PRIVACY POLICY

Last updated: 26 August 2026

This Privacy Policy explains how Aerobit Technologies, operating the Okfit platform ("Okfit", "we", "us", or "our"), collects, uses, stores, discloses, and protects personal data in connection with the Okfit website, web application, mobile applications, integrations, support services, and related services (together, the "Services").

This policy should be read together with our Terms of Service and any agreement or order form signed with a customer.

1. Applicability

Okfit is a fitness studio and gym management SaaS platform. Our customers are gyms, fitness studios, trainers, and similar businesses ("Customers"). Customers use Okfit to manage their business operations, including memberships, attendance, invoices, payments, communications, bookings, and related records.

This Privacy Policy applies to:

  • Customers and their authorised users, including owners, admins, managers, trainers, and staff.
  • Members, leads, guests, or other individuals whose data is entered into Okfit by a Customer.
  • Visitors to our website and people who contact us for demos, support, or sales enquiries.

2. Our Role Under Data Protection Laws

For account, billing, support, sales, and website data relating to our Customers and website visitors, Okfit acts as a data fiduciary/controller because we decide why and how that data is processed.

For personal data of gym members, leads, guests, and staff that a Customer enters into the Okfit platform, the Customer is generally the primary data fiduciary/controller. Okfit processes that data on behalf of the Customer to provide the Services.

Customers are responsible for providing appropriate notices, collecting required consents, and ensuring they have a lawful basis to enter and process personal data in Okfit.

3. Personal Data We Process

Depending on how the Services are used, we may process the following categories of personal data:

  • Customer business information, such as business name, brand name, address, GST number, billing details, and contact details.
  • Account and user information, such as name, phone number, email address, role, permissions, login credentials, and user activity.
  • Member, lead, or guest information entered by Customers, such as name, phone number, email address, address, age, gender, membership details, attendance records, invoices, payment status, bookings, communication history, and notes entered by the Customer.
  • Payment-related information, such as invoice details, transaction references, payment status, and limited payment metadata. Full card, UPI, net banking, or wallet credentials are processed by third-party payment providers and are not stored by Okfit unless expressly stated.
  • Technical and usage information, such as IP address, browser type, device information, operating system, access logs, pages visited, feature usage, crash/error logs, and approximate location derived from technical data.
  • Support and communication information, such as emails, WhatsApp messages, call notes, support tickets, and feedback.

4. Health and Biometric Information

Okfit does not collect or store biometric identifiers, biometric templates, fingerprint templates, facial templates, or similar biometric information of gym members.

Where a gym uses a biometric attendance device, the biometric data is stored on the local biometric device installed at the gym premises and remains under the control of the gym and/or the device vendor. Okfit may receive attendance events or related metadata from such integrations, such as member ID, attendance timestamp, check-in/check-out status, and device reference, only for providing attendance management features.

Okfit does not require Customers to enter clinical health records. If a Customer chooses to enter fitness progress information, body measurements, assessment notes, or similar non-clinical information into the platform, Okfit processes that information only to provide the Services on the Customer's behalf.

5. How We Use Personal Data

We use personal data for the following purposes:

  • To create, operate, maintain, and secure Customer accounts.
  • To provide gym management features such as member management, attendance, billing, bookings, communications, reporting, and support.
  • To process invoices, subscriptions, payments, and related tax or accounting records.
  • To provide customer support, onboarding, training, and troubleshooting.
  • To improve, test, monitor, and secure the Services.
  • To send service-related notices, product updates, support messages, and administrative communications.
  • To send marketing or promotional communications where permitted by law or consented to by the recipient.
  • To detect, prevent, and investigate fraud, misuse, security incidents, or illegal activity.
  • To comply with legal, regulatory, tax, accounting, and contractual obligations.

We do not sell personal data.

6. Consent and Customer Responsibility

Where personal data belongs to gym members, leads, guests, or staff entered by a Customer, the Customer is responsible for ensuring that the data has been collected lawfully and that required notices and consents have been provided.

