Security Incident Response Policy
Last updated: 30 June 2026
1. Purpose
This policy sets out how Ozmuro Pty Ltd (ABN 46 699 269 862) responds to security incidents involving personal data or platform integrity.
2. What Constitutes a Security Incident
A security incident includes any event that compromises or may compromise the confidentiality, integrity, or availability of personal data or platform systems, including:
- Unauthorised access to the Ozmuro platform or database
- Data breach involving personal data of brands, buyers, or recipients
- Loss or theft of devices containing platform credentials
- Compromise of third party services (Stripe, Supabase, Shopify, Resend, Vercel)
- Successful phishing or credential theft affecting platform accounts
3. Detection and Reporting
Anyone who becomes aware of a suspected security incident should report it immediately to hello@ozmuro.com with as much detail as possible including the nature of the incident, systems affected, and when it was discovered.
4. Response Steps
Upon becoming aware of a security incident we will:
Step 1 - Contain (within 2 hours)
- Identify and isolate affected systems
- Revoke compromised credentials immediately
- Suspend affected accounts if necessary to prevent further harm
- Preserve logs and evidence for investigation
Step 2 - Assess (within 24 hours)
- Determine the nature and scope of the incident
- Identify what data was accessed, lost, or compromised
- Identify the number of individuals affected
- Determine whether the incident constitutes an Eligible Data Breach under the Privacy Act 1988
Step 3 - Notify (within 72 hours of confirming an Eligible Data Breach)
Under the Notifiable Data Breaches scheme (Privacy Act 1988), if we determine a data breach is likely to result in serious harm to any individual we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Notify affected individuals directly where possible
- Notify affected brands whose customer data was involved
Notification will include:
- Description of the breach
- What data was involved
- What steps we are taking in response
- What steps affected individuals can take to protect themselves
Step 4 - Remediate
- Fix the vulnerability or system weakness that caused the incident
- Implement additional controls to prevent recurrence
- Review and update security measures as needed
Step 5 - Review
- Document the incident and our response in full
- Review what worked and what needs improvement
- Update this policy and security practices accordingly
5. Limitation of Liability for Security Incidents
While Ozmuro takes reasonable steps to protect personal data, no system is completely secure. To the maximum extent permitted by Australian law, Ozmuro is not liable for any loss or damage arising from a security incident that occurs despite reasonable security measures being in place, including but not limited to unauthorised access by third parties, cyberattacks, or incidents originating with third party service providers.
Nothing in this clause limits any rights you may have under the Australian Privacy Act 1988 or the Australian Consumer Law that cannot be excluded by agreement.
6. Third Party Incidents
If a security incident originates with a third party service provider (Stripe, Supabase, Shopify, Resend, Vercel) we will:
- Follow that provider's incident response procedures
- Assess the impact on Ozmuro customers
- Notify affected individuals where required under Australian law
7. Record Keeping
We maintain a record of all security incidents including those that do not meet the threshold for notification. Records are retained for 2 years.
8. Review
This policy is reviewed annually or following any security incident.
9. Contact
To report a security incident contact hello@ozmuro.com immediately.
