Privacy Notice
Effective 2026-09-21.
This notice explains how buki collects, uses and protects personal data.
1. Controller and scope
MIND TECH CONSULTANCY LTD operates buki and is controller for platform accounts, security, support and product operations. An independent provider is controller for the professional service and records it determines. The role matrix and Data Processing Addendum govern processing performed on a provider’s documented instructions.
2. Data we collect
We process account and contact details; profile and uploaded media; search, booking and attendance data; selected contact details; messages, reviews and reports; payment tokens and transaction references; device, network, consent, security and support records. With separate permission we may process selected health/fitness measurements and feature-scoped location.
3. Sources
Data comes from you, your device and permitted operating-system services, providers you interact with, payment/app-store providers and security signals. We do not buy health data or upload your address book. A provider may add necessary booking details under its own notice.
4. Purposes and lawful bases
We use data to create and secure accounts, perform bookings and payments, provide requested features, communicate service messages, prevent fraud, comply with law, resolve disputes and improve reliability. Bases include contract, legal obligation, legitimate interests balanced against your rights and consent where required. Special-category health processing requires the applicable Article 9/KVKK condition, normally explicit consent for the optional feature.
5. Health and location
Health access is read-only, optional and not used for ads, marketing profiles, credit, employment or insurance decisions. We display the requested data types and purpose before consent, record the policy version and choice, minimise access, and allow permission and explicit consent to be withdrawn without affecting earlier lawful processing. Device measurements and wellness outputs may be incomplete or inaccurate and must not be relied on for medical or emergency decisions. Precise location is used only for the feature explained before permission; background collection requires a separate disclosure. Denial leaves non-dependent functions available.
6. Sharing
We share only necessary data with the provider you book, processors that host or deliver the service, payment and app-store providers, professional advisers and authorities where a lawful and proportionate duty applies. We do not sell personal data. Providers cannot see your relationships with other providers. Health data is not shared with a provider unless you deliberately choose to do so.
7. Processors and international transfers
The current Cookie/SDK and Subprocessor Notice identifies enabled services, purposes and regions. Transfers without an adequacy decision use the applicable SCCs, UK IDTA/Addendum or legally recognised KVKK mechanism, with transfer-risk review and supplementary security. A configuration entry being disabled means no data is sent to that integration.
8. Retention
We keep data only for its stated purpose: raw location up to 90 days, raw synced health data up to 12 months, crash events up to 90 days and backups up to 35 days after active deletion. Booking, payment, tax, consent, dispute and security records follow applicable legal limitation periods. Expired data is deleted or irreversibly anonymised; a documented legal hold preserves only its necessary scope.
9. Security
Controls include encryption in transit and where appropriate at rest, least privilege, strong authentication, tenant separation, secret management, audit logging, secure development, vulnerability handling, backups and incident response. Sensitive admin access is purpose-limited and recorded. No system is risk-free, but we maintain measures proportionate to the data and threat.
10. Your rights
Depending on applicable law you may request access, correction, deletion, restriction, portability and objection; withdraw consent; and request human review of a solely automated decision with legal or similarly significant effect. Requests are normally free and answered within the statutory period after proportionate identity verification.
11. Deletion
Delete an account in app or through the public deletion route. We close access, stop ordinary processing, remove or anonymise profile and social content, revoke push tokens and send deletion to processors. Required financial, fraud or legal records are isolated and not reused. Backups expire within their normal cycle and restored data receives the deletion instruction again.
12. Children
The general service is for users meeting the configured minimum age. We do not knowingly create an under-age account without an approved guardian model. Suspected child exploitation is urgently restricted, preserved only as legally required and reported to the competent authority where required.
13. Marketing and cookies
Service messages do not require marketing consent. Optional marketing and non-essential analytics use the choice and withdrawal controls required in the user’s country. Refusing is as easy as accepting and does not block core booking. Health, precise location and contact data are excluded from advertising audiences.
14. Complaints, updates and contact
Privacy requests go to privacy@bukiby.com. You may complain to your competent data-protection authority. Material changes are notified before effect and a new purpose or sensitive-data scope requires a new lawful basis and, where required, fresh consent. Document version and consent evidence are retained.
15. Regional privacy and US consumer health data
EEA and UK users have GDPR/UK GDPR rights and may complain to their local authority; Türkiye users have KVKK rights and may apply to the Personal Data Protection Authority after the required controller process. Applicable US residents may know, access, correct, delete and obtain a portable copy, opt out of sale or sharing, limit sensitive-data use and appeal a refusal without discrimination. For Washington, Nevada and similar consumer-health laws, this separate Health and Location Notice identifies categories, sources, purposes and recipients; collection or sharing occurs only with required consent, sale would require a separate signed authorisation and we do not sell consumer health data. We honour withdrawal and deletion requests, including notice to processors where required, and do not geofence healthcare facilities for identification, tracking or advertising. A qualifying unsecured health-data breach is handled under the FTC Health Breach Notification Rule and applicable state notice laws. buki is a consumer wellness platform and is not represented as a HIPAA-covered healthcare provider.
16. AI-assisted search
When you choose AI search, we send the sentence you typed and the interface language to the configured external AI provider (OpenAI, Anthropic or Google Gemini) solely to turn it into search filters. The sentence may contain health or other sensitive information, so remove anything you do not want to share. We do not send precise location, account identifiers or structured health measurements. We do not write the raw sentence to our database or logs. We keep the provider's parsed response in server memory for up to 15 minutes; the provider may process or retain the request under its contract and published privacy terms. You can decline AI processing and use keyword search instead.
Operator and contact details
- MIND TECH CONSULTANCY LTD
- Trading as: buki
- Company number
- 11481944
- VAT number
- GB 338119402
- Registered office
- 3 Orchid Mews, Harwell, Didcot, England, OX11 6EX