Privacy policy

Last updated: 5 May 2026

Nyuchi Identity (“Nyuchi”, “we”) is operated by Bundu Foundation, a Zimbabwe company limited by guarantee (“Bundu Foundation CLG”). This notice describes what personal data we collect when you use the Nyuchi Identity platform, how we use it, and the rights you have over it. [placeholder: insert regulator references and DPO contact once appointed.]

Data we collect

We process the following categories of personal data:

  • Identity profile — fields stored on the identity.person record: legal name, preferred name, username, email, date of birth, locale, theme preference, profile photo URL, and any optional fields you add yourself.
  • Verification data — documents and attributes submitted during KYC, retained for the period required by [placeholder: applicable Zimbabwean and regional KYC rules].
  • Family membership — links between your person record and other members of your family entity.
  • Audit logs — timestamps, IP address, user-agent, and the action taken for security-relevant events (sign-in, consent, profile changes, MukokoID mints).
  • Technical telemetry — request metadata required to operate the service. [placeholder: enumerate once observability stack is finalised.]

How we use it

We use your personal data to:

  • authenticate you and maintain your session;
  • operate Bundu Family services you have opted into;
  • verify your identity for KYC and MukokoID issuance;
  • protect the platform from fraud and abuse;
  • comply with legal obligations [placeholder: list applicable statutes].

Our legal bases are: performance of a contract (providing the service you signed up for), legitimate interests (security and abuse prevention), legal obligation (KYC), and consent (optional features such as MukokoID minting).

Third parties

We rely on a small number of processors to deliver the service:

  • WorkOS — hosted authentication provider. Receives your email and authenticator metadata as part of the sign-in flow.
  • Cloudflare — transport and edge network. Receives request metadata and performs DDoS protection.
  • Supabase — managed Postgres storage for the identity.* schema and audit logs.

[placeholder: insert sub-processor list, regions, and links to each provider's data processing addendum.] We do not sell personal data to anyone.

Your rights

Subject to applicable law, you have the right to access, correct, delete, restrict, and port your personal data, and to withdraw consent at any time without affecting prior lawful processing. To exercise any of these rights contact us using the contact details below. We will respond within [placeholder: 30 days or local statutory window].

Cookies and local storage

We do not set tracking cookies. The platform JWT used to authenticate API calls is stored in your browser's sessionStorage for the duration of the tab and is discarded when you close it. Third-party providers (notably our hosted sign-in flow) may set their own cookies on their own domains during sign-in — those are governed by their respective privacy notices.

Children's data

Nyuchi Identity is not directed at children under [placeholder: minimum age — likely 16 under GDPR analogues, 18 for full KYC flows]. We do not knowingly collect personal data from children below that age except where added by a verified parent or guardian to their family entity, in which case the parent or guardian is the data controller of that record from our perspective.

Contact

Bundu Foundation
Zimbabwe CLG
[placeholder: registered address]
Email: support@nyuchi.com

Changes to this policy

We may update this policy from time to time. Material changes will be announced via in-product notice and the “Last updated” date above. Continued use of Nyuchi Identity after the effective date of an update constitutes acceptance of the revised policy. [placeholder: confirm acceptance mechanism with legal team.]