Effective Date: 15 June 2025
Last updated: June 2026
Buni Health ("Buni", "we", "us", or "our") is committed to protecting the privacy and security of the personal data and clinical data entrusted to us. This Privacy Policy describes how we collect, use, store, share, and protect information when you use any product or service within the Buni Atlas suite — including Flamingo, Meridian, PharmaCare, Vigil, and AskBuni — or when you interact with our website at buni.health.
"Buni Health Technologies" refers collectively to Buni Systems Inc. (a Delaware corporation) and its Kenyan operating subsidiary, Buni Health Limited. Our processing of personal data is governed by the Data Protection Act, 2019 (Kenya), the regulations and guidance issued by the Office of the Data Protection Commissioner (ODPC), and applicable international data protection standards.
This Policy applies to: (a) health facilities and their authorised staff who access Buni Atlas products; (b) patients and individuals whose health data is processed through Buni systems on behalf of a facility; (c) diaspora insurance subscribers using Buni Vigil; and (d) visitors to the buni.health website. By using any Buni service, you acknowledge that you have read and understood this Policy.
For the purposes of Kenyan data protection law, Buni Health acts in two distinct capacities:
Buni is the data controller in respect of: (a) account and registration data of Facility administrators and Authorised Users; (b) data collected from visitors to buni.health; and (c) diaspora insurance subscriber data collected directly by Buni through the Vigil platform.
Buni acts as a data processor in respect of patient clinical data submitted to Buni systems by health facilities. In this capacity, Buni processes such data only on the documented instructions of the Facility (the data controller). The Facility bears primary responsibility for ensuring that patients have been informed of, and where required have consented to, the processing of their health data.
Our Data Protection Officer can be contacted at: dpo@buni.health
When a health facility registers for Buni services, we collect:
In the course of providing Buni Atlas services to health facilities, we may process the following categories of patient clinical data on behalf of facilities:
This data constitutes special category (sensitive) data under the Data Protection Act, 2019. Buni implements enhanced safeguards for all health data processing.
For individuals subscribing to diaspora health cover through Buni Vigil, we collect:
When you visit buni.health, we may collect:
Providing, operating, and maintaining the Buni Atlas products and services; processing DHA ESB onboarding and Legal Notice 77/2025 minimum health dataset submissions on behalf of facilities; generating clinical reports, dashboards, and analytics for facilities. Legal basis: performance of contract; legal obligation.
Fulfilling obligations under the Data Protection Act, 2019; responding to lawful requests from the ODPC, DHA, SHA, or other regulatory authorities; maintaining records as required by applicable health sector regulations. Legal basis: legal obligation.
Processing clinical data inputs to generate ICD-11 coding suggestions, clinical decision support outputs, and aggregated health analytics. AskBuni processing is performed on anonymised or pseudonymised data wherever possible. Outputs are informational and do not substitute for professional clinical judgement. Legal basis: legitimate interests of the Facility; performance of contract.
Processing subscriber data to facilitate health insurance placement, premium collection, and claims administration in partnership with IRA-licensed underwriters. Legal basis: performance of contract; legitimate interests.
Monitoring access logs and usage patterns to detect and prevent unauthorised access, fraud, and data breaches. Legal basis: legitimate interests; legal obligation.
Analysing aggregated, anonymised usage data to improve service quality and reliability. We do not use identifiable patient data for product training or development without explicit informed consent. Legal basis: legitimate interests.
Buni does not sell, rent, or trade personal data. We share data only in the following circumstances:
We transmit health dataset records to the DHA Enterprise Service Bus on behalf of facilities, as mandated by Legal Notice 77 of 2025 and DHA onboarding requirements. Data shared with the DHA is governed by the DHA's own data governance frameworks.
Subscriber data is shared with IRA-licensed insurance underwriters solely for the purposes of policy issuance, premium processing, and claims administration. Underwriters are contractually bound to process data in compliance with applicable law.
Buni may engage sub-processors for cloud infrastructure, payment processing, communication services, and AI model inference. All sub-processors are bound by data processing agreements that require compliance with Kenyan data protection law and equivalent international standards. A current list of sub-processors is available upon written request to dpo@buni.health.
We may disclose data where required by Kenyan law, court order, or lawful direction from a competent authority. Where permitted, we will notify the affected party before making such disclosure.
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify affected parties of any such change and ensure appropriate data protection safeguards are maintained.
Buni is committed to data localisation for health data. Clinical data processed on behalf of Kenyan health facilities is stored on infrastructure hosted within Kenya or the East African region, consistent with emerging data localisation requirements under Kenyan health sector regulations.
Where Buni Systems Inc. (Delaware) processes any data in connection with corporate administration, such transfers comply with the cross-border data transfer provisions of the Data Protection Act, 2019, including the application of appropriate safeguards such as standard contractual clauses or adequacy determinations recognised by the ODPC.
Buni retains personal data for the minimum period necessary to fulfil the purposes for which it was collected, consistent with applicable legal retention obligations:
Upon expiry of the applicable retention period, data is securely deleted or anonymised.
Buni implements technical and organisational security measures proportionate to the sensitivity of health data, including:
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Buni will notify the ODPC and affected data controllers within the timeframes prescribed by the Data Protection Act, 2019.
No method of transmission over the internet or electronic storage is 100% secure. While we implement commercially reasonable measures to protect your information, we cannot guarantee absolute security.
As a healthcare provider using our platform, you are responsible for obtaining appropriate consent from your patients for the collection, use, and disclosure of their personal data. Buni processes patient clinical data strictly as a data processor acting on the instructions of the Facility. The Facility, as data controller, bears primary responsibility for informing patients of their rights and obtaining any required consent before submitting data to Buni systems.
Under the Data Protection Act, 2019 (Kenya), you have the following rights in relation to your personal data:
To exercise any of these rights, please submit a written request to dpo@buni.health. We will respond within thirty (30) days of receiving a valid request.
Patients wishing to exercise rights in relation to their clinical data held by a Facility should contact the Facility directly, as Buni processes such data as a data processor on the Facility's behalf.
If you are dissatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya at www.odpc.go.ke.
The buni.health website uses cookies and similar technologies to support website functionality, security, and analytics. We use:
We do not use cookies for targeted advertising or cross-site tracking. You may manage cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use Buni portals.
Buni's products are intended for use by health facilities and professionals, not directly by minors. However, health facilities routinely provide care to children, and as a result Buni may process clinical data relating to minors as a data processor on behalf of a Facility. Such data is treated as sensitive data and subject to enhanced security controls. Buni does not knowingly collect personal data directly from minors without appropriate parental or guardian consent.
Buni may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data practices. Material changes will be communicated by email notification to Facility account holders and by prominent notice on buni.health at least thirty (30) days before the changes take effect. We encourage you to review this Policy periodically. The effective date at the top of this document indicates when the Policy was last revised.
For questions, concerns, or to exercise your data subject rights, please contact:
Data Protection Officer
Buni Health Limited
The Prism, Ngong Road, Kilimani
Nairobi, Kenya
DPO: dpo@buni.health
General enquiries: support@buni.health
Website: buni.health
Buni Health is in the process of registering with the Office of the Data Protection Commissioner of Kenya as a data controller and data processor.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the ODPC at www.odpc.go.ke.
We use cookies and similar technologies to enhance your browsing experience, analyze site traffic, and deliver personalized content. By clicking "Accept All", you consent to our use of cookies.
Learn more in our Privacy Policy