Data Protection Policy

Privacy & Data Governance Policy

Compliance Standard: International Data Protection & Fiscal Security Mandates

1. Information We Collect

The IronCore Gym Chain POS & ERP System processes information strictly necessary for operational gym management, membership lifecycle tracking, and statutory fiscal compliance:

  • Member Profiles: Full name, National Identity / Passport Number, phone number, email address, gender, date of birth, and emergency contact details.
  • Physical Attendance & Access Records: Biometric / Turnstile verification timestamps and check-in history across branch locations.
  • Financial Transactions: Invoice items, base amounts, payment methods (Cash, Card, Digital Wallets), and calculated sales taxes.
  • System Audit Logs: User actor credentials, role, timestamp, IP address, and previous vs new state diffs on all data mutations.

2. Multi-Jurisdiction Fiscal Compliance & Transmission

In accordance with applicable sales tax and digital invoicing regulations, transactional data including Buyer Name, Tax Identification, invoice totals, and calculated taxes are transmitted electronically via secure adapters to designated regulatory authorities:

Provincial / Regional Tax Authorities

Transmitted via encrypted HTTPS payloads for service invoicing at regional fitness branches.

Central / Federal Tax Authorities

Transmitted for capital territory services and retail merchandise goods across chain locations.

3. Multi-Branch Tenant Data Security

The system employs multi-layered architectural safeguards to guarantee data privacy:

  • Branch Scoping Isolation: Front-desk staff can only query member data and transactions associated with their authorized branch ID.
  • Encryption in Transit: All HTTP communications require TLS 1.3 encryption.
  • Password Hashing: User account passwords are cryptographically salted using bcrypt with high cost factors.
  • Immutable Audit Ledgers: All system changes, invoice voids, and role actions are permanently recorded for forensic accountability.

4. Member Rights & Data Retention

Gym members have the right to inspect their active membership status, verify invoice fiscal receipts via the official digital QR code, and request corrections to their profile information through their home gym branch administration.

Transactional records and general ledgers are retained in accordance with statutory accounting retention requirements (minimum of 6 to 10 years as mandated by international corporate accounting standards).

5. Contacting Our Data Privacy Team

For inquiries regarding data governance, system security audits, or compliance disclosures, please contact:

IronCore Global Legal & Compliance Directorate
Metropolitan Center, Executive Tower, Suite 1000
Email: legal@ironcoregym.com
← Read Terms of Service© 2026 Aigentro Corporation. All rights reserved.