Cookie, Mobile SDK and Subprocessor Notice
Effective 2026-09-03.
1. Data we collect
We process account and contact details; profile and uploaded media; search, booking and attendance data; selected contact details; messages, reviews and reports; payment tokens and transaction references; device, network, consent, security and support records. With separate permission we may process selected health/fitness measurements and feature-scoped location.
2. Sources
Data comes from you, your device and permitted operating-system services, providers you interact with, payment/app-store providers and security signals. We do not buy health data or upload your address book. A provider may add necessary booking details under its own notice.
3. Health and location
Health access is read-only, optional and not used for ads, marketing profiles, credit, employment or insurance decisions. We display the requested data types and purpose before consent, record the policy version and choice, minimise access, and allow permission and explicit consent to be withdrawn without affecting earlier lawful processing. Device measurements and wellness outputs may be incomplete or inaccurate and must not be relied on for medical or emergency decisions. Precise location is used only for the feature explained before permission; background collection requires a separate disclosure. Denial leaves non-dependent functions available.
4. Sharing
We share only necessary data with the provider you book, processors that host or deliver the service, payment and app-store providers, professional advisers and authorities where a lawful and proportionate duty applies. We do not sell personal data. Providers cannot see your relationships with other providers. Health data is not shared with a provider unless you deliberately choose to do so.
5. Processors and international transfers
The current Cookie/SDK and Subprocessor Notice identifies enabled services, purposes and regions. Transfers without an adequacy decision use the applicable SCCs, UK IDTA/Addendum or legally recognised KVKK mechanism, with transfer-risk review and supplementary security. A configuration entry being disabled means no data is sent to that integration.
6. Retention
We keep data only for its stated purpose: raw location up to 90 days, raw synced health data up to 12 months, crash events up to 90 days and backups up to 35 days after active deletion. Booking, payment, tax, consent, dispute and security records follow applicable legal limitation periods. Expired data is deleted or irreversibly anonymised; a documented legal hold preserves only its necessary scope.
7. Marketing and cookies
Service messages do not require marketing consent. Optional marketing and non-essential analytics use the choice and withdrawal controls required in the user’s country. Refusing is as easy as accepting and does not block core booking. Health, precise location and contact data are excluded from advertising audiences.
8. Complaints, updates and contact
Privacy requests go to privacy@bukiby.com. You may complain to your competent data-protection authority. Material changes are notified before effect and a new purpose or sensitive-data scope requires a new lawful basis and, where required, fresh consent. Document version and consent evidence are retained.
Operator and contact details
- MIND TECH CONSULTANCY LTD
- Trading as: Bukiby
- Company number
- 11481944
- VAT number
- GB 338119402
- Registered office
- 3 Orchid Mews, Harwell, Didcot, England, OX11 6EX