Business Continuity Policy
Purpose and scope
This policy sets out how RODMENA LIMITED keeps its hosted products and its client services running, or restores them quickly, when something goes wrong. It covers our own platforms, the systems we run for clients, and our ability to keep working as a company.
What we depend on
- Hosting: OVHcloud (UK, France, Germany), iDNet (UK) and Cloud Nord (UK). Our database layer is spread across four hosts in three countries, so the loss of one host or one country does not lose the data.
- Email and documents: Google Workspace.
- Code and its history: GitHub.
- Domain names and DNS, and our bank for payments to and from us.
The full list, with each provider's purpose and location, is the sub-processor table on our Trust Centre.
Backup and recovery
- Data on our managed fleet is replicated so that at most 5 minutes of changes could be lost (our published recovery point objective). See How we run.
- Systems we run for clients have scheduled, encrypted and tested backups designed to the recovery objectives agreed in each contract.
- We restore from backup at least once a year to prove the backups work, and record the date and the result.
If the director cannot work
RODMENA is a young company led by its director, who is today its only key person. We are reducing that risk by:
- documenting how our systems run, so that someone else can operate them;
- keeping credentials and access available to an attorney if the director cannot work or dies;
- bringing in partners as the company grows, chosen with care.
Telling clients
If an incident affects a client, we tell that client without undue delay what we know, what we are doing and when they will hear from us next, as set out on our Security page. Where a contract sets a shorter notice period, the contract applies.
Review
The director owns this policy and reviews it at least annually, and after any incident that tested it.
See also: Information Security Policy · Trust Centre · Exit and portability.