FitOS LogoFitOS/Legal & Compliance Center
Back to App
Version 1.0•Effective: September 25, 2026•Jurisdiction: India

Privacy Policy

This Privacy Policy describes how FitOS collects, processes, stores, protects, and discloses personal data in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 and Indian Information Technology laws.

Section 1

1. Data Fiduciary & Contact Details

FitOS is operated by [LEGAL ENTITY NAME], acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023.

Our Registered Office is located at: [REGISTERED ADDRESS]. For privacy inquiries, reach our Data Protection Officer at: [PRIVACY EMAIL].

Section 2

2. Scope & Applicability of this Policy

This Privacy Policy applies to all personal data collected through the FitOS web portal, mobile applications, API services, reception check-in terminals, and customer support channels.

Section 3

3. DPDP Act 2023 Key Definitions

"Data Fiduciary": Any entity that determines the purpose and means of processing personal data.

"Data Principal": The individual to whom the personal data relates (Gym Owners, Trainers, Staff, and Members).

"Personal Data": Any data about an individual who is identifiable by or in relation to such data.

"Consent Manager": An interoperable entity registered under DPDP Act provisions to manage consent workflows.

Section 4

4. Roles: Gym as Fiduciary vs. FitOS as Processor

For gym-specific member contracts and local physical rules, the Gym Owner acts as the primary Data Fiduciary, and FitOS acts as the Data Processor.

For platform authentication, core user accounts, security logs, and multi-tenant infrastructure, FitOS acts as an independent Data Fiduciary.

Section 5

5. Categories of Personal Data Processed

We process: (a) Identity and Contact data, (b) Membership records, (c) Attendance records, (d) Athletic workout logs, (e) Nutritional logs, (f) Biometric templates (where gym-enabled), (g) Billing records, and (h) Device telemetry.

Section 6

6. Mobile Number & Phone Authentication

Your mobile number is our primary cryptographic identity identifier. We use SMS/WhatsApp OTP verification to prevent unauthorized account hijacking.

Section 7

7. Profile & Demographic Information

You may optionally upload a profile photograph, specify gender, and list your emergency contact details for gym safety purposes.

Section 8

8. Attendance Logs & Check-In Verification

Timestamped access logs are generated when you scan QR terminals or verify entry at a participating fitness facility.

Section 9

9. Workout & Exercise Performance Logs

We store workout routines, exercises, sets, repetitions, weights, and rest intervals you record within the mobile app.

Section 10

10. Diet & Macronutrient Records

Nutritional logs, meal timestamps, and macro totals submitted by users are processed to track dietary goals.

Section 11

11. Biometric Template Processing

Where enabled by a gym facility, biometric hardware converts physical traits into irreversible mathematical hashes. Raw images are never uploaded or retained in cloud storage.

Section 12

12. Financial & Payment Transaction Logs

We store payment receipt IDs, GST invoices, and settlement status. All sensitive payment instruments are tokenized via PCI-DSS certified payment gateways.

Section 13

13. Device Telemetry & Technical Logs

We collect IP addresses, device hardware identifiers, OS build versions, and crash analytics to maintain system integrity.

Section 14

14. Cookies & Local Storage Mechanisms

We utilize essential HTTP cookies and local browser storage strictly for session authentication, security tokens, and theme preferences.

Section 15

15. Specific Purposes of Processing

Data is processed to: (a) authenticate users, (b) record gym attendance, (c) compute training progression, (d) process subscriptions, and (e) safeguard platform security.

Section 16

16. Lawful Grounds under the DPDP Act 2023

We process personal data based on: (a) Explicit Data Principal Consent, (b) Contractual Necessity to deliver requested software services, and (c) Compliance with statutory Indian laws.

Section 20

20. AI Analysis & Recovery Calculations

Algorithmic models process historical exercise volume to suggest training recovery metrics. AI processing does not make automated legal decisions affecting your civil rights.

Section 21

21. Opt-Out of AI Analytics & Model Training

Users can independently disable AI-based routine generation and opt out of contributing anonymized training data in privacy settings.

