Skip to content

Command palette

Search for a page to open.

Legal

Privacy Policy

Last updated: September 20, 2026

This policy explains what we collect, why we collect it and the controls you have. The short version: your content is yours, we never train on it, and we keep as little as possible for as short as possible.

Who this covers

This policy covers www.gymkeeper.fi and the GymKeeper service, both provided by Gymkeeper Oy, business ID 3650234-4, Mekaanikonkatu 15A, 00880 Helsinki, Finland. It sets out what we collect, why, who else sees it, how long we keep it and what you can ask us to do about it.

We follow Finnish national law and European Union law on privacy and data protection, including the General Data Protection Regulation (EU) 2016/679.

Whose data is whose

Where a gym, club or other organisation uses GymKeeper to manage its own members, that organisation decideswhat data is collected and why. It is the controller; Gymkeeper Oy processes that data on the organisation’s behalf and on its instructions, and for nothing else.

If you are a member of a gym that runs on GymKeeper, questions about your own data are best put to that gym first. We will help them answer you, but it is their register.

For the people we deal with directly — account holders, billing and support contacts, and visitors to this website — Gymkeeper Oy is the controller.

Information we collect

We collect information you provide directly, information generated by your use of the services, and limited information from third parties. In practice, this means:

  • Account data — first and last name, email address, the organisation you belong to, and billing details (card data is held by our payment processor, never on our servers). Anything further is optional: a phone number, a staff or worker number, a preferred language and time zone.
  • Customer content — the data you run your business on: uploaded images, product and pricing data, course and booking data, the records of your own customers and their memberships, and whatever else GymKeeper needs in order to operate for you.
  • Usage data — timestamps, IP address, device and browser information, a record of actions taken in the admin, and diagnostics from errors.
  • Support data — messages you send our support team and, where you opt in, session diagnostics.

Signing in

We do not store a password for you. Signing in uses a one-time code sent to your email address or phone, a single-use sign-in link, or an external identity provider such as Google. When you sign in through an external provider, that provider confirms who you are to us — we never see or receive the password you use with them.

Administrator accounts belonging to gym staff may still use a password. Where one is set, it is stored only as a one-way hash — currently bcrypt — which cannot be turned back into the original password.

How we use your information

We use personal data to run the service for you: operating the software itself, working out what you owe and invoicing it, keeping accounts and doors secure against misuse, and answering you when you contact support.

We send the messages the service needs to send — invoices and receipts among them. Marketing email is separate: it is optional, and every one carries an unsubscribe link, added by the sending code rather than left to whoever wrote the campaign. We do not sell personal data, and we do not share it with third parties for their own advertising.

AI features

We do not train AI models on your data, and we do not sell it. GymKeeper uses an external AI provider for two things: reading a discount or membership card from a photograph when a member submits one, and drafting text for your staff in the product, article and email editors.

Card recognition sends the photograph, which carries the cardholder’s name, to that provider so it can be read back as text. It runs only when somebody submits a card, and only for gyms that have the feature switched on. The provider operates in the United States, so this is a transfer out of the European Union — see below. Whether these features are used at all is your decision: they are off unless you switch them on.

Sharing and subprocessors

We do not sell or rent your data. We share it with the service providers that host and operate GymKeeper on our behalf — hosting and backups, email and SMS delivery, payment processing, error monitoring — under contract and only so that they can provide those services to us.

Beyond that, which third parties see a given gym’s data depends on what that gym has switched on: a payment provider, an accounting or e-invoicing system, a campaign mailer, a parcel service. A gym that takes only Paytrail should not be asked to approve Stripe, Smartum, Netvisor and an American AI provider, so we produce the list per gym from its own configuration and attach it to the data processing agreement. Ask us and we will send you yours.

We may disclose information when required by law or to protect the rights and safety of our users. If Gymkeeper Oy or the GymKeeper business is acquired, merged with another company or sold, the data described in this policy may transfer to the acquiring party as part of that transaction. The acquiring party remains bound by this policy until you are notified otherwise, and we will notify you before any such transfer takes effect.

Data retention

Your customer content is kept for as long as your account is open — it is the register you run your business from, and deleting it on a timer would defeat the point. What has a fixed period is what happens afterwards:

  • After an account closes — you can export your data for 30 days, after which it is deleted from the live systems.
  • Accounting records — invoices, receipts and the records that support them are kept for the period Finnish bookkeeping law requires, whatever else has been deleted.
  • Backups — backups rotate on a schedule: daily copies for 30 days, weekly for 12 weeks, monthly for 12 months. A record you delete today disappears from the live system immediately and then ages out of the backups, which can take up to a year for the oldest monthly copy.
  • Logs and diagnostics — kept for a limited period for security, billing accuracy and troubleshooting, then discarded.

Security

Traffic to and from GymKeeper is encrypted with TLS 1.2 or better; older versions of the protocol are refused. Access to production systems goes through single sign-on, is limited to the small number of people who need it, and supports multi-factor authentication, which we recommend enabling. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you without undue delay and within any legally mandated window.

International data transfers

We keep your data in your own region. A customer in the European Union is served by services located in the European Union — servers, mail delivery and the rest — and a customer in the United States by services located there.

One thing leaves that region, and it is yours to decide. The AI features described above are provided by Anthropic, in the United States. If a gym in the European Union switches card recognition on, the photograph a member submits — which carries their name — is sent there to be read; text drafted in the product, article and email editors is processed there too. Where personal data crosses a border this way we rely on the EU Standard Contractual Clauses.

Those features are off unless you turn them on, and you can turn them off again. Leave them off and nothing in your account is processed outside your own region.

Your rights and choices

Depending on where you live (including under GDPR and CCPA), you have the right to:

  • Access, correct or delete the personal data we hold about you.
  • Receive your data in a portable format. Ask us and we will put it together for you — there is no self-service button for it yet.
  • Object to or restrict certain processing, and withdraw consent where processing is based on it.
  • Lodge a complaint with your local supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

You can exercise these rights from your account settings, by emailing privacy@gymkeeper.fi, or by writing to the postal address below. There is no charge, we respond within one month, and we never discriminate against anyone for exercising a right.

If you are a member of a gym rather than our own customer, see whose data is whose above — the gym holds the register, and we will help them answer you.

Cookies and tracking

This website sets no analytics cookies, no advertising cookies and no cross-site tracking pixels. Nothing here follows you anywhere else.

The application sets the cookies it needs in order to work: one that keeps you signed in for the length of your session, and a few that remember choices such as your language and which location you are working in. You can block cookies in your browser’s settings, but signing in will stop working if you do.

Contacting us through this site

When you send us a message or a trial request from this site, what you type is emailed to us and used to answer you and to prepare the trial you asked for. We keep it while it is useful for that, and we do not pass it to anyone else. We will not add you to a mailing list unless you asked to be on one — and if you are on one, every message carries a link to leave it.

Changes to this policy and contact

We may update this policy as the services and the law evolve. For material changes we will notify workspace admins by email at least 30 days before the change takes effect; the "last updated" date above always reflects the current version.

The controller for the personal data described in this policy is Gymkeeper Oy, business ID 3650234-4, Mekaanikonkatu 15A, 00880 Helsinki, Finland.

Questions or concerns? Contact our privacy team at privacy@gymkeeper.fi, or by post to the address above.

Related

See also our Terms of Service.