Legal

Privacy policy.

What personal information we collect, why we hold it, how long we keep it, and what you can make us do about it. Written to meet the Protection of Personal Information Act, which is the law that actually governs us.

Last updated 22 August 2026 Effective 22 August 2026 Governed by South African law

01

Who is responsible for your information

In plain terms

GymFlow Labs decides how your personal information is used, which under POPIA makes us the responsible party. Here is who to contact.

GymFlow Labs (Pty) Ltd is the responsible party for the personal information described in this policy, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA).

Our Information Officer is responsible for how we handle personal information and for dealing with your requests.

Legal name
GymFlow Labs (Pty) Ltd
Registration
2026/029274/07
Legal status
Private company, South Africa
Address
1460 Green Bay Eco Estate,
Gordons Bay, Western Cape, 7135
Information Officer
Andrew Todd
Email
[email protected]
Telephone
+27 72 258 5004
Website
gymflowlabs.com

02

What we collect

In plain terms

Details you give us, plus basic technical data about how you use the site. We do not collect special personal information about you.

Information you give us:

  • Contact details. Name, email address, phone number, gym name, and role, when you book a call, request a guide, or complete a form.
  • Business information. Member numbers, current systems, and goals, when you share them with us during a consultation or onboarding.
  • Correspondence. What you write to us by email, WhatsApp or through a form.
  • Client account information. Where you become a client, the details needed to build and run your systems, and the billing details needed to invoice you.

Information we collect automatically:

  • Usage data. Pages viewed, time on page, referring site, and the links you follow.
  • Device and technical data. IP address, browser, operating system, and approximate location at city level from your IP address.

We do not knowingly collect special personal information as defined in section 26 of POPIA, meaning information about health, religion, race, politics, trade union membership, biometrics or criminal history. Do not send it to us. If you do, we will delete it.

03

Why we process it, and on what basis

In plain terms

Mostly to answer you, deliver what you asked for, run your systems, and keep records. Each purpose has a lawful basis under POPIA.

What we doWhyLawful basis (POPIA s11)
Reply to enquiriesAnswer your question, book and hold a callSteps at your request before a contract
Send a requested guideDeliver the resource you asked forConsent
Deliver our servicesBuild, run and support your systemsPerformance of a contract
Billing and recordsInvoice, account, and meet tax obligationsLegal obligation
Marketing emailsSend gym growth material you signed up forConsent, withdrawable at any time
Improve the siteUnderstand what is read and what is notLegitimate interests
Security and fraud preventionProtect our systems and yoursLegitimate interests

Where we rely on consent, you may withdraw it at any time. That does not affect processing already carried out before you withdrew it.

04

Your members' information, when you are a client

In plain terms

When we run systems for your gym, we handle your members' data on your instructions. You stay responsible for it. We do not use it for anything of our own.

This section matters if you are a gym we work with, because it covers information about your members and leads rather than about you.

When we build and manage systems in your GoHighLevel account, we process that information as an operator under sections 20 and 21 of POPIA. You remain the responsible party.

That means:

  • We process your members' information only on your instructions, to deliver the services you have engaged us for.
  • We do not use it for our own marketing, do not sell it, and do not merge it with data from other clients.
  • We keep it confidential and require the same of anyone on our team who touches it.
  • On termination, access reverts to you. The data stays in your account, which you control.
  • We will tell you immediately if we become aware of any compromise, so you can meet your own obligations under section 22.

Your obligations do not transfer to us. You are responsible for having a lawful basis to hold your members' information and to contact them.

05

Who else sees it

In plain terms

A short list of service providers who help us operate. We do not sell your information to anyone, ever.

We do not sell your personal information. We share it only with providers who help us operate, and only as far as they need it:

ProviderWhat forWhere
GoHighLevelCRM, forms, email and SMS, client portalUnited States
GoogleWorkspace email, analyticsUnited States, EU
MetaAdvertising and measurement, where usedUnited States
Payment providersCollecting fees from clientsSouth Africa

We may also disclose information where the law requires it, to establish or defend a legal claim, or to protect the rights and safety of people.

Sending information outside South Africa

Several of the providers above host data outside South Africa, mainly in the United States. Section 72 of POPIA permits this where the recipient is bound by rules providing an adequate level of protection, or where you consent, or where the transfer is necessary to perform a contract with you.

We rely on the contractual terms these providers offer, which bind them to protect the information and restrict what they may do with it.

06

How long we keep it

In plain terms

Specific periods, not 'as long as necessary'. Anything past its period gets deleted or anonymised.

InformationKept forWhy
Enquiries that did not become clients24 months from last contactConversations often restart
Marketing list subscribersUntil you unsubscribe, then 12 monthsProof of the opt-out
Client records and correspondence5 years after the engagement endsContractual and legal claims
Invoices and financial records5 yearsRequired by tax law
Website analytics14 monthsYear-on-year comparison

When a period ends, we delete the information or anonymise it so it can no longer identify you. Where a legal hold applies, we keep it until that ends.

07

Your rights

In plain terms

You can ask what we hold, correct it, delete it, object to it, and complain about it. Free, within 30 days.

Under sections 23 to 25 of POPIA, you may:

  • Ask what we hold about you, and get a copy.
  • Correct or complete information that is wrong or out of date.
  • Ask us to delete information we no longer have grounds to keep.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time, where consent is the basis.
  • Opt out of direct marketing, immediately and permanently.
  • Not be subject to a decision made only by automated means that significantly affects you.

To exercise any of these, email [email protected]. We will confirm your identity, then respond within 30 days. There is no charge, unless a request is clearly excessive or repetitive.

POPIA also gives you a right of access under the Promotion of Access to Information Act. Our PAIA manual is available on request.

08

Complaining about how we handle it

In plain terms

Come to us first. If we do not resolve it, the Information Regulator is the authority for South Africa.

If you think we have mishandled your personal information, contact our Information Officer at [email protected] first. We would rather fix it directly.

If you are not satisfied, you may lodge a complaint with the regulator:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: [email protected]
General: [email protected]
Telephone: 010 023 5200

If you are in the European Union or the United Kingdom, and the GDPR or UK GDPR applies to our processing of your information, you may also complain to your national supervisory authority. We do not target our services at those regions, so this will rarely apply.

09

How we protect it, and what happens if that fails

In plain terms

Reasonable safeguards, and an honest commitment: if there is a breach, we tell you and the Regulator.

We take reasonable technical and organisational steps to protect personal information, including access controls, encryption in transit, limiting who on our team can see what, and choosing providers with credible security practices.

No system is perfectly secure, and we will not claim otherwise. Sending information over the internet carries risk.

If personal information under our control is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and you. We will do so as soon as reasonably possible after establishing what happened, and tell you what was affected and what to do about it.

10

Children

In plain terms

Our services are for gym owners. We do not market to or knowingly collect information about children.

We sell to businesses. Our Services are not directed at children, and we do not knowingly collect the personal information of anyone under 18.

POPIA gives children's information particular protection under section 34. If you believe we hold information about a child, contact [email protected] and we will delete it.

Where a gym we work with holds information about members under 18, that is the gym's responsibility as the responsible party, and competent consent must be in place.

11

Changes to this policy

In plain terms

We will update this as things change, and tell you directly if a change is material.

We may update this policy to reflect changes in how we work or what the law requires. The date at the top shows when it last changed.

Where a change materially affects your rights or how we use your information, we will notify you directly rather than relying on you to check this page.

Questions about any of this, or want to talk about what a system would look like for your gym?

Book a call