Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Gate | NDA-GL-002 v1.0.0

This is the whole instrument, on screen, before you accept it. It is mutual: it protects what Pensieve Labs shows you and what you tell us about your hospital, on the same terms, for the same two years.

Accepting it takes one click and is recorded at once. Access to the NDA tier is then granted by an administrator, with a target of four business hours. Accepting the mutual instrument up front still removes the multi-day “send us your NDA, our counsel will revert” exchange from the front of every evaluation.

Instrument
NDA-GL-002
Version
1.0.0
Content hash
FC55AD03108E
Last modified
2026-07-31
Term
Two years from acceptance
NDA tier
128 documents

Click-through Mutual Non-Disclosure Agreement

NDA-GL-002 v1.0.0: the Trust Center NDA gate


Applicability

Deployment model Applies Variation
DM-1 Dedicated Yes None
DM-2 Shared Yes None
DM-3 Customer Cloud Yes None
DM-4 On-Premise Yes None

This Agreement is deployment-model neutral. It governs access to documents, not to systems, and imposes no obligation that depends on where the Platform runs.

Scope In Out
Information Material in the T_NDA tier of the Trust Center; what Pensieve Labs tells the accepting person in connection with the evaluation; what the accepting person tells Pensieve Labs about the hospital Anything exchanged under an executed NDA-GL-001, NDA-GL-003 or MSA-IN-001
Personal data None. Expressly excluded; see clause 8 Any processing of personal data, which requires DPA-GL-001
Systems access None Credentials to a Pensieve instance, sandbox or demonstration tenant

Purpose

NDA-GL-002 is the instrument that unlocks the T_NDA document tier without a human in the loop. A prospective customer reads it on screen, accepts it, and has the material in seconds rather than in days.

It is the fastest document in the library and, on the two clocks that matter, the one that removes the most days: it takes the "send us your NDA / we will send ours / our counsel will revert" exchange off the front of every deal. It is not a substitute for NDA-GL-001, and it says so.

Design constraint: the operative text below is under 600 words. That is a hard limit, not an aspiration. A click-through agreement that cannot be read on a screen in ninety seconds is a click-through agreement that will not be read, and an unread standard-form term is exactly the term an Indian court will decline to enforce.


Part A: The Agreement (operative text)

Everything between the two rules below is the agreement. It is rendered verbatim in the acceptance dialogue. Nothing outside it forms part of the contract.


Mutual Non-Disclosure Agreement: NDA-GL-002 version 1.0.0

1. Parties. This agreement is between Edsol Edtech Pvt. Ltd. ("we", "us") and the organisation you name when you accept it ("your organisation", "you"). You confirm you are authorised to accept it for your organisation. If you are not, you accept it in your own name and are bound by it personally.

2. Purpose. To let you evaluate Pensieve using the NDA-gated material in our Trust Center at https://trust.pensievelabs.org, and to let you tell us about your hospital so that we can respond (the "Purpose").

3. What is confidential. (a) Anything we make available to you in the NDA-gated tier of the Trust Center, and anything we tell you in connection with your evaluation. (b) Anything you tell us about your hospital's operations, systems, finances or plans. Each is the Confidential Information of the party that disclosed it.

4. What is not. Information that is public other than through a breach of this agreement; that the receiving party already lawfully held without restriction; that a third party lawfully supplied without restriction; or that the receiving party developed independently without using the other's Confidential Information.

5. Obligations. Each party will use the other's Confidential Information only for the Purpose, protect it with at least reasonable care, and disclose it only to people within its own organisation, and to its professional advisers, who need it for the Purpose and are bound to keep it confidential. Each party is responsible for those people.

6. Compelled disclosure. Either party may disclose where a law, court or regulator requires it. Where it is lawful to do so, that party will notify the other first and disclose only what is required.

7. No licence, no commitment, no warranty. Nothing here grants or transfers any intellectual property right. Nothing obliges either party to proceed, to disclose anything, or to keep anything available. Everything is provided as is, without warranty of accuracy or completeness.

8. No personal data. Do not send us patient data or any other personal data under this agreement. If you do, we will not use it and will delete it on your instruction. Processing personal data requires our Data Processing Agreement (DPA-GL-001).

