DATA SUBJECT - Privacy Notice

BACKGROUND: 


NJR Steel understands that your privacy is important to you and that you care about how your personal information is used. We respect and value the privacy of all those that we have dealings with and use personal information in ways that are described here, and in a way that is consistent with our obligations and your rights under the law.



1.  Information About Us


NJR Steel stocks, distributes and adds value to a broad range of steel products available ex-stock, in our branches located in 5 provinces. NJR Steel's core merchanting business is supplemented by a broad range of steel related hardware and paint products on offer in our ‘Cash & Carry’ shops, for that convenient one-stop-shopping experience. We have a network of 22 Operational Businesses which include 16 merchant businesses open to the trade and public 6 days a week. Our manufacturing businesses produce reinforcing steel, welded mesh products, roofing, flat bar, base plates and fencing products. We service our customers in Sub Saharan Africa through our Exports Division. Our Distribution Centre located in Brakpan supports our branch network and manufacturing plants.



2.  What Does This Notice Cover?


This Privacy Notice explains how we use your personal information: how it is collected, how it is held, and how it is processed. It also explains your rights under the law relating to your personal information.



3.  What Is Personal information?


Personal information is defined by the Protection of Personal Information Act (“POPIA”), as ‘any information relating to an identifiable living natural or existing juristic person’.


Personal information is, in simpler terms, any information about you that enables you to be identified. Personal information covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.


We process personal information by both automated (electronically) and non-automated means (paper based as part of a filing system).


The personal information that we use is set out in Part 5, below.



4.  What Are My Rights?


Under POPIA, you have the right to have your personal information processed according to 8 processing conditions that are summarized as follows:


Condition 1 – Accountability. 


We must ensure that the conditions set out in Chapter 3 of the Act and all the associated measures are complied with. 



Condition 2 – Personal information must be collected and processed lawfully in a reasonable manner that does not infringe on your rights.  Personal information may only be processed if it is adequate, relevant, and not excessive. 


Personal information may only be processed if you consent thereto, alternatively where it is necessary to do so for the conclusion or performance of a contract, an obligation in terms of law, to protect your legitimate interest/s, or to pursue our legitimate interest/s. 


Personal information must as far as possible be collected directly from you. 



Condition 3 requires that personal information must be collected for a specific explicitly defined and lawful purpose related to a function or activity of ours. Such personal information may not be retained any longer than necessary for achieving the purposes for which the information was collected and/or subsequently processed. 



Condition 4 prohibits the further processing of your personal information unless such processing is compatible with the initial purpose of collecting the information. 



Condition 5 requires us to take reasonable, practicable steps to ensure that your personal information is complete, accurate, and not misleading.  Such personal information must also be kept up to date, taking into consideration the purpose of the personal information. 


The nature and purpose of your personal information will dictate as to how often such information must be updated. 



Condition 6 requires that we must, as far as it is practicable, inform you before your personal information is collected and the purpose of collecting and from where your personal information will be collected. 


You are entitled to our details and must be made aware of the consequences of not disclosing personal information to us where it is required for a specific purpose. 


You must also be made aware if your personal information is collected and processed as requirement established in law. 


As per Section 72 of the Act, you will be advised if your personal information will be transferred across the borders of South Africa. 



Condition 7 requires that we must secure the integrity and confidentiality of your personal information by taking appropriate reasonable, technical, and organisational measures, to prevent the loss thereof or unlawful access thereto. 



Condition 8 - You have the right to establish whether your personal information is held by us and to have it corrected or destroyed if it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or have been obtained unlawfully. 



Other rights.


Your further have the following rights, which we will always work to uphold:


  1. The right to be informed about our or collection and use of your personal information. This Privacy Notice should tell you everything you need to know, but you can always contact us to find out more or to ask any questions using the details in Part 11.
  2. The right to access the personal information we hold about you. Part 10 will tell you how to do this.
  3. The right to have your personal information rectified if any of your personal information held by us is inaccurate or incomplete. Please contact us using the details in Part 11 to find out more.
  4. The right to be forgotten, in example the right to ask us to delete or otherwise dispose of any of your personal information that we hold. Please contact us using the details in Part 11 to find out more.
  5. The right to restrict (i.e. prevent) the processing of your personal information.
  6. The right to object to us using your personal information for a particular purpose or purposes.
  7. The right to withdraw consent. This means that, if we are relying on your consent as the legal basis for using your personal information, you are free to withdraw that consent at any time.
  8. The right to not have your personal information processed for the purposes of direct marketing by means of electronic communication without your consent.
  9. You have the right to control how your data is used for advertising purposes. Most web browsers allow you to manage your cookie preferences, including blocking or deleting cookies. Additionally, many advertising platforms offer opt-out mechanisms that allow you to limit the collection and use of your data for targeted advertising.
  10. Please note that opting out of targeted advertising may not completely eliminate the display of ads, but it will prevent the use of your data for personalized ad targeting.


For more information about our use of your personal information or exercising your rights as outlined above, please contact us using the details provided in Part 11.


It is important that your personal information is kept accurate and up to date. If any of the personal information we hold about you changes, please keep us informed as long as we have that information.


