← Governance framework
Platform Operations
Business Continuity and Exit Strategy Policy
Continuity planning beyond incident response, plus data portability and orderly exit for users if ImpactMiles winds down a service or the entity.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-20
- Next review
- 2027-07-19
- Owner
- CTO
- Approver
- Board of Directors
Anchored by content hashissued 2026-07-29
Payload hash
db78d967ea25682f5c986f605d9c7b8534d29e2e06c041beca3273fb5ae5e7beSHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:db78d967ea25682fThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All production services and data
- All user accounts and their credentials
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Backup and disaster-recovery drills at least annually
- Export endpoints for participant, charity and corporate data
- Escrow of TrustMark verification specification
1. Business Continuity
- Documented BCP for critical services (verification API, TAS operations, database).
- Recovery Time Objective 4 hours, Recovery Point Objective 15 minutes for the primary database.
- Annual continuity exercise and tabletop review.
2. Disaster Recovery
- Cross-region encrypted backups.
- Alternate hosting readiness for the verification API.
- Runbooks for key rotation, database restore and TAS failover.
3. Data Portability and Exit Rights
- Users may export their profile, activity history and credentials at any time via /my-provenance.
- Charities and corporates may export their organisation records and issued credentials.
- Machine-readable JSON is provided for all exports.
4. Service or Entity Wind-Down
- Minimum 90 days' notice before discontinuing a core service where practicable.
- TrustMark verification specification and public credential registry preserved through a nominated custodian.
- Deletion or handover of personal data in accordance with the Data Retention and Deletion Schedule.
Questions or concerns about this policy? Contact the DPO.