Search all 478 artefacts by title, document ID or content.
Printed on the legal letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Edsol Edtech Pvt. Ltd.
Pensieve Labs | Pensieve
POL-GL-072
v1.0.0 | 03 August 2026
POL-GL-072 | Version 1.0.0 | Effective 03 August 2026 | Last Modified On 03 August 2026
This Policy states how Edsol Edtech Pvt. Ltd. (Pensieve Labs) contacts people who are not yet its customers, what it says to them, on what basis, and how they stop hearing from it. It governs every communication Pensieve sends in its own right for a commercial, informational or relationship purpose: sales outreach, newsletters, event invitations and Trust Center updates. It also draws the line between those messages and the transactional, service and security messages that are not marketing and that a recipient cannot switch off while the underlying relationship lasts.
It is published so that a prospect, a hospital's counsel, a supplier or a member of the public can see, before giving a single detail, exactly what consent is being asked for, what it covers, and how little effort it takes to withdraw it. Consent that is hard to withdraw is not consent, and a marketing programme a hospital's lawyer cannot audit is not one Pensieve is willing to run.
This Policy governs communications Pensieve sends as a Data Fiduciary in its own right. It binds every Pensieve person and every third party that sends a communication on Pensieve's behalf.
It does not govern a message a hospital sends to its patients or its staff using the Platform. For those, the hospital is the Data Fiduciary and Pensieve is a Data Processor acting on the hospital's documented instructions. DPA-GL-001 governs, and POL-GL-053 clause 2 states the two-role split. Pensieve does not use any hospital tenant data, including patient contact data, for its own marketing, and does not contact a patient for its own purposes. That commitment is unconditional and is stated at POL-GL-053 clause 2.3.
Three further boundaries keep this Policy from restating what another artefact owns:
POL-GL-053 clause 4. This Policy states the operational rules that sit on top of that basis.POL-GL-054). This Policy does not restate the cookie categories.ADD-GL-020), not by this Policy.1.1 The categories. Every communication Pensieve sends falls into one of these categories. The category, not the subject line, decides whether consent is required and whether a recipient can switch it off.
| Category | What it is | Marketing? | How you control it |
|---|---|---|---|
| Transactional and contractual | Invoices, receipts, renewal notices (NTC-GL-010), price-change notices (NTC-GL-009), order confirmations |
No | Cannot be switched off while a contract is live; governed by the agreement and POL-GL-053 |
| Service and operational | Planned and emergency maintenance (NTC-GL-005, NTC-GL-006), service degradation (NTC-GL-007) and deprecation (NTC-GL-008) notices about a service you use |
No | Tied to your use of the Platform; sent while you are a user. Support terms are in SLA-GL-001 and POL-GL-056 |
| Security | Security bulletins (NTC-GL-021), incident and breach notices, and vulnerability advisories relevant to you |
No | Cannot be switched off while you hold a credential or a live relationship. This is a safety channel |
| Trust Center update | The Trust Center Update Bulletin (NTC-GL-020): new or changed policies, evidence and disclosures |
Yes, by subscription | Opt-in only; an unsubscribe control in every issue |
| Sales outreach | A first or follow-up approach to a prospect who is not yet a customer | Yes | Consent in India, or the market rules at 6 and 7; an unsubscribe control in every message |
| Newsletter | Periodic company and product news | Yes | Consent; an unsubscribe control in every issue |
| Event and webinar | Invitations to, and follow-up from, an event or webinar | Yes | Consent, or an existing relationship where the market allows; an unsubscribe control in every message |
1.2 The rule. The three categories marked No are not marketing. They are sent because you have a live relationship, a credential or a contract, they carry information you need to use the service safely, and they continue for the life of that relationship. The four categories marked Yes are marketing. Pensieve sends them only on the basis set out in this Policy, and a recipient can stop each of them at any time.
1.3 A withdrawal removes marketing, not safety information. Where you have no relationship with Pensieve and you withdraw, you are removed entirely. Where you are a customer or a credential holder, withdrawing marketing does not stop the transactional, service and security messages tied to that relationship, because those are not marketing and you continue to need them.
