Data Processing Addendum and Role Matrix
Effective 2026-09-03.
1. Controller and scope
MIND TECH CONSULTANCY LTD operates Bukiby and is controller for platform accounts, security, support and product operations. An independent provider is controller for the professional service and records it determines. The role matrix and Data Processing Addendum govern processing performed on a provider’s documented instructions.
2. Purposes and lawful bases
We use data to create and secure accounts, perform bookings and payments, provide requested features, communicate service messages, prevent fraud, comply with law, resolve disputes and improve reliability. Bases include contract, legal obligation, legitimate interests balanced against your rights and consent where required. Special-category health processing requires the applicable Article 9/KVKK condition, normally explicit consent for the optional feature.
3. Sharing
We share only necessary data with the provider you book, processors that host or deliver the service, payment and app-store providers, professional advisers and authorities where a lawful and proportionate duty applies. We do not sell personal data. Providers cannot see your relationships with other providers. Health data is not shared with a provider unless you deliberately choose to do so.
4. Processors and international transfers
The current Cookie/SDK and Subprocessor Notice identifies enabled services, purposes and regions. Transfers without an adequacy decision use the applicable SCCs, UK IDTA/Addendum or legally recognised KVKK mechanism, with transfer-risk review and supplementary security. A configuration entry being disabled means no data is sent to that integration.
5. Retention
We keep data only for its stated purpose: raw location up to 90 days, raw synced health data up to 12 months, crash events up to 90 days and backups up to 35 days after active deletion. Booking, payment, tax, consent, dispute and security records follow applicable legal limitation periods. Expired data is deleted or irreversibly anonymised; a documented legal hold preserves only its necessary scope.
6. Security
Controls include encryption in transit and where appropriate at rest, least privilege, strong authentication, tenant separation, secret management, audit logging, secure development, vulnerability handling, backups and incident response. Sensitive admin access is purpose-limited and recorded. No system is risk-free, but we maintain measures proportionate to the data and threat.
7. Your rights
Depending on applicable law you may request access, correction, deletion, restriction, portability and objection; withdraw consent; and request human review of a solely automated decision with legal or similarly significant effect. Requests are normally free and answered within the statutory period after proportionate identity verification.
8. Deletion
Delete an account in app or through the public deletion route. We close access, stop ordinary processing, remove or anonymise profile and social content, revoke push tokens and send deletion to processors. Required financial, fraud or legal records are isolated and not reused. Backups expire within their normal cycle and restored data receives the deletion instruction again.
9. Complaints, updates and contact
Privacy requests go to privacy@bukiby.com. You may complain to your competent data-protection authority. Material changes are notified before effect and a new purpose or sensitive-data scope requires a new lawful basis and, where required, fresh consent. Document version and consent evidence are retained.
Operator and contact details
- MIND TECH CONSULTANCY LTD
- Trading as: Bukiby
- Company number
- 11481944
- VAT number
- GB 338119402
- Registered office
- 3 Orchid Mews, Harwell, Didcot, England, OX11 6EX