Trust Centre · Operations

Business policy and procedure register

The controlled operating procedures required to run 24-SEVEN as a real hospitality marketplace.

Register version 3.0Status: defined for formal adoptionEvidence required before launch
Adoption boundary: these procedures are defined in the product governance pack. The legal operating company must approve owners, train users, retain evidence and test the procedures before representing them as fully operational.
IDControlled procedureAccountable roleMinimum evidence
OPS-01Reservation, hold, confirmation, cancellation, no-show and checkout lifecycleOperationsStatus history, guest notice, inventory movement
OPS-02Dated inventory and rate-change controlOperationsVersioned update and no-oversell check
OPS-03Property onboarding, evidence review and publicationOperationsAuthority, hotel evidence and image rights
FIN-01Payment-provider onboarding and production activationFinanceMerchant approval, sandbox, webhook and rollback test
FIN-02Payment-event verification and reservation confirmationFinanceSignature, provider lookup, amount/currency match
FIN-03Settlement reconciliation, commissions and partner payoutsFinanceMatched settlement, variance review, dual approval
FIN-04Refund, chargeback and late-payment remediationFinanceApproval, provider reference and guest outcome
PRV-01Data-subject rights and identity verificationPrivacyReference, verification, decision and response record
PRV-02Personal-data breach assessment and notificationPrivacy / SecurityTimeline, risk assessment, decision and notifications
SEC-01Access provisioning, role review and terminationSecurityApproval, least-privilege role and revocation
SEC-02Security incident response and evidence preservationSecurityIncident log, containment, communications and lessons
TEC-01Encrypted backup, restore testing and disaster recoveryEngineeringEncrypted artifact, off-server copy and restore result
TEC-02Change, release, migration and rollback managementEngineeringApproval, test evidence, backup and rollback decision
VEN-01Supplier due diligence, data agreement and offboardingGovernanceRisk review, contract, transfer basis and exit record
EDT-01Human and AI-assisted editorial publishingEditorSource record, quality gate, disclosure and correction

Document control

Each detailed playbook must name its approver, effective date, scope, inputs, steps, segregation of duties, exception route, records, retention rule, training owner, test cadence and next review date. Emergency deviations are recorded and retrospectively approved.

Segregation of duties

Operations cannot activate providers or view secret configuration. Finance cannot browse guest or property-application correspondence beyond the references needed for financial control. Editors cannot access operational personal data. Settings, backups and role administration are restricted to the super-administrator function.