Privacy Policy

Privacy Policy for BuniAI

Effective Date: December 7, 2025

1. Introduction

Welcome to BuniAI! We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and disclose your information when you use our AI software for building USSD apps and chatbots by dragging and dropping flow nodes (hereinafter referred to as "the Service").

2. Information We Collect

2.1. Personal Information:

While using the Service, we may collect personal information such as:

  • Your name
  • Contact information (email address, phone number)
  • User-generated content within the Service
  • Organization and team information
  • Billing and payment information

2.2. Usage Data:

We may collect usage data, including but not limited to:

  • Log files
  • Device information (hardware model, operating system version)
  • IP address
  • Browser type
  • Pages viewed
  • Workflow and conversation analytics
  • Session information and interaction patterns

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide and improve our Service
  • To communicate with you about updates, news, and support
  • To personalize and enhance your experience
  • To analyze and monitor usage patterns
  • To process payments and manage subscriptions
  • To enable integration features with third-party services
  • To provide customer support and troubleshooting

4. Third-Party Integration Services

4.1. Integration Partners:

Our Service allows you to optionally connect and integrate with various third-party services to enhance your workflows. These integrations are entirely optional and only activated when you explicitly configure them. Our integration partners include:

  • CRM Systems: Salesforce, HubSpot, Zendesk
  • Communication Platforms: Gmail, Twilio, Infobip
  • Productivity Tools: Google Sheets, Google Calendar, Calendly
  • Database Services: Airtable
  • Payment Processing: Stripe
  • Project Management: Jira
  • Automation Platforms: Make (Integromat)

4.2. Authentication Methods:

When you choose to connect third-party services, we support two authentication methods:

  • OAuth 2.0: For services like Gmail, Google Sheets, Google Calendar, HubSpot, Zendesk, and Calendly. We store encrypted OAuth access tokens and refresh tokens to maintain your authorized connections.
  • API Keys: For services like Airtable, Salesforce, Twilio, Infobip, Jira, Stripe, and Make. We store your API keys and authentication credentials in encrypted form to enable service connections.

4.3. Credential Security:

We take the security of your third-party credentials extremely seriously:

  • All credentials (OAuth tokens and API keys) are encrypted at rest using industry-standard encryption
  • Credentials are only accessible to authorized system processes required to execute your workflows
  • We never share your credentials with other users or third parties
  • You can revoke access and delete stored credentials at any time through your account settings
  • We recommend periodically rotating API keys and re-authorizing OAuth connections

4.4. Data Sharing with Integrated Services:

When you configure integrations, data may be shared between BuniAI and the connected services based on your workflow configurations:

  • Outbound Data: Data you specify in your workflows (such as customer information, messages, form responses) may be sent to integrated services to perform actions like creating contacts, sending emails, or updating records.
  • Inbound Data: We may retrieve data from integrated services (such as contact lists, email content, calendar events, or database records) to use within your workflows when you configure such retrieval.
  • User Control: You have complete control over what data is shared through your workflow configurations. Data sharing only occurs for integrations you explicitly set up and according to the logic you define.

4.5. Third-Party Service Scopes:

Different integrations access different types of data based on the permissions you grant. Examples include:

  • Gmail: Send emails and compose replies on your behalf
  • Google Sheets: Read and write data to your spreadsheets
  • Google Calendar: Create, view, and modify calendar events
  • Salesforce/HubSpot: Access and modify CRM data, contacts, leads, and deals
  • Stripe: Access customer and payment information
  • Zendesk/Jira: Create and manage support tickets and issues
  • Twilio/Infobip: Send SMS and voice communications

We encourage you to review the privacy policies of each third-party service you connect to understand how they handle your data. Links to their privacy policies are available on their respective websites.

5. Integration Data Processing and Retention

5.1. Data Processing:

When you use integrations, we process data as necessary to execute your workflows:

  • We temporarily process data in transit between your workflows and integrated services
  • We may log integration activity for troubleshooting and analytics purposes
  • We do not use data from your integrations for any purpose other than providing the Service

5.2. Data Retention:

For integrated services:

  • Workflow configurations and integration settings are retained as long as your account is active
  • Credentials are retained until you disconnect the integration or delete your account
  • Integration activity logs are retained for a limited period (typically 90 days) for support purposes
  • You can disconnect integrations at any time, which will delete stored credentials

5.3. Disconnecting Integrations:

You have the right to disconnect any integration at any time:

  • Navigate to your organization's Credentials page
  • Select the integration you wish to disconnect
  • Click "Delete" or "Disconnect"
  • All associated credentials will be permanently deleted from our systems
  • You may also need to revoke access from the third-party service's settings

6. Data Security

We take appropriate security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:

  • End-to-end encryption for data in transit using TLS/SSL
  • Encryption at rest for sensitive data including credentials and API keys
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Secure credential storage using industry-standard practices

However, please note that no data transmission over the internet or storage system can be guaranteed to be 100% secure. We continuously work to improve our security measures.

7. Third-Party Service Links

Our Service may contain links to third-party websites or services beyond our integration partners. We are not responsible for the privacy practices or content of these third parties. We encourage you to read the privacy policies of any third-party websites or services you visit.

8. Cookies and Tracking Technologies

We may use cookies and similar tracking technologies to collect information and improve your experience. You can control cookies through your browser settings. We use cookies for:

  • Authentication and session management
  • User preferences and settings
  • Analytics and performance monitoring
  • Security and fraud prevention

9. Data Retention

We will retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Account information is retained while your account is active
  • Workflow data is retained for the duration of your subscription
  • Integration credentials are retained until you disconnect the integration
  • Analytics and usage data may be retained in aggregated form indefinitely
  • Upon account deletion, we will delete or anonymize your data within 90 days

10. Your Rights

You have the following rights regarding your personal information:

  • Access: Request access to your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data
  • Portability: Request a copy of your data in a portable format
  • Objection: Object to certain processing of your data
  • Revocation: Withdraw consent for data processing

To exercise these rights, please contact us at admin@buni.ai.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.

12. Children's Privacy

Our Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page, and the "Effective Date" will be updated accordingly. We encourage you to review this Privacy Policy periodically. Material changes will be communicated via email or through a prominent notice on our Service.

14. Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us at admin@buni.ai.