Legal
Privacy Policy
What personal data REPZ handles, why we handle it, who we share it with, and what you can ask us to do about it. Written to be read, not to be got past.
Effective 13 August 2026Governed by the laws of India
1.Who we are, and what this covers
REPZ is gym management software operated by thegr8labs, registered at Kollam, Kerala, India ("we", "us", "our"). This policy explains what personal data we handle, why, and what you can do about it.
It covers our website, the REPZ owner and staff applications, the REPZ member application, and the biometric access-control integration that connects a gym's door terminal to REPZ.
It is published in accordance with Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 made under the Information Technology Act, 2000, and is written to align with the Digital Personal Data Protection Act, 2023 (DPDP Act).
2.The gym owns its members' data; we process it for them
This distinction decides most of your rights, so it comes first.
- Where you are a gym owner or staff member, we are the Data Fiduciary for the account data you give us directly: your name, contact details, gym details, billing records and login credentials.
- Where you are a gym member, the gym you belong to is the Data Fiduciary. It decides what to collect about you and why. We act as a Data Processor on that gym's instructions, and we do not decide the purposes for which your data is used.
In practice this means that if you are a gym member and want your data corrected or erased, the fastest route is to ask your gym. If you ask us directly we will pass the request to your gym and support them in acting on it, but we cannot delete a gym's records on a member's instruction alone.
We never sell personal data, and we never use a gym's member data to market anything to those members ourselves.
3.What we collect
From gym owners and staff, directly: name, gym or business name, place and address, phone number, email address, tax registration details where you enter them, your UPI ID for collecting payments, login credentials, per-staff permission settings, and records of your REPZ subscription and payments.
From gyms, about their members: name, phone number, email address where given, date of birth, gender, member photograph, emergency contact details, membership plan and expiry, payment and invoice history, purchases made at the gym counter, attendance records with check-in and check-out times, height, weight and BMI readings, diet plans written by trainers, and assigned trainer.
From the biometric door terminal: the member's device code, which credentials have been enrolled (fingerprint, face, palm or card) as a status only, punch events with their timestamps, the terminal each punch came from, and access decisions including whether entry was refused and why.
Automatically, from the website: IP address, browser and device type, pages visited, referring page, and approximate location inferred from IP. This comes from Google Analytics and is described in section 8.
When you contact us: whatever you put in the contact form, meaning name, gym name, phone, email and your message, plus the page you submitted it from.
4.Biometric data, specifically
Fingerprint, facial and palm data is sensitive personal data under Rule 3 of the SPDI Rules, and we treat it accordingly. Two things are worth stating plainly.
- The biometric template stays on the terminal. When a member enrols a fingerprint, face or palm, the template is created and held by the door device itself. REPZ stores that a credential is enrolled, not the biometric measurement behind it.
- A photograph is not a face template. Pushing a member's photo to a terminal puts a picture on that terminal's screen so staff can see who punched. It does not enable facial recognition. REPZ shows these as separate statuses and never conflates them.
What REPZ does store is the member's device code, per-credential enrolment status, punch events and access decisions. Where a member is refused entry, we store the reason so the gym can explain it.
A member's code on a device is never reused, so no member can inherit another's attendance history. Removing a member from the device deletes their record and any templates the terminal holds for them.
The gym is responsible for obtaining each member's consent before enrolling their biometrics, and for offering an alternative way in, such as a QR check-in or staff marking, to any member who does not consent. We provide both alternatives in the product for exactly this reason.
5.Why we collect it, and our lawful basis
- To provide the service you or your gym signed up for: memberships, attendance, payments, invoices, the shop, staff earnings and access control.
- To operate the door: to decide whether a punch should open it, and to record the visit either way.
- To send transactional messages you have asked for: renewal reminders, payment confirmations, attendance alerts and invoices, over WhatsApp, email or in-app notification.
- To bill you for your REPZ subscription and issue invoices for it.
- To provide support, investigate faults, and answer a dispute about whether a push, enrolment or block actually happened.
- To keep the service secure, prevent misuse, and meet our legal and tax obligations.
- To understand which pages of this website are useful, in aggregate.
Our lawful basis is consent given at the point of collection, and the legitimate uses permitted under Section 7 of the DPDP Act where we must retain records to comply with Indian law. We do not use personal data for any purpose incompatible with the one it was collected for.
