Data Processing Agreement
How we handle the personal data you store in your CRM account, who else touches it, and what we owe you.
1. Who This Applies To
Peppercord Limited (trading as NotLuck)
- Registration: Registered in England and Wales
- Company Number: 15954819
- Email: hello@notluck.co.uk
- Website: notluck.co.uk
This Data Processing Agreement (the "DPA") applies whenever you use the NotLuck CRM platform, or any other NotLuck service, to store or process personal data belonging to your customers, contacts, staff or any other individuals.
It forms part of, and is incorporated into, the NotLuck CRM Platform Terms and Conditions. You do not need to sign it separately. It takes effect from the moment you begin using the Platform and continues for as long as we process personal data on your behalf.
1.1 Effective Date and Retrospective Effect
This DPA is effective from 31 July 2025, the date our Platform Terms and Conditions took effect, and it applies to all processing we have carried out on your behalf, including processing carried out before this document was published. Existing clients do not need to do anything, and are not in a weaker position for having joined earlier.
It was first published in full on 12 August 2026. Before that date the Terms and Conditions incorporated a data processing agreement by reference, and our obligations as your processor under the UK GDPR applied regardless. This document sets those obligations out properly, and we have chosen to make it apply retrospectively rather than only from its publication date.
If your organisation requires a signed copy for its own compliance records, email hello@notluck.co.uk and we will provide one.
Where this DPA and the Terms and Conditions disagree on the handling of personal data, this DPA takes precedence.
2. Definitions
In this DPA:
- "Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and where relevant the EU GDPR, together with any successor or amending legislation.
- "Client Personal Data" means personal data that you store in, or transmit through, the Platform, and which we process on your behalf.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given to them in Applicable Data Protection Law.
- "Platform" means the NotLuck CRM platform and any associated NotLuck service.
- "Sub-Processor" means any third party engaged by us to process Client Personal Data.
- "You" and "your" mean the NotLuck client who holds the account.
3. Roles and Responsibilities
3.1 The Chain
There are three links in the chain, and it matters that you know which is which:
Separately from this DPA, we are the Controller of the personal data we collect about you directly, such as your billing details and our correspondence with you. That is covered by our Privacy Policy, not by this DPA.
3.2 Our Responsibility for Sub-Processors
We remain fully liable to you for the acts and omissions of our Sub-Processors as if they were our own. You do not need to pursue them directly.
4. Scope of Processing
We process Client Personal Data only for the purpose of providing and supporting the Platform and the services you have asked us to deliver. The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are set out in Annex A.
4.1 Documented Instructions
We will process Client Personal Data only on your documented instructions, which include this DPA, the Terms and Conditions, your configuration of the Platform, and any support request you raise with us.
If we are required by law to process Client Personal Data other than on your instructions, we will tell you before doing so unless the law prohibits us from telling you.
If we consider that an instruction from you would breach Applicable Data Protection Law, we will tell you, and we may decline to carry it out.
4.2 What We Will Never Do
Our Commitments
- We will never sell your data, or share it for anyone else's marketing purposes
- We will never use Client Personal Data to train artificial intelligence models
- We will never use Client Personal Data for our own analytics, product research or marketing
- We access your account only to set it up, support you, deliver the service, or investigate an issue you have reported
- Access is limited to authorised NotLuck staff, each bound by a duty of confidentiality that survives the end of their engagement
5. Our Obligations
We will:
- Process Client Personal Data only on your documented instructions, as set out above
- Ensure that everyone authorised to process Client Personal Data is bound by an appropriate duty of confidentiality
- Implement and maintain the technical and organisational measures described in Annex B
- Respect the conditions in section 7 for engaging a Sub-Processor
- Assist you, so far as is reasonably possible, in responding to requests from data subjects exercising their rights
- Assist you with data protection impact assessments and any prior consultation with the Information Commissioner's Office, taking into account the nature of the processing and the information available to us
- Notify you of a Personal Data Breach in accordance with section 9
- Delete or return Client Personal Data at the end of our services, in accordance with section 12
- Make available to you the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits in accordance with section 11
6. Your Obligations
As the Controller, some things are yours and cannot be delegated to us:
- Having a lawful basis for the processing you ask us to carry out
- Providing your own privacy notice to your data subjects
- Obtaining any consent required, and keeping a record of it
- Ensuring the personal data you upload is accurate and lawfully obtained
- Deciding how long you keep it, and deleting what you no longer need (see section 12)
- Registering with the Information Commissioner's Office where you are required to
- Configuring the Platform, including its consent and marketing settings, in a way that matches your obligations
The Platform is a tool. Using it does not, by itself, make you compliant. We will help you set it up sensibly and we will tell you when we think something is wrong, but the responsibilities above sit with you, and we recommend you take independent legal advice where your sector carries additional duties.
