relationship but Pensieve did not cause or contribute to it, Pensieve uses its influence to seek to prevent or mitigate the impact, and is not thereby the party required to provide the remedy.
Pensieve's largest potential impacts by volume run through its cloud and platform providers, to which it is directly linked and over which a company of its size has limited influence. It says so rather than implying control it does not hold.
3.1 Proportionate by design. Guiding Principle 17 makes the scope of human rights due diligence proportionate to a company's size, the severity of its potential impacts, and its operating context. Pensieve runs a due diligence process scaled to a company of [TO BE SUPPLIED] people with a short, mostly digital value chain. It does not claim exhaustive value-chain mapping, independent human rights impact assessments of every release, or supplier audit programmes it cannot resource.
3.2 The process. Pensieve's due diligence follows the ongoing cycle in Guiding Principles 17 to 21:
| Element | Guiding Principle | What Pensieve does |
|---|---|---|
| Identify and assess | GP 18 | Maintains the salient-risk assessment at 2, reviewed at least annually and on any material change to the product, the data it processes, or a market it enters. New features that prioritise, score or rank a person are assessed against the Responsible AI Principles (STM-GL-034) before release |
| Integrate and act | GP 19 | Assigns each salient risk to an owning policy and an accountable role. Where Pensieve is linked to an impact through a business relationship, it uses its influence, through supplier selection, contract terms under POL-GL-071, and continued custom, to seek prevention or mitigation |
| Track effectiveness | GP 20 | Tracks the indicators it can meaningfully measure: whether every person engaged has a written contract and is paid through the banking system (STM-GL-031), whether any concern has been raised through the channels at 7, and whether identified gaps have closed. It does not report metrics it does not collect |
| Communicate | GP 21 | Publishes this Policy and the related statements openly, and reports aggregate grievance and request volumes in the Transparency Report (POL-GL-068). Pensieve communicates when a concern is raised, with enough information to evaluate its response, without exposing an affected person or breaching a confidentiality obligation |
3.3 Consultation. Where a salient risk bears on a specific affected group, Pensieve seeks the view of that group or its credible representatives to the extent proportionate to the risk. For a company of its size this is direct engagement, not a standing stakeholder-panel programme, and Pensieve describes it as what it is.
4.1 End-use is a human rights question. The B-Tech Project treats the end-use of a technology product as a source of human rights risk that a responsible company must assess, not only the conduct of its immediate counterparty. Pensieve applies this before it sells.
4.2 The pre-contract screen. Before entering a contract, Pensieve shall assess the prospective buyer and the intended use of the Platform against the prohibited and restricted uses in the Use Case Restrictions and Prohibited Uses (ADD-GL-005). Where the intended use would cause or contribute to a severe adverse human rights impact, and the risk cannot be mitigated through restriction, configuration or contract, Pensieve shall decline the engagement. Pensieve does not restate the prohibited-use list here; ADD-GL-005 owns it, and the restrictions that survive the screen flow into the contract.
4.3 Influence, not endorsement. Pensieve's influence over how a hospital uses the Platform is real but bounded: it exercises it through use restrictions, configuration limits, the AI use restrictions in POL-GL-060, and the right to act on a credible report of misuse. Selling the Platform is not an endorsement of every act a customer performs with it, and Pensieve retains the remedies in its agreements where a customer's use breaches ADD-GL-005.
5.1 The commitments. Within its own workforce Pensieve shall: engage no forced, bonded, indentured or involuntary labour and no child labour; not discriminate in employment on any protected ground; not tolerate harassment, threats or abuse; respect freedom of association; pay at least the applicable statutory minimum wage through the banking system; and provide a safe and healthy working environment, including for personnel deployed on a hospital site.
5.2 Where each commitment is operated. These commitments are not restated in operational detail here. They are operated through:
| Commitment | Operating artefact |
|---|---|
| Prohibition on child and forced labour in the workforce | POL-IN-315 |
| Anti-discrimination and equal opportunity | POL-IN-307 |
| Prevention of sexual harassment | POL-IN-306 |
| Code of conduct and ethics | POL-IN-305 |
| Payment of wages and minimum wages | POL-IN-312 |
| Health, safety and vaccination for on-site staff | POL-IN-319 |
| On-site conduct and patient confidentiality | POL-IN-318 |
| Written contracts and payment through the banking system | STM-GL-031 |
5.3 Freedom of association. Every person engaged by Pensieve is free to associate, or not to associate, and to raise a concern about working conditions without detriment, through the whistleblowing route in POL-IN-308. Pensieve does not require any person to waive this freedom.
