fitKendra

Privacy Policy

Last updated: 14 July 2026

fitKendra (“we”, “us”) provides gym-management software to fitness businesses in India. This policy explains what personal data we handle, why, and the choices you have. It is written to align with the Digital Personal Data Protection Act, 2023 (DPDP Act).

Two roles, two kinds of data

Gym account data — when a gym owner or staff member creates or uses a fitKendra account, we are the data fiduciary for that data (name, email, phone, login records, billing details for the subscription).

Member data entered by gyms— gyms record their members' details (name, phone, email, membership, attendance, payments) inside fitKendra. For this data the gym is the data fiduciary and fitKendra acts as its processor: we store and process it only to provide the service to that gym, on its instructions.

What we collect

What we do NOT do

Tenant isolation

Every gym's data is isolated at the database layer using PostgreSQL row-level security: queries physically cannot read another gym's rows. Data is encrypted in transit (TLS) and at rest.

Retention

Workspace data is retained while the gym's account is active. After account closure we delete or anonymise personal data within 90 days, except records we must keep under Indian law (e.g. tax invoices).

Your rights

Under the DPDP Act you may request access to, correction of, or erasure of your personal data, and may withdraw consent where processing is based on it. Gym members should contact their gym first (the fiduciary for their data); we support gyms with export and erasure tooling. You can also reach our grievance officer at privacy@fitkendra.com — we respond within the statutory timelines.

Changes

We'll notify account owners by email about material changes to this policy before they take effect.