Software publisher
Publisher’s privacy policy
This page describes what PT. LTVT CAPITAL GROUP, publisher of FirstGym Tech, does with the data it processes on its own behalf: trial requests, client gyms, visitors to firstgym.tech.
Last updated: 9 August 2026
This page is not for you. Your data is handled by your gym, not by us on our own behalf. Contact your gym: its privacy policy, the one shown in its app, is the one that applies. The details are in section 4.
1. The short version
- We sell no data and run no targeted advertising.
- The firstgym.tech website sets no cookies at all and runs no advertising or embedded social networks. It uses privacy-friendly, self-hosted audience measurement (see section 5.3) that sets no cookie and identifies no one.
- Gym members’ data is processed only on the gym’s instructions — never on our own behalf.
- Every gym has its own database and its own technical secrets. One workspace cannot read another’s data.
- Backups that leave the server are encrypted before they go.
2. Who processes your data
- Data controller
- PT. LTVT CAPITAL GROUP
- Address
- Jalan Pantai Batu Mejan Nomor 33A, RT. 000, Canggu, Kuta Utara, Kabupaten Badung, Bali, Indonesia
- NPWP
- 10.979.476.8-906.000 — NPWP16: 0109 7947 6890 6000
- Contact
- contact@firstgym.tech
Full company details are in the legal notice.
3. Two roles, two regimes
We wear two hats, and they do not follow the same rules. This is the key to the whole page.
For our own data: trial requests, client gyms, website visitors. We decide why and how. That is what sections 5 to 13 are about.
For gym members’ data. The gym decides, we execute. What we may do with it is set by the data processing agreement signed with the gym, not by this page.
4. Gym members’ data
The software processes, on behalf of each gym, the data of its members: identity, email address, phone number, photo, membership, booking and payment history, door access events.
The gym is the controller for that processing. We are its processor. In practice, that means:
- we access that data only to run, maintain or troubleshoot the gym’s workspace, at its request or to meet our service commitments;
- we do not use a gym’s business records — its members’ identities, bookings, orders, payments and loyalty — on our own behalf: no prospecting, no resale, no model training. The one thing we measure for ourselves is how the application is used — which screens and features members open, where they get stuck, technical errors — through the product-analytics tool listed in section 6 (PostHog). This is usage telemetry to improve the software, not the gym’s member records, and it starts when the app loads;
- we never mix it between gyms: each gym has its own dedicated database and its own encryption keys;
- when the contract ends, it is returned or deleted as the contract provides.
Write to your gym: access, correction, deletion, withdrawal of consent — the gym decides and the gym answers. If your request reaches us directly, we forward it to the gym and do not answer in its place.
The details — purposes, retention, security measures, authorised providers — are in the data processing agreement signed with the gym and in the privacy policy the gym shows its members. You can see an example on our demonstration instance: app.firstgym.tech/privacy.
5. What we process on our own behalf
5.1 — Free trial request
The form on firstgym.tech asks for four things: the gym’s name, the subdomain you want, an email address and a country. The appearance choices (main colour, modules) are not personal data; they are there to prepare the workspace.
What it is for: creating the trial workspace, sending you the link that lets you set it up, following up on the request and answering you.
What we rely on: the pre-contractual steps you ask us to take. For the commercial follow-up that comes after, our legitimate interest in contacting a professional who asked for a trial — you can object at any time, with a single email.
We do not store your IP address with the request. The web server does keep a technical trace of it, for the period given in section 8.
5.2 — Client gyms
When a trial becomes a contract, we process: the gym’s company name and address, the name, email and phone number of its contact person, its subdomain, its plan and options, its renewal dates, its invoices and payments, and our support conversations.
What it is for: performing the contract, invoicing, providing support and maintenance, and meeting our Indonesian accounting and tax obligations.
What we rely on: performance of the contract, and legal obligation for everything to do with accounting and tax.
5.3 — When you write to us (contact form)
The contact form on the website collects your name, email address, an optional club name and your message. We use them for one thing: to reply to you and, if it leads somewhere, to prepare a quote. We rely on your request (pre-contractual steps) and our legitimate interest in answering prospects. We keep these messages for the “prospects” period given in section 8, then delete them; if you become a client, they move under section 5.2.
5.4 — Website visitors
The website is static and sets no cookies. It stores one single thing in your browser’s local storage: the display language you picked (French, English, Indonesian or Russian), so it does not have to ask again. That information never reaches a server and disappears when you clear your browser data.
Audience measurement. To know how many people visit and which pages interest them, we use GoatCounter, an analytics tool we host ourselves on our own server (stats.firstgym.tech). It sets no cookie, builds no advertising profile, and sends nothing to a third party. It records a page view with the page address, the referrer and a coarse, non-identifying signal derived from the browser and a daily rotating value — never a stored identifier or your full IP address. We rely on our legitimate interest in understanding our audience.
Our web server also keeps a technical log of each request: IP address, date and time, page requested, response code, browser reported. It is used to run the site, to understand incidents and to contain abuse (rate limiting). We rely on our legitimate interest in the security of our services.