Further information about your rights can also be obtained from the Information Regulator’s Office at https://www.justice.gov.za/inforeg.


If you have any cause for complaint about our use of your personal information, you have the right to lodge a complaint with the Information Regulator’s Office. We would welcome the opportunity to resolve your concerns ourselves, so please contact us first, using the details in Part 11.



5.  What Personal information Do you collect and how?


We may collect and hold some or all of the personal information set out in the table below, using the methods also set out in the table. We do collect ‘special personal information’ where so required by law’ and / or personal information relating to children, younger than 18 years of age, in so far as it relates to the children of our employees and for the purposes of medical insurance. 


Special personal information may include information relating to race, ethnical origin, health, biometric information and criminal behaviour of a data subject. 


The personal information of children may include the name, surname and date of birth or identity number of the child.

Information Collected How We Collect the Personal Information
Identity Information including but not limited to identity numbers, drivers licences, passport numbers, names, surnames, company / entity names and registration details, vehicle registration numbers, CCTV footage, biometric information such as fingerprint images for access control. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Contact and location information including but not limited to telephone and fax numbers, email addresses, physical addresses, postal addresses, geographical location data. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Business information including but not limited to ownership, shareholding, job titles, professions, email communication of an implicit or explicit private and confidential nature, affiliations, products, services, statutory registration information. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Payment information including but not limited to transaction history, bank statements, invoices, credit notes, credit / debit card details, bank account numbers, credit ratings. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public. Banks and credit rating / consumer data verification agencies.
Profile information including but not limited to preferences, customer profiles, transaction history, etc. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Data from third parties including the verification of information, consumer profiles, etc. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.

Data Collection and usage on NJR Steel’s Website

NJR Steel is committed to safeguarding the privacy and security of our website visitors. This privacy policy section outlines how your data is collected and used when you interact with our website through various advertising platforms, ensuring compliance with relevant laws and regulations.


  • Google Advertising Platforms:


When you visit our website, Google Advertising Platforms, including Google Ads and Google Analytics, may collect certain information about your browsing behavior through cookies and similar technologies. This information may include your IP address, browser type, operating system, pages visited, and interactions with our site.


We utilize Google Advertising Platforms to deliver personalized advertisements tailored to your interests and to analyze the effectiveness of our marketing efforts. As part of this process, we may use data segments to enhance the relevance of our ads.


Description of Data Usage: We use your data to advertise online, including showing ads on various websites across the Internet. This allows us to reach audiences who may be interested in our products or services.


Third-Party Vendors and Cookies: Third-party vendors, including Google, may show our ads on sites across the Internet. These vendors may also use cookies and/or device identifiers to serve ads based on your past visits to our website.


Opt-Out Options: You can opt out of Google's use of cookies or device identifiers for personalized advertising by visiting Google's Ads Settings. Alternatively, you can opt out of third-party vendors' use of cookies by visiting the Network Advertising Initiative opt-out page or control the use of device identifiers by using your device’s settings.


Google Marketing Platform's Pixels: As we are using Google Marketing Platform's pixels for our data segments, you can opt out of Google Marketing Platform's use of cookies by visiting the Google Marketing Platform opt-out page or the Network Advertising Initiative opt-out page.



  • Meta Advertising Platforms:


NJR Steel may use advertising services provided by Meta Advertising Platforms, such as Facebook Ads. These platforms may collect data about your interactions with our website, including your device information, browsing activity, and demographic information.


The data collected by Meta Advertising Platforms is used to deliver targeted advertisements to individuals who have shown interest in our products or services and to measure the performance of our advertising campaigns. NJR Steel adheres to Meta's policies regarding data privacy and security. For further details on how Meta handles your data, please consult Meta's Privacy Policy.


To manage your preferences or remove your data from Meta's advertising platforms, you can visit the Facebook Ad Preferences page or adjust your settings in the Facebook Privacy Settings.



  • LinkedIn Advertising Platforms:


When you engage with NJR Steel's website, LinkedIn Advertising Platforms may collect certain data to provide advertising services and analytics. This may include information such as your LinkedIn profile information, website interactions, and demographic details.


We utilize LinkedIn Advertising Platforms to reach relevant audiences and promote our products or services. Your data collected through these platforms is subject to LinkedIn's Privacy Policy. NJR Steel does not have control over the data collected by LinkedIn Advertising Platforms beyond what is specified in our agreements with them.


To manage your preferences or remove your data from LinkedIn's advertising platforms, you can visit the LinkedIn Advertising Preferences page or adjust your settings in the LinkedIn Privacy Settings.



Your Privacy Choices:


You have the right to control how your data is used for advertising purposes. Most web browsers allow you to manage your cookie preferences, including blocking or deleting cookies. Additionally, many advertising platforms offer opt-out mechanisms that allow you to limit the collection and use of your data for targeted advertising.


Please note that opting out of targeted advertising may not completely eliminate the display of ads, but it will prevent the use of your data for personalized ad targeting.

