Data Privacy and Compliance Summary

Last updated: September 12, 2026

Executive Summary

Date

April 20, 2026

Overview

This document provides an overview of Boon's approach to data privacy and regulatory compliance, with specific focus on GDPR, CCPA, and industry standards relevant to our platform. As a referral hiring platform, we recognize the critical importance of handling personal data with the utmost care and transparency.

Data Privacy Framework

Privacy by Design Principles:

  • Privacy is embedded into the design and architecture of our systems and business practices

  • Privacy is proactively integrated into the development lifecycle, not added reactively

  • Full functionality is delivered while ensuring maximum privacy protection

  • End-to-end security with full lifecycle protection of personal data

Data Minimization:

  • We collect only the data necessary for the specific purpose of our platform

  • Personal data is stored only for the duration required for legitimate business purposes

  • Regular data reviews ensure we maintain only necessary information

User Control:

  • Clear mechanisms for users to access, correct, download, or delete their personal data

  • Transparent privacy notices and policies written in clear, understandable language

  • Consent management that provides genuine choice and control

Regulatory Compliance

GDPR Compliance:

  • Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities

  • Documented lawful basis for all data processing activities

  • Robust data subject rights fulfillment process with response times well within required timeframes

  • Regular staff training on GDPR requirements and privacy best practices

CCPA/CPRA Compliance:

  • Clear disclosure of personal information collection, use, and sharing practices

  • Implemented "Do Not Sell My Personal Information" functionality

  • Processes for handling consumer rights requests

  • Regular assessment of third-party data sharing relationships

Industry Standards:

  • Adherence to ISO 27701 privacy information management principles

  • Implementation of NIST Privacy Framework core functions

  • Regular privacy-focused security assessments

Data Processing Activities

Data Collection:

  • Personal identifiers (names, email addresses, phone numbers)

  • Professional information (work history, skills, job roles)

  • Communication records related to referrals

  • Platform usage analytics

Data Processing Purposes:

  • Facilitating employment referrals

  • Platform functionality and user experience

  • Security and fraud prevention

  • Analytics and service improvement

Data Sharing:

  • Limited to the explicit purposes outlined in our privacy policy

  • Subject to appropriate contractual safeguards with all third parties

  • Regular vendor assessment and monitoring

Privacy Governance

Privacy Team:

  • Designated Data Protection Officer (DPO) role

  • Cross-functional privacy committee with representatives from legal, security, and product teams

  • Regular privacy reviews integrated into product development lifecycle

Documentation and Record-keeping:

  • Comprehensive Records of Processing Activities (RoPA)

  • Data flow mapping and visualization

  • Regular policy and procedure reviews

Training and Awareness:

  • Mandatory privacy training for all employees

  • Role-specific privacy training for engineering, product, and customer support teams

  • Regular privacy awareness communications

Recent Enhancements

  • Enhanced Consent Management: Implemented granular consent management for marketing communications

  • Privacy Rights Portal: Deployed a self-service privacy rights portal for data subjects

  • Vendor Assessment: Completed comprehensive privacy assessments of all third-party vendors

  • Privacy Impact Assessment: Updated PIAs for all major platform features

Conclusion

Boon maintains a comprehensive approach to data privacy and compliance, treating these as core elements of our business operations rather than mere regulatory requirements. Our privacy program is designed to build and maintain trust with users, protect personal data, and ensure compliance with relevant regulations. We continuously evaluate and enhance our privacy practices to adapt to the evolving regulatory landscape and to reflect best practices in data protection.

Version Control

Version

Modification Details

Sections Modified

Author

Reviewer

Approver

Date

1.0

Initial document

All

Abdel Z.

Cesar R.

Dakota Y.

2024-09-15

1.2

Minor revision

All

Usama B.

Yasser D.

Dakota Y.

2026-04-20

1.3

Reviewed and migrated to Boon Help Center

All

Usama B.

Yasser D.

Dakota Y.

2026-09-11