01

Introduction

Kaayu Gym Management ("Kaayu," "we," "us," or "our") is a cloud-based gym management platform operated by Kaayu Technology Inc., registered in the Philippines. We operate the website at kaayu.online and the Kaayu software-as-a-service platform.

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website or platform — whether you are a gym operator, a staff member, or a gym member whose information is managed within the platform.

We are committed to compliance with the Philippines Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, applicable Southeast Asian data protection laws, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), as relevant to your jurisdiction.

Not Legal Advice

This policy is a legal document, not legal advice. If you have questions about your specific compliance obligations as a gym operator, please consult qualified counsel in your jurisdiction. Kaayu's built-in contract and consent templates are reviewed by regional counsel but are provided as tools, not guaranteed legal compliance.

02

Who This Policy Covers

This policy applies to three distinct groups of individuals whose data Kaayu may process:

Gym Operators & Staff

If you are the owner, manager, or staff member of a gym that subscribes to Kaayu, you are our direct customer. We collect and process your data to provide you with the platform, manage your account, process subscription payments, and communicate with you about the service.

Gym Members

If you are a member of a gym that uses Kaayu, your data is entered into the platform by your gym — either by staff or by yourself during self-registration. In this context, your gym is the data controller of your personal data, and Kaayu acts as a data processor operating under instruction from your gym. For requests related to your membership data (access, correction, deletion), you should first contact your gym directly. We explain this two-tier model fully in Section 5.

Website Visitors

If you visit kaayu.online without signing up, we collect limited data as described in our Cookies section (Section 13), including analytics and form submissions you voluntarily provide.

03

Data We Collect

From Gym Operators & Staff (Account Data)

  • Identity: Full name, job title or role, profile photo (optional)
  • Contact: Business email address, phone number, business address
  • Account credentials: Encrypted password hash (we never store passwords in plain text)
  • Billing: Subscription plan, billing cycle, invoice history. Payment card data is handled exclusively by our payment processors — we never see or store raw card numbers (see Section 7)
  • Usage data: Feature interactions, login timestamps, session activity, browser/device type, IP address
  • Support communications: Messages you send to our support team, help desk tickets

From Gym Members (Managed on Behalf of Gyms)

  • Identity: Full name, date of birth, gender (if collected by the gym), photo (optional)
  • Contact: Email address, mobile number, emergency contact
  • Membership: Plan type, enrollment date, membership status, renewal dates, member ID
  • Financial: Payment records, invoice history, outstanding balances — no raw card data
  • Health & fitness (optional): Weight, height, fitness goals, medical notes — only if the gym operator chooses to collect this data and the member consents
  • Access control: Entry/exit timestamps, biometric template hashes (where access control hardware is used — see below)
  • Class & booking history: Class attendance, bookings, cancellations, trainer assignments
  • Digital contracts: Signed membership agreements, consent forms, timestamps, IP addresses used at signing
Biometric Data Notice

Where gyms use Kaayu's access control integration (fingerprint or facial recognition hardware), biometric data is processed by the access hardware and matched locally or via a one-way hash. Kaayu stores only the biometric template hash, not raw biometric images. This data is subject to heightened protection under Philippine RA 10173 and applicable laws as "sensitive personal information."

Automatically Collected Technical Data

  • IP address, browser type and version, operating system
  • Pages visited, time on page, referring URL
  • Device identifiers, session tokens (for authentication)
  • Error logs and crash reports (anonymized where possible)
05

Data Ownership & Multi-Tenancy

Kaayu is a multi-tenant platform: each gym subscribing to Kaayu has their own isolated tenant environment. Each gym owns their own data. Kaayu does not commingle tenant data, does not use member data from one gym to benefit another, and does not sell or share individual gym's member data with other Kaayu customers.

Two-Tier Data Model

Gym Operator = Data Controller. The gym decides what member data to collect, why, and how long to keep it. They are responsible for member consent and compliance with local laws regarding their members.

Kaayu = Data Processor. We process member data strictly under the instructions of the gym operator, as governed by our Data Processing Agreement (DPA) included in our Terms of Service. We do not process member data for our own purposes beyond what is necessary to provide the service.

Data Portability & Export

Gym operators can export their complete member data at any time from within the platform in standard CSV and JSON formats. This data belongs to the gym and can be migrated to another system. Upon subscription termination, we provide a 30-day export window, after which data is securely deleted in accordance with our retention policy (Section 11).

Data Isolation

Each gym tenant's data is logically isolated using tenant-scoped database schemas and access controls. Kaayu engineering staff access to production tenant data is role-restricted, logged, and requires multi-party approval for non-routine operations.

