DemiGod Join Us Today
Join Us Today
← Back to DemiGod
Legal Document

Privacy Policy

DemiGod Strength & Conditioning — official privacy & data protection policy.

Effective 17 August 2026
Last updated 17 August 2026
Version 1.0
Jurisdiction India
DPDPA 2023 Compliant IT Act 2000 SPDI Rules 2011 Meta Ads Policy 2025 Google Publisher Policy Consumer Protection Act 2019 GDPR Aligned
Important Notice

This Privacy Policy governs the collection, use, storage and sharing of personal data by DemiGod Strength & Conditioning ("we", "us", "our") through our website www.demigodgym.com, mobile channels, in-person membership registration and all related services. By using our services or visiting our website, you acknowledge and agree to the practices described here. Please read this policy carefully.

01

Who We Are

DemiGod Strength & Conditioning is a premium fitness facility operating under Indian law, located at O-87, 88 1st Floor, Outer Ring Road, New Delhi. Our website is www.demigodgym.com and we can be reached at +91 9873442992.

For the purposes of the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), DemiGod is the Data Fiduciary responsible for your personal data.

Our Commitment

We process your personal data lawfully, fairly and transparently. We collect only what we need, retain it only as long as necessary, and never sell your personal information to third parties.

02

Data We Collect

We collect data through several touchpoints: our website, membership registration forms, in-person interactions and digital advertising platforms. The categories we may collect include:

CategoryExamplesSource
Identity dataFull name, date of birth, gender, photographRegistration form, in-person
Contact dataMobile number, email address, home / billing addressRegistration, website forms, WhatsApp
Membership dataMembership tier, start / end dates, class bookings, check-in logsOur internal systems
Payment dataTransaction IDs, payment method type, billing history (not full card numbers)Payment gateways (Razorpay, UPI, PhonePe)
Health & fitness dataHeight, weight, fitness goals, PAR-Q health screening, voluntarily disclosed medical conditions, injury historyMember health intake form
Usage dataIP address, browser type, pages visited, session duration, referral sourceCookies, Google Analytics
Marketing dataAd interaction data, Meta Pixel events, Google Ads conversions, lead form submissionsMeta, Google advertising platforms
Communications dataWhatsApp messages, email enquiries, feedback formsDirect communication
CCTV dataVideo footage from gym premisesSecurity cameras on-site
Emergency contact dataName and phone number of a designated emergency contactMembership registration
What We Do Not Collect

We do not collect Aadhaar numbers, PAN numbers, bank account details, passwords or any government-issued ID numbers unless expressly required by law and separately consented to. We never collect this data through our website forms.

03

How We Use Your Data

We use your personal data only for the following purposes:

  • Membership management — processing your registration, scheduling, billing and renewal.
  • Service delivery — personal training, class bookings, access control, locker assignment and facility use.
  • Health & safety — ensuring your safe participation in fitness activities and accessing emergency information if required.
  • Payments — processing membership fees and ancillary charges through secure third-party gateways.
  • Communications — appointment reminders, membership updates, renewal notices and promotional offers (with your consent).
  • Marketing & advertising — running targeted campaigns on Meta (Facebook / Instagram) and Google using anonymised or hashed data, with your consent.
  • Analytics & improvement — understanding how our website is used so we can improve our services.
  • Legal compliance — meeting our obligations under applicable Indian law, including lawful requests from courts or regulators.
  • Security — monitoring our premises via CCTV to protect members, staff and property.
  • Dispute resolution — maintaining records to resolve membership or financial disputes.
Purpose Limitation

We will not use your data for any purpose incompatible with those listed above without first obtaining your explicit consent or notifying you of the new purpose.

04

Legal Basis for Processing

Under the DPDPA 2023 and the SPDI Rules 2011, we rely on the following lawful bases:

Processing activityLegal basis
Membership registration and service deliveryContract — necessary to perform your membership agreement
Health and fitness data (PAR-Q, injury history)Explicit consent + vital interests (emergency situations)
Promotional emails, WhatsApp marketingConsent — opt-in required, opt-out available at any time
Meta Pixel, Google Analytics, retargeting adsConsent — via cookie / tracking consent on the website
CCTV surveillance on premisesLegitimate interest — security of persons and property
Payment processingContract + legal obligation
Compliance with court orders / regulator requestsLegal obligation
Retention of records post-membershipLegal obligation (accounting, consumer protection law)

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

05

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies. By continuing to use the site, you consent to their use in accordance with this policy.

