1. Data Fiduciary & Contact Details
FitOS is operated by [LEGAL ENTITY NAME], acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023.
Our Registered Office is located at: [REGISTERED ADDRESS]. For privacy inquiries, reach our Data Protection Officer at: [PRIVACY EMAIL].
2. Scope & Applicability of this Policy
This Privacy Policy applies to all personal data collected through the FitOS web portal, mobile applications, API services, reception check-in terminals, and customer support channels.
3. DPDP Act 2023 Key Definitions
"Data Fiduciary": Any entity that determines the purpose and means of processing personal data.
"Data Principal": The individual to whom the personal data relates (Gym Owners, Trainers, Staff, and Members).
"Personal Data": Any data about an individual who is identifiable by or in relation to such data.
"Consent Manager": An interoperable entity registered under DPDP Act provisions to manage consent workflows.
4. Roles: Gym as Fiduciary vs. FitOS as Processor
For gym-specific member contracts and local physical rules, the Gym Owner acts as the primary Data Fiduciary, and FitOS acts as the Data Processor.
For platform authentication, core user accounts, security logs, and multi-tenant infrastructure, FitOS acts as an independent Data Fiduciary.
5. Categories of Personal Data Processed
We process: (a) Identity and Contact data, (b) Membership records, (c) Attendance records, (d) Athletic workout logs, (e) Nutritional logs, (f) Biometric templates (where gym-enabled), (g) Billing records, and (h) Device telemetry.
6. Mobile Number & Phone Authentication
Your mobile number is our primary cryptographic identity identifier. We use SMS/WhatsApp OTP verification to prevent unauthorized account hijacking.
7. Profile & Demographic Information
You may optionally upload a profile photograph, specify gender, and list your emergency contact details for gym safety purposes.
8. Attendance Logs & Check-In Verification
Timestamped access logs are generated when you scan QR terminals or verify entry at a participating fitness facility.
9. Workout & Exercise Performance Logs
We store workout routines, exercises, sets, repetitions, weights, and rest intervals you record within the mobile app.
10. Diet & Macronutrient Records
Nutritional logs, meal timestamps, and macro totals submitted by users are processed to track dietary goals.
11. Biometric Template Processing
Where enabled by a gym facility, biometric hardware converts physical traits into irreversible mathematical hashes. Raw images are never uploaded or retained in cloud storage.
12. Financial & Payment Transaction Logs
We store payment receipt IDs, GST invoices, and settlement status. All sensitive payment instruments are tokenized via PCI-DSS certified payment gateways.
13. Device Telemetry & Technical Logs
We collect IP addresses, device hardware identifiers, OS build versions, and crash analytics to maintain system integrity.
15. Specific Purposes of Processing
Data is processed to: (a) authenticate users, (b) record gym attendance, (c) compute training progression, (d) process subscriptions, and (e) safeguard platform security.
16. Lawful Grounds under the DPDP Act 2023
We process personal data based on: (a) Explicit Data Principal Consent, (b) Contractual Necessity to deliver requested software services, and (c) Compliance with statutory Indian laws.
17. Unbundled & Freely Given Consent
FitOS presents separate, itemized consent checkboxes for Terms of Service, Privacy Policy, AI Personalization, and Marketing Communications. Essential service access is never contingent on consenting to optional marketing.
18. Mechanism for Withdrawing Consent
You may withdraw optional consent at any time via Settings -> Legal & Privacy. Upon withdrawal, processing of optional features ceases immediately without affecting core gym tools.
19. Consent Audit Trail & Verification
All consent transactions are cryptographically logged with user ID, IP address, user agent, document version, and timestamp to prove compliance.
20. AI Analysis & Recovery Calculations
Algorithmic models process historical exercise volume to suggest training recovery metrics. AI processing does not make automated legal decisions affecting your civil rights.
21. Opt-Out of AI Analytics & Model Training
Users can independently disable AI-based routine generation and opt out of contributing anonymized training data in privacy settings.
22. Sub-processors & Infrastructure Partners
We partner with enterprise sub-processors including AWS India (Cloud Hosting), Razorpay (Payments), and Gupshup/Twilio (SMS/WhatsApp). All sub-processors are bound by stringent Data Protection Agreements.
23. Data Sharing with Your Gym Facility
When you register under a gym, authorized staff and trainers of that gym can view your attendance logs, membership status, and assigned workouts.
24. Absolute Prohibition on Data Sale
FitOS never sells, rents, monetizes, or trades your personal data, workout metrics, or phone numbers to third-party brokers or advertisers.
25. Disclosures Required by Law
We may disclose personal data only when required by valid court order, governmental investigative warrant, or statutory legal process in India.
26. Cross-Border Data Transfers
All core user data is hosted within data centers situated in the Republic of India in accordance with DPDP cross-border transfer rules.
27. Technical & Organizational Security
We maintain robust safeguards including TLS 1.3 in-flight encryption, AES-256 database encryption, role-based isolation, firewall defenses, and periodic penetration testing.
28. Internal Employee Access Controls
FitOS employees access production systems strictly under least-privilege protocols, MFA authentication, and immutable access logging.
29. Breach Notification & Incident Response
In the event of a confirmed data breach impacting personal data, FitOS will notify affected Data Principals and the Data Protection Board of India in accordance with prescribed statutory timelines.
30. Data Retention Schedules
Data is retained as long as your account is active. Financial transaction records are retained for 8 years to comply with Indian tax regulations.
