Skip to content
GymPMS

Privacy Policy

Last updated:

View as Markdown

At GymPMS we take the protection of your personal data seriously. This policy explains what data we process, for what purpose and legal basis, for how long, and what rights you have under Regulation (EU) 2016/679 (GDPR).

1. Data controller

The data controller is Roberto Carlos Solis Garcia, Tax ID 48761636A ("GymPMS").

2. Data we process

  • Identification and contact data (name, email, phone).
  • Account and establishment data (organisation, location, role).
  • Billing and payment data needed to manage your subscription.
  • Service usage and technical data (access logs, IP address, device identifiers).
  • Any data you enter about your own members, for which you act as controller and we act as processor.

3. Purposes and legal bases

  • Service provision and account management: performance of a contract (Art. 6(1)(b) GDPR).
  • Billing and accounting/tax obligations: legal obligation (Art. 6(1)(c) GDPR).
  • Security, fraud prevention and service improvement: legitimate interest (Art. 6(1)(f) GDPR).
  • Analytics cookies and marketing communications: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

4. Processors and recipients

To provide the service we rely on processors under Art. 28 GDPR agreements, including cloud hosting/infrastructure providers, a payment gateway, and AI providers for generating training tables. We do not sell your personal data.

5. International transfers

Where possible, data is hosted within the European Union. Any international transfer relies on an adequacy decision or the European Commission's Standard Contractual Clauses, with additional safeguards where appropriate.

6. Retention

We keep data while the account is active and, after closure, for legally required periods (e.g. tax and accounting obligations). Afterwards it is securely deleted or anonymised.

7. Your rights

You can exercise your rights by writing to [email protected]. You have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Erasure ('right to be forgotten').
  • Restriction of processing.
  • Data portability.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without retroactive effect.

If you believe your request was not handled properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local supervisory authority.

8. Automated decisions and AI

The AI training-table feature generates drafts that gym staff review and approve. We do not make decisions producing legal effects based solely on automated processing.

9. Security

We apply appropriate technical and organisational measures, such as encryption in transit, role-based access control and per-organisation data isolation, to protect data against unauthorised access, loss or alteration.

10. Changes to this policy

We may update this policy to reflect legal or service changes. The current version is published on this page with its update date.

Privacy Policy | GymPMS