HeroPerks

Return

Security

Breach Management

Last updated 25 June 2026

At HeroPerks, we take the protection of personal data and system security seriously. This section explains how we identify, manage, and respond to data breaches and security incidents.

1. What Is a Data Breach?

A data breach is any incident that leads to unauthorised access to personal data, loss or theft of data, accidental disclosure of information, or alteration or destruction of data without permission.

2. Our Approach

We follow a structured approach to managing incidents: identify potential breaches quickly, contain and secure affected systems, assess the impact and risks, notify relevant parties where required, and resolve the issue and prevent recurrence.

3. Detection and Reporting

We use monitoring and internal processes to detect potential security incidents. All employees, partners, and contractors are required to report suspected breaches immediately and escalate concerns through appropriate channels.

4. Investigation and Assessment

When a breach is identified, we will investigate the nature and scope of the incident, identify what data is affected, assess the risk to individuals, and determine appropriate next steps.

5. Containment and Recovery

We take immediate action to secure systems and prevent further access, recover lost or compromised data where possible, and restore normal operations safely.

6. Notification

Where required by law, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of a notifiable breach, and inform affected individuals if there is a high risk to their rights and freedoms. We will provide clear information about what happened, what data was affected, what actions are being taken, and any steps individuals should take.

7. Documentation

All breaches and incidents are recorded, including the cause of the incident, the impact and risks, actions taken, and lessons learned. This helps us improve our processes and prevent future incidents.

8. Prevention and Continuous Improvement

We regularly review our systems and processes to reduce risk, including security monitoring and updates, staff training and awareness, access controls and data protection measures, and policy reviews and improvements.

9. Responsibilities

All individuals with access to HeroPerks systems must handle data securely, follow company policies, and report any suspected incidents immediately. Management is responsible for ensuring appropriate response procedures are in place, incidents are handled promptly and effectively, and HeroPerks maintains an internal incident response plan to support rapid and effective breach management.

10. Contact Us

If you believe a data breach has occurred or have concerns about data security, please contact us immediately: [email protected]


Legal responsibility for the content on this page sits with Employees Global Ltd.