Legal document
Business Continuity Plan
How Desklly maintains service to dental practices during disruption, and how we recover from major incidents.
1. Objectives
Maintain call-answering service for practices even under adverse conditions, meet recovery objectives, and protect people and data throughout.
2. Recovery objectives
Recovery Time Objective (RTO) for the core call-answering service: 1 hour. Recovery Point Objective (RPO): 15 minutes for transactional data; 24 hours for analytics.
3. High availability
Production runs across multiple availability zones in a UK cloud region with automated failover. Telephony is multi-carrier with automatic re-routing on carrier failure. Practice management system integrations are queued and retried on transient failure.
4. Backups
Encrypted, geographically-separated backups every 15 minutes for the primary database and continuous for object storage. Backups are tested by automated restore at least monthly.
5. Loss-of-service scenarios
Documented playbooks cover: cloud region failure, DNS provider failure, upstream telephony failure, PMS integration failure, ransomware, and prolonged staff unavailability.
6. Communications
During a major incident the status page (status.desklly.ai) is updated at least every 30 minutes. Customers are informed by email for any incident exceeding 30 minutes. Practices retain the ability to divert calls back to their existing phone line at any time.
7. Alternative processing
Where the AI service is degraded, calls automatically fall back to a human-operated overflow message or, at the practice's option, to the practice's existing voicemail or on-call number.
8. Testing
Failover, restore, and full BCP tabletop exercises are conducted at least annually. Findings are tracked to closure.
9. Review
This plan is reviewed annually and after any material incident or change in the technology stack.
