version 1.0
The purpose of this policy is to establish standardized procedures for the secure and reliable backup of customer data stored in the LogicalDOC Cloud environment. This ensures data integrity, availability, and recoverability, supporting the organization’s business continuity, Service Level Agreements (SLAs), and compliance obligations.
SCOPE
This policy applies to all systems, services, and data owned, managed, or processed by LogicalDOC within cloud environments, including:
-
Production and staging environments
-
Customer data stored or processed in the SaaS platform
-
Internal business systems (e.g., CRM, ticketing, analytics)
-
Configuration data and infrastructure assets
POLICY STATEMENT
LogicalDOC will maintain reliable, secure, and verifiable cloud backup procedures to ensure that critical SaaS operations and customer data can be restored in the event of accidental deletion, corruption, or system failure.
All backup operations will comply with applicable data protection laws (e.g., GDPR).
BACKUP DETAILS
Frequency
-
Application data and configurations: daily
-
Internal business systems: weekly
Retention
-
Daily backups retained for 30 days
-
Weekly backups retained for 3 months
Storage and Redundancy
Backups are stored in a separate cloud region from production data to ensure resilience against regional outages.
Encryption and Security
-
All backup data gets encrypted in transit (TLS 1.2+) and at rest (AES-256 or stronger)
-
Encryption keys are managed using a centralized Key Management Service (KMS)
-
Access to back up data is limited to authorized DevOps and Security personnel under the principle of least privilege
Validation and Testing
-
Restore tests are conducted to verify data integrity and confirm that restoration procedures meet RTO (Recovery Time Objective) and RPO (Recovery Point Objective) requirements
-
Test results and recovery logs are documented and reviewed by the Security and Compliance team
Monitoring and Alerts
-
Backup processes includes automated monitoring and alerting for failures or integrity issues
-
Failed backups must are remediated within 24 business hours of detection
-
Backup status reports are reviewed weekly by IT Operations
RECOVERY OBJECTIVES
-
RPO (Recovery Point Objective): Maximum allowable data loss is 24 hours
-
RTO (Recovery Time Objective): Critical production systems are restored within 24 business hours of an outage
These objectives may vary based on customer SLAs and must be documented accordingly
This document is published at the "LogicalDOC Cloud Backup Policy" section of this site and is subject to updating.