BuniAtlas

Health Technology for Africa

Back to Home

Privacy Policy

Effective Date: 15 June 2025

Last updated: June 2026

1. Introduction

Buni Health ("Buni", "we", "us", or "our") is committed to protecting the privacy and security of the personal data and clinical data entrusted to us. This Privacy Policy describes how we collect, use, store, share, and protect information when you use any product or service within the Buni Atlas suite — including Flamingo, Meridian, PharmaCare, Vigil, and AskBuni — or when you interact with our website at buni.health.

"Buni Health Technologies" refers collectively to Buni Systems Inc. (a Delaware corporation) and its Kenyan operating subsidiary, Buni Health Limited. Our processing of personal data is governed by the Data Protection Act, 2019 (Kenya), the regulations and guidance issued by the Office of the Data Protection Commissioner (ODPC), and applicable international data protection standards.

This Policy applies to: (a) health facilities and their authorised staff who access Buni Atlas products; (b) patients and individuals whose health data is processed through Buni systems on behalf of a facility; (c) diaspora insurance subscribers using Buni Vigil; and (d) visitors to the buni.health website. By using any Buni service, you acknowledge that you have read and understood this Policy.

2. Who Is Responsible for Your Data

For the purposes of Kenyan data protection law, Buni Health acts in two distinct capacities:

2.1 As a Data Controller

Buni is the data controller in respect of: (a) account and registration data of Facility administrators and Authorised Users; (b) data collected from visitors to buni.health; and (c) diaspora insurance subscriber data collected directly by Buni through the Vigil platform.

2.2 As a Data Processor

Buni acts as a data processor in respect of patient clinical data submitted to Buni systems by health facilities. In this capacity, Buni processes such data only on the documented instructions of the Facility (the data controller). The Facility bears primary responsibility for ensuring that patients have been informed of, and where required have consented to, the processing of their health data.

Our Data Protection Officer can be contacted at: dpo@buni.health

3. Categories of Personal Data We Collect

3.1 Facility Account Data

When a health facility registers for Buni services, we collect:

  • Facility name, address, licence number, and regulatory registration details
  • Contact information of the facility's authorised representative(s)
  • Login credentials for Authorised Users (email address, hashed passwords)
  • Billing and payment information (processed through PCI-compliant payment infrastructure)
  • M-Pesa or bank details for payment processing under applicable M-Pesa Daraja API agreements

3.2 Clinical Data (Processed on Behalf of Facilities)

In the course of providing Buni Atlas services to health facilities, we may process the following categories of patient clinical data on behalf of facilities:

  • Patient demographics: full name, national ID or passport number, date of birth, sex, county of residence
  • Clinical records: diagnoses (ICD-11 coded), prescriptions, clinical notes, referral records, and discharge summaries
  • Insurance and billing information: SHA membership number, insurer details, claims data
  • Pharmacy dispensing records processed through Buni PharmaCare
  • Public health surveillance datasets submitted to the DHA ESB via Buni Flamingo

This data constitutes special category (sensitive) data under the Data Protection Act, 2019. Buni implements enhanced safeguards for all health data processing.

3.3 Diaspora Insurance Subscriber Data (Vigil)

For individuals subscribing to diaspora health cover through Buni Vigil, we collect:

  • Full name, nationality, date of birth, and country of residence
  • Contact details (email, phone number)
  • Identity verification documents
  • Beneficiary details (names and relationship to subscriber)
  • Payment information for premium collection
  • Health declarations as required by the insurance underwriter

3.4 Website and Technical Data

When you visit buni.health, we may collect:

  • IP address, browser type, and device information
  • Pages visited, time spent, and referral source
  • Cookies and similar tracking technologies (see Section 11)

4. Purposes and Legal Bases for Processing

4.1 Service Delivery

Providing, operating, and maintaining the Buni Atlas products and services; processing DHA ESB onboarding and Legal Notice 77/2025 minimum health dataset submissions on behalf of facilities; generating clinical reports, dashboards, and analytics for facilities. Legal basis: performance of contract; legal obligation.

4.2 Regulatory Compliance

Fulfilling obligations under the Data Protection Act, 2019; responding to lawful requests from the ODPC, DHA, SHA, or other regulatory authorities; maintaining records as required by applicable health sector regulations. Legal basis: legal obligation.

4.3 AI-Assisted Clinical Intelligence (AskBuni)

Processing clinical data inputs to generate ICD-11 coding suggestions, clinical decision support outputs, and aggregated health analytics. AskBuni processing is performed on anonymised or pseudonymised data wherever possible. Outputs are informational and do not substitute for professional clinical judgement. Legal basis: legitimate interests of the Facility; performance of contract.

4.4 Insurance Services (Vigil)

Processing subscriber data to facilitate health insurance placement, premium collection, and claims administration in partnership with IRA-licensed underwriters. Legal basis: performance of contract; legitimate interests.

4.5 Security and Fraud Prevention

Monitoring access logs and usage patterns to detect and prevent unauthorised access, fraud, and data breaches. Legal basis: legitimate interests; legal obligation.

4.6 Product Improvement

Analysing aggregated, anonymised usage data to improve service quality and reliability. We do not use identifiable patient data for product training or development without explicit informed consent. Legal basis: legitimate interests.

5. Data Sharing and Third Parties

Buni does not sell, rent, or trade personal data. We share data only in the following circumstances:

5.1 Regulatory Bodies

We transmit health dataset records to the DHA Enterprise Service Bus on behalf of facilities, as mandated by Legal Notice 77 of 2025 and DHA onboarding requirements. Data shared with the DHA is governed by the DHA's own data governance frameworks.

5.2 Insurance Underwriters (Vigil)

Subscriber data is shared with IRA-licensed insurance underwriters solely for the purposes of policy issuance, premium processing, and claims administration. Underwriters are contractually bound to process data in compliance with applicable law.

