Privacy Policy for Forma

Last Updated: 03 September 2025
At Forma, a software of DeltaX LIMITED ("we," "us," or "our"), we are committed to protecting your personal data and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable laws in the European Economic Area (EEA). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our gym management software, including the gym owner portal ("Owner Portal") and the client mobile application ("Mobile App") (collectively, the "Services"). By using our Services, you agree to the terms of this Privacy Policy.

1. Information We Collect

We collect personal data from gym owners ("Owners") and gym members ("Members") to provide and improve our Services. The types of data we collect include:
a. Information Provided by You
Gym Owners:
Gym Members:
b. Automatically Collected InformationUsage Data:
c. Information from Third PartiesPayment Processors:

2. How We Use Your Information

We process your personal data to provide, improve, and personalize our Services. The legal bases for processing under GDPR Article 6 and Article 9 (for special categories of data) are as follows:
Gym Owners:
Gym Members:
For Both Owners and Members:
You may withdraw consent at any time by updating your preferences in the Mobile App or Owner Portal or contacting our Data Protection Officer at dpo@forma.com.cy (mailto:dpo@forma.com.cy).

3. How We Share Your Information

We do not sell your personal data. We may share your data in the following circumstances, in compliance with GDPR:Service Providers:

4. Data Security

We implement industry-standard security measures to protect your personal data, particularly sensitive data like health information and payment details. All personal data is encrypted during transmission and storage using secure protocols. We store data securely on approved virtual private server (VPS) providers that comply with GDPR requirements. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

5. Your Choices and Rights

As an individual in the EEA, you have the following rights under GDPR:Right of Access: Request a copy of the personal data we hold about you.
To exercise these rights, contact our Data Protection Officer at dpo@forma.com.cy (mailto:dpo@forma.com.cy). We will respond within one month, as required by GDPR, though this may be extended by two months for complex requests. You may also update your account settings in the Owner Portal or Mobile App.
Additional Choices:

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or comply with legal obligations. For example:

7. International Data Transfers

Our Services are hosted on approved virtual private server (VPS) providers in Cyprus or the EEA. If you are in the EEA and your data is transferred outside the EEA, we ensure compliance with GDPR by using safeguards such as:
For more information on these safeguards, contact our Data Protection Officer at dpo@forma.com.cy (mailto:dpo@forma.com.cy).

8. Children’s Privacy

Our Services are not intended for individuals under 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent, as required by GDPR Article 8. If you believe we have collected such data, contact us at info@forma.com.cy (mailto:info@forma.com.cy), and we will take steps to delete it.

9. Third-Party Links and Integrations

Our Services may include links to or integrations with third-party services, such as Revolut for payment processing or fitness tracking apps. We are not responsible for their privacy practices. Please review their privacy policies (e.g., Revolut’s privacy policy at www.revolut.com) before sharing data. Third-party integrations are only enabled with your explicit consent, in compliance with GDPR.

10. Data Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours, as required by GDPR, unless the breach is unlikely to result in a risk to your rights and freedoms. If the breach poses a high risk, we will inform you without undue delay, including details of the breach and steps you can take to mitigate any impact.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance functionality, analyze usage, and provide personalized features. Cookies are small data files stored on your device. We use:
Non-essential cookies are only used with your explicit consent, as required by GDPR and the ePrivacy Directive. You can manage preferences through our cookie consent tool or your browser settings.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email, push notifications, in-app alerts, or by posting the updated policy on our website. Your continued use of the Services after such changes constitutes acceptance of the updated policy.

13. Account Deletion (including all relevant user data)

If you would like to delete your account and all associated data collected, you can do so within the Forma mobile app. Login to Forma app, navigate to "Profile" tab, choose "Preferences" and click on "Delete Account". If you would like any further assistance in deleting your account please contact us on info@forma.com.cy

14. Contact Us

For questions about this Privacy Policy or our data practices, contact us at on: info@forma.com.cy
[DeltaX]
Email: info@forma.com.cy
Phone: +357 97823482
Data Protection Officer
For GDPR-related inquiries or to exercise your data subject rights, contact our Data Protection Officer: Email:
dpo@forma.com.cy