Skip to content

Security & Incident Response

How Apperah prepares for, handles, and discloses security incidents.

Effective:
2026-06-29
Last updated:
2026-06-07
Version:
v1.0

If something goes wrong with your data

If a personal-data breach occurs — unauthorised access to personal data, or data being lost, altered, or disclosed — we follow a defined response process and notify those who need to know. This page is the public summary; the detailed internal procedure follows GDPR Articles 33–34 and EDPB guidance.

No organisation can prevent every security incident. This page describes how we respond when one occurs.

What we do

  1. Detect and contain — we work to identify the incident and contain it.
  2. Assess the risk — we determine which data and which people are affected, and how serious it is.
  3. Notify the regulator — where the breach is likely to be a risk, we notify the lead data-protection authority (Datatilsynet in Norway) within 72 hours of becoming aware, as required by GDPR Art. 33.
  4. Notify you — where a breach is likely to cause a high risk to your rights, we tell you directly and without undue delay (GDPR Art. 34).
  5. Learn — we review what happened and improve.

Notification content

If we need to notify you, we will write to you in clear, plain language and include (per Art. 34(2)):

  • What happened and roughly when.
  • What information was involved.
  • The likely consequences.
  • What we’ve done and are doing about it.
  • What you can do to protect yourself, and how to contact us about it.

Transparency reporting

Separately from breaches, we will publish periodic transparency reports about our content-moderation activity and the government/law-enforcement requests we receive — reflecting Digital Services Act Articles 15 and 24. See our Government & Law Enforcement Request Policy.

More


Annex A — What a breach notice looks like

If we ever need to notify you of a personal-data breach under GDPR Art. 34, our message will follow a template like the one below; the specific details are completed at the time of the incident.

Subject: An important security notice about your Apperah account

Hi [name],

We’re writing to let you know about a security incident that may have involved some of your Apperah information.

  • What happened: On/around [date], [short factual description].
  • What information was involved: [categories of data — e.g., name, email, profile details]. [State clearly what was not involved, e.g., “Your password was encrypted and is not believed to be affected.”]
  • What we’ve done: [containment + remediation steps].
  • What you can do: [specific advice — e.g., reset your password here; be alert to phishing emails].
  • More help: Contact us at privacy@apperah.com (or our data-protection contact at dpo@apperah.com).

We’re sorry this happened. — The Apperah team