Privacy Policy
This policy explains how Aureus Platforms Private Limited ("Pace", "we", "us") collects, uses, stores and protects personal data when you visit aureusos.in or use the Pace Operating System. It is written for compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
01 Scope & Definitions
This policy covers two distinct surfaces of Pace:
- The Marketing Site — the public website at
aureusos.inthat you are currently on. It exists to describe the product to prospective customers. It collects almost no personal data; see Section 3. - The Pace Operating System ("the Product") — the web and Android application used by fitness centre operators to run their business, and the related member-facing experience. The Product collects significantly more data, including biometric face templates. See Sections 4–6.
Key terms used in this policy follow the DPDP Act:
- Data Principal — the individual to whom the personal data relates (a website visitor, a fitness centre operator's staff member, or a fitness centre member).
- Data Fiduciary — the entity that decides the purpose and means of processing.
- Data Processor — an entity that processes personal data on behalf of a Data Fiduciary.
- Customer — a fitness centre, fitness studio or operator that subscribes to the Pace Product.
- Member — an end-user of a Customer's fitness centre whose data is processed inside the Product.
Important distinction
For data about Members, the Customer (the fitness centre) is the Data Fiduciary and Pace is a Data Processor acting on the Customer's documented instructions under the Master Subscription Agreement and Data Processing Addendum. For data about Customers themselves (the fitness centre operator and their staff using Pace Admin), Pace is the Data Fiduciary.
02 Who We Are
Pace is operated by Aureus Platforms Private Limited, a private limited company incorporated in India with its registered office in Thiruvananthapuram, Kerala.
03 Data We Collect on the Marketing Site
The marketing site has no signup form, no analytics SDK, no tracking pixels and sets no cookies. We are deliberately minimal here.
What our web server logs collect automatically when you visit:
- IP address (truncated to the /24 network for IPv4 after 24 hours)
- User-agent string (browser and OS family)
- Requested URL and HTTP referer
- Timestamp of the request
We retain these logs for a maximum of 90 days. They are used only for security monitoring, abuse prevention, and aggregated traffic statistics. We do not link them to any other dataset we hold.
When you tap any "Request Access" or CTA button, your browser is sent to
WhatsApp using wa.me with our business number. From that moment
onward, the conversation is governed by your messaging app's privacy practices
(typically WhatsApp's, owned by Meta Platforms). The content of any WhatsApp
message you send us is stored by us in our customer relationship records.
04 Data We Collect from Fitness centre Operators (Customers)
When a fitness centre subscribes to Pace, we collect the following from the Customer and their authorised staff (typically the fitness centre owner and any branch managers who log into Pace Admin):
4.1 Account information
- Business name, GST number and registered business address
- Owner / signatory name, email address, phone number
- Staff members invited to Pace Admin (name, email, role)
- Branch details (e.g. "Kochi Flagship")
4.2 Billing information
- The selected subscription tier (Monthly, 6 Months, 12 Months)
- Payment instrument metadata (UPI ID prefix, card last-four, payment method type) — full card numbers are never stored by Pace; they are handled exclusively by our PCI-DSS compliant payment gateway.
- Invoices, payment timestamps and tax records (which Indian tax law requires us to retain for at least 8 financial years).
4.3 Product telemetry
- Login timestamps and authentication events
- Feature usage counts (which screens are opened, in aggregate)
- Crash logs and error traces from Pace Admin
- Approximate location of the device at login (city-level, derived from IP) — used only for fraud detection on unusual logins
05 Data About Fitness centre Members
Pace's role for member data
The data described in this section belongs to the Customer (the fitness centre). The Customer is the Data Fiduciary. Pace stores and processes this data solely on the Customer's behalf, in our role as a Data Processor under a written Data Processing Addendum. We do not use member data for our own purposes, do not sell it, and do not use it to train third-party AI systems.
The Product enables a Customer to record the following about its Members:
- Full name and a member ID (e.g.
AUR_0421) assigned by the Customer - Mobile phone number and (optionally) email
- Date of birth and gender (optional — collected only if the Customer asks the Member for it during onboarding)
- Membership plan (Monthly, Quarterly, Half-Yearly, Annual, Platinum) and due dates
- Fee payment history — amounts, dates, payment method (UPI, card, cash), reference IDs
- Attendance log — entry timestamp and scan latency for every successful or denied check-in
- Personal-training session records (if the Customer uses Pace Coach, the trainer workspace)
- Free-text notes the Customer's staff add about the Member
- Biometric face template — see Section 6 below, which has its own consent regime
5.1 How members give consent
The Customer is responsible for obtaining each Member's informed, specific, free and unambiguous consent at the point of enrolment, in clear plain-language English or Malayalam, in line with DPDP Act §6. Pace provides the Customer with a default consent notice template inside the Product; the Customer remains responsible for actually presenting it and for retaining the consent record.
