Back to Home

Breach Notification Policy

Version 1.0 — Effective: May 13, 2026

BuildFlow Pro — Security Incident Response & Notification Procedures

This policy governs how BuildFlow Pro detects, responds to, and communicates data security breaches. We are committed to transparency and rapid response in the event of any security incident affecting your data.

1. Purpose

This policy establishes BuildFlow Pro's procedures for detecting, assessing, containing, and notifying affected parties in the event of a personal data breach or security incident. This policy is designed to comply with GDPR Article 33/34, CCPA requirements, and other applicable data protection regulations.

2. Definitions

  • "Security Incident" — Any event that threatens the confidentiality, integrity, or availability of BuildFlow Pro systems or user data
  • "Data Breach" — A security incident that results in the unauthorized access to, disclosure of, alteration of, or destruction of personal data
  • "Affected Parties" — Individuals and organizations whose personal data may have been compromised
  • "Incident Response Team" — The designated BuildFlow Pro personnel responsible for managing security incidents

3. Incident Response Phases

Phase 1: Detection & Reporting

  • Automated monitoring systems continuously scan for anomalies, unauthorized access, and suspicious activity
  • Any employee, contractor, or user who suspects a breach must report it immediately to security@buildflow-pro.com
  • Automated alerts are triggered by: unusual data access patterns, failed authentication attempts, unauthorized API calls, system integrity violations

Phase 2: Assessment & Classification

  • The Incident Response Team assesses the scope, severity, and potential impact within 4 hours of detection
  • Incidents are classified as: Critical (active data exfiltration, ransomware), High (unauthorized access to personal data), Medium (vulnerability discovered, no confirmed access), Low (policy violation, no data impact)
  • A determination is made whether the incident constitutes a reportable data breach under applicable law

Phase 3: Containment & Remediation

  • Immediate containment measures are taken: revoking compromised credentials, isolating affected systems, blocking malicious IPs
  • Evidence is preserved for forensic analysis and potential legal proceedings
  • Root cause analysis is conducted to identify the vulnerability or attack vector
  • Remediation measures are implemented to prevent recurrence

Phase 4: Notification

  • Affected customers are notified without undue delay and within 72 hours of confirmed breach
  • Regulatory authorities are notified as required by applicable law (e.g., GDPR supervisory authority within 72 hours)
  • If the breach is likely to result in a high risk to individuals, affected data subjects are directly notified
  • Notification includes: nature of the breach, data involved, likely consequences, mitigation measures taken, contact information for follow-up

Phase 5: Documentation & Review

  • A detailed incident report is created documenting the timeline, root cause, impact, response actions, and lessons learned
  • Security controls and procedures are updated based on findings
  • A post-incident review is conducted within 14 days to evaluate the effectiveness of the response
  • All documentation is retained for a minimum of 5 years

4. Notification Timeline

AudienceTimelineMethod
Affected CustomersWithin 72 hoursEmail + in-app notification
Regulatory AuthoritiesWithin 72 hours (GDPR)Written notice
Data Subjects (High Risk)Without undue delayDirect email notification
General Public (if required)As required by lawWebsite notice + press release

5. Notification Content

All breach notifications will include:

  • A description of the nature of the breach
  • The categories and approximate number of data subjects and records affected
  • The name and contact details of BuildFlow Pro's data protection contact
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach, including mitigation
  • Recommended steps affected individuals should take to protect themselves

6. User Responsibilities

BuildFlow Pro users also play a role in security:

  • Report suspected security incidents immediately to security@buildflow-pro.com
  • Use strong, unique passwords and enable two-factor authentication when available
  • Do not share account credentials
  • Keep devices and browsers up to date
  • Review account activity logs periodically for unusual behavior

7. Two-Factor Authentication (2FA)

BuildFlow Pro supports and encourages the use of two-factor authentication to add an extra layer of security. When 2FA is enabled:

  • A second verification step is required at login (email verification code)
  • This significantly reduces the risk of unauthorized account access even if passwords are compromised
  • Enterprise accounts may enforce mandatory 2FA for all users in their organization

8. Policy Updates

This policy is reviewed and updated at least annually, or immediately following a significant security incident. Changes will be reflected in the version number and effective date. Users will be notified of material changes via email or in-app notification.

9. Contact

To report a security incident or vulnerability, or for questions about this policy:

10. Related Documents