Privacy Notice
Who we are
LeadRX is a gym and fitness facility management platform. When your organization uses LeadRX, the organization (gym, box, or fitness facility) is the data controller for member data, and LeadRX acts as the data processor on their behalf. For data about organization administrators and account holders who interact directly with LeadRX, LeadRX is the data controller.
What data we process
We process the following categories of personal data, classified by sensitivity:
Identity and contact data (name, email, phone, date of birth, gender, emergency contacts) โ used for account management, membership administration, and communication. Lawful basis: contract performance and legitimate interest.
Health-adjacent data (workout results, readiness signals, and performance notes) โ used for fitness tracking and coaching where that module is enabled. Lawful basis: explicit consent or contract performance where the service inherently involves fitness tracking.
Financial data (billing amounts, transaction descriptions) โ used for membership billing and accounting. Lawful basis: contract performance and legal obligation.
Communications data (messages between staff and members) โ used for service delivery. Lawful basis: contract performance and legitimate interest.
Technical data (session identifiers, audit logs, device identifiers for kiosk check-in) โ used for security, authentication, and platform integrity. Lawful basis: legitimate interest.
How long we keep your data
We retain personal data only as long as necessary for the purposes described above and in compliance with legal requirements:
Identity and contact data is retained for the duration of your organization membership plus a deletion grace period, and is erased or anonymized after a valid request unless a legal retention exception applies. Health-adjacent data is retained for a configurable period (default: 3 years). Communications content is retained for up to 2 years or per organization policy. Financial records are retained for a minimum of 7 years to comply with tax and audit obligations. Audit logs are retained for 7 years for compliance evidence. Session and authentication tokens are retained for the session lifetime plus 30 days.
Your rights
Under the General Data Protection Regulation (GDPR), you have the right to access your personal data, request rectification of inaccurate data, request erasure of your data (right to be forgotten), restrict processing, data portability, and object to processing. You also have the right to withdraw consent at any time where processing is based on consent, and the right to lodge a complaint with your national data protection authority.
To exercise any of these rights, submit a Data Subject Access Request through your organization administrator or contact us directly at privacy@leadrx.eu. Identity verification is required before we process any request.
Data security
We implement technical and organizational measures to protect personal data, including encrypted sessions, audit logging with PII redaction, role-based access control, tenant isolation, and secret detection in configuration surfaces. For more details, see our Security Overview.
Subprocessors
We use a limited number of subprocessors to deliver our service. A current list is available on our GDPR and Data Rights page. We notify organization administrators before adding new subprocessors.
Contact
For privacy inquiries: privacy@leadrx.eu
For general inquiries, visit our Contact page.
This privacy notice was last updated in May 2026.