[https://novasean.com/legal] Legal and trust documents Legal and trust Security incidents and customer notifications How to report a concern and what the applicable notification duties cover.Customer information This page explains its stated scope. Existing agreements and mandatory legal rights continue to apply. On this page • Report a concern safely • Personal-data breaches • Other statutory notifications • Containment, recovery and evidence Report a concern safely Existing customers should use the incident route in their service agreement. You can start a report at [mailto:support@novasean.com?subject=Security%20incident] support@novasean.com; for personal-data concerns use [mailto:privacy@novasean.com] privacy@novasean.com. Identify the service, impact and time, using only the information necessary to start triage. Ask for a secure channel before sharing sensitive evidence. For immediate danger to life, contact emergency services. This page does not establish a continuously staffed incident service or a recovery deadline. The [https://novasean.com/legal/service-levels-and-support] support schedule must identify those arrangements for an agreed service. Personal-data breaches When Novasean acts as a processor, the applicable DPA requires notification to the customer without undue delay after awareness of a personal-data breach. Available facts must be provided promptly and updated as the investigation develops. The controller assesses its own duty to notify a supervisory authority and, for a high risk, affected individuals. The controller’s potential 72-hour authority deadline is distinct from the processor’s duty to inform the customer without undue delay. When Novasean is the controller, it must assess and meet its own GDPR reporting and communication duties. A contractual scope exclusion does not excuse handling an accidental disclosure. Other statutory notifications The Dutch Cyberbeveiligingswet may impose incident and recipient-notification duties where the actual provider and service fall within its scope. That depends on service classification, size and group facts or designation; this website does not claim an exemption or compliance status. If applicable, regulatory early-warning and reporting periods and relevant customer information duties must be met independently of support targets. Hosting providers must also make the notification required by Article 18 DSA where information gives rise to suspicion of an offence involving a threat to life or safety. This is distinct from a routine illegal-content report or a general authority demand. Containment, recovery and evidence The responsible parties must assess the incident, contain harm, protect evidence, coordinate recovery and communicate accurate available information through authorised contacts. Customer content, logs and personal data must not be disclosed more widely than necessary and lawful. The actual service agreement defines operational responsibilities; the law determines duties that cannot be contracted away. Published 4 October 2026 · Version security-incidents-2026-10-04-v1. [https://novasean.com/legal/text/security-incidents-2026-10-04-v1.txt] Save this document as text [https://novasean.com/legal] All legal and trust documents