Incident Response
This page describes how AB-Labz handles security incidents affecting customer data and how customers are notified. It fulfills the breach notification commitment made in the Data Processing Agreement.
1. What Constitutes a Security Incident
A security incident is any event that compromises or threatens to compromise the confidentiality, integrity, or availability of customer data. Examples include:
- Unauthorized access to customer Workspace data or Experiment Data
- Accidental exposure or disclosure of personal data to unauthorized parties
- Ransomware or destructive malware affecting production systems
- Loss of data due to accidental deletion or system failure
- A breach at a sub-processor affecting data processed on AB-Labz's behalf
2. Our Response Commitment
72-hour notification commitment
In the event of a confirmed personal data breach affecting customer data, AB-Labz will notify affected customers without undue delay and within 72 hours of becoming aware of the breach — consistent with GDPR Article 33.
Where a full investigation is not complete within 72 hours, the initial notification will include the information available at that time. A follow-up notification with complete information will be sent as soon as practicable.
3. What the Notification Will Include
The breach notification will include, to the extent known:
- Nature of the incident and approximate date of occurrence
- Categories and approximate number of data subjects affected
- Categories and approximate amount of data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its effects
- Contact details for further information
This information is sufficient to enable the Customer (as data controller) to assess whether notification to their supervisory authority and/or affected data subjects is required under GDPR Articles 33 and 34.
4. How We Detect and Respond
AB-Labz maintains internal incident response procedures that include:
- Access and anomaly monitoring on production systems
- Documented escalation path and decision-making process
- Immediate containment steps (e.g., revoking access, isolating affected systems)
- Root cause analysis and remediation
- Post-incident review to prevent recurrence
The internal playbook is not published publicly, but the customer-facing commitments described on this page are binding.
5. Reporting a Suspected Incident
If you suspect unauthorized access to your account or data, or have observed any suspicious activity related to the AB-Labz platform, please report it immediately:
We will acknowledge receipt within 3 business days and keep you informed of the investigation.
6. Customer Responsibilities After Notification
When a breach affecting personal data is confirmed, the Customer (as data controller) is responsible for:
- Assessing whether notification to their national supervisory authority is required (GDPR Article 33 — within 72 hours of the Customer becoming aware).
- Assessing whether notification to affected data subjects is required (GDPR Article 34).
- Maintaining a record of the breach and the response taken.
AB-Labz will cooperate with the Customer's investigation and provide all reasonably requested information to support these obligations.