Data & compliance
Data handling for DACH gyms and members
Altor is built for European expectations: purpose limitation, data minimization, export, and deletion paths. Final legal packs (DPA, SCCs, sub-processor list) ship with enterprise agreements — this page states engineering and product intent today.
Where data lives
Production targets EU-region Postgres (Supabase-class) with TLS in transit and encryption at rest. Swiss operators should expect nFADP and GDPR overlap when members travel — we design for the stricter intersection, not the lowest common denominator.
Roles: controller vs processor
For gym-sourced member data, the gym is typically the controller for membership operations while Altor processes training and equipment events on documented instructions. Exact language is agreed per DPA — your counsel reviews before signature.
Member rights
- Access and portability — export of training history (product roadmap aligns with performance identity export).
- Erasure — cascading delete requirements are tracked in product specs; timelines follow contract SLAs once enterprise deals are live.
- Consent — explicit flows for health-adjacent feedback where regulators classify it as special-category data (legal review pending).
Security baseline
Multi-tenant RLS on shared schema, least-privilege service roles, no sale of personal data, no ad-tech embeds on consumer surfaces. Penetration tests and SOC reports follow customer demand — ask on a security review call.
Questions: support@altorstrength.com · Back to gym overview
Engineering intent brief — not legal advice. Final legal packs (DPA, SCCs, sub-processor list) are agreed per enterprise contract and reviewed by your counsel before signature.