Privacy policy

Last updated 18 August 2026

This policy explains how Champ Fitness Ltd, trading as UN1T Dublin (“we”, “us”) handles personal data when you use the Repset web application at crm.repset.ie and the Repset iOS application (formerly “CF Studio”) (collectively, the “Service”). We are the data controller for the Service under the EU General Data Protection Regulation and the Irish Data Protection Act 2018.

1. Who this applies to

The Service is an internal operations tool used by UN1T Dublin staff and authorised contractors. It is not a consumer-facing product. If you are not a UN1T staff member, contractor, or a person whose contact details have been entered into our CRM by a staff member (for example because you booked a class, attended an event, or contacted us), this policy is unlikely to apply to you.

2. What data we process

For staff and contractors who sign in to the Service, we process:

  • name, email address, and (for contractors) employment type
  • role assignments, location memberships, and feature permissions
  • shift schedules, time-off requests, swap requests, and clock-in adjustments
  • uploaded invoice PDFs and the metadata of those invoices
  • device push notification tokens once you grant permission
  • audit logs of significant actions (sign-ins, role changes, data exports, master “view as user” sessions)

For members of the public whose details have been entered into the CRM, we may process:

  • name, email, phone number, and any tags or notes a staff member has added
  • booking, event, race, and class history
  • WhatsApp, SMS, and email message history with UN1T
  • marketing preferences and subscription/unsubscribe state
  • payment records (for deposits or race entries) — never card numbers themselves

3. What we do NOT process

  • full credit or debit card numbers — payments are handled by Revolut Business; we only see the last four digits and a token
  • health, fitness, or biometric data — except what a member voluntarily tells a coach (kept only as plain notes) and, for members who opt in to the member side of the Repset app, the health and fitness data described in section 4
  • device contacts, photos other than ones you explicitly attach to invoices, location/GPS coordinates, microphone or camera audio
  • advertising identifiers — the iOS app does not use IDFA or any cross-app tracking

4. Health and fitness data (member app)

Members who use the member side of the Repset app can choose to share health and fitness data with us. Nothing in this section happens unless the member takes that step themselves. Depending on what a member connects, we process:

  • heart-rate readings from a chest strap worn during a class, captured by the in-studio receiver while the class runs
  • workouts and heart-rate data read from Apple Health — only after the member grants permission on their own device; the app can also write a summary of a completed session back to Apple Health
  • body-composition scan results from an InBody scan taken at the studio, shared into the member’s coaching record
  • body weight, entered during profile setup or read from Apple Health, used to estimate calories for a session
  • activities imported from Strava, where a member connects their own Strava account

We use this data solely to provide the app to the member: scoring their training sessions (effort points and heart-rate zones), showing their progress trends, counting them into gym challenges, and supporting coaching they have asked for. It is never used for advertising, never sold, and never used to track anyone across other apps or websites, and it is not read on the staff side of the app.

The member sees their own data. Studio coaches can see summary-level statistics (for example a session’s effort score) in order to coach the member. Raw heart-rate data is never shown to other members. Health and fitness data is deleted with the rest of a member’s data on request — see our account and data deletion page.

5. Why we process it (lawful basis)

  • Contract. To provide rosters, payroll, scheduling, and contractor invoicing to staff who have an employment or service agreement with us.
  • Legitimate interest. To run our gym safely and efficiently — e.g. to send a coach the schedule of classes they’re assigned to coach.
  • Consent. For marketing emails, SMS, and WhatsApp messages — withdraw at any time using the unsubscribe link in any message — and, as explicit consent under Article 9 GDPR, for the health and fitness data described in section 4, which is collected only when a member connects a data source themselves and can be stopped at any time by disconnecting it.
  • Legal obligation. Tax records, payroll records, and similar are kept for the periods required by Irish revenue and employment law.

6. Who we share it with (sub-processors)

The Service relies on the following sub-processors. Each has a Data Processing Agreement in place with us. The maintained register, including regions and safeguards, is published at /legal/subprocessors.

  • Supabase — primary database, file storage, and authentication. Region: EU (Ireland).
  • Vercel — hosts the web application. Region: EU.
  • Postmark — transactional and marketing email delivery.
  • Meta Platforms — WhatsApp Cloud API and Instagram messaging; delivers WhatsApp and Instagram conversations with contacts.
  • Twilio — SMS delivery.
  • Glofox — gym membership and booking platform; member records, bookings, and attendance sync between Glofox and the CRM.
  • Revolut Business — payment processing for deposits and race entries.
  • Stripe — payment processing for event tickets.
  • Upstash — message-queue infrastructure; briefly carries webhook and job payloads between our systems.
  • Xero — accounting; contractor invoices are forwarded to a unique Xero bills-by-email address after approval.
  • Sensibo — controls in-studio AC units; receives a location identifier and the requested set-point.
  • Apple Push Notification Service and Expo — deliver push notifications to staff iPhones.
  • Anthropic — provides the AI assistant used by some staff features. Conversations are sent transiently to Anthropic’s API and are not used to train models.
  • UniFi (Ubiquiti) — door access at studio sites; we send a door-unlock command and store the result.

7. International transfers

Most processing happens within the EU. Some sub-processors (Postmark, Meta, Twilio, Stripe, Upstash, Anthropic, Apple, Expo) are based in the United States and may process data there. Where this happens we rely on the European Commission’s Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework.

8. How long we keep it

  • Active staff and contractor accounts: while your engagement with us continues, plus the periods required by Irish employment and tax law.
  • Contact records (members of the public): until you ask us to delete them or for a maximum of seven years from the last interaction, whichever is earlier.
  • Message history (email, SMS, WhatsApp): up to seven years for compliance and dispute resolution.
  • Audit logs: six years.
  • Payment records: as required by Irish revenue law (currently six years).
  • Push notification tokens: removed automatically when a device is wiped, an app is uninstalled, or after 90 days of inactivity.

9. Mobile-app specifics

The Repset iOS app (bundle ID com.un1tdublin.crm) stores its session token and a small impersonation flag (used by master accounts to debug what another staff member sees) inside the iOS Keychain via Apple’s SecureStore. It does not write to iCloud, the camera roll, contacts, or any other shared system store. The app uses Expo’s over-the-air update channel to ship JavaScript updates between native releases; only the app bundle is downloaded — no personal data is sent during update checks.

10. Your rights

You have the right to:

  • access the personal data we hold about you
  • have it corrected if it is inaccurate
  • have it erased (subject to legal retention obligations)
  • object to processing or restrict it
  • receive a portable copy of data you have provided to us
  • withdraw consent for marketing at any time
  • complain to the Irish Data Protection Commission (dataprotection.ie)

11. Security

Access is gated by Supabase Row-Level Security policies and per-location permission checks. Staff sign in with email and password; we do not store passwords ourselves — they live inside Supabase’s authentication service. Master account actions are logged and reviewable in our internal audit log. Backups are encrypted at rest in the EU.

12. Government and public-authority requests

When a public authority (such as a police force, court, regulator, or government body) asks us to disclose personal data, we review the legality of the request, disclose only the minimum necessary, challenge requests we consider unlawful, and document each one. Our full Government & public authority data request policy explains this process.

13. Changes to this policy

If we change this policy in a way that materially affects how we use your data, we’ll update the “Last updated” date at the top and, where appropriate, notify staff or contacts directly. Older versions are available on request.

14. Contact

For privacy questions or to exercise any of the rights above:

Champ Fitness Ltd (trading as UN1T Dublin)
First Floor Unit, Stillorgan Village Centre,
Lower Kilmacud Road, Dublin, A94 AC67
Email: privacy@un1tdublin.com