Incident Response
Last updated: August 2026 · v1.0
In short
We maintain a documented incident-response process. When something goes wrong, we detect it, contain it, assess the impact, notify the right people, fix the root cause, and learn from it. This page describes that process publicly so you know what to expect.
1. What is a security incident?
A security incident is any event that compromises or could compromise the confidentiality, integrity, or availability of Bookify Malta or the data we process. This includes:
- Unauthorised access to user accounts or data
- Data breaches involving personal data
- Service outages or degradation
- Malware, ransomware, or credential compromise
- API abuse or denial-of-service attacks
- Loss or theft of a device with access to production systems
- Subprocessor security failures affecting Bookify data
2. How we assess severity
Every incident is assigned a severity level during triage. Severity determines our response speed, who is notified, and whether the incident is published on our status page.
Active data breach exposing personal data, complete service outage, or compromise of production credentials. Response begins immediately on detection, day or night.
Significant service degradation, potential data exposure requiring investigation, or subprocessor incident with possible impact. Response begins within 4 hours.
Partial feature unavailability, non-sensitive bug that could be exploited, or rate-limit anomaly. Response begins within 1 working day.
Minor issue, cosmetic bug, or informational alert with no data impact. Addressed in the regular development cycle.
3. Our response process
- Detection: Incidents are detected through automated monitoring, error logging, user reports, or external notification (e.g. from a subprocessor or security researcher).
- Triage: The operator assesses the incident, assigns a severity level, and determines whether personal data is involved.
- Containment: Immediate steps are taken to stop the incident from spreading — this may include revoking access, isolating affected systems, or taking a feature offline.
- Investigation: We determine the root cause, the data affected, and the individuals or salons potentially impacted.
- Notification: Affected parties are notified according to the timelines in section 4.
- Remediation: The root cause is fixed and the fix is deployed. We verify the fix does not introduce new issues.
- Recovery: Affected services are restored to normal operation.
- Post-incident review: Within 14 days of resolution, we conduct a review to identify what went well, what did not, and what we will change to reduce the likelihood or impact of similar incidents. Lessons are added to our internal runbook.
4. Who we notify and when
Where Bookify is the controller
For data that Bookify controls directly (e.g. business-owner account data, support correspondence), we apply the following timelines:
- IDPC notification:Within 72 hours of becoming aware, if the breach is likely to result in a risk to individuals’ rights and freedoms (GDPR Art. 33).
- Individual notification: Without undue delay, if the breach is likely to result in a high risk to individuals’ rights and freedoms (GDPR Art. 34).
Where Bookify is the processor
For data that Bookify processes on behalf of a salon (e.g. client booking data), we notify the affected salon without undue delay after becoming aware of a personal data breach. Our internal target is within 24 hours of confirmed awareness.
Important: The salon, as controller, is responsible for notifying the IDPC and affected individuals within their own 72-hour window. Our prompt notification to the salon is designed to give them the maximum possible time to meet their own obligations.
5. Public communication
Service-affecting incidents are published on our Status Page, including the nature of the incident, affected services, and updates as the situation evolves. Incidents involving personal data are described in general terms to avoid disclosing sensitive details.
6. Evidence preservation
During an incident, we preserve relevant logs, system states, and forensic evidence. This evidence is kept secure and is used for root-cause analysis, regulatory reporting, and legal defence if necessary. Evidence from security incidents is retained for the duration of legal exposure plus 3 years.
7. Subprocessor coordination
If an incident originates with or affects one of our subprocessors (Google Cloud, Epic Communications, SiteGround), we coordinate with that provider to understand the scope, obtain their incident report, and relay relevant information to affected salons and, where applicable, the IDPC.
8. Reporting a suspected incident
If you suspect a security incident affecting your Bookify account or data, contact us immediately at legal@bookify.mt or +356 7956 1688. For a broader overview of our security controls, see our Security & Reliability page. For vulnerability reports, see our Vulnerability Disclosure Policy.