Tool-O

Tool-O

Incident Response Policy

This Incident Response Policy explains how Tool-O prepares for, responds to, manages and reviews operational, security and safety incidents affecting the Platform.

1. INTRODUCTION

1.1 Purpose

This Incident Response Policy explains how Tool-O prepares for, responds to, manages and reviews operational, security and safety incidents affecting the Platform.

The purpose of this Policy is to minimise disruption, protect Users, preserve Platform integrity and support timely and effective incident management.

1.2 Objectives

This Policy seeks to:

  • establish a structured incident response framework;
  • protect Users and Platform assets;
  • minimise operational disruption;
  • support timely investigation of incidents;
  • promote effective communication during incidents;
  • strengthen organisational resilience;
  • comply with applicable legal obligations.

1.3 Scope

This Policy applies to incidents affecting or relating to:

  • the Platform;
  • User Accounts;
  • Platform infrastructure;
  • payment systems;
  • Bookings;
  • communications;
  • information systems;
  • cyber security;
  • physical security where applicable;
  • third-party services supporting Platform operations.

1.4 Guiding Principles

Tool-O administers incident response in accordance with the following principles:

  • preparedness;
  • proportionality;
  • transparency;
  • accountability;
  • timely response;
  • continuous improvement.

1.5 Relationship with Other Policies

This Policy should be read together with the:

  • Business Continuity Policy;
  • Security Policy;
  • Platform Availability Policy;
  • Data Retention Policy;
  • Privacy Policy;
  • Trust & Safety Policy;
  • Marketplace Enforcement Policy;
  • all other Platform policies.

1.6 Updates

Tool-O may amend this Incident Response Policy from time to time.

The latest version published on the Platform replaces all previous versions.

2. INCIDENT RESPONSE

2.1 Incident Identification

Tool-O may identify incidents through:

  • User reports;
  • automated monitoring systems;
  • internal monitoring;
  • third-party service providers;
  • security alerts;
  • regulatory notifications;
  • operational reviews;
  • other reliable sources.

2.2 Types of Incidents

Incidents may include:

  • cyber security events;
  • system failures;
  • Platform outages;
  • payment processing issues;
  • unauthorised Account access;
  • fraud incidents;
  • data integrity issues;
  • service disruptions;
  • infrastructure failures;
  • other operational or security events affecting the Platform.

2.3 Initial Response

Upon becoming aware of an incident, Tool-O may take reasonable steps to:

  • assess the incident;
  • determine its severity;
  • contain immediate risks;
  • protect Users;
  • preserve relevant evidence;
  • initiate appropriate response procedures.

2.4 Incident Classification

Tool-O may classify incidents according to factors including:

  • operational impact;
  • User impact;
  • security implications;
  • legal obligations;
  • financial impact;
  • reputational risk;
  • urgency.

2.5 Containment

Where reasonably appropriate, Tool-O may implement measures to limit the impact of an incident, including:

  • restricting access;
  • isolating affected systems;
  • temporarily disabling affected services;
  • applying security controls;
  • suspending affected functionality;
  • implementing temporary operational procedures.

2.6 Investigation

Tool-O may investigate incidents by reviewing:

  • system logs;
  • Account activity;
  • Platform communications;
  • payment records;
  • technical information;
  • User reports;
  • security monitoring data;
  • other relevant evidence.

2.7 Incident Communications

Where reasonably appropriate, Tool-O may communicate with affected Users regarding:

  • significant service disruptions;
  • operational impacts;
  • recommended User actions;
  • restoration progress;
  • security guidance;
  • other relevant information.

Tool-O may limit communications where disclosure could compromise security, investigations or legal obligations.

2.8 Recovery

Following containment, Tool-O may take reasonable steps to restore affected services by:

  • repairing affected systems;
  • restoring Platform functionality;
  • validating system integrity;
  • monitoring system stability;
  • implementing corrective measures;
  • confirming operational readiness.

2.9 Post-Incident Review

Following significant incidents, Tool-O may conduct a review to identify:

  • contributing factors;
  • lessons learned;
  • process improvements;
  • security enhancements;
  • operational improvements;
  • preventative measures.

2.10 Continuous Improvement

Tool-O seeks to continually improve its incident response capabilities through ongoing planning, testing, operational reviews, security improvements and lessons learned from previous incidents.

3. INCIDENT MANAGEMENT

3.1 Roles and Responsibilities

Tool-O may allocate incident response responsibilities to appropriate personnel, service providers or authorised representatives based on:

  • the nature of the incident;
  • operational requirements;
  • technical expertise;
  • legal obligations;
  • business continuity requirements.