31. Data Minimization & Storage Limitation
We collect only the minimum data required to deliver requested fitness features and securely purge obsolete temporary tokens after 90 days.
32. Right to Access & Confirmation
You have the right to obtain a summary of your personal data processed by FitOS, including the categories of data and processing purposes.
33. Right to Correction & Updating
You have the right to correct inaccurate or misleading personal data directly via your profile settings or by contacting our team.
34. Right to Erasure & Account Deletion
You can submit a formal account deletion request via Settings -> Legal & Privacy. Your data will be scheduled for permanent purge following a 30-day safety buffer.
35. Right to Data Portability & Export
You can download a structured machine-readable archive (JSON / CSV) of your workout history and profile metrics from the Settings portal.
36. Right to Nominate
Under the DPDP Act 2023, you have the right to nominate an individual who, in the event of death or incapacity, may exercise your data rights.
37. Right to Grievance Redressal
You have the right to readily available grievance redressal mechanisms through our designated Grievance Officer before escalating to statutory boards.
38. Grievance Officer Designation
Grievance Officer: FitOS Compliance Desk
Email: [GRIEVANCE EMAIL]
Postal Address: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
Acknowledgement turnaround: within 24 hours. Resolution turnaround: within 15 business days.
39. Escalation to Data Protection Board of India
If you are unsatisfied with our grievance resolution, you may lodge a formal complaint with the Data Protection Board of India (DPBI) pursuant to Section 28 of the DPDP Act, 2023.
40. Protection of Children's Personal Data
FitOS does not knowingly process personal data of children under 18 years without verifiable parental consent obtained through the participating gym.
We do not engage in behavioral tracking or targeted advertising directed at children.
41. Persons with Disabilities
For individuals with disabilities, verified lawful guardians may provide consent and exercise data subject rights on their behalf.
42. De-identified & Aggregated Analytics
We may aggregate and anonymize usage patterns (such as peak gym visit hours) to produce industry insights. De-identified data does not constitute personal data.
43. Immutable Audit Logging
Administrative operations (member deletion, role elevation, data export) are immutably logged for security compliance and audit readiness.
44. Third-Party Websites & Services
FitOS may provide links to external partner services. We are not responsible for the privacy practices of third-party external applications.
45. Marketing & Transactional Communications
Critical transactional alerts (OTP codes, billing receipts, security alerts) cannot be disabled. Promotional notifications can be toggled in profile preferences.
46. Business Transfers & Restructuring
In the event of a corporate reorganization, merger, or asset transfer, user data will remain subject to the commitments made in this Privacy Policy.
47. Amendments & Version Tracking
We may periodically update this Privacy Policy. Substantive modifications will be highlighted via in-app notices requiring re-affirmation where required by law.
48. Governing Legal Framework
This Privacy Policy is governed by the Digital Personal Data Protection Act, 2023, Information Technology Act, 2000, and related Indian data rules.
49. Itemized DPDP Data Collection Notice
Please review the Data Collection Table below for an itemized breakdown of categories, purposes, lawful bases, and statutory retention windows.
50. Contacting the FitOS Privacy Desk
For questions, data subject access requests (DSAR), or privacy inquiries:
Privacy Desk: [PRIVACY EMAIL]
Support Desk: [SUPPORT EMAIL]
Entity: [LEGAL ENTITY NAME]
DPDP Act 2023 Itemized Data Collection Notice
| Category | Data Elements | Processing Purpose | Lawful Basis | Retention |
|---|---|---|---|---|
| Identity & Auth Data |
| User account registration, OTP authentication, and multi-tenant authorization. | Contractual Necessity & Express Consent | Active account duration + 30 days post-deletion. |
| Gym Membership Data |
| Managing gym roster access, facility permissions, and subscription lifecycle. | Contractual Necessity | Duration of gym subscription + statutory tax record period. |
| Attendance & Check-in |
| Validating active gym entry, fraud prevention, and branch occupancy analytics. | Legitimate Facility Interest & Contractual Necessity | 12 months rolling history for facility reporting. |
| Workout & Fitness Data |
| Athletic progress tracking, workout history display, and volume computation. | Contractual Necessity (Service Delivery) | Retained until member deletes specific logs or deletes account. |
| Nutritional & Diet Data |
| Nutritional estimation, macro tracking, and meal journaling. | User Consent (Service Delivery) | Retained until member deletes meal entries. |
| Biometric Attendance Data |
| High-speed facility turnstile verification at participating partner gym branches. | Explicit Affirmative Consent (DPDP Act) | Duration of member enrollment at specific facility. |
| Financial & Billing Data |
| Processing subscription fees, issuing tax invoices, and accounting compliance. | Legal Statutory Obligation & Contractual Necessity | 8 years as mandated by Indian GST and Income Tax laws. |
| Device & Telemetry Data |
| Security monitoring, anomaly detection, rate limiting, and app stability debugging. | Legitimate Security Interest | 90 days rolling log retention. |
Document Version History
| Version | Effective Date | Summary of Changes |
|---|---|---|
| v1.0 | September 25, 2026 | Comprehensive DPDP Act 2023 compliance notice, unbundled consent disclosures, and data fiduciary role classifications. |
Legal Entity & Official Contacts
This document is governed by the laws of India. For formal legal notices or dispute filings, please contact the designated legal contact.
