Software publisher

Publisher’s privacy policy

This page describes what PT. LTVT CAPITAL GROUP, publisher of FirstGym Tech, does with the data it processes on its own behalf: trial requests, client gyms, visitors to firstgym.tech.

Last updated: 9 August 2026

Are you a gym member?

This page is not for you. Your data is handled by your gym, not by us on our own behalf. Contact your gym: its privacy policy, the one shown in its app, is the one that applies. The details are in section 4.

1. The short version

2. Who processes your data

Data controller
PT. LTVT CAPITAL GROUP
Address
Jalan Pantai Batu Mejan Nomor 33A, RT. 000, Canggu, Kuta Utara, Kabupaten Badung, Bali, Indonesia
NPWP
10.979.476.8-906.000 — NPWP16: 0109 7947 6890 6000
Contact
contact@firstgym.tech

Full company details are in the legal notice.

3. Two roles, two regimes

We wear two hats, and they do not follow the same rules. This is the key to the whole page.

Data controller

For our own data: trial requests, client gyms, website visitors. We decide why and how. That is what sections 5 to 13 are about.

Data processor

For gym members’ data. The gym decides, we execute. What we may do with it is set by the data processing agreement signed with the gym, not by this page.

4. Gym members’ data

The software processes, on behalf of each gym, the data of its members: identity, email address, phone number, photo, membership, booking and payment history, door access events.

The gym is the controller for that processing. We are its processor. In practice, that means:

Are you a member and want to exercise your rights?

Write to your gym: access, correction, deletion, withdrawal of consent — the gym decides and the gym answers. If your request reaches us directly, we forward it to the gym and do not answer in its place.

The details — purposes, retention, security measures, authorised providers — are in the data processing agreement signed with the gym and in the privacy policy the gym shows its members. You can see an example on our demonstration instance: app.firstgym.tech/privacy.

5. What we process on our own behalf

5.1 — Free trial request

The form on firstgym.tech asks for four things: the gym’s name, the subdomain you want, an email address and a country. The appearance choices (main colour, modules) are not personal data; they are there to prepare the workspace.

What it is for: creating the trial workspace, sending you the link that lets you set it up, following up on the request and answering you.

What we rely on: the pre-contractual steps you ask us to take. For the commercial follow-up that comes after, our legitimate interest in contacting a professional who asked for a trial — you can object at any time, with a single email.

We do not store your IP address with the request. The web server does keep a technical trace of it, for the period given in section 8.

5.2 — Client gyms

When a trial becomes a contract, we process: the gym’s company name and address, the name, email and phone number of its contact person, its subdomain, its plan and options, its renewal dates, its invoices and payments, and our support conversations.

What it is for: performing the contract, invoicing, providing support and maintenance, and meeting our Indonesian accounting and tax obligations.

What we rely on: performance of the contract, and legal obligation for everything to do with accounting and tax.

5.3 — When you write to us (contact form)

The contact form on the website collects your name, email address, an optional club name and your message. We use them for one thing: to reply to you and, if it leads somewhere, to prepare a quote. We rely on your request (pre-contractual steps) and our legitimate interest in answering prospects. We keep these messages for the “prospects” period given in section 8, then delete them; if you become a client, they move under section 5.2.

5.4 — Website visitors

The website is static and sets no cookies. It stores one single thing in your browser’s local storage: the display language you picked (French, English, Indonesian or Russian), so it does not have to ask again. That information never reaches a server and disappears when you clear your browser data.

Audience measurement. To know how many people visit and which pages interest them, we use GoatCounter, an analytics tool we host ourselves on our own server (stats.firstgym.tech). It sets no cookie, builds no advertising profile, and sends nothing to a third party. It records a page view with the page address, the referrer and a coarse, non-identifying signal derived from the browser and a daily rotating value — never a stored identifier or your full IP address. We rely on our legitimate interest in understanding our audience.

Our web server also keeps a technical log of each request: IP address, date and time, page requested, response code, browser reported. It is used to run the site, to understand incidents and to contain abuse (rate limiting). We rely on our legitimate interest in the security of our services.

