Legal
Data protection
Last updated: 25 August 2026. This page lists controls that are actually built into this website and the way we run client work. It is written for procurement and for users. It is not an ISO 27001 certificate, a penetration-test report, or a claim that a statutory data protection officer has been gazetted for this firm.
1. Roles
For data you submit on this website (forms, accounts, cart, applications), Front Star Digital Innovations determines the purposes. Contact: support@frontstardigital.com, P.O.BOX 202317 Kampala, Uganda.
For a client’s production system we host or build, the client usually remains the controller. We process personal data in that system only as the statement of work and any data-processing schedule allow: hosting, backups, support logins, and named integrations. We do not treat client databases as a marketing list.
2. Controls on this website
These items are implemented in the public site and portals, not promised as a future project:
- Prepared SQL statements for database queries, to reduce injection risk.
- CSRF tokens on state-changing forms (contact, requests, cart, checkout, login, applications).
- Honeypot fields and per-action rate limits on public forms, to cut automated spam.
- Passwords stored with bcrypt. Sessions regenerated at login. Repeated failed logins can lock the account for a period.
- Role-based access: visitors, clients, and administrators do not share one inbox of rights.
- Uploads such as resumes are kept out of a public URL tree so they are not guessed from the browser.
- Payment card data is not stored on this server. Checkout uses DPO hosted pay when keys are present.
- Optional Google Analytics loads only after cookie consent “Accept”, and only if an ID is saved in admin.
The site is served over the hosting stack we operate for it. TLS for the live domain is part of ordinary hosting, not a separate product name. We still expect you to use a current browser and not share passwords.
3. Organisational practice
- Written scope before build, where the contract requires it. Staging review before a public cutover when the project includes staging.
- Named owners on delivery work rather than an unnamed “offshore team” label.
- Client portal for tickets, files and invoices so the record is not only a personal inbox.
- Admin access limited to people who operate the firm. We do not publish staff passwords, SMTP secrets or DPO tokens in the public repository or in page source.
- Backups of this application’s data are stored outside a public download directory. Restore tests are an operations task, not a slogan on every page.
Staff who handle personal data are expected to use the portal and admin tools, not to copy databases onto unmanaged personal machines as a habit. That is policy. It is not a substitute for your own access reviews on a system we hand over to you.
4. Client systems we operate
When we run a client website, ERP, app or host, the controls in the statement of work apply: who may log in, where backups live, what monitoring is included, and when we may access production. We apply the same engineering bar we use on this site - authentication, roles, logging where scoped - but every product is not a copy of this CMS. A hospital or school system is specified in that project’s documents. We do not claim medical-device approval or a sector licence we do not hold.
After handover, your administrators are responsible for who they invite, for keeping their own passwords, and for telling us when an account should be removed. International hosting or subprocessors, if any, are named in that contract. This page does not secretly add a US or EU region we have not agreed.
5. Security incidents
If we confirm a breach of personal data we hold as controller for this website, we will notify affected people and, where Uganda’s Data Protection and Privacy Act requires it, the relevant authority, within the timelines that law sets. We will not invent a “we have never had an incident” claim.
If the incident is in a client-controlled system we host, we notify the client’s named owner first, as processor, so they can meet their own duties. Your contract may set a shorter notice period. We follow the shorter of the contract and the law.
To report a vulnerability in this website, email support@frontstardigital.com with steps to reproduce. Do not use a public form to paste secrets. We do not run a paid bug-bounty programme unless we announce one.
6. Processors and third parties
On this website we currently rely on:
- DPO, for hosted card and mobile-money checkout when configured.
- Our email path, for transactional messages about forms, accounts and orders.
- Google Translate, if you open the language widget.
- Google Analytics, only with consent and a configured ID.
- Cloudflare-hosted Font Awesome and Google Fonts CDNs for icons and type.
- The hosting environment this website runs on.
We do not list every possible plugin a future project might add. A client system’s subprocessors belong in that project’s schedule.
7. Law and what we do not claim
Personal data on this site is handled with Uganda’s Data Protection and Privacy Act, 2019 in view. Cross-border access by a client or a vendor is described in the privacy policy and in contracts, not hidden in this list.
We do not display ISO, PCI-DSS merchant-of-record, or CREST logos we have not earned. PCI for card data is DPO’s hosted checkout, not a Front Star certificate on this server. If a buyer needs an audit report, that is a scoped engagement, not a PDF we invent for the footer.
8. Related documents
Privacy policy - what we collect and why. Terms of use - accounts, cart, services and liability. Questions: +256 779 971 024 or support@frontstardigital.com.
