← Back to Trust Center

Incident Response & Personal Data Breach Policy

Version: 1.0 | Classification: Public | Effective Date: 01. 08. 2026. | Last Updated: 24. 07. 2026.

1. Purpose

This Incident Response & Personal Data Breach Policy describes how Chronos Web Tech Kft. identifies, manages, investigates, documents, and responds to information security incidents and personal data breaches affecting the Appointio.eu platform.

The objective of this Policy is to minimize the impact of incidents while ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Scope

This Policy applies to:

  • employees; contractors; administrators;
  • third-party service providers acting on behalf of the Company;
  • all systems supporting the Appointio platform.

3. Definitions

Security Incident: Any event that may compromise the confidentiality, integrity, or availability of information or systems. Examples include unauthorized access attempts, malware infections, service outages, accidental disclosure of information, and compromised user accounts.

Personal Data Breach: A breach of security leading to accidental destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data.

4. Incident Categories

Low Severity: isolated failed login attempts; non-sensitive configuration issues; temporary service degradation.

Medium Severity: unauthorized account access; phishing affecting internal users; accidental disclosure to an unintended recipient.

High Severity: ransomware; database compromise; credential theft; large-scale service disruption; confirmed personal data breach affecting multiple users.

5. Incident Response Process

1. Identification: Potential incidents are detected through monitoring, log analysis, customer reports, employee reports, third-party notifications.

2. Assessment: The Company evaluates affected systems, users, data, business impact, and legal implications.

3. Containment: Actions may include disabling accounts, blocking malicious traffic, revoking API tokens, isolating affected systems.

4. Investigation: The Company investigates root cause, attack vector, affected information, timeline, and effectiveness of existing controls.

5. Recovery: Activities may include restoring backups, deploying security patches, rotating credentials, validating system integrity, and monitoring for recurring activity.

6. Lessons Learned: After each significant incident, the Company reviews contributing factors, effectiveness of the response, and opportunities for improvement. Internal procedures may be updated accordingly.

6-8. Notifications & Documentation

Where required under Article 33 GDPR, the Company shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a reportable personal data breach. Where required under Article 34 GDPR, affected individuals shall also be informed where the breach is likely to result in a high risk to their rights and freedoms.

Where customer data is affected, the Company will provide information including the nature of the incident, categories of affected data, likely consequences, mitigation measures, recommended customer actions, and contact information.

The Company maintains internal records of significant security incidents including incident identifier, discovery date, incident category, affected systems and data, actions taken, resolution date, and lessons learned.

9-13. Logging, Cooperation & Contact

To support investigations, the Company may maintain authentication logs, application logs, security logs, audit logs, and infrastructure logs. Logs are protected against unauthorized modification where technically feasible. Access to logs is restricted to authorized personnel.

Where an incident involves a subprocessor, the Company shall cooperate with the subprocessor to assess the incident, mitigate risks, fulfil legal obligations, and notify affected parties where required.

Incident response procedures are periodically reviewed and updated to reflect new threats, legal developments, technological changes, and operational experience.

Customers, researchers, and third parties may report suspected vulnerabilities or security incidents to [email protected]. The Company encourages responsible disclosure and will investigate reports in good faith.

Questions regarding this Policy may be directed to: Chronos Web Tech Kft.

Email: [email protected] | Website: www.chronosweb.hu