Trust Center · Policies
Incident Response Policy
Last updated: 2026-09-03 · Owner: Founder / CTO · Design Excellent Group SL
How security incidents and personal-data breaches are detected, handled and communicated.
Purpose
Detect incidents quickly, contain them, restore service and meet our notification obligations.
Definitions
- Security incident — any event that compromises, or could compromise, the confidentiality, integrity or availability of Eduspera systems or customer data.
- Personal-data breach — a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data (GDPR Art. 4(12)).
Detection
- Uptime and error monitoring on the application, database and video delivery (see the public status page).
- Immutable audit log of sensitive actions with an admin viewer and export.
- Rate-limit and abuse signals from Cloudflare and the application.
- Reports from customers, learners or researchers to [email protected] (responsible disclosure: we do not pursue good-faith research).
Response steps
- Triage (within 4 business hours of detection) — confirm, classify severity, appoint an incident lead (founder by default).
- Contain — revoke credentials, rotate secrets in the vault, block traffic at the edge, disable the affected feature or take the service offline if necessary.
- Eradicate & recover — fix the root cause through the change-management pipeline, restore data from Supabase backups where needed, verify.
- Notify — see below.
- Review — a written post-incident review within 10 business days: timeline, root cause, impact, corrective actions with owners and dates.
Notification
- Customers (data controllers) — without undue delay after we become aware of a personal-data breach affecting their learners, with the information needed for their own Art. 33/34 assessment.
- Supervisory authority — where Eduspera acts as controller, within 72 hours of awareness to the Agencia Española de Protección de Datos where required by GDPR Art. 33.
- Affected individuals — when the breach is likely to result in a high risk to their rights and freedoms (Art. 34).
Records
Every incident, whether or not notifiable, is recorded with its classification, timeline and outcome, and retained for at least five years.