2.1 The notice. Pensieve captures consent together with the itemised notice required by Section 5 of the Digital Personal Data Protection Act, 2023, read with Rule 3 of the Digital Personal Data Protection Rules, 2025. That notice gives an itemised description of the personal data collected, the specified purpose, and the goods or services it enables, and it gives the means to withdraw consent, to exercise rights and to complain to the Data Protection Board. The standing notice and the per-collection-point notice blocks are the Notice to the Data Principal at the Point of Collection (NTC-GL-023), and are not restated here.
2.2 The quality of consent Pensieve will accept. Consent for a marketing purpose must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the purpose, as Section 6(1) of the Act requires. In practice this means:
2.2.1 no pre-ticked box, and no consent inferred from silence, from a pre-checked control, or from continued use of a website;
2.2.2 no bundling: agreeing to a contract, downloading a document or booking a demonstration is never conditioned on accepting marketing, and declining marketing costs a person no content and no functionality;
2.2.3 a separate consent for each distinct purpose, so that a newsletter subscription, an event follow-up and sales outreach are asked for and recorded separately, and one is never taken to authorise another.
2.3 Language. Section 5(3) and Section 6(3) of the Act require the Data Principal to be given the option to access the notice and the consent request in English or any language specified in the Eighth Schedule to the Constitution of India. Pensieve presents its notice and consent request in English and in Hindi, and adds further Eighth Schedule language versions on request. The current position is stated in NTC-GL-023.
2.4 The record Pensieve keeps. Because Section 6(10) of the Act places the burden on Pensieve to prove that a valid notice was given and valid consent obtained, Pensieve records, for every marketing consent:
| Field recorded | Why |
|---|---|
| The identifier of the person, being the work email address given | To tie the consent to a specific person and to a later withdrawal |
| The specific purpose or purposes consented to | To show consent was specific and unbundled (Section 6(1)) |
| The exact version of the notice and consent request shown | To reproduce what the person actually saw (Rule 3, Section 6(10)) |
| The language in which the notice and request were presented | To evidence the option required by Sections 5(3) and 6(3) |
| The affirmative action taken, with a timestamp | To evidence a clear affirmative action |
| The withdrawal control offered, and any withdrawal event | To evidence that withdrawal was as easy as consent (Section 6(4)) |
2.5 Retention of the record. The marketing consent and withdrawal record is retained under POL-GL-053 clause 7.2, which sets the period and the trigger. This Policy does not restate the period, because a retention figure kept in two places goes stale in one of them.
2.6 A preference centre, not a Consent Manager. A person may set and change marketing preferences at https://pensievelabs.org/preferences. This is Pensieve's own preference centre. It is not a Consent Manager in the sense of Section 2(g) of the Act, which is a company registered with the Data Protection Board, and Pensieve does not describe it as one.
3.1 As easy to leave as to join. Section 6(4) of the Act requires that the ease of withdrawing consent be comparable to the ease with which it was given. Pensieve builds to that rule. Where consent was a single action, withdrawal is a single action, and Pensieve does not route a withdrawal through a login, a survey, a retention offer or a multi-step confirmation.
3.2 An unsubscribe control in every marketing message. Every marketing message carries a working unsubscribe control, the identity of the sender, and a valid postal address, being Pensieve's registered office at 28, Jamunather, Bulandshahar, Uttar Pradesh, India. A person may also withdraw by writing to info@pensievelabs.org.
3.3 The maximum time to act. An unsubscribe control takes effect at once: the person is removed from the sending list on use, and no further marketing message is sent after the request. The withdrawal is applied across every Pensieve sending system within 5 Business Days. A withdrawal sent by email to info@pensievelabs.org is actioned within the same 5 Business Days. Pensieve applies this single figure to every recipient in every market rather than tuning it market by market.
3.4 The suppression list. When a person withdraws, their contact address is placed on a suppression list so that Pensieve does not contact it again for the withdrawn purpose. The suppression entry is retained for as long as Pensieve operates the relevant channel, because deleting the entry would remove the only record that prevents the person being contacted again. The suppression list holds the minimum data needed to honour the withdrawal and is not used for any other purpose.
