Security Incident Response Policy

SECURITY INCIDENT RESPONSE POLICY – seenly.ad

Version 2026-07.1 · Effective date: 28 July 2026

This policy describes how NOVA MASTERCLASS MARKETING SRL ("seenly.ad") detects, assesses, contains and communicates security incidents affecting data processed through the seenly.ad service. It supplements our Privacy Policy and Data Processing Agreement and gives effect to Articles 33–34 of Regulation (EU) 2016/679 ("GDPR").


1. SCOPE

This policy covers every system that processes or stores customer data: the seenly.ad application, its database, processing queues and logs, and the access credentials held for connected platforms (Google Ads, Google Analytics 4, Google Merchant Center, Meta, TikTok, Shopify, WooCommerce and other commerce platforms).

2. WHAT WE TREAT AS A SECURITY INCIDENT

Any event that compromises, or may compromise, the confidentiality, integrity or availability of data, including:

  • unauthorised access to accounts, to the database or to server infrastructure;
  • exposure or leakage of credentials (OAuth tokens, API keys, passwords);
  • disclosure of one customer's data to another customer (a break in multi-tenant isolation);
  • loss or unauthorised alteration of data;
  • prolonged unavailability caused by an attack;
  • exploitable vulnerabilities identified in our code or dependencies.

3. SEVERITY CLASSIFICATION

LevelDescriptionResponse time
CriticalPersonal data exposed or accessed without authorisation; customer credentials compromised; isolation between accounts broken.Immediately, within 4 hours of detection
HighConfirmed exploitable vulnerability with no evidence of exploitation; unauthorised access to systems holding no personal data.24 hours
Medium / LowVulnerabilities with no direct impact on data; isolated misconfigurations.5 business days

4. RESPONSIBILITY

Coordination of incident response rests with the platform administrator at NOVA MASTERCLASS MARKETING SRL, who decides classification, containment measures and communication. As a small organisation we do not maintain a separate security team; the role is assigned by name and is reachable at all times at [email protected].

5. DETECTION

Incidents may be identified through application and server logs, error and anomaly monitoring, alerts from connected platforms (for example a revoked token or a notification from Google, Meta or Shopify), automated token health checks, and reports from customers or third parties.

Anyone — a customer, an employee or an independent researcher — may report a suspected incident to [email protected]. Security reports are acknowledged within 24 hours.

6. RESPONSE PROCESS

  1. Confirm and classify — establish whether the event is a genuine incident and its severity.
  2. Contain — immediate measures: revoke affected credentials, suspend compromised access, isolate the vulnerable component.
  3. Assess impact — which data was affected, whose, over what period, and whether there is evidence of exfiltration.
  4. Remediate — remove the cause, apply fixes, rotate secrets, restore from backup where necessary.
  5. Notify — as set out in section 7.
  6. Post-incident review — document the root cause and the measures that prevent recurrence.

7. NOTIFICATION

To customers (data controllers). We inform the affected customer without undue delay after becoming aware of a personal data breach concerning them, in accordance with Article 33(2) GDPR. Notice is sent to the account email address and describes: the nature of the incident, the categories and approximate volume of data affected, the likely consequences, the measures taken and recommended, and a contact point for further information. Where not all information is available immediately, we send an initial notification followed by updates.

To the supervisory authority. Where seenly.ad acts as controller, we notify the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Where we act as processor, notifying the authority is the customer's obligation and we provide the support and information they need.

To data subjects. Where an incident is likely to result in a high risk to the rights and freedoms of data subjects, we assist the customer in informing them under Article 34 GDPR.

To partner platforms. Where an incident involves data or credentials originating from a connected platform, we also inform that platform in line with its requirements (for example Shopify, Google or Meta).

8. PREVENTIVE MEASURES

  • traffic is encrypted in transit (TLS);
  • access tokens and API keys are encrypted in the database;
  • end-customer email addresses are never stored in clear text, only as a SHA-256 hash used to recognise returning customers;
  • administrative access requires two-factor authentication;
  • internal access is limited by role, including a strictly read-only role;
  • data deletions are recorded in an immutable audit log;
  • regular database backups.

9. RECORD KEEPING

Every confirmed incident is documented internally: time of detection, classification, data affected, measures taken, notifications sent and the conclusions of the post-incident review. Records are kept for at least 3 years and are made available to the customer or to the supervisory authority on request.

10. REVIEW

This policy is reviewed at least annually and after every incident classified as critical.

11. CONTACT

NOVA MASTERCLASS MARKETING SRL
Security contact: [email protected]