Skip to content
Bukiby

Health/Fitness and Location Notice

Effective 2026-09-03.

1. Health, location and contacts

HealthKit and Health Connect access is read-only, separately optional and never used for advertising. Health and fitness information, automated suggestions and device measurements are general wellness aids, may be incomplete or inaccurate, and are not medical advice, diagnosis, treatment, monitoring or an emergency service. Stop activity and seek a qualified professional if you have symptoms, a condition, pregnancy, medication concerns or doubt about safe participation; contact local emergency services for urgent danger. Location is requested only for a feature that needs it; manual location and unrelated functions remain available. We do not upload an address book: only a contact deliberately selected by the user may be sent for the requested action.

2. Data we collect

We process account and contact details; profile and uploaded media; search, booking and attendance data; selected contact details; messages, reviews and reports; payment tokens and transaction references; device, network, consent, security and support records. With separate permission we may process selected health/fitness measurements and feature-scoped location.

3. Purposes and lawful bases

We use data to create and secure accounts, perform bookings and payments, provide requested features, communicate service messages, prevent fraud, comply with law, resolve disputes and improve reliability. Bases include contract, legal obligation, legitimate interests balanced against your rights and consent where required. Special-category health processing requires the applicable Article 9/KVKK condition, normally explicit consent for the optional feature.

4. Health and location

Health access is read-only, optional and not used for ads, marketing profiles, credit, employment or insurance decisions. We display the requested data types and purpose before consent, record the policy version and choice, minimise access, and allow permission and explicit consent to be withdrawn without affecting earlier lawful processing. Device measurements and wellness outputs may be incomplete or inaccurate and must not be relied on for medical or emergency decisions. Precise location is used only for the feature explained before permission; background collection requires a separate disclosure. Denial leaves non-dependent functions available.

5. Sharing

We share only necessary data with the provider you book, processors that host or deliver the service, payment and app-store providers, professional advisers and authorities where a lawful and proportionate duty applies. We do not sell personal data. Providers cannot see your relationships with other providers. Health data is not shared with a provider unless you deliberately choose to do so.

6. Processors and international transfers

The current Cookie/SDK and Subprocessor Notice identifies enabled services, purposes and regions. Transfers without an adequacy decision use the applicable SCCs, UK IDTA/Addendum or legally recognised KVKK mechanism, with transfer-risk review and supplementary security. A configuration entry being disabled means no data is sent to that integration.

7. Retention

We keep data only for its stated purpose: raw location up to 90 days, raw synced health data up to 12 months, crash events up to 90 days and backups up to 35 days after active deletion. Booking, payment, tax, consent, dispute and security records follow applicable legal limitation periods. Expired data is deleted or irreversibly anonymised; a documented legal hold preserves only its necessary scope.

8. Security

Controls include encryption in transit and where appropriate at rest, least privilege, strong authentication, tenant separation, secret management, audit logging, secure development, vulnerability handling, backups and incident response. Sensitive admin access is purpose-limited and recorded. No system is risk-free, but we maintain measures proportionate to the data and threat.

9. Your rights

Depending on applicable law you may request access, correction, deletion, restriction, portability and objection; withdraw consent; and request human review of a solely automated decision with legal or similarly significant effect. Requests are normally free and answered within the statutory period after proportionate identity verification.

10. Complaints, updates and contact

Privacy requests go to privacy@bukiby.com. You may complain to your competent data-protection authority. Material changes are notified before effect and a new purpose or sensitive-data scope requires a new lawful basis and, where required, fresh consent. Document version and consent evidence are retained.

11. Regional privacy and US consumer health data

EEA and UK users have GDPR/UK GDPR rights and may complain to their local authority; Türkiye users have KVKK rights and may apply to the Personal Data Protection Authority after the required controller process. Applicable US residents may know, access, correct, delete and obtain a portable copy, opt out of sale or sharing, limit sensitive-data use and appeal a refusal without discrimination. For Washington, Nevada and similar consumer-health laws, this separate Health and Location Notice identifies categories, sources, purposes and recipients; collection or sharing occurs only with required consent, sale would require a separate signed authorisation and we do not sell consumer health data. We honour withdrawal and deletion requests, including notice to processors where required, and do not geofence healthcare facilities for identification, tracking or advertising. A qualifying unsecured health-data breach is handled under the FTC Health Breach Notification Rule and applicable state notice laws. Bukiby is a consumer wellness platform and is not represented as a HIPAA-covered healthcare provider.

Operator and contact details

MIND TECH CONSULTANCY LTD
Trading as: Bukiby
Company number
11481944
VAT number
GB 338119402
Registered office
3 Orchid Mews, Harwell, Didcot, England, OX11 6EX
destek@bukiby.comBukiby