Privacy Policy
1. Data Controller
- Company name: NEARSHIFT S.A.S. (“nearShift” or the “Company”).
- Tax ID (NIT): 902076172-7.
- Address: Calle 52 # 78 - 02, Piso 2, Medellín, Antioquia, Colombia.
- Email for personal data matters: [email protected]
- Phone: +57 300 124 8342.
- Website: https://nearshift.co
2. Purpose and legal framework
This Policy sets out how nearShift collects, stores, uses, shares, transmits, transfers and deletes personal data, and how data subjects can exercise their rights. nearShift is a company incorporated in Colombia, and this Policy is issued under Article 15 of the Colombian Constitution, Statutory Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and, where applicable, Law 1266 of 2008, as well as the instructions of the Superintendence of Industry and Commerce (SIC), Colombia’s data protection authority.
This Policy complements the Company’s Information Security Policy, Code of Ethics and Conduct, and Recruitment and Selection Manual.
3. Scope
This Policy covers the personal data of candidates, employees, former staff, contractors, shareholders, clients and prospects (and their representatives and contacts), suppliers, website visitors, and any other individual whose data nearShift processes. It is binding on the Company’s shareholders, legal representatives, employees and contractors, and on third parties that process data on its behalf.
4. Definitions
This Policy uses the definitions of Law 1581 of 2012 and its regulations. In particular:
- Data subject: the individual whose personal data is processed.
- Personal data: any information linked to, or that can be associated with, one or more identified or identifiable individuals.
- Sensitive data: data that affects the data subject’s privacy or whose misuse could lead to discrimination, such as health and biometric data.
- Processing: any operation on personal data, such as collection, storage, use, sharing or deletion.
- Controller: the party that decides on the database and the processing of the data.
- Processor: the party that processes data on behalf of the Controller.
- Authorization: the data subject’s prior, express and informed consent to the processing of their data.
- Transfer: sending data to a recipient that is itself a Controller, inside or outside Colombia.
- Transmission: sending data to a Processor, inside or outside Colombia, to process it on behalf of the Controller.
5. Principles
nearShift applies the principles of legality, purpose limitation, freedom, accuracy, transparency, restricted access and circulation, security and confidentiality set out in Article 4 of Law 1581 of 2012. Accordingly, it only collects the data needed for legitimate purposes disclosed to the data subject, does not use it for other purposes, and limits access to the people who need it to perform their duties.
6. Data processed and purposes
nearShift processes the following data for the purposes listed in each case. In addition to these specific purposes, all data may be processed to comply with legal obligations, respond to requests from competent authorities, and exercise or defend the Company’s rights.
6.1. Job candidates
Data: name, ID number, contact details, city of residence, resume, education, work experience, certifications, skills, compensation expectations, interview and technical assessment results, work references and, with express consent, background check results.
- Assess the candidate’s profile against current openings at nearShift and its clients, for which purpose nearShift may share the candidate’s professional profile (name, experience, skills and availability) with those clients, in Colombia or abroad.
- Contact the candidate for interviews, technical assessments and other stages of the selection process.
- Verify the candidate’s identity, references, education and background, in accordance with the Recruitment and Selection Manual and with the candidate’s consent.
- Keep the resume for up to two (2) years from receipt to consider the candidate for future openings, unless the candidate requests deletion earlier.
6.2. Employees, former staff and contractors
Data: identification, contact details, family member and beneficiary data, education and employment information, bank details, salary or fees, social security affiliations, sick leave information, performance reviews, credentials and usage logs of Company systems, and biometric data (photo or selfie) collected during e-signature processes with identity verification.
- Enter into, perform and terminate the employment or services agreement.
- Process payroll, fees, benefits and social security contributions.
- Comply with labor, tax, accounting and occupational health and safety obligations.
- Create and manage assigned accounts, access rights and equipment, and protect the security of the Company’s and its clients’ information.
- Share the professional profile (name, experience, skills and availability) with the Company’s clients, in Colombia or abroad, to staff them on projects.
- Issue employment certificates and respond to reference requests, at the data subject’s request.
6.3. Clients, prospects and business partners
Data: name, job title, company, email, phone number, and the information shared in meetings, proposals and business communications.
- Respond to inquiries and send commercial proposals.
- Enter into and perform contracts, invoice, and manage collections and payments.
- Send communications about the Company’s services; the data subject may opt out at any time.
6.4. Suppliers and shareholders
Data: identification, contact details, tax and bank information and, for shareholders, the corporate information required by law.
- Manage purchases, payments, tax obligations and the contractual relationship with the supplier.
- Comply with corporate and commercial obligations toward shareholders.
6.5. Website visitors
Data: the information visitors enter in the contact form (name, work email, company, company size, service of interest and message) or send by email, and the technical data generated when visiting the site, such as IP address and browser type.
- Respond to the contact request and follow up commercially.
- Operate the site and protect it against abuse and spam.
The site does not use analytics or advertising cookies. To display fonts and images, the visitor’s browser connects to third-party services (Google Fonts and Unsplash), which receive the visitor’s IP address under their own policies. The contact form is processed through the provider Web3Forms, which acts as a Processor.
7. Sensitive data and children’s data
nearShift only processes sensitive data when necessary for the stated purpose and with the data subject’s explicit authorization, except in the cases set out in Article 6 of Law 1581 of 2012. Data subjects are not required to authorize the processing of sensitive data or to answer questions about it. This applies, among others, to health information in sick leave records and to biometric data used for identity verification in e-signatures.
Data about children and adolescents, such as that of employees’ children registered as social security beneficiaries, is processed only to comply with legal obligations, with the authorization of their legal representative, and with respect for their best interests and fundamental rights.
