OFFICIAL DOCUMENT  ·  ALL STEEL SERVICES CC  ·  SOUTH AFRICA  ·  POPIA COMPLIANT
Ref: ALLSTEEL/PRIV/001
Version 1.0
Effective 1 July 2025

Privacy Policy

Protection of Personal Information Act (POPIA) & Data Privacy Statement
Governing the collection, use, and protection of personal information.

POPIA
Compliant
2025
Document  ALLSTEEL/PRIV/001
Last Updated  1 July 2025
Version  1.0
Sections  15
Governed by  POPIA Act 4 of 2013

Your Privacy Matters to Us

All Steel Services CC ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or engage with our business.

We comply with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable data protection laws in South Africa. This policy outlines our practices concerning personal information and your rights regarding such information.

01

1. Information We Collect

We may collect the following types of information:

1.1 Personal Information

Personal information is information that identifies you as an individual. We collect personal information as defined in POPIA, including but not limited to:

  • Identity information (name, ID number, company registration details)
  • Contact information (email address, telephone number, physical address)
  • Financial information (payment details, bank account information)
  • Transaction information (products purchased, order history)
  • Employment information (for B2B relationships)
  • Communications and correspondence with us

1.2 Non-Personal Information

We also collect non-personal information that does not directly identify you, including:

  • Browser type and version
  • Device information (operating system, hardware model)
  • IP address
  • Usage data (pages visited, time spent on the website)
  • Referral source
02

2. Collection Methods

We collect information through various methods, including:

  • Direct interactions (when you provide information through our website, email, phone, or in person)
  • Forms and applications (when you complete contact forms, quotation requests, or account applications)
  • Automated technologies (cookies, server logs, and similar technologies)
  • Third parties (such as business partners, credit bureaus, or publicly available sources, where permitted by law)
03

3. Purpose of Collection

In accordance with POPIA, we only collect and process personal information for specific, explicitly defined, and legitimate purposes, including:

  • To provide our products and services to you
  • To process and fulfill orders
  • To communicate with you about your orders, inquiries, or account
  • To provide customer support and respond to your queries
  • To maintain and improve our website and services
  • To send you information about our products, services, and promotions (with your consent)
  • To conduct market research and analysis
  • To comply with legal obligations
  • To detect and prevent fraud and unauthorized access
  • To establish, exercise, or defend legal claims
  • For other purposes with your consent
04

4. Legal Basis for Processing

We process your personal information in accordance with POPIA on the following legal grounds:

Consent

Where you have given us consent to process your information for specific purposes.

Contract

Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.

Legal Obligation

Where processing is necessary for compliance with our legal obligations.

Legitimate Interests

Where processing is necessary for our legitimate interests or those of a third party, provided your fundamental rights and freedoms do not override those interests.

Public Interest

Where processing is necessary for the performance of a task carried out in the public interest.

Protection of Interests

Where processing is necessary to protect your vital interests or those of another person.

05

5. Information Sharing and Disclosure

We may share your personal information with the following categories of recipients:

5.1 Service Providers

We may disclose your information to third-party service providers who perform services on our behalf, such as:

  • Payment processors
  • Delivery and logistics providers
  • IT and system administration providers
  • Marketing and communication service providers
  • Professional advisers (lawyers, bankers, auditors, insurers)

These service providers are contractually bound to protect your information and only use it for the specific purposes for which we disclose it to them.

5.2 Business Partners

We may share your information with our business partners, such as steel suppliers or manufacturers, when necessary to fulfill your orders or provide our services.

5.3 Legal Requirements

We may disclose your information when required by law, subpoena, court order, or other legal process, or to establish, protect, or exercise our legal rights or defend against legal claims.

5.4 Business Transfers

If we are involved in a merger, acquisition, financing, or sale of business assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

5.5 With Your Consent

We may share your information with any other third parties where you have provided your explicit consent for such disclosure.

