05-HeroSimpleText
05-HeroSimpleText

JEDI Data Collection Policy & Framework

A comprehensive global compliance framework designed to govern the secure, sensitive collection of Justice, Equity, Diversity, and Inclusion metrics across our operating jurisdictions.

18-ContentGroup

Introduction & Objectives

The purpose of this Data Collection Policy is to define a baseline and direction for collecting company data across all operating regions: the Philippines, Colombia, Singapore, and Canada.

This Policy demonstrates support for, and commitment to, information collection objectives and applies to all forms of data, regardless of origin, format, or storage medium. It ensures that data collection practices remain consistent with applicable laws and international standards (e.g., B Corp).

14-Cards

Regional Legal Compliance Guidelines

  • Philippines:  Governed under the Data Privacy Act of 2012 (RA 10173)

  • Colombia: Governed under Statutory Law 1581 of 2012 and Decree 1377 of 2013

  • Singapore: Governed under the Personal Data Protection Act (PDPA) 2012

  • Canada: Governed under PIPEDA and provincial frameworks (Quebec's Law 25)

18-ContentGroup

Scope of Application

This Policy applies to all of Booth (the Company) and its divisions. All Employees of Booth are subject to this Policy, regardless of the type or length of relationship with Booth.

The Policy is also intended to protect the security of Booth information and assets when they are accessed by customers, vendors, distributors, consultants, business partners, and other third parties (collectively, "Third Parties").

14-Cards

Official Information Definition

"Information" referenced in this Policy includes personal information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.

18-ContentGroup

Definition of Terms

B Corp Certification (B Corp) B Corp Certification is an integrated business certification that assesses and verifies a company's social, environmental, and governance impact against the B Lab Standards.
Justice, Equity, Diversity and Inclusion (JEDI) A B Corp framework used to ensure fair treatment, access, and opportunity. In the context of data, it refers to using information to identify and remove systemic barriers (Justice), provide specific support (Equity), represent various identities (Diversity), and ensure all individuals feel safe and valued (Inclusion).
Data Privacy & Security Data Privacy: The right of an individual to maintain control over how their personal information is collected, used, and shared, ensuring that their personal digital identity is respected.
Data Security: The implementation of technical, physical, and administrative safeguards designed to protect data from unauthorized access, alteration, disclosure, or destruction.
Informed Consent & Data Minimization Informed Consent: A voluntary, specific, and documented agreement by a Data Subject to allow the processing of their personal data.
Data Minimization: The restriction of data collection to the specific points necessary for a defined professional purpose.
Data Masking The technical restriction of access to specific data fields based on user roles and permissions.
Habeas Data The legal right in Colombia for individuals to access, update, and rectify personal information stored in databases.
JEDI Data & Non-Aligned Data JEDI Data: Information concerning gender identity, race, ethnicity, indigenous status, disability, and sexual orientation that is used for diversity reporting.
Non-Aligned Data: Data points that are historically associated with systematic bias or are irrelevant to merit-based selection
Global Technology Excellence (GTE) The department responsible for maintaining the infrastructure, software systems, and security protocols of the company.
18-ContentGroup

Data Classification Tiers

Confidential Data

This includes highly sensitive information such as Personally Identifiable Information (PII), financial records, trade secrets, and other proprietary data. Access is restricted to authorized personnel with a legitimate need.

Approved JEDI Data Points (Collection Non-Mandatory)

Category A: Demographic

  • Gender Identity
  • LGBTQIA+ Status
  • Ethnolinguistic / Indigenous / Afro-descendant Status
  • Age Brackets

Category B: Equity

  • Disability Status
  • Reasonable Accommodation Requirements
  • Socio-economic Indicators (e.g., first-generation graduate)

 

Informed Consent Records: All timestamped digital or physical consent logs must be stored securely.

 

Internal Data

This includes internal reports, operational information, and other non-sensitive data that, while not publicly available, does not pose a major risk if accessed without authorization.

Operational Example
Aggregated, anonymized diversity reports used for internal strategy meetings, department reviews, and operational planning.

 

Public Data

This refers to information intended for public use, such as marketing materials, press releases, and publicly available content on the website.

Operational Example
General corporate statements regarding the company's B Corp status or high-level diversity commitments.
18-ContentGroup

Governance Framework

14-Cards

Mandatory Informed Consent

No digital or physical repository may store personal data without a corresponding timestamped record of Informed Consent. Systems must prevent manual inputs or submissions when consent is absent.


Technical Constraint

Systems must block the submission of any profile that does not include a timestamped Informed Consent Record.

Right of Revocation

Candidates and Employees may withdraw consent at any time. The GTE department ensures that the system flags these records for deletion within 30 days.

 

Role-Based Access Controls & Shield of Neutrality

To mitigate unconscious bias, the company employs a strict system-level "Shield of Neutrality" regarding JEDI metrics.


Selection Personnel

Restricted to professional competency data. JEDI Data is masked and invisible during the selection process.

Administrative Oversight

Access is limited to anonymized, aggregated reporting to monitor organizational health.

System Administration

Access is restricted to maintenance only and governed by rigorous audit logging. 