5.5 — The emails we send

We send service emails: workspace setup link, “your space is ready”, password reset, operational alerts. They go through Resend (section 6), which keeps delivery traces for its own operation: recipient, date, delivery status.

If we write to you for commercial follow-up, you can ask us to stop at any time — reply to the email or write to contact@firstgym.tech. We stop.

6. Our providers

Running software takes a few outside services. Here are ours, all named. When we act as a gym’s processor, these are its sub-processors, authorised by the contract.

ProviderWhat it does for usWhat it sees
HostingerHosts the machine that runs the website, the demo and the gyms’ workspaces — data centre located in Indonesia. Also provides the mailbox for the firstgym.tech domain (inbound mail and mailbox).Everything stored on the machine, within the limits of its hosting contract, plus the emails received at an @firstgym.tech address.
Google Drive (Google)Stores the backup copy that leaves the server every night.Only archives encrypted with AES-256 before they are sent. The key never leaves our infrastructure: Google cannot open those archives.
ResendDelivers our service emails (workspace setup link, “your space is ready”, password reset, operational alerts).The recipient’s address, the content of the email and the delivery status.
Amazon SES (Amazon Web Services)Carries the emails Resend sends on our behalf: it is Resend’s own sub-processor, not a provider we picked directly.What any mail carrier sees: recipient, sender, message content. Our DNS records confirm it (SPF include:amazonses.com on the sending subdomain, bounce address in the ap-northeast-1 region).
Google Fonts (Google)Serves the typefaces used by the application — the one a gym’s members use, NOT this website: firstgym.tech calls no external font.The IP address of the browser downloading the font, and the page the request comes from. It is an outbound request to Google every time the application is opened.
CloudflareManages DNS for our domains, and nothing else: our records are in “DNS only” mode.Nothing about your browsing. Traffic does not go through Cloudflare: it goes straight from your browser to our server.
Let’s Encrypt (ISRG)Issues the certificates that encrypt traffic between your browser and our servers.Domain names, nothing else.
PostHog (PostHog Inc., United States)Product analytics for the member application (app.firstgym.tech) — NOT this website: how members move through the app, which features they use, where they get stuck, and technical errors, so we can improve the product. It runs on PostHog’s US cloud.Pages viewed and actions taken inside the app (clicks, form interactions, page views, heatmaps, rage/dead clicks), technical errors and browser console logs, and MASKED session recordings — the on-screen text and every field a member types are hidden in the browser before anything is sent, so a recording looks like an animated wireframe, not readable content. Plus a device/browser signal and an approximate IP-derived location, tied to a cookie-based identifier. It does not receive members’ names, emails or payment details as such.

We use no advertising network and no data broker. This list is kept up to date: any new provider is added to it, and client gyms are informed as their contract provides.

7. Transfers outside Indonesia

Our company is Indonesian; our providers are established in Europe and in the United States and spread their infrastructure across several continents — the bounce address of our emails, for instance, points to an Asia-Pacific region. Data may therefore be processed outside Indonesia, and outside the European Union. The data centre hosting our servers is, for its part, located in Indonesia: the gyms’ workspaces and their databases reside in the Publisher’s own country (details in the legal notice).

What we have not done yet — and saying so beats hiding it.

As at the date of this page, no standard contractual clauses have been signed with our providers, and no transfer impact assessment has been carried out. We currently rely on the commitments in each provider’s own terms, which, under the GDPR, is not enough.

A gym subject to the GDPR must take this into account: this formality must be completed before data of people located in the European Union is processed. We undertake to do so on request and will supply the corresponding evidence. This is the same thing article 11.4 of our data processing agreement says — the two documents must stay in agreement, and they do.

For backups the question barely arises: the archive leaves the machine already encrypted with AES-256, and the key never leaves our infrastructure.

8. Retention periods

We keep nothing “just in case”. Past the periods below, data is deleted or anonymised.

