Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Privacy | Visitor data

Your data

Two different roles get confused constantly, so this page states them separately. Over a hospital’s data inside the Pensieve platform, the hospital is the Data Fiduciary and Edsol Edtech Pvt. Ltd. is its Data Processor, acting on instruction. Over what this website collects about you as a visitor, Edsol Edtech Pvt. Ltd. is the Data Fiduciary in its own right under the Digital Personal Data Protection Act, 2023, which is why the erasure below is self-serve rather than a request you have to make to somebody.

This site loads no third-party analytics, no advertising pixel, no chat widget, no external font and no script from any origin but this one. That is not a promise you have to take on trust. Open the network tab.

What this site stores about you

All of it, not a summary. Nothing below is sold, enriched from a third-party source, or used to profile you or your organisation, and none of it is used for advertising.

SurfaceWhat it containsWritten whenKept for
Email capturesEmail address, organisation, the tier it was captured for, IP address, timestampWhen you clear the email gate, or when an access request is queued24 months from last contactPOL-GL-053 Section 7.2
Access requestsName, work email, organisation, role, what you asked for, any qualification answers you chose to give, IP address, user agent, the decision and its reasonWhen you submit the request-access form36 months from decision, approved and refused alikePOL-GL-053 Section 7.2
NDA acceptancesName, email, organisation, document ID and version, the SHA-256 digest of the exact text you accepted, timestamp, IP address, user agentWhen you accept the click-through mutual NDA8 years: it is contract evidence, and the term it evidences is two yearsPOL-GL-503 Section 2
Document access eventsDocument ID, action, your email if you have cleared a gate, tier at access, path, IP, user agentEvery time a document is viewed, downloaded, printed or blocked365 days minimum, extended only while an investigation is openPOL-GL-503 Section 2, DIS-GL-034
Update subscriptionsEmail address, the categories you chose, a confirmation tokenWhen you subscribe to bulletins or a sub-processor change feedUntil you unsubscribe, then 3 years of the withdrawal record onlyPOL-GL-053 Section 7.2
Sessions and sign-in codesEmail address, a hash of the session token (never the token itself), IP, user agent, expiryWhen you sign in, or clear a gate on a device365 days for the authentication event; the session itself expires in 12 hours to 30 daysPOL-GL-503 Section 2
Sent messagesRecipient address, subject, the full body, and the delivery stateEvery time this site emails youAs the underlying record: it is the proof of what we told you and whenPOL-GL-503 Section 2
Audit logActor, action, subject, before and after, reason, IP, timestampEvery access decision, gate acceptance, document view and administrative act8 years, append-only. See below: erasure de-identifies this rather than deleting itPOL-GL-503 Section 2.1

Erase it

Enter the address you used on this site. You will receive a verification link. Nothing changes until you follow it, because otherwise this form would be a way to erase somebody else’s record. On verification your identifiers are removed or replaced across every surface listed above, and a confirmation is sent to the same address.

No account, no sign-in and no explanation is required. You do not have to say why, and being asked why would itself be a dark pattern.

What survives erasure, and why

The audit log is append-only by database grant: no UPDATE and no DELETE permission exists on it for any application role. That is not a convention we could quietly relax; it is the property that makes the log worth anything. A log that can be edited proves nothing about who was entitled to read which contract, which is the single question this whole system exists to answer.

So erasure does not delete audit rows. It applies hash-preserving pseudonymisation: every occurrence of your address is replaced with a keyed digest of it, computed once with a key that is destroyed when the sweep completes. The same address always produced the same pseudonym during that sweep, so the sequence of events stays coherent and verifiable, and afterwards nothing, including us, can reverse the pseudonym back to you.

Everything else goes: email captures, access requests, NDA acceptance identity fields, document access events and subscriptions are cleared of your name, address, organisation and IP address. Where the law requires a record to be kept (an executed contract, a tax record, a security incident file), it is kept, and you are told which one and under which provision rather than being given a vague refusal.