5.5 — The emails we send
We send service emails: workspace setup link, “your space is ready”, password reset, operational alerts. They go through Resend (section 6), which keeps delivery traces for its own operation: recipient, date, delivery status.
If we write to you for commercial follow-up, you can ask us to stop at any time — reply to the email or write to contact@firstgym.tech. We stop.
6. Our providers
Running software takes a few outside services. Here are ours, all named. When we act as a gym’s processor, these are its sub-processors, authorised by the contract.
| Provider | What it does for us | What it sees |
|---|---|---|
| Hostinger | Hosts the machine that runs the website, the demo and the gyms’ workspaces — data centre located in Indonesia. Also provides the mailbox for the firstgym.tech domain (inbound mail and mailbox). | Everything stored on the machine, within the limits of its hosting contract, plus the emails received at an @firstgym.tech address. |
| Google Drive (Google) | Stores the backup copy that leaves the server every night. | Only archives encrypted with AES-256 before they are sent. The key never leaves our infrastructure: Google cannot open those archives. |
| Resend | Delivers our service emails (workspace setup link, “your space is ready”, password reset, operational alerts). | The recipient’s address, the content of the email and the delivery status. |
| Amazon SES (Amazon Web Services) | Carries the emails Resend sends on our behalf: it is Resend’s own sub-processor, not a provider we picked directly. | What any mail carrier sees: recipient, sender, message content. Our DNS records confirm it (SPF include:amazonses.com on the sending subdomain, bounce address in the ap-northeast-1 region). |
| Google Fonts (Google) | Serves the typefaces used by the application — the one a gym’s members use, NOT this website: firstgym.tech calls no external font. | The IP address of the browser downloading the font, and the page the request comes from. It is an outbound request to Google every time the application is opened. |
| Cloudflare | Manages DNS for our domains, and nothing else: our records are in “DNS only” mode. | Nothing about your browsing. Traffic does not go through Cloudflare: it goes straight from your browser to our server. |
| Let’s Encrypt (ISRG) | Issues the certificates that encrypt traffic between your browser and our servers. | Domain names, nothing else. |
| PostHog (PostHog Inc., United States) | Product analytics for the member application (app.firstgym.tech) — NOT this website: how members move through the app, which features they use, where they get stuck, and technical errors, so we can improve the product. It runs on PostHog’s US cloud. | Pages viewed and actions taken inside the app (clicks, form interactions, page views, heatmaps, rage/dead clicks), technical errors and browser console logs, and MASKED session recordings — the on-screen text and every field a member types are hidden in the browser before anything is sent, so a recording looks like an animated wireframe, not readable content. Plus a device/browser signal and an approximate IP-derived location, tied to a cookie-based identifier. It does not receive members’ names, emails or payment details as such. |
We use no advertising network and no data broker. This list is kept up to date: any new provider is added to it, and client gyms are informed as their contract provides.
7. Transfers outside Indonesia
Our company is Indonesian; our providers are established in Europe and in the United States and spread their infrastructure across several continents — the bounce address of our emails, for instance, points to an Asia-Pacific region. Data may therefore be processed outside Indonesia, and outside the European Union. The data centre hosting our servers is, for its part, located in Indonesia: the gyms’ workspaces and their databases reside in the Publisher’s own country (details in the legal notice).
- Indonesian law (UU PDP): a transfer is only possible if the destination country provides an at least equivalent level of protection; failing that, with binding safeguards; failing that, with the consent of the person concerned.
- GDPR: where it applies, a transfer outside the European Union must be covered by one of the mechanisms in its Chapter V — an adequacy decision, the European Commission’s standard contractual clauses, or another appropriate safeguard.
As at the date of this page, no standard contractual clauses have been signed with our providers, and no transfer impact assessment has been carried out. We currently rely on the commitments in each provider’s own terms, which, under the GDPR, is not enough.
A gym subject to the GDPR must take this into account: this formality must be completed before data of people located in the European Union is processed. We undertake to do so on request and will supply the corresponding evidence. This is the same thing article 11.4 of our data processing agreement says — the two documents must stay in agreement, and they do.
For backups the question barely arises: the archive leaves the machine already encrypted with AES-256, and the key never leaves our infrastructure.
8. Retention periods
We keep nothing “just in case”. Past the periods below, data is deleted or anonymised.
| What we keep | For how long |
|---|---|
| Trial request that does not become a contract | The length of the trial, then 24 months after our last exchange. |
| Unconverted trial workspace | Disabled at the end of the trial (14 days). 14 days later the workspace is flagged for deletion, and the erasure is triggered by hand by the publisher — no automated process destroys a workspace. |
| Account and contact details of a client gym | For the whole term of the contract. |
| A gym’s data after the contract ends | Returned or deleted as the contract provides; it then disappears from backups as they rotate. |
| Invoices and accounting records | The period required by Indonesian law (up to 10 years for company records). |
| Support conversations | 24 months after the last message. |
| Web server logs (including IP address) | No period: see the box below — we will not announce a deadline that nothing enforces. |
| Backups kept on the server | 14 days. |
| Encrypted off-site backups | 30 days. |
An earlier version of this page announced “30 days at most”. That was false: nothing enforces that period. Our web server writes its logs to standard output, where the container engine picks them up with no rotation and no purge rule at all. They therefore live as long as the container that produces them and disappear when it is recreated, on a date that depends on our deployments — not on a retention period.
