Skip to content
Forenota

Privacy Policy

Last updated: 6 October 2026 · Version 1.0

1. Who we are

Forenota ("Forenota", "we", "us") is a South African business operated by its founders. Forenota is software that helps businesses track tasks, deadlines and follow-ups, and sends reminders to their team through WhatsApp, Telegram and email.

This policy explains how we process personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). Questions go to our Information Officer, Bryce Hornby, at support@forenota.com.

2. Our two roles

We handle personal information in two different capacities, and your rights depend on which applies.

We are the responsible party for information about our own customers and website visitors: the people who sign up, manage a Forenota account or pay for it. We decide why and how that information is processed.

We are an operator for the content our customers put into Forenota: their team members' details, messages, documents, tasks, schedules and anything else they upload or send. The customer business is the responsible party for that information and decides what goes in. We process it only on the customer's instructions, to provide the service, under the data processing terms in our Terms of Service (section 12).

If you are a team member of a business that uses Forenota, your employer controls your information in Forenota. Please contact them first; we will help them respond to you.

3. What we collect

CategoryExamplesSource
Account detailsName, email, phone number, business name, role, password (stored hashed)You, at sign-up
Billing detailsPlan, invoices, payment status. Card details are handled by Paystack; we never see or store full card numbersYou and Paystack
Team member details (operator)Name, role, area, WhatsApp number or Telegram ID, schedule, leave, certificationsThe customer business
Business content (operator)Chat messages and voice notes sent to Forenota, forwarded messages, uploaded files and emails, tasks, reminders, expenses, schedulesThe customer business and its team
Usage and technical dataLog-in times, features used, device and browser type, IP address, error logsAutomatically, when you use the service
Website and waitlist dataName, business, team size, country, contact preferenceYou, via forms on forenota.com
Support messagesAnything you send us when asking for helpYou

We do not intentionally collect special personal information (such as health, religion or biometric data) or information about children. Customers should not upload it unless it is necessary and they have a lawful basis to do so (see section 10).

4. Why we use it

PurposePOPIA justification
Create and run your account, deliver reminders, summaries and the features you useNecessary to perform our contract with you
Process content on behalf of customer businessesThe customer's instructions as responsible party; our operator agreement
Billing, invoicing, tax recordsContract, and legal obligations (including the Tax Administration Act)
Security, fraud prevention, abuse detection, keeping logsOur legitimate interest in protecting the service and our customers
Improving the product, using aggregated or de-identified usage statisticsLegitimate interest
Service messages (outages, changes to terms, billing notices)Contract and legal obligations
Marketing emails about ForenotaYour consent, or as an existing customer with an opt-out in every message (POPIA section 69)

We do not sell personal information. We do not use customer business content to train AI models.

5. How the AI works with your information

Forenota uses AI models to read messages, voice notes and documents, work out tasks and deadlines, and write reminders and summaries. When it does this:

  • Only the information needed for that request is sent to the AI provider, through their business API.
  • We use providers and settings under which your content is not used to train their models, and is kept only for as long as needed to provide the response and meet their abuse-monitoring obligations.
  • AI output can be wrong. Forenota shows where each reminder came from, and important new items are confirmed by a person before they become active.
  • Forenota does not make decisions about people that have legal or similarly significant effects (such as hiring, firing or pay) based solely on automated processing. People make those decisions.

6. Who we share it with

We share personal information only with service providers who help us run Forenota, under written agreements that require them to keep it confidential and secure (POPIA sections 20 and 21), and where the law requires it.

ProviderWhat they doWhere data may be processed
Lovable / Supabase (Lovable Cloud)Hosting, database, file storage, authenticationUnited States and European Union
Google (Gemini) and OpenAI, via the Lovable AI gatewayAI processing of messages, voice notes and documentsUnited States and other regions
Meta (WhatsApp Business Platform)Delivering WhatsApp messagesGlobal
TelegramDelivering Telegram messagesGlobal
PostmarkReceiving forwarded emails and sending service emailsUnited States
PaystackPayment processingSouth Africa and Nigeria
Google, Xero, SageOnly if you choose to connect these integrationsAs per the provider

When your team uses WhatsApp or Telegram, those platforms also process the messages under their own privacy policies.