5.3 Technology Sub-processors

Buni may engage sub-processors for cloud infrastructure, payment processing, communication services, and AI model inference. All sub-processors are bound by data processing agreements that require compliance with Kenyan data protection law and equivalent international standards. A current list of sub-processors is available upon written request to dpo@buni.health.

5.4 Legal Requirements

We may disclose data where required by Kenyan law, court order, or lawful direction from a competent authority. Where permitted, we will notify the affected party before making such disclosure.

5.5 Business Transfers

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify affected parties of any such change and ensure appropriate data protection safeguards are maintained.

6. Data Residency and International Transfers

Buni is committed to data localisation for health data. Clinical data processed on behalf of Kenyan health facilities is stored on infrastructure hosted within Kenya or the East African region, consistent with emerging data localisation requirements under Kenyan health sector regulations.

Where Buni Systems Inc. (Delaware) processes any data in connection with corporate administration, such transfers comply with the cross-border data transfer provisions of the Data Protection Act, 2019, including the application of appropriate safeguards such as standard contractual clauses or adequacy determinations recognised by the ODPC.

7. Data Retention

Buni retains personal data for the minimum period necessary to fulfil the purposes for which it was collected, consistent with applicable legal retention obligations:

  • Facility account data: retained for the duration of the subscription and for five (5) years thereafter for legal and audit purposes
  • Clinical data (processed as data processor): retained for the period specified in the Data Processing Agreement with the Facility, subject to a minimum of seven (7) years as required under the Kenya Health Act for medical records
  • Vigil insurance subscriber data: retained for the duration of the insurance policy and for five (5) years thereafter
  • Website and technical data: retained for up to twelve (12) months
  • AskBuni query logs: retained in pseudonymised form for up to twenty-four (24) months for service quality monitoring

Upon expiry of the applicable retention period, data is securely deleted or anonymised.

8. Security Measures

Buni implements technical and organisational security measures proportionate to the sensitivity of health data, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest using industry-standard algorithms
  • Role-based access control (RBAC) limiting data access to Authorised Users with a documented need
  • Multi-factor authentication for administrative and privileged access
  • Regular security assessments, penetration testing, and vulnerability management
  • Audit logging of access to clinical data, with tamper-evident log retention
  • Incident response procedures aligned with ODPC breach notification requirements (72-hour notification to ODPC where required)

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Buni will notify the ODPC and affected data controllers within the timeframes prescribed by the Data Protection Act, 2019.

No method of transmission over the internet or electronic storage is 100% secure. While we implement commercially reasonable measures to protect your information, we cannot guarantee absolute security.

9. Patient Consent

As a healthcare provider using our platform, you are responsible for obtaining appropriate consent from your patients for the collection, use, and disclosure of their personal data. Buni processes patient clinical data strictly as a data processor acting on the instructions of the Facility. The Facility, as data controller, bears primary responsibility for informing patients of their rights and obtaining any required consent before submitting data to Buni systems.

10. Your Rights as a Data Subject

Under the Data Protection Act, 2019 (Kenya), you have the following rights in relation to your personal data:

  • Access: request confirmation of whether we hold your data and obtain a copy
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your data where there is no legal basis for continued processing
  • Restriction: request that we limit processing of your data in certain circumstances
  • Portability: receive your data in a structured, commonly used, machine-readable format
  • Objection: object to processing based on legitimate interests
  • Withdrawal of Consent: withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing

To exercise any of these rights, please submit a written request to dpo@buni.health. We will respond within thirty (30) days of receiving a valid request.

Patients wishing to exercise rights in relation to their clinical data held by a Facility should contact the Facility directly, as Buni processes such data as a data processor on the Facility's behalf.

If you are dissatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya at www.odpc.go.ke.

11. Cookies and Tracking Technologies

The buni.health website uses cookies and similar technologies to support website functionality, security, and analytics. We use:

  • Essential cookies: necessary for secure login, session management, and portal functionality
  • Analytics cookies: to understand how visitors interact with our website, using tools that anonymise IP addresses where possible
  • Preference cookies: to remember your language and display settings

We do not use cookies for targeted advertising or cross-site tracking. You may manage cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use Buni portals.

12. Children's Data

Buni's products are intended for use by health facilities and professionals, not directly by minors. However, health facilities routinely provide care to children, and as a result Buni may process clinical data relating to minors as a data processor on behalf of a Facility. Such data is treated as sensitive data and subject to enhanced security controls. Buni does not knowingly collect personal data directly from minors without appropriate parental or guardian consent.

13. Changes to This Privacy Policy

Buni may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data practices. Material changes will be communicated by email notification to Facility account holders and by prominent notice on buni.health at least thirty (30) days before the changes take effect. We encourage you to review this Policy periodically. The effective date at the top of this document indicates when the Policy was last revised.

14. Contact and Data Protection Officer

For questions, concerns, or to exercise your data subject rights, please contact:

Data Protection Officer
Buni Health Limited
The Prism, Ngong Road, Kilimani
Nairobi, Kenya

DPO: dpo@buni.health
General enquiries: support@buni.health
Website: buni.health

Buni Health is in the process of registering with the Office of the Data Protection Commissioner of Kenya as a data controller and data processor.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the ODPC at www.odpc.go.ke.

Buni Atlas Core

Clinical Infrastructure Layer for East Africa

Contact

Contact Us

Designed for the realities of rural and urban clinical delivery. Syncing counties, specialists, chemists, and sponsors over legacy telecom and modern databases.© 2026 Buni Inc.

We use cookies and similar technologies to enhance your browsing experience, analyze site traffic, and deliver personalized content. By clicking "Accept All", you consent to our use of cookies.

Learn more in our Privacy Policy