LEGAL

Security incident notification terms

Draft customer security-incident notification and cooperation terms.

Last updated: 30 July 2026

Draft — legal review required. This page is not an approved customer agreement or legal notice.

Trigger

Notification applies when Beetl confirms unauthorised access to, acquisition of, disclosure of, alteration of, loss of, or destruction of customer data affecting the service. Legal counsel must align the definition to the governing agreement.

Timing

The draft target is notice without undue delay after confirmation. The signed agreement must state any fixed period and distinguish an early operational alert from a completed investigation.

Initial notice

Where available, Beetl should identify the incident date, affected systems and customers, categories and approximate volume of data, likely consequences, containment steps and a response contact.

Updates and cooperation

Beetl should provide material updates, preserve relevant evidence, support reasonable customer investigation and document remediation. Notification is not an admission of liability.

External notices

The responsible party or controller ordinarily decides regulator and data-subject notification. Beetl must not notify on the customer's behalf unless legally required or authorised.