e-satisfaction

Backups & disaster recovery

Your feedback programme depends on your data being there tomorrow. e-satisfaction backs up every piece of your organization's data continuously, keeps those backups encrypted in the same region as the data itself, and tests that they actually restore.

This page explains how that works — what's backed up, how far back you can go, and what happens on our side if there's ever an outage, a hardware failure or a mistake. There's nothing to configure here: it's on for every organization, all the time.

How your data is backed up

Different kinds of data change at different speeds, so they're protected in different ways. The table below is the short version; each row is explained underneath.

Data typeWhat it coversHow it's backed upHow far back
ConfigurationWorkspaces, monitors, questionnaires, users and settingsEvery individual change, as it happensAny moment in time
UsageSurvey responses, alerts and the activity around themHourly and daily snapshotsUp to 3 days

Configuration data — every change, as it happens

Configuration is the setup your programme runs on: your workspaces, your monitors, your questionnaires, who has access and what they can do. It changes rarely, but when it does, losing a change is painful — and the change itself is usually the thing that matters.

So configuration isn't backed up on a schedule. Instead, every single change is recorded the moment it's made, one at a time, in order. Think of it as a complete, uninterrupted diary of your setup rather than a photograph taken once a night. Because every change is written down as it happens, your configuration can be rebuilt as it existed at any moment you name — five minutes ago, or the instant before someone deleted a questionnaire.

In practice this means that if configuration is ever lost or damaged, it can be restored right up to the point just before the problem, and the changes made in between aren't lost with it.

Usage data — hourly and daily snapshots

Usage data is everything your programme produces as it runs: survey responses coming in, alerts being raised and resolved, and the activity around them. There's a lot of it and it arrives constantly, so it's protected with snapshots — complete copies of the data taken at a fixed moment.

Snapshots are taken every hour, and a daily snapshot is kept alongside them. Together they give you up to 3 days of recovery points to restore from — hourly ones for a problem spotted quickly, daily ones for a problem that took the weekend to surface.

Backups are not the same as retention

Backups exist so your data can be recovered. Data retention is about how long your data is kept — up to 5 years in cold storage for some categories. They're separate systems answering separate questions.

Backups are also not an undo button for anonymization or comment purging. Those are deliberate, permanent removals of personal data, and they apply to your backups too.

How backups are protected

A backup is only useful if it's safe and if it works. Three things make sure of that:

  • Encrypted, always. Every backup is encrypted using AES-256, the same standard used to protect classified government information. An unencrypted copy of your data never exists.
  • Stored in your region. Backups live in pre-defined datacenters in the same geographic region as the data they protect — today, the European Union. A backup never quietly moves your data somewhere it isn't allowed to be. See Data residency.
  • Tested, not assumed. Backup integrity and the restore procedure itself are tested regularly. A backup that has never been restored is a guess, not a safeguard.

Staying available in the first place

The best recovery is the one you never need. Alongside backups, the platform is built to keep running through the kinds of failures that would otherwise take it down:

  • Redundant infrastructure across regions, with load balancing that shifts traffic away from a failing component automatically.
  • Auto-scaling and self-healing, so unexpected traffic spikes and individual failures are absorbed rather than felt.
  • Version control and rollback, so a problematic release can be returned to a previous known-good state.

When something does go wrong

The platform is monitored 24/7, with automated alerts for suspicious activity and anomalies, and a dedicated incident response team with defined escalation procedures. When an incident is declared, recovery follows a set path:

Identify and assess

The severity and the impact on services are established first, so the response matches the problem. Customers are notified at this stage if the incident affects them.

Contain and mitigate

Failover systems are activated or backup servers deployed, and the affected components are isolated to stop the problem spreading.

Restore and verify

Where data needs restoring, it's recovered from the most recent backup. Data integrity and system stability are both verified before service is considered restored.

Learn from it

A root cause analysis follows every incident, along with any preventive measures it points to. Documentation is updated so the same problem is handled better next time.

Recovery is measured against predefined objectives for how quickly service is restored and how much data could be affected — the second of which is what the backup schedules above are designed to keep as close to zero as possible.

How you'll hear about it

If an incident affects you, you won't have to go looking for it. Updates reach you through the status page, email alerts and in-app notifications, and continue until the incident is resolved.

Keeping the plan honest

The disaster recovery plan isn't written once and filed away:

  • Annual disaster recovery drills rehearse real recovery scenarios through emulations.
  • Regular updates keep the plan current with changes to infrastructure, new threats and new regulations.
  • Audit logs and reviews track every incident and the improvements that came out of it.

Need this for a security review?

If your procurement or security team needs formal documentation of our disaster recovery and backup posture, contact the team — we can walk through the details that apply to your organization.