Privacy Policy

1. Data Controller

This Policy sets out how nearShift collects, stores, uses, shares, transmits, transfers and deletes personal data, and how data subjects can exercise their rights. nearShift is a company incorporated in Colombia, and this Policy is issued under Article 15 of the Colombian Constitution, Statutory Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and, where applicable, Law 1266 of 2008, as well as the instructions of the Superintendence of Industry and Commerce (SIC), Colombia’s data protection authority.

This Policy complements the Company’s Information Security Policy, Code of Ethics and Conduct, and Recruitment and Selection Manual.

3. Scope

This Policy covers the personal data of candidates, employees, former staff, contractors, shareholders, clients and prospects (and their representatives and contacts), suppliers, website visitors, and any other individual whose data nearShift processes. It is binding on the Company’s shareholders, legal representatives, employees and contractors, and on third parties that process data on its behalf.

4. Definitions

This Policy uses the definitions of Law 1581 of 2012 and its regulations. In particular:

5. Principles

nearShift applies the principles of legality, purpose limitation, freedom, accuracy, transparency, restricted access and circulation, security and confidentiality set out in Article 4 of Law 1581 of 2012. Accordingly, it only collects the data needed for legitimate purposes disclosed to the data subject, does not use it for other purposes, and limits access to the people who need it to perform their duties.

6. Data processed and purposes

nearShift processes the following data for the purposes listed in each case. In addition to these specific purposes, all data may be processed to comply with legal obligations, respond to requests from competent authorities, and exercise or defend the Company’s rights.

6.1. Job candidates

Data: name, ID number, contact details, city of residence, resume, education, work experience, certifications, skills, compensation expectations, interview and technical assessment results, work references and, with express consent, background check results.

6.2. Employees, former staff and contractors

Data: identification, contact details, family member and beneficiary data, education and employment information, bank details, salary or fees, social security affiliations, sick leave information, performance reviews, credentials and usage logs of Company systems, and biometric data (photo or selfie) collected during e-signature processes with identity verification.

6.3. Clients, prospects and business partners

Data: name, job title, company, email, phone number, and the information shared in meetings, proposals and business communications.

6.4. Suppliers and shareholders

Data: identification, contact details, tax and bank information and, for shareholders, the corporate information required by law.

6.5. Website visitors

Data: the information visitors enter in the contact form (name, work email, company, company size, service of interest and message) or send by email, and the technical data generated when visiting the site, such as IP address and browser type.

The site does not use analytics or advertising cookies. To display fonts and images, the visitor’s browser connects to third-party services (Google Fonts and Unsplash), which receive the visitor’s IP address under their own policies. The contact form is processed through the provider Web3Forms, which acts as a Processor.

7. Sensitive data and children’s data

nearShift only processes sensitive data when necessary for the stated purpose and with the data subject’s explicit authorization, except in the cases set out in Article 6 of Law 1581 of 2012. Data subjects are not required to authorize the processing of sensitive data or to answer questions about it. This applies, among others, to health information in sick leave records and to biometric data used for identity verification in e-signatures.

Data about children and adolescents, such as that of employees’ children registered as social security beneficiaries, is processed only to comply with legal obligations, with the authorization of their legal representative, and with respect for their best interests and fundamental rights.

8. Authorization

nearShift requests the data subject’s authorization no later than at the time of collection, in writing, electronically, or through unequivocal conduct showing that it was granted, in accordance with Article 7 of Decree 1377 of 2013. Unequivocal conduct includes voluntarily sending a resume to [email protected] or [email protected], or submitting the contact form, after having been informed through the privacy notice of this Policy; this form of authorization does not apply to sensitive data or to data of children and adolescents, which require express authorization. The Company keeps proof of these authorizations.

Authorization is not required in the cases set out in Article 10 of Law 1581 of 2012, such as information requested by a public authority in the exercise of its functions or data of a public nature.

9. Data subjects’ rights

Under Article 8 of Law 1581 of 2012, data subjects have the right to:

These rights may be exercised by the data subject, their successors, their representative or attorney-in-fact, or a person acting on their behalf by stipulation, upon proof of such capacity.

