Lean Solutions Group Acquires SupportZebra.

Learn More
LEAN GROUP
Hero Image

Legal Center

LEAN SOLUTIONS GROUP CORPORATE POLICY ON THE PROCESSING OF PERSONAL DATA

Objective

LEAN SOLUTIONS GROUP, a business group mainly composed of: LEAN STAFFING SOLUTIONS INC, PERFILES Y SOLUCIONES LOGÍSTICAS S.A.S, PERFILES Y SOLUCIONES TECNOLÓGICAS S.A.S, LEAN SOLUTIONS MÉXICO, S. DE R.L. DE C.V, PERFILES Y SOLUCIONES LOGÍSTICAS GUATEMALA S.A., LEAN OUTSOURCING SOLUTIONS GROUP PHIL. INC, LEAN STAFFING SOLUTIONS ECUADOR S.A.S. and the rest of its subsidiaries recognizes the protection of personal data as a fundamental right and a corporate priority.

This Policy establishes general guidelines for the processing of personal data collected, stored, used, transmitted, transferred, or deleted by the company during its commercial and operational activities, ensuring compliance with applicable regulations in the United States, Colombia, Guatemala, the Philippines, Mexico, and Ecuador.

The purpose of this policy is:

  • To guarantee respect for the privacy, confidentiality, and security of personal data.
  • To align information processing practices with international data protection standards and the principles of good corporate governance.

Promote an organizational culture based on responsibility, transparency, and trust.

1. Scope

This Policy applies to all business units, subsidiaries, offices, and employees of LEAN SOLUTIONS GROUP and its subsidiaries, as well as to:

  • Customers, suppliers, contractors, employees, applicants, strategic partners, and third parties whose personal data is processed by the company.
  • Data processors, i.e., third parties who process personal data on behalf of the company, regardless of the country in which they are located.

It includes all means of processing: physical, digital, electronic, or automated. 

  1. Reference Documents and Definitions 
  1. Reference Documents 
  • Colombia: Law 1581 of 2012, Decree 1377 of 2013, Decree 1074 of 2015, Decree 255 of 2022, Law 1266 of 2008, Single Circular of the SIC. Superintendencia de Industria y Comercio (SIC) 
  • Guatemala: Articles 24, 31, and 44 of the Political Constitution of the Republic of Guatemala, Decree 57-2008, (Law on Access to Public Information) and complementary regulations on confidentiality. Procuraduría de Derechos Humanos (PDH) 
  • Philippines: Data Privacy Act of 2012 (R.A. 10173) and its Implementing Rules and Regulations. National Privacy Commission (NPC) 
  • United States: Sectoral legislation such as CCPA/CPRA (California), HIPAA (health), GLBA (finance), COPPA (minors), Florida Digital Bill of Rights (FDBR) Federal Trade Commission (FTC) and state authorities. 
  • Mexico: New Federal Law on Protection of Personal Data Held by Private Parties, published on March 21, 2025. Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) 
  • Ecuador: Organic Law on Personal Data Protection.  Superintendencia De Protección De Datos Personales. (SPDP). 

In the event of a conflict between this Policy and local laws, the provision that provides greater protection to the data subject shall prevail. 

  1. Reference Documents and Definitions 
  1. Reference Documents 
  • Colombia: Law 1581 of 2012, Decree 1377 of 2013, Decree 1074 of 2015, Decree 255 of 2022, Law 1266 of 2008, Single Circular of the SIC. Superintendencia de Industria y Comercio (SIC) 
  • Guatemala: Articles 24, 31, and 44 of the Political Constitution of the Republic of Guatemala, Decree 57-2008, (Law on Access to Public Information) and complementary regulations on confidentiality. Procuraduría de Derechos Humanos (PDH) 
  • Philippines: Data Privacy Act of 2012 (R.A. 10173) and its Implementing Rules and Regulations. National Privacy Commission (NPC) 
  • United States: Sectoral legislation such as CCPA/CPRA (California), HIPAA (health), GLBA (finance), COPPA (minors), Florida Digital Bill of Rights (FDBR) Federal Trade Commission (FTC) and state authorities. 
  • Mexico: New Federal Law on Protection of Personal Data Held by Private Parties, published on March 21, 2025. Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) 
  • Ecuador: Organic Law on Personal Data Protection.  Superintendencia De Protección De Datos Personales. (SPDP). 