9. How long. This agreement runs for two years from acceptance. Confidentiality obligations run for two years from the date each item was disclosed, and, for trade secrets, for as long as they remain trade secrets. On request, each party will delete the other's Confidential Information, except copies in routine backups or under a legal hold, which stay confidential until deleted in the ordinary course.

10. What replaces this. If your organisation and we execute our standard Mutual NDA (NDA-GL-001), a one-way NDA (NDA-GL-003) or a Master Services Agreement (MSA-IN-001), that instrument replaces this agreement and governs everything disclosed under it, including everything already disclosed under this one.

11. Remedies. Damages may not be an adequate remedy for a breach. Either party may seek an injunction.

12. Law. This agreement is governed by Legal governing law. The courts at Legal jurisdiction have exclusive jurisdiction, except that either party may seek interim relief in any competent court. Accepting this agreement electronically binds you as a signature would. Edsol Edtech Pvt. Ltd. will bear any stamp duty that may be assessed on it.

Word count of clauses 1 to 12: 531. The ceiling is 600. A change that breaches the ceiling requires Legal sign-off, because the ceiling is the enforceability argument, not a style preference.


End of the agreement. Everything below is implementation specification and legal commentary. It is not shown in the acceptance dialogue and forms no part of the contract.


Part B: Acceptance UX requirements (binding on the application)

These requirements are derived from the enforceability conditions in Part D. Each is mandatory. A release that fails any of them makes every acceptance recorded by that release weaker evidence than it needs to be.

# Requirement Why (Part D reference)
B1 Unambiguous affirmative action. Acceptance requires ticking a checkbox that is unticked by default, and then activating a button. No pre-ticked box. No "by continuing you agree". No browsewrap, ever. D.3: consensus ad idem; browsewrap is the failure mode Indian commentary singles out
B2 The button states the legal consequence. Its label is exactly Accept NDA and continue. Not Continue, not OK, not Submit. D.3: the click must be linked to the specific terms
B3 Full text on screen. The whole of Part A is rendered inside the dialogue in a scrollable region, not behind a link, not in an iframe, not summarised. A permanent link to the versioned public page is shown alongside, so the text is also one click away in a citable form. D.2: IT Act s.4 "accessible so as to be usable for a subsequent reference"
B4 Proximity. The checkbox, the sentence "I have read and accept the Mutual NDA, version 1.0.0", and the button are contiguous. No other interactive control sits between them. D.3: reasonable notice
B5 Legibility. Body text no smaller than 16 px equivalent, contrast meeting WCAG 2.2 AA, no scroll-jacking, no colour-only signalling, keyboard operable, correctly labelled for screen readers. D.3 and the authoring standard Section 7
B6 A decline path of equal prominence. A visible Decline control that returns the visitor to the public tier without penalty or dark pattern. D.3: unconscionability; a "take it or leave it" screen with no exit is the fact pattern courts dislike
B7 Verified identity before acceptance. The work email address is verified by a one-time code before the acceptance dialogue is shown. An unverified email produces no acceptance record. D.4: the record has to tie the click to a person
B8 Version-pinned acceptance. The record stores the version actually rendered. A later version never applies retroactively. Access granted under version n survives publication of version n+1. D.5
B9 Re-acceptance on material change. A change to Part A increments the minor or major version and requires re-acceptance at the next sign-in. A change confined to Parts B to E increments the patch version and requires none. D.5
B10 Immediate written confirmation. On acceptance the application emails the accepting person a confirmation containing the acceptance identifier, the version, the timestamp, the text hash, and the full text of Part A as a PDF attachment. D.2: subsequent reference; and it is the artefact the hospital's counsel asks for
B11 No bundling. Acceptance of the NDA is a discrete action. It is not combined with marketing consent, cookie consent, account creation terms or any other assent in the same click. D.3: the click must map to one identified instrument
B12 Server-side enforcement. The T_NDA tier is gated in the API, not in the client. A missing or expired acceptance returns 403 regardless of what the browser believes. Operational integrity of the evidentiary record

Part C: Evidentiary record (what the application must persist)

One row per acceptance, in an append-only table with no UPDATE and no DELETE grants, retained for eight (8) years. Every field is mandatory unless marked optional.

