Search all 478 artefacts by title, document ID or content.
Whitepaper | Family 13, Offboarding & Exit
Your data is yours. All of it. At any time. In a form you can use. At no charge. However this ends, including if it ends because you did not pay us.
This document is the source of truth for: marketing:/why-pensieve/no-lock-in, marketing:/legal/exit-commitment, marketing:/product/your-data, trust:/assurance/exit-and-portability, trust:/documents/WPR-GL-400, trust:/objections/data-hostage, marketing:/legal/exit
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
WPR-GL-400 | Version 1.0.0 | Effective 31 July 2026 | Last Modified On 31 July 2026
Ask any hospital administrator in India who has changed software vendor what went wrong, and the answer is usually one of two things: the data came back in a form nobody could use, or it did not come back until a disputed invoice was settled.
Pensieve is an unknown supplier asking a hospital to run its entire operation on a platform it has never heard of. The rational response to that is fear of lock-in, and the honest answer to fear is not reassurance; it is a document with numbers in it that the hospital's counsel can hold Pensieve to.
This is that document. It is public, it is prominent, and it is contractually binding through
MSA-IN-001 clause 22.
| Deployment model | How this Commitment applies |
|---|---|
DM-1 Dedicated (Pensieve-hosted) |
In full. Pensieve generates and delivers the export. |
DM-2 Shared (Pensieve-hosted) |
In full. Tenant isolation means the export contains the hospital's records and nothing else. |
DM-3 Customer Cloud |
In full, and the data is already in the hospital's own cloud project. Pensieve generates the export from that project, delivers the documentation, and leaves the data, backups, logs and keys in place and accessible. |
DM-4 On-Premise |
In full, and the data is already on the hospital's own hardware. Same as DM-3. Pensieve does not delete, disable, encrypt, lock or render inaccessible anything on the hospital's own infrastructure on exit. |
Quotable, testable, and each one is a term of the agreement.
1.1 Completeness. You get everything: every record, every document, every image, every log, every configuration, not a subset chosen by us.
1.2 Usability. You get it in documented, non-proprietary, machine-readable formats, plus a human-readable rendering that needs no software at all, plus the documentation a competent third party needs to load it without asking us a question.
1.3 Speed. Fifteen (15) Business Days for a full export on request. Five (5) Business Days where you need it urgently for a regulatory, medico-legal or patient-safety reason. Immediately and continuously if you turn on the scheduled export at 6.2.
1.4 Cost. Nothing. No export fee, no extraction fee, no media fee, no "data release" fee, no professional-services charge for producing the export, and no charge for correcting it if it is wrong.
1.5 Unconditionality. No payment, no dispute, no release, no waiver, no notice period and no equipment return is a precondition to any of the above.
The complete scope. DIS-GL-401 holds the field-level schemas; this is the inventory.
| # | Content | What it includes |
|---|---|---|
| 2.1 | Structured data | Every record from every table in your tenant, with referential keys preserved and foreign-key relationships documented. Patients, encounters, orders, results, prescriptions, dispensings, admissions, discharges, transfers, appointments, invoices, receipts, payments, claims, inventory movements, purchase orders, staff records, rosters, quality indicators: everything the Platform holds for you |
| 2.2 | Clinical records in FHIR | Clinical data additionally as HL7 FHIR R4 resources wherever the record is representable as one, as newline-delimited JSON bundles, with a profile statement describing the resources and extensions used. Where a record is not representable as a FHIR resource, it appears in the structured export at 2.1 with a documented mapping |
| 2.3 | Imaging | Diagnostic images in DICOM, with study, series and instance metadata intact, in a directory structure with a DICOMDIR index |
| 2.4 | Documents and files | Scanned documents, uploaded files, reports, discharge summaries, consent forms, signed records and correspondence, in their original file formats, with an index mapping every file to its patient, encounter and document type |
| 2.5 | Rendered clinical records | A human-readable PDF rendering of the clinical record for each patient encounter, sufficient to answer a medico-legal or patient request without access to any software |
| 2.6 | Configuration and applications | Your configuration (master data, tariffs, formularies, organisational structure, roles, permission sets, form layouts, report definitions, workflow definitions) and the definitions of any Customer Application you built on the Platform |
| 2.7 | Audit and access logs | The audit and access logs for your tenant, for the retention period held, including who viewed which record and when |
| 2.8 | Statutory registers | The registers the Platform maintains for you, in the statutory format each requires, so that a register survives the migration intact |
| 2.9 | Terminology and code sets | The code sets and terminology mappings in use, and their versions, so that a coded value in the export can be interpreted |
| 2.10 | Documentation | A data dictionary, an entity-relationship description, a description of the export structure, and a load guide: the set a competent third party needs to load the export into another system without further assistance from Pensieve |
| 2.11 | Integrity evidence | A manifest listing every file with its size and SHA-256 hash, and a record count per entity, so that you can verify completeness rather than take it on trust |
| 2.12 | Integration inventory | A list of the third-party systems your tenant was integrated with, the data exchanged with each, and the credential shape required, so your incoming supplier knows what to rebuild |
2.13 What is not in the export, and why. Pensieve's own source code, the Platform software itself, and
other customers' data. The Platform software is addressed separately by source-code escrow (ADD-GL-011
and DIS-GL-407); the export is your data, which is a different thing.