In the event of a conflict between this Policy and local laws, the provision that provides greater protection to the data subject shall prevail. 

2. Reference Documents and Definitions

2.1 Reference Documents

  • Colombia: Law 1581 of 2012, Decree 1377 of 2013, Decree 1074 of 2015, Decree 255 of 2022, Law 1266 of 2008, Single Circular of the SIC. Superintendencia de Industria y Comercio (SIC)
  • Guatemala: Articles 24, 31, and 44 of the Political Constitution of the Republic of Guatemala, Decree 57-2008, (Law on Access to Public Information) and complementary regulations on confidentiality. Procuraduría de Derechos Humanos (PDH)
  • Philippines: Data Privacy Act of 2012 (R.A. 10173) and its Implementing Rules and Regulations. National Privacy Commission (NPC)
  • United States: Sectoral legislation such as CCPA/CPRA (California), HIPAA (health), GLBA (finance), COPPA (minors), Florida Digital Bill of Rights (FDBR) Federal Trade Commission (FTC) and state authorities.
  • Mexico: New Federal Law on Protection of Personal Data Held by Private Parties, published on March 21, 2025. Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI)
  • Ecuador: Organic Law on Personal Data Protection. Superintendencia De Protección De Datos Personales. (SPDP).

In the event of a conflict between this Policy and local laws, the provision that provides greater protection to the data subject shall prevail.

3. Guiding Principles of Processing

The processing of personal data shall be governed by the following universal principles:

  • 1. Legality: processing will always be carried out in accordance with the law.
  • 2. Purpose: data is collected for legitimate purposes, which are communicated to the data subject.
  • 3. Freedom: processing will only be carried out with prior, express, and informed consent.
  • 4. Accuracy or quality: the information shall be accurate, complete, up-to-date, and verifiable.
  • 5. Transparency: the data subject may always know how their data is being used.
  • 6. Restricted access and circulation: data will not be disclosed without authorization or outside the established purposes.
  • 7. Security: technical, human, and administrative measures will be adopted to prevent unauthorized access or loss of information.
  • 8. Confidentiality: all people involved in the processing are subject to confidentiality obligations.
  • 9. Accountability: the company must demonstrate compliance with its obligations to authorities and data subjects.

Categories of Data Processed

The company may collect and process the following categories of information:

  • Identification data: names, documents, nationality, age, gender, signature, photograph.
  • Contact details: address, email, telephone number, corporate networks.
  • Financial or credit data: bank accounts, income, tax information.
  • Employment data: employment history, evaluations, payroll information.
  • Sensitive data: biometric, emotional, psychological, or physical health information, or information about beliefs, when strictly necessary and authorized for the ordinary course of its operations and human resources processing.
  • Online and website data (cookies): information collected through cookies and similar tracking technologies when a Data Subject visits LSG’s website(s). The collection, categories, purposes, and management of this data are governed by LSG’s Cookie Policy, available in our Legal Center.
  • In the case of sensitive data, LEAN SOLUTIONS GROUP will inform the Data Subject that, due to the nature of this type of data, they are not obliged to authorize its processing. In cases where collection is necessary for the employment relationship or legal compliance, enhanced security measures will be guaranteed.
  • In the case of video surveillance, the images captured are considered sensitive data and their processing will be limited exclusively to security purposes.

5. Purposes of Processing

LEAN SOLUTIONS GROUP and its affiliated companies may carry out the processing activities necessary for the proper conduct of their operations, in accordance with applicable law and the Global Corporate Policy. Such activities include, among others, collection, access, consultation, use, analysis, circulation, transmission, transfer, storage, systematization, purification, updating, blocking, conservation, and eventual deletion of personal data, in accordance with the purposes informed to each owner and the principles of legality, purpose, freedom, truthfulness, transparency, restricted access and circulation, security, and confidentiality.