06

How We Use Your Data

For Gym Operators & Staff

  • Provisioning and operating your Kaayu account and tenant environment
  • Processing subscription fees and issuing invoices
  • Providing customer support, onboarding assistance, and training
  • Sending transactional emails: account alerts, invoices, feature announcements
  • Sending promotional communications where you have opted in (you may opt out at any time)
  • Improving the platform through aggregate, anonymized usage analysis
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with legal obligations including tax requirements and court orders

For Gym Member Data (Processed as Data Processor)

  • Storing and displaying membership records, payment history, and class bookings as directed by the gym
  • Processing check-ins and access control entries
  • Generating reports and analytics for gym staff (aggregate or individual, per gym configuration)
  • Facilitating digital contract signing and archiving signed agreements
  • Sending automated notifications on behalf of the gym (e.g. payment reminders, class confirmations) — only when configured by the gym

We do not use gym member data for: advertising, profiling unrelated to the gym's operations, training AI or machine learning models, or any purpose not directed by the gym operator.

07

Payment Processing

Kaayu uses third-party payment processors to handle all financial transactions. Kaayu does not collect, store, or transmit payment card numbers, bank account numbers, or other sensitive financial account credentials.

We use the following payment processors depending on your region:

Processor Regions Data Shared Their Privacy Policy
Xendit Philippines, Indonesia, Malaysia, Vietnam, Thailand Name, email, amount, transaction reference xendit.co/privacy-policy
PayMongo Philippines Name, email, amount, transaction reference paymongo.com/privacy
Stripe Global (EU, US, Scandinavia, SEA) Name, email, amount, transaction reference stripe.com/privacy

When you make a payment, you are interacting directly with the payment processor's secure form or hosted payment page. Card data is tokenized by the processor and never passes through Kaayu's servers. Our processors are PCI DSS compliant. We retain only: payment status (success/fail), transaction reference IDs, invoice amounts, and dates — for accounting, support, and dispute resolution purposes.

Gym Member Payments

When gyms use Kaayu to process member payments (membership fees, PT sessions, etc.), the same processor rules apply. The gym's members' payment card data is handled by the payment processor — not stored by Kaayu or the gym. Kaayu stores only the payment record (date, amount, status, reference ID) in the gym's tenant environment.

08

Data Sharing & Sub-Processors

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We share data only as necessary to provide the service, as described below.

Service Providers (Sub-Processors)

We engage trusted third-party vendors who process personal data on our behalf under data processing agreements:

Vendor Purpose Data Category Location
Cloud hosting provider (AWS / GCP) Infrastructure, database storage All data Singapore / US (with SCCs)
Transactional email provider System emails, notifications Email, name US (with SCCs)
SMS gateway OTP, appointment reminders Phone number Regional
Analytics (self-hosted / anonymized) Product usage analytics Anonymized usage events Philippines
Customer support platform Help desk, support tickets Email, name, messages US (with SCCs)
Payment processors See Section 7 See Section 7 Regional

Legal Disclosures

We may disclose personal data if required to do so by law, regulation, court order, or government authority. Where permitted, we will notify the affected party prior to disclosure. We will challenge requests we believe are overly broad or unlawful.

Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will provide notice before such a transfer and ensure the receiving entity is bound by privacy obligations at least as protective as this policy.

09

International Data Transfers

Kaayu is headquartered in the Philippines and serves customers globally. Personal data may be stored or processed outside the country where it was collected. We take appropriate safeguards to ensure your data remains protected regardless of where it is processed.

  • Philippines: Processing is subject to RA 10173 and NPC guidelines
  • European Economic Area (EEA): Transfers outside the EEA are protected by Standard Contractual Clauses (SCCs) as approved by the European Commission
  • United States: We work with US sub-processors that comply with applicable data transfer mechanisms
  • Southeast Asia: We comply with applicable national data protection laws in countries where we operate, including the Personal Data Protection Act (PDPA) in Singapore, Malaysia, and Thailand

Our primary data center is located in Singapore (AWS ap-southeast-1), chosen for its data sovereignty posture within Southeast Asia. Backup systems may operate in secondary regions, each subject to equivalent security standards and contractual protections.

10

Data Security

We implement technical and organizational security measures appropriate to the risk of processing personal data. These include:

  • Encryption in transit: All data transmitted between your browser and Kaayu is encrypted using TLS 1.2 or higher
  • Encryption at rest: Database storage is encrypted using AES-256
  • Access controls: Role-based access control (RBAC) limits data access to authorized personnel. Multi-factor authentication (MFA) is enforced for all Kaayu staff accounts
  • Tenant isolation: Each gym's data is logically isolated; cross-tenant access is technically prevented
  • Audit logging: All administrative access to production systems is logged with full audit trails
  • Penetration testing: We conduct periodic third-party security assessments
  • Backups: Encrypted backups are taken daily with point-in-time recovery capability
  • Incident response: We maintain a documented incident response plan. In the event of a data breach affecting your data, we will notify affected parties and regulators within the timeframes required by applicable law (72 hours under GDPR; prescribed NPC timelines under RA 10173)
No System Is Perfect

While we implement strong security measures, no internet transmission or electronic storage is 100% secure. We encourage gym operators to use strong passwords, enable two-factor authentication, and train staff on data handling best practices.