Customers must not enter personal data into Okfit unless they have the right to do so. This includes personal data collected through forms, attendance devices, invoices, payment links, WhatsApp/SMS/email communications, or any third-party integration used by the Customer.

7. Sharing and Disclosure

We may share personal data with:

  • Service providers and subprocessors who help us provide hosting, infrastructure, analytics, payment processing, messaging, support, email, SMS, WhatsApp, logging, monitoring, or other operational services.
  • Payment gateways and financial service providers, where payments are processed.
  • The relevant Customer, where the data relates to that Customer's gym, members, staff, leads, or business operations.
  • Professional advisers, auditors, accountants, legal advisers, insurers, or consultants where reasonably required.
  • Government authorities, law enforcement, courts, regulators, or other third parties where disclosure is required by law or necessary to protect legal rights, safety, or security.

We require service providers to process personal data only for authorised purposes and to apply reasonable security safeguards.

8. Hosting and Cross-Border Processing

Okfit may use cloud hosting providers, infrastructure vendors, communication vendors, analytics tools, and other service providers located in India or outside India. Where personal data is processed outside India, we take reasonable steps to ensure that such processing is consistent with applicable law and contractual obligations.

9. Security Safeguards

We use reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These safeguards may include:

  • HTTPS/TLS encryption for data in transit.
  • Role-based access controls.
  • Restricted internal access to customer data.
  • Authentication controls for administrative access.
  • Regular backups.
  • Logging and monitoring of key systems.
  • Secure cloud infrastructure practices.
  • Incident review and response processes.
  • Vendor and access review practices.

No internet-based service can guarantee absolute security. Customers are responsible for using strong passwords, limiting user access, securing their devices, managing staff permissions, and protecting any local hardware or biometric devices installed at their premises.

10. Retention and Deletion

We retain personal data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain backups, and support legitimate business needs.

On termination of a Customer account, Customer data may be retained for up to 12 months, after which it may be deleted or anonymised unless retention is required by law or a separate agreement.

Customers may request export or deletion support by contacting us. Some deleted data may continue to exist in encrypted backups for a limited backup retention period before being overwritten or removed in the normal backup cycle.

11. Cookies and Analytics

Our website and Services may use cookies, local storage, analytics tools, and similar technologies to operate the platform, remember preferences, understand usage, improve performance, and secure the Services.

The web application may also use session replay and error-monitoring tools. These tools may record how authorised users interact with the portal, including pages viewed, clicks, and information visible on screen while using the Services. We use this information to troubleshoot issues, provide support, and improve reliability and security. Password fields are not recorded. Session replay data may be processed by a third-party provider located outside India.

Users may disable cookies through browser settings, but some parts of the Services may not function properly without required cookies.

12. Rights of Individuals

Subject to applicable law and verification, individuals may request access, correction, updating, deletion, withdrawal of consent, or grievance redressal regarding their personal data.

Where the data is controlled by a Customer, such as gym member records entered into Okfit, requests should generally be directed to the relevant gym. We may assist the Customer in responding to such requests where required by law or contract.

Requests can be sent to [email protected].

13. Children's Data

Okfit is not intended for direct use by children without involvement of a gym, parent, guardian, or authorised representative. If a Customer enters data of minors into the platform, the Customer is responsible for ensuring appropriate parental/guardian consent and compliance with applicable law.

14. Data Breach and Incident Handling

If we become aware of a security incident affecting personal data, we will assess the incident and take reasonable steps to contain, investigate, and remediate it. Where required by applicable law or contract, we will notify affected Customers, individuals, and/or authorities.

Customers must promptly notify Okfit if they become aware of any unauthorised access, misuse, compromise, or breach involving their account, users, devices, or data.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will be posted on our website. Continued use of the Services after an update means the updated policy applies from the effective date stated above, unless otherwise required by law.

16. Contact Us

For questions, requests, or grievances related to this Privacy Policy or personal data, please contact:

Aerobit Technologies
Email: [email protected]
Website: https://okfit.in