Security & Compliance

Backup Policy

The backup practices that protect Skoolfly data from loss and enable recovery.

1. Policy Statement

Skoolfly maintains reliable backup and recovery arrangements to protect data against accidental loss, corruption, deletion and disasters. This policy defines what is backed up, how often, where backups are stored and how restoration is verified.

2. Purpose

The purpose of this policy is to ensure that critical data can be restored within defined timeframes following an incident, and to support the objectives of the Disaster Recovery Policy and the Incident Response Policy.

3. Scope

This policy applies to all production data and configuration used to operate the Skoolfly platform, including databases, file storage, application configuration, administrative records and any data stored on behalf of schools and users.

4. Backup Principles

Critical data is backed up automatically on a defined schedule.

Backups are held separately from primary data to survive primary-system failure.

Backups are protected by the same access and encryption controls as primary data, including encryption in transit and at rest where appropriate.

Restoration is tested regularly to confirm backups are usable.

Backup integrity is monitored, and failures are alerted and resolved.

5. Data Covered

Backups cover databases and structured records, uploaded content and files, application configuration, and essential business records. Ephemeral or non-critical data may be excluded where its loss does not materially affect operations.

6. Backup Schedule

Databases & structured recordsContinuous or frequent backup, with periodic snapshots.
Uploaded files & contentFrequent backup to a reliable storage target.
Configuration & infrastructure stateBacked up on change and periodically.
Long-term / archive copiesDefined in the Data Retention Policy.

7. Storage and Security

Backups are stored in secure, redundant storage, staged off-site or in a different location where practical.

A copy suitable for recovery is kept in a separate environment from production.

Backup access is restricted to authorised personnel and logged.

Backup data is not used as a substitute for lawful access control or retention compliance.

8. Testing and Restoration

Restoration is tested at least periodically to confirm data can be recovered.

Tests validate data integrity, completeness and restoration time.

Failed tests are treated as incidents and escalated.

9. Monitoring and Alerts

Backup jobs are monitored for success and failure. Failures are alerted and investigated promptly, and missed backups are addressed before the next scheduled run where possible.

10. Roles and Responsibilities

DevOps / InfrastructureOperate backup systems, monitor jobs and execute restoration.
EngineeringEnsure application data is backup-compatible and reproduce data loss conditions.
Security OwnerOversees policy compliance and tests.

11. Compliance and Enforcement

Backup coverage and restoration tests are reviewed regularly. Non-compliance is corrected promptly and reported where material.

12. Review

This policy is reviewed at least annually, or when significant changes to systems, data volumes or recovery requirements occur.