Field Type Note
acceptance_id uuid Primary key. Quoted in the confirmation email and in every downstream access grant
accepting_person_name text As entered
accepting_person_email text Work email, verified before acceptance
email_verified_at timestamptz Time the one-time code was validated
email_verification_method text e.g. otp_6_digit
organisation_name text As entered by the accepting person
organisation_domain text Derived from the email address
job_title text Optional
authority_affirmed boolean The clause 1 affirmation. Must be true
nda_doc_id text NDA-GL-002
nda_version text Semver of the template rendered, e.g. 1.0.0
nda_version_id uuid Immutable template-version row
rendered_text text The exact Part A text shown, token-resolved, byte for byte
rendered_text_sha256 char(64) Full 64-hex digest of rendered_text. Never truncated in storage
hash_algorithm text Literal string SHA-256. Stored explicitly because the BSA Schedule certificate must state it
rendered_text_object_key text Immutable object-storage key holding the same bytes
accepted_at timestamptz UTC, from a monotonic server clock. Never a client-supplied time
server_time_source text NTP source identifier
client_ip inet As observed at the edge
client_ip_country text Geo-resolved at write time; stored, not recomputed
user_agent text Raw header string, unparsed
page_url text The URL of the acceptance dialogue
referrer text Optional
locale text Rendered locale
checkbox_state boolean Must be true
button_label text The exact label activated: evidence that B2 held at the time
scrolled_to_end boolean Whether the text region was scrolled to its end
dwell_ms integer Milliseconds between dialogue render and acceptance
confirmation_email_message_id text Provider message id for the B10 email
confirmation_email_sent_at timestamptz
confirmation_email_delivery_state text Provider delivery status, updated by webhook into a separate table, never by mutating this row
record_sha256 char(64) Digest over the canonicalised row, written at insert. Detects tampering
expires_at timestamptz accepted_at + two years. Drives re-acceptance
superseded_by_instance_id uuid Set when NDA-GL-001, NDA-GL-003 or MSA-IN-001 is executed by the same organisation

Derived artefacts the record must be able to produce, on demand and without reconstruction:

  1. Acceptance Certificate (PDF): a one-page, letterhead-rendered statement of who accepted what, when, from where, with the version, the full hash and the algorithm. Issued to the accepting organisation on request, and attached to any dispute file.
  2. The exact text as accepted, re-served from rendered_text_object_key and verified against rendered_text_sha256 on read.
  3. Input to the certificate under section 63(4), Bharatiya Sakshya Adhiniyam, 2023, which requires the hash value of the electronic record and the algorithm used to obtain it. This is the operational reason the full 64-character digest and the literal algorithm string are stored, and not a truncated display hash.

Commentary. Not part of the agreement.

D.1 What this instrument is, and what it is not

NDA-GL-002 is a contract formed by electronic means. It is not signed with an electronic signature within section 3A of the Information Technology Act, 2000, and this document does not claim that it is. Ticking a box and activating a button is not a Second Schedule technique. It follows that the statutory presumptions attaching to signed electronic records do not attach automatically here, and that the evidentiary record in Part C is doing the work the signature would otherwise do. Stating this plainly is deliberate: a vendor who claims a clickwrap is an "electronic signature" loses the room the moment the hospital's counsel opens the IT Act.

Where the value of the information warrants a signed instrument, NDA-GL-001 exists and is executed with Aadhaar eSign or a Digital Signature Certificate, both of which are Second Schedule techniques.

D.2 The statutory basis

Provision Effect Application here
IT Act s.10A A contract is not unenforceable merely because electronic means were used to communicate the proposal, the acceptance or its revocation This is the operative provision. It is what makes the click binding
IT Act s.4 A legal requirement that information be in writing is satisfied by an electronic record that is accessible so as to be usable for a subsequent reference Satisfied by rendering the full text (B3), storing the exact bytes (Part C) and emailing them to the accepting person (B10)
IT Act s.5 An electronic signature affixed in the prescribed manner satisfies a signature requirement Cited for completeness and expressly not relied on: see D.1. No statute requires an NDA to be signed
Indian Contract Act, 1872, ss.2 and 10 Offer, acceptance, lawful consideration, capacity, free consent The offer is the published text; acceptance is the affirmative act; consideration is the mutual exchange of promises and of access; capacity and authority are affirmed under clause 1
Bharatiya Sakshya Adhiniyam, 2023, s.63 Admissibility of electronic records, subject to the s.63(4) certificate, which must state the hash value and algorithm Drives the storage requirements in Part C
BSA 2023, ss.85 and 86 Presumptions as to electronic agreements and secure electronic records Available for the signed forms (NDA-GL-001). Their application to an unsigned clickwrap is doubtful, which is precisely why Part C exists [UNVERIFIED: no Indian authority located applying s.85 to an unsigned clickwrap]

