Privacy | Visitor data
Your data
Two different roles get confused constantly, so this page states them separately. Over a hospital’s data inside the Pensieve platform, the hospital is the Data Fiduciary and Edsol Edtech Pvt. Ltd. is its Data Processor, acting on instruction. Over what this website collects about you as a visitor, Edsol Edtech Pvt. Ltd. is the Data Fiduciary in its own right under the Digital Personal Data Protection Act, 2023, which is why the erasure below is self-serve rather than a request you have to make to somebody.
This site loads no third-party analytics, no advertising pixel, no chat widget, no external font and no script from any origin but this one. That is not a promise you have to take on trust. Open the network tab.
What this site stores about you
All of it, not a summary. Nothing below is sold, enriched from a third-party source, or used to profile you or your organisation, and none of it is used for advertising.
| Surface | What it contains | Written when | Kept for |
|---|---|---|---|
| Email captures | Email address, organisation, the tier it was captured for, IP address, timestamp | When you clear the email gate, or when an access request is queued | 24 months from last contactPOL-GL-053 Section 7.2 |
| Access requests | Name, work email, organisation, role, what you asked for, any qualification answers you chose to give, IP address, user agent, the decision and its reason | When you submit the request-access form | 36 months from decision, approved and refused alikePOL-GL-053 Section 7.2 |
| NDA acceptances | Name, email, organisation, document ID and version, the SHA-256 digest of the exact text you accepted, timestamp, IP address, user agent | When you accept the click-through mutual NDA | 8 years: it is contract evidence, and the term it evidences is two yearsPOL-GL-503 Section 2 |
| Document access events | Document ID, action, your email if you have cleared a gate, tier at access, path, IP, user agent | Every time a document is viewed, downloaded, printed or blocked | 365 days minimum, extended only while an investigation is openPOL-GL-503 Section 2, DIS-GL-034 |
| Update subscriptions | Email address, the categories you chose, a confirmation token | When you subscribe to bulletins or a sub-processor change feed | Until you unsubscribe, then 3 years of the withdrawal record onlyPOL-GL-053 Section 7.2 |
| Sessions and sign-in codes | Email address, a hash of the session token (never the token itself), IP, user agent, expiry | When you sign in, or clear a gate on a device | 365 days for the authentication event; the session itself expires in 12 hours to 30 daysPOL-GL-503 Section 2 |
| Sent messages | Recipient address, subject, the full body, and the delivery state | Every time this site emails you | As the underlying record: it is the proof of what we told you and whenPOL-GL-503 Section 2 |
| Audit log | Actor, action, subject, before and after, reason, IP, timestamp | Every access decision, gate acceptance, document view and administrative act | 8 years, append-only. See below: erasure de-identifies this rather than deleting itPOL-GL-503 Section 2.1 |
Erase it
Enter the address you used on this site. You will receive a verification link. Nothing changes until you follow it, because otherwise this form would be a way to erase somebody else’s record. On verification your identifiers are removed or replaced across every surface listed above, and a confirmation is sent to the same address.
What survives erasure, and why
The audit log is append-only by database grant: no UPDATE and no DELETE permission exists on it for any application role. That is not a convention we could quietly relax; it is the property that makes the log worth anything. A log that can be edited proves nothing about who was entitled to read which contract, which is the single question this whole system exists to answer.
So erasure does not delete audit rows. It applies hash-preserving pseudonymisation: every occurrence of your address is replaced with a keyed digest of it, computed once with a key that is destroyed when the sweep completes. The same address always produced the same pseudonym during that sweep, so the sequence of events stays coherent and verifiable, and afterwards nothing, including us, can reverse the pseudonym back to you.
Everything else goes: email captures, access requests, NDA acceptance identity fields, document access events and subscriptions are cleared of your name, address, organisation and IP address. Where the law requires a record to be kept (an executed contract, a tax record, a security incident file), it is kept, and you are told which one and under which provision rather than being given a vague refusal.