PACE
// Privacy Policy
// Contents
  1. Scope & Definitions
  2. Who We Are
  3. Data on the Marketing Site
  4. Data from Fitness centre Operators
  5. Data About Fitness centre Members
  6. Biometric Face Templates
  7. Purposes & Legal Bases
  8. Disclosure & Sharing
  9. Retention & Deletion
  10. Security Measures
  11. Your Rights (DPDP)
  12. Children & Minors
  13. Cross-Border Transfers
  14. Cookies & Tracking
  15. Third-Party Services
  16. Breach Notification
  17. Changes to this Policy
  18. Contact

Privacy Policy

Last updated: 13 May 2026 · Version 1.0

This policy explains how Aureus Platforms Private Limited ("Pace", "we", "us") collects, uses, stores and protects personal data when you visit aureusos.in or use the Pace Operating System. It is written for compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

Data Fiduciary
Aureus Platforms Private Limited
Registered office
Thiruvananthapuram, Kerala, IN
Governing law
Republic of India
Contact
privacy@aureus.app

01 Scope & Definitions

This policy covers two distinct surfaces of Pace:

  1. The Marketing Site — the public website at aureusos.in that you are currently on. It exists to describe the product to prospective customers. It collects almost no personal data; see Section 3.
  2. The Pace Operating System ("the Product") — the web and Android application used by fitness centre operators to run their business, and the related member-facing experience. The Product collects significantly more data, including biometric face templates. See Sections 4–6.

Key terms used in this policy follow the DPDP Act:

  • Data Principal — the individual to whom the personal data relates (a website visitor, a fitness centre operator's staff member, or a fitness centre member).
  • Data Fiduciary — the entity that decides the purpose and means of processing.
  • Data Processor — an entity that processes personal data on behalf of a Data Fiduciary.
  • Customer — a fitness centre, fitness studio or operator that subscribes to the Pace Product.
  • Member — an end-user of a Customer's fitness centre whose data is processed inside the Product.

Important distinction

For data about Members, the Customer (the fitness centre) is the Data Fiduciary and Pace is a Data Processor acting on the Customer's documented instructions under the Master Subscription Agreement and Data Processing Addendum. For data about Customers themselves (the fitness centre operator and their staff using Pace Admin), Pace is the Data Fiduciary.

02 Who We Are

Pace is operated by Aureus Platforms Private Limited, a private limited company incorporated in India with its registered office in Thiruvananthapuram, Kerala.

03 Data We Collect on the Marketing Site

The marketing site has no signup form, no analytics SDK, no tracking pixels and sets no cookies. We are deliberately minimal here.

What our web server logs collect automatically when you visit:

  • IP address (truncated to the /24 network for IPv4 after 24 hours)
  • User-agent string (browser and OS family)
  • Requested URL and HTTP referer
  • Timestamp of the request

We retain these logs for a maximum of 90 days. They are used only for security monitoring, abuse prevention, and aggregated traffic statistics. We do not link them to any other dataset we hold.

When you tap any "Request Access" or CTA button, your browser is sent to WhatsApp using wa.me with our business number. From that moment onward, the conversation is governed by your messaging app's privacy practices (typically WhatsApp's, owned by Meta Platforms). The content of any WhatsApp message you send us is stored by us in our customer relationship records.

04 Data We Collect from Fitness centre Operators (Customers)

When a fitness centre subscribes to Pace, we collect the following from the Customer and their authorised staff (typically the fitness centre owner and any branch managers who log into Pace Admin):

4.1 Account information

  • Business name, GST number and registered business address
  • Owner / signatory name, email address, phone number
  • Staff members invited to Pace Admin (name, email, role)
  • Branch details (e.g. "Kochi Flagship")

4.2 Billing information

  • The selected subscription tier (Monthly, 6 Months, 12 Months)
  • Payment instrument metadata (UPI ID prefix, card last-four, payment method type) — full card numbers are never stored by Pace; they are handled exclusively by our PCI-DSS compliant payment gateway.
  • Invoices, payment timestamps and tax records (which Indian tax law requires us to retain for at least 8 financial years).

4.3 Product telemetry

  • Login timestamps and authentication events
  • Feature usage counts (which screens are opened, in aggregate)
  • Crash logs and error traces from Pace Admin
  • Approximate location of the device at login (city-level, derived from IP) — used only for fraud detection on unusual logins

05 Data About Fitness centre Members

Pace's role for member data

The data described in this section belongs to the Customer (the fitness centre). The Customer is the Data Fiduciary. Pace stores and processes this data solely on the Customer's behalf, in our role as a Data Processor under a written Data Processing Addendum. We do not use member data for our own purposes, do not sell it, and do not use it to train third-party AI systems.

