Legal  ›  Incident Response and Breach Notification
Nova System Inc.

Incident Response and Breach Notification

What we do when something goes wrong, when and how we tell you, and what Canadian privacy law requires of us.

Effective September 25, 2026 · Version 1.0

1. Scope

This policy covers security incidents affecting the Meridian platform and the data our customers hold in it. A security incident is any event that compromises, or credibly threatens, the confidentiality, integrity or availability of the service or of customer data.

Not every alert is an incident and not every incident is a breach of personal information. This page explains how we tell the difference and what happens in each case.

2. How we respond

Detect. Alerts, logs, customer reports and researcher reports all start the same process. Anyone at Nova System can raise an incident and we would rather investigate a false alarm than miss a real one.

Contain. The first priority is stopping the harm: isolating the affected component, revoking credentials, or taking a feature offline if that is what it takes.

Assess. We establish what happened, what data was involved, which firms are affected, and whether there is a real risk of significant harm to any individual.

Notify. See the next two sections. Notification runs in parallel with the fix, not after it.

Recover and review. We restore normal service, then write the incident up, including what we would do differently. Material lessons change the runbooks.

3. Telling our customers

Where a firm uses Meridian, that firm is the organisation accountable to its own clients, and we act on the firm behalf. So we tell the firm.

On confirmation of a personal data breach affecting a customer, we notify that customer without undue delay, as set out in the Data Processing Addendum. The notice describes what we know at the time: the nature of the incident, the categories and approximate volume of data involved, the likely consequences, the measures we have taken, and a contact point for more information.

We update the notice as the picture becomes clearer rather than waiting until we know everything. We do not publish a guaranteed notification time in hours, because a number we could not always honour would be worth less than the commitment to move as fast as the facts allow.

4. What Canadian law requires

Under the Personal Information Protection and Electronic Documents Act, an organisation must report a breach of security safeguards to the Office of the Privacy Commissioner of Canada, and notify affected individuals, as soon as feasible where the breach creates a real risk of significant harm. Records of every breach of security safeguards must be kept for twenty four months, whether or not the breach was reportable.

We keep those records. Where we are the service provider rather than the organisation holding the relationship with the individual, we support the firm in meeting its own obligations and we do not substitute our judgement for theirs.

Firms in Quebec should also read the Privacy Policy section on Law 25, which carries its own confidentiality incident register and notification duties.

5. Service disruption that is not a data incident

An outage with no data exposure is handled under the Service Availability and Support SLA documents. Incidents are posted on the Status page, and material ones are emailed to account owners.

6. Reporting something to us

Customers and clients should email security@thenovasystem.com. Security researchers should read the Responsible Disclosure Policy first.

If you believe client information has been exposed, say so in the subject line. That routes the message differently.

7. Related documents

The Security Policy describes the controls. The Business Continuity and Disaster Recovery policy covers what happens when the problem is availability rather than exposure. The Government and Law Enforcement Requests page covers demands for data.

© 2026 Nova System Inc. · British Columbia, Canada · Legal & Trust Center