Legal document

Business Continuity Plan

How Desklly maintains service to dental practices during disruption, and how we recover from major incidents.

Version 1.0Last updated 7 July 2026Governing law England & Wales

1. Objectives

Maintain call-answering service for practices even under adverse conditions, meet recovery objectives, and protect people and data throughout.

2. Recovery objectives

Recovery Time Objective (RTO) for the core call-answering service: 1 hour. Recovery Point Objective (RPO): 15 minutes for transactional data; 24 hours for analytics.

3. High availability

Production runs across multiple availability zones in a UK cloud region with automated failover. Telephony is multi-carrier with automatic re-routing on carrier failure. Practice management system integrations are queued and retried on transient failure.

4. Backups

Encrypted, geographically-separated backups every 15 minutes for the primary database and continuous for object storage. Backups are tested by automated restore at least monthly.

5. Loss-of-service scenarios

Documented playbooks cover: cloud region failure, DNS provider failure, upstream telephony failure, PMS integration failure, ransomware, and prolonged staff unavailability.

6. Communications

During a major incident the status page (status.desklly.ai) is updated at least every 30 minutes. Customers are informed by email for any incident exceeding 30 minutes. Practices retain the ability to divert calls back to their existing phone line at any time.

7. Alternative processing

Where the AI service is degraded, calls automatically fall back to a human-operated overflow message or, at the practice's option, to the practice's existing voicemail or on-call number.

8. Testing

Failover, restore, and full BCP tabletop exercises are conducted at least annually. Findings are tracked to closure.

9. Review

This plan is reviewed annually and after any material incident or change in the technology stack.