7. Sub-Processors
7.1 General Authorisation
You give us general authorisation to engage Sub-Processors to process Client Personal Data. The current list is published and kept up to date at notluck.co.uk/sub-processors.
7.2 Terms Imposed on Sub-Processors
Where we engage a Sub-Processor, we impose on it data protection obligations that are no less protective than those in this DPA.
7.3 Changes and Your Right to Object
We will give you at least 30 days' notice before adding or replacing a Sub-Processor. You may object on reasonable data protection grounds within that period by emailing hello@notluck.co.uk.
If you object, we will work with you to find a reasonable solution. If none is available, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any fees paid in advance for the unused period.
7.4 The Underlying Platform
The NotLuck CRM platform is built on infrastructure operated by HighLevel, Inc. and its affiliate LeadConnector LLC. They act as a Sub-Processor beneath us. Their own data processing terms are published at gohighlevel.com/data-processing-agreement, and their sub-processor list at gohighlevel.com/sub-processors.
8. International Transfers
8.1 Where Your Data Is Processed
Client Personal Data is stored and processed in the United States. The platform infrastructure runs on Google Cloud Platform and Amazon Web Services, both in US regions. There is no UK or EU hosting option for the Platform.
We tell you this plainly because you may need to record it in your own documentation. Several of the supporting services listed at notluck.co.uk/sub-processors are also US-based.
8.2 The Legal Basis for the Transfer
Transfers of Client Personal Data outside the UK are made under one or more of the following safeguards:
- The European Commission's Standard Contractual Clauses, together with the International Data Transfer Addendum issued under section 119A(1) of the Data Protection Act 2018 and approved by the UK Parliament
- The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under it
- Any successor mechanism recognised as providing an adequate level of protection
Where the Standard Contractual Clauses apply, the Information Commissioner's Office is the competent supervisory authority, and they are governed by the law of England and Wales.
8.3 If a Safeguard Fails
If a transfer mechanism we rely on is invalidated or withdrawn, we will notify you and put an alternative safeguard in place without undue delay. If no lawful alternative is available, you may terminate the affected service without penalty.
9. Security Measures
We implement appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Those measures are described in Annex B.
We review those measures periodically and may update them, provided the level of protection is not reduced.
10. Breach Notification
If we become aware of a Personal Data Breach affecting Client Personal Data, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it.
Our notification will include, so far as we know it at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records affected
- The likely consequences
- The measures taken or proposed to address it and mitigate its effects
- A contact point for further information
We will provide further detail as it becomes available, and will cooperate with you in any notification you need to make to the Information Commissioner's Office or to affected individuals. Reporting a breach to the ICO is your responsibility as Controller, and the 72-hour clock on that obligation is yours, not ours.
Report a suspected breach to us at hello@notluck.co.uk, marked urgent.
11. Data Subject Rights
Most of your data subjects' rights can be satisfied by you directly, because you have full access to your account and can search, export, correct and delete records yourself.
Where you need our help, we will provide it. If a data subject contacts us directly about data held in your account, we will not respond to them on the substance. We will tell them to contact you, and we will let you know, normally within 3 working days.
