Legal
Privacy policy
How GAB Digital Systems handles information you share through this website. Last updated 29 September 2026.
Who we are
GAB Digital Systems is the public brand of GAB Software Company Limited, a company based in Uganda. This policy covers the website at gabdigitalsystem.com. It does not cover our separate products, which have their own policies.
What we collect
When you send a project enquiry or a consultation request we store what you type: your name, business name if given, email address, phone number if given, your preferred contact method, and the description of your project or question, including any budget or timeline preference you choose to share.
We also record when the enquiry was made, the page it came from and any campaign parameters in the link you followed (for example utm_source), so we know which advertising is useful. A one-way hash of your network address is kept briefly to limit spam. We do not store the address itself.
Why we use it
Only to respond to you, prepare a proposal, arrange a consultation and keep a record of our conversation. We do not sell or rent your information, and we do not add you to a newsletter without asking.
Where it is stored and who can see it
Enquiries are saved in a database managed by our hosting provider and are visible only to authorised GAB staff through a password-protected area. Internal notes staff add about an enquiry are private to GAB. If email notifications are enabled, a copy of your enquiry is sent to our team inbox through our email provider.
Cookies and analytics
The public website sets no tracking cookies. Staff sign-in uses a session cookie. Studio email verification uses a separate essential, HttpOnly session cookie lasting up to 24 hours. Our analytics counts events such as "enquiry submitted" without any personal data: names, emails, phone numbers and project text are never sent to analytics.
GAB Vision Studio
GAB Vision Studio creates illustrative concepts. Do not include personal, customer or confidential information. When model generation is available and you choose to use it, your idea and optional answers are sent through OpenRouter to an approved model provider. Email addresses, contact details and campaign attribution are not sent to the model. Requests require an approved model and provider with no data collection and zero data retention; if that route is unavailable, we use a labelled Starter concept. OpenRouter and the selected provider process requests under their own privacy policies, and processing may occur outside Uganda.
This pilot allows one model attempt per verified email address. Different addresses remain possible; this is not a limit per person. To verify an address, we send an eight-digit code through our email delivery provider, Resend. The code expires after 10 minutes and permits at most five incorrect guesses. GAB stores a keyed email hash and hashed verification credentials rather than the raw address in the Studio verification database. Resend processes the recipient address and verification message. The verification session expires after 24 hours.
Your draft idea stays in this tab's session storage for up to 30 minutes, including navigation and refresh. A successful model result, original idea and answers are saved privately in our Neon database for authorized recovery for 24 hours. A daily cleanup removes expired result contents and verification sessions, normally within 48 hours of creation; a retry also removes an expired result. We retain the keyed email hash, attempt state and reservation timestamp for this pilot to prevent a second model call, even after an OpenRouter 429, compatible-provider failure, timeout, rejected result or expired result. These hashes are pseudonymous personal data, not anonymous records. Ending the pilot requires a reviewed deletion of its attempt records and verification data.
If you choose to start a project or request a consultation, a temporary copy, your entered email address and campaign attribution use tab session storage to prefill the enquiry. This handoff expires after 30 minutes and is removed on a successful enquiry. Studio enquiries do not use persistent browser drafts. Only submitting the enquiry stores the full brief as a lead for authorized GAB staff. There are no public result links and contents are not sent to analytics.
Connection and global request counters remain separate abuse and cost controls. We store a daily rotating hash of the network address supplied by our host and clear Studio counters older than 48 hours on subsequent requests. Cloudflare Turnstile checks are verified on our server for the configured hostname and action. Anonymous model token counts and cost may be recorded without the idea, result, email or verification code.
OpenRouter privacy policy. You can leave AI unchecked to use a starter concept without sending your idea to a model provider.
How long we keep it
We keep enquiries for as long as needed to respond and, if we work together, for the life of the project and our record-keeping obligations. You can ask us to delete an enquiry at any time.
Your choices
You can ask what we hold about you, ask us to correct it, or ask us to delete it. Contact us through support@gabdigitalsystem.com, quoting your reference number if you have one.
Changes
If this policy changes we will update the date at the top of this page. Material changes will be explained here.