Data & compliance

Data handling for DACH gyms and members

Altor is built for European expectations: purpose limitation, data minimization, export, and deletion paths. Final legal packs (DPA, SCCs, sub-processor list) ship with enterprise agreements — this page states engineering and product intent today.

Where data lives

Production targets EU-region Postgres (Supabase-class) with TLS in transit and encryption at rest. Swiss operators should expect nFADP and GDPR overlap when members travel — we design for the stricter intersection, not the lowest common denominator.

Roles: controller vs processor

For gym-sourced member data, the gym is typically the controller for membership operations while Altor processes training and equipment events on documented instructions. Exact language is agreed per DPA — your counsel reviews before signature.

Member rights

Security baseline

Multi-tenant RLS on shared schema, least-privilege service roles, no sale of personal data, no ad-tech embeds on consumer surfaces. Penetration tests and SOC reports follow customer demand — ask on a security review call.

Questions: support@altorstrength.com · Back to gym overview

Engineering intent brief — not legal advice. Final legal packs (DPA, SCCs, sub-processor list) are agreed per enterprise contract and reviewed by your counsel before signature.