Backup and Disaster Recovery Policy
PART I - PURPOSE, SCOPE, AND LEGAL BASIS
Article 1. Purpose
1.1. This Policy sets out the principles, standards, and procedures for data backup and disaster recovery (DR), to ensure data availability and integrity, maintain business continuity, and meet SLA commitments to Customers.
Article 2. Scope of application
2.1. Applies to all production systems, Customer data, internal operational data, system configuration, source code and databases managed by HiTechCloud.
2.2. The division of backup responsibility between HiTechCloud and the Customer is determined by the shared responsibility model in Article 10. The Customer remains obliged to maintain independent backups of their own under Article 6.2 of the Terms of Service.
Article 3. Legal basis
- The Cybersecurity Law 2025 (Luật An ninh mạng 2025, Law No. 116/2025/QH15); Decree 85/2016/ND-CP on securing information systems by classification level, and the decrees implementing the Cybersecurity Law 2025;
- The Personal Data Protection Law 2025 (Law No. 91/2025/QH15) and Decree 356/2025/ND-CP (on data safety and retention periods);
- Data Law 2024; Accounting Law 2015 and Tax Administration Law 2025 (on document retention);
- Penal Code 2015, as amended and supplemented in 2017 (Bộ luật Hình sự 2015); reference standards ISO/IEC 27031 (ICT continuity), ISO 22301 (BCMS), NIST SP 800-34;
- Decision No. 4567/QD-VBPL dated 01/06/2026 issuing the company's Legal Compliance Framework.
PART II – BACKUP STRATEGY
Article 4. The 3-2-1-1-0 rule
4.1. HiTechCloud applies these backup principles: 3 copies of the data; 2 different types of storage media; 1 off-site copy (in a different geographic location); 1 an offline/air-gapped or immutable copy (ransomware resistant); 0 errors after a restore check (verified restore).
Article 5. Backup classification and frequency
| Data type | Frequency | Target RPO | Retention |
|---|---|---|---|
| Production databases | Continuous (CDP) / every 1 hour | ≤ 1 hour | 30 days |
| Customer website & applications | Daily | ≤ 24 hours | 30 days |
| System and infrastructure configuration (IaC) | After each change + daily | ≤ 24 hours | 90 days |
| VPS (snapshot) | Daily + before major changes | ≤ 24 hours | 14 days |
| Business Email | Daily | ≤ 24 hours | 30 days |
| Financial records, invoices | Per transaction | ≤ 24 hours | 10 years |
| System logs | Continuous | ≤ 1 hour | 12 months |
5.1. The backup cycle follows the GFS (Grandfather-Father-Son) model: daily copies (Son), weekly copies (Father) and monthly copies (Grandfather).
Article 6. Backup encryption and protection
6.1. All backups are encrypted with AES-256 at rest and TLS 1.3 in transit.
6.2. Backups containing personal data are protected in accordance with the PDPD; encryption keys are managed through a KMS/HSM kept separate from the data; and immutable/WORM copies are used to guard against encryption or deletion by ransomware.
6.3. Access to the backup repository follows the principle of least privilege, with mandatory MFA and full logging (per the Information Security Policy).
PART III – DISASTER RECOVERY (DR)
Article 7. RTO/RPO targets by service tier
| Service tier | RTO (recovery time) | RPO (maximum data loss) |
|---|---|---|
| Enterprise / Cloud Server | ≤ 2 hours | ≤ 15 minutes |
| Cloud Hosting / Business | ≤ 4 hours | ≤ 1 hour |
| Shared / WordPress Hosting | ≤ 12 hours | ≤ 24 hours |
| Email Hosting | ≤ 4 hours | ≤ 24 hours |
7.1. RTO/RPO are recovery objectives; compensation for service interruption is governed by the Service Level Agreement (SLA).
Article 8. Disaster classification and response plans
8.1. Level 1 – Local incident (disk failure, single application fault): restore in place from the most recent snapshot or backup. Level 2 – Cluster/infrastructure incident (node loss, regional network fault): shift load to a standby node or cluster (failover). Tier 3 – Data center disaster (fire, flood, wide-area power loss, natural disaster): activate the DR site in a different geographic location. Level 4 – Widespread disaster/severe cyberattack (system-wide ransomware): restore from an offline/immutable copy, coordinated with the Incident Response (IR) process.
8.2. For incidents involving a cyber attack or a data breach, restoration is performed only from a backup confirmed to be clean, and in accordance with the Incident Response Procedure and the Personal Data Breach Notification Procedure.
Article 9. Restore process
9.1. Sequence: (a) a Disaster Declaration is made by the Incident Commander; (b) the DR team and the corresponding runbook are activated; (c) systems are restored in priority order (Tier 0 → Tier 3); (d) data integrity is verified after restoration (integrity check, checksum); (e) service operation is confirmed and Customers are notified; and (f) enhanced monitoring runs for 7 days after restoration.
PART IV - TESTING, RESPONSIBILITIES, AND EFFECT
Article 10. Shared responsibility model
10.1. HiTechCloud is responsible for: backing up platform infrastructure, virtual machine snapshots according to the service plan, and system configuration, and providing backup tools to the Customer.
10.2. Customer responsibilities: maintain independent backups of their important data and content; test their ability to restore that data; and correctly configure the backup options provided. HiTechCloud recommends that Customers not treat the service as their only backup.
10.3. For plans that do not include a backup service, the Customer is solely responsible for backups; HiTechCloud does not guarantee recovery of Customer data in such cases.
Article 11. Restore testing
11.1. HiTechCloud performs: monthly sample test restores for critical systems; a full DR drill at least every 6 months; and a written test report with an updated runbook after each exercise.
11.2. Every backup must meet the principle of “zero restore failures” — a backup that cannot be restored is treated as invalid and must be recreated.
Article 12. Backup retention and destruction
12.1. Backups that have reached the end of their retention period are securely destroyed (crypto-shredding or secure erasure), and the destruction is recorded. Data that must be retained by law (financial records for 10 years; data required by competent authorities) is kept for exactly the statutory retention period.
12.2. Destruction of personal data held in backups complies with the PDPD and the Personal Data Protection Law 2025.
Article 13. Effect
13.1. This policy takes effect on 01/07/2026 and is reviewed at least every 12 months, or after each actual DR activation. The Vietnamese version is the authoritative legal text.