Privacy and Data Protection Policy

 

1. Introduction

This Privacy Policy explains how Gym&Go collects, uses, stores, and protects users’ personal data in accordance with Regulation (EU) 2016/679 (GDPR), Law 190/2018, and related legislation.

By using our platform and services, you express your agreement to the processing of your personal data in accordance with this policy.


2. Data Collected

Gym&Go collects the following categories of personal data:

  • Full name,

  • Email address,

  • Phone number,

  • Authentication data (e.g., unique PIN codes, ID copies),

  • Reservation details and attendance history,

  • Feedback and data resulting from service use,

  • Video images from monitored areas (entrance lobby).


3. Purpose of Data Processing

Personal data is processed for the following purposes:

  • Managing reservations and access,

  • Confirming and notifying session details,

  • Organizing and conducting training sessions,

  • Improving services and analyzing feedback,

  • Fulfilling legal obligations,

  • Securing locations and preventing fraud.


4. Data Disclosure

Personal data will not be sold or rented to third parties. Data may be disclosed only to:

  • Contractual partners strictly necessary for providing services (e.g., IT platforms, email services),

  • Public authorities, when required by law.

All partners are bound by contractual confidentiality and security obligations.


5. Data Security

Gym&Go implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or unauthorized alteration. Access to data is restricted to authorized personnel only.


6. User Rights

Under the GDPR, you have the following rights:

  • Right of access,

  • Right to rectification,

  • Right to erasure (“right to be forgotten”),

  • Right to restriction of processing,

  • Right to data portability,

  • Right to object,

  • Right to file a complaint with the Romanian Data Protection Authority (ANSPDCP) at www.dataprotection.ro.

To exercise these rights, you can contact us at: gdpr@gymandgo.ro.


7. Data Retention Period

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by legal obligations. After this period, the data will be anonymized or permanently deleted.


8. Policy Updates

This Privacy Policy may be updated periodically. Any changes will be published on the website, with appropriate notification to users.