Security incident process

Last updated: 2 September 2026

This is an internal operating process for suspected security or personal-data incidents. It does not by itself create a legal notification duty. Whether the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 require notice to individuals or the Data Protection Board — and from which date — is LEGAL REVIEW REQUIRED.

Steps we take

  • Detect: unusual admin access, corrupted uploads, unexpected data exposure, or a credible report.
  • Contain: rotate secrets, disable a compromised account, take a feature offline if needed. Do not destroy evidence.
  • Investigate and preserve: keep logs, note systems touched, avoid overwriting backups that may be needed.
  • Assess: whose personal data may be affected (accounts, listings, student records, payments identifiers).
  • Notify: inform affected users in plain language when we reasonably believe it is necessary, and take legal advice before any Board or other authority notice.
  • Recover and document: restore service, record what happened, and improve the control that failed.

How to report

  • Email info@shardaitservices.com with “security” in the subject. Do not attach password lists or live card numbers.