nampa Get an invite

Incident response plan

What we do when something goes wrong with security or privacy, and how and when we'll tell you.

Last updated 2 October 2026. These policies take effect when the Nampa app launches. Until then they describe how we are building it.

The short version: we act fast, we contain it, and if your information was affected we tell you within 72 hours of confirming it, in plain words.

What counts as an incident

Anything that puts the privacy or security of people on Nampa at risk. For example, someone getting into our systems, data reaching someone it shouldn't, a weakness being exploited, or our deletion not working as promised.

Who does what

  • Incident lead. One named person on call at all times who takes charge and makes decisions.
  • Engineering. The people who investigate, contain and fix the problem.
  • Communications. The person who tells you, and anyone else who needs to know, what happened.

How serious is it

LevelWhat it means and how fast we move
CriticalPersonal data exposed, or deletion or encryption not working. Work starts within 1 hour, day or night.
HighA real weakness that could expose data but hasn't yet. Work starts within 4 hours.
LowA problem with no realistic path to anyone's data. Fixed in the normal course of work.

The steps

  1. Notice. Alerts, a member of staff or an outside report tells us something is wrong.
  2. Assess. The incident lead decides how serious it is and who needs to be involved.
  3. Contain. We stop it spreading, for example by shutting off access or rotating credentials.
  4. Fix. We remove the cause and check nothing else was affected.
  5. Recover. We bring things back carefully and watch closely.
  6. Tell people. See below.
  7. Learn. We write up what happened and what we're changing so it doesn't happen again.

How we'll tell you

If your information was affected, we'll tell you within 72 hours of confirming it, in the app and by text message. We'll say what happened, what it means for you, what we've done and what you can do. We'll tell data protection authorities and anyone else the law requires within the legal deadlines.

Afterwards

For any critical incident we'll publish a plain write up on this site once it's safe to do so. We practise this plan at least twice a year, so it works when it matters.

Questions

Write to hello@nampa.app. A person reads every message.