Tool-O
Incident Response Policy
This Incident Response Policy explains how Tool-O prepares for, responds to, manages and reviews operational, security and safety incidents affecting the Platform.
1. INTRODUCTION
1.1 Purpose
This Incident Response Policy explains how Tool-O prepares for, responds to, manages and reviews operational, security and safety incidents affecting the Platform.
The purpose of this Policy is to minimise disruption, protect Users, preserve Platform integrity and support timely and effective incident management.
1.2 Objectives
This Policy seeks to:
- establish a structured incident response framework;
- protect Users and Platform assets;
- minimise operational disruption;
- support timely investigation of incidents;
- promote effective communication during incidents;
- strengthen organisational resilience;
- comply with applicable legal obligations.
1.3 Scope
This Policy applies to incidents affecting or relating to:
- the Platform;
- User Accounts;
- Platform infrastructure;
- payment systems;
- Bookings;
- communications;
- information systems;
- cyber security;
- physical security where applicable;
- third-party services supporting Platform operations.
1.4 Guiding Principles
Tool-O administers incident response in accordance with the following principles:
- preparedness;
- proportionality;
- transparency;
- accountability;
- timely response;
- continuous improvement.
1.5 Relationship with Other Policies
This Policy should be read together with the:
- Business Continuity Policy;
- Security Policy;
- Platform Availability Policy;
- Data Retention Policy;
- Privacy Policy;
- Trust & Safety Policy;
- Marketplace Enforcement Policy;
- all other Platform policies.
1.6 Updates
Tool-O may amend this Incident Response Policy from time to time.
The latest version published on the Platform replaces all previous versions.
2. INCIDENT RESPONSE
2.1 Incident Identification
Tool-O may identify incidents through:
- User reports;
- automated monitoring systems;
- internal monitoring;
- third-party service providers;
- security alerts;
- regulatory notifications;
- operational reviews;
- other reliable sources.
2.2 Types of Incidents
Incidents may include:
- cyber security events;
- system failures;
- Platform outages;
- payment processing issues;
- unauthorised Account access;
- fraud incidents;
- data integrity issues;
- service disruptions;
- infrastructure failures;
- other operational or security events affecting the Platform.
2.3 Initial Response
Upon becoming aware of an incident, Tool-O may take reasonable steps to:
- assess the incident;
- determine its severity;
- contain immediate risks;
- protect Users;
- preserve relevant evidence;
- initiate appropriate response procedures.
2.4 Incident Classification
Tool-O may classify incidents according to factors including:
- operational impact;
- User impact;
- security implications;
- legal obligations;
- financial impact;
- reputational risk;
- urgency.
2.5 Containment
Where reasonably appropriate, Tool-O may implement measures to limit the impact of an incident, including:
- restricting access;
- isolating affected systems;
- temporarily disabling affected services;
- applying security controls;
- suspending affected functionality;
- implementing temporary operational procedures.
2.6 Investigation
Tool-O may investigate incidents by reviewing:
- system logs;
- Account activity;
- Platform communications;
- payment records;
- technical information;
- User reports;
- security monitoring data;
- other relevant evidence.
2.7 Incident Communications
Where reasonably appropriate, Tool-O may communicate with affected Users regarding:
- significant service disruptions;
- operational impacts;
- recommended User actions;
- restoration progress;
- security guidance;
- other relevant information.
Tool-O may limit communications where disclosure could compromise security, investigations or legal obligations.
2.8 Recovery
Following containment, Tool-O may take reasonable steps to restore affected services by:
- repairing affected systems;
- restoring Platform functionality;
- validating system integrity;
- monitoring system stability;
- implementing corrective measures;
- confirming operational readiness.
2.9 Post-Incident Review
Following significant incidents, Tool-O may conduct a review to identify:
- contributing factors;
- lessons learned;
- process improvements;
- security enhancements;
- operational improvements;
- preventative measures.
2.10 Continuous Improvement
Tool-O seeks to continually improve its incident response capabilities through ongoing planning, testing, operational reviews, security improvements and lessons learned from previous incidents.
3. INCIDENT MANAGEMENT
3.1 Roles and Responsibilities
Tool-O may allocate incident response responsibilities to appropriate personnel, service providers or authorised representatives based on:
- the nature of the incident;
- operational requirements;
- technical expertise;
- legal obligations;
- business continuity requirements.
