Privacy Policy
Your privacy, as well as the confidentiality, availability, and integrity of your personal data, are a priority for us, which is why we are deeply committed to handling them with respect and security.
1. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA?
The entity responsible for processing your personal data is SHIFTIFY – ESTRATÉGIAS DE SUSTENTABILIDADE LDA, with its headquarters at Avenida Fontes Pereira de Melo – Idea Spaces – 16, Lisbon, NIPC 518231690, hereinafter “Shiftify.”
2. WHAT PERSONAL DATA DO WE PROCESS, FOR HOW LONG, AND FOR WHAT PURPOSES?
We will only process your personal data to the extent strictly necessary to ensure the proper functioning of the Shiftify website, guaranteeing that you can use all of its features, as well as to submit contact requests, in accordance with the General Data Protection Regulation (GDPR), Law No. 58/2019 of August 8, 2019 (the law implementing the GDPR into national law), Directive 2002/58/EC of July 12, 2002 (Directive on the processing of personal data and the protection of privacy in the electronic communications sector), Law No. 41/2004, of August 18 (the law transposing Directive 2002/58/EC into national law), and all other applicable legislation regarding privacy and the protection of personal data.
Your personal data will be deleted or anonymized as soon as the purposes that justified its processing no longer apply, without prejudice to situations in which the law requires it to be retained for longer periods.
Below, we provide you with all the information regarding our processing of your personal data, including the purpose of such processing, the legal basis, the categories of personal data involved, and the retention periods applied:
2.1 CONTACT REQUEST
If you need to contact us, submit a complaint, make a suggestion, offer praise, or request information or a service, you can do so through the channels provided for that purpose.
Therefore, in order to fulfill our legitimate interest in managing and responding to your requests, we will process certain categories of personal data—identifying information, contact information, and professional information—as well as any other information we deem relevant.
2.2 APPLICATIONS AND RECRUITMENT
If you submit an unsolicited application or respond to a job opening using the form provided on the website—including by uploading your resume or other relevant documents—we will process your personal data for the purpose of evaluating your application and, where appropriate, contact you as part of the recruitment and selection process.
To this end, in pursuit of our legitimate interest in identifying and evaluating candidates, we process the following categories of personal data: identifying information, contact information, and professional and academic information, including the information contained in your resume or other documents you voluntarily provide to us.
Your personal data will be retained for as long as necessary to evaluate your application, and if you are not selected, it will be deleted within 12 months of receiving your application, unless you expressly authorize us to include it in a candidate database for future opportunities.
3. TO WHOM MAY WE DISCLOSE YOUR PERSONAL DATA?
Your personal data may be shared with partner companies (subcontractors) whose involvement is essential to ensuring the proper functioning of this website and guaranteeing that you can take full advantage of all its features; it is understood that, whenever these companies process your personal data, on our behalf and at our expense, we guarantee the same level of security and privacy in such processing.
Shiftify may be required to disclose your personal data to the competent authorities in accordance with legal and/or judicial requirements.
Furthermore, in our pursuit of excellence in the provision of our services—particularly those related to cloud services, information security management, or when our partners’ subcontractors need to access personal data under specific circumstances— we may rely on the support of partners located or headquartered outside the European Economic Area (“third countries”), such as in the United States and the United Kingdom.
Because we recognize that in these situations the level of protection for your personal data may differ from that guaranteed by the European Union’s General Data Protection Regulation, prior to any transfer, we commit to taking appropriate measures to ensure a high standard of protection and security for your personal data, in accordance with that Regulation, giving priority to third countries for which the Commission has adopted an adequacy decision.
4. WHAT ARE YOUR RIGHTS REGARDING THE PROTECTION OF PERSONAL DATA, AND HOW CAN YOU EXERCISE THEM?
As a data subject, you may, at any time, exercise your data protection rights—the right of access, the right to rectification, the right to erasure, the right to restriction, the right to data portability, and the right to object—by contacting us at the following email address: geral@shiftify.pt
We will carefully review your requests, assess their validity and relevance, and commit to responding within the legally prescribed timeframe.
If you believe that we have not respected your rights, you may file a complaint with the National Data Protection Commission (CNPD):
Address: Av. D. Carlos I, 134 – 1st Floor, 1200-651 – Lisbon
Phone: +351 213 928 400
Fax: +351 213 976 832
Email: geral@cnpd.pt
5. CONTACT INFORMATION FOR THE DATA PROTECTION OFFICER (DPO)
If necessary, you may contact our DPO at the following email address: geral@shiftify.pt.
6. HOW DO WE PROTECT YOUR PERSONAL DATA?
We implement appropriate technical and organizational measures to protect your personal data, in accordance with industry best practices.
Administrative, technical, and physical measures, as well as technological controls and procedures, are implemented to prevent your personal data from being used, accessed, disclosed, or destroyed in an improper or unauthorized manner.
Among others, we highlight some of the measures that have been implemented:
Secure storage and transfer of your personal data;
Protection of information systems through controls that prevent unauthorized access to your personal data;
Implementation of mechanisms that ensure the integrity and quality of your personal data;
Continuous monitoring of information systems to prevent, detect, and stop the misuse of your personal data;
Redundancy of equipment used for the storage, processing, and transmission of your personal data, to prevent loss of availability;
Periodic analysis to detect vulnerabilities or security flaws in information systems.
This Privacy Policy may be revised and updated at any time, and you will always be provided with the necessary information on this website.