ConformOps
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resources
Sign inStart free
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resourcesSign in
Trust

Breach notification commitment

Last updated 29 August 2026

Our commitment

When ConformOps acts as a processor and becomes aware of a personal-data breach affecting Customer Personal Data, the operator will notify the affected customer without undue delay. The initial notice may be preliminary and will not be held back until every fact is known. ConformOps does not publish a fixed one-hour, 24-hour, or 24/7 response promise that the current operation cannot support.

How notice is delivered

Notice will be sent to the workspace Owner's registered email address and to any separate security contact the customer has documented with the operator. If the normal account channel is part of the incident, the operator will use another documented contact method where available.

What the notice includes

As information becomes available, ConformOps will provide:

  • the nature of the breach and the affected service or workspace;
  • the categories of affected data and data subjects, and approximate numbers where known;
  • the likely consequences identified at that time;
  • the containment, remediation, and risk-reduction measures taken or planned;
  • a contact for follow-up and the timing of the next update where known.

Updates and cooperation

ConformOps will provide material updates without undue delay, preserve relevant service records where lawful, and give the customer information reasonably needed for its own assessment and notification duties. ConformOps will not notify regulators or affected people on the customer's behalf unless required by law or separately agreed in writing.

Scope

This commitment covers a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed by ConformOps. A service outage or vulnerability with no affected personal data is handled as a security or availability incident, but is not described as a personal-data breach without evidence.

Report a suspected incident

Report suspected exposure or misuse to privacy@conformops.eu. Do not include secret values or unnecessary source content in the first email.

ConformOps
How it worksPricingReporting deadlinesSecurityCRA resourcesAI infoTrust centerDPALegal noticePrivacyTerms
Readiness assistance, not legal certification.