3.5 A withdrawal is honoured against every source. A suppressed address stays suppressed even if the same address later appears in a public register, a referral or an event list. Pensieve does not treat a fresh source as a reason to re-approach a person who has opted out.
4.1 Pensieve does not sell contact data. Pensieve does not sell, rent, license or trade the personal data of any person, and does not share a contact for another organisation's marketing. This restates, for the marketing context, the commitment at POL-GL-053 clause 8.1, and it is unconditional.
4.2 Pensieve does not buy lists. Pensieve does not purchase, rent or use a bought or scraped marketing list, and it does not send marketing to an address it acquired that way.
4.3 Contacts obtained from a public source. Where Pensieve obtains a business contact from a public register, an industry directory, a conference list or a referral, it says so on first contact and gives an immediate way to stop hearing from it, as POL-GL-053 clause 3.4 requires. A person contacted this way is never added to a recurring marketing programme without a fresh, specific consent.
5.1 SMS and voice under the TRAI regulation. Commercial SMS and voice calls routed through Indian access providers are governed by the Telecom Commercial Communications Customer Preference Regulations, 2018, made by the Telecom Regulatory Authority of India. A sender of such messages must register as a Principal Entity on the Distributed Ledger Technology platform operated by the access providers, register the sender header, register content and consent templates, capture consent through that framework for promotional and explicit-consent categories, and scrub every send against the National Customer Preference Register, formerly the National Do Not Call registry. Where Pensieve sends any commercial SMS or makes any telemarketing call to an Indian number, it does each of these and honours the recipient's registered preferences.
[UNVERIFIED: the final text and in-force status of any TRAI TCCCPR Third Amendment 2026, which was at draft consultation as at March 2026, and the current consent-validity figures. TCCCPR 2018, as amended to February 2025, is the operative regulation; confirm the amendment position before relying on any new figure.]
5.2 Pensieve's practice for outreach. Pensieve's sales outreach to a person who is not yet a customer is by email and by direct human contact, not by automated promotional SMS. Pensieve does not run a bulk promotional SMS programme to prospects.
5.3 Email marketing in India. India has no dedicated anti-spam or email-marketing statute equivalent to the ones in the other markets in this Policy. Section 66A of the Information Technology Act, 2000, which had touched on offensive electronic messages, was struck down by the Supreme Court of India in Shreya Singhal v. Union of India (2015) and is void. Email marketing is therefore governed by general law: the Digital Personal Data Protection regime, under which an email address is personal data and marketing to it requires consent under Section 6, with the itemised notice at 2.1 and easy withdrawal at 3.1; and the privacy-policy duty that binds now. There is no legitimate-interests or legitimate-use ground for marketing in the Act. Pensieve runs its Indian email marketing on express, recorded, withdrawable consent, as this Policy sets out.
6.1 Prior consent for electronic marketing. Article 13(1) of the ePrivacy Directive (2002/58/EC), as transposed in each member state and applied in Denmark and in Norway, and Regulation 22 of the United Kingdom Privacy and Electronic Communications Regulations 2003, require prior consent before sending electronic-mail direct marketing to an individual subscriber. Pensieve obtains that consent before sending, except where the narrow soft opt-in at 6.2 applies.
6.2 The soft opt-in, applied only within its limits. Article 13(2) of the ePrivacy Directive permits marketing without prior consent only where every one of these conditions is met: Pensieve itself obtained the contact details, in the context of a sale or negotiations for a sale of a product or service; the marketing is of Pensieve's own similar products or services; and an easy, free opt-out is offered when the details are collected and in every message. Pensieve relies on the soft opt-in only within those limits, and never for a bought list, an unrelated product, or a contact obtained by another group entity.
6.3 The absolute objection right. Article 21(2) of the General Data Protection Regulation gives a data subject the right to object to processing for direct marketing at any time, and Article 21(3) requires that the personal data then no longer be processed for that purpose. No balancing test applies to a marketing objection. Pensieve treats an objection to marketing as final and applies it on the timeline at 3.3.
