Data Breach Response Policy
Last updated: August 1, 2026
This Data Breach Response Policy ("Policy") describes the procedures Aiiplan ("Aiiplan," "we," "our," or "us") follows to identify, investigate, respond to, mitigate, and recover from actual or suspected security incidents involving personal information, confidential information, or other protected data processed through the Aiiplan platform ("Platform"). This Policy applies to all employees, contractors, service providers, vendors, subprocessors, and other authorized persons with access to Platform systems or data.
1. Purpose
Aiiplan is committed to maintaining the confidentiality, integrity, and availability of information entrusted to the Platform. The objectives of this Policy are to detect and respond to security incidents promptly, minimize the impact of data breaches, protect users and business partners, comply with applicable legal and regulatory obligations, restore normal Platform operations as quickly and securely as reasonably possible, and continuously improve security practices.
2. Incident Investigation
Upon becoming aware of an actual or suspected security incident, Aiiplan may promptly initiate an investigation to determine the nature and scope of the incident, the systems, accounts, or services affected, the categories of information involved, the number of potentially affected users, whether unauthorized access, disclosure, alteration, loss, or destruction of data occurred, and appropriate containment and remediation measures. Aiiplan may engage qualified internal personnel, legal counsel, cybersecurity specialists, forensic investigators, or other trusted third parties to assist in the investigation.
3. User Notification
Where required by applicable law or where Aiiplan determines that a security incident presents a material risk to affected users, Aiiplan will provide notice within the timeframe required by applicable law. Notifications may include, where appropriate, a general description of the incident, the categories of information affected, the actions Aiiplan has taken in response, recommended steps users may take to help protect their accounts or personal information, and contact information for additional assistance. Notifications may be delivered by email, SMS, in-app notification, telephone, postal mail, or other reasonable communication methods.
4. Government and Regulatory Notification
Where required by applicable law, Aiiplan may notify appropriate governmental authorities, regulators, law enforcement agencies, or supervisory authorities regarding qualifying security incidents. The timing, content, and method of notification will be determined in accordance with applicable legal and regulatory requirements. Nothing in this Policy limits Aiiplan's ability to cooperate with lawful investigations or governmental requests.
5. Recovery Procedures
Following containment of a security incident, Aiiplan may take reasonable measures to restore affected systems and services, including restoring data from secure backups, rebuilding or replacing affected systems, resetting credentials and authentication mechanisms, monitoring systems for continued malicious activity, validating system integrity before returning services to normal operation, and implementing additional safeguards to reduce the likelihood of recurrence. Recovery activities will be prioritized based on operational impact, user safety, legal obligations, and business continuity requirements.
6. Security Improvements
Following a security incident, Aiiplan may conduct a post-incident review to evaluate the effectiveness of its response and identify opportunities for improvement. Corrective measures may include enhancing security controls, updating security policies and procedures, strengthening access controls, improving monitoring and detection capabilities, increasing employee security awareness and training, reviewing third-party service providers, and implementing additional technical, administrative, or organizational safeguards. Aiiplan may modify its security practices as technology, business operations, legal requirements, and cybersecurity risks evolve.
7. User Responsibilities
Users are encouraged to help protect their accounts by maintaining strong and unique passwords, enabling multi-factor authentication where available, protecting verification codes and login credentials, promptly reporting suspected unauthorized account activity, keeping contact information current, and following Platform security recommendations. Users who become aware of a suspected security issue should promptly notify Aiiplan through the appropriate support channels.
8. Limitation of Liability
While Aiiplan maintains reasonable administrative, technical, and organizational safeguards designed to protect information, no security system can guarantee absolute protection against every threat or unauthorized access. Except as otherwise required by applicable law, Aiiplan makes no guarantee that security incidents will never occur and shall not be liable for damages beyond those required under applicable law and the governing agreements between the parties.
9. Policy Updates
Aiiplan may revise this Data Breach Response Policy periodically to reflect changes in legal requirements, cybersecurity practices, technology, or Platform operations. Updated versions become effective upon publication on the Platform. Continued use of the Platform constitutes acceptance of the revised Policy.
Contact Information
Customer Support Department
Aiiplan
Email: support@aiiplan.com
Website: www.aiiplan.com
Questions regarding Terms and Conditions and policies please contact us with the information above.
"Aiiplan reserves the right to add, remove, modify, or discontinue features, functionality, and services at any time."