Incident Response

Version 1.0 Effective: 21 July 2026 Last updated: 21 July 2026

This page describes how AB-Labz handles security incidents affecting customer data and how customers are notified. It fulfills the breach notification commitment made in the Data Processing Agreement.

1. What Constitutes a Security Incident

A security incident is any event that compromises or threatens to compromise the confidentiality, integrity, or availability of customer data. Examples include:

  • Unauthorized access to customer Workspace data or Experiment Data
  • Accidental exposure or disclosure of personal data to unauthorized parties
  • Ransomware or destructive malware affecting production systems
  • Loss of data due to accidental deletion or system failure
  • A breach at a sub-processor affecting data processed on AB-Labz's behalf

2. Our Response Commitment

72-hour notification commitment

In the event of a confirmed personal data breach affecting customer data, AB-Labz will notify affected customers without undue delay and within 72 hours of becoming aware of the breach — consistent with GDPR Article 33.

Where a full investigation is not complete within 72 hours, the initial notification will include the information available at that time. A follow-up notification with complete information will be sent as soon as practicable.

3. What the Notification Will Include

The breach notification will include, to the extent known:

  • Nature of the incident and approximate date of occurrence
  • Categories and approximate number of data subjects affected
  • Categories and approximate amount of data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects
  • Contact details for further information

This information is sufficient to enable the Customer (as data controller) to assess whether notification to their supervisory authority and/or affected data subjects is required under GDPR Articles 33 and 34.

4. How We Detect and Respond

AB-Labz maintains internal incident response procedures that include:

  • Access and anomaly monitoring on production systems
  • Documented escalation path and decision-making process
  • Immediate containment steps (e.g., revoking access, isolating affected systems)
  • Root cause analysis and remediation
  • Post-incident review to prevent recurrence

The internal playbook is not published publicly, but the customer-facing commitments described on this page are binding.

5. Reporting a Suspected Incident

If you suspect unauthorized access to your account or data, or have observed any suspicious activity related to the AB-Labz platform, please report it immediately:

Security Contact
[email protected]
Mark the subject line: [SECURITY] to ensure rapid triage.

We will acknowledge receipt within 3 business days and keep you informed of the investigation.

6. Customer Responsibilities After Notification

When a breach affecting personal data is confirmed, the Customer (as data controller) is responsible for:

  • Assessing whether notification to their national supervisory authority is required (GDPR Article 33 — within 72 hours of the Customer becoming aware).
  • Assessing whether notification to affected data subjects is required (GDPR Article 34).
  • Maintaining a record of the breach and the response taken.

AB-Labz will cooperate with the Customer's investigation and provide all reasonably requested information to support these obligations.