5.2 Members' rights against the fitness centre
Members exercising their DPDP rights (access, correction, erasure, grievance) should first contact the fitness centre at which they are enrolled. If the fitness centre does not resolve the request within 30 days, the Member may escalate to Pace using the contact details in Section 18 and we will work with the Customer to resolve the matter.
06 Biometric Face Templates
Sensitive personal data
Biometric data is classified as sensitive personal data or information under Rule 3 of the SPDI Rules, 2011 and receives heightened protection under the DPDP Act. We treat it accordingly.
6.1 What is actually stored
When a Member enrols on Pace Gate (our biometric entry experience), the camera at the fitness centre captures a sequence of frames. On-device, the BlazeFace ML model extracts a numerical face embedding — a fixed-length vector of floating-point numbers that represents the geometry of the face. We do not store the original photographs or video frames. The raw frames are discarded as soon as the embedding has been produced.
The embedding is stored encrypted-at-rest, tied to the Member's record inside the Customer's tenant. It is mathematically a one-way representation — it cannot be inverted to reconstruct a photograph of the Member's face.
6.2 What it is used for
- To verify the Member's identity when they present themselves at the fitness centre's entry camera ("scan").
- To produce the entry-allowed / entry-denied decision shown in the live check-in feed.
- To enable the Ghost Protocol (automated access denial for Members whose payment is overdue beyond the grace period the Customer has configured).
Face embeddings are never:
- Sold, licensed or shared with any third party.
- Used to train Pace's models or any external model.
- Pooled across Customers — each fitness centre's enrolment dataset is logically isolated.
- Used for emotion detection, demographic inference, surveillance, or any purpose other than verifying Member identity at entry.
6.3 Alternative to biometric entry
A Member who does not consent to biometric enrolment must be offered a non-biometric alternative by the Customer (typically a personal QR code or PIN). Pace supports this in the Product. Refusing biometric enrolment must not be a condition of fitness centre membership.
6.4 Erasure
A face embedding is permanently deleted, with no recovery, in any of the following cases:
- The Member requests deletion of their biometric data (the Customer can action this in one click in the Member Profile screen).
- The Member leaves the fitness centre and the standard retention window of 30 days after exit has elapsed.
- The Customer's subscription ends and the contractually agreed wind-down period expires (see Section 9).
07 Purposes & Legal Bases for Processing
| Purpose | Lawful basis | Categories of data |
|---|---|---|
| Operating the marketing site and answering enquiries | Legitimate interest (DPDP §7(g)) | IP, user-agent, WhatsApp message content |
| Providing the Product to Customers | Performance of a contract (DPDP §7(b)) | Account, billing, telemetry |
| Processing Member data inside the Product | Documented instructions of the Customer; consent obtained by Customer (DPDP §6) | Member PII, attendance, payments, face embedding |
| Tax and statutory record keeping | Compliance with a legal obligation (DPDP §7(c)) | Invoices, GST records, payment metadata |
| Security monitoring and abuse prevention | Legitimate interest (DPDP §7(g)) | Access logs, login metadata |
| Defending legal claims | Legitimate interest (DPDP §7(i)) | Any of the above, as relevant |
09 Data Retention & Deletion
| Category | Retention period |
|---|---|
| Marketing-site server access logs | 90 days |
| WhatsApp / sales enquiry records | 24 months after last interaction |
| Customer account & staff records | Duration of subscription + 90 days |
| Member records (PII, attendance, fees) | Controlled by the Customer; default 30 days after Member exits the fitness centre |
| Biometric face embedding | Deleted within 7 days of Member exit, or immediately on request |
| Invoices and tax records | 8 financial years (statutory minimum under the Income-tax Act) |
| Security audit logs | 12 months |
When a Customer's subscription ends, we provide a 30-day window for the Customer to export their data. After this window, all Customer and Member data (except statutorily-required tax records) is permanently deleted from production systems within 60 days. Backup copies are purged within an additional 90 days under our normal backup-rotation cycle.
