Data Security & Breach Notification Policy

Last updated: 28 August 2025Effective date: 28 August 2025

1. Purpose

This Policy sets out how Hazelbit SRL protects personal and business data collected through its Services and how we respond to data breaches in line with GDPR (EU 2016/679) and international best practices (ISO 27001 principles).

2. Scope

This Policy applies to:

πŸ‘₯ Personal Data

All personal data processed by Hazelbit (customers, partners, employees)

πŸ’» Systems

All Hazelbit systems (website, mobile apps, hosted wallets, blockchain integrations)

🀝 Third Parties

All third-party processors and sub-processors handling Hazelbit data

3. Security measures

Hazelbit implements the following technical and organizational safeguards:

a) Technical measures

πŸ” Encryption

All data in transit (TLS 1.3) and at rest (AES-256)

πŸ›‘οΈ Access Control

Role-based access, MFA for staff, least-privilege principle

πŸ” Monitoring

Continuous logging of system access and suspicious activities

πŸ’Ύ Backups

Encrypted daily backups, stored in EU data centers

πŸ”„ Data Segregation

Customer data logically separated per system

πŸ—οΈ Resilience

Redundant infrastructure with disaster recovery plan

b) Organizational measures

πŸŽ“ Staff Training

Annual security and GDPR awareness training

🀝 Vendor Management

Security due diligence on all sub-processors

πŸ“‹ Policies

Acceptable Use Policy, AML/KYC Policy, and Internal IT guidelines

πŸ‘₯ Response Team

Dedicated DPO & Security Officer

4. Data minimization & retention

β€’ Only necessary data is collected (identity, wallet info, contact, billing).

β€’ Data is kept for the minimum period required by law or service needs.

β€’ Blockchain records (TxIDs, wallet addresses) are permanent and immutable; Hazelbit discloses this at registration.

5. Data breach definition

⚠️ What Constitutes a Data Breach:

A data breach means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

Examples:

β€’ Unauthorized access to customer database

β€’ Loss/theft of devices with unencrypted data

β€’ Successful cyberattack (malware, ransomware, phishing)

β€’ Human error causing public disclosure

6. Breach response procedure

Hazelbit follows a structured 4-step response:

1

Identification

Detect and confirm breach

2

Containment

Isolate affected systems, limit damage

3

Assessment

Analyze scope, type of data, number of data subjects

4

Notification & Remediation

Inform stakeholders and fix vulnerabilities

7. Notification timeline

In line with Art. 33 GDPR:

πŸ›οΈ Authority Notification (72 hours)

Hazelbit will notify the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) within 72 hours of becoming aware of a breach, unless unlikely to pose a risk.

πŸ‘₯ Data Subject Notification (Without Delay)

If the breach poses a high risk to individuals, Hazelbit will also notify affected data subjects without undue delay via email.

πŸ“‹ Notification Content Will Include:

β€’ Nature of breach

β€’ Categories and number of data subjects affected

β€’ Likely consequences

β€’ Measures taken or proposed to mitigate

8. Sub-processor obligations

Hazelbit requires all sub-processors (e.g., hosting, payments, blockchain partners) to:

πŸ›‘οΈ Security Standards

Maintain industry-standard security

⚑ Rapid Reporting

Report breaches to Hazelbit immediately (within 24h)

🀝 Cooperation

Cooperate fully in incident investigations

9. User responsibilities

πŸ‘€ What You Must Do:

β€’ Keep their account credentials secure

β€’ Report suspected account breaches to Hazelbit at info@hazelbit.ro

β€’ Avoid phishing and social engineering risks

10. Continuous improvement

Hazelbit reviews its security policies annually or after any significant incident. Independent audits or penetration tests may be conducted periodically.

11. Contact

For security or breach concerns:

Hazelbit SRL – Data Protection & Security

Str. FΓ’ntΓ’nilor 43, Bl. B14, Ap. B39, IaΘ™i, Romania

Email:info@hazelbit.ro