Security, backups & disaster recovery
Last updated: 28 August 2026
This policy describes how we approach information security, backups, and business continuity for ScaffOps™, Scaffolder Near Me (scaffoldernearme.co.uk), Scaff Connect™, ScaffSlot™, Scaff Exchange™, and related ScaffOps products. It supplements our terms of service and privacy policy. It is not a service-level agreement unless we agree one in writing.
1. Scope and intent
We implement measures we consider appropriate to the nature of the Platform and the data we process. No online service can guarantee absolute security, uninterrupted availability, or perfect recovery from every failure. You use the Platform at your own risk and should maintain your own backups of business-critical records.
2. Security measures
Depending on the service and environment, we may use measures such as:
- Encryption in transit (HTTPS/TLS) for web and API traffic
- Access controls, role-based permissions, and authentication for accounts
- Hosting with reputable cloud providers and infrastructure hardening
- Monitoring, logging, and abuse detection for suspicious activity
- Segregation between customer environments where the architecture supports it
- Review and patching of dependencies as part of normal development
You are responsible for protecting your login credentials, PINs, API keys, and devices used to access the Platform. Notify us promptly if you suspect unauthorised access.
3. Backups
- We may maintain automated backups of production databases and files to support recovery from accidental deletion, corruption, or infrastructure failure.
- Backup frequency, retention, and scope may change without notice as we adjust infrastructure.
- Backups are for our operational recovery — they are not a substitute for your own exports of quotes, compliance records, invoices, or other data you require for your business or legal obligations.
- We do not guarantee that any backup will be restorable, complete, or available for point-in-time recovery for a specific customer request.
4. Disaster recovery and availability
- We aim to restore core services after major incidents using commercially reasonable efforts, but we do not commit to specific recovery time (RTO) or recovery point (RPO) objectives unless agreed in a separate written contract.
- Planned or emergency maintenance, provider outages, network failures, cyber incidents, and force majeure events may cause downtime or degraded performance.
- Features labelled beta, preview, or experimental may be withdrawn or fail without prior notice.
5. Security incidents
If we become aware of a personal data breach likely to affect your rights, we will handle it in line with applicable law, which may include notifying you and/or the ICO where required. Our liability for incidents is subject to the limits in our terms of service.
6. Your responsibilities
- Export and archive records you need for tax, CDM, insurance, or contractual purposes
- Use strong, unique credentials and limit staff access appropriately
- Do not upload malware or attempt to probe or breach our systems
- Ensure data you upload complies with law and that you have rights to process it
7. Third-party services
The Platform relies on subprocessors (hosting, email, payments, messaging, AI, analytics, and others). Their security practices govern data they process on our behalf. See our privacy policy for categories of providers.
8. Changes
We may update this policy as our infrastructure and practices evolve. Material changes will be reflected in the last-updated date.