Skip to content
DIRI AI

DIRI AI legal

DIRI AI Security Incident and Notification Policy

Version 1.0.0Effective 26 August 2026Owner-approved English version

OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.

1. Scope and definitions

A Security Incident is an event that actually compromises, or presents a credible material risk to, the confidentiality, integrity or availability of DIRI AI systems or data. A Personal Data Breach is a confirmed accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Blocked scans, unsuccessful login attempts and harmless availability alerts are not automatically personal data breaches, but may still be investigated.

2. Reporting

Customers and researchers should report suspected incidents to security@diriai.com. Privacy requests or suspected personal-data exposure may also be sent to privacy@diriai.com. The initial message should include time, affected account/route, observed behaviour and safe reproduction details, but must not include passwords, full card data or unnecessary exposed content.

3. Severity and response

DIRI AI classifies an event by data sensitivity, number and vulnerability of affected people, tenant boundary impact, privilege, active exploitation, availability and legal/contractual duties.

SeverityExampleResponse priority
Criticalconfirmed cross-tenant disclosure, privileged takeover, active destructive compromiseimmediate owner escalation, containment and legal/privacy assessment
Highlikely unauthorised access to Customer Personal Data or severe service integrity failureurgent containment and same-day assessment
Mediumlimited confirmed impact without sensitive data or controlled vulnerabilityprioritised investigation and remediation
Lowblocked attempt, minor weakness or no confirmed compromisenormal security queue and trend review

These are internal priorities, not guaranteed resolution times.

4. Response lifecycle

The incident owner will, proportionately:

  1. record and validate the report;
  2. preserve timestamps, logs and other evidence with restricted access;
  3. contain affected credentials, routes, providers or data flows;
  4. determine affected data, customers, people, countries and time period;
  5. assess notification duties with privacy/legal ownership;
  6. eradicate the cause, safely restore service and monitor recurrence;
  7. provide required updates; and
  8. document root cause, lessons and corrective actions.

5. Customer notification where DIRI AI is processor

For Customer Personal Data, DIRI AI will notify the affected organisational customer without undue delay after becoming aware of a Personal Data Breach. The operational target is an initial notice within 48 hours where reasonably possible. Information may be supplied in phases and will include the nature, likely consequences, affected data/people, mitigations and contact point as it becomes available.

The customer remains responsible for its regulator and data-subject decisions unless DIRI AI has a separate legal duty. The 48-hour target does not delay an earlier notice and is an operational goal, not a guaranteed contractual deadline.

6. Notifications where DIRI AI is controller

Where DIRI AI is controller, it will document every Personal Data Breach and assess risk to people. If the GDPR requires regulator notification, DIRI AI will notify the competent authority without undue delay and, where feasible, within 72 hours after becoming aware, explaining any delay. If the breach is likely to create a high risk, affected people will be informed without undue delay unless a lawful exception applies.

Other supported territories may require different content or shorter deadlines; the earliest applicable deadline controls.

7. Service-status communications

Material availability incidents may be communicated through an in-app notice, verified status channel or email. A public notice must not expose exploitable detail, another customer's data or an unverified cause. Security and privacy notification duties do not depend on whether a public status page is available.

8. Updates and post-incident review

For a material notified incident, DIRI AI should provide material updates until containment and a closure summary when reasonably safe. A business post-incident report may describe timeline, impact, root cause and corrective actions, subject to security, privilege, confidentiality and law. No notification is an admission of liability.

9. Evidence and retention

Incident evidence is access-restricted and retained only for the response, legal duties, claims and control improvement. The default is the case life plus five years, adjusted by severity, limitation periods, regulator instructions and legal holds. Unrelated personal data must be removed or minimised.

10. Contact and version

Security contact: security@diriai.com. Privacy contact: privacy@diriai.com. Effective version: 1.0.0. Effective date: 26 August 2026.

DIRI AI Security Incident and Notification Policy | DIRI AI