LEGAL DOCUMENT

Data Breach
Notification Policy

Effective: 1 June 2025 Last Updated: 1 June 2025 DPDPA 2023 S.8(6) Compliant

Table of Contents

  1. Purpose & Scope
  2. What Is a Data Breach
  3. Breach Detection & Assessment
  4. Notification Timelines
  5. Notification to Customers
  6. Notification to DPBI
  7. Notification to Data Principals
  8. Post-Breach Review
  9. Your Obligations as a Customer
  10. Contact
01 —

Purpose & Scope

This Data Breach Notification Policy describes how Servyn AI detects, assesses, and responds to personal data breaches, and how we notify affected parties as required under DPDPA 2023 S.8(6) and the SPDI Rules 2011.

This Policy applies to all personal data processed through the Servyn AI platform, including data held in our Supabase database, backup systems, and any data held by Sub-Processors.

02 —

What Is a Data Breach

A personal data breach is any accidental or unlawful event that results in:

Not all security incidents are data breaches. A server error that does not expose personal data is an incident, not a breach.

03 —

Breach Detection & Assessment

Upon becoming aware of a potential breach, Servyn AI will:

  1. Contain: Take immediate steps to stop ongoing unauthorised access or data loss
  2. Preserve evidence: Preserve logs and evidence for investigation without destroying affected systems
  3. Assess severity: Determine the nature of the breach, categories of data affected, number of Data Principals affected, and likely consequences
  4. Classify: Classify the breach as Low, Medium, or High severity based on the type of data and impact
SeverityDescriptionExample
LowLimited impact; no SPDI exposed; contained quicklyA single user account password reset email sent to wrong address
MediumSome personal data exposed; limited number of individuals; quickly containedA bug temporarily exposed job records of one company to another company's admin
HighSPDI exposed (Aadhaar, PAN, salary, bank details); large number of individuals; potential for harmDatabase credentials compromised; bulk export of payroll data by unauthorised party
04 —

Notification Timelines

RecipientTimelineTrigger
Affected Customer (company admin)Within 24 hours of Servyn AI becoming awareAny Medium or High severity breach affecting that customer's data
Data Protection Board of India (DPBI)Within 72 hours of Servyn AI becoming awareAny breach likely to result in harm to Data Principals (once DPBI is operational)
Affected Data PrincipalsPromptly after DPBI notification, as directed by DPBIAs required by DPBI direction or when notification is necessary to protect Data Principals
Internal recordImmediately upon detectionAll incidents, regardless of severity
05 —

Notification to Customers

When Servyn AI notifies a Customer of a breach, the notification will include:

Notification will be sent via email to the registered admin email address and, for High severity breaches, also via WhatsApp.

If not all information is available within 24 hours, Servyn AI will send an initial notification with available information and follow up with complete information as soon as reasonably practicable.

06 —

Notification to the Data Protection Board of India

Servyn AI will notify the Data Protection Board of India (DPBI) within 72 hours of becoming aware of a breach that is likely to result in harm to Data Principals, as required under DPDPA 2023 S.8(6).

The DPBI notification will be submitted via the DPBI's official online portal (dataprivacy.gov.in) once it is operational, and will contain all information required under the DPDPA 2023 rules.

Servyn AI will cooperate fully with any DPBI inquiry or investigation arising from a breach notification.

07 —

Notification to Data Principals

Servyn AI will notify affected Data Principals (individual employees and customers whose data was breached) when:

Because employee and customer data is entered by the Customer (the Data Fiduciary), Servyn AI will coordinate with the Customer on the content and delivery of Data Principal notifications. The Customer is responsible for contacting their employees and customers using contact details they hold.

08 —

Post-Breach Review

Following any Medium or High severity breach, Servyn AI will:

09 —

Your Obligations as a Customer

As a Data Fiduciary under DPDPA 2023, you also have breach notification obligations to your employees and customers. When Servyn AI notifies you of a breach:

10 —

Contact — Report a Suspected Breach

If you suspect a data breach or security incident involving the Servyn AI platform, report it immediately:

Security Incident Reporting

Rahul Birwadkar — Grievance Officer

📧 founder@servynai.in — Subject: "Security Incident Report"

📞 +91 97684 46498 (call or WhatsApp for urgent matters)

Available: Mon–Sat, 9 AM – 7 PM IST. For critical incidents outside these hours, call directly.