The Product enables a Customer to record the following about its Members:

  • Full name and a member ID (e.g. AUR_0421) assigned by the Customer
  • Mobile phone number and (optionally) email
  • Date of birth and gender (optional — collected only if the Customer asks the Member for it during onboarding)
  • Membership plan (Monthly, Quarterly, Half-Yearly, Annual, Platinum) and due dates
  • Fee payment history — amounts, dates, payment method (UPI, card, cash), reference IDs
  • Attendance log — entry timestamp and scan latency for every successful or denied check-in
  • Personal-training session records (if the Customer uses Pace Coach, the trainer workspace)
  • Free-text notes the Customer's staff add about the Member
  • Biometric face template — see Section 6 below, which has its own consent regime

5.1 How members give consent

The Customer is responsible for obtaining each Member's informed, specific, free and unambiguous consent at the point of enrolment, in clear plain-language English or Malayalam, in line with DPDP Act §6. Pace provides the Customer with a default consent notice template inside the Product; the Customer remains responsible for actually presenting it and for retaining the consent record.

5.2 Members' rights against the fitness centre

Members exercising their DPDP rights (access, correction, erasure, grievance) should first contact the fitness centre at which they are enrolled. If the fitness centre does not resolve the request within 30 days, the Member may escalate to Pace using the contact details in Section 18 and we will work with the Customer to resolve the matter.

06 Biometric Face Templates

Sensitive personal data

Biometric data is classified as sensitive personal data or information under Rule 3 of the SPDI Rules, 2011 and receives heightened protection under the DPDP Act. We treat it accordingly.

6.1 What is actually stored

When a Member enrols on Pace Gate (our biometric entry experience), the camera at the fitness centre captures a sequence of frames. On-device, the BlazeFace ML model extracts a numerical face embedding — a fixed-length vector of floating-point numbers that represents the geometry of the face. We do not store the original photographs or video frames. The raw frames are discarded as soon as the embedding has been produced.

The embedding is stored encrypted-at-rest, tied to the Member's record inside the Customer's tenant. It is mathematically a one-way representation — it cannot be inverted to reconstruct a photograph of the Member's face.

6.2 What it is used for

  • To verify the Member's identity when they present themselves at the fitness centre's entry camera ("scan").
  • To produce the entry-allowed / entry-denied decision shown in the live check-in feed.
  • To enable the Ghost Protocol (automated access denial for Members whose payment is overdue beyond the grace period the Customer has configured).

Face embeddings are never:

  • Sold, licensed or shared with any third party.
  • Used to train Pace's models or any external model.
  • Pooled across Customers — each fitness centre's enrolment dataset is logically isolated.
  • Used for emotion detection, demographic inference, surveillance, or any purpose other than verifying Member identity at entry.

6.3 Alternative to biometric entry

A Member who does not consent to biometric enrolment must be offered a non-biometric alternative by the Customer (typically a personal QR code or PIN). Pace supports this in the Product. Refusing biometric enrolment must not be a condition of fitness centre membership.

6.4 Erasure

A face embedding is permanently deleted, with no recovery, in any of the following cases:

  • The Member requests deletion of their biometric data (the Customer can action this in one click in the Member Profile screen).
  • The Member leaves the fitness centre and the standard retention window of 30 days after exit has elapsed.
  • The Customer's subscription ends and the contractually agreed wind-down period expires (see Section 9).

07 Purposes & Legal Bases for Processing

PurposeLawful basisCategories of data
Operating the marketing site and answering enquiries Legitimate interest (DPDP §7(g)) IP, user-agent, WhatsApp message content
Providing the Product to Customers Performance of a contract (DPDP §7(b)) Account, billing, telemetry
Processing Member data inside the Product Documented instructions of the Customer; consent obtained by Customer (DPDP §6) Member PII, attendance, payments, face embedding
Tax and statutory record keeping Compliance with a legal obligation (DPDP §7(c)) Invoices, GST records, payment metadata
Security monitoring and abuse prevention Legitimate interest (DPDP §7(g)) Access logs, login metadata
Defending legal claims Legitimate interest (DPDP §7(i)) Any of the above, as relevant

08 Disclosure & Sharing

We do not sell personal data. We share data only with the following categories of recipients, under contract and only for the purposes listed:

  • Cloud infrastructure — vetted hosting providers within India used to run the Product. Data remains within India.
  • Payment gateway — handles card and UPI transactions. Pace does not see full card numbers or CVVs.
  • SMS / WhatsApp messaging — only the Member's phone number and the templated message body are shared with delivery partners when the Customer triggers a payment reminder.
  • Transactional email — used for invoices, password reset, and similar service notices.
  • Authorities — to comply with a legally binding request from an Indian court, regulator, or law-enforcement agency. We will, where legally permitted, notify the affected Customer.
  • Successor entity — in the event of a merger, acquisition or asset sale, the acquirer would inherit the obligations of this policy. We will notify Customers 30 days before such a transfer.

09 Data Retention & Deletion

CategoryRetention period
Marketing-site server access logs90 days
WhatsApp / sales enquiry records24 months after last interaction
Customer account & staff recordsDuration of subscription + 90 days
Member records (PII, attendance, fees)Controlled by the Customer; default 30 days after Member exits the fitness centre
Biometric face embeddingDeleted within 7 days of Member exit, or immediately on request
Invoices and tax records8 financial years (statutory minimum under the Income-tax Act)
Security audit logs12 months

When a Customer's subscription ends, we provide a 30-day window for the Customer to export their data. After this window, all Customer and Member data (except statutorily-required tax records) is permanently deleted from production systems within 60 days. Backup copies are purged within an additional 90 days under our normal backup-rotation cycle.

