Privacy
A clearer privacy policy for how BuniAI handles data today
This policy explains what information BuniAI processes, why we process it, and where third-party services fit into the delivery of the platform.
It is intentionally written to be understandable without claiming protections or hosting models that do not exist today.
Last updated: 17 September 2026 · Type: Privacy Policy
What this notice covers
1.Overview
This Privacy Policy describes how BuniAI Ltd (collectively, BuniAI, we, us, and our) collects, uses, stores, shares, and otherwise processes personal information when you use our website, software platform, hosted services, and related support channels.
BuniAI helps teams design, test, deploy, and manage chatbot, automation, and USSD workflows. Because the service involves hosted applications, integrations, analytics, and AI-assisted features, we need to process information in order to provide the platform.
Where we process personal data of people in the European Economic Area, we do so in accordance with the EU General Data Protection Regulation (GDPR), which applies to us under Article 3 regardless of our being established in Rwanda. We also process personal data under Rwanda's Law No. 058/2021 relating to the protection of personal data and privacy.
Two different roles. For our own account, billing, support and marketing data we are the controller: we decide why and how it is processed. For the end-users who interact with workflows our customers build, we are a processor: the customer organisation decides what is collected and why, and we act on their documented instructions. Which role applies changes who can act on a request about that data, and is set out under Lawful basis below.
Categories of data
2.Information we collect
Depending on how you use BuniAI, we may collect the following categories of information:
- Account and contact information: such as your name, email address, phone number, organization details, and billing contact details.
- Customer content: such as workflow definitions, prompts, messages, chatbot content, uploaded materials, user responses, and project configuration data.
- Integration credentials and tokens: such as API keys, access tokens, refresh tokens, and other secrets you provide when connecting external services.
- Usage and device information: such as IP address, browser type, device characteristics, operating system, session data, feature usage, page views, performance information, and error telemetry.
- Billing and transaction information: such as subscription status, invoice information, and payment-related records processed through our payment provider.
- Support and communications data: such as messages you send to us, support tickets, meeting requests, and feedback.
Sources
3.How we collect information
We collect information in three main ways:
- Directly from you when you register, configure a workspace, connect an integration, contact support, or submit content into the platform.
- Automatically when you use the website or application, including through logs, essential cookies, analytics tools you consent to, and technical monitoring.
- From connected services when you authorize integrations and request data to be read from or written to third-party systems.
Processing purposes
4.How we use information
We use personal information to:
- provide, operate, maintain, and secure BuniAI;
- create and manage accounts, teams, plans, and billing relationships;
- process workflow execution, integrations, and user-configured automations;
- support AI-assisted features and provider requests initiated through the product;
- respond to support requests, product feedback, and operational communications;
- understand product performance and improve reliability and usability;
- detect abuse, investigate incidents, and enforce our Terms;
- comply with legal obligations and defend our legal rights.
Why we are allowed to
5.Lawful basis for each processing activity
GDPR requires a specific lawful basis for each processing activity, not a single blanket justification. Where we act as controller, these are ours:
- Account creation, authentication, and delivery of the service: Article 6(1)(b), performance of our contract with you.
- Billing, subscriptions, and transaction records: Article 6(1)(b) for the contract, and Article 6(1)(c) where tax and accounting law requires us to retain records.
- Support requests and operational notices: Article 6(1)(b).
- Demo requests, build requests, and other forms you submit: Article 6(1)(a), your consent, withdrawable at any time.
- Product analytics: Article 6(1)(a), your consent, collected only where you accept analytics cookies and not otherwise.
- Security logging, abuse detection, and incident investigation: Article 6(1)(f), our legitimate interest in keeping the platform secure, balanced against your rights.
- Product update and digest emails to existing customers: Article 6(1)(f), with an unsubscribe link in every message.
Where we act as processor (for the end-users of workflows our customers build), the lawful basis is the customer organisation's to establish, not ours. We process that data only on their documented instructions, under a data processing agreement.
Special category data. Customers can build workflows that collect health or other Article 9 data. Where they do, the customer is responsible for establishing a valid Article 9 condition (usually explicit consent or a public-interest exemption) and for carrying out a Data Protection Impact Assessment before launch.
Feature-specific processing
6.Integrations, credentials, and AI processing
BuniAI supports optional integrations with third-party tools such as CRM, support, messaging, spreadsheet, calendar, automation, payment, and database services. When you connect those services, we process the credentials and tokens needed to execute the workflows you configure.
