FynGym FynGym
Sign in Book a demo
Features Pricing About Contact Download Book a demo
Back to site
Legal

Data processing addendum

The contractual terms under which we process member data on behalf of your gym, as required by the Digital Personal Data Protection Act, 2023. Signed automatically with your subscription.

Last updated 12 September 2026·Effective 12 September 2026·Webspace IN Private Limited
01

Roles of the parties

Your gym is the data fiduciary for the member data in your workspace: you decide what is collected and why. Webspace IN Private Limited is the data processor, acting only on your documented instructions. For your own account data — the owner and staff records — we are the fiduciary, as described in the privacy policy.

This addendum forms part of the terms of service and applies for as long as we process data for you.

02

Subject matter and duration

ItemDetail
Subject matterProvision of the FynGym gym management platform
DurationThe subscription term, plus the 60-day export window
Nature of processingStorage, retrieval, computation, transmission, backup, deletion
PurposeMembership administration, check-in, billing, messaging, reporting
Data subjectsGym members, prospects, staff and trainers
Data typesIdentity, contact, membership, attendance, payment, biometric templates
03

Our obligations

  • Process member data only to provide the service, or as you instruct in writing.
  • Never use it for our own purposes, for advertising, or to train machine-learning models.
  • Keep it confidential, and bind every employee with the same duty.
  • Limit access to staff who need it, with two-factor authentication and quarterly review.
  • Tell you promptly if an instruction appears to breach Indian law.
  • Give you the tools to answer member requests yourself, and help if you cannot.
04

Security measures

ControlImplementation
Encryption in transitTLS 1.2 or higher, HSTS enforced
Encryption at restAES-256, per-gym keys for biometric templates
Access controlRole-based, least privilege, 2FA mandatory, quarterly audit
SegregationPer-gym logical isolation with query-level tenancy checks
AuditabilityImmutable write log for every change, 13 months
BackupsHourly encrypted snapshots, 35-day retention, quarterly restore tests
Vulnerability managementDependency scanning, annual external penetration test
PersonnelBackground checks, signed confidentiality, annual security training
05

Sub-processors

You authorise the sub-processors below. We stay responsible for their performance and bind each one to terms no weaker than this addendum.

Sub-processorFunctionLocation
Amazon Web ServicesHosting and backupsMumbai & Hyderabad
Razorpay SoftwarePayments and UPI mandatesIndia
Meta PlatformsWhatsApp Business messagingIndia / Ireland
TwilioSMS deliveryIndia / United States
Zoho CorporationSupport desk and emailIndia
Google CloudCrash and error reportingIndia / United States

We give 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds and we cannot offer an alternative, you may terminate the affected service without penalty and take a pro-rata refund.

06

Location and transfers

Member data is stored in India. Limited operational data may be processed outside India by the sub-processors marked above, under contractual safeguards. On the Multi-site and Enterprise plans you may require India-only processing, which disables those tools.

07

Data subject requests

The console lets you find, correct, export and delete any member record yourself, which is usually the fastest route. If a member approaches us directly we will not act on their record — we will refer them to you and tell you within two working days, unless the law requires otherwise.

08

Breach notification

If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and in any case within 48 hours, with the nature of the breach, the categories and approximate number of records involved, the likely consequences and the steps taken. We will help you meet your own notification duty to the Data Protection Board of India and to affected members.

09

Audits and evidence

Once a year, on 30 days’ notice, you may request our current security documentation, penetration-test summary and a completed security questionnaire. Enterprise customers may arrange an on-site or remote audit, at their cost, subject to confidentiality and no disruption to other gyms.

10

Return and deletion

During the term you can export everything at any time. On termination: biometric templates are deleted immediately, the workspace stays exportable for 60 days, then all copies including backups are deleted within a further 35 days. We will confirm deletion in writing on request, except for records we must retain by law, which are held in a restricted archive for 8 years.

Questions about this document?

Write to privacy@fyngym.com or post to the Grievance Officer, Webspace IN Private Limited, 4th floor, Pride Icon, Kharadi, Pune, Maharashtra 411014. We answer legal and data requests within seven working days.