Skip to content

Meet Nearsoft at LATAM Fintech Market in Barranquilla, Colombia on September 17 and 18!

Learn More
Nearsoft

Nearsoft Privacy Policy

Last updated: 19 August 2026

Effective date: 20 August 2026

Scope

This Privacy Policy sets out what personal data we collect, how and why we use it, the lawful bases we rely on, with whom we share it, how long we keep it and the rights available to you under the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and Portuguese Law no. 58/2019 of 8 August, which ensures the implementation of the GDPR in the national legal order, and, as regards cookies and similar technologies, Law no. 41/2004 of 18 August, as currently worded.

Data Controller

  • Your personal data is the responsibility of PTNearsoft, Lda (Zona Franca da Madeira), hereinafter referred to as “NEARSOFT”, with registered office at Rua do Comboio n.º 3, 2.º Andar, 9050-053 Funchal, Portugal.
  • The Data Protection Officer may be contacted at the following e-mail address: privacy@nearsoft.pt.

Personal Data Collected

We collect the following categories of personal data:
  • Personal Identification Data, such as name, email address, telephone number, job title, company name and other information provided through the forms on our website.
  • Usage Data, such as information about how you use our website and services.
  • Technical Data, such as Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Marketing / Newsletter Data, such as email address and other data necessary to manage newsletter subscriptions and marketing communications, where applicable.
  • Job Application Data, such as name, contact details, curriculum vitae (CV), academic qualifications, professional experience and other information you voluntarily submit through our recruitment form. In the recruitment context, NEARSOFT does not, as a rule, request information relating to private life, health, pregnancy, political or religious beliefs or trade union membership, except where this is legally required or justifiable under the applicable employment legislation.
  • Reference Data, where the candidate provides it, the name and contact details of the persons given as references, as well as the information they provide to us about the candidate’s professional background.
If you are given as a reference by a candidate, we process your contact details solely in order to obtain information about that candidate, on the basis of our legitimate interest in the recruitment process. Your data is retained for the same retention period applicable to the data of the candidate concerned, and you have the same rights as described in the ‘Your Rights’ section of this policy.

Our services are intended for a professional audience (companies in the banking and financial sectors) and are not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. Should we become aware that we have collected personal data from a minor without the appropriate consent of the holder of parental responsibility, we will delete it.

How We Use Your Information

We use your personal data for the following purposes, on the lawful bases indicated below:
  • Contact and lead management
    • Purpose: Responding to enquiries, contacting potential clients and scheduling meetings.
    • Lawful basis: Consent (Article 6(1)(a)) and/or legitimate interest in developing business relationships (Article 6(1)(f)).
  • Improvement and development
    • Purpose: Analysing usage in order to improve the website and services.
    • Lawful basis: Legitimate interest in improving our offering (Article 6(1)(f)).
  • Marketing communications
    • Purpose: Sending news, content and other marketing communications where legally permitted.
    • Lawful basis: Consent (Article 6(1)(a)) or legitimate interest for existing contacts, where permitted (Article 6(1)(f)).
  • Legal compliance
    • Purpose: Complying with legal obligations and responding to valid requests from authorities.
    • Lawful basis: Compliance with a legal obligation (Article 6(1)(c)).
  • Recruitment and selection
    • Purpose: Assessing applications and ongoing recruitment processes submitted through the website.
    • Lawful basis: Pre-contractual steps at your request (Article 6(1)(b)) and, if you consent to being kept in a database for future opportunities, consent (Article 6(1)(a)).
  • Reference checking
    • Purpose: Contacting references given by the candidate, where applicable.
    • Lawful basis: Legitimate interest in the recruitment process (Article 6(1)(f)).
Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You may object to this processing at any time.

Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of the processing carried out before its withdrawal.

Providing your personal data for contact management and marketing communication purposes is voluntary; if you do not provide it, this simply means that we will not be able to contact you or respond to your request. 

The provision of certain data for the delivery of contracted services is, however, necessary for the performance of the relevant contract; failure to provide it may prevent us from providing the requested service.

Data Retention

We retain your personal data only for as long as is necessary for the purposes for which it was collected:
  • Contact / Lead Data: up to 24 months after the last relevant contact or interaction, unless the data is required for a shorter period or there is a legal basis for longer retention, or until you unsubscribe.
  • Marketing / Newsletter Data: until you withdraw your consent or unsubscribe.
  • Usage and Technical Data: retained for the period necessary for website analytics and improvement purposes, in accordance with the retention settings applicable to Google Analytics.
  • Data Retained under a Legal Obligation: for the period required by the applicable legislation
  • Job Application Data: up to 1 year after the conclusion of the recruitment process, after which it is deleted, unless the candidate consents to being kept in a database for future opportunities. If you are hired, your data will then be processed within the scope of the employment relationship, for additional purposes about which you will be informed separately.
  • Reference Data: for the same retention period applicable to the data of the candidate to whom it relates.
Once the data is no longer necessary, we securely delete it or it will be securely anonymised, unless its retention is legally required or necessary for the establishment or defence of legal claims.