6.Consent, and withdrawing it
Providing personal data is voluntary. You may decline, and you may withdraw consent at any time by writing to us at the address in section 13. But where the data is necessary to run the service, withdrawing consent means we can no longer provide it, and we may have to close the account.
Withdrawal is not retrospective: processing already carried out lawfully stays lawful, and records we are required to keep for tax or accounting purposes are retained as described in section 10.
9.How we protect it
We maintain reasonable security practices and procedures as required by Rule 8 of the SPDI Rules, proportionate to the sensitivity of the data. These include:
- Encryption of data in transit, including all traffic between a door terminal and REPZ, which is both authenticated and encrypted end to end.
- Role-based access control, plus per-staff permission switches so a gym can withhold data such as contact details at the server rather than merely hiding it in the app.
- Passwords stored only as salted hashes, and temporary-password onboarding that forces a change on first login.
- Audit logging of every push, enrolment, block and access decision, recording what the terminal replied, so that "we asked" and "it happened" remain separate answerable facts.
- Reversible deletion, so an accidental deletion is recoverable rather than final.
- Restricting staff access on our side to those who need it for support, under confidentiality obligations.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required by the DPDP Act, without undue delay.
10.How long we keep it
We keep personal data only as long as the purpose requires it, then delete or anonymise it.
- Active account data is kept while the account is open.
- After an account is closed, we retain the data for a short wind-down period so it can be exported or an accidental closure reversed, then delete it.
- Deleted members can be restored from within the product. Deleting a member never deletes the payments they made, because those are the gym's financial records.
- Financial records, meaning invoices, payments and tax records, are retained for the period Indian tax and company law requires, currently eight years, even where the related account has closed.
- Biometric enrolment status and punch records are deleted when the member is removed from the device, subject to the attendance history the gym chooses to keep.
- Contact-form enquiries are kept for as long as we are in conversation with you, and for a reasonable period afterwards.
11.Your rights
Under the DPDP Act and the SPDI Rules you may:
- Ask what we hold about you and how it is being used.
- Correct or complete anything inaccurate or out of date.
- Ask for erasure of data no longer needed for the purpose it was collected for, subject to the retention periods in section 10.
- Withdraw consent, as described in section 6.
- Nominate another person to exercise these rights on your behalf if you are unable to.
- Complain to us, and if we do not resolve it, to the Data Protection Board of India.
To exercise any of these, write to info@thegr8labs.com. We will verify who you are before acting, and respond within 7 working days. If you are a gym member, see section 2, and please ask your gym first, as they hold the decision.
12.Members under 18
Gyms do enrol minors, and the DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed.
Where a gym enrols a member under 18, the gym is responsible for obtaining that consent, including for any biometric enrolment, and for recording it. We do not knowingly collect data directly from anyone under 18 through this website.
We do not carry out tracking, behavioural monitoring or targeted advertising directed at children, on anyone, at any age.
13.Where the data lives
We host data in India wherever possible. Some of our processors, email delivery and analytics in particular, operate servers outside India, so limited data may be transferred abroad.
Where that happens, the transfer is made under contractual protections, only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and only for the purposes described in this policy.
14.Grievance officer
In accordance with Rule 5(9) of the SPDI Rules and the grievance-redressal duties under the DPDP Act, the following officer will address any complaint about how your personal data has been handled:
- The Grievance Officer, thegr8labs
- Email: info@thegr8labs.com
- Phone: +91 70340 83071
- Address: Kollam, Kerala, India
Please write "Privacy grievance" in the subject line. We acknowledge every complaint and aim to resolve it within 7 working days, and in any case within the one month the SPDI Rules allow. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.
15.Changes to this policy
We may update this policy as the product or the law changes. The effective date at the top always reflects the current version.
Where a change materially affects how we handle your data, we will tell account holders by email or in-app notice before it takes effect. Continuing to use REPZ after that means you accept the updated policy.
Grievance officer
Any complaint about how your personal data has been handled goes to info@thegr8labs.com or +91 70340 83071. We acknowledge every complaint and aim to resolve it within 7 working days.
These pages describe how REPZ actually works. They are not legal advice, and if a clause here conflicts with a signed agreement between us, the signed agreement wins. Questions about any of it: get in touch.