Elevale maintains an incident response process to contain threats, protect users, and meet regulatory notification obligations. This page describes our commitments and your role.
Our commitment
If a personal data breach occurs, we will:
- Contain and assess the incident promptly
- Notify the relevant supervisory authority within 72 hours where required (UK GDPR / EU GDPR Article 33)
- Notify affected users without undue delay when the breach poses high risk to individuals (Article 34)
- Notify business customers (controllers) without undue delay when their workspace data is affected
- Document the breach, remediation steps, and lessons learned
Security incidents
Not all security incidents involve personal data breaches. We classify incidents by severity and respond according to runbooks. Users may experience temporary service disruption during containment.
If you suspect an issue
Contact contact form immediately with "Security incident" in the subject line. Include affected workspace, timeframe, and symptoms. Workspace admins should also notify their agency or data protection contact if applicable.
Your responsibilities
- Protect credentials and enable MFA for all admin accounts
- Review audit logs regularly for unusual activity
- Report phishing or suspicious access promptly
- Do not share admin credentials or API keys in unsecured channels
- Maintain accurate contact details for incident notifications
Regulatory contacts
In the UK, personal data breaches may be reported to the Information Commissioner's Office (ico.org.uk). EU customers should contact their local supervisory authority. We cooperate with regulators as required.