We may disclose information if required by law, a court order or a regulator, to protect our rights or the safety of others, or to a buyer if Forenota is sold or merged, who must then honour this policy.

7. Transfers outside South Africa

Some of our providers store or process information outside South Africa. We only transfer personal information where POPIA section 72 allows it: the recipient is bound by law, binding corporate rules or a written agreement giving protection substantially similar to POPIA, or the transfer is necessary to perform our contract with you. Using Forenota means your information may be processed in the countries listed above.

8. Security

We protect personal information with measures appropriate to the risk (POPIA section 19), including:

  • Encryption in transit (TLS) and at rest
  • Each customer business's data separated at database level, so one business can never access another's
  • Private file storage with access limited to authorised roles within each business
  • Access controls and logging for our own staff, who access customer content only to provide support you request, to fix problems, or where the law requires
  • Treating uploaded content strictly as data, with protections against attempts to manipulate the AI through content
  • Regular review of our security measures and our providers' measures

No system is perfectly secure, but we work to keep risk low and will tell you promptly if something goes wrong (section 11).

9. How long we keep it

InformationKept for
Account and business contentWhile your subscription is active. After cancellation, 90 days so you can export or return, then deleted
Voice note audio30 days by default, then deleted (the text transcript stays with your content)
Uploaded filesUntil you or your business deletes them, or the account is deleted
Billing records and invoices5 years after the transaction, as tax law requires
Security and system logsUp to 12 months
Waitlist and marketing contactsUntil you unsubscribe or ask us to delete them
BackupsOverwritten on a rolling cycle of up to 30 days after deletion

We may keep information longer where the law requires it or to resolve a dispute, and then only for that purpose.

10. Businesses using Forenota with their team

If you add team members to Forenota, you are the responsible party for their information. You agree to:

  • Tell your team members that you use Forenota, what it does, and that their messages to it are processed by AI (a short template is available on request)
  • Have a lawful basis for the information you add, including any special personal information (for example, health information in a sick-leave note)
  • Only add information that is relevant to running your business
  • Pass on any requests from team members about their information that you need our help with

Team members can stop using Forenota at any time by telling their employer, and can ask us to stop messaging them by replying STOP or contacting support@forenota.com.

11. If there is a data breach

If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected customers as soon as reasonably possible, as required by POPIA section 22, with what happened, what information was involved, what we are doing, and what you can do to protect yourself. Where we act as operator, we will tell the customer business immediately so it can meet its own obligations.

12. Your rights

Under POPIA you have the right to:

  • Ask whether we hold personal information about you, and for a copy of it
  • Ask us to correct or delete information that is inaccurate, out of date, excessive or unlawfully obtained
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent where we rely on it, without affecting earlier processing
  • Not be subject to decisions based solely on automated processing that significantly affect you
  • Complain to the Information Regulator

To use these rights, email support@forenota.com. We will confirm your identity and respond within 30 days. Requests for access are free unless they are clearly excessive. Requests about information a business put into Forenota (section 2) will be passed to that business, and we will help them respond.

13. Marketing and cookies

We send marketing emails only with your consent or, if you are a customer, about similar Forenota services, with an unsubscribe link in every message. We never send marketing through the reminder channels your team uses.

Our website uses essential cookies to keep you signed in and secure, and privacy-friendly analytics to understand how the site is used. We do not use advertising cookies or sell browsing data. You can block cookies in your browser, but signing in may then not work.

14. Children

Forenota is a business service for people aged 18 and over. We do not knowingly collect information about children. If you believe a child's information has been added, contact us and we will delete it.

15. Changes to this policy

We will update this policy when our practices or the law change. For material changes we will notify account owners by email or in the app at least 14 days before they take effect. The "last updated" date at the top shows the current version.

16. Contact and complaints

If you are unhappy with how we handled your information, please contact us first so we can fix it. You can also complain to the Information Regulator (South Africa) at https://inforegulator.org.za, using the complaint form on their website.