10. nearShift’s duties

As Controller, nearShift complies with the duties in Article 17 of Law 1581 of 2012, including guaranteeing the exercise of data subjects’ rights, keeping proof of authorization, disclosing the purpose of processing, keeping information secure, updating and correcting it when appropriate, handling inquiries and claims within the legal deadlines, and reporting security incidents to the SIC.

When nearShift processes personal data on behalf of its clients as part of the software development and engineering services it provides to them, it acts as a Processor: it processes that data only on the client’s instructions and as agreed in the contract, and complies with the duties in Article 18 of Law 1581 of 2012.

11. Inquiries and claims

The Company’s Principal Legal Representative, or the person they designate in writing, is responsible for handling inquiries and claims. Requests can be sent to [email protected] or in writing to the Company’s address, stating the data subject’s name, ID number, contact details and a description of the request.

11.1. Inquiries

Inquiries are answered within a maximum of ten (10) business days from receipt. If this is not possible, the requester will be informed of the reason for the delay and the response date, which may not exceed five (5) additional business days.

11.2. Claims

Anyone who believes their data should be corrected, updated or deleted, or who notices a possible breach of this Policy or the law, may file a claim including the data subject’s identification, a description of the facts, a reply address and any supporting documents. If the claim is incomplete, the requester will be asked to complete it within five (5) business days of receipt; if two (2) months pass without a response, the claim will be deemed withdrawn. If nearShift is not competent to resolve the claim, it will forward it to the appropriate party within two (2) business days and inform the requester.

Once a complete claim is received, the legend “claim in process” will be added to the database within two (2) business days. Claims are resolved within a maximum of fifteen (15) business days; if this is not possible, the requester will be informed of the reasons and the response date, which may not exceed eight (8) additional business days.

Requests for deletion or revocation of authorization do not apply when the data subject has a legal or contractual duty to remain in the database.

12. International transmissions and transfers

To operate, nearShift uses technology providers that act as Processors and may store or process data outside Colombia, including cloud email and storage, website hosting, e-signature, web forms, accounting and payroll, and international payment services. These transmissions are governed by each provider’s data processing contracts or agreements, which require the Processor to process the data only on nearShift’s instructions and with appropriate security measures, in accordance with Article 25 of Decree 1377 of 2013.

nearShift may also transfer data to its clients abroad, mainly in the United States and Canada, for the purposes in sections 6.1 and 6.2. International transfers are made to countries that provide an adequate level of protection according to the SIC or, where the destination country is not listed as adequate, based on the data subject’s express and unequivocal authorization or the other exceptions in Article 26 of Law 1581 of 2012.

13. Information security

nearShift implements technical, human and administrative measures to protect personal data against tampering, loss, and unauthorized access or use, in accordance with its Information Security Policy. Incidents affecting personal data will be reported to the SIC as required by law.

14. Data retention

Data is kept only for as long as reasonable and necessary to fulfill the purposes of processing and the applicable legal or contractual obligations, in accordance with Article 11 of Decree 1377 of 2013. In particular:

After these periods, data is securely deleted or anonymized.

15. National Database Registry

nearShift will register its databases in the National Database Registry (RNBD) managed by the SIC when required to do so under the regulations in force.

16. Effective date and changes

This Policy takes effect upon its publication at https://nearshift.co. The databases will remain in force for as long as the purposes described above apply. Any material change will be communicated to data subjects before it takes effect, through the website or the contact details on file.

Annex. Privacy notice

NEARSHIFT S.A.S. (Tax ID 902076172-7), located at Calle 52 # 78 - 02, Piso 2, Medellín, Colombia, is the controller of the personal data you provide to us. We will use it to respond to your request and, if you are applying for a job, to assess your profile for current and future openings at nearShift and its clients, who may receive your professional profile in Colombia or abroad, for up to two (2) years. You have the right to access, update, correct and delete your data and to revoke your authorization by writing to [email protected]. Answering questions about sensitive data is optional. Read our full Privacy Policy at https://nearshift.co/privacy.