06

6. Cross-Border Data Transfers

International Data Transfers
In accordance with Section 72 of POPIA, we may transfer your personal information to recipients outside South Africa. When we do so, we will ensure that appropriate safeguards are in place.
  • The recipient is subject to laws, binding corporate rules, or binding agreements that provide an adequate level of protection similar to POPIA;
  • You consent to the transfer;
  • The transfer is necessary for the performance of a contract between you and us;
  • The transfer is necessary for the conclusion or performance of a contract concluded in your interest; or
  • The transfer is for your benefit and it is not reasonably practicable to obtain your consent, but if it were, you would likely provide such consent.
07

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, accidental loss, alteration, disclosure, or destruction, as required by Section 19 of POPIA. These measures include:

  • Access controls and authentication procedures
  • Encryption of sensitive data
  • Secure network infrastructure
  • Regular security assessments and testing
  • Staff training on data protection and security
  • Physical security measures at our premises
Security Disclaimer
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee the absolute security of your information.
08

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider:

  • The amount, nature, and sensitivity of the personal information
  • The potential risk of harm from unauthorized use or disclosure
  • The purposes for which we process the information and whether we can achieve those purposes through other means
  • Applicable legal requirements

In some circumstances, we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

09

9. Cookies and Similar Technologies

Our website uses cookies and similar technologies to enhance your browsing experience, analyze website traffic, and personalize content. Cookies are small text files that are stored on your device when you visit our website.

9.1 Types of Cookies We Use

Essential Cookies

Necessary for the website to function properly.

Analytical / Performance

Allow us to recognise and count visitors and see how they navigate our website.

Functionality Cookies

Used to recognise you when you return to our website.

Targeting Cookies

Record your visit to our website, the pages you visit, and the links you follow.

9.2 Managing Cookies

You can control and manage cookies in various ways. Most web browsers allow you to block or delete cookies. Please note that if you choose to block all cookies, you may not be able to access all or parts of our website or some features may not function properly.

10

10. Your Rights Under POPIA

As a data subject under POPIA, you have the following rights regarding your personal information:

Right to AccessYou have the right to request confirmation of whether we hold personal information about you and to access that information.
Right to CorrectionYou have the right to request the correction of inaccurate personal information.
Right to DeletionYou have the right, in certain circumstances, to request the deletion or destruction of your personal information.
Right to ObjectYou have the right to object to the processing of your personal information for direct marketing purposes or on grounds relating to your particular situation.
Right to Refuse Direct MarketingYou have the right to refuse the processing of your personal information for direct marketing purposes.
Right to Submit a ComplaintYou have the right to submit a complaint to the Information Regulator regarding alleged interference with your protection of personal information.
Exercise Your Rights
To exercise any of these rights, please contact our Information Officer using the contact details provided in Section 14 of this Privacy Policy.
11

11. Children's Privacy

Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.

12

12. Third-Party Links

Our website may contain links to third-party websites, plugins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.

13

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time in response to changing legal, technical, or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material changes if and where required by applicable data protection laws.

You can see when this Privacy Policy was last updated by checking the date at the top of this page. You are advised to review this Privacy Policy periodically for any changes.

14

14. Contact Information

Information Officer

In accordance with POPIA, we have appointed an Information Officer who is responsible for ensuring our compliance with POPIA and addressing any requests or queries regarding your personal information:

Information Officer
All Steel Services CC
110a North Reef Rd
Meadowbrook Park
Germiston 1401
South Africa

Email: [email protected]
Phone: +27 11 974 8883

Information Regulator

If you believe that we have not adequately addressed your concerns or complaints, you have the right to lodge a complaint with the Information Regulator of South Africa:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001

Email: [email protected]
Website: www.justice.gov.za/inforeg/
15

15. POPIA Compliance Statement

All Steel Services CC is committed to complying with the Protection of Personal Information Act 4 of 2013 (POPIA). We have implemented the following measures to ensure compliance:

Governance

  • Appointed an Information Officer
  • Developed POPIA compliance framework
  • Regular compliance reviews

Risk Assessment

  • Personal information impact assessment
  • Risk monitoring and management
  • Vulnerability assessments

Security Safeguards

  • Appropriate security safeguards
  • Access controls and monitoring
  • Data breach response procedures

Staff Training

  • POPIA training for all staff
  • Data handling procedures
  • Privacy awareness programs

Privacy questions?

Contact our Information Officer directly, we respond within 48 hours.

Email Us

Prefer to speak to someone?

One call, one team, one less thing to worry about.

Call (011) 974-8883