Security governance

Personal data breach response

The response process BuildPilot follows when a security incident may involve personal data.

Last updated: 13 August 2026

1. Contain and preserve evidence

We first limit ongoing exposure, preserve relevant logs and evidence, identify affected systems and prevent unnecessary further processing. Credentials, sessions or integrations may be revoked where appropriate.

2. Assess the facts and risk

We record what happened, when we became aware, the data and people potentially affected, likely consequences, containment actions and the likelihood and severity of harm to individuals.

3. Decide whether notification is required

If a personal data breach is likely to result in a risk to people's rights and freedoms, the operator will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. If the risk is likely to be high, affected individuals will also be informed without undue delay.

4. Record the decision

Every confirmed personal data breach must be documented, including incidents that do not meet the threshold for ICO notification. The record includes the facts, effects, remedial action and the reason for the reporting decision.

5. Recover and learn

We restore normal service safely, validate corrective actions, review whether controls should change and record lessons learned. Provider or processor incidents are handled alongside the relevant contractual notification obligations.

Report a security concern

Security concerns should be reported privately to admin@buildpilotai.co.uk. Please provide enough information for investigation but do not send passwords, payment-card security codes or unnecessary sensitive information.