This Privacy Policy governs the collection, use, storage and sharing of personal data by DemiGod Strength & Conditioning ("we", "us", "our") through our website www.demigodgym.com, mobile channels, in-person membership registration and all related services. By using our services or visiting our website, you acknowledge and agree to the practices described here. Please read this policy carefully.
DemiGod Strength & Conditioning is a premium fitness facility operating under Indian law, located at O-87, 88 1st Floor, Outer Ring Road, New Delhi. Our website is www.demigodgym.com and we can be reached at +91 9873442992.
For the purposes of the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), DemiGod is the Data Fiduciary responsible for your personal data.
We process your personal data lawfully, fairly and transparently. We collect only what we need, retain it only as long as necessary, and never sell your personal information to third parties.
We collect data through several touchpoints: our website, membership registration forms, in-person interactions and digital advertising platforms. The categories we may collect include:
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, gender, photograph | Registration form, in-person |
| Contact data | Mobile number, email address, home / billing address | Registration, website forms, WhatsApp |
| Membership data | Membership tier, start / end dates, class bookings, check-in logs | Our internal systems |
| Payment data | Transaction IDs, payment method type, billing history (not full card numbers) | Payment gateways (Razorpay, UPI, PhonePe) |
| Health & fitness data | Height, weight, fitness goals, PAR-Q health screening, voluntarily disclosed medical conditions, injury history | Member health intake form |
| Usage data | IP address, browser type, pages visited, session duration, referral source | Cookies, Google Analytics |
| Marketing data | Ad interaction data, Meta Pixel events, Google Ads conversions, lead form submissions | Meta, Google advertising platforms |
| Communications data | WhatsApp messages, email enquiries, feedback forms | Direct communication |
| CCTV data | Video footage from gym premises | Security cameras on-site |
| Emergency contact data | Name and phone number of a designated emergency contact | Membership registration |
We do not collect Aadhaar numbers, PAN numbers, bank account details, passwords or any government-issued ID numbers unless expressly required by law and separately consented to. We never collect this data through our website forms.
We use your personal data only for the following purposes:
We will not use your data for any purpose incompatible with those listed above without first obtaining your explicit consent or notifying you of the new purpose.
Under the DPDPA 2023 and the SPDI Rules 2011, we rely on the following lawful bases:
| Processing activity | Legal basis |
|---|---|
| Membership registration and service delivery | Contract — necessary to perform your membership agreement |
| Health and fitness data (PAR-Q, injury history) | Explicit consent + vital interests (emergency situations) |
| Promotional emails, WhatsApp marketing | Consent — opt-in required, opt-out available at any time |
| Meta Pixel, Google Analytics, retargeting ads | Consent — via cookie / tracking consent on the website |
| CCTV surveillance on premises | Legitimate interest — security of persons and property |
| Payment processing | Contract + legal obligation |
| Compliance with court orders / regulator requests | Legal obligation |
| Retention of records post-membership | Legal obligation (accounting, consumer protection law) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Our website uses cookies and similar tracking technologies. By continuing to use the site, you consent to their use in accordance with this policy.
| Cookie type | Purpose | Can be declined? |
|---|---|---|
| Strictly necessary | Website functionality, security, session management | No — required for the site to function |
| Analytics | Google Analytics — site traffic and user behaviour, anonymised | Yes — via cookie consent |
| Marketing / advertising | Meta Pixel, Google Ads conversion tracking, remarketing audiences | Yes — explicit opt-in required |
| Preference | Remembering your language, region and display preferences | Yes |
You can manage cookies at any time through your browser settings or our cookie consent banner on first visit. Withdrawing marketing cookie consent will not affect your membership or website access. Disabling strictly necessary cookies may impair website functionality.
We use Google Analytics 4 with IP anonymisation enabled; we do not use Universal Analytics. For details of Google's processing, see policies.google.com/privacy.
This section documents our compliance with Meta's updated 2025 advertising data requirements and Google Publisher Standards.
Meta (Facebook & Instagram) advertising
Google advertising
DemiGod takes full responsibility for compliance with Meta's and Google's advertising policies. We maintain internal consent logs, audit our ad targeting quarterly, and remediate any violation identified within 48 hours.
We do not sell, rent or trade your personal data to any third party for commercial gain. We may share data with the following trusted service providers, who process it on our behalf under strict contractual obligations:
| Third party | Purpose | Data shared |
|---|---|---|
| Razorpay / PhonePe / UPI providers | Payment processing | Name, amount, transaction reference (we store no full card numbers) |
| Google LLC | Analytics (GA4), Google Ads | Anonymised usage data, hashed email with consent |
| Meta Platforms Inc. | Facebook / Instagram advertising | Hashed email or phone with consent, Pixel events |
| WhatsApp Business API provider | Member communications | Name, phone number |
| Email service provider | Email campaigns | Name, email address |
| Gym management software | Membership administration | Full member profile, access controlled |
| CCTV monitoring service | On-premises security | Video footage only |
| Legal advisors / chartered accountants | Legal and financial compliance | As required by applicable law |
| Law enforcement / courts | Legal obligation | Disclosed only under court order or statutory requirement |
All third-party processors are required to maintain confidentiality, implement appropriate security measures, and use your data only for the purposes we specify.
Health and fitness data is classified as Sensitive Personal Data or Information (SPDI) under the IT (SPDI) Rules 2011 and receives enhanced protection under our systems and this policy.
