Security and governance
This page describes how ALAS TECHNOLOGY LLC protects the data of people who use Gym+, how we respond to security incidents and how to report a vulnerability. The processing of personal data itself is covered by the Privacy policy.
1. Governance and certifications
ALAS TECHNOLOGY LLC holds the ISO/IEC 27001 and ISO/IEC 27701 certifications and runs an information security and privacy management system under those standards. The system assigns responsibilities, assesses risks at regular intervals and documents the controls applied to Gym+, described in section 2.
ISO/IEC certifications: Information Security Management 27001:2022 (Certificate Q7LUQTCU20251113BRAIS1Z1), Privacy Information Management 27701:2025 (Certificate Q7LUQTCU20251113BRAPI15R) and Compliance Management System 37301:2021 (Certificate Q7LUQTCC20251113BRACM1X7). Check the certificates (opens in a new tab)
2. Security controls
- Encryption in transit: all communication between the app, this website and our server must use HTTPS. The app refuses any redirect that would carry a credential.
- Encryption at rest: data stored on the server is encrypted at rest; what we store about subscriptions is additionally encrypted with AES-256-GCM, and account and installation identifiers are stored as cryptographic digests.
- Data minimisation: we process only what each purpose described in the privacy policy needs. Health data, the training log and the exact location coordinate never leave the device.
- Access control: access to production systems is limited to the people who need it to run the service, with strong authentication and periodic review of permissions. In the app, session credentials live in memory only and are discarded when you sign out.
- Logging and audit: access to production systems and administrative actions are logged, and those logs are reviewed to detect misuse.
- No trackers: the app ships no advertising or analytics SDK.
The retention period for each category of data and the processors that handle data on our behalf are set out in the privacy policy, section 12, and in the privacy policy, section 11.
3. Incident response
No system is unbreakable. We maintain an incident response procedure to detect, contain, assess and remedy any security incident. If an incident may result in relevant risk or harm to data subjects, we notify Brazil's National Data Protection Authority (ANPD) and the affected data subjects within the deadline set by the ANPD's regulations. For people in the European Economic Area, the United Kingdom or Switzerland, we notify the competent supervisory authority within 72 hours of becoming aware of the incident and, where the risk is high, we inform the affected data subjects without undue delay, as the GDPR requires (arts. 33 and 34).
4. Data protection officer
Our data protection officer (the encarregado under the LGPD) oversees this management system and is the point of contact for data subjects and authorities: privacy@gymplus.life. Your rights as a data subject are set out in the privacy policy, section 14 (LGPD) and section 15 (GDPR).
5. How to report a vulnerability
If you have found a security flaw in the Gym+ app, our server or this website, write to security@gymplus.life. The contact details are also published at https://gymplus.life/.well-known/security.txt.
What to include
- the affected part: the app (with platform and version), the server or the website, and the address or screen where the flaw appears;
- a description of the flaw and the impact you believe it has;
- the steps to reproduce it, with the requests, screenshots or proof-of-concept code needed;
- how we can reach you, if you want to follow the fix.
Do not include other people's personal data. If you accessed any by accident, say so in the report and do not keep a copy.
What we do
We acknowledge every report, assess the flaw, keep you informed of progress and let you know when it has been fixed.
Coordinated disclosure
We ask that you do not disclose the flaw publicly, or to third parties, before it has been fixed or before we have agreed a disclosure date with you.
Good-faith research
We will not take legal action against anyone who researches and reports a vulnerability in good faith, in line with this page, and respects users' privacy. That means:
- testing only with your own account or with accounts you created for the test;
- not accessing, changing, deleting or keeping other people's data beyond the minimum needed to demonstrate the flaw;
- not degrading the service, for example through denial of service or bulk messaging;
- not using social engineering, phishing or physical access against users or the company;
- stopping the test and telling us as soon as you realise you have accessed data that is not yours.
6. Contact
- Vulnerabilities and security: security@gymplus.life
- Privacy and data protection officer: privacy@gymplus.life
ALAS TECHNOLOGY LLC · EIN 93-3927200