Policies Internal operating policies
Backup and Recovery Policy
How Map.ca backs up production systems, how often, and how recovery interacts with deletion rights.
- Version
- 0.1.0
- Effective
- May 20, 2026
- Last reviewed
- May 20, 2026
- Review cycle
- every 6 months
- Master Policy Index entry
- §4 #67
Policy text
Backups protect against operational failure. They must not silently undo a user’s right to delete. The Backup and Recovery Policy defines the backup cadence by data class, the encryption posture for backups, the geographic distribution, the recovery-time and recovery-point objectives, and the rule that deletion in production propagates to backups within the documented cycle so a delete is real, not a delayed restore.
It applies to engineering, security, and operations functions.
Principles this policy enforces
- Collect less, protect more
- Public data and personal data are not the same thing
- Community benefit must survive scale
What it requires
- Encrypt backups at rest.
- Propagate user deletions to backups within the documented cycle.
What it forbids
- Do not restore deleted personal content from a backup without a documented legal basis.
- Do not store backups in unauthorized jurisdictions.
How it applies
- Engineering
- Security
- Operations
References
- Map.ca Policy Constitution §2 principle 6
Related policies
Security Policy
How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.
Data Retention and Deletion Policy
How long Map.ca keeps data, what happens on deletion, and how URL permanence interacts with content deletion.
Data Residency Policy
Defines where Map.ca stores and processes data. Canadian-first residency wherever practical; disclosure when trusted vendors process data outside Canada.