JEDI Data Collection Policy & Framework
A comprehensive global compliance framework designed to govern the secure, sensitive collection of Justice, Equity, Diversity, and Inclusion metrics across our operating jurisdictions.
Introduction & Objectives
The purpose of this Data Collection Policy is to define a baseline and direction for collecting company data across all operating regions: the Philippines, Colombia, Singapore, and Canada.
This Policy demonstrates support for, and commitment to, information collection objectives and applies to all forms of data, regardless of origin, format, or storage medium. It ensures that data collection practices remain consistent with applicable laws and international standards (e.g., B Corp).
Regional Legal Compliance Guidelines
-
Philippines: Governed under the Data Privacy Act of 2012 (RA 10173)
-
Colombia: Governed under Statutory Law 1581 of 2012 and Decree 1377 of 2013
-
Singapore: Governed under the Personal Data Protection Act (PDPA) 2012
-
Canada: Governed under PIPEDA and provincial frameworks (Quebec's Law 25)
Scope of Application
This Policy applies to all of Booth (the Company) and its divisions. All Employees of Booth are subject to this Policy, regardless of the type or length of relationship with Booth.
The Policy is also intended to protect the security of Booth information and assets when they are accessed by customers, vendors, distributors, consultants, business partners, and other third parties (collectively, "Third Parties").
Official Information Definition
"Information" referenced in this Policy includes personal information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
Definition of Terms
| B Corp Certification (B Corp) | B Corp Certification is an integrated business certification that assesses and verifies a company's social, environmental, and governance impact against the B Lab Standards. |
| Justice, Equity, Diversity and Inclusion (JEDI) | A B Corp framework used to ensure fair treatment, access, and opportunity. In the context of data, it refers to using information to identify and remove systemic barriers (Justice), provide specific support (Equity), represent various identities (Diversity), and ensure all individuals feel safe and valued (Inclusion). |
| Data Privacy & Security | Data Privacy: The right of an individual to maintain control over how their personal information is collected, used, and shared, ensuring that their personal digital identity is respected. Data Security: The implementation of technical, physical, and administrative safeguards designed to protect data from unauthorized access, alteration, disclosure, or destruction. |
| Informed Consent & Data Minimization | Informed Consent: A voluntary, specific, and documented agreement by a Data Subject to allow the processing of their personal data. Data Minimization: The restriction of data collection to the specific points necessary for a defined professional purpose. |
| Data Masking | The technical restriction of access to specific data fields based on user roles and permissions. |
| Habeas Data | The legal right in Colombia for individuals to access, update, and rectify personal information stored in databases. |
| JEDI Data & Non-Aligned Data | JEDI Data: Information concerning gender identity, race, ethnicity, indigenous status, disability, and sexual orientation that is used for diversity reporting. Non-Aligned Data: Data points that are historically associated with systematic bias or are irrelevant to merit-based selection |
| Global Technology Excellence (GTE) | The department responsible for maintaining the infrastructure, software systems, and security protocols of the company. |
Data Classification Tiers
Confidential Data
This includes highly sensitive information such as Personally Identifiable Information (PII), financial records, trade secrets, and other proprietary data. Access is restricted to authorized personnel with a legitimate need.
Approved JEDI Data Points (Collection Non-Mandatory)
|
Category A: Demographic
|
Category B: Equity
|
| Informed Consent Records: All timestamped digital or physical consent logs must be stored securely. |
Internal Data
This includes internal reports, operational information, and other non-sensitive data that, while not publicly available, does not pose a major risk if accessed without authorization.
| Operational Example Aggregated, anonymized diversity reports used for internal strategy meetings, department reviews, and operational planning. |
Public Data
This refers to information intended for public use, such as marketing materials, press releases, and publicly available content on the website.
| Operational Example General corporate statements regarding the company's B Corp status or high-level diversity commitments. |
Governance Framework
Mandatory Informed Consent
No digital or physical repository may store personal data without a corresponding timestamped record of Informed Consent. Systems must prevent manual inputs or submissions when consent is absent.
|
Technical Constraint Systems must block the submission of any profile that does not include a timestamped Informed Consent Record. |
Right of Revocation Candidates and Employees may withdraw consent at any time. The GTE department ensures that the system flags these records for deletion within 30 days. |
Role-Based Access Controls & Shield of Neutrality
To mitigate unconscious bias, the company employs a strict system-level "Shield of Neutrality" regarding JEDI metrics.
