Privacy Notice
Last updated: 12 August 2026
1. Who we are
Gymnaly is a gym management platform operated by Clicxo ("Clicxo", "we", "us"). Clicxo is the data controller for the personal data described in this notice, meaning we decide why and how that data is processed.
You can reach us about anything in this notice at contact@getgymly.com or on WhatsApp at +961 81 950 451.
Where a gym uses Gymnaly to manage its own members, the gym is the controller of its member records and Clicxo acts as a processor on the gym's instructions for that data.
2. Personal data we collect
- Account data — name, email address, password credentials, gym name and role (owner, trainer, trainee).
- Gym and member records — member profiles, memberships, class and PT bookings, workout programs, attendance and body metrics that you or your gym choose to record.
- Support and enquiry data — messages, contact details and attachments you send us by form, email or WhatsApp.
- Usage and technical data — log entries, device and browser information, IP address, pages viewed and feature usage.
- Subscription data — plan, status, renewal dates and billing-related identifiers we receive from our payment provider. We do not collect or store your card details.
3. Why we process it, and our legal basis
- Providing the service — creating accounts, running gym operations, delivering features you use. Legal basis: performance of a contract.
- Customer support — answering enquiries and resolving issues. Legal basis: performance of a contract and legitimate interests.
- Security and fraud prevention — protecting accounts, detecting abuse, keeping audit logs. Legal basis: legitimate interests and legal obligation.
- Product improvement — understanding how features are used in aggregate. Legal basis: legitimate interests.
- Service and marketing emails — transactional notices are sent on the basis of contract; optional marketing is sent with consent and can be withdrawn at any time.
- Legal and accounting obligations — retaining records we are required to keep. Legal basis: legal obligation.
4. Who we share data with
- Service providers (subprocessors) — hosting, database, email delivery and analytics providers who process data on our instructions under contract.
- Merchant of Record — Paddle.com. Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders and processes payments, subscription management, invoicing, sales-tax compliance, customer billing enquiries and refunds. Paddle acts as a controller for the data it collects for these purposes; see the Paddle privacy notice.
- Professional advisers — legal, accounting and audit advisers where needed.
- Authorities — where disclosure is required by law or to protect legal rights.
We do not sell personal data.
5. International transfers
Our providers may process data in countries outside your own, including the European Economic Area and the United States. Where required, transfers are protected by appropriate safeguards such as Standard Contractual Clauses or an adequacy decision. You can request details of the safeguards used by contacting us.
6. Retention
- Account and gym records: kept while the account is active, then deleted or anonymised within 90 days of closure, unless a longer period is legally required.
- Contact and support messages: up to 24 months.
- Security and access logs: up to 12 months.
- Billing and tax records: retained for the period required by applicable law (typically up to 10 years) — largely held by Paddle as Merchant of Record.
When data is no longer needed for these purposes we delete or anonymise it.
7. Your rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, data portability, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. To exercise a right, email contact@getgymly.com. We respond within one month. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection supervisory authority.
If your data was entered by a gym that uses Gymnaly, we may forward your request to that gym as the controller of those records.
8. Security
We apply appropriate technical and organisational measures, including encryption in transit, encryption of data at rest by our hosting provider, row-level access controls in our database, role-based access for staff, and least-privilege credentials. No system is completely secure, so we also monitor for abuse and keep incident procedures in place.
9. Cookies and similar technologies
We use strictly necessary cookies and local storage to keep you signed in and to secure the service. Where we use analytics cookies to understand aggregate usage, they are not used to build advertising profiles. You can clear or block cookies in your browser settings, but the service may not function correctly without the essential ones. Our payment provider may set cookies during checkout.
10. Children
Gymnaly is intended for gym operators and their adult members. Where a gym records data about a minor, the gym is responsible for obtaining any consent required by local law.
11. Changes to this notice
We may update this notice as the service evolves. Material changes will be announced in the app or by email, and the "last updated" date above will change.