We would rather write this down than leave a promise nothing keeps. Putting real rotation and purging in place is an identified piece of work; this page will be corrected the day a period is actually enforced, and not before.
Two regimes coexist in this table, and it is better to know it. The backup periods and the life cycle of a trial workspace are run by our scripts, every night. The periods announced for trial requests and support threads are internal policy commitments: no automatic purge enforces them today, we honour them by hand. Accounting records fall under a statutory retention obligation, not a choice.
Data deleted from a database still lives for a while in backups: it disappears from them as those rotate, within the periods above.
9. Security
- Traffic is encrypted in transit: the whole service is served over HTTPS and requests arriving in cleartext are redirected. Certificates are renewed automatically and their expiry is monitored every day.
- Each gym has its own dedicated database, its own database account restricted to that database alone, and its own technical secrets: one workspace cannot read another’s data.
- A gym’s secrets — its database credentials, its integration keys, including those of its payment provider — are held in a file specific to its workspace, outside the code repository, readable only by the machine’s administrator account. They are stored in cleartext in that file: what protects them is the file’s permissions, not encryption.
- What is encrypted at rest with a key specific to the gym’s workspace: the member credentials the software has to replay in order to re-authenticate, and the tokens of the services the gym connects. A member’s password is never kept in cleartext: it is hashed (bcrypt, salted).
- Every database is backed up daily. The copy that leaves the server is encrypted with AES-256 before it is sent; the key is not stored with the backup host. Restoring is not a hypothesis: an archive has been downloaded back, decrypted and restored into a throwaway database, then compared collection by collection against production.
An earlier version of this page claimed that administrative access was “limited to the people who need it, and is logged”. The second half was false. Access to a workspace’s administration console rests on a password specific to that workspace and shared among the gym’s administrators. There is currently no named account per administrator, no two-factor authentication and no throttling of attempts on that route. As a result, an administrative action cannot be tied to an individual.
That password is stored as a salted bcrypt hash, like member passwords — it has been since 7 August 2026; a space created before then is re-hashed automatically on the first successful sign-in. The gym should still take the shared nature of the password into account in its own risk assessment: restrict its circulation and request a change whenever an authorised person leaves. This matches article 9.4 of our data processing agreement.
No system is invulnerable. In the event of a data breach affecting a gym’s data, we notify that gym within 24 hours (article 12 of our data processing agreement). Where we act as controller in our own right, we notify the competent authority and the people concerned within the deadlines the law sets — 72 hours under the GDPR, 3 × 24 hours under Indonesian law.
10. Your rights
For the data we process on our own behalf, you can:
- know what we process, why, and for how long;
- obtain a copy of it;
- have it corrected or completed;
- have it erased;
- ask for a processing operation to be restricted or suspended;
- object to a processing operation, in particular to commercial prospecting;
- receive it in a reusable format, or ask us to pass it on;
- withdraw your consent, where the processing relies on it;
- not be subject to a decision taken entirely by automated means producing legal effects — we take none;
- claim compensation for damage caused by a breach of Indonesian data protection law.
How: write to contact@firstgym.tech setting out your request. We answer as quickly as we can, and within 30 days at the latest. If there is doubt about your identity, we may ask for what is needed to verify it — for that purpose only.
If our answer does not satisfy you: you can lodge a complaint with the competent data protection authority. In the European Union, the one in your country of residence. In Indonesia, the authority provided for by Law No. 27 of 2022.
A reminder: if you are a gym member, these requests go to the gym (section 4).
11. UU PDP and GDPR
The publisher is an Indonesian company. Its processing falls under Law No. 27 of 2022 on personal data protection (UU PDP).
Our clients, however, may be established elsewhere. A gym established in the European Union, or addressing people located there, falls under the GDPR: it is the controller, and its obligations pass on to us through the data processing agreement (GDPR article 28).
The two frameworks add up; neither replaces the other. Where they differ, we apply the rule that protects the individual more.
12. Minors
FirstGym Tech is aimed at professionals. We do not knowingly collect children’s data on our own behalf. A gym may have members who are minors: it is then up to the gym to obtain the consent of a parent or legal guardian, under the law of its own country.
13. Changes
We update this page whenever our processing changes: a new provider, a new purpose, a revised period. The version date is at the top of the page. A change that affects a client gym is notified to it as its contract provides.
14. Write to us
A question about this page, a request about your data, a doubt: write to contact@firstgym.tech. By post: PT. LTVT CAPITAL GROUP, Jalan Pantai Batu Mejan Nomor 33A, RT. 000, Canggu, Kuta Utara, Kabupaten Badung, Bali, Indonesia.
Version of 9 August 2026. See also the legal notice.