Legal
Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how 4-Dimensions Media Network Ltd (registered in England and Wales, company number 10810404) of Suite 1 (First Floor), 239 High Road, Ilford, United Kingdom, IG1 1NE (the “Operator”, “we”, “us”) collects, uses, and protects personal data when you use the MyNextBusiness platform at mynextbusiness.co.uk (the “Platform”). We are the controller of the personal data described here. This Policy should be read with our Terms of Service.
1. The data we collect
Account and profile data: name, email address, password (stored only as a secure hash), role, and profile details you provide (for buyers, this may include investment preferences, budget range, preferred sectors and locations; for sellers, business ownership details).
Verification data: information and documents you submit to verify identity, proof of funds, or business ownership as part of qualification. Where this includes identity documents, it is treated as higher-risk data and handled with additional safeguards (restricted access, encryption of sensitive values, and audit logging).
Listing and transaction data: the content of Listings, enquiries, offers, messages, and documents you exchange in deal rooms.
Technical and usage data: IP address, device and browser information, authentication and security events, audit logs, and how you interact with the Platform. Uploaded images are processed to strip embedded location (EXIF/GPS) metadata before display.
Communications: messages you send us, and records of notifications and emails we send you.
2. How and why we use it (lawful bases)
We process personal data on the following bases under the UK GDPR:
- Contract — to create and operate your account, provide the marketplace, enable messaging, offers and deal rooms, and provide support.
- Legitimate interests — to secure the Platform, prevent fraud and misuse, verify users, maintain audit logs, improve the service, and protect users’ and sellers’ confidential information (balanced against your rights).
- Legal obligation — to comply with law, including tax and record-keeping obligations, and to respond to lawful requests.
- Consent — for optional communications such as marketing newsletters and non-essential cookies, which you can withdraw at any time.
Where we process identity documents or other higher-risk data as part of verification, we rely on your provision of that data for the specific purpose of qualification and fraud-prevention, and we retain it only as described in section 5.
3. Identity protection and disclosure between users
A core feature of the Platform is that sellers’ identities and detailed business information are protected. Public Listings are anonymised. Your identity and information are disclosed to another user only after the qualification and NDA steps are completed, and only to the extent needed for a potential transaction. Information you disclose to another user through the Platform is then also handled by that user; where they determine their own purposes for it, they act as a separate controller.
4. Service providers and where data is held
We use trusted third-party providers to run the Platform, each processing personal data on our instructions under written terms. These currently include a cloud-hosted application database, a cloud object-storage provider for uploaded files, a transactional-email provider, and background-job infrastructure. We may add identity-verification and payment providers in future, and will update this Policy accordingly.
Where a provider processes data outside the UK, we rely on an appropriate safeguard such as UK adequacy regulations or the International Data Transfer Agreement or Addendum, so that your data receives an equivalent level of protection.
5. Retention
We keep personal data only as long as necessary for the purposes above. Account and profile data are kept while your account is active. When you delete your account, we delete or anonymise your personal data within six (6) months, except for the limited records below, which we retain for longer where we have a legitimate or legal reason to do so:
- Completed-transaction records — records that a transaction was progressed or completed through the Platform, retained for dispute-resolution, fraud-prevention and accounting purposes.
- Security and audit logs — append-only logs of security-relevant events, retained for a longer defined period to investigate fraud, account-takeover and misuse.
These retained records are minimised (limited to what is necessary), access-controlled, and deleted once the retention purpose no longer applies.
6. Your rights
Subject to conditions under data-protection law, you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent. The Platform provides tools to export your data and to delete your account. To exercise a right, use the in-Platform tools or contact us using the details below; we will respond within one month, subject to identity verification. Where an erasure request affects records we are permitted to retain under section 5, we will erase everything except those specific records. You also have the right to complain to the Information Commissioner’s Office (ICO).
7. Security
We apply security measures including encryption of sensitive secrets, secure password hashing, access controls with least-privilege and re-checked authorisation, rate limiting and account-protection controls, secure and access-controlled file storage with watermarking of sensitive documents, stripping of location metadata from images, and append-only audit logging. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents. Where a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours where required, and affected users where the risk is high.
8. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary to operate the Platform (for example, to keep you signed in and to keep the Platform secure), and, only with your consent, optional cookies such as analytics. You can manage non-essential cookies through the Platform’s cookie controls; see our cookie notice. Strictly-necessary cookies do not require consent; all others are off until you opt in.
9. Children
The Platform is intended for business and professional users and is not directed at children. We do not knowingly collect personal data from anyone under 18.
10. Changes and contact
We may update this Policy and will post the updated version with a new date; where changes are material we will give reasonable notice. For any privacy question or request, contact us at privacy@mynextbusiness.co.uk, or by post at Suite 1 (First Floor), 239 High Road, Ilford, United Kingdom, IG1 1NE.
We are registering with the Information Commissioner’s Office (ICO); our registration number will be published here once issued.