Last Updated: 29 September 2026
This Privacy Policy explains how Bitbox OÜ ("Bitbox," "we," "us," or "our") collects, uses, discloses, and protects personal data when you access or use GymGate (the "Service").
This Policy is intended to comply with the EU General Data Protection Regulation (GDPR) and is designed for global use.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
For purposes of GDPR, Bitbox OÜ acts primarily as a data processor when processing personal data on behalf of gyms, studios and other fitness schools using the Service, and as a data controller for limited data related to its own business operations.
This Privacy Policy applies to:
It does not apply to personal data processed by gyms or schools outside of the Service.
Depending on how the Service is used, we may process the following categories of personal data:
Payment card information is not stored by Bitbox OÜ. Payments are processed by third-party payment providers.
Gyms can show their GymGate class schedule on their own websites. When you open such a page, your browser requests the schedule from GymGate and sends us:
We use this only to deliver the schedule, and we do so as a processor on behalf of the gym, as for other gym data. Your IP address is used to answer the request and is not stored. We keep the website's address so the gym can see where its schedule appears; it says nothing about you.
We process personal data only when at least one lawful basis applies:
Where Bitbox OÜ acts as a data processor, processing is based on the instructions of the customer (data controller).
We use personal data to:
GymGate may process personal data relating to children, as many members are minors.
Bitbox OÜ does not collect children’s data directly. All such data is submitted and controlled by the gym or school, which is responsible for:
If personal data is transferred outside the EU/EEA, appropriate safeguards are used, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs).
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy.
Customer-submitted data is retained for the duration of the customer’s account and is typically deleted or anonymized within 30 days of account termination, unless a longer retention period is required by law for tax or legal compliance.
We may share personal data with:
All subprocessors are bound by contractual obligations consistent with GDPR requirements.
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and regular security monitoring. However, no system can be guaranteed to be 100% secure.
Where applicable, individuals have the right to:
Requests should be directed to the relevant gym or school (data controller). Bitbox OÜ will assist controllers as required.
GymGate uses only strictly necessary cookies for authentication, session management, security, and fraud prevention.
Because we do not use tracking or advertising cookies, we do not show a cookie consent banner. You can control cookie settings through your browser, but the Service may not function correctly without these essential cookies.
The schedule widget on gym websites sets no cookies at all.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email. Continued use of the Service constitutes acceptance of the updated Policy.
For questions about this Privacy Policy or data protection matters, contact:
Bitbox OÜ
solutions.bitbox@gmail.com
Kirsi tn 4-21, 76606, Keila, Estonia
This Privacy Policy is provided as a general template and does not constitute legal advice. You should have this document reviewed by qualified legal counsel before use.