Roles of the parties
Your gym is the data fiduciary for the member data in your workspace: you decide what is collected and why. Webspace IN Private Limited is the data processor, acting only on your documented instructions. For your own account data — the owner and staff records — we are the fiduciary, as described in the privacy policy.
This addendum forms part of the terms of service and applies for as long as we process data for you.
Subject matter and duration
| Item | Detail |
|---|---|
| Subject matter | Provision of the FynGym gym management platform |
| Duration | The subscription term, plus the 60-day export window |
| Nature of processing | Storage, retrieval, computation, transmission, backup, deletion |
| Purpose | Membership administration, check-in, billing, messaging, reporting |
| Data subjects | Gym members, prospects, staff and trainers |
| Data types | Identity, contact, membership, attendance, payment, biometric templates |
Our obligations
- Process member data only to provide the service, or as you instruct in writing.
- Never use it for our own purposes, for advertising, or to train machine-learning models.
- Keep it confidential, and bind every employee with the same duty.
- Limit access to staff who need it, with two-factor authentication and quarterly review.
- Tell you promptly if an instruction appears to breach Indian law.
- Give you the tools to answer member requests yourself, and help if you cannot.
Security measures
| Control | Implementation |
|---|---|
| Encryption in transit | TLS 1.2 or higher, HSTS enforced |
| Encryption at rest | AES-256, per-gym keys for biometric templates |
| Access control | Role-based, least privilege, 2FA mandatory, quarterly audit |
| Segregation | Per-gym logical isolation with query-level tenancy checks |
| Auditability | Immutable write log for every change, 13 months |
| Backups | Hourly encrypted snapshots, 35-day retention, quarterly restore tests |
| Vulnerability management | Dependency scanning, annual external penetration test |
| Personnel | Background checks, signed confidentiality, annual security training |
Sub-processors
You authorise the sub-processors below. We stay responsible for their performance and bind each one to terms no weaker than this addendum.
| Sub-processor | Function | Location |
|---|---|---|
| Amazon Web Services | Hosting and backups | Mumbai & Hyderabad |
| Razorpay Software | Payments and UPI mandates | India |
| Meta Platforms | WhatsApp Business messaging | India / Ireland |
| Twilio | SMS delivery | India / United States |
| Zoho Corporation | Support desk and email | India |
| Google Cloud | Crash and error reporting | India / United States |
We give 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds and we cannot offer an alternative, you may terminate the affected service without penalty and take a pro-rata refund.
Location and transfers
Member data is stored in India. Limited operational data may be processed outside India by the sub-processors marked above, under contractual safeguards. On the Multi-site and Enterprise plans you may require India-only processing, which disables those tools.
Data subject requests
The console lets you find, correct, export and delete any member record yourself, which is usually the fastest route. If a member approaches us directly we will not act on their record — we will refer them to you and tell you within two working days, unless the law requires otherwise.
Breach notification
If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and in any case within 48 hours, with the nature of the breach, the categories and approximate number of records involved, the likely consequences and the steps taken. We will help you meet your own notification duty to the Data Protection Board of India and to affected members.
Audits and evidence
Once a year, on 30 days’ notice, you may request our current security documentation, penetration-test summary and a completed security questionnaire. Enterprise customers may arrange an on-site or remote audit, at their cost, subject to confidentiality and no disruption to other gyms.
Return and deletion
During the term you can export everything at any time. On termination: biometric templates are deleted immediately, the workspace stays exportable for 60 days, then all copies including backups are deleted within a further 35 days. We will confirm deletion in writing on request, except for records we must retain by law, which are held in a restricted archive for 8 years.
Questions about this document?
Write to privacy@fyngym.com or post to the Grievance Officer, Webspace IN Private Limited, 4th floor, Pride Icon, Kharadi, Pune, Maharashtra 411014. We answer legal and data requests within seven working days.