3.2 User Responsibilities

Users are encouraged to promptly report suspected incidents affecting the Platform, including:

  • suspected unauthorised Account access;
  • fraud;
  • security concerns;
  • technical faults;
  • payment issues;
  • other significant operational issues.

Users should provide accurate information to assist with investigation and response.

3.3 Preservation of Evidence

Where reasonably appropriate, Tool-O may preserve information relevant to an incident, including:

  • system logs;
  • transaction records;
  • Platform communications;
  • authentication records;
  • technical diagnostics;
  • other relevant evidence.

Evidence may be retained in accordance with applicable laws, the Privacy Policy and the Data Retention Policy.

3.4 Third-Party Coordination

Where an incident involves third-party providers, Tool-O may cooperate with those providers to:

  • investigate the incident;
  • restore affected services;
  • address technical issues;
  • improve security;
  • comply with contractual or legal obligations.

3.5 Regulatory and Legal Requirements

Where required by applicable law, Tool-O may:

  • notify relevant regulators;
  • cooperate with law enforcement agencies;
  • preserve evidence;
  • comply with court orders;
  • fulfil statutory reporting obligations.

3.6 Temporary Protective Measures

During an incident, Tool-O may implement temporary protective measures including:

  • Account restrictions;
  • password resets;
  • additional verification requirements;
  • temporary suspension of affected services;
  • payment safeguards;
  • enhanced monitoring.

Such measures are intended to reduce risk and do not necessarily indicate wrongdoing by any User.

3.7 Business Continuity

Where an incident significantly affects Platform operations, Tool-O may activate appropriate business continuity or disaster recovery procedures in accordance with the Business Continuity Policy.

3.8 External Communications

Public statements regarding significant incidents may be issued only by Tool-O or authorised representatives.

Users should not rely on unofficial communications regarding Platform incidents.

3.9 Documentation

Tool-O may maintain records relating to incidents, including:

  • incident reports;
  • investigation findings;
  • response actions;
  • recovery activities;
  • corrective measures;
  • lessons learned.

3.10 Responsible Incident Management

Tool-O seeks to manage incidents promptly, proportionately and effectively to minimise disruption, protect Users and strengthen the ongoing security, resilience and reliability of the Platform.

4. REVIEW, COMPLIANCE AND POLICY ADMINISTRATION

4.1 Governance

Tool-O is responsible for administering this Incident Response Policy and may maintain internal procedures, response plans and operational frameworks to support effective incident management.

4.2 Compliance

Tool-O seeks to manage incidents in accordance with applicable laws, regulatory requirements and recognised operational practices where appropriate.

Nothing in this Policy creates a guarantee regarding response times, recovery outcomes or uninterrupted Platform availability.

4.3 Policy Review

Tool-O may periodically review this Policy to reflect:

  • legislative changes;
  • regulatory guidance;
  • technological developments;
  • cyber security risks;
  • operational experience;
  • lessons learned from previous incidents;
  • evolving marketplace practices.

4.4 Testing and Preparedness

Tool-O may periodically review and test its incident response capabilities through activities including:

  • operational exercises;
  • response planning;
  • system testing;
  • disaster recovery testing;
  • security assessments;
  • procedural reviews.

The purpose of these activities is to improve preparedness and organisational resilience.

4.5 Continuous Improvement

Following reviews, testing or significant incidents, Tool-O may implement improvements including:

  • updated procedures;
  • enhanced monitoring;
  • improved security controls;
  • infrastructure enhancements;
  • revised communication processes;
  • additional staff training where appropriate.

4.6 Relationship with Other Policies

This Incident Response Policy should be read together with the:

  • Business Continuity Policy;
  • Security Policy;
  • Platform Availability Policy;
  • Privacy Policy;
  • Data Retention Policy;
  • Trust & Safety Policy;
  • Marketplace Enforcement Policy;
  • all other Platform policies.

Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.

4.7 Contact

Questions regarding this Incident Response Policy may be directed to Tool-O using the contact details published on the Platform.

4.8 Policy Updates

Tool-O may amend this Incident Response Policy from time to time.

The latest version published on the Platform replaces all previous versions.

4.9 Commitment

Tool-O is committed to responding to incidents in a timely, responsible and proportionate manner while protecting Users, maintaining Platform integrity and supporting the continued reliability and resilience of the marketplace.

4.10 Final Statement

Effective incident management is an essential component of maintaining a secure and dependable marketplace.

By maintaining structured response procedures, promoting continuous improvement and learning from operational experience, Tool-O seeks to minimise disruption and strengthen the long-term resilience of the Platform.

END OF INCIDENT RESPONSE POLICY

Related documents