|
Selection Personnel Restricted to professional competency data. JEDI Data is masked and invisible during the selection process. |
Administrative Oversight Access is limited to anonymized, aggregated reporting to monitor organizational health. |
System Administration Access is restricted to maintenance only and governed by rigorous audit logging. |
Prohibited & Restricted JEDI Data Points
Processing of JEDI information not outlined in Section 4.0 is prohibited. The following policies are enforced during the recruitment process:
|
Prohibited Data Points > Religious affiliation |
Restricted Data Points Pregnancy Status: Prohibited in recruitment; post-hire collection only for maternity benefit logistics. |
Technical Request Process for New Data Points
Stakeholders requesting additional JEDI data parameters must submit a ticket to support@hirebooth.com detailing the target region, proposed fields, and study/report objectives. Implementation requires Approval Triage from the regional Data Privacy Officer, Information Security Officer, and department Glocom representative. If the regional DPO and Glocom
Data Lifecycle & Purging SLAs
Data must not reside in company systems indefinitely. GTE configures systems to automatically purge inactive records after 3 years (Philippines) or in accordance with standard legal labor statutes (Colombia).
|
Disposal Method Physical files undergo secure shredding. Digital directories undergo database anonymization so details can no longer be accessed or reconstructed. |
Deletion Request SLAs Erasure requests submitted to dpo@hirebooth.com are executed strictly within: |
Data Utilization Framework
Data at Booth serves as a strategic corporate resource to identify structural barriers and support a just, equitable workspace, rather than acting as a passive compliance record.
JUSTICE
Systemic Barrier Removal
Used to audit existing company mechanisms, identify hidden structural biases, and intentionally dismantle bottlenecks that block fair access.
Operational Example: Recruitment Funnel Audits: slicing candidate progression rates to identify dropout trends.
EQUITY
Specific Support Allocation
Used to allocate resources, adjust historical imbalances, and provide tailored support structures to ensure everyone has a fair shot.
Operational Example: Pay Equity & Compensation Audits: conducting wage checks in identical roles to close pay gaps.
DIVERSITY
Tracking Representation
Used to track organizational demographics against macro labor markets to ensure Booth is inviting a broad spectrum of human identities.
Operational Example: Comparing internal headcount demographics against regional B Corp indices to inform sourcing.
INCLUSION
Sentiment Summaries
Used to evaluate how safe, valued, and respected employees feel within the organization, tracking actual workplace culture.
Operational Example: JEDI Impact Assessments: aggregating survey results to guide the next year's resource roadmaps
Strict Processing Boundaries
-
Permitted Scope: Information processing is strictly confined to professional assessment, aggregate B Corp reporting, and safety/accommodation configurations.
-
Anti-Discrimination: JEDI parameters must never be used to grade, disadvantage, or rank candidates or employees.
-
Aggregate-Only Strategic Studies: Slicing datasets for planning requires fully masked datasets to prevent candidate tracing.
-
Contractual Agreements: Third-party entities must strictly sign documentation enforcing masking rules.
Stakeholder Accountabilities
| STAKEHOLDER ROLE | CORE ACCOUNTABILTIES & RESPONSIBILTIES |
| GTE Department | Responsible for managing this policy, ensuring system configurations reflect compliance boundaries, role masking, and audits for B Corp. |
| Data Privacy Officer (DPO) | Ensures system setups comply with local laws (RA 10173, Law 1581) across geographical branches, acting as final legal authority. |
| People Team | Adheres to consent-first workflows for candidate intake; manages alerts to GTE regarding unauthorized transmission of confidential metrics. |
| Employees | Acts as custodians of our corporate JEDI values. Strictly follows the mandatory "Duty to Report" protocol to report data breaches. |
Non-Compliance Framework
In coordination with the Booth Employee Handbook, corporate global operations operate in full compliance with local regulatory frameworks (the Data Privacy Act of 2012 for the Philippines and Law 1581 for Colombia).
Adherence to company policies on privacy, collection parameters, and network security is a mandatory condition of professional employment at Booth.
Disciplinary Standard:
Personnel violating these processing guidelines will undergo review, resulting in appropriate disciplinary action, which may include suspension up to and including immediate termination of relationship. Booth reserves legal rights against former employees who breach this privacy covenant.
Security Incident Reporting Procedures
Global Centralized Response Channel Coverage (24/7)
Incident Definition
Data security incidents are defined as any unauthorized database entry, transmission, leak, or unapproved processing of restricted candidate metrics. Reports submitted in good faith will face no corporate repercussions or penalties.
|
Official Chat (GChat) Message the space or send a direct message to IT Support for on-call responders. |
Secondary (Email) Direct inquiries to: support@hirebooth.com |
Emergency Hotline Call the emergency line: +63 966 771 6357. |
Centralized Triage
Centralized Manila-based security operations utilize a Follow-the-Sun approach, delivering technical response support across South American and North American offices within a guaranteed 30-minute triage SLA.
|
Required Log Report Details: Affected systems/interfaces, category of threat, relevant screenshots/logs, and source vectors. |