- Credentials and tokens are stored in encrypted form and are used only by authorized service processes that need them to run the integration.
- Data may flow out to connected services or into BuniAI depending on the workflow you design. Those transfers happen at your direction, as steps you placed in a flow, and not otherwise.
- You control which integrations are enabled and what information your workflows send or retrieve.
BuniAI also offers AI-assisted features that may send prompts, workflow context, conversation history, or other relevant inputs to third-party AI providers selected within the product. Some of these run as steps inside your flows; others, such as the Inbox reply drafts your agents request, are features of the product that act on a conversation when someone asks them to. Those providers process data only to deliver the requested feature or response, and no input we send them is used to train their models.
Where any of this involves data obtained from Google APIs, the narrower commitments in Use of data from Google APIs apply and take precedence over the general description above.
Google user data
7.Use of data from Google APIs
Connecting Gmail, Google Sheets, Google Calendar, or Google Drive lets your workflows act on that account through Google APIs: sending mail from your address, reading and writing rows in a spreadsheet you identify, managing events on a calendar you choose, and opening, storing, and organising files in Drive. We request the permissions those steps need and not more: for Gmail, only the permission to send, never to read your mailbox. In Drive, what a workflow may read is wider than what it may change: files it did not create and was not given cannot be modified, deleted, or re-shared.
BuniAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data to run the steps you configured and to show you the result. AI features of the product may act on it where your steps have already brought it into a conversation.
- It is never used to train AI models, ours or a provider's, and never used for advertising. We do not sell it or pass it to data brokers.
- People do not read it, beyond the exceptions Google's policy allows: your own support request, security and abuse investigation, or a legal obligation.
- Connection tokens are stored encrypted. We keep no standing copy of your mailbox, spreadsheets, calendar, or Drive; Google data persists only where a step wrote it into your records, and expires with them.
Disconnect the integration in BuniAI, or revoke access at myaccount.google.com/permissions, and we delete the stored tokens. For deletion of Google data already in your workspace records, write to privacy@buni.ai.
How long we keep data
10.Retention and deletion
We keep information for as long as necessary to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account and organization records are generally kept while the account remains active.
- Workflow data, configuration, and integration settings are retained while needed to provide the service to your workspace.
- Credentials are retained until you disconnect the integration, replace the secret, or delete the relevant account or workspace, subject to limited backup retention.
- Logs, security records, and analytics data may be retained for shorter or longer periods depending on operational necessity and legal requirements.
How we protect data
11.Security safeguards
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction.
- Encryption in transit is used for data moving through supported network channels.
- Sensitive credentials are stored in encrypted form.
- Access to systems and data is limited to authorized processes and personnel.
- We monitor platform reliability and investigate suspected misuse or security events.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Control and access
12.International transfers and your rights
Where your data goes. BuniAI Ltd is registered in Rwanda, and the platform runs on Amazon Web Services in the United States (us-east-1). Personal data you give us is therefore processed outside the EEA, and outside Rwanda.
Neither Rwanda nor the relevant United States transfer is covered by an EU adequacy decision applicable to us. Transfers of personal data from the EEA therefore rely on Standard Contractual Clauses executed between BuniAI and the customer acting as controller, and between BuniAI and each of our sub-processors. We name our sub-processors rather than describe them in categories; see the list on our Data Privacy page.
Your rights. Under GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time where consent is the basis we rely on. You also have the right to lodge a complaint with your supervisory authority. Rwanda's Law No. 058/2021 provides comparable rights.
To exercise a request, contact privacy@buni.ai. We will respond within one month, as Article 12(3) requires, and will tell you inside that month if a complex request needs longer. We may need to verify your identity first, and will not ask for more information than the request itself involves.
If you are an end-user of a service built on BuniAI (for example, if you messaged a chatbot run by an organisation that uses us), that organisation is the controller of your data, not us. We generally cannot act on your request on our own. Write to us and we will identify the organisation concerned and pass your request to them, or you can approach them directly.
Closing notes
13.Children, updates, and contact
BuniAI is not intended for children under 18, and we do not knowingly collect personal information from children through the platform.
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. When we do, we will update the effective date on this page.
Questions about this notice or our privacy practices can be sent to privacy@buni.ai. For anything else, including billing and support, use support@buni.ai.
Privacy requests
Contact us if you need help with access, correction, deletion, or another privacy-related request.