Privacy & Data Protection
Data Breach Notification
How we respond to a suspected data breach, including our commitment to notify affected customers within 72 hours.
Last reviewed: July 2026
Risely is committed to safeguarding the data that we collect for the delivery of our services. This page outlines how we notify affected customers, regulatory authorities, and other relevant parties in the event of a data breach, so that prompt and appropriate action is taken to mitigate its impact.
If sensitive data is acquired, accessed, used, or disclosed in a manner not permitted under privacy law, or in a manner that compromises the security or privacy of that sensitive personal data, it may be considered a breach. We maintain procedures to ensure a quick, effective, consistent, and orderly response to security incidents that lead to a data breach.
Reporting a suspected breach
Any Risely team member who discovers a potential breach of sensitive data reports it to our security function immediately.
Investigating a suspected breach
We review the circumstances of a suspected breach to determine whether the incident was intentional or unintentional. Certain unintentional incidents do not constitute reportable breaches:
- If sensitive data was acquired, accessed, or used by a Risely team member in good faith and within the scope of their permitted activities, and there is no further unpermitted use or disclosure, this does not constitute a breach.
- If sensitive data was inadvertently disclosed by one Risely team member to another, and there is no further unpermitted use or disclosure, this does not constitute a breach.
We also review whether the incident poses a risk to the rights and freedoms of affected individuals, or a risk of financial, reputational, or other harm to the customer. This risk assessment is documented. If it concludes that such a risk exists, notification is made as described below.
Notifying affected customers and authorities
Where the affected personal data is processed on behalf of a customer organization, with Risely acting as a data processor, we notify the affected customer without undue delay after becoming aware of the breach, and in any event within 72 hours. As set out in our Data Processing Agreement, the customer, as the controller, is then responsible for notifying the competent supervisory authority and affected individuals, and we provide reasonable cooperation for that purpose.
Where Risely is itself the controller of the affected data, we will, without undue delay and where feasible not later than 72 hours after becoming aware of it, notify the competent authority in accordance with the laws governing the contract, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where notification to the supervisory authority is not made within 72 hours, it is accompanied by reasons for the delay.
Mitigation
We mitigate, to the extent practicable, any harmful effect known to us of a use or disclosure of sensitive data in violation of this policy or our contractual commitments.
Questions
If you have any questions about this policy, contact us at [email protected].
Questions about this policy? [email protected]