When you complete our health intake or Physical Activity Readiness Questionnaire (PAR-Q), you voluntarily disclose health information such as:
This data is used exclusively to:
Access to health data is strictly limited to your assigned personal trainer, the gym manager and emergency response personnel. Health data is never used for marketing or advertising, and never shared with third parties except in a genuine medical emergency.
Body metrics — weight, height, BMI, body fat percentage — collected for fitness tracking are stored securely and accessible only to you and your trainer.
You may request correction or deletion of your health data at any time. Deletion will not affect your membership, but may limit our ability to provide personalised training recommendations.
We implement industry-standard technical and organisational security measures:
Despite our best efforts, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we commit to taking all reasonable steps to protect your data.
| Data category | Retention period | Reason |
|---|---|---|
| Active membership records | Duration of membership + 3 years | Legal disputes, Consumer Protection Act |
| Financial / payment records | 8 years from transaction date | GST and Income Tax Act obligations |
| Health & fitness data (PAR-Q) | Duration of membership + 1 year | Liability protection; deleted on request after cessation |
| CCTV footage | 30 days, overwritten automatically | Security monitoring; longer if an incident is under investigation |
| Marketing consent records | 3 years from last consent action | Meta / Google advertiser compliance |
| Website analytics (GA4) | 14 months | Service improvement |
| Email enquiries / lead forms | 2 years from last interaction | Business operations |
| Cancelled / lapsed memberships | 3 years from cancellation | Dispute resolution, re-joining |
Once retention periods expire, data is securely deleted or anonymised so that it can no longer be linked to an identifiable individual.
Under the Digital Personal Data Protection Act 2023, you have the following rights over your personal data:
| Right | What it means | How to exercise it |
|---|---|---|
| Information | Know what personal data we hold about you and how it is used | Written request to our Grievance Officer |
| Correction | Correct inaccurate or incomplete personal data | Email or in-person request at the gym |
| Erasure | Request deletion of your data, subject to legal retention obligations | Written request to our Grievance Officer |
| Withdraw consent | Withdraw any consent at any time, without affecting prior processing | Email, WhatsApp, or the unsubscribe link in our emails |
| Grievance redressal | Lodge a complaint with us and escalate to the Data Protection Board of India if unresolved | Contact our Grievance Officer (section 18) |
| Nominate | Nominate someone to exercise your rights in the event of death or incapacity | Written nomination submitted to us |
We respond to all valid requests within 30 days. Complex requests may take up to 45 days, with notice to you. We do not charge a fee for routine requests.
If you are dissatisfied with our response you may escalate to the Data Protection Board of India once it is operational under DPDPA 2023 rules. You may also seek redressal under the Consumer Protection Act 2019 or approach the Adjudicating Officer under the IT Act 2000.
Our services are intended for individuals aged 16 years and above. Members under 18 require written consent from a parent or legal guardian before enrolling.
Parents or guardians who believe their child's data has been collected without consent should contact our Grievance Officer immediately using the details in section 18.
DemiGod operates CCTV cameras across its premises for the safety and security of members, staff and property. By entering our premises you acknowledge and consent to being recorded.
DemiGod may photograph or film members, classes or events for marketing and social media purposes — Instagram, Facebook, YouTube and our website.
Photography and video release consent is a separate, voluntary opt-in during membership registration. Your membership is never conditional on granting it.
This section forms part of our overall terms of use. Your membership agreement contains a separate, signed liability waiver; this section supplements that waiver for website visitors and prospective members.
Physical exercise involves inherent risks including, but not limited to, muscular strain, joint injury, cardiovascular stress and, in rare cases, serious injury. By using DemiGod's facilities and services you acknowledge and accept these risks.
Some of our third-party service providers — Google LLC and Meta Platforms Inc. — are headquartered outside India and may process your data on servers in the United States or other countries.
As India's DPDPA 2023 rules on cross-border transfers are finalised and notified by the Government of India, we will update our practices and this policy accordingly.
We may update this Privacy Policy periodically to reflect changes in law, our services or our data practices. We will notify you of material changes by:
Your continued use of our services after the effective date of a revised policy constitutes acceptance of the updated terms. Previous versions are archived and available on request.
Current version effective 17 August 2026. Policy version 1.0.
In compliance with Rule 5(9) of the IT (SPDI) Rules 2011 and Section 13 of the DPDPA 2023, we have appointed a Grievance Officer to address data protection concerns and complaints.
We acknowledge complaints within 5 business days and aim to resolve them within 30 days. If unresolved, you may escalate to the Data Protection Board of India.
If you are unsatisfied with the resolution provided by our Grievance Officer, you have the right to approach:
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India, including but not limited to:
Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of New Delhi, India. Both parties agree to attempt resolution through good-faith negotiation before initiating formal legal proceedings.
If any provision of this Privacy Policy is found unenforceable or invalid under applicable law, that provision shall be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible. The remaining provisions continue in full force and effect.
For any query, request or concern regarding this Privacy Policy or your personal data, contact us through any of the following channels:
This Privacy Policy has been prepared in good faith to reflect applicable Indian law and platform advertising requirements as of August 2026. DemiGod will seek periodic review by a qualified Indian legal practitioner, particularly as DPDPA 2023 rules are fully implemented in Phase 2 from November 2026 onwards, and will update this document accordingly.