Skip to content
MiseCentral
Platform Overview Work Intelligence Product Tour Technology Profile Integrations Implementation Enterprise Administration
Solutions Overview Capabilities Overview Recipes Production Operations Inventory Purchasing Quality Traceability Food Safety Labor Planning Company Brain
All Industries Restaurants Hospitality Catering Production Retail Food Distribution
Work Intelligence Trust
Resource Center Customer Stories ROI Pricing Support
About How We Operate Media Trust Center Procurement Contact
Sign In Book a Demo
Home · Security · Incident Response Policy

Incident Response Policy

How MiseCentral responds to security and service incidents.

Version
1.0
Effective
August 1, 2026
Last updated
August 1, 2026
Document ID
LEGAL-SUP-003
Download PDF Contact Legal Contact Privacy

On this page

  1. 1. Purpose and Scope
  2. 2. Incident Classification
  3. 3. Incident Response Lifecycle
  4. 4. Customer Cooperation
  5. 5. Service Incident Communication
  6. 6. Personal Data Breach Notification
  7. 7. Law Enforcement and Legal Process
  8. 8. Support Mode in Incidents
  9. 9. Subprocessors
  10. 10. Contact

All legal documents

Incident Response Policy

This Incident Response Policy describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") identifies, manages, and communicates about security incidents and Personal Data breaches affecting the Services. This policy supplements the Agreement, Data Processing Agreement ("DPA"), and Security and Privacy Controls Overview.

1. Purpose and Scope

1.1. This policy applies to incidents affecting the confidentiality, integrity, or availability of the Services or Customer Data processed by MiseCentral.

1.2. This policy does not govern incidents occurring solely within Customer-managed systems, Connected Services, or Connected Devices outside MiseCentral's control, though MiseCentral may cooperate with Customer upon request.

2. Incident Classification

2.1. MiseCentral classifies incidents by severity:

2.2. Personal Data breaches are handled under enhanced notification procedures in Section 6 regardless of broader incident severity.

3. Incident Response Lifecycle

3.1. Detection and Reporting. Incidents may be detected through monitoring, personnel reports, Customer reports, or Subprocessor notifications. Customers may report suspected incidents to security@misecentral.com.

3.2. Triage and Assignment. MiseCentral security personnel assess severity, assign an incident lead, and initiate containment steps.

3.3. Containment. MiseCentral takes actions reasonably necessary to limit harm, which may include blocking malicious access, isolating affected systems, rotating credentials, disabling compromised integrations, or activating Support Mode only as authorized.

3.4. Investigation. MiseCentral analyzes root cause, scope of affected Customer Data, timeline, and indicators of compromise. Evidence is preserved as appropriate for remediation and legal requirements.

3.5. Eradication and Recovery. MiseCentral removes malicious artifacts, applies patches, restores systems from clean backups where needed, and validates Service integrity before declaring recovery.

3.6. Post-Incident Review. MiseCentral conducts a review for Critical and High incidents to identify corrective and preventive measures.

4. Customer Cooperation

4.1. Customer will promptly notify MiseCentral if Customer believes a security incident affects the Services or MiseCentral-managed credentials.

4.2. Customer will cooperate with reasonable investigation requests, including preserving logs, confirming Authorized User activity, and implementing recommended mitigations on Customer-managed endpoints.

4.3. Customer will designate security contacts for urgent communications.

5. Service Incident Communication

5.1. For incidents causing material Service unavailability, MiseCentral will communicate status updates through the status page, email to Customer administrators, or other channels specified in the Agreement.

5.2. Communications include, as information becomes available: incident summary, affected components, actions taken, and estimated recovery timing.

5.3. Availability-related incidents are also addressed under the Service Availability Policy and SLA where applicable.

6. Personal Data Breach Notification

6.1. If MiseCentral becomes aware of a Personal Data breach affecting Customer Data processed under the DPA, MiseCentral will notify Customer without undue delay and within seventy-two (72) hours where feasible, consistent with Section 8 of the DPA.

6.2. Notification includes, to the extent known: nature of the breach; categories of data subjects and data affected; likely consequences; and measures taken or proposed.

6.3. MiseCentral will cooperate with Customer's regulatory and data subject notification obligations by providing additional information as it becomes available, subject to confidentiality and law enforcement restrictions.

6.4. Customer is responsible for determining whether and how to notify supervisory authorities, data subjects, or other parties, except where MiseCentral acts as Controller for affected data.

7. Law Enforcement and Legal Process

7.1. MiseCentral may engage law enforcement or regulators where required or appropriate. Unless prohibited, MiseCentral will notify Customer before disclosing Customer Data in response to legal process and will challenge overbroad requests where permitted.

8. Support Mode in Incidents

8.1. Emergency Support Mode for security containment is permitted under Section 2.1(c) of the Support Mode Policy when Customer is unresponsive and immediate action is necessary to prevent imminent harm.

8.2. All emergency actions are documented in the incident record and reported to Customer as soon as practicable.

9. Subprocessors

9.1. MiseCentral requires Subprocessors to notify MiseCentral of incidents affecting Customer Data. MiseCentral evaluates Subprocessor notifications under this policy.

10. Contact

Report a security incident: security@misecentral.com

MiseCentral LLC Attn: Security 8 The Green, Suite A Dover, DE 19901 United States

Privacy breach coordination: privacy@misecentral.com

Version history

VersionEffectiveSummary
1.0August 1, 2026Initial publication of the Legal Library (LEGAL-01).

Previous versions remain available for reference and are never overwritten.

MiseCentral

The Adaptive Operating System for Hospitality—smoother operations, adaptive intelligence, and people in command.

Product

Product Tour Platform Work Intelligence Solutions Industries Pricing

Trust

Trust Center Legal Privacy Security Status Responsible AI

Company

About Resources Support Procurement Contact Book a Demo
© MiseCentral LLC. All rights reserved. · Terms · Privacy · Cookies · Trust Center · Trademark