Data Sharing and Disclosure

We do not sell, trade or otherwise transfer your personal data to third parties without your consent, except as described in this Privacy Policy. We may share your data with:
  • Web analytics tools (Google Analytics), which process usage and technical data for improvement and development purposes.
  • CRM and Marketing platforms, which process personal identification data for contact management and marketing communication purposes.
  • Applicant tracking systems (ATS), which process job application data for recruitment and selection purposes.
  • Authorities or third parties, where required by law or to protect our legal rights.
  • In the context of any merger, acquisition, corporate restructuring or sale of assets of NEARSOFT, your personal data may be shared with the parties involved in that transaction, subject to appropriate confidentiality obligations.
All of the above providers process data on our behalf under written data processing agreements (Article 28 of the GDPR), which require them to process the data only in accordance with our instructions and to apply appropriate security measures.

International Data Transfers

We use Google Analytics to analyse the use of our website. The use of this service may involve the processing of personal data outside the European Economic Area (EEA), including in the United States. Google applies appropriate mechanisms for international data transfers, including, where applicable, the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.

You may request further information about these safeguards by contacting privacy@nearsoft.pt.

Security of Your Data

We adopt appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 of the GDPR. These measures include, in particular:
  • Encryption of data in transit and at rest, and the exclusive use of secure connections (HTTPS/TLS) on our website;
  • Access control based on the need-to-know principle, multi-factor authentication and periodic review of privileges;
  • Logging and monitoring of access and security events, with documented incident management procedures;
  • Regular information security and data protection training for our employees, who are subject to contractual confidentiality duties;
  • Careful assessment and selection of processors, bound by data processing agreements under Article 28 of the GDPR;
  • Backups and recovery procedures tested periodically.
In addition, NEARSOFT maintains an Information Security Management System certified to the ISO/IEC 27001 standard, subject to periodic independent audits.

Should a personal data breach occur that is likely to result in a risk to your rights and freedoms, we will notify the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados) within 72 hours and, where the risk is high, we will also inform you directly, in accordance with Articles 33 and 34 of the GDPR.

Your Rights

Under the General Data Protection Regulation, you have certain rights in relation to your personal data. The exercise of these rights may be subject to the conditions and limitations provided for in the applicable legislation.
  • Right to be informed: You have the right to receive clear, transparent and easily accessible information about how we process your personal data, including the purposes of the processing, the lawful bases, the categories of data processed, the retention periods, the recipients of the data and your rights. This Privacy Policy is intended to provide that information.
  • Right of access: You have the right to obtain confirmation as to whether we process personal data concerning you and, if so, to request access to that data and to certain information about the processing, including the purposes, categories of data, recipients and, where possible, the retention period. In certain circumstances, you are also entitled to obtain a copy of your personal data. 
  • Right to rectification: You have the right to request the correction of inaccurate personal data and, considering the purposes of the processing, to have incomplete personal data completed. 
  • Right to erasure (‘right to be forgotten’): You may request the erasure of your personal data where, in particular, the data is no longer necessary for the purposes for which it was collected, where you withdraw your consent and there is no other legal basis for the processing, or where the processing is unlawful. This right is not absolute and may not apply where the retention of the data is necessary for compliance with a legal obligation or for the establishment or defence of legal claims. 
  • Right to restriction of processing: You may request the restriction of the processing of your personal data in certain circumstances, for example, where you contest the accuracy of the data, where you consider the processing to be unlawful but prefer to restrict its use rather than request erasure, or where you need the data for the establishment or defence of legal claims. 
  • Right to data portability: Where legally applicable, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller. This right applies only in certain situations, in particular where the processing is based on consent or on a contract and is carried out by automated means. 
  • Right to object: You have the right to object, on grounds relating to your particular situation, to the processing of your personal data that is based on our legitimate interest, including certain profiling situations. Where data is processed for direct marketing purposes, including profiling related to that marketing, you may object to that processing at any time. 
  • Right to withdraw consent: Where the processing of your personal data is based on your consent, you may withdraw that consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent before its withdrawal.
  • Right not to be subject to solely automated decisions: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where one of the situations provided for in the GDPR applies.
To exercise any of these rights, please contact us at privacy@nearsoft.pt. We may request additional information to confirm your identity, where necessary to protect your personal data. We will respond to your request without undue delay and, as a rule, within one month of receipt.

If you consider that we have not processed your data appropriately, you have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or with the supervisory authority of your country of residence.

Automated Decisions

We do not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Cookies

Cookies are small files downloaded to your computer, which store information such as your session status and preferences. We use:
  • Essential cookies, necessary for the operation of the website, which do not require consent.
  • Analytics cookies and other non-essential cookies, which are only installed with your prior consent, given through our Cookie Banner.
This processing complies with Law no. 41/2004 of 18 August, as currently worded, which transposes Directive 2002/58/EC concerning privacy and electronic communications.

You may accept, refuse or withdraw your consent to non-essential cookies at any time through the cookie settings, and you may also manage cookies in your browser settings.

Third-Party Cookies

Our website uses Google Analytics as a tracking tool. This tool is only activated once the user has given their consent. Please consult the privacy policy of the relevant provider for further information about the processing it carries out.

External Links

Our website may contain links to external sites not operated by us. We have no control over their content and practices and cannot accept responsibility for their privacy policies.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will publish the updated version on our website and revise the ‘Last updated’ date indicated above. In the event of substantial changes affecting processing based on your consent, we will obtain your new consent or notify you directly, where required by law.

Contact Us

The Data Protection Officer may be contacted at the following e-mail address: privacy@nearsoft.pt

Address: Rua do Comboio n.º 3, 2.º Andar, 9050-053 Funchal, Portugal