Tool-O

Tool-O

Vendor and Third-Party Services Policy

This Vendor & Third-Party Services Policy explains how Tool-O manages relationships with third-party service providers that support the operation of the Platform.

1. INTRODUCTION

1.1 Purpose

This Vendor & Third-Party Services Policy explains how Tool-O manages relationships with third-party service providers that support the operation of the Platform.

The purpose of this Policy is to promote responsible governance of third-party services, protect Users and reduce operational, security and compliance risks associated with external providers.

1.2 Objectives

This Policy seeks to:

  • promote responsible vendor management;
  • support reliable Platform operations;
  • protect User information;
  • reduce third-party risks;
  • encourage appropriate due diligence;
  • strengthen operational resilience;
  • comply with applicable legal obligations.

1.3 Scope

This Policy applies to third-party providers supporting Platform operations, including providers of:

  • cloud infrastructure;
  • payment services;
  • identity verification;
  • communications;
  • hosting;
  • mapping services;
  • analytics;
  • artificial intelligence services;
  • customer support services;
  • software development tools;
  • cybersecurity services;
  • other operational services.

1.4 Guiding Principles

Tool-O administers third-party relationships in accordance with the following principles:

  • accountability;
  • transparency;
  • security;
  • reliability;
  • proportionality;
  • continuous improvement.

1.5 Relationship with Other Policies

This Policy should be read together with the:

  • Privacy Policy;
  • Security Policy;
  • Risk Management Policy;
  • Platform Availability Policy;
  • Business Continuity Policy;
  • Payment & Payout Policy;
  • Terms of Use;
  • all other Platform policies.

1.6 Updates

Tool-O may amend this Vendor & Third-Party Services Policy from time to time.

The latest version published on the Platform replaces all previous versions.

2. VENDOR MANAGEMENT

2.1 Selection of Vendors

Tool-O may select third-party service providers after considering factors including:

  • reliability;
  • security;
  • operational capability;
  • legal compliance;
  • reputation;
  • technical compatibility;
  • business continuity capability;
  • other relevant operational considerations.

2.2 Due Diligence

Where reasonably appropriate, Tool-O may undertake due diligence before engaging third-party providers by reviewing matters including:

  • security practices;
  • privacy practices;
  • operational resilience;
  • regulatory compliance;
  • contractual commitments;
  • service capabilities;
  • other relevant risk factors.

2.3 Categories of Third-Party Services

Third-party providers may support Platform functions including:

  • payment processing;
  • cloud hosting;
  • identity verification;
  • email delivery;
  • SMS and notification services;
  • mapping and geolocation services;
  • artificial intelligence services;
  • analytics;
  • cybersecurity monitoring;
  • customer support;
  • software development;
  • other operational services.

2.4 User Information

Where necessary for Platform operations, Tool-O may provide limited information to third-party providers in accordance with:

  • the Privacy Policy;
  • applicable laws;
  • contractual obligations;
  • reasonable operational requirements.

Tool-O seeks to limit information shared to that which is reasonably necessary for the relevant service.

2.5 Vendor Security

Tool-O seeks to engage third-party providers that maintain security practices reasonably appropriate to the services they provide.

However, Tool-O does not control the internal operations of independent third-party providers.

2.6 Service Interruptions

Platform functionality may be affected where third-party providers experience:

  • outages;
  • security incidents;
  • maintenance activities;
  • operational failures;
  • network disruptions;
  • other service interruptions.

Tool-O will seek to minimise the impact of such interruptions where reasonably practicable.

2.7 Vendor Changes

Tool-O may replace, remove or introduce third-party providers from time to time where reasonably necessary for:

  • operational improvements;
  • security;
  • performance;
  • regulatory compliance;
  • business continuity;
  • User experience.

2.8 User Responsibilities

Users acknowledge that certain Platform functionality depends upon third-party providers and that those providers may have their own:

  • terms and conditions;
  • privacy policies;
  • operational practices;
  • service limitations.

Users may be required to comply with applicable third-party requirements when using relevant Platform functionality.

2.9 Monitoring

Tool-O may periodically review third-party service providers to assess:

  • operational performance;
  • security;
  • reliability;
  • compliance;
  • contractual performance;
  • other relevant operational factors.

2.10 Commitment to Responsible Vendor Management

Tool-O seeks to engage and manage third-party providers responsibly to support secure, reliable and efficient Platform operations while continually reviewing vendor performance and operational risks.

3. VENDOR GOVERNANCE

3.1 Vendor Oversight

Tool-O may maintain governance processes for the ongoing oversight of third-party service providers, including periodic reviews of:

  • operational performance;
  • security practices;
  • service reliability;
  • legal compliance;
  • contractual obligations;
  • risk management.

