Privacy and Cookie Policy

03 December 2025

  1. Introduction
    1.1 About our privacy policy
  2. Data processing and parties involved
    2.1 Webshop software
    2.2 Web hosting and e-mail
    2.3 Payment service providers
    2.4 Reviews
    2.5 Shipping and logistics
  3. Purpose and legal basis of data processing
    3.1 General purpose of the processing
    3.2 Automatically collected data
    3.3 Cooperation with tax and criminal investigations
    3.4 Retention periods
  4. Your rights as a data subject
    4.1 Right of access
    4.2 Right to rectification
    4.3 Right to restriction of processing
    4.4 Right to data portability
    4.5 Right to object and other rights
  5. Cookies
    5.1 Google Analytics
    5.2 Third-party cookies
  6. Changes to this privacy policy
  7. Contact details of My Steel BV

1. Introduction

1.1 About our privacy policy

My Steel BV attaches great importance to protecting your privacy. We therefore only process data that we need in order to provide (and improve) our services, and we handle the information we have collected about you and your use of our services with care. We will never make your data available to third parties for commercial purposes.

This privacy policy applies to the use of the website and the services made available on it by My Steel BV. The effective date of these provisions is 11/02/2020; when a new version is published, all previous versions cease to be valid.

This privacy policy describes which data about you we collect, for what purposes this data is used, and with whom, and under what conditions, this data may be shared with third parties. We also explain how we store your data, how we protect it against misuse, and which rights you have in relation to the personal data you have provided to us. If you have any questions about our privacy policy, you can contact our privacy contact person; their contact details can be found at the end of this privacy policy.

2. Data processing and parties involved

Below you can read how we process your data, where we (arrange to) store it, which security techniques we use, and who has access to the data.

2.1 Webshop software
Magento
Our webshop has been developed using Magento software. The personal data that you provide to us for the purpose of our services is shared with this party. Magento has access to your data in order to provide us with (technical) support, but will never use your data for any other purpose. On the basis of the agreement we have concluded with Magento, this party is obliged to take appropriate security measures. Magento uses cookies to collect technical information about your use of the software; no personal data is collected and/or stored for this purpose.

2.2 Web hosting and e-mail
Office365
For our regular business e-mail traffic we use the services of Office365. This party has taken appropriate technical and organisational measures to prevent, as far as possible, misuse, loss and corruption of your data and ours. Office365 has no access to our mailbox and we treat all our e-mail correspondence as confidential.

Microsoft Clarity
We work with Microsoft Clarity to record how you use our website and how you interact with it. This is done using behavioural data, heatmaps and session replays, which help us to improve our products and services. Data on website usage is collected using first-party and third-party cookies and other tracking technologies. We also use this information for website optimisation and for fraud-prevention and security purposes. For more information on how Microsoft collects and uses your data, please refer to Microsoft’s privacy statement.

2.3 Payment service providers
Mollie
For handling (part of) the payments in our webshop we use the platform provided by Mollie. Mollie processes your name, address and town/city, as well as your payment details such as your bank account number or credit card number. Mollie has taken appropriate technical and organisational measures to protect your personal data. Mollie reserves the right to use your data in order to further improve its services and, in that context, to share (anonymised) data with third parties. All of the safeguards mentioned above regarding the protection of your personal data also apply to those parts of Mollie’s services for which it engages third parties. Mollie does not retain your data for longer than is permitted under the applicable statutory retention periods.

2.4 Reviews
Trusted Shops
We collect reviews via the Trusted Shops platform. When you leave a review via Trusted Shops, you will be asked to provide, among other things, your name and e-mail address. Trusted Shops shares this data with us so that we can link the review to your order and verify its authenticity.

Your name may be published together with your review on the Trusted Shops website. In some cases, Trusted Shops may contact you to request further clarification of your review.

When we invite you to leave a review, we share your name and e-mail address with Trusted Shops solely for the purpose of sending you this invitation.

Trusted Shops has taken appropriate technical and organisational measures to protect your personal data and may engage third parties in the provision of its services. These third parties are bound by the same security and confidentiality obligations.

2.5 Shipping and logistics
Micodo
When you place an order with us, it is our responsibility to ensure that your parcel or pallet is delivered to you. We use the services of Micodo to carry out deliveries. For this purpose, it is necessary for us to share your name, address, town/city and telephone number with Micodo. Micodo uses this data solely for the performance of the contract. If Micodo engages subcontractors, your data will also be made available to those parties.

Monta
When you place an order with us, it is our responsibility to ensure that your parcel or pallet is delivered to you. We use the services of Monta to carry out deliveries. For this purpose, it is necessary for us to share your name, address, town/city and telephone number with Monta. Monta uses this data solely for the performance of the contract.

