Who we are and who controls your data
NEXA Distribution Ltd is the controller of personal information described in this Privacy Policy unless we specifically state otherwise. We operate a business-to-business wholesale and distribution website serving professional buyers, trade customers, distributors, importers, exporters and marketplace sellers.
New Addington Vulcan Way,
Croydon, Surrey CR0 9UG,
United Kingdom
Scope of this Privacy Policy
This notice applies when you visit our website, create or apply for a trade account, submit an enquiry, request pricing, place or discuss an order, communicate with our team, receive business marketing from us, or otherwise interact with us in a commercial context.
It is intended to provide the privacy information required under Articles 13 and 14 of the UK GDPR and should be read together with any more specific privacy information shown at the point where information is collected.
Personal information we may collect
Name, company name, role, business type, company registration details, VAT or tax identifiers and website details.
Business email address, telephone number, billing address, delivery address and other contact information.
Application details, approval status, account history and information needed to assess and administer B2B access.
Products, quantities, order references, invoice/proforma information, payment references, shipping details, delivery status and commercial correspondence.
IP address, browser/device information, page activity, security logs, identifiers and information collected through cookies or similar technologies.
Emails, contact-form enquiries, support messages, complaints, preference requests and records of business discussions.
Business interests, source of business contact details, campaign engagement where lawfully measured, and opt-out/suppression preferences.
Information reasonably required to prevent misuse, protect accounts, investigate suspicious activity and secure our services.
Passwords: website account passwords are handled by the website authentication system in protected/hashed form. We do not need to know or store your readable password.
Where personal information comes from
We collect information directly from you when you submit forms, create an account, place an order request, contact us or correspond with our team. We may also receive information through our website systems, service providers and commercial partners.
For legitimate B2B prospecting and due diligence, we may obtain business-contact information from publicly available professional or corporate sources, such as company websites, public corporate registers, professional networks or business directories. Where UK GDPR requires us to provide privacy information because data came from another source, we will do so within the applicable timeframe, subject to lawful exceptions.
Why we use personal information
| Purpose | Examples |
|---|---|
| Provide B2B services | Trade-account administration, catalogue access, enquiries, quotations and order management. |
| Perform commercial transactions | Order verification, proforma/sales invoicing, payment reconciliation, fulfilment, shipping and after-sales support. |
| Business administration | Accounting, tax, record keeping, audits, supplier/customer management and professional advice. |
| Security & fraud prevention | Protecting accounts, systems, website availability, business assets and transaction integrity. |
| Customer service | Responding to questions, complaints, change requests and account support. |
| Website improvement | Understanding performance, diagnosing errors and improving usability in accordance with applicable cookie/tracking rules. |
| B2B marketing | Relevant wholesale offers, catalogue updates and commercial communications, subject to UK GDPR and PECR. |
| Legal & regulatory compliance | Tax, customs, accounting, fraud prevention, legal claims and responding to lawful regulatory or law-enforcement requests. |
Our lawful bases for processing
We use one or more lawful bases depending on the purpose and context:
Where processing is necessary to take steps at your request before entering into a contract or to perform a contract, such as administering a trade account or order.
Where we need to comply with applicable law, including tax, accounting, customs, fraud-prevention or regulatory requirements.
Where necessary for proportionate business purposes such as B2B customer management, network security, fraud prevention, service improvement, debt/claims management and certain B2B marketing, provided those interests are not overridden by individual rights and interests.
Where consent is required, including certain forms of electronic marketing or storage/access technologies. You may withdraw consent at any time without affecting prior lawful processing.
Where we rely on legitimate interests, we consider the purpose, necessity and impact on individuals. We do not use legitimate interests where the impact on your rights would be disproportionate.
Trade accounts, enquiries and wholesale orders
Our website is designed for business customers. When you apply for a trade account, we use the information provided to assess the application, verify the business context, administer account permissions and communicate the outcome.
When you submit a wholesale order request, we use relevant customer, product, delivery and contact information to verify stock/pricing, prepare commercial documentation, process the transaction, fulfil the order and maintain records. Some information is required for us to enter into or perform the commercial relationship. If required information is not provided, we may be unable to approve an account, issue a quotation/proforma, accept an order or arrange delivery.
B2B direct marketing and your right to object
Use the unsubscribe/opt-out method in a message or email us at sales@nexadistributionltd.com. We will respect applicable objections and may retain minimal suppression information so that we do not contact you again for the same marketing purpose.
