Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Exit and portability

How you leave, and what you take with you

This page is published so it can be read before signature rather than discovered at termination.

Ask any hospital administrator who has changed software vendor what went wrong and the answer is usually one of two things: the data came back in a form nobody could use, or it did not come back until a disputed invoice was settled. Pensieve Labs is an unknown supplier asking you to run your entire operation on a platform you had not heard of last month. The rational response to that is fear of lock-in, and the honest answer to fear is not reassurance: it is a document with numbers in it that your counsel can hold Pensieve Labs to.

The commitment, in one box

Your data is yours. All of it. At any time. In a form you can use. At no charge. However this ends, including if it ends because you did not pay us.

Edsol Edtech Pvt. Ltd.will never withhold, delay, degrade, condition or charge for a hospital’s access to its own records: not over an unpaid invoice, not over a commercial dispute, not over a breach of contract, not over a bad-tempered exit, and not on the way out to a competitor. Pensieve Labs waives any lien, right of retention and right of set-off it might otherwise assert over customer data. Any term anywhere that purports to permit a charge for, or a condition on, a data export is of no effect.

This is not a policy statement. It is contractually binding through the Master Services Agreement, and it applies identically in all four deployment models: in DM-3 and DM-4 the data is already in your own cloud project or on your own hardware, and Pensieve Labs does not delete, disable, encrypt, lock or render inaccessible anything on infrastructure you own.

Section 1

What the export contains

Not a database dump and not a screen scrape. The test Pensieve Labs sets itself is that a competent third party can load the export into another system without further assistance from Pensieve Labs. That is what makes an export portability rather than a gesture.

ComponentFormatWhat it means
Structured dataCSV and JSONLEvery record from every table in your tenant with referential keys preserved: patients, encounters, orders, results, prescriptions, dispensings, admissions, discharges, transfers, appointments, invoices, receipts, payments, claims, inventory movements, purchase orders, staff records, rosters and quality indicators.
Clinical recordsHL7 FHIR R4Newline-delimited JSON bundles with a profile statement describing the resources and extensions used. Where a record is not representable as a FHIR resource it appears in the structured export with a documented mapping.
ImagingDICOMStudy, series and instance metadata intact, in a directory structure with a DICOMDIR index.
Documents and filesOriginal formats, plus PDF/A-2Scanned documents, uploads, reports, discharge summaries, consent forms and signed records, with an index mapping every file to its patient, encounter and document type.
Rendered clinical recordsPDF per encounterA human-readable rendering of the clinical record for each patient encounter, sufficient to answer a medico-legal or patient request without access to any software at all. This is the component that matters on the day a summons arrives.
Configuration and applicationsCSV and JSONLMaster data, tariffs, formularies, organisational structure, roles, permission sets, form layouts, report definitions, workflow definitions, and the definitions of any application you built on the platform.
Audit and access logsJSONLWho viewed which record and when, amendments with prior values, disclosures and administrative changes, for the retention period held.
Terminology and code setsCSVThe code systems and mappings in use, with versions, so that a coded value in the export can still be interpreted in five years.
DocumentationMarkdown and CSVA data dictionary covering every file, every column, every code system and every identifier; an entity-relationship description; a description of the export structure; and a load guide. An export without a data dictionary is not portability.
Integrity evidenceManifest with SHA-256Every file listed with its size and hash, plus a record count per entity, so you can verify completeness rather than take it on trust.
Integration inventoryMarkdownThe third-party systems your tenant was integrated with, the data exchanged with each, and the credential shape required, so your incoming supplier knows what to rebuild.

The clause-level specification is the Data Export Format Specification: file layouts, encodings, date and identifier conventions, the split boundary for large volumes, and what happens if you want a format that is not on the list. Dates and times are ISO 8601 with an explicit time zone; internal identifiers are preserved and documented so relationships can be reconstructed.

Section 2

The timetable

Every row is a commitment with a number in it. The clock starts on receipt of the written request, not on completion of an internal approval, and Pensieve Labs acknowledges within one business day and names the person responsible. If Pensieve Labs is going to miss a date it tells you before the date passes, with the reason and a revised date.

RequestCommitmentNote
Self-service export you run yourselfImmediateNo ticket, no approval, no notice period.
Scheduled export to storage you ownContinuousAt your chosen cadence. Daily is available. Configured at no charge, on request, at any time.
Full export on written request during the term15 business daysYou do not have to be leaving to ask.
Urgent export for a regulatory, medico-legal or patient-safety reason5 business daysStated separately because these do not arrive with notice.
Full export on termination or expiry15 business daysFrom the request, and in any event before the end of the exit period.
Correction of an omission or defect you identify10 business daysAt no charge. Missing an export commitment is treated internally as a severity-1 matter.
Delivery certificateOn deliveryIssued as a countersigned certificate recording scope, record counts and hashes.

What it costs

Nothing. There is no export fee, no extraction fee, no data-release fee, no professional-services charge for producing the export, no media fee, no per-record fee, no per-gigabyte fee, no reactivation fee to run an export after suspension, and no charge for a correction.

