INCIDENT RESPONSE POLICY

How ReggaeVerse OS responds when something goes wrong: detection, containment, investigation, notification and learning.

Last updated 29 July 2026 · ReggaeVerse OS

1. WHAT COUNTS AS AN INCIDENT

Any confirmed or suspected event that threatens the confidentiality, integrity or availability of the platform or of personal data — including unauthorised access, account takeover, data exposure, malware, credential leakage, destructive error or extended outage.

2. HOW INCIDENTS REACH US

3. SEVERITY

  • Critical — personal data exposed, funds at risk, or the platform is unusable.
  • High — a security control has failed but exposure is limited or unconfirmed.
  • Medium — degraded functionality or a contained issue with no data impact.
  • Low — minor defect with no security or privacy consequence.

4. RESPONSE STEPS

  1. Triage — confirm the report and assign severity, immediately for critical and high.
  2. Contain — revoke credentials or sessions, disable the affected path, or take the feature offline.
  3. Eradicate — fix the root cause and ship the change as a reviewed release and, where relevant, a database migration.
  4. Recover — restore service, verify data integrity and restore from backup if needed.
  5. Review — write up the timeline, cause and follow-up actions, and track them to completion.

5. NOTIFICATION

Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, we notify affected members directly by email without undue delay, describing what happened, what data was involved, what we have done and what you should do. Where we act as a processor for a business customer, we notify that customer without undue delay so they can meet their own obligations (see the Data Processing Agreement).

6. RECORDS

We keep an internal record of all incidents, including those not requiring notification, with the facts, effects and remedial action taken.

7. PAYMENTS

Card and billing data are held by our Merchant of Record, not by us. Incidents affecting payment data are handled by that provider under their own programme; we cooperate fully and relay notices to affected buyers.

8. CONTACT

Incident and breach queries: privacy@reggaeverseos.com.