Note for anyone drafting from older material: the Bharatiya Sakshya Adhiniyam, 2023 came into force on 1 July 2024 and repealed the Indian Evidence Act, 1872. Sections 65B, 85A, 85B and 67A no longer exist. Much published Indian commentary on clickwrap, including sources otherwise relied on here, still cites s.65B. Do not repeat that error in front of a hospital's counsel.

D.3 The case law, and the conditions it produces

Indian courts have not produced a dedicated clickwrap judgment of the kind the United States has. The position is assembled from three lines of authority.

  1. Contracts can be concluded without a signed instrument, by electronic exchange. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd., (2010) 3 SCC 1: the Supreme Court held a contract concluded by an exchange of e-mails, with no formal signed agreement, where the essential terms were agreed and acceptance was unconditional. (Indian Kanoon; SSRN case comment)

    Correction to widely-published commentary. Several 2025 and 2026 secondary sources describe Trimex as "a Delhi High Court decision upholding a click-wrap agreement". It is neither: it is a Supreme Court decision under section 11(6) of the Arbitration and Conciliation Act, 1996, about e-mail exchange. Cite it for what it decided.

  2. Unconscionable terms in standard-form contracts are unenforceable where bargaining power is unequal. Central Inland Water Transport Corporation Ltd. v. Brojo Nath Ganguly, (1986) 3 SCC 156; LIC of India v. Consumer Education & Research Centre, (1995) 5 SCC 482. (AdvocateKhoj: LIC v. CERC; Indian Kanoon: LIC v. CERC) This is the live risk for any click-through instrument, and it is why the terms in Part A are mutual, short, and modest: there is nothing in them that a court would be asked to strike. No indemnity, no liability cap, no non-solicit, no perpetual restraint, no waiver of rights, no unilateral variation.
  3. Unusual or onerous terms must be brought to the other party's attention. The general Indian rule on notice of terms in standard-form contracts. This produces requirements B1 to B6 and B11.

The conditions that follow, and which Part B implements: conspicuous notice adjacent to the assent control; the full terms visible or one click away in legible form; an unambiguous affirmative act linked to one identified instrument; a real alternative to accepting; and an audit-ready log tying the act to a person, a time and a specific version of the text. (Mondaq on Clickwrap, Browsewrap and Negotiated SaaS Contracts: Enforceability in India; iPleaders: Enforceability of clickwrap agreements in India)

Browsewrap is not an option. Terms notified only by a footer link, with no affirmative act, are the weakest form and the one Indian commentary consistently marks as high-risk. Pensieve Labs does not use browsewrap for any gated tier.

One narrowing that helps. The counterparty here is a hospital acting in business, not a consumer. The "unfair contract" machinery of section 2(46) of the Consumer Protection Act, 2019 addresses consumer contracts and does not reach a business-to-business NDA. The unconscionability line at (2) above still does.

D.4 Why identity verification precedes acceptance

An acceptance record that cannot be tied to an identified person is a record of a click, not of a contract. Requirement B7 (verify the work email by one-time code before the dialogue is shown) converts an anonymous event into evidence that a named individual, at a named organisation, on a named domain, accepted a specific version at a specific time. It costs the visitor about twenty seconds. It is the single highest- value line in Part B.

D.5 Stamp duty

Section 3 of the Indian Stamp Act, 1899 charges duty on instruments executed. The better view is that an unsigned click-through acceptance is not an executed instrument and attracts no duty, and this is the view the market takes. (iPleaders: Indian Stamp and Registration Act; RSRR, Beyond Pen and Paper: stamping of e-contracts in India) [UNVERIFIED: no Indian judgment located deciding whether a clickwrap is an "instrument" for the purposes of s.3.]

Pensieve Labs does not rely on that view. Clause 12 commits Edsol Edtech Pvt. Ltd. to bear any duty assessed on this agreement. Section 35 of the Indian Stamp Act renders an insufficiently stamped instrument inadmissible until duty and penalty are paid, not void, so the exposure is a payment, not the loss of the agreement, and the payment is ours.

