Business Continuity & Disaster Recovery
Ensuring operational resilience and service continuity through proportionate planning and tested backups
Last Updated: September 2026
Program Overview
POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Business Continuity and Disaster Recovery (BC/DR) program designed to ensure operational resilience and minimal service disruption in the face of adverse events. Our program is proportionate to a small company operating a single-server platform.
Key Objectives
- Service Continuity: Maintain critical operations during and after disruptive events
- Data Protection: Limit data loss to at most one day (daily encrypted backups)
- Rapid Recovery: Recovery is by restoring the latest backup to a rebuilt server
- Stakeholder Communication: Maintain transparent communication with clients and partners
- Regulatory Compliance: Meet all applicable business continuity requirements
Recovery Time & Point Objectives
Critical Systems (Tier 1)
Recovery Time Objective (RTO)
4–8 hours
Recovery Point Objective (RPO)
24 hours
Systems: feed/ad delivery, publisher dashboard, API
Important Systems (Tier 2)
Recovery Time Objective (RTO)
8–24 hours
Recovery Point Objective (RPO)
24 hours
Systems: Reporting dashboards, analytics platform, customer portal, API services
Standard Systems (Tier 3)
Recovery Time Objective (RTO)
24–48 hours
Recovery Point Objective (RPO)
24 hours
Systems: Email services, internal tools, documentation, support ticketing
Infrastructure Resilience
Hosting Architecture
- Hosting Region: Single-region hosting (United States) behind a global CDN/edge network
- Recovery Model: Recovery is by restoring the latest backup to a rebuilt server
Cloud Infrastructure
- Cloud Provider: Enterprise-grade cloud infrastructure under the provider’s SLA, with daily encrypted off-site database backups
- Server: Single virtual server; capacity is resized manually
- CDN Integration: Global content delivery network for static assets and edge caching
Network Redundancy
- Network, DNS & DDoS: Network, DNS and DDoS mitigation are provided by our CDN/edge provider
Data Protection & Backup Systems
Database Recovery
- Recovery Model: Recovery is by restoring the latest backup to a rebuilt server
Backup Strategy
- Full Daily Backups: Complete database backups at 02:30 UTC daily
- Encrypted at Rest: All backups encrypted with AES-256 encryption
- Storage Locations: Backups are stored on attached block storage and pushed to a separate off-site location
Backup Testing & Validation
- Restore Tests: Restores are tested periodically and results recorded
Backup Retention Policy
Operational Backups
- Daily backups retained 14 days locally plus the off-site copy
Compliance Archives
- Financial data: 7 years
- Transaction logs: 7 years
- Customer records: 7 years after closure
Incident Response Procedures
Phase 1: Detection & Assessment (as soon as practicable, target within 4 hours)
- Automated monitoring alerts the operator
- Initial assessment of incident severity and scope
- Activation of incident response team based on severity classification
- Documentation begins in incident management system
Phase 2: Containment
- Isolate affected systems to prevent spread of impact
- Begin restoring the latest backup to a rebuilt server where required
- Begin preliminary root cause investigation
- Initial stakeholder notification if service impact expected
Phase 3: Recovery (within the RTO for the affected tier)
- Execute appropriate recovery procedures based on incident type
- Restore services from backups if necessary
- Validate system functionality and data integrity
- Gradual restoration of traffic to recovered systems
Phase 4: Post-Incident (1-24 hours)
- Complete root cause analysis and documentation
- Post-incident review meeting within 24 hours
- Implementation of corrective actions to prevent recurrence
- Final stakeholder communication with incident summary
Stakeholder Communication Plan
Internal Communication
- Alerting: Automated monitoring alerts the operator
- Contractors: Notified by email or messaging where their help is needed
External Communication
- Status Page: Updates on pops.gg/status for service availability
- Customer Notifications: Email and dashboard alerts for affected customers as soon as practicable, normally within 24 hours
- Regulators: Notification as required by applicable regulations (GDPR breach notification within 72 hours)
- Public Updates: Updates during extended incidents as soon as practicable, normally within 24 hours
Communication Templates
Pre-approved communication templates for rapid stakeholder notification:
- Initial incident notification
- Service disruption alert
- Recovery progress update
- Service restoration confirmation
- Post-incident summary report
Testing & Maintenance Program
Regular Testing Schedule
- Annual: Annual restore test from backup
- Annual: Comprehensive BC/DR plan review and update
Test Documentation
- Detailed test plans with success criteria defined in advance
- Test results documented with actual vs. expected outcomes
- Issues identified during testing tracked to resolution
- Reviewed annually by the company director
Continuous Improvement
- Lessons learned from tests incorporated into plan updates
- Industry best practices monitored and adopted
- Regular review of RTO/RPO targets against business needs
- Technology upgrades evaluated for improved resilience
Third-Party Service Resilience
We rely on our providers’ published SLAs and status pages; there is one CDN/DNS provider:
- Cloud Infrastructure: Provider SLAs, daily encrypted off-site backups, and a public live status page
- CDN / DNS Provider: Single provider; we rely on its published SLA and status page
- Payment Providers: Third-party providers under their own SLAs; no card data is stored by us
- Regular Reviews: Annual review of all third-party BC/DR capabilities
Governance & Oversight
Roles & Responsibilities
- Company Director: All roles are held by the company director (program management, technical recovery, stakeholder communication)
- Contractors: May assist with technical recovery under the director’s instruction
Plan Maintenance
- BC/DR plan reviewed and updated quarterly
- Contact information verified monthly
- Technology changes trigger plan updates within 30 days
- Version control maintained for all plan documents
- Reviewed annually by the company director
Certifications & Compliance
- Reviewed annually by the company director
- UK GDPR-compliant data recovery and breach notification procedures
Contact Information
For questions regarding our Business Continuity & Disaster Recovery program:
Company Director
CASH.BH LTD
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Email: operations@pops.gg
Incidents: operations@pops.gg