Back to policies

Incident Response Policy

How EduInsight approaches security and service incidents.

Published
4 May 2026
Last updated
5 January 2026
Next review
5 January 2026
Version
Version 1

Incident handling

EduInsight triages incidents based on severity, customer impact, data risk and service availability.

Incident response may include investigation, containment, mitigation, recovery, communication and follow-up improvements.

Where an incident affects customer personal data, EduInsight will support customers with relevant information so they can meet their own obligations.

Notification

EduInsight will notify affected customers without undue delay where required by law, contract or the circumstances of the incident.

Notifications will avoid exposing sensitive internal infrastructure details while providing enough information for customers to understand impact and next steps.

Incident and security concerns can be sent to support@eduinsight.co.uk.

Security note

These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.

This policy is reviewed regularly to ensure compliance.

Back to policies
Incident Response Policy | EduInsight Observe | EduInsight Observe