2.14 Third-party credentials. Credentials you supplied under the bring-your-own-credential model are
not returned in the export, because you already hold them and an export file is not a safe place for a
secret. They are revoked and deleted on offboarding, and the deletion is certified. See ADD-GL-007.
3.1 Principles. Every format below is documented, non-proprietary and readable without a Pensieve licence. Nothing is delivered in a format that only Pensieve can read.
| Content | Primary format | Secondary format |
|---|---|---|
| Structured records | Delimited text (RFC 4180 CSV, UTF-8) with a documented schema per file | A columnar format (Apache Parquet) for large tables |
| Clinical records | HL7 FHIR R4, newline-delimited JSON | Included in the structured export with a mapping |
| Imaging | DICOM Part 10 files with DICOMDIR | None |
| Documents | Original format as uploaded (PDF, JPEG, TIFF, DOCX and so on) | None |
| Rendered records | PDF/A where the source permits, otherwise PDF | None |
| Configuration | JSON, with a documented schema | None |
| Audit logs | Newline-delimited JSON, with a documented event schema | Delimited text |
| Manifest and record counts | Delimited text and JSON | None |
| Documentation | Markdown and PDF | None |
3.2 Character encoding. UTF-8 throughout, including Devanagari and other Indic scripts, with a stated collation. Names in Indian languages survive the export intact, a point that sounds trivial until a migration destroys it.
3.3 Dates and identifiers. Dates and times in ISO 8601 with an explicit time zone. Internal identifiers preserved and documented so that relationships can be reconstructed.
3.4 Large volumes. Files are split at a documented size boundary with a documented naming convention, so that a multi-terabyte imaging archive transfers without a bespoke arrangement.
3.5 If you want a different format. Ask. Where a reasonable alternative is available, Pensieve will provide it. Where it is not, Pensieve says so and provides the documented mapping instead.
| Request | Commitment |
|---|---|
| Self-service export you run yourself | Immediate. No ticket, no approval, no notice |
| Scheduled export to storage you own | Continuous, at your chosen cadence, daily available |
| Full export on written request during the term | 15 Business Days |
| Urgent export for a regulatory, medico-legal or patient-safety reason | 5 Business Days |
| Full export on termination or expiry | 15 Business Days from the request, and in any event before the end of the Exit Period |
| Correction of an omission or defect you identify | 10 Business Days, at no charge |
| Delivery certificate | Issued on delivery (CRT-GL-010) |
4.1 When the clock starts. On receipt of the written request, not on completion of an internal approval. Pensieve acknowledges within one (1) Business Day and names the person responsible.
4.2 If Pensieve will miss a date. Pensieve tells you before the date passes, with the reason and a revised date. Missing an export commitment is treated internally as a Severity-1 matter, because it is the commitment on which this document's credibility rests.
5.1 Nothing. The complete export in 2, in the formats in 3, on the timings in 4, with the documentation and integrity evidence, is provided at no charge, at any time, for any reason, however many times you ask.
5.2 Fees that do not exist. There is no export fee, no extraction fee, no data-release fee, no professional-services charge for producing the export, no media fee, no per-record fee, no per-gigabyte fee, no reactivation fee to run an export after suspension, and no charge for a correction under 4.