The processing may be carried out through physical, electronic, automated, or hybrid means, including internal tools, technological platforms of the corporate ecosystem, cloud services, telemetry solutions, physical and logical security systems, and automation or artificial intelligence mechanisms implemented by the group, always under schemes of proportionality, minimization, and appropriate safeguards.

Purposes for Employees

a) Labor administration and legal compliance

  • Hiring, administration, and termination of the employment contract.
  • Payroll, benefits, mandatory social security.
  • Management of labor development, disabilities, licenses, certificates, and health care.
  • Creation, updating, and maintenance of employment history.
  • Compliance with legal labor, tax, administrative, and social security obligations.

b) Security, access control, and video surveillance.

  • Control of entry, stay, and exit at physical locations.
  • Video surveillance for physical security purposes, with images stored for 90 days (except for preservation).
  • Verification of identity using biometrics where applicable.
  • Investigation of security incidents. (Based on physical notices and operational purposes).

c) Corporate benefits management

  • Administration of employee benefits and wellness programs, including:
    • Insurance/group policies.
    • Emotional wellness programs.
    • Extended benefits for family members (if applicable).
    • Processes involving insurers, brokers, or other third parties.

d) Internal communications and organizational culture incidents.

  • Sending internal corporate communications (changes, events, programs, initiatives).
  • Management of wellness activities, work environment, and internal culture.
  • Issuance of internal content.

e) Internal and external use of images.

  • Capture and use photographs, videos, and audiovisual material for internal and external corporate communications, institutional marketing, networks, and campaigns.

f) Disciplinary processes and compliance.

  • Conducting disciplinary proceedings, internal audits, and regulatory compliance.
  • Prevention and handling of cases of workplace harassment or other psychosocial risks.

g) Technology management, telemetry, and IT security.

  • Administration of access to corporate systems, platforms, and tools.
  • Collection of logs, telemetry, usage times, device identifiers, and IP addresses.
  • Cybersecurity, operational continuity, and incident prevention.
  • Performance evaluation/operational metrics where applicable

h) AI/automation.

  • Use of automation and artificial intelligence tools to:
    • Optimize internal processes.
    • Improve operational efficiency.
    • Managing Employee Interactions
    • Conduct automated surveys or wellness checks.
    • Analyze operational patterns.

Always under the principles of transparency, proportionality, and security 

i) General administrative management

  • Archiving, auditing, internal reports, management reports, and associated statistics.
  • Response to judicial and administrative authorities.
  • Adopt measures for the prevention, detection, and management of information security incidents, including internal audits, access controls, technical monitoring, and incident response.
  • Developing wellness programs, organizational climate, training activities, psychological support, or other support programs offered by the Company or third-party partners.
  • Respond to requests from judicial or administrative authorities and manage administrative, disciplinary, or legal processes related to the employment relationship.
  • Allow data processing by external providers that support operational, administrative, technological, occupational health, safety, wellness, and payroll processes, in accordance with the purposes described herein.

Retain information for evidentiary purposes, internal or external audits, compliance with legally required document retention periods, and the defense of the Company in potential judicial or administrative proceedings. 

j) Capture and processing of biometric voice and image data for employment purposes

With the express, voluntary, and separate authorization of the employee, LEAN SOLUTIONS GROUP may:

  • Capture, store, and process the employee’s voiceprint for identity verification purposes in telephone calls related to the Company’s employment, operational, administrative, or security matters.
  • Record and store the employee’s voice during telephone or virtual communications for verification, quality control, training, process auditing, and job performance purposes.
  • Capture and store facial images and facial recognition biometric data for identity verification on corporate platforms, attendance monitoring, and compliance with security protocols.
  • Use voice and image biometric data in artificial intelligence or automation systems to optimize identity verification and improve operational efficiency.

