Privacy / data protection
Privacy Policy
Last updated: 18 July 2026
This notice explains how Cater Elite collects and uses personal information when you visit this website, contact us, enquire about hospitality staff, register your interest in work, submit a CV, subscribe to updates or use an account feature.
1. Who we are
Cater Elite is the controller responsible for the personal information described in this notice. We are a hospitality staffing business based in Dorset, United Kingdom.
- Email: nanzy@caterelite.co.uk
- Telephone: 01202 119748
- Postal correspondence: contact us using the details above for our current correspondence address.
This notice reflects the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003. The EU GDPR also applies where our activities fall within its territorial scope.
2. Information we collect
Depending on how you deal with us, we may collect:
- Identity and contact details, such as your name, email address, telephone number, username and organisation.
- Candidate and recruitment details, such as your CV, work history, qualifications, role preferences, availability, right-to-work information, cover letter and references.
- Client and assignment details, such as venue, staffing requirements, dates, shift times, headcount, correspondence and commercial records.
- Enquiry and account details, including messages, subjects, subscription choices, account credentials and records of our response.
- Technical and usage details, such as IP address, device and browser information, security events, cookie identifiers, pages viewed and interaction data.
We normally receive this information directly from you. We may also receive relevant information from a referee, a client or venue, publicly available professional sources, or our website and security providers. If you give us information about another person, please make sure you are allowed to do so.
Special category and criminal-offence information
We do not ask for sensitive information unless it is necessary for recruitment, workplace adjustments, equal-opportunity monitoring, safeguarding or a legal requirement. Where we process health, disability or other special category information, or criminal-offence information, we will identify both a lawful basis and the additional condition required by data protection law, restrict access and apply appropriate safeguards.
3. Why we use information and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Respond to enquiries and discuss staffing or work opportunities | Steps before a contract; legitimate interests in operating a responsive staffing service |
| Assess candidates, match people to suitable assignments and administer placements | Steps before a contract; performance of a contract; legitimate interests in recruitment and staffing |
| Provide staff, manage client relationships, payments and business records | Performance of a contract; legal obligation; legitimate interests in business administration and legal claims |
| Operate accounts, protect the website, prevent misuse and diagnose faults | Legitimate interests in security and service reliability; legal obligation where applicable |
| Send optional news or direct marketing | Consent where required by PECR; otherwise legitimate interests where the law permits |
| Use non-essential cookies or similar technologies | Consent, unless a specific statutory exception applies |
| Meet employment, tax, equality, safeguarding and regulatory duties | Legal obligation; substantial public interest or employment-law conditions where sensitive information is involved |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and do not use that basis where your rights and interests override ours. You can ask for details of a relevant assessment.
You may decline to provide information, but we may be unable to respond, assess an application or provide a requested service where that information is necessary. We do not use this website to make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. Who we share information with
We share personal information only where it is necessary and proportionate. Recipients may include:
- authorised Cater Elite personnel;
- clients, venues or hiring organisations considering or receiving staffing services, after an appropriate recruitment discussion;
- referees and screening providers where checks are appropriate and lawful;
- hosting, IT, email, form, security, communications and professional-service providers acting under appropriate terms;
- technology providers used by the website, including Google services for maps, reCAPTCHA or sign-in where those features are used, and a mailing-list provider where you subscribe; and
- regulators, courts, law-enforcement bodies or other parties where disclosure is required by law or necessary to establish, exercise or defend legal claims.
We do not sell personal information. We do not give a candidate’s CV to unrelated organisations for their own marketing.
International transfers
Some technology or service providers may process information outside the United Kingdom or European Economic Area. Where restricted-transfer rules apply, we use an applicable adequacy decision, approved contractual safeguards such as the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, or another lawful transfer mechanism. You can ask us for information about the relevant safeguard.
5. How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose collected. We determine the period by considering the status and age of an enquiry or application, whether a working or client relationship continues, legal and tax recordkeeping duties, limitation periods, safeguarding needs, dispute or complaint records, and whether you have asked us to retain your details for future suitable work.
When information is no longer required, we delete it securely or anonymise it. You may ask us for the retention criteria applying to your information.
6. Security
We use proportionate technical and organisational measures designed to protect personal information, including access controls, service-provider checks, system maintenance and secure deletion. No internet service is completely secure, so please do not send unnecessary sensitive information through an ordinary email or website form. If a personal-data breach is likely to create a risk to people, we will assess it and notify the relevant regulator and affected people where the law requires.
7. Your data-protection rights
Depending on the circumstances and the law that applies, you may have the right to:
- be informed and obtain access to your personal information;
- correct inaccurate or incomplete information;
- ask for deletion or restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable, machine-readable format;
- withdraw consent at any time, without affecting earlier lawful processing; and
- ask for human intervention where a significant decision is made solely by automated means.
To exercise a right, email nanzy@caterelite.co.uk. We may ask for proportionate information to verify your identity. Requests are normally free of charge and answered without undue delay, usually within one month. The law allows limited extensions or a reasonable fee in specific circumstances, and we will explain if either applies.
9. Children
This website is not designed to collect information from children under 16. If you believe a child has provided personal information without an appropriate basis or safeguard, please contact us so we can investigate and take suitable action.
10. Questions and complaints
Contact nanzy@caterelite.co.uk with a question, rights request or data-protection complaint. Please describe what happened, the information involved and the outcome you want.
We will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, keep you appropriately informed and tell you the outcome. You can also complain to the UK Information Commissioner’s Office using its data-protection complaints service. If EU GDPR applies, you may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
11. Changes to this notice
We review this notice when our services, technology or legal duties change. Material changes will be published on this page with a new update date and, where appropriate, brought to the attention of affected people.