Privacy Policy
1. Who we are
MGA Associates Ltd. is the controller of your personal data for the purposes of UK GDPR and the Data Protection Act 2018. Our contact details are:
Business name: MGA Associates Ltd.
Trading name: Nexus Catering
Email: info@nexuscatering.co.uk
If you have any questions about this privacy policy or how we use your data, you can contact us using the details above.
2. What information we collect
We may collect and use the following personal data:
- Name.
- Email address.
- Phone number.
- Delivery or event address.
- Billing information.
- Order details and dietary requirements.
- Enquiry details sent through our website forms, email, or phone.
- Technical data such as IP address, browser type, and cookie data if you use our website.
3. How we use your information
We use your personal data to:
- Respond to enquiries and provide quotes.
- Take, manage, and deliver catering orders.
- Handle payments, refunds, and accounting.
- Manage venue, delivery, and event logistics.
- Deal with dietary and allergy-related requests.
- Send service messages about your order.
- Send marketing, where permitted.
- Improve our website and services.
4. Lawful basis
We only use your data when we have a lawful basis to do so. Depending on the situation, this may include:
- Contract: to provide quotes, take orders, and deliver catering services.
- Legal obligation: to keep records for tax and accounting purposes.
- Consent: for marketing emails or non-essential cookies.
- Legitimate interests: to run and improve our business, handle enquiries, and protect against fraud or misuse.
5. Sharing your data
We may share your data with trusted third parties where necessary, including:
- Payment providers.
- Accountants and bookkeepers.
- Delivery couriers.
- Website hosting, email, and IT service providers.
- Professional advisers, insurers, or legal advisers.
We only share what is necessary and expect third parties to keep your data secure.
6. International transfers
If any of our service providers store or process data outside the UK, we will make sure appropriate safeguards are in place to protect your information.
7. How long we keep data
We keep personal data only for as long as necessary for the purpose it was collected. In general:
- Order and invoice records are kept for up to 6 years.
- Enquiry emails are kept for up to 6 years.
- Marketing data is kept until you unsubscribe or withdraw consent.
- Cookie data is kept in line with our cookie settings and policy.
8. Marketing
If you opt in, we may send you marketing emails about our services, offers, or events. You can unsubscribe at any time by clicking the link in our emails or contacting us directly. We will never send you marketing where we do not have a lawful basis to do so.
9. Cookies
Our website uses cookies. Strictly necessary cookies help the site function, while analytics and marketing cookies are only used where required consent has been given. You can manage your cookie choices through our cookie banner or settings tool.
10. Your rights
Under UK GDPR, you may have the right to:
- Access your personal data.
- Correct inaccurate data.
- Erase your data in some circumstances.
- Restrict or object to certain processing.
- Withdraw consent where consent is the lawful basis.
- Receive a copy of your data in a portable format, where applicable.
11. Complaints
If you are unhappy with how we use your data, please contact us first so we can try to resolve the issue. You also have the right to complain to the Information Commissioner’s Office (ICO).
12. Changes to this policy
We may update this privacy policy from time to time. The latest version will always be posted on this page with an updated date.
Last updated: 31/05/2026
