Sign in

Veyla · Privacy Policy

Privacy.

Last updated 8 August 2026

Veyla builds entry protection and access control for gyms. That work involves personal information — some of it, like an opt-in face photo, among the most sensitive there is. This policy explains what we collect, why, where it lives, who sees it, and how it is destroyed. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and this policy is written to be read, not skimmed.

Who we are

Veyla (“we”, “us”) is an Australian software and hardware platform, built in Brisbane, that provides gyms and fitness facilities with entry verification (Veyla Protect), door access control (Veyla Access), and member management tools (Veyla Manage). Privacy questions, requests and complaints all reach a human at hello@veyla.com.au.

The two hats we wear

Most personal information on the platform belongs to a gym’s relationship with its own members. For that data the gym is the organisation collecting it, and we process it on the gym’s behalf to run their doors, alerts and memberships — we don’t use it for our own purposes, sell it, or advertise with it. Ever.

Biometric data is different. When a member opts in to face entry, Veyla is the collecting custodian — the consent names us, the storage is ours, and the destruction obligations are ours. We hold that role deliberately: it means the gym and its management software never touch a photo or a face template at all.

What we collect

Gym staff accountsName, email address, sign-in records, and — only if a staff member turns notifications on — a push subscription for their device. That is what running a dashboard login requires, and nothing more.

Member records (held for your gym)Name, contact details, membership plan and status, entry history, and credential records (which fob, PIN or face credential is issued). If your gym bills through Veyla, direct-debit mandates are established and stored with our payment partner GoCardless — we never see or store your full bank details.

Face photos and templates (opt-in only)If — and only if — a member chooses face entry, we collect one photo, captured on the member’s own phone after a standalone consent step that is never bundled into terms and conditions. From that photo we derive the reader templates that let a door recognise you. Members who prefer not to enrol simply don’t: a fob or PIN works just as well, at no detriment. No one is ever scanned into the system passively.

Entry and camera data (Veyla Protect)Protect’s cameras count people through the door and compare that count against credential scans. The system records entry events, door telemetry, and short video clips or snapshots of the moments around an entry alert so that gym staff can review what actually happened. Protect counts people — it does not identify them.

Operational dataDevice health heartbeats, service logs and diagnostic telemetry from the hardware we run at a site. This is about keeping equipment alive, not about people.

What we use it for

To run the doors, catch what shouldn’t happen, and keep the gym’s records straight: deciding whether a credential opens a door, alerting staff to tailgating and unauthorised entry, sending the messages a gym asks us to send (entry alerts, enrolment links, membership notices), billing where the gym uses Veyla for billing, and improving the reliability of our detection at that site. We do not use personal information for advertising, we do not sell it, and we do not share it with anyone except as set out below.

Where it lives

Face photos are stored encrypted in Australia. Reader face templates are derived, disposable caches held on the door hardware at the member’s own gym — instantly revocable and never the source of truth. Platform data is hosted with established cloud infrastructure providers under encryption in transit and at rest, with strict per-gym isolation enforced at the database layer.

Who we share it with

Only service providers that are necessary to run the platform, and only the data each one needs: cloud hosting and database infrastructure (Supabase, Vercel), payment processing where a gym bills through Veyla (GoCardless), transactional email (Resend), and SMS delivery for the messages gyms send through us. Government agencies or law enforcement only where the law requires it, or where a gym chooses to hand over evidence footage of an incident at their own site. No data brokers, no advertisers, no exceptions.

How biometric data is destroyed

Destruction is built into the product, not handled by support tickets:

Change your mindWithdrawing consent destroys the photo and every derived template — in our storage and on every reader that ever held one — immediately, with an audit trail.

Leave the gymWhen a membership ends, face data is destroyed automatically after a short grace window (currently seven days, in case a member rejoins), without anyone needing to remember to do it.

Either way, the member keeps entering the gym for as long as they’re entitled to — a fob or PIN takes over the moment the face credential is gone.

How long we keep the rest

Member records are kept for as long as the gym has an active relationship with the member and as required by law after that. Entry events and alert evidence are kept only as long as they are useful for the gym’s security review and reporting, after which they are removed. Camera clips attach only to entry alerts — Protect is not a surveillance archive, and continuous footage never leaves the building.

Your rights

You may request access to the personal information we hold about you, ask us to correct it, or complain about how it has been handled — email hello@veyla.com.au and we will respond within 30 days. For member records our role may be to route the request to your gym, but we will never leave you without an answer. If you are unsatisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). If a data breach occurs that is likely to result in serious harm, we will notify affected people and the OAIC as required by the Notifiable Data Breaches scheme.

Cookies

The Veyla app uses cookies for one thing: keeping you signed in. No advertising cookies, no cross-site tracking.

Changes

When this policy changes we will update this page and the date at the top. If a change materially affects how biometric data is handled, we will tell enrolled members directly before it takes effect.