10 Security Measures

We follow the "Reasonable Security Practices and Procedures" expected under Rule 8 of the SPDI Rules and the DPDP Act's requirement to protect personal data through reasonable safeguards. Specifically:

  • Encryption in transit — TLS 1.2 or higher on every public endpoint, with HSTS preload.
  • Encryption at rest — AES-256 on databases, file storage and backups; biometric embeddings are additionally wrapped with a per-Customer key.
  • Access control — role-based access in Pace Admin, mandatory multi-factor authentication for Pace staff with production access.
  • Network — production database has no public network surface; access is brokered through a bastion with auditable session logging.
  • Software supply chain — third-party JavaScript on the marketing site is pinned to exact versions and protected with Subresource Integrity hashes (verifiable in the page source).
  • Logging — every read of biometric data is logged with the operator identity and outcome.
  • Backup — encrypted daily snapshots with point-in-time recovery for the last 30 days.
  • Testing — vulnerability scans on every release and periodic independent penetration tests.

No security system is perfect; if you discover a vulnerability please contact us at security@aureus.app. We commit to acknowledging vulnerability reports within 72 hours.

11 Your Rights as a Data Principal

Under the DPDP Act you have the following rights:

  • Right to information (§11) about what personal data of yours we hold and how it is processed.
  • Right to correction and erasure (§12) of inaccurate or outdated data.
  • Right of grievance redressal (§13) using the contact details in Section 18.
  • Right to nominate (§14) another individual to exercise these rights on your behalf in case of death or incapacity.
  • Right to withdraw consent (§6(4)) as easily as it was given — for example, by replying STOP to a WhatsApp message, or by deleting biometric enrolment from the Pace Fit.

To exercise any of these rights, email privacy@aureus.app with the subject "DPDP request". We will respond within 30 days. If we cannot verify your identity from the request, we may ask you for additional information solely for that verification.

If you are a Member and your request concerns data held in your fitness centre's account, you should first approach the fitness centre (see Section 5.2).

12 Children & Minors

The Product is sold to and used by adult fitness centre operators. We do not knowingly solicit data from anyone under 18 through the marketing site.

When a Customer enrols a Member who is below 18, the Customer must obtain verifiable parental consent before any data — and in particular any biometric data — is recorded. The Customer is solely responsible for this verification. Pace will not knowingly process a minor's data for any purpose that profiles them or could cause detrimental effects, as required by DPDP §9.

13 Cross-Border Transfers

All personal data is processed and stored within India by default. If, in the future, we use a service provider whose servers are located outside India, we will transfer data only to jurisdictions that have not been restricted by the Central Government under DPDP §16, and only where contractual safeguards equivalent to this policy are in place.

14 Cookies & Tracking Technologies

The marketing site sets no cookies. It loads no analytics SDKs, no advertising pixels, no fingerprinting scripts. You can verify this by opening your browser's developer-tools Application tab and confirming the cookies list is empty.

The Product (Pace Admin) sets a single first-party cookie — a session cookie — strictly necessary to keep an operator logged in. This cookie is marked HttpOnly, Secure, and SameSite=Lax, and is deleted on logout.

15 Third-Party Services Loaded by this Page

The marketing site loads the following third-party assets so the page can render. None of them have access to data we hold; they only serve fonts, icons, animation libraries and similar utilities:

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — serves the Inter typeface. Subject to Google's privacy policy.
  • jsDelivr (cdn.jsdelivr.net) — serves the Remix Icon webfont. Logs the IP address of incoming requests, per its own policy.
  • unpkg (unpkg.com) — serves the Lenis smooth-scroll library.
  • cdnjs / Cloudflare (cdnjs.cloudflare.com) — serves the GSAP animation library.

Every third-party asset is pinned to an exact version and verified by Subresource Integrity (SRI) hash. If the bytes ever change, the browser refuses to execute the resource.

16 Personal Data Breach Notification

If Pace suffers a personal data breach that is likely to result in a risk to your rights, we will notify the Data Protection Board of India and the affected Data Principals without undue delay, as required under DPDP §8(6). Notifications will include the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures we have taken to mitigate impact.

For breaches concerning Member data, we will notify the Customer (as Data Fiduciary) without undue delay so they can in turn notify the affected Members.

17 Changes to this Policy

We may revise this policy from time to time. The "Last updated" date at the top reflects the most recent revision. We will notify Customers of material changes by email at least 15 days before the change takes effect. Continued use of the Product after the effective date constitutes acceptance of the revised policy.

Historical versions are available on request.

18 Contact

For privacy questions, access or correction requests, or other processing matters, email privacy@aureus.app.

For grievance redressal under the DPDP Act and the SPDI Rules, email grievance@aureus.app. We will acknowledge your message within 48 hours and aim to resolve grievances within 30 days of receipt. If you remain dissatisfied, you may refer the matter to the Data Protection Board of India once established under the DPDP Act.

← PACE
WAITLIST LEGAL PRIVACY TERMS CONTACT
AUREUS PLATFORMS PRIVATE LIMITED