12. Audit and Assurance
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA.
The underlying platform holds ISO/IEC 27001:2022 certification and undergoes annual SOC 2 Type II assessment. Where a request can reasonably be satisfied by those reports or by a completed security questionnaire, we will provide those rather than host an on-site audit.
Where that is not sufficient, you may audit us, or appoint an independent auditor to do so, on 30 days' written notice, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach. Audits take place during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality.
13. Retention and Deletion
13.1 During the Agreement
The Platform does not currently support automatic retention rules. Deleting personal data you no longer need is a manual task, and it is yours as Controller. If you hold sensitive records, we strongly recommend agreeing a written retention routine and diarising it. We are happy to help you set one up.
You can export your data yourself, at any time, in a commonly used format.
13.2 On Termination
When our services end, we will retain Client Personal Data for 30 days so that you can export it. After that period we will delete it, or return it to you if you ask before the period expires.
Where you transfer your account to another provider rather than closing it, your data moves with the account and this deletion obligation does not apply.
We may retain Client Personal Data beyond that period only where required by law, and only for as long as the law requires.
14. Special Category and Criminal Offence Data
Some clients use the Platform to hold health data, or other special category data as defined in Article 9 of the UK GDPR. That is permitted, and the Platform is capable of it, but it carries extra duties that sit with you:
- Identifying an Article 9 condition for the processing, in addition to your lawful basis
- Where you rely on explicit consent, capturing it explicitly and keeping a record of it
- Completing a data protection impact assessment where the processing is likely to result in a high risk
- Applying a shorter and clearly documented retention period
- Meeting any additional requirements imposed by your professional or regulatory body
Tell us before you begin processing special category data through the Platform, so that we can configure your forms, consent capture and access controls appropriately.
15. General
15.1 Changes to This DPA
We may update this DPA to reflect changes in law, in the Platform, or in our supply chain. Where a change materially reduces your protection, we will give you at least 30 days' notice by email before it takes effect.
15.2 Liability
The limitations and exclusions of liability in the Terms and Conditions apply to this DPA, except that nothing in either document limits liability that cannot be limited under Applicable Data Protection Law.
15.3 Governing Law
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
15.4 Severability
If any provision of this DPA is found to be unenforceable, the rest remains in force.
Annex A: Details of Processing
- Subject matter
- Provision of the NotLuck CRM platform and associated services
- Duration
- For as long as your account is active, plus 30 days
- Nature and purpose
- Storing, organising, retrieving, transmitting and deleting contact records; sending communications you instruct; scheduling appointments; taking payments; running automations you configure
- Types of personal data
- Names, contact details, addresses, correspondence and message history, appointment records, payment records, form responses, marketing preferences, and any other data you choose to store
- Special category data
- Only where you choose to process it, and subject to section 14
- Categories of data subject
- Your customers, prospects, enquirers, staff and any other individuals whose data you store
Annex B: Technical and Organisational Measures
Encryption
- TLS 1.2 or above for all data in transit
- AES-256 encryption for data at rest
Access Control
- Role-based permissions within your account, controlled by you
- Access by NotLuck staff limited to those who need it to deliver or support your service
- Multi-factor authentication available on all accounts, and required on NotLuck administrative accounts
- Access removed promptly when a staff member's engagement ends
Platform Assurance
- ISO/IEC 27001:2022 certification held by the platform provider
- Annual SOC 2 Type II assessment
- Web application firewall and distributed denial of service mitigation
- Infrastructure hosted with Google Cloud Platform and Amazon Web Services, relying on their audited physical and environmental controls
Resilience and Recovery
- Regular backups maintained by the platform provider
- Data exportable by you at any time, which is the recommended way to hold your own copy
Organisational
- Confidentiality obligations on all staff and contractors
- Sub-processors subject to written data protection terms no less protective than this DPA
- Breach response process with the 72-hour notification commitment in section 10
Contact
For anything to do with this DPA, data protection, a data subject request or a suspected breach:
You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.