6.4 Business contacts are still personal data. A named-individual business address, such as a person's name at an organisation's domain, is personal data under the General Data Protection Regulation everywhere in the Union and the European Economic Area, and the objection right at 6.3 applies to it. Protection of a non-natural-person subscriber is left to each member state, and several require opt-in for business-to-business email marketing. Pensieve applies an easy opt-out to every business contact everywhere, and defaults to consent where a member state requires it.
6.5 Honest sender identity. Article 13(4) of the ePrivacy Directive prohibits marketing email that disguises the sender or gives no valid address for a stop request. Every Pensieve marketing message identifies the sender and gives a working reply address and the unsubscribe control at 3.2. The fuller privacy position for this market is the GDPR variant of the Privacy Policy (POL-EU-053).
7.1 Australia. The Spam Act 2003 (Cth) applies to a commercial electronic message with an Australian link. It requires consent, which may be express or inferred from an existing relationship the recipient would reasonably expect; clear and accurate identification of the sender and how to contact it; and a functional unsubscribe facility that stays operational for at least 30 days and is actioned promptly. Pensieve actions an Australian opt-out within the 5 Business Days at 3.3 and charges no unsubscribe fee. Telemarketing calls and marketing faxes are separately subject to the Do Not Call Register Act 2006 (Cth), and Pensieve does not call a number on the Do Not Call Register without consent. The Australian privacy position is stated in POL-AU-053.
7.2 United States. The CAN-SPAM Act of 2003 and the Federal Trade Commission Rule at 16 CFR Part 316 apply to commercial email to United States recipients. They require accurate header and routing information, non-deceptive subject lines, identification of the message as an advertisement where it is one, a valid physical postal address, and a working opt-out honoured within 10 business days. Pensieve meets each requirement and applies its own shorter 5 Business Day opt-out standard.
7.3 One standard, applied to everyone. Where these regimes differ, Pensieve applies the strictest requirement to every recipient rather than tuning the message by country to raise a consent or delivery rate. It is simpler to operate and it is the only version of this that is defensible to a hospital. Pensieve takes the same approach to its consent banner in POL-GL-054 clause 5.5.
8.1 Cookies and web tracking. The cookies, pixels and similar technologies Pensieve sets on its own web properties, the categories they fall into, the consent banner, and the position that the Trust Center uses no third-party analytics, advertising or tracking technology at all, are the Cookie Policy & Consent Notice (POL-GL-054). This Policy does not restate the categories.
8.2 Measurement in a marketing email. A marketing email Pensieve sends may contain a first-party measurement element that records whether the message was opened and which links were followed. Pensieve uses this only to keep its lists relevant and to remove addresses that no longer engage. It is not combined into a cross-message or cross-site profile of a person, and it is not shared with any third party. No advertising technology, no session-replay tool and no cross-site tracker is used in any Pensieve message, consistent with the categories Pensieve declines to use in POL-GL-054 clause 2. Unsubscribing ends the measurement, because it ends the message.
9.1 Only under a signed consent. Pensieve may name a customer, use its logo, quote it, or publish a case study or a metric attributable to it only under an executed Reference & Publicity Consent (ADD-GL-020). Absent that consent, Pensieve describes an engagement only in anonymised terms. The permission grid, the withdrawal right and the protection of patient and personal data in a reference are all in ADD-GL-020, and are not restated here.
9.2 A published claim must be true. A testimonial, review or reference Pensieve publishes is genuine, consented and unedited beyond length, and is never paid for, incentivised or written by Pensieve personnel. The authenticity standard is the Customer Feedback, Reviews and Testimonials Authenticity Statement (STM-GL-035). This Policy asserts no figure for how many customers Pensieve has or how satisfied they are; where a number is needed it resolves through [TO BE SUPPLIED], and a claim about satisfaction is made only where the underlying record supports it.
10.1 That is a failure, and here is what to do. If you withdraw and still receive marketing from Pensieve, that is a failure of this Policy. Raise it with the Grievance Officer under the Grievance Redressal Policy (POL-GL-066), which names the Grievance Officer, the channels, and the acknowledgement, response and escalation timelines. Pensieve treats a message sent after a withdrawal as a data-protection grievance, not a marketing preference, and POL-GL-066 applies in full.