What we keepFor how long
Trial request that does not become a contractThe length of the trial, then 24 months after our last exchange.
Unconverted trial workspaceDisabled at the end of the trial (14 days). 14 days later the workspace is flagged for deletion, and the erasure is triggered by hand by the publisher — no automated process destroys a workspace.
Account and contact details of a client gymFor the whole term of the contract.
A gym’s data after the contract endsReturned or deleted as the contract provides; it then disappears from backups as they rotate.
Invoices and accounting recordsThe period required by Indonesian law (up to 10 years for company records).
Support conversations24 months after the last message.
Web server logs (including IP address)No period: see the box below — we will not announce a deadline that nothing enforces.
Backups kept on the server14 days.
Encrypted off-site backups30 days.
Web server logs: what is true, said frankly.

An earlier version of this page announced “30 days at most”. That was false: nothing enforces that period. Our web server writes its logs to standard output, where the container engine picks them up with no rotation and no purge rule at all. They therefore live as long as the container that produces them and disappear when it is recreated, on a date that depends on our deployments — not on a retention period.

We would rather write this down than leave a promise nothing keeps. Putting real rotation and purging in place is an identified piece of work; this page will be corrected the day a period is actually enforced, and not before.

Two regimes coexist in this table, and it is better to know it. The backup periods and the life cycle of a trial workspace are run by our scripts, every night. The periods announced for trial requests and support threads are internal policy commitments: no automatic purge enforces them today, we honour them by hand. Accounting records fall under a statutory retention obligation, not a choice.

Data deleted from a database still lives for a while in backups: it disappears from them as those rotate, within the periods above.

9. Security

Administrative access: the limitation, stated plainly.

An earlier version of this page claimed that administrative access was “limited to the people who need it, and is logged”. The second half was false. Access to a workspace’s administration console rests on a password specific to that workspace and shared among the gym’s administrators. There is currently no named account per administrator, no two-factor authentication and no throttling of attempts on that route. As a result, an administrative action cannot be tied to an individual.

That password is stored as a salted bcrypt hash, like member passwords — it has been since 7 August 2026; a space created before then is re-hashed automatically on the first successful sign-in. The gym should still take the shared nature of the password into account in its own risk assessment: restrict its circulation and request a change whenever an authorised person leaves. This matches article 9.4 of our data processing agreement.

No system is invulnerable. In the event of a data breach affecting a gym’s data, we notify that gym within 24 hours (article 12 of our data processing agreement). Where we act as controller in our own right, we notify the competent authority and the people concerned within the deadlines the law sets — 72 hours under the GDPR, 3 × 24 hours under Indonesian law.

10. Your rights

For the data we process on our own behalf, you can:

How: write to contact@firstgym.tech setting out your request. We answer as quickly as we can, and within 30 days at the latest. If there is doubt about your identity, we may ask for what is needed to verify it — for that purpose only.

If our answer does not satisfy you: you can lodge a complaint with the competent data protection authority. In the European Union, the one in your country of residence. In Indonesia, the authority provided for by Law No. 27 of 2022.

A reminder: if you are a gym member, these requests go to the gym (section 4).

11. UU PDP and GDPR

The publisher is an Indonesian company. Its processing falls under Law No. 27 of 2022 on personal data protection (UU PDP).

Our clients, however, may be established elsewhere. A gym established in the European Union, or addressing people located there, falls under the GDPR: it is the controller, and its obligations pass on to us through the data processing agreement (GDPR article 28).

The two frameworks add up; neither replaces the other. Where they differ, we apply the rule that protects the individual more.

12. Minors

FirstGym Tech is aimed at professionals. We do not knowingly collect children’s data on our own behalf. A gym may have members who are minors: it is then up to the gym to obtain the consent of a parent or legal guardian, under the law of its own country.

13. Changes

We update this page whenever our processing changes: a new provider, a new purpose, a revised period. The version date is at the top of the page. A change that affects a client gym is notified to it as its contract provides.

14. Write to us

A question about this page, a request about your data, a doubt: write to contact@firstgym.tech. By post: PT. LTVT CAPITAL GROUP, Jalan Pantai Batu Mejan Nomor 33A, RT. 000, Canggu, Kuta Utara, Kabupaten Badung, Bali, Indonesia.

Version of 9 August 2026. See also the legal notice.