Tool-O
Vendor and Third-Party Services Policy
This Vendor & Third-Party Services Policy explains how Tool-O manages relationships with third-party service providers that support the operation of the Platform.
1. INTRODUCTION
1.1 Purpose
This Vendor & Third-Party Services Policy explains how Tool-O manages relationships with third-party service providers that support the operation of the Platform.
The purpose of this Policy is to promote responsible governance of third-party services, protect Users and reduce operational, security and compliance risks associated with external providers.
1.2 Objectives
This Policy seeks to:
- promote responsible vendor management;
- support reliable Platform operations;
- protect User information;
- reduce third-party risks;
- encourage appropriate due diligence;
- strengthen operational resilience;
- comply with applicable legal obligations.
1.3 Scope
This Policy applies to third-party providers supporting Platform operations, including providers of:
- cloud infrastructure;
- payment services;
- identity verification;
- communications;
- hosting;
- mapping services;
- analytics;
- artificial intelligence services;
- customer support services;
- software development tools;
- cybersecurity services;
- other operational services.
1.4 Guiding Principles
Tool-O administers third-party relationships in accordance with the following principles:
- accountability;
- transparency;
- security;
- reliability;
- proportionality;
- continuous improvement.
1.5 Relationship with Other Policies
This Policy should be read together with the:
- Privacy Policy;
- Security Policy;
- Risk Management Policy;
- Platform Availability Policy;
- Business Continuity Policy;
- Payment & Payout Policy;
- Terms of Use;
- all other Platform policies.
1.6 Updates
Tool-O may amend this Vendor & Third-Party Services Policy from time to time.
The latest version published on the Platform replaces all previous versions.
2. VENDOR MANAGEMENT
2.1 Selection of Vendors
Tool-O may select third-party service providers after considering factors including:
- reliability;
- security;
- operational capability;
- legal compliance;
- reputation;
- technical compatibility;
- business continuity capability;
- other relevant operational considerations.
2.2 Due Diligence
Where reasonably appropriate, Tool-O may undertake due diligence before engaging third-party providers by reviewing matters including:
- security practices;
- privacy practices;
- operational resilience;
- regulatory compliance;
- contractual commitments;
- service capabilities;
- other relevant risk factors.
2.3 Categories of Third-Party Services
Third-party providers may support Platform functions including:
- payment processing;
- cloud hosting;
- identity verification;
- email delivery;
- SMS and notification services;
- mapping and geolocation services;
- artificial intelligence services;
- analytics;
- cybersecurity monitoring;
- customer support;
- software development;
- other operational services.
2.4 User Information
Where necessary for Platform operations, Tool-O may provide limited information to third-party providers in accordance with:
- the Privacy Policy;
- applicable laws;
- contractual obligations;
- reasonable operational requirements.
Tool-O seeks to limit information shared to that which is reasonably necessary for the relevant service.
2.5 Vendor Security
Tool-O seeks to engage third-party providers that maintain security practices reasonably appropriate to the services they provide.
However, Tool-O does not control the internal operations of independent third-party providers.
2.6 Service Interruptions
Platform functionality may be affected where third-party providers experience:
- outages;
- security incidents;
- maintenance activities;
- operational failures;
- network disruptions;
- other service interruptions.
Tool-O will seek to minimise the impact of such interruptions where reasonably practicable.
2.7 Vendor Changes
Tool-O may replace, remove or introduce third-party providers from time to time where reasonably necessary for:
- operational improvements;
- security;
- performance;
- regulatory compliance;
- business continuity;
- User experience.
2.8 User Responsibilities
Users acknowledge that certain Platform functionality depends upon third-party providers and that those providers may have their own:
- terms and conditions;
- privacy policies;
- operational practices;
- service limitations.
Users may be required to comply with applicable third-party requirements when using relevant Platform functionality.
2.9 Monitoring
Tool-O may periodically review third-party service providers to assess:
- operational performance;
- security;
- reliability;
- compliance;
- contractual performance;
- other relevant operational factors.
2.10 Commitment to Responsible Vendor Management
Tool-O seeks to engage and manage third-party providers responsibly to support secure, reliable and efficient Platform operations while continually reviewing vendor performance and operational risks.
3. VENDOR GOVERNANCE
3.1 Vendor Oversight
Tool-O may maintain governance processes for the ongoing oversight of third-party service providers, including periodic reviews of:
- operational performance;
- security practices;
- service reliability;
- legal compliance;
- contractual obligations;
- risk management.
