Legal

Legal Documents — Not A Big Four
Legal Document

Privacy & Data Protection Policy

Not A Big Four — a trading name of Opera Capital Management Ltd

Effective date: 01 April 2026 Last reviewed: 01 April 2026 Version: 1.0
Save a copy of this policy for your records
Plain English first: We collect only the personal data we need to respond to your enquiries and deliver our services. We do not sell it, share it with advertisers, or use it to profile you. We store it securely, keep it only as long as necessary, and give you full control over it. This policy explains what we collect, why, and what your rights are.

1. Who we are

Opera Capital Management Ltd (trading as Not A Big Four) is the data controller for personal data collected through this website and in the course of our business activities.

Data Controller

Opera Capital Management Ltd
Trading as Not A Big Four
2nd Floor, 33 Newman Street, London W1T 1PY
Registered in England and Wales — Company No. 08355935
Email: hello [at] notabig4.com

This policy applies to personal data we process about visitors to our website (notabig4.com), prospective clients, current and former clients, business contacts, and any other individuals whose data we handle in the course of our operations.

This policy complies with the UK GDPR and the Data Protection Act 2018, as well as the EU General Data Protection Regulation (EU) 2016/679 insofar as we process the personal data of individuals located in the European Economic Area.

2. What data we collect and why

2.1 Website enquiries

When you contact us via our website or by email, we may collect your name, email address, company name and the content of your message.

Why: To respond to your enquiry and assess whether we can be of assistance to you.

2.2 Client and business relationship data

Where you engage us as a client or enter into discussions with a view to doing so, we may collect and process:

  • Contact details (name, email, telephone, business address)
  • Business information (company name, registration details, sector, size)
  • Information necessary to fulfil our engagement (which may include commercial, financial or operational data depending on the scope of work)
  • Correspondence and communications

Why: To deliver our consultancy services, manage our client relationship, fulfil our contractual obligations, and comply with our legal and regulatory obligations.

2.3 Website analytics data

We use Google Analytics to collect aggregated, anonymised information about how visitors use our website. This includes pages visited, time spent on the site, device and browser type, and approximate geographic location (country/city level). This data does not identify you as an individual.

Why: To understand how the website is used and to improve its content and functionality. This processing is based on your consent, given via our cookie banner.

2.4 Booking and consultation data

When you book a free consultation via our cal.eu booking page, the following data is collected and shared with us by Cal.com:

  • Your name
  • Your email address
  • Your selected date and time
  • Any notes or additional information you choose to provide in the booking form

Why: To confirm, prepare for and conduct the consultation. Legal basis: legitimate interests (taking pre-contractual steps at your request) and, where a client relationship develops, contract performance.

Please note that Cal.com operates as an independent data controller for the data you submit on their platform. Their privacy policy governs that relationship: cal.com/privacy.

2.5 Data you provide in other contexts

We may also collect personal data when you connect with us via LinkedIn or other professional platforms, attend an event at which we are present, or are referred to us by a mutual contact.

3. Legal bases for processing

Under UK GDPR and EU GDPR, we must have a legal basis for each type of processing activity. Our legal bases are:

  • Contract (Art. 6(1)(b)): Processing necessary to perform a contract with you, or to take steps at your request before entering a contract. This applies to the delivery of our consultancy services.
  • Legitimate interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, where those interests are not overridden by your rights. This applies to responding to enquiries, maintaining business records, and improving our website.
  • Legal obligation (Art. 6(1)(c)): Processing necessary to comply with a legal obligation, including applicable financial services regulations, tax law, and anti-money laundering requirements.
  • Consent (Art. 6(1)(a)): Where you have freely given, specific and informed consent. This applies to non-essential cookies and to any direct marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. Who we share your data with

We do not sell, rent or trade your personal data. We share your data only in the following limited circumstances:

4.1 Service providers (data processors)

4.2 Legal and regulatory disclosure

We may disclose personal data to regulatory authorities, law enforcement agencies, or courts where required by law or where necessary to protect our legal rights or those of a third party.

4.3 Professional advisers

We may share data with our lawyers, accountants or insurers where necessary for the conduct of our business, subject to appropriate confidentiality obligations.

5. International transfers

Some of our third-party service providers are located outside the UK and/or EEA. Where we transfer personal data internationally, we ensure appropriate safeguards are in place.

6. How long we keep your data

7. How we protect your data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration or destruction. These measures include:

  • Encrypted data transmission (TLS/HTTPS) for all website communications
  • Access controls limiting data access to those with a legitimate need
  • Use of reputable, security-vetted service providers
  • Regular review of our data handling practices
  • Strong password policies and multi-factor authentication on systems that hold personal data

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly.

8. Your rights

Under UK GDPR and EU GDPR, you have the following rights. We will respond to all verified requests within one month of receipt.

Right of access

You have the right to request a copy of the personal data we hold about you (a Subject Access Request).

Right to rectification

You have the right to ask us to correct inaccurate personal data or complete incomplete data.

Right to erasure

You have the right to ask us to delete your personal data in certain circumstances.

Right to restrict processing

You have the right to ask us to pause processing your data while a request is resolved.

Right to data portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, machine-readable format.

Right to object

You have the right to object to processing based on legitimate interests, and to processing for direct marketing purposes.

Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

Rights re: automated decisions

You have the right not to be subject to decisions based solely on automated processing. We do not engage in such processing.

9. Children’s data

Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it promptly.

10. Third-party services and links

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Any changes will be published on this page with an updated effective date. Where changes are material, we will take reasonable steps to notify you.

12. Contact and complaints

For any questions about this policy, to exercise your rights, or to raise a concern about our data practices:

Opera Capital Management Ltd (trading as Not A Big Four)
2nd Floor, 33 Newman Street, London W1T 1PY
Company No. 08355935
Email: hello [at] notabig4.com

Supervisory authorities

If you are not satisfied with our response, or believe we are processing your data unlawfully, you have the right to lodge a complaint with the relevant supervisory authority:

  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk — 0303 123 1113
  • Italy: Garante per la protezione dei dati personali — garanteprivacy.it
  • Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
  • EU (general): The supervisory authority of your EU member state of habitual residence, place of work, or place of the alleged infringement

We would however appreciate the opportunity to address your concern directly before you approach a supervisory authority.