Privacy Policy
Version 1.0 · Effective 18 September 2026
This policy explains how KriyaCore handles personal data. It is written for the people who sign in to KriyaCore: gym owners, gym staff and our own team.
If you are a member of a gym that uses KriyaCore, your gym decides what is recorded about you and is responsible for it. We store and process that data only on the gym’s behalf, under our Data Processing Agreement with them. Please contact your gym about your data. If you contact us instead, we will pass your request to them.
1. What we collect about people who sign in
- Account details: your name, email address, your role, and which gym you belong to.
- Sign-in security: your password, stored only as a one-way hash that cannot be turned back into the password; your two-factor secret and backup codes if you turn two-factor sign-in on; and a count of recent failed sign-in attempts, used to lock an account temporarily after repeated wrong passwords.
- Activity records: a log of important actions, such as creating a gym, resetting a password, accepting these policies or signing in as a gym for support, with who did it and when.
- Technical data: your IP address and browser details, recorded in our hosting provider’s server logs, which are kept for a short period.
2. What we process for gyms
On each gym’s behalf we store what the gym enters: member details (name, phone, email, date of birth, joining date, notes), memberships and payments, attendance, staff records (including salary and emergency contacts), expenses, and consent records for WhatsApp messages and Face ID.
Face ID: the gym’s entry terminal keeps the face data on the device. KriyaCore receives and stores only the terminal’s ID number for a member, the date they gave consent, and the time of each entry. It never receives a photo or face template.
3. Why we use it
- To provide KriyaCore: signing you in, showing your gym’s data, sending the messages you ask it to send.
- To keep it secure: spotting and blocking attacks, locking accounts after repeated failed sign-ins, and keeping an audit trail.
- To support you and your gym, and to bill the gym for its plan.
- To meet our legal obligations.
We do not sell personal data, show advertising, or use analytics or tracking tools.
4. Where it is stored and who else handles it
KriyaCore runs on servers in Singapore. A small number of service providers handle data for us, each only to provide their service. They are listed on our Sub-processors page, which we keep up to date.
We share personal data with anyone else only when the law requires it, for example a valid order from a court or government authority.
5. How we protect it
- All connections are encrypted (HTTPS).
- Passwords are hashed, never stored in readable form. Two-factor sign-in is available for every account.
- Accounts lock for a while after repeated wrong passwords, and sessions end after an hour without activity.
- Each gym can see only its own data.
- Database backups are encrypted before they leave the server.
- Sensitive actions by our own team, such as signing in as a gym for support, are recorded in an audit log.
If a breach affects personal data, we will tell the affected gyms within 72 hours of becoming aware of it, and notify the Data Protection Board of India as the law requires.
6. How long we keep it
- Account and gym data: for as long as the gym uses KriyaCore.
- After a gym cancels: kept for 30 days so the gym can export it, then deleted. Copies in our backups are gone within a further 30 days.
- Server logs: a short period set by our hosting provider.
7. Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask us for a summary of the personal data we hold about you, ask us to correct or erase it, and nominate someone to exercise these rights for you if you die or become unable to. Email info@kriyacore.in. We may need to confirm who you are first.
Gym members: your gym handles these requests for data it holds about you, and KriyaCore gives it the tools to do so.
8. Cookies
We use only the cookies needed to keep you signed in. See the Cookie Policy.
9. Grievance officer
For any complaint about how we handle personal data, contact our grievance officer at info@kriyacore.in. If you are not satisfied with our response, you can complain to the Data Protection Board of India.
10. Changes
We will update this page when our practices change, with a new version number and effective date. For significant changes we will also tell gym owners by email or inside KriyaCore.