Privacy Policy
Version 2026-08-draft · Last updated 2 August 2026 · Effective [TO CONFIRM: effective date — set at launch]
What personal data Open Gym collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We do not sell personal data.
1. What this covers
This policy applies to everyone who visits opengym.in, uses our mobile apps, buys a ticket, or lists activities as an Expert. It is written to meet the information requirements of Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Hungarian Act CXII of 2011 on informational self-determination and freedom of information ("Infotv.").
It does not cover the practices of Experts. An Expert who collects your data separately — for example on their own sign-up sheet or their own website — is an independent controller for that data, and you should ask them about it.
2. Who is responsible
The controller of your personal data is Nomo Consulting Kft., registered seat 1082 Budapest, Baross utca 74., Hungary, company number 01-09-294594.
You can reach our privacy contact at privacy@opengym.in. (We are not required to appoint a Data Protection Officer under GDPR Art. 37 and have not appointed one; privacy requests go to the address above.)
3. What we collect
Data you give us
- Account: email address, name, and — if you choose to add them — phone number, profile photo, biography, and language preference.
- Billing: billing address and the name on the order.
- Content: photos you upload, activity descriptions, and reviews you write.
- Experts only: the identity, address, and tax details you provide to Stripe for onboarding, and your attestation that you hold liability insurance. Stripe collects verification documents directly — we receive only the verification status, not the documents.
We do not ask you for health data. Please do not put health information into free-text fields such as reviews or profile biographies — tell the Expert directly instead.
Data generated by your use
- Orders, tickets, vouchers, payments, refunds, and applied discount codes.
- Attendance records for sessions you booked.
- Technical data: IP address, browser and device information, sign-in events and sessions.
- Approximate location derived from your IP address, at city level, used to show you activities near you. We do not collect precise GPS location.
- Cart contents, including carts you abandon, and a visitor identifier stored in a cookie.
- Usage analytics — see section 10.
Data from others
- If you sign in with Google, Facebook, or X: your email address and name from that provider. We do not receive your password or post on your behalf.
- From Stripe: payment status, the last four digits and brand of the card, and payout status for Experts. We never receive your full card number.
- If someone gives you a voucher, we learn that you claimed or cancelled it.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account; sign you in | Account data, sign-in events | Contract — 6(1)(b) |
| Process orders, issue tickets and vouchers, send confirmations and reminders, handle cancellations and refunds | Account, order, payment, ticket data | Contract — 6(1)(b) |
| Give the Expert the attendee list so they can run the session | First name, last initial, ticket status | Contract — 6(1)(b) |
| Pay Experts and account for platform fees | Expert identity, payout and order data | Contract — 6(1)(b) |
| Issue invoices; keep accounting and tax records | Order, payment, billing data | Legal obligation — 6(1)(c) |
| Prevent fraud and abuse; enforce our Terms; keep the Platform secure | Technical data, order patterns, reports | Legitimate interests — 6(1)(f) |
| Show you activities near you | City-level location from IP | Legitimate interests — 6(1)(f) |
| Publish reviews and ratings | Review text, rating, reviewer display name | Contract — 6(1)(b) |
| Invite you to review a session you attended; milestone reminders | Attendance and review status, email address | Legitimate interests — 6(1)(f) |
| Analytics to understand and improve the Platform | Usage events, device data, identifiers | Consent — 6(1)(a) |
| Marketing emails and newsletters | Email address, city of interest | Consent — 6(1)(a) |
| Respond to legal claims and authority requests | Whatever is strictly relevant | Legal obligation / legitimate interests — 6(1)(c), (f) |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. You can object at any time — see section 8 — and you can withdraw consent at any time without affecting processing already carried out.
6. International transfers
Your data is stored in the European Economic Area. Our application and database run in an EEA datacentre region, and our analytics run on PostHog's EU infrastructure, so the storage of your data is not a transfer outside the EEA.
Two of our processors are nonetheless US companies — Stripe and DigitalOcean. Their staff may be able to access data from the United States for support and administration even though it is stored in Europe, and that access counts as a transfer. For it we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where the recipient is certified, the EU–US Data Privacy Framework, together with the supplementary technical measures described in each processor's documentation. You may request a copy of the relevant safeguards at privacy@opengym.in.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | Until you close your account, then anonymised |
| Orders, payments, invoices, accounting records | 8 years from the end of the financial year, as required by the Hungarian Accounting Act (Act C of 2000, §169) |
| Tax records | As required by Hungarian tax law |
| Reviews | Until deleted; retained in anonymised form after account closure |
| Security and audit logs | 12 months |
| Analytics data | 14 months |
| Marketing consent records | Until you withdraw consent, plus 3 years to evidence the consent |
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, except where we must keep it by law (see section 7).
- Restriction — have processing paused while a dispute is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, including profiling. We stop unless we can show compelling legitimate grounds that override your rights.
- Withdraw consent — at any time, for analytics and marketing, without affecting processing already carried out.
Email privacy@opengym.in from the address on your account. We respond within one month, extendable by two further months for complex requests — we will tell you if that happens. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.
9. Closing your account
You can close your account from Account → Security. When you do, we overwrite the following fields with anonymised values: email address, name, phone number, profile photo, biography, billing address, date of birth, and the link to your Stripe account. Any activities you own are archived, and every active sign-in session is ended, so you are signed out on all devices.
We keep your orders, payments, tickets, and audit records, because we are legally required to — but they then reference an anonymised user rather than an identifiable person. This is why account closure is described as anonymisation rather than complete erasure.
11. Security
We use TLS for all traffic, encrypt data at rest with our hosting and storage providers, restrict internal access on a least-privilege basis, require multi-factor authentication for administrator accounts, and keep audit logs of administrative actions. We never store full card numbers — Stripe handles card data under PCI DSS.
No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights, we will notify the Hungarian supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high, as GDPR Arts. 33 and 34 require.
12. Children
Open Gym is not intended for children under 16, and we do not knowingly collect their personal data. Sixteen is also the age at which a child can consent to information society services in Hungary under Infotv. If you are a parent or guardian who believes a child under 16 has created an account, contact privacy@opengym.in and we will close it and delete the data.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Automated rules do flag suspicious orders and payments for fraud review, but a person decides before any account is suspended or any order is refused, and you can contest that decision by writing to privacy@opengym.in. Stripe applies its own automated fraud screening to card payments.
14. Changes
We will update this policy as the Platform changes. For material changes we notify registered users by email at least 15 days before they take effect. The version and date at the top of this page always tell you which version is current.
15. Contact & complaints
Privacy questions and requests: privacy@opengym.in, or by post to Nomo Consulting Kft., 1082 Budapest, Baross utca 74., Hungary.
If you are unhappy with our response, you can complain to the Hungarian Data Protection Authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
1055 Budapest, Falk Miksa utca 9–11.
Postal: 1363 Budapest, Pf. 9.
naih.hu
If you live in another EEA country, you may instead complain to your local supervisory authority. You also have the right to an effective judicial remedy.