Data Privacy
Directive
STATUS: ACTIVE
ENCRYPTION: AES-256
JURISDICTION: INDIA
COMPLIANCE: IT ACT 2000
LAST SYNC: 14 FEB 2026
01 // Executive Overview
Scope and Applicability
Elite Fitness ("The Lab", "We", "Us") operates under strict confidentiality protocols. This Privacy Directive articulates the parameters under which we collect, utilize, process, and store the personal data of our members ("Agents") and visitors. This policy constitutes a binding electronic record under the Information Technology Act, 2000 and the rules made thereunder.
By entering our facilities or interfacing with our digital nodes (Website, App), you explicitly consent to the data practices outlined herein. If you dissent from these protocols, immediate termination of facility access is required.
02 // Data Acquisition
Harvested Information Types
To maintain the operational integrity of The Lab, we harvest specific data vectors:
- Legal Name & Date of Birth
- Government Issued ID (Aadhaar/PAN/Passport)
- Physical Residential Coordinates
- Emergency Contact Frequencies
- Body Composition Metrics (BMI, Fat %)
- Medical History & Contraindications
- Dietary Logs & Workout Performance Data
- Heart Rate Variability (if using Lab tech)
- Tokenized Credit/Debit Card Data
- UPI IDs and Transaction Histories
- Billing Cycles and Payment Behaviors
- IP Addresses & Device Fingerprints
- Login Timestamps & Geolocation
- App Usage Analytics
03 // Biometric & Access
High-Security Entry Protocols
Sensitive Data Alert
Elite Fitness utilizes advanced biometric scanning (Fingerprint/FaceID) strictly for facility access control and identity verification.
Processing: Biometric inputs are not stored as raw images. They are immediately converted into a cryptographic hash (a one-way mathematical string) that cannot be reverse-engineered into a visual representation of your face or fingerprint.
Consent: By enrolling in the membership, you grant explicit permission for the processing of this biometric data solely for security and access authentication. This data is isolated from external marketing databases.
04 // Surveillance Grid
CCTV and Physical Monitoring
For the safety of all Agents and the protection of Lab equipment, the facility is monitored by a closed-circuit television (CCTV) network 24 hours a day.
- Coverage AreasEntry/Exit points, workout floors, reception, and equipment zones. Locker rooms and restrooms are strictly excluded from video surveillance to preserve privacy.
- Data StorageFootage is stored on secure local servers for a period of 30 to 90 days (rolling cycle) depending on storage capacity, after which it is overwritten unless flagged for incident investigation.
- Access ProtocolFootage access is restricted to the Chief of Security and Legal Management. Law enforcement agencies may request access via proper legal warrants.
05 // Usage Protocols
How We deploy Your Data
Your data is processed to execute the following mission-critical commands:
Operational Execution
Managing your membership account, processing payments, and enabling entry through automated turnstiles.
Performance Optimization
Analyzing gym usage patterns to improve equipment availability, class scheduling, and facility maintenance.
Tactical Communication
Sending critical alerts regarding facility hours, payment failures, or emergency closures via SMS, Email, or App Notifications.
06 // Third-Party Uplinks
Data Sharing & Disclosure
We operate a closed loop. We do not sell, rent, or trade your personal identity vectors to unauthorized external nodes. However, data may be transmitted to the following trusted sub-processors:
- Financial Gateways(Razorpay / Stripe) for secure payment processing.
- CRM Systems(Salesforce / GymMaster) for membership database management.
- Legal AuthoritiesWhen compelled by a court order or to prevent physical harm.
07 // Security & Retention
Encryption Standards
Encryption: All sensitive data at rest is encrypted using AES-256 standards. Data in transit is secured via TLS 1.3 protocols.
Retention: We retain your data only as long as your membership is active or as required by tax laws (usually 5-7 years for financial records). Upon termination, your biometric hash is purged from the active access controller within 48 hours.
08 // Agent Rights
Your Control Over Data
Under the IT Act and global privacy standards, you possess the following rights:
- Right to Access: Request a copy of all data held about you.
- Right to Rectification: Update incorrect metrics or contact details.
- Right to Erasure: Request deletion of data (subject to legal retention requirements).
- Right to Withdraw Consent: Revoke permission for marketing communications.
09 // Grievance Officer
In accordance with the Information Technology Act 2000, the contact details of the Grievance Officer are provided below:
Mr. Vikram Rathore
Chief Data Security Officer
LOC: Elite Fitness HQ, Palasia, Indore, MP
EMAIL: PRIVACY@ELITEFITNESS.LAB
COMM: +91 731 444 XXXX
End of Directive // ELITE_PRIV_01 // SECURE_CHANNEL_CLOSE