3.2 Risk Assessment
Tool-O may assess risks associated with third-party providers by considering:
- information security;
- privacy protections;
- business continuity capability;
- operational resilience;
- regulatory compliance;
- financial stability where appropriate;
- geographic or jurisdictional risks;
- dependency on the provider.
3.3 Contractual Arrangements
Where reasonably appropriate, Tool-O may enter into contractual arrangements with third-party providers addressing matters including:
- confidentiality;
- privacy;
- information security;
- service standards;
- legal compliance;
- termination rights;
- other operational requirements.
3.4 Incident Management
Where a third-party provider experiences a security incident, service interruption or other operational issue that may affect the Platform, Tool-O may:
- assess the impact;
- cooperate with the provider;
- implement temporary mitigation measures;
- communicate with affected Users where appropriate;
- activate relevant business continuity procedures;
- review future risk management measures.
3.5 Compliance Monitoring
Tool-O may periodically review whether third-party providers continue to satisfy operational, legal and security expectations relevant to the services they provide.
Where concerns arise, Tool-O may request additional information or implement appropriate risk mitigation measures.
3.6 Data Protection
Where third-party providers process Personal Information on behalf of Tool-O, Tool-O seeks to ensure that such processing occurs in accordance with:
- applicable privacy laws;
- contractual obligations;
- the Privacy Policy;
- reasonable information security practices.
3.7 Service Changes
Third-party providers may update, modify or discontinue their services from time to time.
Tool-O may adapt Platform functionality, replace providers or implement alternative operational arrangements where reasonably necessary.
3.8 Record Keeping
Tool-O may maintain records relating to third-party service providers, including:
- vendor assessments;
- contractual documentation;
- operational reviews;
- security assessments;
- incident records;
- performance monitoring;
- other governance records.
Records may be retained in accordance with the Data Retention Policy and applicable laws.
3.9 User Awareness
Users acknowledge that certain Platform features depend upon independent third-party providers whose services remain subject to their own operational practices and availability.
Tool-O cannot guarantee the continuous availability or performance of independent third-party services.
3.10 Commitment to Responsible Vendor Governance
Tool-O seeks to manage third-party relationships responsibly through appropriate governance, ongoing oversight, proportionate risk management and continual review to support the security, reliability and long-term resilience of the Platform.
4. REVIEW, COMPLIANCE AND POLICY ADMINISTRATION
4.1 Governance
Tool-O is responsible for administering this Vendor & Third-Party Services Policy and may maintain governance frameworks, operational procedures and oversight processes relating to third-party service providers.
4.2 Compliance
Tool-O seeks to engage and manage third-party service providers in accordance with applicable laws, contractual obligations and recognised operational and security practices where appropriate.
Nothing in this Policy guarantees the continuous availability, performance or conduct of independent third-party providers.
4.3 Policy Review
Tool-O may periodically review this Policy to reflect:
- legislative changes;
- regulatory guidance;
- technological developments;
- operational experience;
- changes in third-party services;
- emerging risks;
- industry best practices.
4.4 Continuous Improvement
Tool-O may periodically review its vendor management framework to improve:
- vendor governance;
- operational resilience;
- information security;
- privacy protections;
- service reliability;
- risk management processes.
4.5 Vendor Reviews
Tool-O may periodically assess third-party providers having regard to:
- service quality;
- operational performance;
- information security;
- legal compliance;
- contractual obligations;
- business continuity capability;
- User impact.
The frequency and scope of reviews may vary depending on the nature of the services provided.
4.6 Relationship with Other Policies
This Vendor & Third-Party Services Policy should be read together with the:
- Privacy Policy;
- Security Policy;
- Risk Management Policy;
- Platform Availability Policy;
- Business Continuity Policy;
- Payment & Payout Policy;
- Terms of Use;
- all other Platform policies.
Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.
4.7 Contact
Questions regarding this Vendor & Third-Party Services Policy may be directed to Tool-O using the contact details published on the Platform.
4.8 Policy Updates
Tool-O may amend this Vendor & Third-Party Services Policy from time to time.
The latest version published on the Platform replaces all previous versions.
4.9 Commitment
Tool-O is committed to responsibly selecting, managing and reviewing third-party service providers to support the secure, reliable and resilient operation of the Platform while protecting Users and maintaining appropriate governance standards.
4.10 Final Statement
Third-party service providers play an important role in supporting the operation of the Tool-O marketplace.
By applying appropriate governance, conducting proportionate oversight and continually reviewing third-party risks, Tool-O seeks to maintain a secure, dependable and trusted Platform for all Users.
END OF VENDOR & THIRD-PARTY SERVICES POLICY
