Safeli
DemoPricingLogin

GOVERNANCE

Incident Response Policy

This policy describes how Safeli Limited prepares for and responds to security incidents affecting client data or its systems, in support of its due-diligence and regulatory obligations.

Version 1.0 — 27 August 2026

1. Purpose and scope

This Incident Response Policy defines how Safeli Limited identifies, responds to, and reports security incidents that affect client data or Safeli systems. It applies to all Safeli staff, contractors and assessors, and covers any suspected or confirmed breach of confidentiality, integrity or availability of data.

2. Roles and responsibilities

A named incident lead is responsible for coordinating the response to any security incident, including assessment, containment, communication and post-incident review. All staff and contractors must report suspected incidents immediately to the incident lead. Where a client is affected, the client’s nominated contact is informed without undue delay.

3. Incident identification

A security incident may be identified through monitoring alerts, audit log review, staff or client reports, or notifications from the hosting provider. Suspected incidents are triaged by the incident lead to confirm whether a genuine incident has occurred and to assess its severity and potential impact on personal data.

4. Containment and investigation

Upon confirmation, the incident lead takes immediate steps to contain the incident, which may include revoking affected user access, isolating systems, or disabling compromised credentials. An investigation is conducted to determine the scope, the data affected, the root cause, and any remediation required. The hosting provider (Base44) is engaged where infrastructure or platform controls are implicated.

5. Breach notification

Where an incident is likely to result in a risk to the rights and freedoms of individuals, Safeli notifies the affected client without undue delay and provides the information required for the client, as controller, to meet its obligations under GDPR (notification to the ICO within 72 hours and, where required, communication to affected individuals). Safeli, as processor, does not notify regulators or individuals directly except on the client’s documented instruction.

6. Recovery and lessons learned

Once contained, the incident lead coordinates recovery actions to restore affected systems and data. A post-incident review is conducted within 14 days to identify root cause, assess the effectiveness of the response, and implement corrective actions to prevent recurrence. Outcomes are documented and, where relevant, shared with affected clients.

7. Response times

Initial triage of any reported incident is commenced within 24 hours of identification. Client notifications, where required, are made without undue delay and in any event within 72 hours of confirmation of a notifiable breach. Post-incident reviews are completed within 14 days.

8. Records and review

All incidents and the response actions taken are documented and retained for a minimum of two years, or longer where required by the client’s contract or applicable law. This policy is reviewed at least annually and updated in response to any material incident or change in the regulatory environment. The current version date is 27 August 2026.

Safeli

Commercial Compliance. Done Properly.

The modern alternative to clipboard compliance and spreadsheet audits - software that tracks every obligation, backed by people who know your buildings.

Nottinghamshire·Lincolnshire

Platform

  • Live Demo
  • Pricing
  • Client Login
  • Contact Us

Resources

  • Security & IT
  • Privacy Notice
  • Terms
  • DPA
  • Info Security Policy
  • Incident Response Policy

Get in touch

  • 0330 043 3501
  • WhatsApp
  • hello@safeli.co.uk

Email answered 24/7 · Site visits Mon-Sat

Safeli Limited is a company registered in England and Wales. Company number: 16932254. Registered office: 11 Woodland Walk, Newark, NG23 7QX.

© 2026 Safeli. All rights reserved.

Chat for a quote