Privacy Policy

Last updated on 29 June 2026

Contents

  1. Who we are
  2. Our Privacy Promise
  3. What Information we collect
  4. How we use the information we collect
  5. Lawful basis we use to process your information
  6. Consent
  7. Disclosure of your information
  8. Where we store your personal data
  9. Retention period
  10. Your rights as a data subject
  11. Complaints and Contact

1. Who we are

Notchup, operated by Future of Work Limited, is a global digital platform that lets companies hire digital talent and lets talent provide digital software products and services. To provide the full range of Notchup products and services, we need to collect and process information about you. This Privacy Policy and our Cookies Policy apply to all visitors to and users of our website, online services and customers (both individuals and companies).

For the purposes of this Policy, the data controller is Future of Work Limited (registered in England and Wales under company number 12752302), whose registered office is at The Retreat, 406 Roding Lane South, Woodford Green, Essex, United Kingdom, IG8 8EY. References to "Notchup" also apply to its channels, including the Talent Dashboard, Company Dashboard and Admin Portal.

This policy applies to our website at www.notchup.com, any Notchup website that links to this Privacy Policy or our Cookies Policy, our apps, and information you provide by phone, SMS, email, in correspondence or in person.

2. Our Privacy Promise

We are committed to protecting your personal information, being transparent about the data we hold, and wherever possible giving you control over how it is used. Please read this policy to understand what information we may hold about you, how we use it, and how you can access, update or delete it.

We do not sell your personal data. We use your information only for the purposes described in this policy, and we apply heightened safeguards to sensitive information such as your identity-verification documents and financial details.

We process personal data in line with applicable laws, including the UK GDPR, the EU GDPR, the UK Data Protection Act 2018, the Privacy and Electronic Communications Regulations, the California Consumer Privacy Act (as amended) and other U.S. state privacy laws. We may update this policy from time to time; revisions will be posted on this page with a new "Last updated" date.

3. What Information we collect

We collect the following categories of personal data:

4. How we use the information we collect

We use the information we collect to:

5. Lawful basis we use to process your information

If you are in the United Kingdom or European Economic Area, we rely on the following legal bases under the UK GDPR and EU GDPR, and may rely on more than one depending on the specific purpose:

6. Consent

Where consent is required for us to process certain personal data, it must be clearly given. You may give consent to receive our marketing communications, or when you ask us to share your details with a client or other third party in connection with the services.

Where you have given consent, you may withdraw it at any time by emailing dataprotection@notchup.com. We will stop the processing based on that consent, although this does not affect any processing carried out before withdrawal. If your details have already been shared with a client or third party at your request, you may need to contact them directly to withdraw your consent to their use of your data.

7. Disclosure of your information

We do not sell your personal data. We disclose it only as described here:

8. Where we store your personal data

We use appropriate technical, organizational and administrative safeguards designed to protect your personal data, including encryption of data in transit and at rest, access controls, secure servers and strict procedures to prevent unauthorized access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please help protect your account by using a strong password and keeping your credentials confidential.

Protection of sensitive data. Some of the data we process is especially sensitive — in particular your identity-verification documents (such as passport, driver's license or national ID) and your financial and bank account details. We apply heightened safeguards to this data, including: encryption in transit and at rest; strict role-based, least-privilege access limited to personnel who genuinely need it; restricted and isolated storage; use of this data only for identity verification, KYC/AML and payment purposes; contractual confidentiality and security restrictions on the verification and payment providers who process it on our behalf; monitoring, logging and access reviews; and defined retention limits after which the data is securely deleted. We never use sensitive data for unrelated purposes.

International transfers. All information you provide is stored securely, and where possible within the UK or EU. Where we transfer personal data outside the UK or EEA, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement/Addendum and the European Commission's Standard Contractual Clauses, or rely on another lawful transfer mechanism. Some third parties to whom we disclose data may process it outside the UK/EEA under their own privacy policies.

Cookies. We use cookies and similar technologies to operate and secure our sites, remember your preferences, understand usage and improve performance and marketing; please see our Cookies Policy. You can control cookies through your browser settings.

Children. Notchup is not directed to children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us at dataprotection@notchup.com and we will delete it.

9. Retention period

We retain personal data for as long as necessary to fulfil the purposes we collected it for, including to provide the services and to satisfy our legal, accounting, AML and reporting requirements, and for as long as necessary for the prevention and detection of fraud or criminal activity. Where you hold an account, we retain your data for as long as your account is active and for a period afterwards to meet those obligations.