LEAN SOLUTIONS GROUP may collect, store, and process voice biometric data (vocal fingerprint, voice recordings, voice recognition patterns) and image biometric data (photographs, facial captures, facial biometric identifiers) from its employees for purposes strictly related to the performance of their job duties and identity verification in corporate communications. The processing of this data will only be carried out with the prior, express, informed, and separate authorization of the data subject, who may refuse to grant it without affecting their employment or working conditions. The company guarantees that this data will be processed under strict reinforced security measures and will not be used for purposes other than those expressly authorized.

PURPOSES FOR APPLICANTS/CANDIDATES

  • To evaluate resumes, verify work experience, and academic background.
  • Schedule and manage interviews, psychometric tests, and exams (when applicable).
  • Validate employment references and background information that is strictly necessary.
  • Maintain talent databases for future processes (if the owner allows it).
  • Communicate the status of the process.
  • Technological management of the portal (audio, usage records, activity duration).

PURPOSES FOR INDIVIDUAL USERS OF THE WEB PORTAL

  • Create user accounts.
  • Enable the use of portal features (upload CV, apply for vacancies, browse).
  • Perform online psychometric tests.
  • Record audio, activity, usage times, and operational traceability.
  • Generate usage statistics and measurements for the purpose of improving the site.
  • Contact the user for job or business opportunities.

PURPOSES FOR BUSINESS USERS

  • Create and manage business accounts within the portal.
  • Identify the contact person for the client company.
  • Enable service management, commercial and operational communication.
  • Verify identity, contractual relationship, and contact details.

PURPOSES FOR SUPPLIERS, CONTRACTORS, AND LESSORS

  • Evaluate, execute, and enforce service agreements/purchase orders.
  • Verify legal, commercial, and corporate requirements (including due diligence).
  • Compliance with tax, accounting, and regulatory obligations.
  • Administrative, financial, and payment management.
  • Operational, commercial, and contractual communication.

PURPOSES FOR CUSTOMERS AND PARTNERS  

  • Commercial, contractual, and operational management of services provided.  
  • Billing, payments, reconciliation, and audits.  
  • Compliance with ethics, transparency, and AML/CFT programs.  
  • Communication of news, surveys, satisfaction and promotions (with consent).  
  • Handling of requests, PQRSF, complaints, or requirements.  

 

PURPOSES FOR VISITORS AND THIRD PARTIES  

  • Control of entry and stay in facilities.  
  • Identity verification.  
  • Video surveillance and physical security. 
  • Recording attendance at meetings and events.  
  • Handling of requests or requirements.  

 

PURPOSES FOR SHAREHOLDERS  

  • Calling ordinary and extraordinary meetings.  
  • Comply with corporate, tax, accounting, and regulatory reporting obligations before competent authorities in accordance with applicable law..  
  • Comply with corporate duties and legal obligations.  
  • Corporate due diligence. 

6. Right of Data Subjects

Data subjects have the right to:

  • 1. Know, update, and rectify their data.
  • 2. Request proof of the authorization granted.
  • 3. Be informed about the use that has been made of their data.
  • 4. File complaints with the competent authority.
  • 5. Revoke authorization or request the deletion of data when there is no legal or contractual obligation preventing it.

7. Shared Use of Your Personal Information

Your data may be shared with other divisions or subsidiaries of LEAN SOLUTIONS GROUP, always ensuring maximum protection of the same. Likewise, such information may be shared and processed in relation to the following categories of recipients:

Third parties: Potentially important third parties include:

    • 1. Service providers: who assist us with IT, cybersecurity, and data hosting providers, marketing, advertising, and communications agencies, cookie analytics providers, online advertisers, and website testing/analysis service providers.
    • 2. Consultants and advisors who assist us with legal, regulatory, and business activities, such as legal advisors, compliance consultants, and business auditors.
    • 3. Business partners in the event of a merger or sale, for example, if LEAN SOLUTIONS GROUP merges with another organization, or in the event of a transfer of our assets or operations.

