Scope and purpose
This policy describes how Valverna AB detects, responds to, and recovers from security incidents affecting personal data or the integrity of our service — and how and when we notify those affected. It complements our Privacy Policy and applies to every system that stores or processes your account data and the transaction data we handle on your behalf.
How we protect data
Our preventive measures include:
- Encryption — TLS for all data in transit and encryption at rest for stored data and backups.
- Access control — production access is restricted on a least-privilege, need-to-know basis; credentials are protected with strong authentication and multi-factor where supported.
- Authentication — user credentials are managed by Firebase Authentication; we never store plaintext passwords.
- Separation — test and production data are kept separate, and secrets are stored outside source control.
- Logging — access to personal data and key system events are logged for monitoring and investigation.
No system is ever 100% secure. This policy covers what happens when something goes wrong despite these measures.
What we treat as an incident
A security incident is any actual or suspected event that compromises the confidentiality, integrity, or availability of personal data or our systems — for example unauthorized access, accidental data exposure, credential or token compromise, malware, or loss of data. Incidents at a sub-processor that affect your data are treated the same way.
Our response process
When an incident is identified, we follow a defined lifecycle:
1 · Detect & record
The incident is logged with a timestamp, whether surfaced by monitoring or reported to [email protected]. The clock for our assessment starts here.
2 · Triage & contain
We assess severity and act immediately to stop ongoing harm — revoking compromised credentials or tokens, isolating affected systems, and disabling affected access.
3 · Assess
We determine what happened, which systems and whose personal data are affected, and the level of risk to the individuals concerned.
4 · Notify
We inform affected parties and authorities on the timelines in the next section.
5 · Remediate & recover
We fix the root cause, rotate secrets, and restore from backups where needed to return to normal, secure operation.
6 · Review
After resolution we conduct a post-incident review and document changes to prevent recurrence.
Breach notification
Our notification duties follow our role under GDPR (see our Privacy Policy for the controller/processor distinction):
- As a processor (for the transaction and customer data we handle on your behalf) — we notify affected merchants without undue delay after becoming aware, in practice within 72 hours, so you can meet your own obligations as controller.
- As a controller (for your account data) — we notify the competent supervisory authority (Sweden's IMY) within 72 hours where required (Art. 33), and affected individuals without undue delay where the breach is likely to pose a high risk (Art. 34).
- Connected platforms — where a breach involves data from a platform you connected (a payment processor or sales channel), we also notify that platform as required by our agreements with them.
Notifications describe, as far as known: the nature of the breach, the data and individuals affected, the likely consequences, and the measures we have taken or propose to take.
Reporting a vulnerability
If you believe you've found a security vulnerability, please email [email protected] with enough detail to reproduce it. We'll acknowledge your report and keep you updated as we investigate.
We ask that you give us a reasonable opportunity to remediate before any public disclosure, and that you don't access or modify other users' data, degrade the service, or run intrusive automated scans. We don't currently run a paid bug-bounty program, but we're grateful for good-faith reports and will credit you if you'd like.
Contact
Security reports: [email protected]
Data protection enquiries: [email protected]
Postal: Valverna AB, Stockholm, Sweden