Cookie typePurposeCan be declined?
Strictly necessaryWebsite functionality, security, session managementNo — required for the site to function
AnalyticsGoogle Analytics — site traffic and user behaviour, anonymisedYes — via cookie consent
Marketing / advertisingMeta Pixel, Google Ads conversion tracking, remarketing audiencesYes — explicit opt-in required
PreferenceRemembering your language, region and display preferencesYes
Your Cookie Controls

You can manage cookies at any time through your browser settings or our cookie consent banner on first visit. Withdrawing marketing cookie consent will not affect your membership or website access. Disabling strictly necessary cookies may impair website functionality.

We use Google Analytics 4 with IP anonymisation enabled; we do not use Universal Analytics. For details of Google's processing, see policies.google.com/privacy.

06

Meta & Google Advertising Compliance

Meta Ads Policy 2025 Compliant

This section documents our compliance with Meta's updated 2025 advertising data requirements and Google Publisher Standards.

Meta (Facebook & Instagram) advertising

  • We use the Meta Pixel to measure ad performance and build custom audiences. It activates only with your explicit consent via our cookie banner.
  • When you submit a lead form — on our website or through Meta's Instant Forms — you give explicit consent for us to use your contact data for marketing. That consent is logged with a timestamp.
  • We may upload hashed email addresses or phone numbers to Meta's Custom Audience tool to reach existing members or similar prospects. All uploaded data is hashed using SHA-256 and never transferred in plain text.
  • We do not upload data without documented consent. Consent records are kept for a minimum of three years.
  • You may opt out of Meta Custom Audience targeting at any time at facebook.com/ads/preferences or by emailing us.
  • We do not run ads in Meta's Special Ad Categories (housing, employment, credit, financial services, political), so no special category restrictions apply to our campaigns.
  • Lookalike audiences are built only from consented seed data, in compliance with Meta's Terms of Service.

Google advertising

  • We use Google Ads and Google Analytics 4. Conversion tracking is enabled only after cookie consent is obtained.
  • We follow Google's EU User Consent Policy as a best-practice standard even for Indian users, given our website's international reach.
  • We do not use Google's restricted ad categories (clinical trials, gambling, alcohol); our fitness content is general wellness advertising.
  • Remarketing lists are built only from users who accepted marketing cookies, and never on sensitive data such as health conditions or income.
  • We comply with Google Publisher Policies — no misleading claims, no prohibited content, accurate ad descriptions.
Advertiser Accountability

DemiGod takes full responsibility for compliance with Meta's and Google's advertising policies. We maintain internal consent logs, audit our ad targeting quarterly, and remediate any violation identified within 48 hours.

07

Third-Party Sharing & Data Processors

We do not sell, rent or trade your personal data to any third party for commercial gain. We may share data with the following trusted service providers, who process it on our behalf under strict contractual obligations:

Third partyPurposeData shared
Razorpay / PhonePe / UPI providersPayment processingName, amount, transaction reference (we store no full card numbers)
Google LLCAnalytics (GA4), Google AdsAnonymised usage data, hashed email with consent
Meta Platforms Inc.Facebook / Instagram advertisingHashed email or phone with consent, Pixel events
WhatsApp Business API providerMember communicationsName, phone number
Email service providerEmail campaignsName, email address
Gym management softwareMembership administrationFull member profile, access controlled
CCTV monitoring serviceOn-premises securityVideo footage only
Legal advisors / chartered accountantsLegal and financial complianceAs required by applicable law
Law enforcement / courtsLegal obligationDisclosed only under court order or statutory requirement

All third-party processors are required to maintain confidentiality, implement appropriate security measures, and use your data only for the purposes we specify.

08

Health & Sensitive Personal Data

Sensitive Data — Special Protection Applies

Health and fitness data is classified as Sensitive Personal Data or Information (SPDI) under the IT (SPDI) Rules 2011 and receives enhanced protection under our systems and this policy.

When you complete our health intake or Physical Activity Readiness Questionnaire (PAR-Q), you voluntarily disclose health information such as:

  • Cardiovascular conditions, joint or musculoskeletal issues, blood pressure
  • Surgical history relevant to exercise
  • Medications that may affect exercise capacity
  • Other conditions you choose to disclose

This data is used exclusively to:

  • Ensure your safe participation in gym activities and personal training
  • Inform your trainer so your programme can be modified appropriately
  • Facilitate emergency medical response on the premises if required

Access to health data is strictly limited to your assigned personal trainer, the gym manager and emergency response personnel. Health data is never used for marketing or advertising, and never shared with third parties except in a genuine medical emergency.

Body metrics — weight, height, BMI, body fat percentage — collected for fitness tracking are stored securely and accessible only to you and your trainer.

Your Rights Over Health Data

You may request correction or deletion of your health data at any time. Deletion will not affect your membership, but may limit our ability to provide personalised training recommendations.

