Privacy Policy
This policy explains how Alchemetryx Consulting Pvt Ltd handles your data when you use Fitosys. Written in plain English — no legalese.
1. Who We Are
Alchemetryx Consulting Pvt Ltd operates Fitosys, a SaaS platform for independent fitness, wellness, and yoga coaches. We are registered in India. Our platform is accessible at fitosys.alchemetryx.com.
Data Controller (India — DPDP Act 2023):
Alchemetryx Consulting Private Limited
Email: fitosys@alchemetryx.com
Data Processors acting on our behalf are listed in Section 5 of this policy.
2. What Data We Collect
Fitosys has two types of users: Coaches and their Clients.
Coach Data
- Full name, email address, WhatsApp number
- Coaching type, timezone, check-in preferences
- Razorpay payment details (processed by Razorpay, not stored by us)
- GST number, business name, billing address (optional, for invoice generation)
- IP address (for security and rate limiting, retained 90 days)
Client Data (collected on behalf of coaches)
- Full name, WhatsApp number, email address, age
- Primary fitness/wellness goal
- Health notes (optional, provided voluntarily)
- Weekly check-in responses (energy scores, sessions completed, free-text notes)
- Payment records (Razorpay payment ID, amount, date)
- Enrollment start and end dates
- Consent timestamps
3. Why We Collect It (Legal Basis)
- •Coach account data: Contract — necessary to deliver the service
- •Client personal data: Legitimate interest of coach (coaching relationship) + explicit consent
- •Health data (energy scores, wellness notes): Explicit consent — collected only with specific opt-in
- •Payment data: Contract + Legal obligation (GST/tax records, retained 7 years)
- •WhatsApp communication data: Explicit consent — collected via intake form opt-in
- •IP addresses: Legitimate interest (fraud prevention, platform security)
4. How We Use Your Data
- Deliver automated WhatsApp check-ins and renewal reminders
- Generate AI-powered weekly coaching summaries (processed by Google Gemini API)
- Generate GST-compliant invoices
- Enable coach dashboard and client management
- Improve platform performance and reliability
5. Who We Share Data With
| Third Party | Role | Data Processed | Legal Basis | Privacy Policy |
|---|---|---|---|---|
| Supabase (ap-south-1, Mumbai) | Database hosting and authentication | All user and client data | Contract | supabase.com/privacy |
| Vercel (Global Edge Network) | Application hosting, serverless functions, edge computing | IP addresses, request logs, application data | Contract | vercel.com/legal/privacy-policy |
| Razorpay | Payment processing and subscription billing | Payment details, name, email, billing address | Contract + Legal obligation | razorpay.com/privacy |
| Meta / WhatsApp Business Platform | Message delivery and WhatsApp API infrastructure | Phone numbers, message content, delivery status | Contract + Consent | facebook.com/policy |
| Google (Gemini API) | AI-powered weekly coaching summary generation | Check-in response text only — no names or phone numbers transmitted | Contract | policies.google.com/privacy |
| Resend | Transactional email delivery | Name, email address, invoice PDF | Contract | resend.com/privacy |
| OpenRouter | AI program description generation | Program title and category only — no PII transmitted | Contract | openrouter.ai/privacy |
We never sell your data. We never share it for advertising purposes.
5A. Meta Platform Data
Fitosys uses Meta's WhatsApp Business Platform to send automated messages to clients on behalf of coaches. We access and process the following Meta Platform Data:
- WhatsApp phone numbers of enrolled clients
- Message delivery status and read receipts
- WhatsApp Business Account (WABA) information
- Message template performance data
How we use Meta Platform Data
- To deliver automated weekly check-in messages to clients
- To send program renewal reminders to clients
- To send enrollment confirmation messages
- To monitor message delivery quality
How we do NOT use Meta Platform Data
- We do not use it for advertising or marketing purposes
- We do not sell or transfer it to third parties
- We do not use it to build profiles beyond the coaching relationship
- We do not combine it with data from other Meta products for targeting
Retention: Meta Platform Data is retained for 1 year rolling in our WhatsApp message log and then permanently deleted.
Compliance: Our use of Meta Platform Data complies with Meta's Platform Terms and WhatsApp Business Policy. Coaches are responsible for ensuring clients have provided consent before enrollment.
6. Where Your Data Is Stored
- Primary database: Supabase (region: ap-south-1, Mumbai, India)
- File storage (invoices): Supabase Storage (same region)
- Hosting: Vercel (global edge network)
- AI processing: Google Gemini API (check-in text only, no names or phone numbers sent)
7. How Long We Keep Your Data
- Coach and client records: 3 years from last active date
- Payment and invoice records: 7 years (Indian tax law requirement)
- WhatsApp message logs: 1 year rolling
- IP addresses: 90 days
- Deleted accounts: PII wiped within 30 days, anonymised payment records retained for tax
8. Your Rights
India (DPDP Act 2023)
- Right to access your data
- Right to correct inaccurate data
- Right to erase your data (submit request to fitosys@alchemetryx.com)
- Right to withdraw consent at any time
- Right to nominate a representative for data access
UK / EU (GDPR)
- All above rights plus right to data portability and restriction of processing
- Right to lodge a complaint with the ICO (ico.org.uk)
To exercise any right, email: fitosys@alchemetryx.com. Response within 30 days.
8A. Public Authority and Government Data Requests
Required legal review:
All requests from public authorities for user data undergo mandatory legal review before any data is disclosed. We do not comply with informal or unverified requests.
Challenging unlawful requests:
We reserve the right to challenge any request we believe to be overbroad or unlawful. Where legally permitted, we will notify affected users before disclosing their data.
Data minimization:
In response to any lawful authority request, we disclose only the minimum data required to satisfy the specific legal obligation.
Documentation:
We maintain records of all public authority requests received, the legal basis cited, and the data disclosed. Records retained for 7 years.
History:
Fitosys has received zero public authority or national security requests for user data since inception (as of May 2026).
9. WhatsApp Communications
Fitosys sends automated WhatsApp messages on behalf of coaches to their clients. These include:
- Weekly check-in messages (every Sunday)
- Program renewal reminders
- Enrollment confirmation messages
These messages are sent only to clients who have explicitly opted in on the enrollment form.
Clients can opt out at any time by replying STOP to any message or contacting their coach. See our WhatsApp Communication Policy.
10. Cookies
We use only essential cookies for authentication (httpOnly, secure). No advertising cookies. No third-party tracking pixels. No cookie consent banner required.
11. Children
Our platform is not intended for users under 18. Coaches must not enroll clients under 18 without verified parental consent. We do not knowingly collect data from minors.
12. Changes to This Policy
We will notify coaches via email and dashboard notification before material changes take effect. Continued use after the effective date constitutes acceptance.
13. Contact and Grievance Officer
For privacy concerns or to exercise your rights:
Email: fitosys@alchemetryx.com
Phone: +917738363495
Grievance Officer (India): Ashok Kumar, Alchemetryx Consulting Pvt Ltd
Response time: Within 30 days