Incident Response Summary
Last updated: 26 August 2026
This page explains what happens if Projexa experiences a security incident or personal data breach affecting your data — what we commit to doing, and how quickly.
What we treat as an incident
Any event that could put your data at risk: unauthorized access to our systems, a leaked credential, a vulnerability that could expose one Customer's data to another, accidental data loss, or a compromised account with access to your data.
What we commit to
- Containment first. We act immediately to stop ongoing exposure — revoking access, disabling affected accounts, or deploying a fix — before anything else.
- Assessment. We determine what data was affected and which Customers, using our own audit logs and those of our infrastructure providers.
- Notification to you, without undue delay, consistent with our Data Processing Addendum's breach clause. We'll tell you what happened, what data was affected, what we've done about it, and anything you may need to do.
- Notification to the UK Information Commissioner's Office (ICO) within 72 hours of becoming aware, wherever the breach is likely to pose a risk to individuals' rights and freedoms, as required under UK GDPR.
- A written post-incident summary on request, once our internal review is complete — covering what happened, the root cause, and what changed to prevent recurrence.
What we ask of you
If you believe you've discovered a security vulnerability, or suspect a breach affecting Projexa, please tell us immediately at legal@getprojexa.com rather than a general support channel, and avoid testing further against live Customer data. We treat good-faith reports seriously and won't take action against anyone reporting responsibly.
Related documents
- Data Processing Addendum — the contractual breach-notification commitment this page summarises.
- Privacy Policy