5.3 The only things that are ever chargeable, and their limits.
| Item | Position |
|---|---|
| Continued production use of the Platform during the Exit Period | Charged at the Platform Fee rate applying immediately before termination, pro-rated. Read-only access instead is free for the whole Exit Period. Where you terminated for Pensieve's cause, insolvency or a change in law, the first 90 days are free in production capability too |
| Transition assistance beyond the free allowance | 40 person-hours free. Beyond that, at then-current rates, and only where you ask for it in writing |
| Physical media where the volume makes electronic transfer impractical | At cost, or you supply the media |
| Bespoke transformation into a format that is not in 3 and is not a reasonable alternative | Quoted in advance. Declining it never affects your right to the standard export |
5.4 The line. Pensieve may charge for work you ask it to do. Pensieve may never charge for giving you your data.
6.1 Self-service, any time. The Platform provides a self-service export you run yourself, during normal operation, without asking Pensieve. It is not gated on a ticket, an approval, an invoice or a notice period. A hospital that can export on a Tuesday afternoon for no reason is a hospital that is not locked in.
6.2 Scheduled export to storage you own: the recommendation. Pensieve will configure, at no charge and on request at any time, a scheduled export of your complete data set to a storage location you own and pay for: your own cloud bucket, your own on-premise storage, or an appliance in your own server room. Cadence is your choice; daily is available.
Turn this on at go-live. It costs nothing, it takes an hour to configure, and it means a current copy of your data sits permanently outside Pensieve's control. It is item 1 on the five-item checklist in
DIS-GL-407clause 12, and it is on the go-live checklist for that reason.
6.3 Test it before you commit. Pensieve will run a full export during your evaluation, before any contract is signed, so that your team can open the files, read the data dictionary, count the records and form its own view. Ask for it. Pensieve would rather you tested this than trusted it.
6.4 Annual verification. Pensieve performs a full export-and-verify test for each production customer at least annually and records the result, which is available to that customer on request.
7.1 The rule. The export is not conditional on:
7.1.1 payment of any amount, disputed or undisputed;
7.1.2 the resolution of any dispute, claim or arbitration;
7.1.3 signing a release, a waiver, a settlement or a non-disparagement undertaking;
7.1.4 returning any equipment or material;
7.1.5 giving a reason for leaving, completing an exit interview, or attending a retention conversation;
7.1.6 the identity of your incoming supplier, including where it is a competitor of Pensieve;
7.1.7 having served a notice period; or
7.1.8 the absence of a breach by you, including a breach of the Acceptable Use Policy or the Use Case Restrictions.
7.2 Waiver of lien and set-off. Pensieve waives any lien, right of retention and right of set-off it might otherwise assert over Customer Data.
7.3 Suspension does not touch it. Where Pensieve suspends access for non-payment or for any other
ground, the export rights in this Commitment continue to operate throughout the suspension. See
POL-GL-050 clause 15.5.
7.4 Debts survive; hostage-taking does not. Pensieve retains every ordinary remedy for an unpaid
invoice: interest, suspension of the service, termination, and recovery through the dispute mechanism in
MSA-IN-001 clause 25. Withholding clinical records is not one of them, and Pensieve gives it up
deliberately.
7.5 Contractually unbreakable. These commitments are within the never-limited category at
POL-GL-050 clause 18.1. No Termination & Exit Agreement, Transition Services Agreement, Order Form,
settlement or side letter may reduce them (MSA-IN-001 clause 22.10), and Pensieve will not use its
right to change the standing terms to weaken them (POL-GL-050 clause 26.4).
7.6 Why Pensieve gives this up. Because a hospital that fears it cannot leave will not move its whole operation onto an unknown platform, and because the bargaining power is worth less than the deals it costs. Pensieve would rather win on the product than on the exit cost.
8.1 The Exit Period. Unless the parties agree otherwise, an Exit Period of ninety (90) days begins on the effective date of expiry or termination, extendable once by a further ninety (90) days by written notice given before it expires. During it:
8.1.1 the Platform remains available in full production capability on payment of the Platform Fee at the pre-termination rate, pro-rated;
8.1.2 or, at your election, read-only access at no charge for the whole Exit Period;
8.1.3 support continues at the severity levels in SLA-GL-001; and
8.1.4 where you terminated for Pensieve's cause, Pensieve's insolvency or a change in law, the first ninety (90) days are provided at no charge in full production capability.
