Legal
Incident & Personal Data Breach Policy
This Policy sets out how Infotech Solutions detects, manages and reports security incidents and personal data breaches affecting Tamanor, in accordance with Articles 33 and 34 GDPR.
Last updated: 17 July 2026
1. Scope and definitions
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. A security incident is any event that may compromise the confidentiality, integrity or availability of the Service or data.
2. Detection and reporting internally
Incidents may be identified through monitoring, alerts, audit logs, staff or user reports, or third-party notifications. Anyone can report a suspected incident to info@tamanor.com without delay. All reports are logged and triaged promptly.
3. Response lifecycle
- Identify & record — capture what is known, time, and reporter.
- Contain — stop ongoing harm (e.g. revoke tokens, isolate systems, activate kill switches for live actions).
- Assess — determine whether personal data is involved, the categories and approximate number of data subjects and records, and the likely consequences.
- Eradicate & recover — remove the cause and restore normal, secure operation.
- Notify — as required (Sections 4–5).
- Review — conduct a post-incident review and implement improvements.
4. Notifying the supervisory authority (Art. 33)
Where we are the controller and a breach is likely to result in a risk to individuals' rights and freedoms, we notify the Office for Personal Data Protection of the Slovak Republic without undue delay and, where feasible, within 72 hours of becoming aware. If notification is delayed beyond 72 hours, we include the reasons. The notification describes the nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken or proposed. Where information is not all available at once, we provide it in phases.
5. Notifying affected individuals (Art. 34)
Where a breach is likely to result in a high risk to individuals, we inform them without undue delay, in clear language, describing the nature of the breach, our contact point, likely consequences, and measures taken. We may use public communication where individual notice would involve disproportionate effort.
6. When we act as a processor
Where the breach affects personal data we process on a Customer's behalf, we notify the Customer (controller) without undue delay after becoming aware, and assist them with their Art. 33/34 obligations (see the DPA). We do not notify the authority or data subjects on the Customer's behalf unless separately instructed.
7. Record-keeping
We document all personal data breaches — facts, effects and remedial action — regardless of whether they were notifiable, so that the supervisory authority can verify compliance (Art. 33(5)).
8. Prevention and improvement
Findings feed into our Security Policy, access controls, monitoring and staff awareness. Preventive controls include encryption, tenant isolation, least privilege, audit logging and fail-safe defaults.
9. Contact
Report incidents to info@tamanor.com · +421 901 724 290.