This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
Exit and portability
How you leave, and what you take with you
This page is published so it can be read before signature rather than discovered at termination.
Ask any hospital administrator who has changed software vendor what went wrong and the answer is usually one of two things: the data came back in a form nobody could use, or it did not come back until a disputed invoice was settled. Pensieve Labs is an unknown supplier asking you to run your entire operation on a platform you had not heard of last month. The rational response to that is fear of lock-in, and the honest answer to fear is not reassurance: it is a document with numbers in it that your counsel can hold Pensieve Labs to.
The commitment, in one box
Your data is yours. All of it. At any time. In a form you can use. At no charge. However this ends, including if it ends because you did not pay us.
Edsol Edtech Pvt. Ltd.will never withhold, delay, degrade, condition or charge for a hospital’s access to its own records: not over an unpaid invoice, not over a commercial dispute, not over a breach of contract, not over a bad-tempered exit, and not on the way out to a competitor. Pensieve Labs waives any lien, right of retention and right of set-off it might otherwise assert over customer data. Any term anywhere that purports to permit a charge for, or a condition on, a data export is of no effect.
This is not a policy statement. It is contractually binding through the Master Services Agreement, and it applies identically in all four deployment models: in DM-3 and DM-4 the data is already in your own cloud project or on your own hardware, and Pensieve Labs does not delete, disable, encrypt, lock or render inaccessible anything on infrastructure you own.
Section 1
What the export contains
Not a database dump and not a screen scrape. The test Pensieve Labs sets itself is that a competent third party can load the export into another system without further assistance from Pensieve Labs. That is what makes an export portability rather than a gesture.
| Component | Format | What it means |
|---|---|---|
| Structured data | CSV and JSONL | Every record from every table in your tenant with referential keys preserved: patients, encounters, orders, results, prescriptions, dispensings, admissions, discharges, transfers, appointments, invoices, receipts, payments, claims, inventory movements, purchase orders, staff records, rosters and quality indicators. |
| Clinical records | HL7 FHIR R4 | Newline-delimited JSON bundles with a profile statement describing the resources and extensions used. Where a record is not representable as a FHIR resource it appears in the structured export with a documented mapping. |
| Imaging | DICOM | Study, series and instance metadata intact, in a directory structure with a DICOMDIR index. |
| Documents and files | Original formats, plus PDF/A-2 | Scanned documents, uploads, reports, discharge summaries, consent forms and signed records, with an index mapping every file to its patient, encounter and document type. |
| Rendered clinical records | PDF per encounter | A human-readable rendering of the clinical record for each patient encounter, sufficient to answer a medico-legal or patient request without access to any software at all. This is the component that matters on the day a summons arrives. |
| Configuration and applications | CSV and JSONL | Master data, tariffs, formularies, organisational structure, roles, permission sets, form layouts, report definitions, workflow definitions, and the definitions of any application you built on the platform. |
| Audit and access logs | JSONL | Who viewed which record and when, amendments with prior values, disclosures and administrative changes, for the retention period held. |
| Terminology and code sets | CSV | The code systems and mappings in use, with versions, so that a coded value in the export can still be interpreted in five years. |
| Documentation | Markdown and CSV | A data dictionary covering every file, every column, every code system and every identifier; an entity-relationship description; a description of the export structure; and a load guide. An export without a data dictionary is not portability. |
| Integrity evidence | Manifest with SHA-256 | Every file listed with its size and hash, plus a record count per entity, so you can verify completeness rather than take it on trust. |
| Integration inventory | Markdown | The third-party systems your tenant was integrated with, the data exchanged with each, and the credential shape required, so your incoming supplier knows what to rebuild. |
The clause-level specification is the Data Export Format Specification: file layouts, encodings, date and identifier conventions, the split boundary for large volumes, and what happens if you want a format that is not on the list. Dates and times are ISO 8601 with an explicit time zone; internal identifiers are preserved and documented so relationships can be reconstructed.
Section 2
The timetable
Every row is a commitment with a number in it. The clock starts on receipt of the written request, not on completion of an internal approval, and Pensieve Labs acknowledges within one business day and names the person responsible. If Pensieve Labs is going to miss a date it tells you before the date passes, with the reason and a revised date.
| Request | Commitment | Note |
|---|---|---|
| Self-service export you run yourself | Immediate | No ticket, no approval, no notice period. |
| Scheduled export to storage you own | Continuous | At your chosen cadence. Daily is available. Configured at no charge, on request, at any time. |
| Full export on written request during the term | 15 business days | You do not have to be leaving to ask. |
| Urgent export for a regulatory, medico-legal or patient-safety reason | 5 business days | Stated separately because these do not arrive with notice. |
| Full export on termination or expiry | 15 business days | From the request, and in any event before the end of the exit period. |
| Correction of an omission or defect you identify | 10 business days | At no charge. Missing an export commitment is treated internally as a severity-1 matter. |
| Delivery certificate | On delivery | Issued as a countersigned certificate recording scope, record counts and hashes. |
What it costs
Nothing. There is no export fee, no extraction fee, no data-release fee, no professional-services charge for producing the export, no media fee, no per-record fee, no per-gigabyte fee, no reactivation fee to run an export after suspension, and no charge for a correction.