8.2 Transition assistance. On request during the Exit Period, Pensieve provides: attendance at
transition planning meetings; explanation of the data model, schema and export formats to you or your
incoming supplier under a confidentiality undertaking; support for reconciliation of exported data; and
reasonable cooperation with your incoming supplier's technical queries. Up to forty (40) person-hours at
no charge. Beyond that, chargeable at then-current rates, and recordable in a Transition Services
Agreement (ADD-GL-018).
8.3 Cooperation with your incoming supplier. Pensieve will speak to your incoming supplier, answer its technical questions, and explain the export. Pensieve will not be obstructive, will not slow-walk a response, and will not use the transition period to attempt to retain the account by making the migration difficult.
8.4 The sequence.
| Step | Who | Artefact |
|---|---|---|
| 1. Request offboarding | Hospital | Offboarding Request Form (FRM-GL-402) |
| 2. Agree the export scope, formats and delivery method | Both | Data Export Scope & Acceptance Form (FRM-GL-404) |
| 3. Record any legal hold or retention instruction | Hospital | Legal Hold / Retention Instruction Form (FRM-GL-405) |
| 4. Generate and deliver the export | Pensieve | Data Export Delivery Certificate (CRT-GL-010) |
| 5. Verify against the manifest and record counts | Hospital | 30-day window at 9 |
| 6. Correct any omission | Pensieve | At no charge, within 10 Business Days |
| 7. Knowledge transfer and handover | Both | Handover Pack Index (FRM-GL-408) |
| 8. Instruct deletion | Hospital | None |
| 9. Delete and certify | Pensieve | Certificate of Data Deletion & Destruction (CRT-GL-011) |
| 10. Final settlement | Both | Final Settlement Statement (FIN-GL-021), Offboarding Completion Certificate (CRT-GL-012) |
The operational detail is the Offboarding Runbook (RBK-GL-024).
8.5 An exit interview is offered, not required. Pensieve will ask why you left (FRM-GL-403). You do
not have to answer, and the export does not wait on it.
9.1 What you get to check with. Every delivery includes a manifest listing every file with its size and SHA-256 hash, and a record count per entity taken from the live system at the point of export.
9.2 How to verify. Hash every delivered file and compare against the manifest; count the rows in each delivered table and compare against the record counts; open a sample of rendered PDFs and confirm they match the records; open a sample of DICOM studies in any standard viewer. The documentation at 2.10 tells you how.
9.3 The verification window. You have thirty (30) days from delivery to identify an omission or a defect and require Pensieve to correct it. Correction is at no charge, within 10 Business Days.
9.4 Extension. Where the volume or your migration schedule makes 30 days impractical, ask before it expires and Pensieve will extend it.
9.5 Nothing is deleted until you have verified. Deletion under 10 begins only after the later of the end of the verification window and the end of the Exit Period, unless you instruct earlier deletion in writing.
10.1 Deletion. After the later of the end of the verification window and the end of the Exit Period,
Pensieve deletes Customer Data from production systems within thirty (30) days, and from backups within
the backup rotation period stated in DIS-GL-023, and issues a Certificate of Data Deletion &
Destruction (CRT-GL-011) identifying what was deleted, from where, when and by what method.
10.2 Earlier deletion. You may instruct earlier deletion in writing; Pensieve complies within fifteen (15) Business Days, and you bear the consequence of having asked before verifying.
10.3 What Pensieve retains, and why. Stated openly rather than buried:
| Retained | Reason | Period |
|---|---|---|
| Contract, order, invoice and tax records | Statutory accounting and tax retention | 8 financial years |
| Customer know-your-customer record | Direction (v) of the CERT-In Directions of 2022 | 5 years from cancellation |
| Trust Center access and audit records | Evidence of what was disclosed to whom | Per POL-GL-503 |
| Data relevant to an actual or anticipated legal claim | To establish, exercise or defend it | Only for the period required, then deleted with a supplementary certificate |
| Aggregated, de-identified operational statistics containing no personal data | Capacity planning and product improvement | Indefinite, and it is not personal data |
Clinical records, patient data and tenant content are not in that list. The full position is
DIS-GL-406 and DPA-GL-001 clause 14.
10.4 Legal hold. Where you instruct a legal hold (FRM-GL-405), Pensieve suspends deletion for the
scope and period you specify and confirms in writing what is being held.
11.1 An export is data, not a working hospital system. Loading it into another platform is a migration project. Pensieve gives you the data, the documentation and 40 hours of help; it does not perform your migration.
