1. Introduction
The Federation of Uganda Salons & Beauty Professionals ("we", "our", "the Federation") is committed to protecting the privacy of members and users. This page describes the current behavior of FUSPro Verify - Certification & Verification Portal as implemented in the application.
2. Information We Collect
We collect the following categories of information:
- Personal Identity: Full name, email address, phone number, national identification details.
- Business Information: Salon name, business address, salon type, operating details.
- Verification Data: GPS coordinates, premises photographs, inspection checklists, timestamps, and consent/signature data.
- Payment Records: Transaction references, payment amounts, and confirmation status.
- System Usage: Login times, actions performed, device metadata, session data, and IP addresses.
3. How We Use Your Information
- To process membership registrations and salon certifications.
- To verify premises through scheduled on-site inspections.
- To generate and manage digital certificates.
- To maintain the Federation registry of recognized salons and members.
- To enable public certificate validation via QR codes.
- To send notifications about account status, renewals, and service updates.
- To maintain audit trails for security and compliance review.
- To generate aggregated reports and regional statistics.
4. Public Information
The public verification portal currently shows different fields depending on the certificate type:
- Business verification: certificate number, business name, owner name, tier/status, validity dates, and active badge labels.
- Member verification: membership ID, member name, phone, email, district/region, and validity dates.
Raw inspection evidence, payment records, and audit logs are not publicly displayed.
5. Data Security
- The application is built to support HTTPS/TLS, and non-local deployments can enforce HTTPS through middleware.
- Passwords are hashed and never stored in plain text.
- Access controls restrict sensitive data to authorized roles.
- Verification reports are locked after submission within the standard inspection workflow.
- Audit logs are hash-linked, and sensitive actions can create sealed records for integrity review.
- Sensitive files are served through authenticated secure-media routes rather than public file links.
6. Data Retention
The current application enforces some lifecycle windows directly and leaves some long-term retention to operational controls.
- Provisional certificates: 30-day corrective deadline before automatic expiry.
- Quarterly self-check obligations: due date plus 14-day grace window before AT_RISK automation.
- Audit logs and sealed records: retained in the application database for reporting and integrity review.
- Backups and long-term archival: managed outside the standard application workflow.
7. Data Sharing
We do not sell personal data. Information may be shared with:
- Authorized Federation Personnel: Access is limited to authorized personnel where required to provide the service, protect the platform, or comply with the law.
- Regulatory Bodies: When required by law or regulatory obligation.
- Payment Processors: Transaction information necessary for payment processing.
8. Your Rights
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request corrections to inaccurate data, subject to review controls.
- Objection: You may object to certain processing activities.
- Withdrawal: You may withdraw from the platform, though some records remain protected for compliance or integrity reasons.
To exercise these rights, use the official support channels provided on the platform.
9. Cookies & Tracking
The system uses essential cookies for session management and security. We do not describe advertising or third-party tracking cookies in the current application literature.
10. Children's Privacy
This platform is intended for professional use by adults. We do not knowingly collect personal information from individuals under the age of 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Members may be notified of significant changes through the platform.
12. Contact
For privacy-related enquiries, contact the Federation through the official support channels provided on the platform.
Effective Date: September 2026 · Last Updated: 17 Sep 2026