Seen CRM
Incident Response Policy
| Document number | SEEN-POL-04 |
|---|---|
| Version | 1.0 |
| Effective date | On approval |
| Policy owner | Seen CRM Management |
| Approved by | Seen CRM Management |
| Classification | Public |
| Next review | Within 12 months of the effective date |
1. Purpose
This policy sets out how Seen CRM detects, contains and recovers from security incidents, and how it informs those affected.
2. Scope
This policy applies to any event that threatens the confidentiality, integrity or availability of the platform or of customer data.
3. Policy
- Reporting. Anyone may report a suspected incident or vulnerability to info@seencrm.com.
- Classification. Every reported event is assessed and assigned a severity. Where there is doubt, the higher severity applies.
- Containment. Incidents are contained as quickly as possible. Evidence is preserved before any repair.
- Customer notification. Customers affected by an incident involving their data are notified without undue delay, with the information they need, including to meet their own legal obligations.
- Regulatory notification. Seen CRM notifies the competent authorities where required by the Personal Data Protection Law and other applicable laws.
- Learning. Every significant incident is followed by a written review of its root cause and the corrective actions taken.
4. Responsibilities
Management decides on severity for major incidents and on all external notifications. The engineering team carries out containment and recovery.
5. Exceptions
No exception may delay a notification required by law.
6. Review
This policy is reviewed at least once a year, and after any major security incident.
7. Contact
Questions about this policy: info@seencrm.com