3.2 User Responsibilities
Users are encouraged to promptly report suspected incidents affecting the Platform, including:
- suspected unauthorised Account access;
- fraud;
- security concerns;
- technical faults;
- payment issues;
- other significant operational issues.
Users should provide accurate information to assist with investigation and response.
3.3 Preservation of Evidence
Where reasonably appropriate, Tool-O may preserve information relevant to an incident, including:
- system logs;
- transaction records;
- Platform communications;
- authentication records;
- technical diagnostics;
- other relevant evidence.
Evidence may be retained in accordance with applicable laws, the Privacy Policy and the Data Retention Policy.
3.4 Third-Party Coordination
Where an incident involves third-party providers, Tool-O may cooperate with those providers to:
- investigate the incident;
- restore affected services;
- address technical issues;
- improve security;
- comply with contractual or legal obligations.
3.5 Regulatory and Legal Requirements
Where required by applicable law, Tool-O may:
- notify relevant regulators;
- cooperate with law enforcement agencies;
- preserve evidence;
- comply with court orders;
- fulfil statutory reporting obligations.
3.6 Temporary Protective Measures
During an incident, Tool-O may implement temporary protective measures including:
- Account restrictions;
- password resets;
- additional verification requirements;
- temporary suspension of affected services;
- payment safeguards;
- enhanced monitoring.
Such measures are intended to reduce risk and do not necessarily indicate wrongdoing by any User.
3.7 Business Continuity
Where an incident significantly affects Platform operations, Tool-O may activate appropriate business continuity or disaster recovery procedures in accordance with the Business Continuity Policy.
3.8 External Communications
Public statements regarding significant incidents may be issued only by Tool-O or authorised representatives.
Users should not rely on unofficial communications regarding Platform incidents.
3.9 Documentation
Tool-O may maintain records relating to incidents, including:
- incident reports;
- investigation findings;
- response actions;
- recovery activities;
- corrective measures;
- lessons learned.
3.10 Responsible Incident Management
Tool-O seeks to manage incidents promptly, proportionately and effectively to minimise disruption, protect Users and strengthen the ongoing security, resilience and reliability of the Platform.
4. REVIEW, COMPLIANCE AND POLICY ADMINISTRATION
4.1 Governance
Tool-O is responsible for administering this Incident Response Policy and may maintain internal procedures, response plans and operational frameworks to support effective incident management.
4.2 Compliance
Tool-O seeks to manage incidents in accordance with applicable laws, regulatory requirements and recognised operational practices where appropriate.
Nothing in this Policy creates a guarantee regarding response times, recovery outcomes or uninterrupted Platform availability.
4.3 Policy Review
Tool-O may periodically review this Policy to reflect:
- legislative changes;
- regulatory guidance;
- technological developments;
- cyber security risks;
- operational experience;
- lessons learned from previous incidents;
- evolving marketplace practices.
4.4 Testing and Preparedness
Tool-O may periodically review and test its incident response capabilities through activities including:
- operational exercises;
- response planning;
- system testing;
- disaster recovery testing;
- security assessments;
- procedural reviews.
The purpose of these activities is to improve preparedness and organisational resilience.
4.5 Continuous Improvement
Following reviews, testing or significant incidents, Tool-O may implement improvements including:
- updated procedures;
- enhanced monitoring;
- improved security controls;
- infrastructure enhancements;
- revised communication processes;
- additional staff training where appropriate.
4.6 Relationship with Other Policies
This Incident Response Policy should be read together with the:
- Business Continuity Policy;
- Security Policy;
- Platform Availability Policy;
- Privacy Policy;
- Data Retention Policy;
- Trust & Safety Policy;
- Marketplace Enforcement Policy;
- all other Platform policies.
Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.
4.7 Contact
Questions regarding this Incident Response Policy may be directed to Tool-O using the contact details published on the Platform.
4.8 Policy Updates
Tool-O may amend this Incident Response Policy from time to time.
The latest version published on the Platform replaces all previous versions.
4.9 Commitment
Tool-O is committed to responding to incidents in a timely, responsible and proportionate manner while protecting Users, maintaining Platform integrity and supporting the continued reliability and resilience of the marketplace.
4.10 Final Statement
Effective incident management is an essential component of maintaining a secure and dependable marketplace.
By maintaining structured response procedures, promoting continuous improvement and learning from operational experience, Tool-O seeks to minimise disruption and strengthen the long-term resilience of the Platform.
END OF INCIDENT RESPONSE POLICY
