What we do when personal information is exposed, who decides, and who gets told.
Effective 31 August 2026. This policy sets out what The Alpha Nova does when personal information in our control is lost, accessed without authorization, or disclosed without authorization. It reflects the breach obligations in PIPEDA and its Breach of Security Safeguards Regulations.
This applies to personal information we hold as an organization and, unless a client contract says otherwise, to personal information we process on behalf of a client. Where we process a client's data, we notify that client without delay so they can meet their own obligations; they remain the organization in control of the information.
Athif Shaffy, Co-Founder & Software Lead, as Privacy Officer, owns the response. Anyone at The Alpha Nova who suspects a breach must report it to the Privacy Officer immediately and directly. There is no intermediate approval step, and no one is penalised for reporting something that turns out not to be a breach.
Stop the exposure first. Revoke or rotate affected credentials, remove access, take a system offline if that is what it takes, and recover copies where possible. Preserve logs and evidence before changing anything that would destroy them.
The Privacy Officer assesses whether the breach creates a real risk of significant harm to any individual, considering the sensitivity of the information, the probability of misuse, who obtained it, and whether it was encrypted or otherwise unusable. Significant harm includes humiliation, damage to reputation or relationships, loss of employment or professional opportunity, financial loss, identity theft, and damage to or loss of property.
We keep a record of every breach of security safeguards, including those judged not to meet the notification threshold, and retain each record for at least 24 months after the day we determined the breach occurred. Records are available to the Privacy Commissioner on request.
After containment the Privacy Officer records the root cause and the fix, and updates safeguards, tooling or training so the same route closes. A breach that recurs the same way is treated as an unresolved incident, not a new one.
If you believe information held by us has been exposed, tell us immediately: info@thealphanova.com or +1 437 424 5384. Please include what you saw, where, and when. We would far rather investigate a false alarm than miss a real one.
Tell us what you're trying to build. We'll spend 30 minutes understanding the problem and tell you how we'd approach it.
Book a 30-Minute Discovery Call