Prohibited & Restricted JEDI Data Points

Processing of JEDI information not outlined in Section 4.0 is prohibited. The following policies are enforced during the recruitment process:


Prohibited Data Points

> Religious affiliation
> Marital status
> Union affiliation
> Political leanings
> Current or past salary history 

Restricted Data Points

Pregnancy Status: Prohibited in recruitment; post-hire collection only for maternity benefit logistics.
Immigration Status: Only confirmed post conditional-offer to avoid national-origin bias.
Criminal Records: Requested at final background checks only if directly job-relevant.

 

Technical Request Process for New Data Points

Stakeholders requesting additional JEDI data parameters must submit a ticket to support@hirebooth.com detailing the target region, proposed fields, and study/report objectives. Implementation requires Approval Triage from the regional Data Privacy Officer, Information Security Officer, and department Glocom representative. If the regional DPO and Glocom 

Data Lifecycle & Purging SLAs

Data must not reside in company systems indefinitely. GTE configures systems to automatically purge inactive records after 3 years (Philippines) or in accordance with standard legal labor statutes (Colombia).


Disposal Method

Physical files undergo secure shredding. Digital directories undergo database anonymization so details can no longer be accessed or reconstructed.

Deletion Request SLAs

Erasure requests submitted to dpo@hirebooth.com are executed strictly within:

Physical records: 15 business days
Digital directories: 20 business days

 

18-ContentGroup

Data Utilization Framework

Data at Booth serves as a strategic corporate resource to identify structural barriers and support a just, equitable workspace, rather than acting as a passive compliance record.

14-Cards

JUSTICE

Systemic Barrier Removal

Used to audit existing company mechanisms, identify hidden structural biases, and intentionally dismantle bottlenecks that block fair access.

Operational Example: Recruitment Funnel Audits: slicing candidate progression rates to identify dropout trends.

EQUITY

Specific Support Allocation

Used to allocate resources, adjust historical imbalances, and provide tailored support structures to ensure everyone has a fair shot.

Operational Example: Pay Equity & Compensation Audits: conducting wage checks in identical roles to close pay gaps.

DIVERSITY

Tracking Representation

Used to track organizational demographics against macro labor markets to ensure Booth is inviting a broad spectrum of human identities.

Operational Example: Comparing internal headcount demographics against regional B Corp indices to inform sourcing.

INCLUSION

Sentiment Summaries

Used to evaluate how safe, valued, and respected employees feel within the organization, tracking actual workplace culture.

Operational Example: JEDI Impact Assessments: aggregating survey results to guide the next year's resource roadmaps

14-Cards

Strict Processing Boundaries

  • Permitted Scope: Information processing is strictly confined to professional assessment, aggregate B Corp reporting, and safety/accommodation configurations.

  • Anti-Discrimination: JEDI parameters must never be used to grade, disadvantage, or rank candidates or employees.

  • Aggregate-Only Strategic Studies: Slicing datasets for planning requires fully masked datasets to prevent candidate tracing.

  • Contractual Agreements: Third-party entities must strictly sign documentation enforcing masking rules.

18-ContentGroup

Stakeholder Accountabilities

STAKEHOLDER ROLE CORE ACCOUNTABILTIES & RESPONSIBILTIES
GTE Department Responsible for managing this policy, ensuring system configurations reflect compliance boundaries, role masking, and audits for B Corp.
Data Privacy Officer (DPO) Ensures system setups comply with local laws (RA 10173, Law 1581) across geographical branches, acting as final legal authority.
People Team Adheres to consent-first workflows for candidate intake; manages alerts to GTE regarding unauthorized transmission of confidential metrics.
Employees Acts as custodians of our corporate JEDI values. Strictly follows the mandatory "Duty to Report" protocol to report data breaches.
18-ContentGroup

Non-Compliance Framework

In coordination with the Booth Employee Handbook, corporate global operations operate in full compliance with local regulatory frameworks (the Data Privacy Act of 2012 for the Philippines and Law 1581 for Colombia).

Adherence to company policies on privacy, collection parameters, and network security is a mandatory condition of professional employment at Booth.

14-Cards

Disciplinary Standard:

Personnel violating these processing guidelines will undergo review, resulting in appropriate disciplinary action, which may include suspension up to and including immediate termination of relationship. Booth reserves legal rights against former employees who breach this privacy covenant.

18-ContentGroup

Security Incident Reporting Procedures

Global Centralized Response Channel Coverage (24/7)

14-Cards

Incident Definition

Data security incidents are defined as any unauthorized database entry, transmission, leak, or unapproved processing of restricted candidate metrics. Reports submitted in good faith will face no corporate repercussions or penalties.


Official Chat (GChat)

Message the space or send a direct message to IT Support for on-call responders.

Secondary (Email)

Direct inquiries to: support@hirebooth.com

Emergency Hotline

Call the emergency line: +63 966 771 6357.

Centralized Triage

Centralized Manila-based security operations utilize a Follow-the-Sun approach, delivering technical response support across South American and North American offices within a guaranteed 30-minute triage SLA.


Required Log Report Details: Affected systems/interfaces, category of threat, relevant screenshots/logs, and source vectors.