Legal
What personal information we collect, why we hold it, how long we keep it, and what you can make us do about it. Written to meet the Protection of Personal Information Act, which is the law that actually governs us.
Last updated 22 August 2026 Effective 22 August 2026 Governed by South African law
01
GymFlow Labs decides how your personal information is used, which under POPIA makes us the responsible party. Here is who to contact.
GymFlow Labs (Pty) Ltd is the responsible party for the personal information described in this policy, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA).
Our Information Officer is responsible for how we handle personal information and for dealing with your requests.
02
Details you give us, plus basic technical data about how you use the site. We do not collect special personal information about you.
Information you give us:
Information we collect automatically:
We do not knowingly collect special personal information as defined in section 26 of POPIA, meaning information about health, religion, race, politics, trade union membership, biometrics or criminal history. Do not send it to us. If you do, we will delete it.
03
Mostly to answer you, deliver what you asked for, run your systems, and keep records. Each purpose has a lawful basis under POPIA.
| What we do | Why | Lawful basis (POPIA s11) |
|---|---|---|
| Reply to enquiries | Answer your question, book and hold a call | Steps at your request before a contract |
| Send a requested guide | Deliver the resource you asked for | Consent |
| Deliver our services | Build, run and support your systems | Performance of a contract |
| Billing and records | Invoice, account, and meet tax obligations | Legal obligation |
| Marketing emails | Send gym growth material you signed up for | Consent, withdrawable at any time |
| Improve the site | Understand what is read and what is not | Legitimate interests |
| Security and fraud prevention | Protect our systems and yours | Legitimate interests |
Where we rely on consent, you may withdraw it at any time. That does not affect processing already carried out before you withdrew it.
04
When we run systems for your gym, we handle your members' data on your instructions. You stay responsible for it. We do not use it for anything of our own.
This section matters if you are a gym we work with, because it covers information about your members and leads rather than about you.
When we build and manage systems in your GoHighLevel account, we process that information as an operator under sections 20 and 21 of POPIA. You remain the responsible party.
That means:
Your obligations do not transfer to us. You are responsible for having a lawful basis to hold your members' information and to contact them.
05
A short list of service providers who help us operate. We do not sell your information to anyone, ever.
We do not sell your personal information. We share it only with providers who help us operate, and only as far as they need it:
| Provider | What for | Where |
|---|---|---|
| GoHighLevel | CRM, forms, email and SMS, client portal | United States |
| Workspace email, analytics | United States, EU | |
| Meta | Advertising and measurement, where used | United States |
| Payment providers | Collecting fees from clients | South Africa |
We may also disclose information where the law requires it, to establish or defend a legal claim, or to protect the rights and safety of people.
Several of the providers above host data outside South Africa, mainly in the United States. Section 72 of POPIA permits this where the recipient is bound by rules providing an adequate level of protection, or where you consent, or where the transfer is necessary to perform a contract with you.
We rely on the contractual terms these providers offer, which bind them to protect the information and restrict what they may do with it.
06
Specific periods, not 'as long as necessary'. Anything past its period gets deleted or anonymised.
| Information | Kept for | Why |
|---|---|---|
| Enquiries that did not become clients | 24 months from last contact | Conversations often restart |
| Marketing list subscribers | Until you unsubscribe, then 12 months | Proof of the opt-out |
| Client records and correspondence | 5 years after the engagement ends | Contractual and legal claims |
| Invoices and financial records | 5 years | Required by tax law |
| Website analytics | 14 months | Year-on-year comparison |
When a period ends, we delete the information or anonymise it so it can no longer identify you. Where a legal hold applies, we keep it until that ends.
07
You can ask what we hold, correct it, delete it, object to it, and complain about it. Free, within 30 days.
Under sections 23 to 25 of POPIA, you may:
To exercise any of these, email [email protected]. We will confirm your identity, then respond within 30 days. There is no charge, unless a request is clearly excessive or repetitive.
POPIA also gives you a right of access under the Promotion of Access to Information Act. Our PAIA manual is available on request.
08
Come to us first. If we do not resolve it, the Information Regulator is the authority for South Africa.
If you think we have mishandled your personal information, contact our Information Officer at [email protected] first. We would rather fix it directly.
If you are not satisfied, you may lodge a complaint with the regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: [email protected]
General: [email protected]
Telephone: 010 023 5200
If you are in the European Union or the United Kingdom, and the GDPR or UK GDPR applies to our processing of your information, you may also complain to your national supervisory authority. We do not target our services at those regions, so this will rarely apply.
09
Reasonable safeguards, and an honest commitment: if there is a breach, we tell you and the Regulator.
We take reasonable technical and organisational steps to protect personal information, including access controls, encryption in transit, limiting who on our team can see what, and choosing providers with credible security practices.
No system is perfectly secure, and we will not claim otherwise. Sending information over the internet carries risk.
If personal information under our control is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and you. We will do so as soon as reasonably possible after establishing what happened, and tell you what was affected and what to do about it.
10
Our services are for gym owners. We do not market to or knowingly collect information about children.
We sell to businesses. Our Services are not directed at children, and we do not knowingly collect the personal information of anyone under 18.
POPIA gives children's information particular protection under section 34. If you believe we hold information about a child, contact [email protected] and we will delete it.
Where a gym we work with holds information about members under 18, that is the gym's responsibility as the responsible party, and competent consent must be in place.
11
We will update this as things change, and tell you directly if a change is material.
We may update this policy to reflect changes in how we work or what the law requires. The date at the top shows when it last changed.
Where a change materially affects your rights or how we use your information, we will notify you directly rather than relying on you to check this page.
Questions about any of this, or want to talk about what a system would look like for your gym?
Book a call