मुख्य कंटेंट तक स्किप करें

Personal-data breach response

DRAFT — requires legal review

This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.

The detailed operational procedure is maintained internally (breach-notification runbook). This page summarises the commitments.

Timeline​

Clock (from awareness)ActionOwner
0 hIncident declared, severity assigned, breach lead appointed; evidence preservedOn-call engineer → Incident commander
≤ 6 hReport to CERT-In if the incident is a reportable cyber-security incidentSecurity lead
≤ 24 hNotify affected healthcare providers (the Data Fiduciaries) with known factsBreach lead / customer success
Without delayIntimation to the Data Protection Board (by the fiduciary; we support providers as processor, and file for our own customer data)Fiduciary
≤ 72 hDetailed report to the Board: nature, extent, timing, likely impact, measures taken, notifications madeFiduciary with our assistance
Without delayNotify affected data principals in plain language: what happened, likely consequences, mitigation, what they can do, contactFiduciary
≤ 5 business days after closurePost-incident review with corrective actionsIncident commander

What counts as a breach​

Any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability — including cross-tenant data exposure, lost devices with cached data, mis-sent WhatsApp messages and leaked credentials.