BUSINESS CONTINUITY AND BACKUP POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Business Continuity and Backup Policy is to establish procedures and controls designed to ensure the continuity of critical business operations and the protection of Company information assets in the event of disruptions, failures or security incidents.
The Company recognizes that uninterrupted availability of systems, data and services is essential to maintaining customer trust and operational effectiveness.
2. Scope
This policy applies to:
- Cloud infrastructure
- Applications
- Databases
- Source code repositories
- Internal systems
- Communication platforms
- Customer information
- Business information
The policy applies to all personnel, contractors and service providers involved in operating or supporting Company systems.
3. Business Continuity Objectives
The Company aims to:
- Minimize service disruptions
- Protect critical business data
- Restore systems within reasonable timeframes
- Maintain operational capability during incidents
- Reduce the impact of unexpected events
Examples of events covered by this policy include:
- Infrastructure failures
- Cloud service disruptions
- Cybersecurity incidents
- Human errors
- Data corruption
- Hardware failures
- Network outages
4. Critical Assets
The Company identifies and prioritizes critical assets including:
- Production systems
- Customer databases
- Source code repositories
- Cloud infrastructure
- Internal business documentation
- Authentication systems
- Communication platforms
Protection of these assets is considered essential for business operations.
5. Backup Strategy
The Company maintains backup procedures designed to support recovery and business continuity.
Backup activities may include:
- Database backups
- Infrastructure configuration backups
- Application backups
- Source code repository backups
- Operational data backups
Backups are performed periodically according to operational requirements.
6. Backup Security
Backup data is protected using appropriate safeguards including:
- Access controls
- Authentication mechanisms
- Secure storage locations
- Encryption where appropriate
- Restricted administrative access
Only authorized personnel may access backup resources.
7. Recovery Procedures
Recovery procedures are maintained to restore systems and data following operational disruptions.
Recovery activities may include:
- Data restoration
- Service restoration
- Infrastructure rebuilding
- Credential recovery
- Configuration restoration
The Company seeks to restore critical services as quickly as reasonably possible.
8. Disaster Recovery
In the event of a major disruption, the Company may implement disaster recovery measures designed to:
- Restore critical business operations
- Recover essential data
- Minimize customer impact
- Maintain operational continuity
Recovery priorities are determined according to business impact and operational requirements.
9. Testing and Verification
The Company periodically reviews backup and recovery processes to ensure effectiveness.
Verification activities may include:
- Backup integrity checks
- Recovery testing
- Infrastructure reviews
- Operational assessments
Any identified issues are addressed through corrective actions.
10. Roles and Responsibilities
Management is responsible for ensuring adequate continuity and recovery capabilities.
Personnel are responsible for:
- Following established procedures
- Reporting operational issues
- Supporting recovery activities when required
Third-party providers may support continuity and recovery efforts where appropriate.
11. Continuous Improvement
The Company reviews continuity and recovery processes periodically and implements improvements where necessary.
Lessons learned from incidents, outages and operational reviews are incorporated into future planning.
12. Policy Review
This policy shall be reviewed annually or following significant operational, organizational or technological changes.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board