NotForgot

Privacy Policy

Last updated: 23 September 2026

1. Who we are

NotForgot is a service operated by Peppercord Limited, trading as NotLuck. Peppercord Limited is registered in England and Wales, company number 15954819, at Fenchurch House, King Street, Nottingham NG1 2AS. Our main privacy policy is at notluck.co.uk/privacy; this page covers what is specific to NotForgot.

For the time entries, client records and team records your agency puts into NotForgot, your agency is the data controller and we are its data processor: we handle that data only on your agency's instructions, under our Data Processing Agreement. We are the data controller only for what we collect about you directly, such as your contact details when you sign up and, if you allow it, website analytics. Questions or requests can be sent to [email protected].

2. What NotForgot is

NotForgot is a time-tracking tool for virtual assistant agencies and other service teams. Team members log time against client codes through a personal signed link. All entries are stored inside the agency's own sub-account on the NotLuck platform, which runs on HighLevel (LeadConnector). NotForgot does not have its own separate database — your data lives in your agency's CRM.

3. What personal data we process

When your agency uses NotForgot, the following categories of data are processed:

We do not capture screenshots, keystrokes, clipboard content, or any other form of activity data at any time. Logging is entirely self-reported.

4. Where your data is stored

All time entries, client records and team member records are stored within your agency's own sub-account on the NotLuck HighLevel installation. HighLevel Inc (operating as LeadConnector) stores and processes this data in the United States. Transfers are covered by standard contractual clauses, as set out in our main privacy policy and our Data Processing Agreement.

The NotForgot web app itself (the pages you visit at notforgot.notluck.co.uk) is hosted on Netlify. Netlify may log standard server-side request metadata (IP address, user agent, timestamp) for security and reliability purposes. Netlify's privacy policy governs that processing.

5. Our processors

All processors are bound by data processing agreements and applicable law.

6. Lawful basis for processing

7. The personal-link model

NotForgot uses signed personal links instead of passwords. Your unique link is generated by the agency and acts as your credential. You should treat it like a password — do not share it with others.

If your link is compromised, contact the agency admin. They can revoke your link and issue a new one at any time from within the HighLevel sub-account. Revoked links stop working immediately.

We do not use your link to track your browsing activity outside of NotForgot, and we do not share link identifiers with third parties.

8. No activity monitoring

NotForgot does not monitor, record or report on what you do on your device. We capture only what you explicitly submit: the time entry fields you fill in, or the WhatsApp message you send. There are no screenshots, no keyloggers, no screen recordings, and no activity feeds visible to the agency. Your working time outside of submitted entries is entirely your own.

9. Your clients stay confidential

Your client list, what you do for each client and how many hours you spend are your agency's confidential business information. We treat them that way.

You also decide how much goes in. A short client code and a first name are enough for NotForgot to work, and a task description can be as general as you like.

10. How long we keep data

Time entries, client records and team member records are retained for as long as the agency's HighLevel sub-account remains active. If the agency closes its account, the data is deleted within 30 days and purged from backups within 90 days, in line with our main privacy policy.

You can request an export of your own time entries at any time by contacting the agency admin or emailing us at [email protected]. Deletion requests are handled within 30 days.

11. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email [email protected]. We will respond within one calendar month.

12. Complaints

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

We would welcome the chance to address your concern directly first — please contact us at [email protected] before escalating to the ICO.

13. Changes to this policy

We will update this page when our practices change. The "Last updated" date at the top shows when it was last revised. Significant changes will be communicated to active users.