D.6 Versioning, supersession and the access grant

  • Acceptance is pinned to a version. The record stores the version identifier and the hash of the exact text rendered. A subsequent version has no retroactive effect on an existing acceptance (B8).
  • A change to Part A is a minor or major version increment and triggers re-acceptance (B9). A change to Parts B, C, D or E is a patch increment and does not.
  • Access to the T_NDA tier is granted for the life of the acceptance and expires with it (expires_at). Expiry closes the tier; it does not end the confidentiality obligations, which run under clause 9.
  • On execution of NDA-GL-001, NDA-GL-003 or MSA-IN-001 by the same organisation, the application sets superseded_by_instance_id. The clickwrap acceptance is retained as evidence (it is never deleted) but the executed instrument governs from that point under clause 10.

Part E: What this document does not do

Stated because the gap is the point of the design, not an oversight.

  1. It does not grant access to any Pensieve instance, sandbox or demonstration tenant. Systems access requires credentials issued under the Trust Center access model and, where any live data is involved, an executed DPA-GL-001.
  2. It does not authorise the disclosure or processing of personal data in either direction. Clause 8 is an express prohibition, not a caution.
  3. It does not carry a liability cap, an indemnity, a non-solicit, an exclusivity or a standstill. Those would be the terms a court examined, and none of them is worth the examination.
  4. It does not support negotiation. There is no redline path for a click-through instrument. A counterparty who wants to negotiate is routed to NDA-GL-001, which is published for exactly that reason.
  5. It is not stamped at acceptance, and no stamp certificate is bound into it. See D.5.

Identifier Artefact Relationship
NDA-GL-001 Mutual Non-Disclosure Agreement Supersedes this Agreement on execution (clause 10)
NDA-GL-003 One-way NDA (hospital-disclosing) Supersedes this Agreement on execution (clause 10)
MSA-IN-001 Master Services Agreement Supersedes this Agreement on execution (clause 10)
DPA-GL-001 Data Processing Agreement The only instrument authorising processing of personal data (clause 8)
SPEC-001 Client Lifecycle Model & Document Taxonomy Defines the T_NDA tier this Agreement unlocks
SPEC-003 Token Registry & Document Engine Defines the freeze and hashing behaviour Part C depends on
CHK-GL-003 NDA & Access Grant Checklist Operational verification of Parts B and C

Change History

Version Date Author Summary
1.0.0 31 July 2026 Legal Initial issue. 531-word operative text against a 600-word ceiling; mutual, two-year term with two-year per-disclosure survival and unlimited trade-secret survival; express personal-data prohibition; automatic supersession by NDA-GL-001, NDA-GL-003 or MSA-IN-001. Twelve binding acceptance-UX requirements derived from the Indian position on clickwrap formation and unconscionability. Thirty-four-field append-only evidentiary record specified, including the full SHA-256 digest and explicit algorithm string required by the certificate under s.63(4), Bharatiya Sakshya Adhiniyam, 2023. Records the correction that Trimex is a Supreme Court e-mail-formation case, not a High Court clickwrap case, and that BSA 2023 has replaced the Evidence Act sections still cited in most published commentary.

Accept it

  • Acceptance is recorded at once. The 128 documents in the NDA tier are then opened by an administrator, with a target of four business hours. You will get a sign-in link by email when access is granted.
  • A person at Pensieve approves tier access. The acceptance itself is recorded immediately and is the evidentiary record either way; access to the documents is granted by an administrator. Everything a security review actually needs is already public and never waits on this.
  • It binds both parties. The same obligations, for the same two years, over what we show you and over what you tell us about your hospital.
  • Documents you open at this tier carry your email address as a watermark, baked into the render rather than overlaid. It is said here so that it is not a surprise later.
Decline

Declining costs you nothing: 108 documents stay open with no gate at all, including the security whitepaper, the architecture overview, the sub-processor register, the standard MSA, the DPA, the SLA and the exit commitment.

On acceptance we record your name, the address and organisation you entered, the document ID and version, the SHA-256 digest of the exact text above, the server timestamp, your IP address and your browser’s user-agent string, and email you a copy of the same record. That is the whole of it, and it is what either party would produce if this agreement were ever disputed. It is not used for anything else, is never sold and is never enriched from third-party sources.