10.2 External escalation. You may escalate to the Data Protection Board of India, once operational, or to the supervisory authority in your market, at any time, without exhausting Pensieve's internal process first. The routes are listed in POL-GL-066.
| Role | Responsibility |
|---|---|
| Legal | Owns this Policy. Approves the notice and consent text (NTC-GL-023), reviews the consent-capture design, and authorises any exception under 12. |
| Commercial and marketing | Operates within this Policy. Sends only on a lawful basis, maintains the consent record at 2.4 and the suppression list at 3.4, and applies every withdrawal within the time at 3.3. |
| Grievance Officer | Receives and resolves a complaint that marketing continued after withdrawal, under POL-GL-066. |
| Every Pensieve person | Routes an opt-out or a marketing complaint received on any channel to the marketing team and, where it alleges a failure, to the Grievance Officer, the same Business Day. |
| Any third party sending on Pensieve's behalf | Is bound by this Policy by contract. It may send only what Pensieve authorises, must honour the suppression list, and must pass every opt-out back to Pensieve at once. A failure to honour a withdrawal is a breach of contract. |
12.1 No exception permits sending a marketing communication without a lawful basis, ignoring a withdrawal, or contacting a suppressed address.
12.2 Any other exception to this Policy is authorised in writing by Legal in advance, is recorded with the reason and the person authorising it, and is time-limited. An exception granted without a recorded, time-limited authorisation is a breach of this Policy.
13.1 Enforcement. A breach of this Policy by a Pensieve person is a disciplinary matter. A breach by a third party sending on Pensieve's behalf is a breach of its contract and is grounds for suspension of its access to Pensieve's contact data and for termination.
13.2 Auditability. Each commitment in this Policy is testable. A reviewer can check that a consent record contains the fields at 2.4, that a sample withdrawal was applied within the time at 3.3, that a suppressed address received no further marketing, and that no marketing was sent to a bought list.
13.3 Review. This Policy is reviewed annually, on any change to the applicable law in any market Pensieve operates in, and after any grievance that reveals a defect in it. The review date is 03 August 2027.
| Subject | Document that owns it |
|---|---|
| The lawful basis for marketing, retention of consent records, and the no-sale commitment | POL-GL-053 |
| The GDPR privacy position for the European Union and the European Economic Area | POL-EU-053 |
| The Australian privacy position | POL-AU-053 |
| Cookies, pixels, the consent banner and web tracking categories | POL-GL-054 |
| The itemised notice and consent blocks shown at the point of collection | NTC-GL-023 |
| The grievance mechanism, the Grievance Officer and external escalation | POL-GL-066 |
| Naming, logo use, case studies and reference calls for a named customer | ADD-GL-020 |
| Authenticity of reviews, testimonials and references | STM-GL-035 |
| Processing of hospital tenant data, where Pensieve is a Data Processor | DPA-GL-001 |
| The Trust Center Update Bulletin and the Security Bulletin | NTC-GL-020, NTC-GL-021 |
| Aggregate complaint and grievance figures | POL-GL-068 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-03 | Legal | First published version. Sets the categories of communication and which are governed by consent; the consent-capture standard and record meeting Section 6 and Rule 3, deferring the notice text to NTC-GL-023; withdrawal as easy as consent with a 5 Business Day maximum and a permanent suppression list; the India TCCCPR and DND position and the honest email-marketing position; the GDPR, ePrivacy soft opt-in and PECR position for the European Union, the European Economic Area and the United Kingdom; the Australian Spam Act and the United States CAN-SPAM position under one strictest standard; the no-sale and no-bought-list commitment; email and web tracking deferred to POL-GL-054; customer naming deferred to ADD-GL-020; and the escalation route to the Grievance Officer under POL-GL-066. |
POL-GL-072 v1.0.0 | Last Modified On 03 August 2026 | Review due 03 August 2027 | Published at https://trust.pensievelabs.org