10 Security Measures
We follow the "Reasonable Security Practices and Procedures" expected under Rule 8 of the SPDI Rules and the DPDP Act's requirement to protect personal data through reasonable safeguards. Specifically:
- Encryption in transit — TLS 1.2 or higher on every public endpoint, with HSTS preload.
- Encryption at rest — AES-256 on databases, file storage and backups; biometric embeddings are additionally wrapped with a per-Customer key.
- Access control — role-based access in Pace Admin, mandatory multi-factor authentication for Pace staff with production access.
- Network — production database has no public network surface; access is brokered through a bastion with auditable session logging.
- Software supply chain — third-party JavaScript on the marketing site is pinned to exact versions and protected with Subresource Integrity hashes (verifiable in the page source).
- Logging — every read of biometric data is logged with the operator identity and outcome.
- Backup — encrypted daily snapshots with point-in-time recovery for the last 30 days.
- Testing — vulnerability scans on every release and periodic independent penetration tests.
No security system is perfect; if you discover a vulnerability please contact us at security@aureus.app. We commit to acknowledging vulnerability reports within 72 hours.
11 Your Rights as a Data Principal
Under the DPDP Act you have the following rights:
- Right to information (§11) about what personal data of yours we hold and how it is processed.
- Right to correction and erasure (§12) of inaccurate or outdated data.
- Right of grievance redressal (§13) using the contact details in Section 18.
- Right to nominate (§14) another individual to exercise these rights on your behalf in case of death or incapacity.
- Right to withdraw consent (§6(4)) as easily as it was given — for example, by replying STOP to a WhatsApp message, or by deleting biometric enrolment from the Pace Fit.
To exercise any of these rights, email privacy@aureus.app with the subject "DPDP request". We will respond within 30 days. If we cannot verify your identity from the request, we may ask you for additional information solely for that verification.
If you are a Member and your request concerns data held in your fitness centre's account, you should first approach the fitness centre (see Section 5.2).
12 Children & Minors
The Product is sold to and used by adult fitness centre operators. We do not knowingly solicit data from anyone under 18 through the marketing site.
When a Customer enrols a Member who is below 18, the Customer must obtain verifiable parental consent before any data — and in particular any biometric data — is recorded. The Customer is solely responsible for this verification. Pace will not knowingly process a minor's data for any purpose that profiles them or could cause detrimental effects, as required by DPDP §9.
13 Cross-Border Transfers
All personal data is processed and stored within India by default. If, in the future, we use a service provider whose servers are located outside India, we will transfer data only to jurisdictions that have not been restricted by the Central Government under DPDP §16, and only where contractual safeguards equivalent to this policy are in place.
15 Third-Party Services Loaded by this Page
The marketing site loads the following third-party assets so the page can render. None of them have access to data we hold; they only serve fonts, icons, animation libraries and similar utilities:
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) — serves the Inter typeface. Subject to Google's privacy policy. - jsDelivr (
cdn.jsdelivr.net) — serves the Remix Icon webfont. Logs the IP address of incoming requests, per its own policy. - unpkg (
unpkg.com) — serves the Lenis smooth-scroll library. - cdnjs / Cloudflare (
cdnjs.cloudflare.com) — serves the GSAP animation library.
Every third-party asset is pinned to an exact version and verified by Subresource Integrity (SRI) hash. If the bytes ever change, the browser refuses to execute the resource.
16 Personal Data Breach Notification
If Pace suffers a personal data breach that is likely to result in a risk to your rights, we will notify the Data Protection Board of India and the affected Data Principals without undue delay, as required under DPDP §8(6). Notifications will include the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures we have taken to mitigate impact.
For breaches concerning Member data, we will notify the Customer (as Data Fiduciary) without undue delay so they can in turn notify the affected Members.
17 Changes to this Policy
We may revise this policy from time to time. The "Last updated" date at the top reflects the most recent revision. We will notify Customers of material changes by email at least 15 days before the change takes effect. Continued use of the Product after the effective date constitutes acceptance of the revised policy.
Historical versions are available on request.
18 Contact
For privacy questions, access or correction requests, or other processing matters, email privacy@aureus.app.
For grievance redressal under the DPDP Act and the SPDI Rules, email grievance@aureus.app. We will acknowledge your message within 48 hours and aim to resolve grievances within 30 days of receipt. If you remain dissatisfied, you may refer the matter to the Data Protection Board of India once established under the DPDP Act.