09

Data Security

We implement industry-standard technical and organisational security measures:

  • Encryption — all data in transit is protected using TLS 1.2 or higher (HTTPS). Sensitive stored data is encrypted at rest.
  • Access controls — personal data is accessible only to authorised staff on a need-to-know basis, and access is logged and audited.
  • Password security — staff accounts use strong passwords and multi-factor authentication on all critical systems.
  • Payment security — we do not store full card numbers; all payment processing is handled by PCI-DSS compliant gateways.
  • Physical security — on-premises records are stored in locked facilities with restricted access.
  • Vendor security — all third-party processors are vetted for security compliance before engagement.
  • Incident response — we maintain a data breach response procedure. In the event of a breach affecting your data we will notify you and, where required, the Data Protection Board of India within the timeframes prescribed under DPDPA 2023.

Despite our best efforts, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we commit to taking all reasonable steps to protect your data.

10

Data Retention

Data categoryRetention periodReason
Active membership recordsDuration of membership + 3 yearsLegal disputes, Consumer Protection Act
Financial / payment records8 years from transaction dateGST and Income Tax Act obligations
Health & fitness data (PAR-Q)Duration of membership + 1 yearLiability protection; deleted on request after cessation
CCTV footage30 days, overwritten automaticallySecurity monitoring; longer if an incident is under investigation
Marketing consent records3 years from last consent actionMeta / Google advertiser compliance
Website analytics (GA4)14 monthsService improvement
Email enquiries / lead forms2 years from last interactionBusiness operations
Cancelled / lapsed memberships3 years from cancellationDispute resolution, re-joining

Once retention periods expire, data is securely deleted or anonymised so that it can no longer be linked to an identifiable individual.

11

Your Rights as a Data Principal

Under the Digital Personal Data Protection Act 2023, you have the following rights over your personal data:

RightWhat it meansHow to exercise it
InformationKnow what personal data we hold about you and how it is usedWritten request to our Grievance Officer
CorrectionCorrect inaccurate or incomplete personal dataEmail or in-person request at the gym
ErasureRequest deletion of your data, subject to legal retention obligationsWritten request to our Grievance Officer
Withdraw consentWithdraw any consent at any time, without affecting prior processingEmail, WhatsApp, or the unsubscribe link in our emails
Grievance redressalLodge a complaint with us and escalate to the Data Protection Board of India if unresolvedContact our Grievance Officer (section 18)
NominateNominate someone to exercise your rights in the event of death or incapacityWritten nomination submitted to us

We respond to all valid requests within 30 days. Complex requests may take up to 45 days, with notice to you. We do not charge a fee for routine requests.

Escalation Path

If you are dissatisfied with our response you may escalate to the Data Protection Board of India once it is operational under DPDPA 2023 rules. You may also seek redressal under the Consumer Protection Act 2019 or approach the Adjudicating Officer under the IT Act 2000.

12

Children's Privacy

Our services are intended for individuals aged 16 years and above. Members under 18 require written consent from a parent or legal guardian before enrolling.

  • We do not knowingly collect personal data from children under 16 without verifiable parental consent.
  • Our website is not directed at children under 16, and we do not display targeted advertising to users identified as minors.
  • For members aged 16 to 17, all communications regarding health data and marketing are directed to the consenting parent or guardian.
  • If we discover we have inadvertently collected data from a child under 16 without parental consent, we will delete it immediately.

Parents or guardians who believe their child's data has been collected without consent should contact our Grievance Officer immediately using the details in section 18.

13

CCTV & Premises Surveillance

DemiGod operates CCTV cameras across its premises for the safety and security of members, staff and property. By entering our premises you acknowledge and consent to being recorded.

  • Cameras are not installed in changing rooms, shower areas or restrooms.
  • Footage is stored for a maximum of 30 days and then automatically overwritten, unless retained for investigation of an incident.
  • Access to footage is restricted to senior management and authorised security personnel.
  • Footage is shared with law enforcement only on receipt of a valid legal order or in response to a security incident.
  • Signage notifying members of CCTV operation is displayed at all entry points.
14

Photography, Video & Media Release

DemiGod may photograph or film members, classes or events for marketing and social media purposes — Instagram, Facebook, YouTube and our website.

Opt-In Required

Photography and video release consent is a separate, voluntary opt-in during membership registration. Your membership is never conditional on granting it.

  • If you have opted in, you grant DemiGod a non-exclusive, royalty-free licence to use your image or likeness in marketing materials for the duration of your consent.
  • You may withdraw consent at any time in writing. Withdrawal applies to future use; material already published in print may not be immediately removable.
  • We will never use your image in a context that is demeaning, discriminatory or misleading.
  • Members who have not opted in should not be incidentally captured in shared content. If you appear without consent, tell us and we will remove the content promptly.
  • Transformation photographs (before / after) require separate written consent specifying the intended platforms and duration of use.
15

Liability Disclaimer — Physical Activity

Important — Please Read Carefully

This section forms part of our overall terms of use. Your membership agreement contains a separate, signed liability waiver; this section supplements that waiver for website visitors and prospective members.

