If we confirm an incident that affects the confidentiality, integrity or availability of your data, we contain it first, then notify the account owner and security contact by email within 72 hours of confirmation, with what happened, what data was involved, what we have done and what you should do.
We follow with a written root cause and the changes made, normally within 14 days. Where a regulator must be informed, we support you with the facts and timelines you need.