Privacy
A clearer privacy policy for how BuniAI handles data today
This policy explains what information BuniAI processes, why we process it, and where third-party services fit into the delivery of the platform.
It is intentionally written to be understandable without claiming protections or hosting models that do not exist today.
What this notice covers
1.Overview
This Privacy Policy describes how BuniAI Ltd (collectively, BuniAI, we, us, and our) collects, uses, stores, shares, and otherwise processes personal information when you use our website, software platform, hosted services, and related support channels.
BuniAI helps teams design, test, deploy, and manage chatbot, automation, and USSD workflows. Because the service involves hosted applications, integrations, analytics, and AI-assisted features, we need to process information in order to provide the platform.
Where we process personal data of people in the European Economic Area, we do so in accordance with the EU General Data Protection Regulation (GDPR), which applies to us under Article 3 regardless of our being established in Rwanda. We also process personal data under Rwanda's Law No. 058/2021 relating to the protection of personal data and privacy.
Two different roles. For our own account, billing, support and marketing data we are the controller — we decide why and how it is processed. For the end-users who interact with workflows our customers build, we are a processor: the customer organisation decides what is collected and why, and we act on their documented instructions. Which role applies changes who can act on a request about that data, and is set out under Lawful basis below.
Categories of data
2.Information we collect
Depending on how you use BuniAI, we may collect the following categories of information:
- Account and contact information: such as your name, email address, phone number, organization details, and billing contact details.
- Customer content: such as workflow definitions, prompts, messages, chatbot content, uploaded materials, user responses, and project configuration data.
- Integration credentials and tokens: such as API keys, access tokens, refresh tokens, and other secrets you provide when connecting external services.
- Usage and device information: such as IP address, browser type, device characteristics, operating system, session data, feature usage, page views, performance information, and error telemetry.
- Billing and transaction information: such as subscription status, invoice information, and payment-related records processed through our payment provider.
- Support and communications data: such as messages you send to us, support tickets, meeting requests, and feedback.
Sources
3.How we collect information
We collect information in three main ways:
- Directly from you when you register, configure a workspace, connect an integration, contact support, or submit content into the platform.
- Automatically when you use the website or application, including through logs, essential cookies, analytics tools you consent to, and technical monitoring.
- From connected services when you authorize integrations and request data to be read from or written to third-party systems.
Processing purposes
4.How we use information
We use personal information to:
- provide, operate, maintain, and secure BuniAI;
- create and manage accounts, teams, plans, and billing relationships;
- process workflow execution, integrations, and user-configured automations;
- support AI-assisted features and provider requests initiated through the product;
- respond to support requests, product feedback, and operational communications;
- understand product performance and improve reliability and usability;
- detect abuse, investigate incidents, and enforce our Terms;
- comply with legal obligations and defend our legal rights.
Why we are allowed to
5.Lawful basis for each processing activity
GDPR requires a specific lawful basis for each processing activity, not a single blanket justification. Where we act as controller, these are ours:
- Account creation, authentication, and delivery of the service — Article 6(1)(b), performance of our contract with you.
- Billing, subscriptions, and transaction records — Article 6(1)(b) for the contract, and Article 6(1)(c) where tax and accounting law requires us to retain records.
- Support requests and operational notices — Article 6(1)(b).
- Demo requests, build requests, and other forms you submit — Article 6(1)(a), your consent, withdrawable at any time.
- Product analytics — Article 6(1)(a), your consent, collected only where you accept analytics cookies and not otherwise.
- Security logging, abuse detection, and incident investigation — Article 6(1)(f), our legitimate interest in keeping the platform secure, balanced against your rights.
- Product update and digest emails to existing customers — Article 6(1)(f), with an unsubscribe link in every message.
Where we act as processor — for the end-users of workflows our customers build — the lawful basis is the customer organisation's to establish, not ours. We process that data only on their documented instructions, under a data processing agreement.
Special category data. Customers can build workflows that collect health or other Article 9 data. Where they do, the customer is responsible for establishing a valid Article 9 condition — usually explicit consent or a public-interest exemption — and for carrying out a Data Protection Impact Assessment before launch.
Feature-specific processing
6.Integrations, credentials, and AI processing
BuniAI supports optional integrations with third-party tools such as CRM, support, messaging, spreadsheet, calendar, automation, payment, and database services. When you connect those services, we process the credentials and tokens needed to execute the workflows you configure.
- Credentials and tokens are stored in encrypted form and are used only by authorized service processes that need them to run the integration.
- Data may flow out to connected services or into BuniAI depending on the workflow you design.
- You control which integrations are enabled and what information your workflows send or retrieve.
BuniAI also offers AI-assisted features that may send prompts, workflow context, or other relevant inputs to third-party AI providers selected within the product. Those providers process data only to deliver the requested feature or response.
How long we keep data
9.Retention and deletion
We keep information for as long as necessary to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account and organization records are generally kept while the account remains active.
- Workflow data, configuration, and integration settings are retained while needed to provide the service to your workspace.
- Credentials are retained until you disconnect the integration, replace the secret, or delete the relevant account or workspace, subject to limited backup retention.
- Logs, security records, and analytics data may be retained for shorter or longer periods depending on operational necessity and legal requirements.
How we protect data
10.Security safeguards
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction.
- Encryption in transit is used for data moving through supported network channels.
- Sensitive credentials are stored in encrypted form.
- Access to systems and data is limited to authorized processes and personnel.
- We monitor platform reliability and investigate suspected misuse or security events.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Control and access
11.International transfers and your rights
Where your data goes. BuniAI Ltd is registered in Rwanda, and the platform runs on Amazon Web Services in the United States (us-east-1). Personal data you give us is therefore processed outside the EEA, and outside Rwanda.
Neither Rwanda nor the relevant United States transfer is covered by an EU adequacy decision applicable to us. Transfers of personal data from the EEA therefore rely on Standard Contractual Clauses executed between BuniAI and the customer acting as controller, and between BuniAI and each of our sub-processors. We name our sub-processors rather than describe them in categories — see the list on our Data Privacy page.
Your rights. Under GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time where consent is the basis we rely on. You also have the right to lodge a complaint with your supervisory authority. Rwanda's Law No. 058/2021 provides comparable rights.
To exercise a request, contact privacy@buni.ai. We will respond within one month, as Article 12(3) requires, and will tell you inside that month if a complex request needs longer. We may need to verify your identity first, and will not ask for more information than the request itself involves.
If you are an end-user of a service built on BuniAI — for example you messaged a chatbot run by an organisation that uses us — that organisation is the controller of your data, not us. We generally cannot act on your request on our own. Write to us and we will identify the organisation concerned and pass your request to them, or you can approach them directly.
Closing notes
12.Children, updates, and contact
BuniAI is not intended for children under 18, and we do not knowingly collect personal information from children through the platform.
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. When we do, we will update the effective date on this page.
Questions about this notice or our privacy practices can be sent to privacy@buni.ai. For anything else, including billing and support, use support@buni.ai.