Section 22

22. Sub-processors & Infrastructure Partners

We partner with enterprise sub-processors including AWS India (Cloud Hosting), Razorpay (Payments), and Gupshup/Twilio (SMS/WhatsApp). All sub-processors are bound by stringent Data Protection Agreements.

Section 23

23. Data Sharing with Your Gym Facility

When you register under a gym, authorized staff and trainers of that gym can view your attendance logs, membership status, and assigned workouts.

Section 24

24. Absolute Prohibition on Data Sale

FitOS never sells, rents, monetizes, or trades your personal data, workout metrics, or phone numbers to third-party brokers or advertisers.

Section 25

25. Disclosures Required by Law

We may disclose personal data only when required by valid court order, governmental investigative warrant, or statutory legal process in India.

Section 26

26. Cross-Border Data Transfers

All core user data is hosted within data centers situated in the Republic of India in accordance with DPDP cross-border transfer rules.

Section 27

27. Technical & Organizational Security

We maintain robust safeguards including TLS 1.3 in-flight encryption, AES-256 database encryption, role-based isolation, firewall defenses, and periodic penetration testing.

Section 28

28. Internal Employee Access Controls

FitOS employees access production systems strictly under least-privilege protocols, MFA authentication, and immutable access logging.

Section 29

29. Breach Notification & Incident Response

In the event of a confirmed data breach impacting personal data, FitOS will notify affected Data Principals and the Data Protection Board of India in accordance with prescribed statutory timelines.

Section 30

30. Data Retention Schedules

Data is retained as long as your account is active. Financial transaction records are retained for 8 years to comply with Indian tax regulations.

Section 31

31. Data Minimization & Storage Limitation

We collect only the minimum data required to deliver requested fitness features and securely purge obsolete temporary tokens after 90 days.

Section 32

32. Right to Access & Confirmation

You have the right to obtain a summary of your personal data processed by FitOS, including the categories of data and processing purposes.

Section 33

33. Right to Correction & Updating

You have the right to correct inaccurate or misleading personal data directly via your profile settings or by contacting our team.

Section 34

34. Right to Erasure & Account Deletion

You can submit a formal account deletion request via Settings -> Legal & Privacy. Your data will be scheduled for permanent purge following a 30-day safety buffer.

Section 35

35. Right to Data Portability & Export

You can download a structured machine-readable archive (JSON / CSV) of your workout history and profile metrics from the Settings portal.

Section 36

36. Right to Nominate

Under the DPDP Act 2023, you have the right to nominate an individual who, in the event of death or incapacity, may exercise your data rights.

Section 37

37. Right to Grievance Redressal

You have the right to readily available grievance redressal mechanisms through our designated Grievance Officer before escalating to statutory boards.

Section 38

38. Grievance Officer Designation

Grievance Officer: FitOS Compliance Desk

Email: [GRIEVANCE EMAIL]

Postal Address: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]

Acknowledgement turnaround: within 24 hours. Resolution turnaround: within 15 business days.

Section 39

39. Escalation to Data Protection Board of India

If you are unsatisfied with our grievance resolution, you may lodge a formal complaint with the Data Protection Board of India (DPBI) pursuant to Section 28 of the DPDP Act, 2023.

Section 40

40. Protection of Children's Personal Data

FitOS does not knowingly process personal data of children under 18 years without verifiable parental consent obtained through the participating gym.

We do not engage in behavioral tracking or targeted advertising directed at children.

Section 41

41. Persons with Disabilities

For individuals with disabilities, verified lawful guardians may provide consent and exercise data subject rights on their behalf.

Section 42

42. De-identified & Aggregated Analytics

We may aggregate and anonymize usage patterns (such as peak gym visit hours) to produce industry insights. De-identified data does not constitute personal data.

Section 43

43. Immutable Audit Logging

Administrative operations (member deletion, role elevation, data export) are immutably logged for security compliance and audit readiness.

Section 45

45. Marketing & Transactional Communications

Critical transactional alerts (OTP codes, billing receipts, security alerts) cannot be disabled. Promotional notifications can be toggled in profile preferences.

