Privacy Policy
Version 2026-01 · Effective January 15, 2026 · Last updated May 1, 2026
What this covers
This policy explains what data OpenGym collects, why, how we use it, and the rights you have over it. It applies to anyone who visits opengym.in, uses our mobile app, or transacts on our marketplace.
OpenGym Mozgás Kft. is the data controller. Our Data Protection Officer can be reached at dpo@opengym.in.
1. Information we collect
We collect three categories of personal data:
- You give us: email, name, profile photo, language preference, payment-card details (held by Stripe, not us), emergency contact, government ID (only if we ask for verification).
- From your use: sessions you book, vouchers you hold, reviews you write, devices and browsers you sign in from, IP address, approximate location (city-level) for currency display.
- From others: if you sign in with Google, Facebook, or X — your email and name from those providers.
2. How we use it
- To deliver tickets, vouchers, and reminders for sessions you've booked.
- To enforce safety — verifying Expert credentials, checking attendees at the door.
- To improve the product, anonymously, in aggregate.
- To meet our legal obligations (invoicing, tax reporting, fraud prevention).
- To send you marketing — only with your explicit opt-in, with a clear unsubscribe link.
5. Your rights under GDPR
If you're in the EU/UK you have the right to:
- Access the personal data we hold about you.
- Correct anything that's wrong.
- Delete your account and most associated data — see retention.
- Object — to our payment processing. We never see your full card number.
- Receive your data in a portable format.
- Complain to the Hungarian NAIH or your local supervisory authority.
To exercise any of these rights, email dpo@opengym.in from your account email. We respond within 30 days.
6. Data retention
Most personal data is deleted when you close your account. Order, payment, and invoice records are retained for 7 years as required by Hungarian tax law, but they are anonymised: your name and email are replaced with internal identifiers.
7. International transfers
Some of our processors (Stripe, email delivery) operate outside the EU. Where data leaves the EU, we rely on the European Commission's Standard Contractual Clauses and, where applicable, additional safeguards.
8. Security
We use TLS everywhere, encrypted backups, MFA for staff access, and least-privilege internal controls. We notify affected users and the supervisory authority of any breach within 72 hours, as GDPR requires.
9. Children
OpenGym is for adults 16+. We don't knowingly collect data from children. If you're a parent who has discovered an under-16 account, please contact us and we'll close it.
10. Changes
When we make material changes to this policy we'll notify registered users by email at least 14 days before they take effect.
11. Contact
Questions? Email dpo@opengym.in or write to OpenGym Mozgás Kft., Budapest, Hungary.