Dachser
When you place an order with us, it is our responsibility to ensure that your parcel or pallet is delivered to you. We use the services of Dachser to carry out deliveries. For this purpose, it is necessary for us to share your name, address, town/city and telephone number with Dachser. Dachser uses this data solely for the performance of the contract. If Dachser engages subcontractors, your data will also be made available to those parties.

3. Purpose and legal basis of data processing

3.1 General purpose of the processing
We use your data exclusively in order to provide our services. This means that the purpose of the processing is always directly related to the assignment you give us. We do not use your data for (targeted) marketing purposes. If you share data with us and we wish to use this data at a later point to contact you in a way other than at your explicit request, we will always ask for your explicit consent beforehand.

Your data is not shared with third parties, other than where this is necessary in order to comply with accounting obligations or other administrative requirements. All such third parties are bound by confidentiality, either under the agreement we have with them or by an oath or statutory obligation.

3.2 Automatically collected data
When you visit our website, we automatically collect certain data. This includes, for example, your IP address, the type of web browser you use, the operating system you use and how you use our website. In some cases, this data may constitute personal data.

We process this information in order to improve our website and our services, to detect faults, to monitor security and to prevent misuse. The processing is based on our legitimate interest in operating a properly functioning and secure website.

3.3 Cooperation with tax and criminal investigations
In certain cases, My Steel BV may be required by law to share your data in connection with tax or criminal investigations carried out by public authorities. In such a situation we are obliged to disclose your data, but we will, within the limits of the law, oppose any requests that we consider to be too broad or unfounded.

3.4 Retention periods
We retain your data for as long as you are our customer. This means that we keep your customer profile until you inform us that you no longer wish to use our services. If you inform us of this, we will treat this as a request to erase your data.

Due to applicable administrative obligations, we are required to retain invoices containing your (personal) data for the duration of the statutory retention period. However, our employees will no longer have access to your customer profile or to documents that we have created in connection with your assignment.

4. Your rights as a data subject

Under applicable Dutch and European legislation, you, as a data subject, have certain rights in relation to the personal data that is processed by us or on our behalf. Below we explain which rights these are and how you can exercise them.

As a rule, and in order to prevent misuse, we send copies and transcripts of your data only to the e-mail address already known to us. If you wish to receive the data at another e-mail address or by post, we will ask you to provide proof of identity. We keep a record of requests that we have handled; in the case of an erasure request we record data in anonymised form. All copies and transcripts of data are provided to you in a machine-readable data format that we use within our systems.

You also have the right at any time to lodge a complaint with the competent supervisory authority if you believe that we are processing your personal data in an unlawful way.

4.1 Right of access
You always have the right to access the data that we (arrange to) process and that relates to you or can be traced back to you. You can submit a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send a copy of all data to the e-mail address we have on record for you, together with an overview of the processors who hold this data, specifying the category under which we have stored this data.

4.2 Right to rectification
You always have the right to have the data that we (arrange to) process and that relates to you or can be traced back to you corrected. You can submit a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send a confirmation to the e-mail address we have on record for you stating that the data has been amended.

4.3 Right to restriction of processing
You always have the right to request a restriction on the processing of the data that we (arrange to) process and that relates to you or can be traced back to you. You can submit a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send a confirmation to the e-mail address we have on record for you stating that the data will no longer be processed until you lift the restriction.

4.4 Right to data portability
You always have the right to request that the data we (arrange to) process and that relates to you or can be traced back to you be transferred to another controller. You can submit a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send copies or transcripts of all data about you that we have processed, or that has been processed on our behalf by other processors or third parties, to the e-mail address we have on record for you. It is likely that, in such a case, we will no longer be able to continue providing our services, as a secure link between data sets can then no longer be guaranteed.

4.5 Right to object and other rights
In certain situations you have the right to object to the processing of your personal data by or on behalf of My Steel BV. If you lodge an objection, we will immediately suspend the processing of your data pending the outcome of your objection. If your objection is well-founded, we will provide you with copies and/or transcripts of the data that we (arrange to) process and permanently cease processing this data.

You also have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. We do not process your data in a way that would give rise to such decisions. If you nevertheless believe that this is the case, please contact our privacy contact person.

5. Cookies

5.1 Google Analytics
Cookies from the US company Google are placed via our website as part of the “Analytics” service. We use this service to track how visitors use our website and to obtain reports on this. This processor may be required by law to grant access to this data to public authorities. We have not allowed Google to use the analytics information obtained for any other Google services.

5.2 Third-party cookies
If software solutions from third parties make use of cookies, this will be stated in this privacy policy.

6. Changes to this privacy policy

We reserve the right to amend our privacy policy at any time. The most recent version will always be available on this page. If the new privacy policy has consequences for the way in which we process data about you that we have already collected, we will inform you of this by e-mail.

7. Contact details

My Steel BV
Energieweg 35
5422 VM Gemert
Netherlands

T +31 (0)492 745200
E info@mysteel.nl