Business Continuity & Disaster Recovery

Ensuring operational resilience and service continuity through proportionate planning and tested backups

Last Updated: September 2026

Program Overview

POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Business Continuity and Disaster Recovery (BC/DR) program designed to ensure operational resilience and minimal service disruption in the face of adverse events. Our program is proportionate to a small company operating a single-server platform.

Key Objectives

  • Service Continuity: Maintain critical operations during and after disruptive events
  • Data Protection: Limit data loss to at most one day (daily encrypted backups)
  • Rapid Recovery: Recovery is by restoring the latest backup to a rebuilt server
  • Stakeholder Communication: Maintain transparent communication with clients and partners
  • Regulatory Compliance: Meet all applicable business continuity requirements

Recovery Time & Point Objectives

Critical Systems (Tier 1)

Recovery Time Objective (RTO)

4–8 hours

Recovery Point Objective (RPO)

24 hours

Systems: feed/ad delivery, publisher dashboard, API

Important Systems (Tier 2)

Recovery Time Objective (RTO)

8–24 hours

Recovery Point Objective (RPO)

24 hours

Systems: Reporting dashboards, analytics platform, customer portal, API services

Standard Systems (Tier 3)

Recovery Time Objective (RTO)

24–48 hours

Recovery Point Objective (RPO)

24 hours

Systems: Email services, internal tools, documentation, support ticketing

Infrastructure Resilience

Hosting Architecture

  • Hosting Region: Single-region hosting (United States) behind a global CDN/edge network
  • Recovery Model: Recovery is by restoring the latest backup to a rebuilt server

Cloud Infrastructure

  • Cloud Provider: Enterprise-grade cloud infrastructure under the provider’s SLA, with daily encrypted off-site database backups
  • Server: Single virtual server; capacity is resized manually
  • CDN Integration: Global content delivery network for static assets and edge caching

Network Redundancy

  • Network, DNS & DDoS: Network, DNS and DDoS mitigation are provided by our CDN/edge provider

Data Protection & Backup Systems

Database Recovery

  • Recovery Model: Recovery is by restoring the latest backup to a rebuilt server

Backup Strategy

  • Full Daily Backups: Complete database backups at 02:30 UTC daily
  • Encrypted at Rest: All backups encrypted with AES-256 encryption
  • Storage Locations: Backups are stored on attached block storage and pushed to a separate off-site location

Backup Testing & Validation

  • Restore Tests: Restores are tested periodically and results recorded

Backup Retention Policy

Operational Backups

  • Daily backups retained 14 days locally plus the off-site copy

Compliance Archives

  • Financial data: 7 years
  • Transaction logs: 7 years
  • Customer records: 7 years after closure

Incident Response Procedures

Phase 1: Detection & Assessment (as soon as practicable, target within 4 hours)

  • Automated monitoring alerts the operator
  • Initial assessment of incident severity and scope
  • Activation of incident response team based on severity classification
  • Documentation begins in incident management system

Phase 2: Containment

  • Isolate affected systems to prevent spread of impact
  • Begin restoring the latest backup to a rebuilt server where required
  • Begin preliminary root cause investigation
  • Initial stakeholder notification if service impact expected

Phase 3: Recovery (within the RTO for the affected tier)

  • Execute appropriate recovery procedures based on incident type
  • Restore services from backups if necessary
  • Validate system functionality and data integrity
  • Gradual restoration of traffic to recovered systems

Phase 4: Post-Incident (1-24 hours)

  • Complete root cause analysis and documentation
  • Post-incident review meeting within 24 hours
  • Implementation of corrective actions to prevent recurrence
  • Final stakeholder communication with incident summary

Stakeholder Communication Plan

Internal Communication

  • Alerting: Automated monitoring alerts the operator
  • Contractors: Notified by email or messaging where their help is needed

External Communication

  • Status Page: Updates on pops.gg/status for service availability
  • Customer Notifications: Email and dashboard alerts for affected customers as soon as practicable, normally within 24 hours
  • Regulators: Notification as required by applicable regulations (GDPR breach notification within 72 hours)
  • Public Updates: Updates during extended incidents as soon as practicable, normally within 24 hours

Communication Templates

Pre-approved communication templates for rapid stakeholder notification:

  • Initial incident notification
  • Service disruption alert
  • Recovery progress update
  • Service restoration confirmation
  • Post-incident summary report

Testing & Maintenance Program

Regular Testing Schedule

  • Annual: Annual restore test from backup
  • Annual: Comprehensive BC/DR plan review and update

Test Documentation

  • Detailed test plans with success criteria defined in advance
  • Test results documented with actual vs. expected outcomes
  • Issues identified during testing tracked to resolution
  • Reviewed annually by the company director

Continuous Improvement

  • Lessons learned from tests incorporated into plan updates
  • Industry best practices monitored and adopted
  • Regular review of RTO/RPO targets against business needs
  • Technology upgrades evaluated for improved resilience

Third-Party Service Resilience

We rely on our providers’ published SLAs and status pages; there is one CDN/DNS provider:

  • Cloud Infrastructure: Provider SLAs, daily encrypted off-site backups, and a public live status page
  • CDN / DNS Provider: Single provider; we rely on its published SLA and status page
  • Payment Providers: Third-party providers under their own SLAs; no card data is stored by us
  • Regular Reviews: Annual review of all third-party BC/DR capabilities

Governance & Oversight

Roles & Responsibilities

  • Company Director: All roles are held by the company director (program management, technical recovery, stakeholder communication)
  • Contractors: May assist with technical recovery under the director’s instruction

Plan Maintenance

  • BC/DR plan reviewed and updated quarterly
  • Contact information verified monthly
  • Technology changes trigger plan updates within 30 days
  • Version control maintained for all plan documents
  • Reviewed annually by the company director

Certifications & Compliance

  • Reviewed annually by the company director
  • UK GDPR-compliant data recovery and breach notification procedures

Contact Information

For questions regarding our Business Continuity & Disaster Recovery program:

Company Director

CASH.BH LTD

71–75 Shelton Street, Covent Garden

London, WC2H 9JQ, United Kingdom

Email: operations@pops.gg

Incidents: operations@pops.gg