Effective Date: September 4, 2026
This policy establishes how Pool Party Pick 'Em ("the Company," "we," "us") detects, investigates, contains, and provides notification for security incidents that may compromise personal information belonging to our users. It is designed to satisfy the Company's obligations under applicable state data breach notification laws, given that our users reside across the United States.
This policy applies to all personal information collected or processed by Pool Party Pick 'Em, including account credentials, email addresses, and any payment-related data handled through our systems or third-party processors. It applies to the Company's website, backend infrastructure, hosting environment, and any third-party service providers with access to user data.
Cameron Mayer serves as Incident Response Lead and is responsible for coordinating detection, investigation, containment, notification, and remediation for any security incident. The Incident Response Lead may engage outside counsel, a security consultant, or the Company's hosting/infrastructure provider as needed to investigate or remediate an incident.
Anyone with access to Company systems (including contractors or third-party developers) must report a suspected security incident to the Incident Response Lead immediately upon discovery, and no later than 24 hours after discovery.
Potential incidents may be identified through, among other things:
Any suspected incident must be reported to the Incident Response Lead as soon as it is discovered, using the contact information in Section 11. Reports should include what was observed, when it was observed, and any systems or accounts believed to be affected.
Upon receiving a report, the Incident Response Lead will, within 48 hours where practicable:
If the investigation confirms that personal information was accessed or acquired without authorization, the incident is treated as a data breach and the notification process in Section 8 is initiated.
Once an incident is confirmed, the Incident Response Lead will take reasonable steps to:
The Incident Response Lead documents the incident internally regardless of severity, and treats confirmed breaches as the highest priority until resolved.
Because Pool Party Pick 'Em is based in North Carolina but has users nationwide, the notification requirements that apply to a given breach depend on where the affected individuals reside — not just where the Company is located. For each confirmed breach, the Incident Response Lead will identify the state(s) of residence of affected individuals and consult the applicable breach notification statute for each state (as well as North Carolina General Statute § 75-65, which governs the Company's own obligations as a North Carolina business). Requirements that commonly appear across state laws include:
State requirements differ in their deadlines, thresholds, and required notice content, and they change over time. This policy sets a baseline internal process; it does not substitute for a state-by-state legal review at the time of an actual incident. See Section 12.
Where a breach is confirmed to involve personal information, the Incident Response Lead will notify affected individuals by email using the address on file, in plain language, including:
Notification to affected individuals will be made without unreasonable delay following confirmation of the breach, and in no event later than the shortest deadline required by an applicable state law, except where law enforcement requests a delay to avoid impeding an investigation.
The Incident Response Lead will determine, on a state-by-state basis, whether notice to any state Attorney General or other regulator is required based on the number of affected residents in that state, and will submit any required regulatory notices within the applicable deadline.
The Incident Response Lead maintains a written incident log for every reported security incident, whether or not it is ultimately confirmed as a breach. Each entry includes: date reported, date discovered, description, systems and data affected, individuals affected (including state of residence, once known), containment actions taken, notifications sent (and to whom), and final resolution. Incident records are retained for at least three years.
This policy is reviewed at least annually, and promptly after any confirmed security incident, to incorporate lessons learned and to reflect changes in applicable law or in the Company's systems and vendors.
Incident Response Lead: Cameron Mayer — cameronmayer0@gmail.com
Reporting Channel: Email the Incident Response Lead immediately upon discovering a suspected incident.
This document is a general operational template, not legal advice, and it does not by itself guarantee compliance with any specific state's breach notification law. Because breach notification requirements (deadlines, thresholds, required notice content, and regulator notification rules) vary by state and change periodically, this policy — and the Company's response to any actual incident — should be reviewed by an attorney licensed in North Carolina and, where relevant, in the states where affected users reside.