UK rules distinguish between corporate subscribers and individual subscribers. In general, PECR's electronic-mail consent rule does not apply to corporate subscribers such as limited companies and LLPs, but UK GDPR still applies where a named business contact's personal information is processed. Sole traders and certain partnerships are treated as individual subscribers for PECR purposes and may require consent unless another PECR exception applies.
We do not disguise our identity in marketing communications and provide a valid method to opt out. We use business-contact information only where we have an appropriate lawful basis and consider reasonable expectations, relevance and privacy impact.
International transfers
Some providers or commercial operations may involve processing outside the United Kingdom. Where a transfer is a restricted transfer under UK data-protection law, we use a lawful transfer mechanism as applicable.
This may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework for eligible US recipients, or appropriate safeguards such as the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses. Where required, we also complete the applicable transfer risk assessment / data protection test and implement supplementary measures so that the standard of protection is not materially lower than in the UK.
You may contact us for information about the relevant transfer safeguard where this applies to your personal information.
How long we keep personal information
We retain personal information only for as long as reasonably necessary for the purpose collected, including legal, accounting, tax, contractual, fraud-prevention and claims requirements. Typical retention periods or criteria include:
| Record | Typical retention approach |
|---|---|
| Customer, order, invoice and VAT records | Normally at least 6 years where required for UK VAT/accounting records, and longer only where another legal requirement or live dispute applies. |
| Approved trade-account records | For the active relationship and normally up to 6 years after the final relevant transaction/relationship where needed for legal, tax or claims purposes. |
| Rejected, incomplete or inactive applications | Normally up to 24 months after the decision or last activity, unless a longer period is needed for fraud prevention, a complaint, dispute or legal requirement. |
| General business enquiries | Normally up to 24 months after the last meaningful contact unless the enquiry becomes part of a customer/order relationship. |
| Marketing suppression / opt-out records | Minimal information may be retained for as long as necessary to ensure the opt-out remains respected. |
| Website/security logs | Kept for a limited period proportionate to security, fraud prevention, diagnostics and legal requirements; longer only where an incident or investigation requires it. |
| Cookie / technology identifiers | According to the relevant cookie/technology lifespan and consent settings, subject to applicable law. |
How we protect personal information
We use appropriate technical and organisational measures proportionate to the nature of the information and risks involved. Measures may include access controls, authentication, role-based permissions, security monitoring, encryption in transit where supported, protected backups, software updates, data minimisation and procedures for responding to security incidents.
No online service can guarantee absolute security. If we become aware of a personal-data breach, we assess it and notify affected individuals and/or the ICO where the law requires us to do so.
Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
These rights are not absolute and exemptions may apply. We may need to verify your identity before fulfilling a request. We aim to respond within the timeframe required by applicable law; many UK GDPR rights requests are ordinarily due within one month.
MAKE A DATA RIGHTS REQUEST →Automated decision-making and profiling
We do not currently use solely automated decision-making to approve trade accounts or accept wholesale orders where that decision would produce legal or similarly significant effects on an individual. Trade-account and commercial order decisions may involve human review.
If this changes, we will update this notice and provide any additional information and safeguards required by law.
Children's information
Our website and wholesale services are intended for businesses and professional buyers, not children. We do not knowingly seek to create trade accounts for children or collect children's personal information for B2B sales purposes.
Third-party websites and services
Our website may link to third-party websites, marketplaces, carriers or services. Their processing is governed by their own privacy information where they act as independent controllers. We are not responsible for the privacy practices of independent third-party websites merely because we link to them.
Changes to this Privacy Policy
We keep this policy under review and may update it to reflect changes in our business, systems, suppliers, legal obligations or regulatory guidance. The latest version will be published on this page with the updated date. Where a change materially affects how we use personal information, we will take reasonable steps to bring the change to the attention of affected individuals where required.
Questions, complaints and the ICO
If you have a privacy question, wish to exercise a right or believe we have not handled your personal information properly, please contact us first so we can investigate.
You can make a data-protection complaint to us using the privacy email below. We will acknowledge receipt within 30 days, take appropriate steps to investigate and respond without undue delay, keep you appropriately informed, and tell you the outcome without undue delay. You may still complain to the Information Commissioner's Office if you remain dissatisfied.
NEXA Distribution Ltd
sales@nexadistributionltd.com +44 7869644883Unit 28, Addington Business Center,
New Addington Vulcan Way,
Croydon, Surrey CR0 9UG,
United Kingdom
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Helpline: 0303 123 1113
VISIT ICO WEBSITE →This policy has been structured around the transparency requirements of the UK GDPR and Data Protection Act 2018, current ICO guidance, the Privacy and Electronic Communications Regulations 2003 (PECR), and relevant amendments introduced by the Data (Use and Access) Act 2025.