Privacy Policy
i Our Commitment to Your Privacy
Prime Focus Uganda Limited ("we", "us", or "our") operates the Primebooks platform. We are committed to protecting your personal data in accordance with the Uganda Data Protection and Privacy Act, 2019 and all other applicable laws.
1 Who This Policy Applies To
This policy applies to all visitors to primebooks.sale, registered account holders, Authorised Users of a Primebooks workspace, and anyone who contacts us for support. "You" refers to any of the above.
2 Data We Collect
2.1 Information You Provide Directly
- Account registration: company name, subdomain, email address, phone number, country, first/last name, password (hashed — never stored in plain text).
- Business details: industry, business type, estimated number of users.
- Client Data: invoices, inventory records, customer records, financial transactions, and all other data you enter into the Platform.
- Support communications: tickets, chat messages, emails.
2.2 Data Collected Automatically
- Log data: IP address, browser type and version, pages visited, timestamps, referring URL.
- Device data: operating system, screen resolution, device type.
- Usage data: features used, module interactions, session duration — used only for product improvement.
- Cookies: essential session and preference cookies only. See Section 9.
2.3 Data from Third Parties
If you sign up via a referral partner, we receive your company name and email from that partner solely to attribute the referral. We do not purchase marketing lists or receive data from data brokers.
3 How We Use Your Data
- Provide the Platform: Provision your workspace, authenticate users, process transactions.
- Billing & payments: Generate invoices, process payments, handle subscription management.
- Support: Respond to tickets, diagnose technical issues, provide onboarding assistance.
- Security: Detect fraud, prevent abuse, monitor for unauthorised access.
- Product improvement: Aggregate usage analytics to guide feature development. We never profile you individually for advertising.
- Legal compliance: Meet obligations under Ugandan law and respond to lawful authority requests.
- Communications: Transactional emails only (account creation, password reset, invoices). Marketing emails require your explicit consent.
4 Legal Basis for Processing
- Contract performance: Processing necessary to provide the Platform under our Terms of Service.
- Legitimate interests: Fraud prevention, security monitoring, product analytics.
- Legal obligation: Tax records, regulatory reporting.
- Consent: Marketing communications — you may withdraw at any time.
5 Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share data only as follows:
- Service providers: Hosting infrastructure, email delivery, payment processing — bound by data-processing agreements and confidentiality obligations.
- Legal requirements: When required by Ugandan law, court order, or regulatory authority. We will notify you where legally permitted.
- Business transfers: In the event of a merger or acquisition, data may transfer to the successor entity under equivalent protections.
- Your consent: Any other sharing only with your explicit prior consent.
6 Data Location & International Transfers
7 Data Retention
- Active accounts: Data retained for the duration of your subscription.
- After termination: Client Data available for export for 30 days, then securely deleted within 90 days.
- Backups: Automated backups retained for 30 days.
- Log data: Retained for up to 12 months for security and debugging.
- Legal obligations: Financial records retained for 7 years as required by Ugandan tax law.
8 Cookies
We use only essential cookies required for the Platform to function:
- sessionid: Keeps you logged in during a browser session.
- csrftoken: Protects against cross-site request forgery (security requirement).
- Theme preference: Remembers your light/dark mode choice.
We do not use advertising, tracking, or third-party analytics cookies. You can disable cookies in your browser, but some Platform features will not function correctly.
9 Security
- AES-256 encryption for data at rest.
- TLS 1.2+ encryption for all data in transit.
- Regular third-party security audits and vulnerability assessments.
- Role-based access controls; staff access to Client Data is limited and logged.
- Multi-tenant data isolation: your workspace data is logically separated from all other tenants.
- Breach notification within 72 hours of discovering a breach affecting your data.
10 Your Rights
Under the Uganda Data Protection and Privacy Act, 2019, you have the following rights:
To exercise any of these rights, contact us at primefocusug@gmail.com. We will respond within 30 days.
11 Children's Privacy
The Platform is intended for business use and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us immediately.
12 Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the Platform at least 30 days before the change takes effect. Continued use of the Platform after the effective date constitutes acceptance.
13 Contact & Complaints
- Data Controller: Prime Focus Uganda Limited
- Email: primefocusug@gmail.com
- Phone / WhatsApp: +256 785 230 670
- Address: Sentamu Kavule A, Nakawa, Kampala, Uganda