With digital human transformation tools: As part of the development and operation of various applications, the organization and its business lines use and develop technology platforms designed to ensure the protection of users’ personal information. These platforms allow for the collection, storage, use, circulation, and deletion of data in a secure manner and in accordance with current regulations. All information processing carried out through these tools complies with the principles of legality, purpose, freedom, accuracy, transparency, restricted access and circulation, security, and confidentiality. These tools use different platforms exclusively for the purposes defined in this policy, in compliance with legal and contractual obligations, and under technical and organizational measures that ensure the ethical, responsible, and secure processing of personal data, for which the data subject will be informed of such processing.

– Sensitive Data and Emotional Well-being: The processing of sensitive data, including biometric information and data related to mood, emotional health, or well-being (collected through tools such as Pulse), will be carried out under strict security measures and with the prior consent of the data subject. This data will be processed exclusively for the purpose of improving the organizational climate, occupational health programs, and supporting the overall well-being of employees. LEAN SOLUTIONS GROUP guarantees that no discriminatory decisions will be made based exclusively on the automated processing of this sensitive data.

8. Procedures For Exercising Rights

LEAN SOLUTIONS GROUP guarantees the owners of personal data the full exercise of their rights to know, update, rectify, delete, revoke authorization, and access information.

8.1 Contact channels.

Data subjects may exercise their rights through the following channels:

Country  Contact 
In Colombia   

  • Company name: PERFILES Y SOLUCIONES TECNOLÓGICAS S.A.S. / PERFILES Y SOLUCIONES LOGÍSTICAS S.A.S. 
In Guatemala 
  • Company name: PERFILES Y SOLUCIONES LOGISTICAS GUATEMALA S.A. 
In the Philippines 
  • Company name: LEAN OUTSOURCING SOLUTIONS GROUP PHIL. INC, 
 

 

In the United States 

  • Company name: Lean Staffing Solutions Inc. 
In México 
  • Company name: Lean Solutions México, S. de R.L. de C.V. 
In Ecuador 
  • Company name: Lean Staffing Solutions Ecuador S.A.S. 

For all other countries, the data subject must contact the legal entity of LEAN SOLUTIONS GROUP where such data is being processed, without prejudice against being able to communicate with any of the entities provided herein.

  • 8.2 Types of Requests
    • 8.2.1 Inquiries:

When the data subject wishes to know the personal information stored in the databases. Response time: 10 business days from receipt.

    • 8.2.2 Complaints:

When the owner requests correction, updating, or deletion of information, or submits complaints. Response time: 15 business days from receipt. If the request does not contain sufficient information or require verification, the area responsible will ask the owner to correct it within the following 5 days, suspending the terms until additional information is provided.

8.3 Responsible for customer service

Without prejudice against the contact channels established in section 9.1, LEAN SOLUTIONS GROUP guarantees that requests will be handled by its designated representatives in each jurisdiction. The Data Protection Officer (DPO) for Colombia, or the compliance officer in each country of operation, will coordinate the handling of requests and ensure compliance with the legal terms established for inquiries and complaints. To exercise their rights, the data subject may contact the corresponding legal entity in their country of location:

  • México: Lean Solutions México, S. de R.L. de C.V.
  • Guatemala: Perfiles y Soluciones Logísticas Guatemala S.A.
  • Ecuador: Lean Staffing Solutions Ecuador S.A.S.
  • United States: Lean Staffing Solutions Inc.
  • Philippines: Lean Outsourcing Solutions Group Phil. Inc

In all cases, the data subject may choose to communicate through the global centralized channel (tratamientodedatos@leangroup.com), which will act as a liaison with the local data controller to ensure a timely response in accordance with the applicable law in their territory.

