Sub-processors & Data Transfers
Last updated: September 12, 2026
Boon engages a limited number of trusted third-party service providers (“Sub-processors”) that support the delivery of our products and services. Each Sub-processor is vetted for security, privacy, and compliance posture and is bound by written agreements requiring data-protection standards consistent with Boon's obligations under applicable privacy laws, including the GDPR and CCPA.
Boon reviews this list periodically and updates it to reflect operational or vendor changes. Customers may request notification of material changes by contacting privacy@goboon.co.
Vendor due diligence and safeguards
Before engaging a Sub-processor, Boon performs a security and privacy review that includes:
Assessment of the vendor's data-handling practices, technical and organisational controls, and relevant certifications (for example SOC 2, ISO 27001, PCI DSS)
Execution of a written data-processing or confidentiality agreement requiring compliance with applicable laws and Boon's security standards
Ongoing monitoring for material changes, incidents, or compliance issues
All personal data handled by Sub-processors remains Boon's responsibility, and processing occurs only under Boon's documented instructions.
Sub-processor list
Sub-processor | Purpose of processing | Categories of personal data | Processing location | Security / certifications |
|---|---|---|---|---|
Amazon Web Services (AWS) | Cloud infrastructure and hosting | User data, usage data | United States | SOC 2, ISO 27001 |
Supabase | Database and backend infrastructure | User data, authentication data, application data, usage data | United States | SOC 2 Type II, ISO 27001, HIPAA, GDPR |
SendGrid (Twilio Inc.) | Transactional email delivery | Name, email address, phone number, geolocation, images | United States | SOC 2 Type II, ISO 27001 |
Twilio | Transactional SMS delivery | Contact information, customer account data, communications usage data | United States | SOC 2 Type II, ISO 27001 |
Stripe | Payment processing | Billing information, transaction data, identity information | United States, EU | PCI DSS Level 1, SOC 2 Type II, ISO 27001 |
WorkOS | Authentication and SSO | Name, email address, IP address, device details | United States | SOC 2 Type II |
Authentication and SSO | Employee data, user data | United States | SOC 2, ISO 27001 | |
Microsoft Outlook | Authentication and SSO | Name, email address, contact information | United States | SOC 2, ISO 27001 |
Algolia | Search indexing and retrieval | Identifiers (name, email address, IP address), usage data | United States, EU | SOC 2 Type II, ISO 27001 |
ATS and HRIS integrations | Customer data, personal information | United States, EU, APAC | SOC 2 Type II, ISO 27001, HIPAA, GDPR | |
Slack | Internal collaboration and integrations | Contact information, usage data, messages | United States, EU | SOC 2, SOC 3, ISO 27001, HIPAA, GDPR |
Rollbar | Application error monitoring | Error data, IP address, person ID, name, email address | United States | SOC 2 Type I/II, SOC 3, ISO 27001, HIPAA |
Sentry | Application error monitoring | Error data, usage data | United States, EU | HIPAA, GDPR, CCPA |
Hyperping | Uptime and availability monitoring | Name, email address, phone number, company name, IP address | EU | SOC 2 Type II, ISO 27001 |
Nightfall AI | Data loss prevention | User data, application content, personal information, credentials, usage data | United States | SOC 2 Type II |
Last updated: August 2026.
View the live Sub-processor Directory
Data transfer mechanisms
Where Sub-processors are located outside the region in which customer data originates, Boon relies on established transfer mechanisms such as the EU–U.S. Data Privacy Framework, the UK Extension, and/or Standard Contractual Clauses to ensure an adequate level of protection for personal data.
Questions or requests
For questions regarding Sub-processors, or to request a copy of Boon's Data Processing Agreement, contact privacy@goboon.co.