English
English

Privacy Policy

Last updated: August 5, 2026

When you buy a subscription at the Gymly, or if you place an order via our website (www.gymly.io), we require some of your personal data. We are happy to explain why we need this personal data and what we do with this data in this Privacy Statement.

Gymly believes privacy is important so is very committed to protecting the privacy of its members. Personal data is therefore carefully stored, processed and secured by us. Gymly carefully complies with all obligations arising from the General Data Protection Regulation (Regulation (EU) 2016/679) and other privacy legislation. Gymly B.V. registered at the Chamber of Commerce with number 86153528 and its office is located at Herengracht 406 in (1017 BX) Amsterdam.


What personal data do we collect?

The personal data that we store and process are: First and last name; Sex; Date of birth; E-mail address; (Mobile) phone number; Address data; Bank details; Information about your visit to the gyms; Transaction data from orders; Operating system IP addresses and browser type and timestamps; Health and fitness data (body weight and body fat percentage), only if you choose to connect Apple Health or Health Connect. We use this information for the following purposes: creating a membership; drafting, sending and drawing up invoices; providing information; improving our services; answering questions asked via, for example, the website; to fulfill our obligations arising from contracts we have with you, as well as for billing and delivery. The legal ground for the processing is contractual necessity and legal obligations (our obligations towards the Tax Authority for example). For health and fitness data the legal ground is your explicit consent, as described below. Gymly does not use automated decision-making or profiling with regard to your personal data.


Health and fitness data

The Gymly app can connect to Apple Health (HealthKit) on iOS and Health Connect on Android so you can keep your training and body composition data in one place. This connection is optional and stays switched off until you turn it on yourself.

What we access and collect

When you enable the connection, we read the following data from Apple Health or Health Connect:

  • Body weight

  • Body fat percentage

On Android this requires the permissions android.permission.health.READ_WEIGHT and android.permission.health.READ_BODY_FAT. We only read data. We do not access any other health category, and we do not read historical data beyond what is needed to show your progress.

Why we use it

We use this data for one purpose only: to show your progress inside the Gymly app and, if you choose to share it, to make it visible to the gym, studio or trainer where you are a member so they can support your training. We do not use health data for advertising, marketing, market research, data mining, profiling or automated decision-making, and we do not use it to determine pricing or eligibility.

Your consent

Health data is a special category of personal data under Article 9 of the General Data Protection Regulation. We only process it on the basis of your explicit consent, which you give through the permission prompt on your device. You can withdraw your consent at any time:

  • iOS: Settings, Privacy & Security, Health, Gymly

  • Android: the Health Connect app, App permissions, Gymly

  • Or by revoking the connection in the Gymly app settings

Withdrawing consent stops any further reading of your health data immediately. It does not affect the lawfulness of processing that took place before you withdrew.

Sharing

We never sell or trade your health data and we never share it with advertisers, data brokers or any other third party for their own purposes. Health data obtained through Apple Health or Health Connect is not transferred to third parties. It is only accessible to you, to the fitness organisation where you hold a membership, and to the sub-processors that host our platform under a data processing agreement.

Storage, security and retention

Health data is transmitted over an encrypted connection and stored encrypted on servers located in the Netherlands. We do not store health data in iCloud or in any other consumer cloud service. We keep it for as long as your connection is active. If you withdraw your consent, disconnect the integration or delete your account, the health data we obtained is deleted from our systems within 30 days, unless we are legally required to keep it longer.

Requesting deletion

You can request deletion of your health data at any time by disconnecting the integration in the app or by emailing info@gymly.io. Deleting data in Gymly does not delete it from Apple Health or Health Connect, and deleting it there does not automatically remove copies already stored in Gymly, so use both if you want it gone everywhere.


Provision of personal data to third parties

We do not sell or trade personal data and do not provide personal data to third parties without your explicit permission.


Processors

To provide our services, we use processors. We use cloud based software from Google. We use the payment Services from Adyen N.V. and we use Sendgrid to send our newsletters.


Your rights

You always have the right to inspect the personal data that we keep about you. If this information is incorrect, you can help us correct it. You also have the right to ask us to delete your personal data or to make your personal data available to you on a data carrier. You have the right to restrict or object the processing. Requests for this are always honored. You can exercise these rights by sending an email to the contact address on the site.


How long do we keep your personal data?

We keep your personal data for as long as necessary for the realization of the purposes for which we process your personal data. After you have canceled your membership, your data will be stored for a maximum of 7 years. Health and fitness data is an exception and is deleted within 30 days after you withdraw your consent, disconnect the integration or delete your account.


Security and Storage

Due to the nature of our services and the trust you must be able to place in us, taking into account the state of the art and the implementation costs, we take appropriate technical and organizational measures to ensure that the processing of personal data takes place in accordance with the General Data Protection Regulation. We only store the data in the Netherlands and have verified that our partners also only store your data in a country that the Personal Data Authority has classified as adequate or that the necessary measures have been taken to ensure the security of personal data.


Dutch Data Protection Authority

Of course we are happy to help you if you have complaints about the processing of your personal data. Under the privacy law you also have the right to file a complaint with the Dutch Data Protection Authority against this processing of personal data. You can contact the Dutch Data Protection Authority for this.


Modifications

Gymly reserves the right to adjust and change its privacy statement. If you have a question, please contact us at info@gymly.io.

Designed & Engineered by fitness and tech lover from Amsterdam. (Em)Powered by the industry.

Designed & Engineered by fitness and tech lover from Amsterdam. (Em)Powered by the industry.

Carefully engineered to empower your community, and to let you focus on what really matters.