Legal & Trust Center

Incident Response & Breach Notification

How incidents are detected, contained and notified.

Version
1.0
Effective date
17 August 2026
Last updated
17 August 2026
Document owner
the Groundmaster project, with responsibility assigned to its legal and compliance function
Applicable jurisdiction
Portugal, European Union
Permanent URL
https://www.groundmaster.pt/legal/breach

1.Scope

This policy covers security incidents affecting the confidentiality, integrity or availability of the Platform or of data processed through it, including personal data breaches.

2.Incident lifecycle

PhaseActivities
DetectionMonitoring, alerting, provider notifications, user and researcher reports
TriageVerification, severity classification and assignment of an incident owner
ContainmentRestricting access, revoking credentials or sessions, isolating affected components
AssessmentDetermining scope, affected organisations, data categories and likely consequences
NotificationInforming affected customers and, where applicable, authorities and individuals
RecoveryRestoring service and data integrity, including restoration from backups where needed
ReviewRoot-cause analysis and corrective and preventive actions

3.Notification to customers

Where we become aware of a personal data breach affecting a Customer's data, we will notify that Customer without undue delay, using the administrative contacts on record, so that the Customer can meet its own obligations as controller. Notification is not an admission of fault or liability.

4.Information provided

  • the nature of the incident and, where known, its cause;
  • the categories of data and, in approximate terms, the records or individuals affected;
  • the likely consequences and any risk indicators;
  • the containment, mitigation and recovery measures taken or planned;
  • recommended actions for the Customer, such as credential resets or access reviews;
  • a contact point for follow-up, and confirmation of when further information will be provided.

5.Notification to authorities and individuals

Where we act as controller and a breach is likely to result in a risk to individuals, we will notify the competent supervisory authority within the period required by applicable law and inform affected individuals where required. Where we act as processor, notification to authorities and individuals is the Customer's responsibility and we will provide reasonable assistance.

6.Availability incidents

Significant availability incidents are communicated to affected customers with status updates until service is restored, and are followed by a summary of cause and corrective action for major events. Continuity and recovery arrangements are described in the Business Continuity & Disaster Recovery Statement.

7.Reporting an incident to us

Suspected incidents, compromised credentials or unexpected access should be reported immediately to groundmaster.web@gmail.com or groundmaster.web@gmail.com, with as much detail as possible. Suspected vulnerabilities should follow the Responsible Disclosure Policy.

Change history

VersionDateChange
1.017 August 2026Initial incident response and notification policy.
Contact

Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.

Related documents