INCIDENT RESPONSE POLICY
How ReggaeVerse OS responds when something goes wrong: detection, containment, investigation, notification and learning.
Last updated 29 July 2026 · ReggaeVerse OS
1. WHAT COUNTS AS AN INCIDENT
Any confirmed or suspected event that threatens the confidentiality, integrity or availability of the platform or of personal data — including unauthorised access, account takeover, data exposure, malware, credential leakage, destructive error or extended outage.
2. HOW INCIDENTS REACH US
- Automated error, security and dependency monitoring.
- Reports from members or artists to support@reggaeverseos.com.
- Security reports to abuse@reggaeverseos.com.
- Notifications from our hosting, payment or email providers.
3. SEVERITY
- Critical — personal data exposed, funds at risk, or the platform is unusable.
- High — a security control has failed but exposure is limited or unconfirmed.
- Medium — degraded functionality or a contained issue with no data impact.
- Low — minor defect with no security or privacy consequence.
4. RESPONSE STEPS
- Triage — confirm the report and assign severity, immediately for critical and high.
- Contain — revoke credentials or sessions, disable the affected path, or take the feature offline.
- Eradicate — fix the root cause and ship the change as a reviewed release and, where relevant, a database migration.
- Recover — restore service, verify data integrity and restore from backup if needed.
- Review — write up the timeline, cause and follow-up actions, and track them to completion.
5. NOTIFICATION
Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, we notify affected members directly by email without undue delay, describing what happened, what data was involved, what we have done and what you should do. Where we act as a processor for a business customer, we notify that customer without undue delay so they can meet their own obligations (see the Data Processing Agreement).
6. RECORDS
We keep an internal record of all incidents, including those not requiring notification, with the facts, effects and remedial action taken.
7. PAYMENTS
Card and billing data are held by our Merchant of Record, not by us. Incidents affecting payment data are handled by that provider under their own programme; we cooperate fully and relay notices to affected buyers.
8. CONTACT
Incident and breach queries: privacy@reggaeverseos.com.