Chapters
PART VII · APPENDICES

Data protection and security

Draft — screenshots coming

You run a business on Prism — memberships, money, door access, cameras, member photos. This page explains, in plain language, how that data is protected: how gyms are kept separate from each other, why money records cannot be quietly edited, what your devices can and cannot do on your network, and what happens when a member asks to be forgotten.

Your gym's data is isolated

Every record in Prism belongs to exactly one gym, and that boundary is enforced by the platform itself — not by the apps remembering to filter. Staff at one gym cannot see or touch another gym's members, sales or settings, even inside the same chain unless the chain explicitly enables sharing. Multi-location groups get controlled cross-location features — visiting members, chain reporting — and each of those is opt-in on both sides, off by default.

Staff see only what their role allows

Every staff account has a role and a fine-grained set of permissions, and those checks run on the server, not just in the app. A front-desk account cannot open payroll; a trainer cannot issue refunds; sensitive actions check the permission at the moment they run. When a staff member leaves, ending their employment also revokes their sign-in and their door access.

Money records stay honest

Prices come from your catalogue on the server — a tampered app cannot invent its own. Sales, payments and wallet movements cannot be edited or deleted from a staff device: corrections happen through refunds and adjustments that leave a trace. Every sale is recorded in your gym's books currency along with the tender currency and the exchange rate used, so reports never drift, and a lost connection mid-payment can never double-charge — a retried purchase is recognised and answered with the original result.

Every sensitive action is logged — with a face

Destructive and money-touching actions land in an append-only audit log: who did it, what it touched, and when. For actions you designate, the app also captures a selfie of the staff member authorising it, so "who gave that discount?" has a photographic answer. Log entries cannot be edited or deleted from the apps; owners can archive entries from view, but the underlying history is preserved, and permanently purging old entries is deliberately slow, owner-only and itself audited.

Encrypted traffic, managed infrastructure

All traffic between your apps, your devices and the platform is encrypted in transit. Your data lives in a managed cloud database with continuous backups, and the platform services that process it are a small, deliberately curated set that we operate and monitor — you never have to run a server, and there is nothing at the gym to patch.

Devices only dial out

Door readers, camera boxes, kiosks and signage players never accept incoming connections. They reach out to the platform, collect their instructions and report back — so installing Prism hardware never means opening ports, setting static addresses or touching your router's firewall. Door readers also keep a local copy of every active credential, so the front door keeps making correct decisions even with the internet down, and catches up the moment it returns.

Updates are signed and verified

Your devices never choose their own software. Updates are published by Prism through a controlled release channel, and every device verifies the download against a cryptographic fingerprint before installing it — a file that does not match is refused. A device cannot be handed arbitrary code, by anyone.

The platform heals itself

Real gyms have power cuts and patchy Wi-Fi, so Prism assumes failure and checks its own work. Background sweeps run around the clock, looking for anything that got stranded mid-way — a door permission that never reached a terminal, a device that missed an update — and re-queue it automatically, in both directions: a member who should have access gets it, and a member who should have lost access loses it. Scheduled housekeeping also handles the routine: expiry reminders, monthly plan credits, overnight locker releases, report emails.

Messaging without extra accounts to secure

Notifications and member messaging — including the owner alert channel and re-engagement campaigns — run through integrations that Prism owns and operates. Your gym never has to register with a messaging provider, hold API keys, or secure another vendor account: there is simply less surface to attack, and nothing for you to maintain.

Member privacy and the right to be forgotten

Member photos, staff photos and audit selfies live in private storage, readable only by authorised people in your own gym. When a member asks to be erased, Prism honours it with a 30-day grace window (protecting against both regret and account takeover), then removes their personal details while preserving the anonymous attendance and payment history your accounting needs. Message attachments and similar transient files are purged on a schedule.

Security is a practice, not a feature

Prism's security posture is maintained as an ongoing, dated discipline: regular hardening reviews, each fix verified against the live platform before release, with the reasoning recorded. When issues are found — internally or in the field — they are closed at the platform level so every gym benefits at once, usually with no app update required.

Still stuck? Email hello@prismgym.com — include your gym name, the device, and a photo of what you see.