Data Breach Policy

How we handle and notify users about data breaches

GDPR Compliant
Last Updated: January 2025

At EarnLayer, we take data security seriously. This policy explains how we handle data breaches, what constitutes a breach, and how we will notify you if your personal data is affected.

This policy is designed to comply with the General Data Protection Regulation (GDPR) Article 33 and 34, which require us to notify supervisory authorities and affected individuals about certain data breaches.

What is a Data Breach?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data.

Examples of data breaches include:

  • Unauthorized access to our systems resulting in personal data being accessed
  • Accidental loss or deletion of personal data
  • Personal data being sent to the wrong recipient
  • Personal data being altered without authorization
  • Ransomware or malware attacks affecting personal data
  • Physical theft of devices containing personal data

Note: Not all security incidents are data breaches. For example, a failed login attempt that doesn't result in access to personal data is not a breach.

Our Response Process

1. Immediate Response

When we become aware of a potential data breach, we immediately:

  • Contain the breach to prevent further unauthorized access
  • Assess the scope and impact of the breach
  • Identify what personal data may have been affected
  • Begin remediation measures

2. Assessment

We assess each incident to determine:

  • Whether it constitutes a personal data breach under GDPR
  • The nature and scope of the breach
  • The categories and approximate number of individuals affected
  • The likely consequences and risks to individuals
  • Whether notification is required

3. Remediation

We take immediate steps to address the breach, including:

  • Securing affected systems
  • Changing compromised credentials
  • Implementing additional security measures
  • Working with security experts to prevent future incidents
Notification to Supervisory Authority (Article 33)

Under GDPR, we are required to notify the relevant supervisory authority (data protection authority) of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Our notification to the supervisory authority includes:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate number of personal data records concerned
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

Timeline: We notify the supervisory authority within 72 hours of becoming aware of the breach, or as soon as possible if we cannot provide all information immediately.

Notification to Affected Individuals (Article 34)

We will notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.

When we notify you:

  • The breach is likely to result in a high risk to your rights and freedoms
  • Your personal data has been compromised in a way that could cause harm
  • Immediate action is needed to protect your interests

What the notification will include:

  • Description of the nature of the breach
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Recommendations for steps you can take to mitigate potential adverse effects
  • Contact information for our data protection team

Note: We may not notify individuals if the breach is unlikely to result in a high risk, if we have implemented appropriate technical and organizational measures (such as encryption) that render the data unintelligible, or if notification would involve disproportionate effort.

How We Notify You

If we need to notify you about a data breach, we will contact you using the primary email address associated with your EarnLayer account.

In cases of high-risk breaches, we may also:

  • Post a notice on our website
  • Send notifications through our application
  • Use other communication channels if email is not available

Important: We will never ask you to provide passwords, credit card information, or other sensitive data in a breach notification email. Be cautious of phishing attempts and always verify communications by contacting us directly.

What You Can Do

If you receive a breach notification from us, we recommend:

  • Review the notification carefully - Understand what data may have been affected and what risks you may face
  • Change your password - If your account credentials may have been compromised, change your password immediately
  • Monitor your accounts - Keep an eye on your EarnLayer account and any other accounts that use the same email or password
  • Enable two-factor authentication - If not already enabled, add an extra layer of security to your account
  • Review your account activity - Check for any unauthorized access or changes
  • Report suspicious activity - If you notice anything unusual, contact us immediately
Reporting Suspected Breaches

If you suspect a data breach or notice any suspicious activity related to your EarnLayer account, please contact us immediately:

Contact:

Email: support@earnlayerai.com

Please include as much detail as possible about the suspected breach, including:

  • What you observed or discovered
  • When it occurred
  • Any relevant account information
  • Screenshots or other evidence if available
Our Prevention Measures

We implement comprehensive security measures to prevent data breaches, including:

  • Encryption - All data in transit and at rest is encrypted using industry-standard protocols
  • Access Controls - Strict access controls and authentication requirements
  • Regular Security Audits - We conduct regular security assessments and penetration testing
  • Employee Training - All staff receive regular security and data protection training
  • Incident Response Plan - We maintain a documented incident response procedure
  • Monitoring and Detection - Continuous monitoring for suspicious activity
  • Backup and Recovery - Regular backups and tested recovery procedures
Updates to This Policy

We may update this Data Breach Policy from time to time to reflect changes in our practices, legal requirements, or security measures. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date.

Questions or Concerns?

If you have questions about this policy or our data breach procedures, please contact us: