Sub-processors & Data Transfers

Last updated: September 12, 2026

Boon engages a limited number of trusted third-party service providers (“Sub-processors”) that support the delivery of our products and services. Each Sub-processor is vetted for security, privacy, and compliance posture and is bound by written agreements requiring data-protection standards consistent with Boon's obligations under applicable privacy laws, including the GDPR and CCPA.

Boon reviews this list periodically and updates it to reflect operational or vendor changes. Customers may request notification of material changes by contacting privacy@goboon.co.

Vendor due diligence and safeguards

Before engaging a Sub-processor, Boon performs a security and privacy review that includes:

  • Assessment of the vendor's data-handling practices, technical and organisational controls, and relevant certifications (for example SOC 2, ISO 27001, PCI DSS)

  • Execution of a written data-processing or confidentiality agreement requiring compliance with applicable laws and Boon's security standards

  • Ongoing monitoring for material changes, incidents, or compliance issues

All personal data handled by Sub-processors remains Boon's responsibility, and processing occurs only under Boon's documented instructions.

Sub-processor list

Sub-processor

Purpose of processing

Categories of personal data

Processing location

Security / certifications

Amazon Web Services (AWS)

Cloud infrastructure and hosting

User data, usage data

United States

SOC 2, ISO 27001

Supabase

Database and backend infrastructure

User data, authentication data, application data, usage data

United States

SOC 2 Type II, ISO 27001, HIPAA, GDPR

SendGrid (Twilio Inc.)

Transactional email delivery

Name, email address, phone number, geolocation, images

United States

SOC 2 Type II, ISO 27001

Twilio

Transactional SMS delivery

Contact information, customer account data, communications usage data

United States

SOC 2 Type II, ISO 27001

Stripe

Payment processing

Billing information, transaction data, identity information

United States, EU

PCI DSS Level 1, SOC 2 Type II, ISO 27001

WorkOS

Authentication and SSO

Name, email address, IP address, device details

United States

SOC 2 Type II

Google

Authentication and SSO

Employee data, user data

United States

SOC 2, ISO 27001

Microsoft Outlook

Authentication and SSO

Name, email address, contact information

United States

SOC 2, ISO 27001

Algolia

Search indexing and retrieval

Identifiers (name, email address, IP address), usage data

United States, EU

SOC 2 Type II, ISO 27001

Merge.dev

ATS and HRIS integrations

Customer data, personal information

United States, EU, APAC

SOC 2 Type II, ISO 27001, HIPAA, GDPR

Slack

Internal collaboration and integrations

Contact information, usage data, messages

United States, EU

SOC 2, SOC 3, ISO 27001, HIPAA, GDPR

Rollbar

Application error monitoring

Error data, IP address, person ID, name, email address

United States

SOC 2 Type I/II, SOC 3, ISO 27001, HIPAA

Sentry

Application error monitoring

Error data, usage data

United States, EU

HIPAA, GDPR, CCPA

Hyperping

Uptime and availability monitoring

Name, email address, phone number, company name, IP address

EU

SOC 2 Type II, ISO 27001

Nightfall AI

Data loss prevention

User data, application content, personal information, credentials, usage data

United States

SOC 2 Type II

Last updated: August 2026.

View the live Sub-processor Directory

Data transfer mechanisms

Where Sub-processors are located outside the region in which customer data originates, Boon relies on established transfer mechanisms such as the EU–U.S. Data Privacy Framework, the UK Extension, and/or Standard Contractual Clauses to ensure an adequate level of protection for personal data.

Questions or requests

For questions regarding Sub-processors, or to request a copy of Boon's Data Processing Agreement, contact privacy@goboon.co.