Legal

Incident Response Policy

How SparrowHawk CRM LLC prepares for, detects, contains, investigates, and communicates security incidents.

Effective: July 13, 2026

Last updated: July 13, 2026

Version
v1.0
Effective
July 13, 2026
Last Updated
July 13, 2026

1. Purpose

This Incident Response Policy describes SparrowHawk CRM LLC's approach to security incidents affecting the platform, Customer Data, or the availability of the service. It complements the safeguards described on the Security & Trust Center page and the notification commitments in the Data Processing Addendum.

2. Definitions

For purposes of this policy:

  • "Event" means any observable occurrence in a system or network.
  • "Incident" means an Event that violates security policies, jeopardizes the confidentiality, integrity, or availability of Customer Data, or represents a credible threat to the platform.
  • "Personal Data Breach" has the meaning given by applicable Data Protection Laws.

3. Response Phases

SparrowHawk CRM LLC's incident response follows a defined lifecycle:

  • Preparation — documented procedures, on-call rotation, communications templates, and tabletop exercises.
  • Detection and analysis — monitoring, alerting, triage, and classification of an Event as an Incident.
  • Containment — short-term and long-term steps to prevent further impact, including credential revocation, session termination, network isolation, and vendor coordination.
  • Eradication and recovery — root-cause remediation, restoration from backups where appropriate, verification of system integrity, and return to service.
  • Post-incident review — a written retrospective, corrective actions, and follow-up tracking.

4. Roles and Responsibilities

The Incident Commander leads response, coordinates workstreams, and owns communications. Technical responders investigate, contain, and remediate. Legal and privacy advisers evaluate notification obligations. Customer communications are drafted, approved, and issued centrally.

5. Detection and Reporting

Incidents may be detected through internal monitoring, customer reports, subprocessor notifications, or external researchers.

Customers who suspect an incident affecting their data should contact security@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if the security address is not yet monitored) with as much detail as possible.

6. Customer Notification

Where an Incident constitutes a Personal Data Breach affecting a Customer's Personal Data, SparrowHawk CRM LLC will notify the affected Customer without undue delay and, in any event, within the timeframe required by applicable Data Protection Laws or a signed enterprise order form. Notice will contain the information reasonably available at the time and will be updated as additional information is confirmed.

For Incidents affecting availability, planned recovery updates will be posted through the platform's in-product notice mechanism and, for significant events, by email to the organization owner on file.

7. Post-Incident Review

After significant Incidents, SparrowHawk CRM LLC conducts a blameless post-incident review focused on causes, contributing factors, and corrective actions. Summaries may be shared with affected Customers on request, subject to appropriate confidentiality restrictions.

8. Testing and Continuous Improvement

Response procedures are periodically tested through tabletop exercises and drills. Learnings are used to update runbooks, tooling, monitoring, and training.

9. Contact

Report suspected incidents to security@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if the security address is not yet monitored).