3.2 Risk Assessment

Tool-O may assess risks associated with third-party providers by considering:

  • information security;
  • privacy protections;
  • business continuity capability;
  • operational resilience;
  • regulatory compliance;
  • financial stability where appropriate;
  • geographic or jurisdictional risks;
  • dependency on the provider.

3.3 Contractual Arrangements

Where reasonably appropriate, Tool-O may enter into contractual arrangements with third-party providers addressing matters including:

  • confidentiality;
  • privacy;
  • information security;
  • service standards;
  • legal compliance;
  • termination rights;
  • other operational requirements.

3.4 Incident Management

Where a third-party provider experiences a security incident, service interruption or other operational issue that may affect the Platform, Tool-O may:

  • assess the impact;
  • cooperate with the provider;
  • implement temporary mitigation measures;
  • communicate with affected Users where appropriate;
  • activate relevant business continuity procedures;
  • review future risk management measures.

3.5 Compliance Monitoring

Tool-O may periodically review whether third-party providers continue to satisfy operational, legal and security expectations relevant to the services they provide.

Where concerns arise, Tool-O may request additional information or implement appropriate risk mitigation measures.

3.6 Data Protection

Where third-party providers process Personal Information on behalf of Tool-O, Tool-O seeks to ensure that such processing occurs in accordance with:

  • applicable privacy laws;
  • contractual obligations;
  • the Privacy Policy;
  • reasonable information security practices.

3.7 Service Changes

Third-party providers may update, modify or discontinue their services from time to time.

Tool-O may adapt Platform functionality, replace providers or implement alternative operational arrangements where reasonably necessary.

3.8 Record Keeping

Tool-O may maintain records relating to third-party service providers, including:

  • vendor assessments;
  • contractual documentation;
  • operational reviews;
  • security assessments;
  • incident records;
  • performance monitoring;
  • other governance records.

Records may be retained in accordance with the Data Retention Policy and applicable laws.

3.9 User Awareness

Users acknowledge that certain Platform features depend upon independent third-party providers whose services remain subject to their own operational practices and availability.

Tool-O cannot guarantee the continuous availability or performance of independent third-party services.

3.10 Commitment to Responsible Vendor Governance

Tool-O seeks to manage third-party relationships responsibly through appropriate governance, ongoing oversight, proportionate risk management and continual review to support the security, reliability and long-term resilience of the Platform.

4. REVIEW, COMPLIANCE AND POLICY ADMINISTRATION

4.1 Governance

Tool-O is responsible for administering this Vendor & Third-Party Services Policy and may maintain governance frameworks, operational procedures and oversight processes relating to third-party service providers.

4.2 Compliance

Tool-O seeks to engage and manage third-party service providers in accordance with applicable laws, contractual obligations and recognised operational and security practices where appropriate.

Nothing in this Policy guarantees the continuous availability, performance or conduct of independent third-party providers.

4.3 Policy Review

Tool-O may periodically review this Policy to reflect:

  • legislative changes;
  • regulatory guidance;
  • technological developments;
  • operational experience;
  • changes in third-party services;
  • emerging risks;
  • industry best practices.

4.4 Continuous Improvement

Tool-O may periodically review its vendor management framework to improve:

  • vendor governance;
  • operational resilience;
  • information security;
  • privacy protections;
  • service reliability;
  • risk management processes.

4.5 Vendor Reviews

Tool-O may periodically assess third-party providers having regard to:

  • service quality;
  • operational performance;
  • information security;
  • legal compliance;
  • contractual obligations;
  • business continuity capability;
  • User impact.

The frequency and scope of reviews may vary depending on the nature of the services provided.

4.6 Relationship with Other Policies

This Vendor & Third-Party Services Policy should be read together with the:

  • Privacy Policy;
  • Security Policy;
  • Risk Management Policy;
  • Platform Availability Policy;
  • Business Continuity Policy;
  • Payment & Payout Policy;
  • Terms of Use;
  • all other Platform policies.

Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.

4.7 Contact

Questions regarding this Vendor & Third-Party Services Policy may be directed to Tool-O using the contact details published on the Platform.

4.8 Policy Updates

Tool-O may amend this Vendor & Third-Party Services Policy from time to time.

The latest version published on the Platform replaces all previous versions.

4.9 Commitment

Tool-O is committed to responsibly selecting, managing and reviewing third-party service providers to support the secure, reliable and resilient operation of the Platform while protecting Users and maintaining appropriate governance standards.

4.10 Final Statement

Third-party service providers play an important role in supporting the operation of the Tool-O marketplace.

By applying appropriate governance, conducting proportionate oversight and continually reviewing third-party risks, Tool-O seeks to maintain a secure, dependable and trusted Platform for all Users.

END OF VENDOR & THIRD-PARTY SERVICES POLICY

Related documents