8.4 Escalation to authorities

If the data subject does not receive a response within the legal deadlines or considers it unsatisfactory, they may contact the competent authority:

  • In Colombia: to the Superintendencia de Industria y Comercio (SIC).
  • In Guatemala: to the Procuraduría de Derechos Humanos (PDH).
  • In Filipinas: to the National Privacy Commission (NPC).
  • In Mexico: to the Instituto Nacional de Acceso a la Información (INAI)
  • In Ecuador: to the SuperIntendencia De Protección De Datos Personales. (SPDP)
  • In EE. UU.: to the relevant state or sectoral authority.

9. International Data Transfer and Transmission

Depending on the entity responsible for LEAN SOLUTIONS GROUP and the recipients, your personal information may be processed and hosted in countries other than the one in which the information was originally collected, including those that may have less stringent data protection laws than the country in which you initially provided the information or in which it was originally collected, and those that do not provide adequate levels of security (provided that the owner authorizes it).

LEAN SOLUTIONS GROUP operates primarily in the United States, Mexico, Ecuador, Guatemala, the Philippines, and Colombia. In the case of international data transfers, we will protect your personal information as required by all applicable data protection laws.

9.1 Definitions

  • International transfer: the sending of personal data by LEAN SOLUTIONS GROUP, as the data controller, to another data controller outside the country.
  • International transmission: communication of data to a processor located in another country, who processes the data on behalf of the company.

9.2 General principles

All transfers or transmissions shall be governed by:

  • Compliance with applicable data protection laws.
  • Legitimate and proportionate purpose.
  • Demonstrated responsibility.

9.3 International Circulation for Employment Purposes: In the context of providing global services, LEAN SOLUTIONS GROUP may transfer or transmit personal data to customers, parent companies, or suppliers located in the United States and other countries of operation. The specific purpose of this transfer is to manage the employment relationship, allocate resources to international customer projects, evaluate performance, and audit services provided. The company will ensure that these third parties act as data processors under security standards equivalent to those described herein.

10. Security Measures

LEAN SOLUTIONS GROUP has implemented technical, administrative, and physical measures aimed at ensuring the integrity, availability, and confidentiality of the personal information processed during its operations.

10.1 Security Principles

The company applies the principle of reasonable security, ensuring that the level of protection is proportional to the sensitivity and risk associated with each type of data.

The measures adopted are based on the best international practices in information security and data protection, including ISO/IEC 27001 and ISO/IEC 27701 standards.

10.2 Technical measures

  • Role-based access control (RBAC) and secure passwords.
  • Encryption of information in transit and at rest.
  • Automatic backups in protected environments.
  • Network segmentation and continuous traffic monitoring.
  • Multi-factor authentication (MFA) protocols.
  • Permanent system updates and security patches.
  • Corporate antivirus and antimalware protection.
  • Vulnerability management procedures and periodic penetration testing.

10.3 Administrative Measures

  • Internal policies on acceptable use of technological resources.
  • Confidentiality agreements signed by employees and contractors.
  • Regular training in information security and data protection.
  • Annual security and privacy risk assessment.
  • Review and audit of suppliers with access to personal data.
  • Change control and segregation of duties protocols.
  • In compliance with the principle of Demonstrated Responsibility, LEAN SOLUTIONS GROUP undertakes to report to the competent administrative authorities in each country any security incident that affects confidentiality, integrity, or availability of personal or sensitive data. Such reporting will be carried out in accordance with local legal protocols once the risk event has been detected and classified.
  • Centralized Authorization Repository: LEAN SOLUTIONS GROUP will maintain a centralized and digitized record of authorization forms regarding data processing.

10.4 Physical Measures

  • Control of access to facilities by means of cards, biometrics, or manual records.
  • Video surveillance in critical areas.
  • Physical storage of documents in locked files and restricted areas.
  • Secure document disposal (shredding, secure erasure, or certified destruction).

10.5 Specific measures for voice and image biometric data:

  • Encrypted storage of voiceprints and facial biometric patterns on servers with restricted access.
  • Segregation of biometric databases from other corporate databases.
  • Enhanced access control (multi-factor authentication) for personnel authorized to consult biometric data.
  • Automated deletion of voice recordings that are not necessary for evidentiary or training purposes, in accordance with established retention periods.
  • Express prohibition on the use of biometric data for purposes other than those authorized.