11.2 Pensieve does not warrant that another vendor will accept the export. The formats are open, standard and documented, which is the most any supplier can do. Whether an incoming supplier can ingest FHIR R4 or DICOM is a question for that supplier, and it is worth asking it early.
11.3 Structural fidelity, not visual fidelity. The export preserves the data, its relationships and a human-readable rendering. It does not reproduce the Platform's screens, workflows or user experience.
11.4 Configuration is exported as definitions, not as software. Your Customer Applications and workflows are exported as their definitions. They will not execute outside the Platform.
11.5 Retention holds may prevent complete deletion, and where they do, 10.3 says exactly what is kept.
11.6 An export is a point in time. Data entered after the export is not in it. That is why 6.2 matters.
11.7 Under DM-4, Pensieve depends on access. Where the Platform runs on your hardware and Pensieve
has no remote access, Pensieve provides the export tooling and the documentation and your team runs it.
The commitment is unchanged; the mechanics differ, and ADD-GL-008 records them.
11.8 If Pensieve is insolvent, someone else is in control. This Commitment binds Pensieve. It cannot
bind an insolvency estate. That is exactly why 6.2 is the recommendation and why
DIS-GL-407 ranks a hospital-held copy above every contractual promise in this document, including the
ones on this page.
12.1 During the term. Run the self-service export, or ask Pensieve to configure the scheduled export at
6.2. For a full export on request, write to info@pensievelabs.org or your named contact.
12.2 Urgently, for a regulatory, medico-legal or patient-safety reason. Write to
info@pensievelabs.org with "URGENT EXPORT" in the subject line and state the reason.
Acknowledgement within 1 Business Day, delivery within 5 Business Days.
12.3 On exit. Submit the Offboarding Request Form (FRM-GL-402), or simply write to
info@pensievelabs.org. Pensieve will not refuse an export because the wrong form was used.
12.4 If Pensieve does not perform. Escalate to info@pensievelabs.org and to the Grievance Officer at
info@pensievelabs.org under POL-GL-066. A failure to deliver an export in accordance with
this Commitment is a material breach of MSA-IN-001, and the remedies in MSA-IN-001 clauses 21 and
25 apply.
12.5 Contact.
| Purpose | Contact |
|---|---|
| Export requests and offboarding | info@pensievelabs.org |
| Contractual and escalation | info@pensievelabs.org |
| Grievance | [TO BE SUPPLIED], info@pensievelabs.org |
| Registered office | `28, Jamunather |
| Bulandshahar | |
| Uttar Pradesh | |
| India` |
13.1 This Commitment is given effect by MSA-IN-001 clause 22 (consequences of termination and exit
assistance), DPA-GL-001 clause 14 (retention, return and deletion) and POL-GL-050 clauses 21 and 26.4.
13.2 Where this document and an executed agreement differ, the agreement governs, and Pensieve undertakes that no agreement it executes will be less favourable to the Customer than this document. If one ever is, tell Pensieve and it will be corrected.
13.3 This Commitment survives expiry, termination, suspension, dispute, deprecation, end of life and sunset, to the extent Pensieve is able to perform at all.
A short list, because a commitment you have tested is worth more than one you have read.
| Subject | Document that owns it |
|---|---|
| Field-level export schemas and format specification | DIS-GL-401 |
| Deletion and return practice, backup rotation | DIS-GL-023 |
| What Pensieve retains after termination | DIS-GL-406 |
| What happens if Pensieve fails | DIS-GL-407 |
| Contractual exit clause | MSA-IN-001 clause 22 |
| Retention, return and deletion under data protection law | DPA-GL-001 clause 14 |
| End-of-life and deprecation notice periods | POL-GL-064 |
| Source-code escrow | ADD-GL-011 |
| Offboarding runbook and forms | RBK-GL-024, FRM-GL-402, FRM-GL-404, FRM-GL-405, FRM-GL-408 |
| Certificates | CRT-GL-010, CRT-GL-011, CRT-GL-012 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-07-31 | Founder | First published version. Five headline commitments; complete twelve-item export inventory including a human-readable PDF rendering of every encounter; open documented formats; named timings including a 5-Business-Day urgent path; zero cost with the non-existent fees listed by name; an eight-limb anti-hostage clause that survives non-payment, dispute and breach; the free daily scheduled export to hospital-owned storage; a verification regime with hashes and record counts; and an honest limitations section including the insolvency limit. |
WPR-GL-400 v1.0.0 | Last Modified On 31 July 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org