If something goes wrong with your data
If a personal-data breach occurs — unauthorised access to personal data, or data being lost, altered, or disclosed — we follow a defined response process and notify those who need to know. This page is the public summary; the detailed internal procedure follows GDPR Articles 33–34 and EDPB guidance.
No organisation can prevent every security incident. This page describes how we respond when one occurs.
What we do
- Detect and contain — we work to identify the incident and contain it.
- Assess the risk — we determine which data and which people are affected, and how serious it is.
- Notify the regulator — where the breach is likely to be a risk, we notify the lead data-protection authority (Datatilsynet in Norway) within 72 hours of becoming aware, as required by GDPR Art. 33.
- Notify you — where a breach is likely to cause a high risk to your rights, we tell you directly and without undue delay (GDPR Art. 34).
- Learn — we review what happened and improve.
Notification content
If we need to notify you, we will write to you in clear, plain language and include (per Art. 34(2)):
- What happened and roughly when.
- What information was involved.
- The likely consequences.
- What we’ve done and are doing about it.
- What you can do to protect yourself, and how to contact us about it.
Transparency reporting
Separately from breaches, we will publish periodic transparency reports about our content-moderation activity and the government/law-enforcement requests we receive — reflecting Digital Services Act Articles 15 and 24. See our Government & Law Enforcement Request Policy.
More
Annex A — What a breach notice looks like
If we ever need to notify you of a personal-data breach under GDPR Art. 34, our message will follow a template like the one below; the specific details are completed at the time of the incident.
Subject: An important security notice about your Apperah account
Hi [name],
We’re writing to let you know about a security incident that may have involved some of your Apperah information.
- What happened: On/around [date], [short factual description].
- What information was involved: [categories of data — e.g., name, email, profile details]. [State clearly what was not involved, e.g., “Your password was encrypted and is not believed to be affected.”]
- What we’ve done: [containment + remediation steps].
- What you can do: [specific advice — e.g., reset your password here; be alert to phishing emails].
- More help: Contact us at privacy@apperah.com (or our data-protection contact at dpo@apperah.com).
We’re sorry this happened. — The Apperah team