Legal · Security

Security at GymStack

The measures that protect your studio's business data and your members' personal data.

Last updated · July 7, 2026 · v1.0
// template copy, align with your actual infrastructure and certifications before publishing.

Practices at a glance

01

Encryption

All traffic uses TLS 1.2+; data is encrypted at rest with AES-256. Backups are encrypted with separate keys.

02

Infrastructure

Hosted on ISO 27001-certified cloud providers in Türkiye and the EU, with network isolation between customers.

03

Access control

Role-based permissions, mandatory 2FA for staff and GymStack personnel, and audit logs for sensitive actions.

04

Payments

Card payments run through PCI DSS Level 1 providers. Full card numbers never reach GymStack servers.

05

Backups & recovery

Encrypted daily backups with point-in-time recovery; restore drills run every quarter.

06

Monitoring

24/7 infrastructure monitoring, anomaly alerts, and centralized logging with restricted access.

07Organizational measures

Access to production is limited to a small, named engineering group under least-privilege rules; access rights are reviewed quarterly.

All personnel sign confidentiality agreements and complete annual security and KVKK awareness training.

08Incident response

We maintain a written incident-response plan. If an incident affects personal data, we notify the affected gyms and the authorities within the statutory deadlines (72 hours under the KVKK/GDPR frameworks), including the facts, the impact, and the countermeasures taken.

09Responsible disclosure

Found a vulnerability? E-mail [email protected] with steps to reproduce. We confirm receipt within 48 hours and keep you updated until resolution.

We do not pursue good-faith research that respects member data and service availability.

Report a vulnerability
Write to our security team with steps to reproduce; we confirm receipt within 48 hours.
[email protected]