1. Scope & Role
Aymorix Technologies operates GymShakti (app.gymshakti.in). Aymorix acts solely as a Data Processor. The Business Client (gym owner) is the Data Controller and bears full legal responsibility for obtaining End User consent before entering any data into the Platform.
Processor–Controller SplitThe Business Client indemnifies Aymorix against any regulatory action, fine, or third-party claim arising from the Business Client's failure to comply with applicable data protection law, including consent obligations.
2. Data Collected
2.1 Business Client Data
- Business name, GST number, registered address
- Owner name, email, mobile number
- Login credentials (bcrypt-hashed; plaintext never stored)
- Subscription, billing, and payment reference records
2.2 End User Data (Gym Members — entered by Business Client)
| Category | Sensitivity | Data Points |
|---|
| Physical metrics | Sensitive — High | Weight, height, BMI |
| Fitness records | Sensitive — High | Workout logs, trainer notes |
| Attendance | Personal — Medium | Check-in timestamps, QR events |
| Billing | Personal — Medium | Plan, payment method, amounts |
| Contact | Personal — Medium | Name, phone, date of birth |
| WhatsApp delivery | Operational — Low | Delivery status only — no message content stored by Aymorix |
3. Consent — Business Client's Obligation
- Business Client must obtain explicit, documented consent from each End User before entering their data into the Platform
- WhatsApp consent must be specific to automated messaging — not bundled into general membership terms
- Business Client must provide End Users a clear opt-out mechanism for WhatsApp communications
- Aymorix does not audit or verify consent compliance; this is the Business Client's sole responsibility
WhatsApp Consent ChainThe consent chain runs: End User → Business Client → GymShakti Platform → WhatsApp API. Aymorix has no visibility into End User consent. Any regulatory action arising at the End User level is the exclusive liability of the Business Client.
4. How Data Is Used
- Rendering dashboard metrics, attendance records, and billing reports
- Generating PDF receipts and subscription management
- Triggering WhatsApp messages via the Business Client's registered WABA
- Generating anonymized, non-identifiable aggregate usage statistics for internal product development
- Aymorix does not sell, rent, or trade any data to third parties
- Aymorix does not use End User health data to train AI or ML models
5. Third-Party Sub-Processors
| Sub-processor | Role | Data Shared |
|---|
| Razorpay | Payment processing | Transaction reference IDs and amounts only |
| Meta / WhatsApp Business API | Automated messaging via Business Client's WABA | Name, phone, message content (Business Client-controlled) |
| Cloud Hosting Provider | Application and database infrastructure | All Platform data, encrypted at rest |
| Supabase / PostgreSQL | Database layer | All structured member and operational data |
Aymorix is not responsible for the data practices, uptime, or policy changes of any sub-processor. Meta's WhatsApp API restrictions or account actions on the Business Client's WABA are entirely outside Aymorix's control and liability.
6. Data Retention
| Data Type | Retention Period |
|---|
| Member records | Subscription period + 1 year; deleted upon account cancellation + 12 months |
| Health & fitness data | Membership duration + 6 months; deleted upon account termination |
| Attendance logs | 3 years; deleted upon account closure |
| Payment records | 7 years — statutory, non-deletable |
| WhatsApp delivery logs | 90 days (status only) — automatic rolling deletion |
| Audit & access logs | 1 year — rolling purge |
| Backup snapshots | 30 days — automatic overwrite |
- Data export is available for 30 days post-termination in Aymorix's standard format only — no migration assistance or custom format export is obligated
- After 30 days, Aymorix may permanently delete all data without further notice
- Aymorix bears no liability for data loss where the Business Client failed to export within the 30-day window
7. Security
- AES-256 encryption at rest; TLS 1.3 in transit
- Bcrypt-hashed credentials; role-based access controls; row-level data isolation per Business Client
- Daily encrypted backups; internal access logged with timestamp, user ID, and action
- No security measure guarantees absolute protection. Aymorix's liability for security incidents is capped under Section 9
8. Data Breach Protocol
| Timeframe | Action (Aymorix) |
|---|
| 0–6 hours | Containment and root-cause analysis |
| 6–48 hours | Written notification to Business Client's registered email |
| 48–72 hours | Regulatory notification if required under DPDP Act 2023 |
| 72 hours+ | Post-incident report to Business Client |
Aymorix's notification obligation is satisfied upon email to the registered address. Notifying End Users is the Business Client's sole obligation as Data Controller.
9. Limitation of Liability
- Aymorix's total liability under this Policy is capped at twelve (12) months of subscription fees paid by the Business Client
- Aymorix is not liable for indirect, consequential, punitive, or special damages of any kind
- Aymorix bears no liability to End Users — their recourse is against the Business Client
- The Business Client's indemnification and IP breach obligations to Aymorix are uncapped and not subject to this limitation
10. WhatsApp Automation — Liability
Aymorix provides the automation workflow only; the sending WABA belongs to and is operated by the Business Client. Aymorix bears no liability for any restriction, suspension, or permanent ban of the Business Client's WhatsApp Business Account by Meta Platforms Inc., whether or not such action results from use of GymShakti. A WhatsApp ban does not constitute Platform failure, service outage, or grounds for refund or credit. Any legal claim by an End User arising from unsolicited WhatsApp messages is the exclusive liability of the Business Client.
| Level | Description | Outcome |
|---|
| 1 — Warning | Meta policy warning issued to WABA | Business Client rectifies. Aymorix not liable. |
| 2 — Throttling | Messaging temporarily restricted | Business Client's responsibility. Subscription continues. |
| 3 — Suspension | WABA suspended (recoverable) | Business Client appeals Meta directly. No refund. |
| 4 — Permanent Ban | WABA permanently banned | Business Client's sole liability. No refund, no credit. |
| 5 — Legal Action | End User files complaint re: spam messages | Business Client indemnifies Aymorix in full. |
11. Jurisdiction
- This Policy is governed by the laws of the Republic of India
- All disputes arising under this Policy shall be subject to the exclusive jurisdiction of the competent courts of Nagpur, Maharashtra, India
- Business Client irrevocably submits to the personal jurisdiction of Nagpur courts and waives any objection to venue in Nagpur
- Filing proceedings in any court or consumer forum outside Nagpur constitutes a material breach of this Agreement
12. Policy Changes
- Aymorix may modify this Policy at any time with 14 days' written notice for material changes
- Continued use after the notice period constitutes acceptance
- The current version at app.gymshakti.in is always the governing version
13. Contact
CompanyAymorix Technologies
Legal Noticessupport@gymshakti.in
Registered OfficeNagpur, Maharashtra, India
Exclusive JurisdictionCourts of Nagpur, Maharashtra, India
Governing LawRepublic of India
AcceptanceBy using GymShakti, the Business Client confirms they have read, understood, and accepted this Privacy Policy in full, including the WhatsApp liability provisions (Section 10) and the exclusive Nagpur jurisdiction clause (Section 11). Continued use of the Platform constitutes ongoing acceptance.
© 2026 Aymorix Technologies. All rights reserved.