Physical exercise involves inherent risks including, but not limited to, muscular strain, joint injury, cardiovascular stress and, in rare cases, serious injury. By using DemiGod's facilities and services you acknowledge and accept these risks.

  • You confirm that you are physically capable of participating in the activities you choose to undertake at DemiGod.
  • You are responsible for consulting a qualified medical practitioner before beginning any new exercise programme, particularly if you have a pre-existing health condition.
  • Any health information you disclose is used to help us provide safer training guidance — it does not constitute medical advice from DemiGod.
  • DemiGod, its owners, directors, employees and trainers shall not be liable for any injury, illness, loss or damage arising from your voluntary participation in gym activities, except in cases of proven gross negligence on our part.
  • DemiGod is not responsible for loss or theft of personal belongings on or from the premises, except where directly caused by our negligence.
  • Information on our website and social media channels is for general fitness awareness only and does not constitute medical, nutritional or clinical advice.
16

Cross-Border Data Transfers

Some of our third-party service providers — Google LLC and Meta Platforms Inc. — are headquartered outside India and may process your data on servers in the United States or other countries.

  • These transfers are protected by the respective companies' standard contractual clauses, adequacy decisions or other approved transfer mechanisms.
  • We only transfer data to countries or entities providing data protection standards comparable to those required under DPDPA 2023.
  • We rely on Google's and Meta's commitments under their respective Data Processing Addenda and privacy policies for the protection of transferred data.
  • Where possible, data is anonymised or pseudonymised before transfer to minimise risk.
DPDPA Cross-Border Compliance

As India's DPDPA 2023 rules on cross-border transfers are finalised and notified by the Government of India, we will update our practices and this policy accordingly.

17

Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in law, our services or our data practices. We will notify you of material changes by:

  • Posting a prominent notice on our website with the updated effective date
  • Sending an email or WhatsApp notification to active members
  • Displaying an on-premises notice where appropriate

Your continued use of our services after the effective date of a revised policy constitutes acceptance of the updated terms. Previous versions are archived and available on request.

Current version effective 17 August 2026. Policy version 1.0.

18

Grievance Officer

In compliance with Rule 5(9) of the IT (SPDI) Rules 2011 and Section 13 of the DPDPA 2023, we have appointed a Grievance Officer to address data protection concerns and complaints.

Grievance Officer — DemiGod

Designation
Grievance Officer / Manager
Address
O-87, 88 1st Floor, Outer Ring Road, New Delhi, India
Working hours
Monday to Saturday, 9:00 AM – 6:00 PM IST

We acknowledge complaints within 5 business days and aim to resolve them within 30 days. If unresolved, you may escalate to the Data Protection Board of India.

If you are unsatisfied with the resolution provided by our Grievance Officer, you have the right to approach:

  • The Data Protection Board of India, once constituted under DPDPA 2023
  • The Adjudicating Officer under the Information Technology Act 2000
  • The Consumer Disputes Redressal Commission under the Consumer Protection Act 2019
  • A court of competent jurisdiction in India
19

Governing Law & Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India, including but not limited to:

  • Digital Personal Data Protection Act, 2023 (DPDPA)
  • Digital Personal Data Protection Rules, 2025
  • Information Technology Act, 2000 and IT (Amendment) Act, 2008
  • IT (Reasonable Security Practices and Procedures and SPDI) Rules, 2011
  • Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020
  • Indian Contract Act, 1872

Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of New Delhi, India. Both parties agree to attempt resolution through good-faith negotiation before initiating formal legal proceedings.

Severability

If any provision of this Privacy Policy is found unenforceable or invalid under applicable law, that provision shall be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible. The remaining provisions continue in full force and effect.

20

Contact Us

For any query, request or concern regarding this Privacy Policy or your personal data, contact us through any of the following channels:

DemiGod — Data & Privacy Contact

Phone / WhatsApp
+91 9873442992
Address
O-87, 88 1st Floor, Outer Ring Road, New Delhi, India
Gym hours
Mon – Sat: 5am – 12am  ·  Sunday: 8am – 8pm
Legal Disclaimer

This Privacy Policy has been prepared in good faith to reflect applicable Indian law and platform advertising requirements as of August 2026. DemiGod will seek periodic review by a qualified Indian legal practitioner, particularly as DPDPA 2023 rules are fully implemented in Phase 2 from November 2026 onwards, and will update this document accordingly.