8. Authorization
nearShift requests the data subject’s authorization no later than at the time of collection, in writing, electronically, or through unequivocal conduct showing that it was granted, in accordance with Article 7 of Decree 1377 of 2013. Unequivocal conduct includes voluntarily sending a resume to [email protected] or [email protected], or submitting the contact form, after having been informed through the privacy notice of this Policy; this form of authorization does not apply to sensitive data or to data of children and adolescents, which require express authorization. The Company keeps proof of these authorizations.
Authorization is not required in the cases set out in Article 10 of Law 1581 of 2012, such as information requested by a public authority in the exercise of its functions or data of a public nature.
9. Data subjects’ rights
Under Article 8 of Law 1581 of 2012, data subjects have the right to:
- Access, update and correct their personal data.
- Request proof of the authorization granted, except where it is not required.
- Be informed, upon request, of how their data has been used.
- File complaints with the Superintendence of Industry and Commerce after completing the inquiry or claim process with nearShift.
- Revoke their authorization and request deletion of their data when there is no legal or contractual duty to keep it.
- Access their personal data free of charge at least once every calendar month and whenever there are substantial changes to this Policy that give rise to new inquiries; additional inquiries may incur shipping or reproduction costs, which will be disclosed in advance.
These rights may be exercised by the data subject, their successors, their representative or attorney-in-fact, or a person acting on their behalf by stipulation, upon proof of such capacity.
10. nearShift’s duties
As Controller, nearShift complies with the duties in Article 17 of Law 1581 of 2012, including guaranteeing the exercise of data subjects’ rights, keeping proof of authorization, disclosing the purpose of processing, keeping information secure, updating and correcting it when appropriate, handling inquiries and claims within the legal deadlines, and reporting security incidents to the SIC.
When nearShift processes personal data on behalf of its clients as part of the software development and engineering services it provides to them, it acts as a Processor: it processes that data only on the client’s instructions and as agreed in the contract, and complies with the duties in Article 18 of Law 1581 of 2012.
11. Inquiries and claims
The Company’s Principal Legal Representative, or the person they designate in writing, is responsible for handling inquiries and claims. Requests can be sent to [email protected] or in writing to the Company’s address, stating the data subject’s name, ID number, contact details and a description of the request.
11.1. Inquiries
Inquiries are answered within a maximum of ten (10) business days from receipt. If this is not possible, the requester will be informed of the reason for the delay and the response date, which may not exceed five (5) additional business days.
11.2. Claims
Anyone who believes their data should be corrected, updated or deleted, or who notices a possible breach of this Policy or the law, may file a claim including the data subject’s identification, a description of the facts, a reply address and any supporting documents. If the claim is incomplete, the requester will be asked to complete it within five (5) business days of receipt; if two (2) months pass without a response, the claim will be deemed withdrawn. If nearShift is not competent to resolve the claim, it will forward it to the appropriate party within two (2) business days and inform the requester.
Once a complete claim is received, the legend “claim in process” will be added to the database within two (2) business days. Claims are resolved within a maximum of fifteen (15) business days; if this is not possible, the requester will be informed of the reasons and the response date, which may not exceed eight (8) additional business days.
Requests for deletion or revocation of authorization do not apply when the data subject has a legal or contractual duty to remain in the database.
12. International transmissions and transfers
To operate, nearShift uses technology providers that act as Processors and may store or process data outside Colombia, including cloud email and storage, website hosting, e-signature, web forms, accounting and payroll, and international payment services. These transmissions are governed by each provider’s data processing contracts or agreements, which require the Processor to process the data only on nearShift’s instructions and with appropriate security measures, in accordance with Article 25 of Decree 1377 of 2013.
nearShift may also transfer data to its clients abroad, mainly in the United States and Canada, for the purposes in sections 6.1 and 6.2. International transfers are made to countries that provide an adequate level of protection according to the SIC or, where the destination country is not listed as adequate, based on the data subject’s express and unequivocal authorization or the other exceptions in Article 26 of Law 1581 of 2012.
13. Information security
nearShift implements technical, human and administrative measures to protect personal data against tampering, loss, and unauthorized access or use, in accordance with its Information Security Policy. Incidents affecting personal data will be reported to the SIC as required by law.
14. Data retention
Data is kept only for as long as reasonable and necessary to fulfill the purposes of processing and the applicable legal or contractual obligations, in accordance with Article 11 of Decree 1377 of 2013. In particular:
- Candidates not selected: up to two (2) years from receipt of the resume, unless deletion is requested earlier.
- Employees and contractors: for the duration of the relationship and, after it ends, for the periods required by labor, social security, accounting, tax and commercial regulations.
- Clients, prospects and suppliers: for as long as the business relationship lasts and for the retention periods that the law requires for accounting and commercial records.
- Website inquiries that do not lead to a business relationship: up to two (2) years from receipt.
After these periods, data is securely deleted or anonymized.
15. National Database Registry
nearShift will register its databases in the National Database Registry (RNBD) managed by the SIC when required to do so under the regulations in force.
16. Effective date and changes
This Policy takes effect upon its publication at https://nearshift.co. The databases will remain in force for as long as the purposes described above apply. Any material change will be communicated to data subjects before it takes effect, through the website or the contact details on file.
Annex. Privacy notice
NEARSHIFT S.A.S. (Tax ID 902076172-7), located at Calle 52 # 78 - 02, Piso 2, Medellín, Colombia, is the controller of the personal data you provide to us. We will use it to respond to your request and, if you are applying for a job, to assess your profile for current and future openings at nearShift and its clients, who may receive your professional profile in Colombia or abroad, for up to two (2) years. You have the right to access, update, correct and delete your data and to revoke your authorization by writing to [email protected]. Answering questions about sensitive data is optional. Read our full Privacy Policy at https://nearshift.co/privacy.