6.1 What Pensieve requires of suppliers. Pensieve's requirements of its suppliers, subcontractors and subprocessors are set out in the Supplier Code of Conduct (POL-GL-071) and are not restated here. Its modern slavery and ethical sourcing position, including the tiered supply-chain risk assessment, is owned by the Modern Slavery and Ethical Sourcing Statement (STM-GL-031). Inbound assessment of vendors that touch Pensieve's own operations is governed by the Vendor and Third-Party Risk Management Policy (POL-GL-120).
6.2 The influence asymmetry, stated openly. Pensieve's supplier base is dominated by large cloud and software vendors that will not countersign a small customer's code. Pensieve does not pretend otherwise. It segments its suppliers and applies the mechanism it can actually operate:
6.2.1 for large infrastructure and software providers, Pensieve conducts due diligence by reference, assessing the provider against its own published human rights and labour commitments, its certifications and its third-party attestations, and recording that assessment. Its influence here is selection and continued custom, not signature or audit rights;
6.2.2 for smaller vendors and subcontractors, where Pensieve has genuine influence, it requires acceptance of POL-GL-071 as a contract term, with the right to ask questions and to terminate for a serious unremedied breach.
Pensieve does not claim audit rights over, or enforcement of its code against, hyperscale providers, because that claim would not be true.
6.3 How mandatory value-chain due diligence laws reach Pensieve. A hospital customer in the European Union, Norway or elsewhere may itself be subject to a mandatory human rights and environmental due diligence law and may ask Pensieve for information as a link in its value chain. None of these laws imposes a direct duty on Pensieve, which is far below every threshold: the EU Corporate Sustainability Due Diligence Directive (Directive (EU) 2024/1760, as amended by Directive (EU) 2026/470) applies to enterprises above 5,000 employees and EUR 1.5 billion net turnover; the EU Corporate Sustainability Reporting Directive applies above 1,000 employees and EUR 450 million net turnover; and Norway's Transparency Act binds larger enterprises and does not impose a direct duty on a mere foreign supplier. Pensieve supports these instruments and responds to value-chain data requests from covered customers, drawing on this Policy and the artefacts it references. It does not represent itself as a regulated entity under any of them. [UNVERIFIED: the first-application dates of the amended EU Directives are still settling and should be confirmed against the amending Directive before any date is quoted; they are not relied on here because the Directives do not apply to Pensieve directly.]
7.1 The remedy route. Anyone who believes a Pensieve act or omission has adversely affected their human rights may raise a grievance through the Grievance Redressal Policy and Grievance Officer Notice (POL-GL-066). That Policy owns the channels, the acknowledgement and response timelines, the routing rule for grievances about a hospital's own processing, the external escalation routes, and non-retaliation. It is designed against the eight effectiveness criteria in Guiding Principle 31: legitimate, accessible, predictable, equitable, transparent, rights-compatible, a source of learning, and based on engagement. This Policy does not restate those mechanics.
7.2 Remediation. Consistent with Guiding Principle 22, where Pensieve has caused or contributed to an adverse human rights impact, it shall provide for or cooperate in remediation through a legitimate process, and shall prioritise the safety and remediation of the affected person over commercial or reputational considerations. Where an impact is directly linked to Pensieve through a business relationship without Pensieve having caused or contributed to it, Pensieve shall use its influence to seek prevention or mitigation, and will engage the party responsible rather than disengage abruptly where abrupt disengagement would worsen the position of the affected people.
7.3 Reporting a concern. A human rights concern, including one raised anonymously, may be reported to info@pensievelabs.org or, for a matter involving Pensieve personnel or a suspected wrongdoing, through the whistleblowing route in POL-IN-308 and the reporting channel published with POL-GL-059. No person who raises a concern in good faith will suffer any detriment, whether or not the concern is upheld.
8.1 Pensieve publishes this Policy and its related statements openly, rather than releasing them on request. A company that will only state its human rights position behind a login has said something about that position.
8.2 Pensieve reports the aggregate volume of grievances and rights requests, with a denominator, in the Transparency Report (POL-GL-068). It does not publish a headline figure without the context that makes it meaningful, and it does not assert a satisfaction figure it cannot evidence.
8.3 Where a concern is raised, Pensieve communicates enough for the affected person or their representative to evaluate the adequacy of its response, without disclosing information that would put an affected person at risk or breach a confidentiality obligation.