6.  How Do You Use My Personal information?


Under POPIA, we must always have a lawful basis for using personal information. We may use your personal information for one or all of the following purposes:


  • The administration of our business.
  • Supplying our products and / or services to you.
  • Managing payments for our products and / or services.
  • Personalising and tailoring our products and / or services for you.
  • Communicating with you.
  • Supplying you with information by electronic communication if you have agreed thereto (you may opt-out at any time by using the details in Part 11).
  • With your permission we may also use your personal information for marketing purposes, which may include contacting you by email and / or telephone and / or text message with information, news, and offers on our products and / or services. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with our obligations under POPIA, and you will always have the opportunity to opt-out. 


We will only use your personal information for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal information for that purpose. If we do use your personal information in this way and you wish us to explain how the new purpose is compatible with the original, please contact us using the details in Part 11.


If we need to use your personal information for a purpose that is unrelated to, or incompatible with, the purpose(s) for which it was originally collected, we will inform you and explain the legal basis which allows us to do so or obtain permission from you to do so.


In some circumstances, where permitted or required by law, we may process your personal information without your knowledge or consent. This will only be done within the bounds of POPIA and your legal rights.



7.  How Long Will You Keep My Personal information?


We will not keep your personal information for any longer than is necessary in light of the reason(s) for which it was first collected. Your personal information will therefore be kept for:


  • as long as it serves the purpose it was collected and intended for, 
  • such periods as prescribed in any legislation applicable to our business, 
  • any period agreed to in a contract, 
  • the purposes of fulfilment of a contract, or
  • any period you may have agreed to.



8.  How and Where Do You Store or Transfer My Personal information?


We will endeavour to store your personal information in South Africa. This means that it will be fully protected under POPIA.


We may however transfer your personal information across the borders of South Africa for the purposes of storage, performance of a contract, an obligation in terms of international law or for internal purposes. These are referred to as “third countries”. We will take additional steps in order to ensure that your personal information is treated just as safely and securely as it would be within South Africa and under POPIA as follows:


8.1 We will ensure that your personal information is protected under binding corporate rules. Binding corporate rules are a set of common rules which all our group companies are required to follow when processing personal information. 


OR


8.2  We will only store or transfer personal information in or to countries that are deemed to provide an adequate level of protection for personal information.


OR


8.3 We will use contracts and / or service agreements which ensure the same levels of personal information protection that apply under POPIA.


The security of your personal information is essential to us, and to protect your information, we take a number of important measures, including the following:


  • Limiting access to your personal information to those employees, agents, contractors, and other third parties with a legitimate need to know and, where applicable, ensuring that they are subject to duties of confidentiality.
  • Procedures for dealing with data breaches (the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, your personal information) including notifying you and the Information Regulator’s Office where we are legally required to do so.
  • We have identified all reasonable and foreseeable technical and organizational risks, both internal and external, and introduced safeguards to mitigate such risks. 
  • Continuous maintenance and updating of such safeguards to secure your personal information.



9.  Do You Share My Personal information?


We will not share any of your personal information with any third parties for any purposes, subject to the following exception/s:


  • For the purposes of inter alia fulfilment of an application, contract, rendering of a service or goods.
  • If we sell, transfer, or merge parts of our business or assets, your personal information may be transferred to a third party. Any new owner of our business may continue to use your personal information in the same way(s) that we have used it, as specified in this Privacy Notice.
  • In some limited circumstances, we may be legally required to share certain personal information, which might include yours, if we are involved in legal proceedings or complying with legal obligations, a court order, or the instructions of a government authority.
  • We may share your personal information with other companies in our group. This includes our holding company and its subsidiaries.


If any of your personal information is shared with a third party, as described above, we will take reasonable steps to ensure that your personal information is handled safely, securely, and in accordance with your rights.


Operators:


We may make use of third-party service providers to process personal information on our behalf. To protect such personal information, we will enter into a formal written agreement with the service provider. In terms of such agreement the service provider will be required to process personal information in accordance with conditions as prescribed by us, including measures to protect the security and integrity for such personal information. 



10.  How Can I Access My Personal information?


If you want to know what personal information we have about you, you can ask us for details of that personal information and for a copy of it (where any such personal information is held). This is known as a Subject Access Request (“SAR”).


All SARs should be made in writing and sent to the email or postal addresses shown in Part 11. To make this as easy as possible for you, a Subject Access Request Form is available for you to use (SAR Form 1). You do not have to use this form, but it is the easiest way to tell us everything we need to know to respond to your request as quickly as possible.



There may be a fee charged for a Subject Access Request, especially if your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.


We will respond to your data subject access request within one month. Normally, we aim to provide a complete response, including a copy of your personal information within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.



11.  How Do I Contact You?


NJR Steel is committed to transparency and providing you with control over your privacy choices. To contact us about anything to do with your personal information and the protection of your personal information, including to make a data subject access request, please use the following details (for the attention of The Information Officer):


Email address: popi@njrsteel.co.za

Telephone number: 011 477 5515

Postal Address: P.O.BOX 58337, Newville, 2114



12.  Changes to this Privacy Notice


NJR Steel reserves the right to update or revise this privacy policy section at any time to reflect changes in our data practices or applicable laws. We encourage you to review this policy periodically for the latest information on how we handle your data. Any changes will be made available on our company website.

Share by: