This policy describes the backup, data protection, and security practices applied by WebDraco across its website and all WebDraco software solutions and related services (collectively, the “Services”).
Effective Date: January 2026 · Version: 2.0
Email: security@webdraco.com · Legal notice
1. Purpose and scope
The purpose of this Backup & Security Policy is to define baseline measures used by WebDraco to protect customer data, support service continuity, and reduce operational risk.
This policy applies to all WebDraco Services, including cloud-hosted, managed, and self-hosted (on-premise) deployments, subject to the Customer’s selected service layer and contractual terms.
2. Shared responsibility model
Security and data protection follow a shared responsibility model:
- WebDraco is responsible for the security of the software, managed infrastructure (where applicable), and operational processes under its control.
- The Customer is responsible for access control, credential management, endpoint security, and compliance with internal policies, especially in self-hosted deployments.
3. Backup policy
3.1 Managed / Cloud services
- Automated backups are performed on a schedule appropriate to the Service.
- Backups typically include application data, configuration, and essential metadata.
- Backups are stored encrypted and segregated from primary production systems.
- Typical retention period: up to 30 days, unless otherwise agreed in writing.
3.2 Self-hosted (On-Premise) deployments
- The Customer is primarily responsible for implementing and maintaining backups.
- WebDraco may provide guidance or best practices, but does not guarantee data recovery unless backup services are explicitly contracted.
Backup availability and retention may vary by service layer and are not intended as a substitute for the Customer’s own business continuity planning.
4. Data restoration
- Restoration requests must be submitted through official support channels.
- Restores are handled on a best-effort basis within the applicable support plan.
- Granular restores (single records or transactions) may not be technically feasible.
- WebDraco does not guarantee restoration to a specific point in time unless explicitly contracted.
5. Security controls
5.1 Technical measures
- Encrypted communications using HTTPS / TLS (1.2 or higher).
- Encrypted storage and encrypted backups where supported by the Service.
- Role-based access control (RBAC) and least-privilege principles.
- Audit logging for critical system actions.
5.2 Organizational measures
- Restricted access to production systems for authorized personnel only.
- Confidentiality obligations for employees and contractors.
- Periodic security reviews and risk assessments.
6. Access management
- Administrative access is limited to trained personnel with a legitimate operational need.
- Multi-factor authentication (MFA) is used where technically feasible.
- Access rights are reviewed periodically and revoked upon role changes or termination.
7. Security incident response
WebDraco maintains procedures to detect, assess, and respond to security incidents.
- Incidents are logged, investigated, and mitigated in a timely manner.
- For personal data breaches, notifications are made in accordance with GDPR requirements.
- Customers may be informed of material incidents affecting their data or service availability.
8. Business continuity and availability
WebDraco designs its Services with resilience in mind, including redundancy where appropriate. However, no system is entirely immune to failures or force majeure events.
Availability commitments, if any, are defined exclusively in the applicable Service Level Agreement (SLA).
9. Limitations
- This policy does not constitute an unconditional guarantee of data preservation.
- WebDraco is not responsible for data loss caused by Customer actions, third-party integrations, or factors outside WebDraco’s reasonable control.
- Customers remain responsible for maintaining independent backups where required by their risk profile.
- WebDraco does not provide legal advice, tax advice, accounting certification, statutory audit services, or regulatory certification unless expressly agreed in a separate written engagement.
10. Governing Law and Jurisdiction
This Backup & Security Policy is governed by the laws of the Kingdom of the Netherlands. Any disputes shall be subject to the exclusive jurisdiction of the courts of the Netherlands.
11. Changes to this policy
WebDraco may update this Backup & Security Policy to reflect changes in technology, legal requirements, or operational practices. The current version is always published on the WebDraco website.
Contact
For security, backup, or incident-related inquiries:
📧 security@webdraco.com
🌐 www.webdraco.com
“Security is not a feature. It is a discipline.”