9.1 Candour is the point of this clause. The table states Pensieve's maturity as at 03 August 2026, for a company of [TO BE SUPPLIED] people, and marks what is deliberately not built.
| Element | Position as at 03 August 2026 |
|---|---|
| A published policy commitment approved at senior level (GP 16) | In place. This Policy |
| A salient human rights risk assessment | In place (2), reviewed at least annually |
| A proportionate human rights due diligence process (GP 17 to 21) | In place and scaled to Pensieve's size and risk, not to an enterprise |
| An operational grievance channel (GP 29 to 31) | In place (POL-GL-066) |
| A pre-contract end-use screen | In place (ADD-GL-005, 4) |
| Contractual human rights expectations of smaller suppliers | In place (POL-GL-071) |
| Due diligence by reference for large infrastructure providers | In place, in place of an audit right Pensieve cannot exercise |
| Independent human rights impact assessment of each release | Not in place, by design. Disproportionate for a company of this size; Pensieve runs the proportionate assessment at 2 and 3 instead, and says so |
| Supplier human rights audits over hyperscale providers | Not in place. Not exercisable; replaced by assessment by reference at 6.2 |
| A formal human rights training programme | Not in place. Pensieve judges a written standard and direct engagement proportionate for its size, and describes that rather than a programme it does not run |
| A UN Global Compact Communication on Progress | Not filed. Pensieve aligns with the ten principles; it does not claim participant status |
9.2 Where an element above moves from "not in place" to "in place", it will be recorded in the change history and the maturity table updated. Pensieve does not describe a control that does not yet exist as though it did.
10.1 Roles.
| Role | Responsibility |
|---|---|
| Board of Directors | Approves this Policy and any material change to it. Bears ultimate accountability for the commitment to respect human rights |
| Legal | Owns this Policy. Maintains the salient-risk assessment, runs the due diligence cycle, operates the pre-contract screen with the commercial function, and reports under 8 |
| Grievance Officer | Receives and handles human rights grievances under POL-GL-066 |
| Every Pensieve person | Complies with this Policy, and routes any human rights concern or grievance to the Grievance Officer the same Business Day |
10.2 Exceptions. Any exception to this Policy must be approved in advance by the Director, recorded in the exception register (REG-GL-210) with the reason, the scope, the compensating measure and an expiry date, and reviewed on expiry. No exception may authorise conduct that would cause or contribute to a severe adverse human rights impact.
10.3 Enforcement. For personnel, a breach of this Policy is a disciplinary matter under POL-GL-322 and may amount to a breach of the code of conduct at POL-IN-305. For suppliers, the consequences of breach are those in the Supplier Code of Conduct (POL-GL-071), ending at termination for a serious unremedied breach.
10.4 Review. This Policy is reviewed at least annually, on any material change to the Platform, the data it processes or a market Pensieve enters, and after any grievance that reveals a defect in it. The next review date is 03 August 2027.
| Document ID | Title | What it carries that this one does not |
|---|---|---|
STM-GL-031 |
Modern Slavery and Ethical Sourcing Statement | The statutory thresholds, the tiered supply-chain risk assessment, and the substantive modern slavery commitments |
STM-GL-030 |
Anti-Bribery and Anti-Corruption Declaration | The anti-bribery position and controls |
POL-GL-071 |
Supplier Code of Conduct | The binding requirements Pensieve places on its suppliers, and the consequences of breach |
ADD-GL-005 |
Use Case Restrictions and Prohibited Uses | The prohibited and restricted uses screened at 4 |
POL-GL-066 |
Grievance Redressal Policy and Grievance Officer Notice | The grievance channels, timelines, routing rule and external escalation |
STM-GL-034 |
Responsible AI Principles | The principles governing algorithmic features and human accountability |
POL-GL-060 |
Responsible AI Use Policy | The AI use restrictions placed on customers |
POL-GL-132 |
AI Governance and Model Risk Policy | Pensieve's internal model-risk governance |
DIS-GL-028 |
Clinical Safety Boundary Statement | Why Pensieve is not a medical device and takes no clinical decision |
POL-GL-053 |
Privacy Policy | What personal data Pensieve holds and the rights over it |
POL-GL-120 |
Vendor and Third-Party Risk Management Policy | Inbound assessment of vendors that touch Pensieve's operations |
POL-IN-307 |
Anti-Discrimination and Equal Opportunity Policy | Equal opportunity in employment |
POL-IN-308 |
Whistleblower and Grievance Policy | The internal speak-up route and non-retaliation |
POL-IN-315 |
Child and Forced Labour Prohibition Statement | The workforce prohibition on child and forced labour |
POL-GL-068 |
Transparency Report | The aggregate reporting of grievance and request volumes |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-03 | Legal | First issue. Policy commitment under Guiding Principle 16, framed on the UN Guiding Principles, the ILO fundamental principles (with the honest note that India has not ratified Conventions 87 and 98), the UN Global Compact and the OECD 2023 Guidelines; a health-software salient-risk set tied to named rights; a proportionate due diligence cycle; a pre-contract end-use screen referencing ADD-GL-005; the supply-chain influence asymmetry stated openly; remediation on the cause, contribute and directly-linked distinction; and a candid maturity table naming what is deliberately not built. References STM-GL-031 and POL-GL-071 rather than restating modern slavery or supplier expectations. |
POL-GL-069 v1.0.0 | Last Modified On 03 August 2026 | Review due 03 August 2027 | Published at https://trust.pensievelabs.org