In some circumstances you can ask us to delete your data (see "Your rights as a data subject" below). We may also anonymize your data so it can no longer be associated with you, in which case we may use it indefinitely without further notice.

10. Your rights as a data subject

UK and EEA residents. While we hold or process your personal data, you have the right to access a copy of your data, to rectify inaccurate or incomplete data, to request erasure, to restrict processing, to data portability, to object to certain processing (such as direct marketing), and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

U.S. state privacy rights. Depending on your state of residence (including under the California Consumer Privacy Act as amended by the CPRA, and the privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states), you may have the right to:

We do not sell your personal information for money, and we do not use or disclose sensitive personal information for purposes beyond those described in this policy. To exercise any of these rights, email dataprotection@notchup.com. You may use an authorized agent and may appeal a decision by replying to our response. We may need to verify your identity before responding and will respond within the timeframes required by law.

11. Complaints and Contact

If you have any questions, requests or complaints about how your personal data is processed by Notchup (or by third parties as described above), or about how a complaint has been handled, please contact us in the first instance at dataprotection@notchup.com.

Future of Work Limited (Notchup), The Retreat, 406 Roding Lane South, Woodford Green, Essex, United Kingdom, IG8 8EY.

You also have the right to lodge a complaint directly with the UK supervisory authority, the Information Commissioner's Office, via ico.org.uk. If we update this policy, we will post the revised version on this page with a new "Last updated" date.

12. Third-Party Platform Data & Limited Use

When you connect third-party accounts and platforms to Notchup — for example Google Workspace, OpenAI, Microsoft 365, Zoom, and Meta / WhatsApp Business — we access and process data from those services only to provide and improve the features you enable, and we handle that data in accordance with each provider's developer and data-use requirements, including the commitments below. You can review and revoke any connected integration at any time in your account settings, which stops our further access to that platform's data.

Google Workspace APIs. Notchup's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of data obtained from Google Workspace APIs (such as Gmail, Google Calendar, Google Drive and Contacts), including raw data and data aggregated, anonymized or derived from it, is limited to providing or improving user-facing features that are prominent in the Notchup interface; we do not transfer this data except to provide or improve those features with your consent, for security purposes, to comply with applicable law, or as part of a merger or acquisition with your prior consent; we do not allow humans to read this data except with your affirmative consent, for security, to comply with law, or where it is aggregated or anonymized and used for internal operations; and we never use it for advertising, to train generalized AI or machine-learning models, or to determine credit-worthiness or for lending, nor do we sell it.

OpenAI. We use OpenAI's API to power certain AI features. Content sent to OpenAI to provide those features is processed under OpenAI's API data-usage and enterprise-privacy commitments: it is not used to train or improve OpenAI's models unless you explicitly opt in, remains owned by you, is encrypted in transit and at rest, and is retained by OpenAI only for a limited period (currently up to 30 days) to provide the service and detect abuse before deletion, except where longer retention is required by law.

Microsoft 365 (Microsoft Graph). Our use of data obtained through Microsoft 365 and the Microsoft Graph API (such as Outlook mail and calendar, Teams, and OneDrive files) complies with the Microsoft APIs Terms of Use. We request only the minimum data and permissions needed to provide the features you enable, use that data solely in connection with those features, do not use it for advertising or marketing other than in connection with the application, obtain the consents required, apply reasonable security measures, and honour applicable retention, correction and deletion requirements.

Zoom. Our use of data obtained through the Zoom APIs complies with the Zoom API License and Terms of Use and the Zoom Marketplace Developer Agreement. We access Zoom data only to perform the integration activities and to provide the features you request, in accordance with Zoom's API documentation and use rules, and we describe how we collect, use, share, retain and otherwise process that data as required by Zoom.

Meta / WhatsApp Business. Our use of data obtained through Meta's platforms and the WhatsApp Business Platform (Cloud API) complies with the Meta Platform Terms, the Meta Developer Policies, and the WhatsApp Business Solution Terms. We process this data only for the permitted purposes of providing and improving the messaging features you enable and as permitted by applicable law; we do not use WhatsApp Business data to create, develop, train or improve generalized AI or machine-learning models; and we adhere to applicable retention limits (for example, Cloud API message retention of up to 30 days).