How we handle and notify users about data breaches
At EarnLayer, we take data security seriously. This policy explains how we handle data breaches, what constitutes a breach, and how we will notify you if your personal data is affected.
This policy is designed to comply with the General Data Protection Regulation (GDPR) Article 33 and 34, which require us to notify supervisory authorities and affected individuals about certain data breaches.
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data.
Examples of data breaches include:
Note: Not all security incidents are data breaches. For example, a failed login attempt that doesn't result in access to personal data is not a breach.
1. Immediate Response
When we become aware of a potential data breach, we immediately:
2. Assessment
We assess each incident to determine:
3. Remediation
We take immediate steps to address the breach, including:
Under GDPR, we are required to notify the relevant supervisory authority (data protection authority) of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
Our notification to the supervisory authority includes:
Timeline: We notify the supervisory authority within 72 hours of becoming aware of the breach, or as soon as possible if we cannot provide all information immediately.
We will notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
When we notify you:
What the notification will include:
Note: We may not notify individuals if the breach is unlikely to result in a high risk, if we have implemented appropriate technical and organizational measures (such as encryption) that render the data unintelligible, or if notification would involve disproportionate effort.
If we need to notify you about a data breach, we will contact you using the primary email address associated with your EarnLayer account.
In cases of high-risk breaches, we may also:
Important: We will never ask you to provide passwords, credit card information, or other sensitive data in a breach notification email. Be cautious of phishing attempts and always verify communications by contacting us directly.
If you receive a breach notification from us, we recommend:
If you suspect a data breach or notice any suspicious activity related to your EarnLayer account, please contact us immediately:
Contact:
Email: support@earnlayerai.com
Please include as much detail as possible about the suspected breach, including:
We implement comprehensive security measures to prevent data breaches, including:
We may update this Data Breach Policy from time to time to reflect changes in our practices, legal requirements, or security measures. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date.
If you have questions about this policy or our data breach procedures, please contact us:
Email: support@earnlayerai.com