Our breach-notification commitments (GDPR Articles 33 and 34, US states)
HIIE publishes specific breach-notification commitments on its Security page, covering both EU and US obligations.
GDPR Article 33: notifying authorities
Under GDPR Article 33, HIIE commits to notifying the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a qualifying personal-data breach.
GDPR Article 34: notifying affected individuals
Under GDPR Article 34, HIIE commits to directly notifying the individuals affected by a breach when it is likely to result in a high risk to their rights and freedoms.
US state breach-notification commitments
In addition to the GDPR commitments, HIIE lists US state breach-notification commitments, specifically naming California, Wyoming, and Nebraska, plus any other state where affected individuals reside.
How this fits the broader security posture
These notification commitments sit alongside HIIE's technical protections: TLS in transit, AES-GCM encryption at rest with server-only keys, per-user data isolation, and Sentry-based error and dependency monitoring that helps detect issues. The Security page also reiterates that HIIE does not sell user data or train third-party models on it.
Where to read more and who to contact
The full commitments are on the /security page. For security matters, you can reach the team at [email protected]; for privacy questions, [email protected]. HIIE is operated by Arthur Labs, Inc. If you believe you've found a vulnerability or suspect an incident, the security contact is the fastest route to the right people.