Data Privacy and Compliance Summary
Last updated: September 12, 2026
Executive Summary
Date
April 20, 2026
Overview
This document provides an overview of Boon's approach to data privacy and regulatory compliance, with specific focus on GDPR, CCPA, and industry standards relevant to our platform. As a referral hiring platform, we recognize the critical importance of handling personal data with the utmost care and transparency.
Data Privacy Framework
Privacy by Design Principles:
Privacy is embedded into the design and architecture of our systems and business practices
Privacy is proactively integrated into the development lifecycle, not added reactively
Full functionality is delivered while ensuring maximum privacy protection
End-to-end security with full lifecycle protection of personal data
Data Minimization:
We collect only the data necessary for the specific purpose of our platform
Personal data is stored only for the duration required for legitimate business purposes
Regular data reviews ensure we maintain only necessary information
User Control:
Clear mechanisms for users to access, correct, download, or delete their personal data
Transparent privacy notices and policies written in clear, understandable language
Consent management that provides genuine choice and control
Regulatory Compliance
GDPR Compliance:
Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities
Documented lawful basis for all data processing activities
Robust data subject rights fulfillment process with response times well within required timeframes
Regular staff training on GDPR requirements and privacy best practices
CCPA/CPRA Compliance:
Clear disclosure of personal information collection, use, and sharing practices
Implemented "Do Not Sell My Personal Information" functionality
Processes for handling consumer rights requests
Regular assessment of third-party data sharing relationships
Industry Standards:
Adherence to ISO 27701 privacy information management principles
Implementation of NIST Privacy Framework core functions
Regular privacy-focused security assessments
Data Processing Activities
Data Collection:
Personal identifiers (names, email addresses, phone numbers)
Professional information (work history, skills, job roles)
Communication records related to referrals
Platform usage analytics
Data Processing Purposes:
Facilitating employment referrals
Platform functionality and user experience
Security and fraud prevention
Analytics and service improvement
Data Sharing:
Limited to the explicit purposes outlined in our privacy policy
Subject to appropriate contractual safeguards with all third parties
Regular vendor assessment and monitoring
Privacy Governance
Privacy Team:
Designated Data Protection Officer (DPO) role
Cross-functional privacy committee with representatives from legal, security, and product teams
Regular privacy reviews integrated into product development lifecycle
Documentation and Record-keeping:
Comprehensive Records of Processing Activities (RoPA)
Data flow mapping and visualization
Regular policy and procedure reviews
Training and Awareness:
Mandatory privacy training for all employees
Role-specific privacy training for engineering, product, and customer support teams
Regular privacy awareness communications
Recent Enhancements
Enhanced Consent Management: Implemented granular consent management for marketing communications
Privacy Rights Portal: Deployed a self-service privacy rights portal for data subjects
Vendor Assessment: Completed comprehensive privacy assessments of all third-party vendors
Privacy Impact Assessment: Updated PIAs for all major platform features
Conclusion
Boon maintains a comprehensive approach to data privacy and compliance, treating these as core elements of our business operations rather than mere regulatory requirements. Our privacy program is designed to build and maintain trust with users, protect personal data, and ensure compliance with relevant regulations. We continuously evaluate and enhance our privacy practices to adapt to the evolving regulatory landscape and to reflect best practices in data protection.
Version Control
Version | Modification Details | Sections Modified | Author | Reviewer | Approver | Date |
|---|---|---|---|---|---|---|
1.0 | Initial document | All | Abdel Z. | Cesar R. | Dakota Y. | 2024-09-15 |
1.2 | Minor revision | All | Usama B. | Yasser D. | Dakota Y. | 2026-04-20 |
1.3 | Reviewed and migrated to Boon Help Center | All | Usama B. | Yasser D. | Dakota Y. | 2026-09-11 |