Gym+ Gym+

EN Languages

Security and governance

Version 1.0Effective 22 September 2026Applies to the Gym+ app and this website

This page describes how ALAS TECHNOLOGY LLC protects the data of people who use Gym+, how we respond to security incidents and how to report a vulnerability. The processing of personal data itself is covered by the Privacy policy.

1. Governance and certifications

ALAS TECHNOLOGY LLC holds the ISO/IEC 27001 and ISO/IEC 27701 certifications and runs an information security and privacy management system under those standards. The system assigns responsibilities, assesses risks at regular intervals and documents the controls applied to Gym+, described in section 2.

ISO/IEC certifications: Information Security Management 27001:2022 (Certificate Q7LUQTCU20251113BRAIS1Z1), Privacy Information Management 27701:2025 (Certificate Q7LUQTCU20251113BRAPI15R) and Compliance Management System 37301:2021 (Certificate Q7LUQTCC20251113BRACM1X7). Check the certificates (opens in a new tab)

2. Security controls

The retention period for each category of data and the processors that handle data on our behalf are set out in the privacy policy, section 12, and in the privacy policy, section 11.

3. Incident response

No system is unbreakable. We maintain an incident response procedure to detect, contain, assess and remedy any security incident. If an incident may result in relevant risk or harm to data subjects, we notify Brazil's National Data Protection Authority (ANPD) and the affected data subjects within the deadline set by the ANPD's regulations. For people in the European Economic Area, the United Kingdom or Switzerland, we notify the competent supervisory authority within 72 hours of becoming aware of the incident and, where the risk is high, we inform the affected data subjects without undue delay, as the GDPR requires (arts. 33 and 34).

4. Data protection officer

Our data protection officer (the encarregado under the LGPD) oversees this management system and is the point of contact for data subjects and authorities: privacy@gymplus.life. Your rights as a data subject are set out in the privacy policy, section 14 (LGPD) and section 15 (GDPR).

5. How to report a vulnerability

If you have found a security flaw in the Gym+ app, our server or this website, write to security@gymplus.life. The contact details are also published at https://gymplus.life/.well-known/security.txt.

What to include

Do not include other people's personal data. If you accessed any by accident, say so in the report and do not keep a copy.

What we do

We acknowledge every report, assess the flaw, keep you informed of progress and let you know when it has been fixed.

Coordinated disclosure

We ask that you do not disclose the flaw publicly, or to third parties, before it has been fixed or before we have agreed a disclosure date with you.

Good-faith research

We will not take legal action against anyone who researches and reports a vulnerability in good faith, in line with this page, and respects users' privacy. That means:

6. Contact

ALAS TECHNOLOGY LLC · EIN 93-3927200