10.6 Incident and security breach management

LEAN SOLUTIONS GROUP has an Information Security Incident Response Procedure, which includes:

  • Detection and classification of the incident.
  • Immediate containment and mitigation of impact.
  • Internal communication to the DPO or Compliance department.
  • Impact assessment on data subjects and systems.
  • Notification to competent authorities and data subjects, when required by law.
  • Recording and subsequent analysis to prevent recurrence.

11. Data Controller and Data Processors

Designated representatives in each country, responsible for regulatory compliance and interactions with local authorities. They shall:

  • Implement, maintain, and supervise compliance with the data protection policy.
  • Respond to inquiries and complaints from data subjects.
  • Coordinate internal or external audits and reviews.
  • Advice on new projects involving the processing of personal data (impact assessments).
  • Manage security incidents and coordinate notifications to authorities.
  • Report periodically to senior management.

12. Data Retention and Deletion

Personal data will be retained:

  • For the time required by accounting, tax, labor, or contractual regulations.
  • As long as necessary to fulfill the purpose for which it was collected.

Once the term has expired, the data will be securely deleted or anonymized, in accordance with the company’s information retention policies.

Registration and Notification to Authorities: LEAN SOLUTIONS GROUP undertakes to register, enroll, and/or update its databases with the control authorities and national registries of each country where it operates, whenever required by local regulations. This compliance ensures the transparency and traceability of the processing of personal information.

13. Video Surveillance

For security purposes and to comply with its obligations, LEAN SOLUTIONS GROUP uses various means of video surveillance installed at different internal and external locations on our premises or in our offices. At the entrance to our premises, the corresponding privacy notices will be posted, stating the purpose of the processing of the data collected by these means and warning of the sensitive nature of such information, as well as the voluntary nature of providing it.

14. Annex By Country

This Corporate Personal Data Processing Policy establishes the general principles and guidelines applicable to the processing of personal data across all operations of LEAN SOLUTIONS GROUP. However, considering that the company operates in multiple jurisdictions, this Policy may be supplemented by specific annexes for each country.

The jurisdiction-specific annexes will further develop and regulate those aspects of personal data processing that must be adapted to the applicable legislation in each country where LEAN SOLUTIONS GROUP operates, including, among others, local regulatory requirements, data subject rights, obligations before supervisory authorities, compliance mechanisms, and specific procedures required by the applicable legal framework.

Such annexes shall form an integral part of this Corporate Policy. In the event of any discrepancy or conflict between the general provisions contained in this Policy and the provisions established in the jurisdiction-specific annexes, the provisions contained in the respective annexes shall prevail to the extent that they reflect legal or regulatory obligations applicable in the relevant jurisdiction.

LEAN SOLUTIONS GROUP may create, modify, update, or supplement these annexes whenever necessary to comply with regulatory changes, guidance issued by competent authorities, or the expansion of operations into new jurisdictions, without requiring a full amendment of this Policy.

15. Update and Validity

This Corporate Policy on the Processing of Personal Data is effective as of its publication and will remain in force indefinitely. LEAN SOLUTIONS GROUP reserves the right to modify or update this document at any time to adapt it to new legislation, case law, internal policies, or new technological services (such as the use of AI agents).

Any substantial change affecting the purposes of the processing or the identity of the controller will be communicated in a timely manner to the data subjects via the official website, emails, or public notices, before it comes into effect.

The validity of the databases will be subject to the purpose of the processing and the legal terms of information retention.

15.1 Change Control Table. 

Change Control 

Version  Date  Change Description  Responsible 
001  June 09, 2020  Document creation  Continuous improvement 
002  May 12, 2023  Modification to terms and conditions  Legal 
01  April 9, 2026  Review and update of the Policy, including the assignment of a new coding structure in accordance with the Company’s updated branding  Legal