Section 46

46. Business Transfers & Restructuring

In the event of a corporate reorganization, merger, or asset transfer, user data will remain subject to the commitments made in this Privacy Policy.

Section 47

47. Amendments & Version Tracking

We may periodically update this Privacy Policy. Substantive modifications will be highlighted via in-app notices requiring re-affirmation where required by law.

Section 48

48. Governing Legal Framework

This Privacy Policy is governed by the Digital Personal Data Protection Act, 2023, Information Technology Act, 2000, and related Indian data rules.

Section 49

49. Itemized DPDP Data Collection Notice

Please review the Data Collection Table below for an itemized breakdown of categories, purposes, lawful bases, and statutory retention windows.

Section 50

50. Contacting the FitOS Privacy Desk

For questions, data subject access requests (DSAR), or privacy inquiries:

Privacy Desk: [PRIVACY EMAIL]

Support Desk: [SUPPORT EMAIL]

Entity: [LEGAL ENTITY NAME]

DPDP Act 2023 Itemized Data Collection Notice

CategoryData ElementsProcessing PurposeLawful BasisRetention
Identity & Auth Data
  • Full Name
  • Mobile Number
  • Email Address
  • Profile Avatar
  • Role Identifier
User account registration, OTP authentication, and multi-tenant authorization.Contractual Necessity & Express ConsentActive account duration + 30 days post-deletion.
Gym Membership Data
  • Gym Facility Name
  • Branch Location
  • Assigned Trainer
  • Plan Tier
  • Start & Expiry Dates
Managing gym roster access, facility permissions, and subscription lifecycle.Contractual NecessityDuration of gym subscription + statutory tax record period.
Attendance & Check-in
  • Check-in Timestamp
  • Terminal Identifier
  • Verification Method (QR / PIN / Biometric Template)
Validating active gym entry, fraud prevention, and branch occupancy analytics.Legitimate Facility Interest & Contractual Necessity12 months rolling history for facility reporting.
Workout & Fitness Data
  • Exercise Logs
  • Sets
  • Reps
  • Weights Lifted
  • Rest Durations
  • PR Benchmarks
Athletic progress tracking, workout history display, and volume computation.Contractual Necessity (Service Delivery)Retained until member deletes specific logs or deletes account.
Nutritional & Diet Data
  • Daily Calorie Goals
  • Macro Ratios (Protein, Carbs, Fats)
  • Meal Photos (Food Scanner)
Nutritional estimation, macro tracking, and meal journaling.User Consent (Service Delivery)Retained until member deletes meal entries.
Biometric Attendance Data
  • One-way Mathematical Hash / Encrypted Facial or Fingerprint Template
High-speed facility turnstile verification at participating partner gym branches.Explicit Affirmative Consent (DPDP Act)Duration of member enrollment at specific facility.
Financial & Billing Data
  • Payment Gateway Order IDs
  • Transaction Timestamp
  • GSTIN Details
  • Invoice History
Processing subscription fees, issuing tax invoices, and accounting compliance.Legal Statutory Obligation & Contractual Necessity8 years as mandated by Indian GST and Income Tax laws.
Device & Telemetry Data
  • IP Address
  • Device Model
  • Operating System
  • App Build Version
  • Error Crash Logs
Security monitoring, anomaly detection, rate limiting, and app stability debugging.Legitimate Security Interest90 days rolling log retention.

Document Version History

VersionEffective DateSummary of Changes
v1.0September 25, 2026Comprehensive DPDP Act 2023 compliance notice, unbundled consent disclosures, and data fiduciary role classifications.

Legal Entity & Official Contacts

[LEGAL ENTITY NAME]
Limited Liability Partnership (LLP) (India)
[REGISTERED ADDRESS]
General Support:[SUPPORT EMAIL]
Privacy Officer:[PRIVACY EMAIL]
Grievance Officer:[GRIEVANCE EMAIL]

This document is governed by the laws of India. For formal legal notices or dispute filings, please contact the designated legal contact.