The only chargeable items are work you ask Pensieve Labs to do: continued production use of the platform during the exit period (read-only access instead is free for the whole period), transition assistance beyond the free allowance of forty person-hours, physical media where the volume makes electronic transfer impractical, and bespoke transformation into a format that is not on the standard list, which you may decline without affecting your right to the standard export. Pensieve Labs may charge for work; Pensieve Labs may never charge for giving you your data.
Test it before you commit, and turn on the scheduled export at go-live
Pensieve Labs will run a full export during your evaluation, before any contract is signed, so your team can open the files, read the data dictionary and count the records. Ask for it. Pensieve Labs would rather you tested this than trusted it. And configure the scheduled export to storage you own on day one: it costs nothing, it takes an hour, and it means a current copy of your data sits permanently outside Pensieve Labs’s control. A hospital that can export on a Tuesday afternoon for no reason is a hospital that is not locked in.
Section 3
Post-termination retention and deletion
Three things are routinely conflated, and the published statement keeps them apart. Retention is data Pensieve Labs deliberately keeps because a law, a hold or an evidential need requires it. Residue is data deleted from every live system that still exists as ciphertext inside a backup generation that has not yet expired, and whose key has been destroyed. Aggregate is statistics containing no personal data. Residue is not retention, and Pensieve Labs states the date on which it expires rather than describing it as deletion.
| Step | When | What happens |
|---|---|---|
| Production and non-production deletion | Within 30 days | Of the deletion instruction taking effect. Patient records, encounters, orders, results, prescriptions, imaging, documents, billing and claims, inventory, HR, configuration, user accounts, your supplied third-party credentials, support artefacts and migration staging data (from production, replicas, indices, caches and analytics). |
| Backup residue | On the rotation period | A backup taken before deletion still contains the data as ciphertext until that generation expires. The expiry date is stated rather than glossed. |
| Key destruction | After the backups | Once the keys are destroyed the residue cannot be read, restored or used, including by Pensieve. |
| Certificate of Data Deletion & Destruction | Within 10 business days of deletion completing | States what was deleted, from where, when, by what method, and what was retained under the published retention list, with the names of the individuals who executed and verified it. |
What Pensieve Labs retains after that is a closed list, and each item carries its legal basis, its period and whether it contains personal data. It covers records Pensieve Labs is itself required by law to keep, the deletion evidence pack, and anything under a legal hold, customer-instructed or required by a court or regulator. A hold is reviewed on a cadence, you are told about it unless Pensieve Labs is legally prohibited from saying so, and release is followed by deletion within thirty days and a supplementary certificate.
Nothing here is conditional. Deletion is not withheld pending payment and is not accelerated to avoid a cost. And Pensieve Labs’s deletion does not discharge your own retention obligation: the retention statement reconciles the two explicitly, because a hospital that deletes with its vendor and then loses the export has not discharged its medico-legal retention duty. It has moved it, and then failed it.
Section 4
The two certificates that close an exit
An exit is not complete because both parties believe it is. It is complete because two countersigned instruments say so, and because the final settlement is cleared. Both certificates sit in your workspace, because they name a specific hospital and a specific deal.
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
The offboarding gate is satisfied only when the data export has been delivered, the Certificate of Deletion has been issued and the final settlement is cleared. Until all three are true the deal is not closed, and the tracker in your workspace says so.
Section 5
If Pensieve fails as a business
Edsol Edtech Pvt. Ltd.is a small company with no track record, and the question “what happens to us if you disappear” is the correct question to ask. It deserves a document rather than reassurance, and it has one.
You already hold a current copy
The mitigation that does not depend on Pensieve Labs acting at the moment of failure. Self-service export runs on your instruction at any time, and the scheduled export writes a complete copy to storage you own and pay for, daily if you choose. This is item one on the go-live checklist for exactly this reason.
In DM-3 and DM-4 the data is already yours
It is in your own cloud project or on your own hardware. Pensieve Labs ceasing to exist does not move it, encrypt it or switch it off.
A run-out commitment, not a switch-off
If Pensieve Labs resolves to cease operating the platform, affected customers are notified before the market is, production services are the last thing switched off, and the run-out period is long enough to migrate rather than to panic. The funding assumption behind it is stated, and so is its limit: a run-out funded from available resources is a plan, not a guarantee.
Source-code escrow
A tri-party deposit with an independent agent, with beneficiary accession by joinder so you become a beneficiary without a fresh tripartite negotiation. Release events include insolvency, ceasing to support the platform, uncured material breach of the support obligation, and assignment to a party that does not assume the obligations. Your data is not deposited, because it is not Pensieve Labs’s to deposit.
Key-person dependency, stated rather than hidden
A small company has key-person risk. The continuity plan lists what has been done about it and what has not, because a continuity document that lists only what is in place is a marketing document.
No lien, no set-off, no conditions
The waiver in the commitment above is what makes every mitigation above operable. An export right that can be suspended over a disputed invoice is not an export right.
The scenarios, the mitigations ranked by how much they actually help, and the escrow mechanics are in the Business Failure Continuity Plan.
Section 6
The documents behind this page
Every commitment on this page is a summary of one of these. Where a summary and a document differ, the document is correct.
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
Supporting instruments
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours
This belongs to a specific hospital's workspace. Sign in with your workspace credential to read it.Sign in to your workspaceWait: target 4 business hours
Ask for an export during the evaluation. It either happens, or it does not.