11

Data Retention

Gym Operator Account Data

We retain your account data for the duration of your subscription plus 30 days following termination (to allow data export). After the 30-day export window, account data is deleted, with the exception of billing records and transaction logs, which are retained for 7 years to comply with Philippine tax and accounting regulations.

Gym Member Data

Because gyms are the data controllers of member data, retention is governed by the gym's own data retention policies, not Kaayu's. Gym operators can configure retention periods and delete member records within the platform. When a gym account is terminated, all associated member data is deleted within 30 days (following the export window), unless a longer period is required by law.

Marketing Data

If you have opted in to marketing communications, we retain your contact information and preferences until you unsubscribe. You can unsubscribe at any time via the link in any marketing email or by contacting us at privacy@kaayu.online.

Anonymized Data

Anonymized, aggregated usage data (from which no individual can be identified) may be retained indefinitely to improve the platform and for business analytics purposes.

12

Your Rights

Depending on where you are located, you have the following rights regarding your personal data. Note that gym members should first contact their gym for requests related to membership data, as the gym is the data controller.

🇵🇭
Philippines
RA 10173 — Data Privacy Act
  • Right to be informed
  • Right of access
  • Right to object
  • Right to erasure / blocking
  • Right to rectification
  • Right to data portability
  • Right to file a complaint with the NPC
  • Right to damages
🇪🇺
European Union
GDPR — Art. 15–22
  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Rights re: automated decisions (Art. 22)
  • Right to lodge a complaint with your supervisory authority
🇺🇸
United States
CCPA / CPRA (California)
  • Right to know what data is collected
  • Right to know if data is sold or disclosed
  • Right to opt-out of sale
  • Right to deletion
  • Right to non-discrimination
  • Right to correct inaccurate data
  • Right to limit use of sensitive personal information

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@kaayu.online with your full name and the nature of your request. We will respond within 30 days (or sooner as required by applicable law). We may need to verify your identity before fulfilling your request. We will not charge a fee for legitimate requests.

If you are a gym member, your gym is the primary contact for data requests. If your gym is unable or unwilling to assist, you may contact us and we will work with the gym to facilitate the request as required under applicable law.

We Do Not Sell Personal Data

Kaayu does not sell personal data to third parties in any form, including under the CCPA definition of "sale." California residents do not need to submit an opt-out request — we do not engage in this activity.

13

Cookies & Tracking Technologies

We use cookies and similar technologies on kaayu.online and within the platform. Here is what we use and why:

Cookie Type Purpose Duration Consent Required?
Essential Session management, authentication, CSRF protection, load balancing Session / 24 hours No — essential for service
Functional Remembering language preference, UI layout preferences 1 year No — service functionality
Analytics Understanding how pages are used to improve the platform (self-hosted, anonymized) 13 months Yes (cookie banner)
Marketing We do not use marketing or advertising cookies on the platform N/A N/A

You can control cookies through your browser settings. Disabling essential cookies will affect the functionality of the platform. Our cookie banner (shown on first visit) allows you to accept or decline non-essential cookies. You may change your cookie preferences at any time via the cookie settings link in the footer.

14

Children's Privacy

The Kaayu platform is intended for use by gym businesses and their adult members. We do not knowingly collect personal data from children under the age of 13 (or the applicable age of digital consent in your jurisdiction — 16 in certain EU member states, 18 in the Philippines for independent consent).

Gym operators may enroll minor members (e.g., youth fitness programs) into the platform, but doing so requires that the gym operator has obtained verifiable parental or guardian consent in compliance with applicable laws. Gym operators represent and warrant that they have obtained such consent prior to entering minor member data into Kaayu.

If we become aware that we have collected personal data from a child without appropriate consent, we will delete that data promptly. If you believe we have inadvertently collected data about a child, please contact privacy@kaayu.online immediately.

15

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, the platform's features, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to active gym operator accounts at least 14 days before the change takes effect
  • Display an in-app banner notifying users of the update

For non-material changes (such as correcting typos or clarifying existing practices without substantively changing them), we may update the policy without prior notice beyond updating the revision date.

Your continued use of the platform after the effective date of an updated policy constitutes your acceptance of the changes. If you do not agree with a material change, you may terminate your account prior to the effective date.

16

Contact Us

For any privacy-related questions, requests to exercise your rights, or concerns about our data practices, please contact:

Data Protection Contact

Kaayu Technology Inc.
Attn: Data Privacy Officer
Email: privacy@kaayu.online
Phone: +63 947 984 1430
Manila, Philippines

We aim to respond to all privacy inquiries within 5 business days and to resolve requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority:

  • Philippines: National Privacy Commission (NPC) — privacy.gov.ph
  • EU: Your national Data Protection Authority (DPA) — edpb.europa.eu/about-edpb/board/members
  • California: California Privacy Protection Agency — cppa.ca.gov