Legal
Data Processing Agreement
How Murai handles your members' personal data on your behalf. It forms part of our Terms of Service.
Last updated 21 Sep 2026
1. Purpose and scope
This Data Processing Agreement ("DPA") applies whenever Murai ("Murai", the "Processor") processes personal data on behalf of a gym or fitness business that uses the Service (the "Customer"). It forms part of the Terms of Service and applies for as long as we process that data.
2. Roles
The Customer is the Data Fiduciary and decides why and how its members' personal data is processed. Murai is the Data Processor and processes that data only to provide the Service. These terms are used as defined in the Digital Personal Data Protection Act, 2023 ('DPDP Act').
3. What we process
- Subject: running the Customer's gym on the Service, across its branches.
- People: the Customer's members, prospects and staff.
- Data: names, phone numbers, email addresses, addresses, dates of birth or age, blood group, emergency contacts, membership and payment records, attendance logs, notes, and, where the Customer enables it, fingerprint or face attendance identifiers.
- Duration: for as long as the Customer's subscription is active, plus the export period described below.
4. Customer's instructions and responsibilities
We process personal data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the Service's features. If we believe an instruction breaks the law, we will tell the Customer.
The Customer is responsible for giving members the required notice, obtaining valid consent, and having a lawful basis for the data it puts into the Service. This includes explicit consent for biometric data and verifiable parental consent for anyone under 18.
5. Confidentiality
Everyone at Murai who can access the Customer's personal data is bound by a duty of confidentiality and is given access only where their work needs it.
6. Security measures
We maintain reasonable technical and organisational safeguards, including:
- encryption of data in transit;
- role-based access control and database-level rules that keep each Customer's data separate from every other Customer's;
- least-privilege access for our own staff, and logging of administrative access;
- regular backups and a process for restoring them;
- prompt fixing of security issues we become aware of.
7. Sub-processors
The Customer authorises us to use sub-processors to deliver the Service. They fall into these categories: cloud hosting and database, authentication, email and WhatsApp messaging, and payment processing. We bind each sub-processor by contract to protect personal data to a standard no lower than this DPA, and we remain responsible for their performance.
We will give the Customer notice of a new sub-processor before it starts processing the Customer's data. On request, email us at contact.murai.app@gmail.com for the current list.
8. Helping with members' requests
If a member contacts us about their data, we will refer them to the Customer. We will give the Customer reasonable help, using the Service's features, to respond to requests to access, correct or erase personal data, and to meet its obligations under the DPDP Act.
9. Personal data breaches
If we become aware of a personal data breach affecting the Customer's data, we will tell the Customer without undue delay, and in any case within 72 hours, with what we know about the nature of the breach, the data affected and the steps taken. We will help the Customer meet its duty to notify the Data Protection Board of India and affected members.
10. Return and deletion
When the subscription ends, the Customer has 30 days to export its data. After that we delete or anonymise it, except where the law requires us to keep it, in which case we keep it securely and only for that purpose.
11. Audits
On reasonable written request, and not more than once a year unless there has been a breach, we will provide the information needed to show that we meet this DPA. The Customer may carry out an audit on at least 30 days' notice, during business hours, subject to confidentiality and without disrupting other customers.
12. Transfers outside India
We transfer personal data outside India only where the DPDP Act and any restrictions notified under it allow, and only to sub-processors bound as described above.
13. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms of Service. If this DPA conflicts with the Terms on the handling of personal data, this DPA prevails.
14. Contact
For questions about this DPA, email us at contact.murai.app@gmail.com.