You plan for the incident and for your exit before the service goes live.
Two distinct questions, which your IT department and your legal team ask before signing. What happens if the service is interrupted? What happens if you leave the programme? Both are dealt with before the service goes live and written into the contract. Not at the time of the incident, nor at the time of departure.
Continuity
What happens if the service is interrupted
Continuity is prepared, tested and documented. It is not promised by an availability figure displayed on a commercial page.
Measures and tests
The continuity and recovery measures, their objectives and their tests are described in the documentation file, with their limits and their date. No availability rate and no recovery objective is published on this site before being established and contractually agreed. A service commitment is read in a contract, not on a page.
Dependencies
A payment service relies on third parties: hosting, technical providers, account-holding institutions, card issuers. Critical dependencies, that is, those whose interruption stops the service, are identified together with the consequences of their unavailability and the measures planned.
Incident handling
An incident follows a procedure. We establish its nature and severity, we handle it, we inform the parties concerned, and we draw the lessons learned. The applicable notification time limits are those provided for by the regulations and by the contract, and not a general commercial commitment. During an incident, the rule of the programme remains the rule. No operation is executed outside the framework you have set on the grounds that the service is degraded.
Programme exit
What you take with you, and in what state
Reversibility, that is, your exit from the programme and the recovery of your data, is prepared before the service goes live. You know what you take away, in what format, within what time limit, and what becomes of the balances in circulation.
- Data returned
- The log of the programme’s operations, the rules applied and the reference data you provided
- Formats
- Open, usable exchange formats, settled at the first discussion and written into the contract
- Return time limit
- Written into the contract, with the event that starts it running
- Balances in circulation
- Handled under the programme contract, separately from the right to redeem electronic money
- Recorded proof
- Payments already recorded on the blockchain remain tamper-proof and verifiable after the exit
- Erasure
- Fate of off-chain data at the end of the applicable retention periods
Balances and redemption
The closure of a programme and the right to redeem electronic money remain two distinct questions. The treatment of balances in circulation at the time of exit is the one provided for in the programme contract. The holder’s right to redemption falls under the framework applicable to electronic money. It follows the flow described with the safeguarding of funds.
What you take with you, and in which formats
You get back data that are usable without the service. It is a log readable by your own tools, not an export whose reading would require remaining a client. The formats are validated at the first discussion, and what has been recorded on the blockchain remains verifiable independently of MAP.
Documents
The documents that establish this page
A document appears here once it exists and can be provided in the mode indicated.