Legal

Incident & Personal Data Breach Policy

This Policy sets out how Infotech Solutions detects, manages and reports security incidents and personal data breaches affecting Tamanor, in accordance with Articles 33 and 34 GDPR.

Last updated: 17 July 2026

This is early-product wording provided for transparency. It is not legal advice and will be finalized before general availability.

1. Scope and definitions

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. A security incident is any event that may compromise the confidentiality, integrity or availability of the Service or data.

2. Detection and reporting internally

Incidents may be identified through monitoring, alerts, audit logs, staff or user reports, or third-party notifications. Anyone can report a suspected incident to info@tamanor.com without delay. All reports are logged and triaged promptly.

3. Response lifecycle

  • Identify & record — capture what is known, time, and reporter.
  • Contain — stop ongoing harm (e.g. revoke tokens, isolate systems, activate kill switches for live actions).
  • Assess — determine whether personal data is involved, the categories and approximate number of data subjects and records, and the likely consequences.
  • Eradicate & recover — remove the cause and restore normal, secure operation.
  • Notify — as required (Sections 4–5).
  • Review — conduct a post-incident review and implement improvements.

4. Notifying the supervisory authority (Art. 33)

Where we are the controller and a breach is likely to result in a risk to individuals' rights and freedoms, we notify the Office for Personal Data Protection of the Slovak Republic without undue delay and, where feasible, within 72 hours of becoming aware. If notification is delayed beyond 72 hours, we include the reasons. The notification describes the nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken or proposed. Where information is not all available at once, we provide it in phases.

5. Notifying affected individuals (Art. 34)

Where a breach is likely to result in a high risk to individuals, we inform them without undue delay, in clear language, describing the nature of the breach, our contact point, likely consequences, and measures taken. We may use public communication where individual notice would involve disproportionate effort.

6. When we act as a processor

Where the breach affects personal data we process on a Customer's behalf, we notify the Customer (controller) without undue delay after becoming aware, and assist them with their Art. 33/34 obligations (see the DPA). We do not notify the authority or data subjects on the Customer's behalf unless separately instructed.

7. Record-keeping

We document all personal data breaches — facts, effects and remedial action — regardless of whether they were notifiable, so that the supervisory authority can verify compliance (Art. 33(5)).

8. Prevention and improvement

Findings feed into our Security Policy, access controls, monitoring and staff awareness. Preventive controls include encryption, tenant isolation, least privilege, audit logging and fail-safe defaults.

9. Contact

Report incidents to info@tamanor.com · +421 901 724 290.

Incident & Personal Data Breach Policy — Tamanor