Draft — pending final solicitor review. Maintained by VenueCore Ltd. Not legal advice.
Incident Response & Breach Notification
Version 2026-06-A · Forms part of the MSA and DPA.
1. Definitions
Security incident: any event that compromises the confidentiality, integrity or availability of the Services or Customer Data. Personal-data breach: an incident meeting the UK GDPR Art. 4(12) definition.
2. Detection
Centralised logging across edge, backend, database and payment layers. Automated alerts on: anomalous auth, privilege escalation, bulk data egress, failed webhook signatures, payment anomalies, rate-limit spikes, error-rate breaches. On-call rotation 24/7 with 15-minute acknowledgement target for P1.
3. Containment & investigation
P1 incidents trigger immediate isolation of affected systems, rotation of credentials, revocation of compromised tokens, and preservation of forensic evidence (logs, snapshots, audit rows). An Incident Commander runs the response per the internal runbook.
4. Customer notification
For any incident materially affecting a Customer, VenueCore will notify the Customer's primary contact without undue delay and in any event within 24 hours of confirmation, with: what happened, what data is affected, what we're doing, what the Customer should do, and a follow-up cadence. A written post-incident report is delivered within 10 business days.
5. Regulator notification (UK GDPR)
Where required and where VenueCore acts as controller, VenueCore will notify the ICO within 72 hours of becoming aware of a notifiable personal-data breach. Where VenueCore is a processor, it will assist the Customer (as controller) in meeting the Customer's own 72-hour obligation by providing the information required by UK GDPR Art. 33(3).
6. Data subject notification
Where a breach is likely to result in a high risk to data subjects, VenueCore will assist the Customer in notifying affected individuals as required by UK GDPR Art. 34, including drafting copy and providing affected-record lists.
7. Post-incident review
Every P1/P2 incident gets a written blameless review covering root cause, timeline, customer impact, regulatory exposure, and corrective actions with owners and dates. Review summaries are available under NDA on request.
8. Reporting channel
Customers and end users can report a suspected incident at security@venuecore.solutions — see also our Security & Vulnerability Disclosure policy.