The only chargeable items are work you ask Pensieve Labs to do: continued production use of the platform during the exit period (read-only access instead is free for the whole period), transition assistance beyond the free allowance of forty person-hours, physical media where the volume makes electronic transfer impractical, and bespoke transformation into a format that is not on the standard list, which you may decline without affecting your right to the standard export. Pensieve Labs may charge for work; Pensieve Labs may never charge for giving you your data.

Test it before you commit, and turn on the scheduled export at go-live

Pensieve Labs will run a full export during your evaluation, before any contract is signed, so your team can open the files, read the data dictionary and count the records. Ask for it. Pensieve Labs would rather you tested this than trusted it. And configure the scheduled export to storage you own on day one: it costs nothing, it takes an hour, and it means a current copy of your data sits permanently outside Pensieve Labs’s control. A hospital that can export on a Tuesday afternoon for no reason is a hospital that is not locked in.

Section 3

Post-termination retention and deletion

Three things are routinely conflated, and the published statement keeps them apart. Retention is data Pensieve Labs deliberately keeps because a law, a hold or an evidential need requires it. Residue is data deleted from every live system that still exists as ciphertext inside a backup generation that has not yet expired, and whose key has been destroyed. Aggregate is statistics containing no personal data. Residue is not retention, and Pensieve Labs states the date on which it expires rather than describing it as deletion.

StepWhenWhat happens
Production and non-production deletionWithin 30 daysOf the deletion instruction taking effect. Patient records, encounters, orders, results, prescriptions, imaging, documents, billing and claims, inventory, HR, configuration, user accounts, your supplied third-party credentials, support artefacts and migration staging data (from production, replicas, indices, caches and analytics).
Backup residueOn the rotation periodA backup taken before deletion still contains the data as ciphertext until that generation expires. The expiry date is stated rather than glossed.
Key destructionAfter the backupsOnce the keys are destroyed the residue cannot be read, restored or used, including by Pensieve.
Certificate of Data Deletion & DestructionWithin 10 business days of deletion completingStates what was deleted, from where, when, by what method, and what was retained under the published retention list, with the names of the individuals who executed and verified it.

What Pensieve Labs retains after that is a closed list, and each item carries its legal basis, its period and whether it contains personal data. It covers records Pensieve Labs is itself required by law to keep, the deletion evidence pack, and anything under a legal hold, customer-instructed or required by a court or regulator. A hold is reviewed on a cadence, you are told about it unless Pensieve Labs is legally prohibited from saying so, and release is followed by deletion within thirty days and a supplementary certificate.

Nothing here is conditional. Deletion is not withheld pending payment and is not accelerated to avoid a cost. And Pensieve Labs’s deletion does not discharge your own retention obligation: the retention statement reconciles the two explicitly, because a hospital that deletes with its vendor and then loses the export has not discharged its medico-legal retention duty. It has moved it, and then failed it.

Section 4

The two certificates that close an exit

An exit is not complete because both parties believe it is. It is complete because two countersigned instruments say so, and because the final settlement is cleared. Both certificates sit in your workspace, because they name a specific hospital and a specific deal.

The offboarding gate is satisfied only when the data export has been delivered, the Certificate of Deletion has been issued and the final settlement is cleared. Until all three are true the deal is not closed, and the tracker in your workspace says so.

Section 5

If Pensieve fails as a business

Edsol Edtech Pvt. Ltd.is a small company with no track record, and the question “what happens to us if you disappear” is the correct question to ask. It deserves a document rather than reassurance, and it has one.

  • You already hold a current copy

    The mitigation that does not depend on Pensieve Labs acting at the moment of failure. Self-service export runs on your instruction at any time, and the scheduled export writes a complete copy to storage you own and pay for, daily if you choose. This is item one on the go-live checklist for exactly this reason.

  • In DM-3 and DM-4 the data is already yours

    It is in your own cloud project or on your own hardware. Pensieve Labs ceasing to exist does not move it, encrypt it or switch it off.

  • A run-out commitment, not a switch-off

    If Pensieve Labs resolves to cease operating the platform, affected customers are notified before the market is, production services are the last thing switched off, and the run-out period is long enough to migrate rather than to panic. The funding assumption behind it is stated, and so is its limit: a run-out funded from available resources is a plan, not a guarantee.

  • Source-code escrow

    A tri-party deposit with an independent agent, with beneficiary accession by joinder so you become a beneficiary without a fresh tripartite negotiation. Release events include insolvency, ceasing to support the platform, uncured material breach of the support obligation, and assignment to a party that does not assume the obligations. Your data is not deposited, because it is not Pensieve Labs’s to deposit.

  • Key-person dependency, stated rather than hidden

    A small company has key-person risk. The continuity plan lists what has been done about it and what has not, because a continuity document that lists only what is in place is a marketing document.

  • No lien, no set-off, no conditions

    The waiver in the commitment above is what makes every mitigation above operable. An export right that can be suspended over a disputed invoice is not an export right.

The scenarios, the mitigations ranked by how much they actually help, and the escrow mechanics are in the Business Failure Continuity Plan.

Section 6

The documents behind this page

Every commitment on this page is a summary of one of these. Where a summary and a document differ, the document is correct.

Supporting instruments

Ask for an export during the evaluation. It either happens, or it does not.