Effective: to be set upon publication · Version: 0.3 (Draft)
How Pawa IT Solutions Limited collects, uses, stores, and protects personal data through the Lattice Customer Portal.
CONTENTS
This policy describes how Pawa IT handles personal data through the Lattice Customer Portal, a platform that lets organisations using Google Workspace manage their corporate email signatures, employee directory, licence assignments, billing, and support in one place. It applies to:
@pawait.co.ke accounts) who operate our internal Management Portal to onboard and support customers, including as a Google Workspace resellerThe Portal allows a subscribing organisation to:
Once your organisation's Super Administrator authorises us (Section 4.1), we read the following:
We do not read your email messages, drafts, attachments, calendar, Drive files, contacts, or any Google service other than Gmail's signature settings and the Directory API through this mechanism. See Section 4.1 for the exact permissions requested.
If your organisation purchases its Google Workspace subscription through Pawa IT as its reseller, we also receive, via Google's Cloud Channel API, your organisation's customer record, subscription plan, and SKU/seat counts, and billing and invoicing data derived from that subscription. This is organisation-level data — we do not process payment card or bank account details through this platform.
We access Google Workspace data through two distinct mechanisms, established differently and covering different data. It's important these aren't conflated.
We cannot access your directory or deploy signatures until your organisation's Super Administrator explicitly authorises our service account via Domain-Wide Delegation in the Google Admin Console. This is a deliberate, manual action, specific to your organisation — we cannot grant ourselves this access, and it is not implied by any other relationship you have with Pawa IT.
We send the Super Administrator a link that pre-fills our service account's Client ID and the exact scopes below, so they can review and approve (or decline) with full visibility of what is being requested.
gmail.settings.basicgmail.settings.sharingadmin.directory.useradmin.directory.group.readonlyadmin.directory.orgunit.readonlyadmin.directory.customer.readonlyWe request no DWD scope covering Gmail messages, Calendar, Drive, Contacts, Chat, or any other Google service.
Separately, if Pawa IT is your organisation's Google Workspace reseller of record, Google's Workspace Reseller Program gives us certain administrative capabilities over your subscription as a function of that commercial relationship — including the ability to view your subscription, plan, and seat counts, which we use to populate the billing and invoice information shown in the Portal. This access is established by the reseller relationship itself, not by a separate per-feature consent screen in the Portal.
If you did not purchase your Workspace subscription through Pawa IT, this mechanism does not apply to your organisation, and we hold no reseller-level access to your data.
When you raise a support request through the Portal, it is created as a ticket in Freshdesk, a third-party helpdesk platform operated by Freshworks Inc. This includes the subject, description, and your email address; any file attachments you include; the full reply conversation between you and our support team; and any email addresses you choose to CC or add as watchers.
Freshdesk tickets are also visible to and manageable by Pawa IT support staff and agents. Freshdesk processes this data under its own privacy policy as our sub-processor; see Freshworks' Privacy Policy for how Freshdesk itself handles data on our behalf.
Please avoid including sensitive personal data (e.g. passwords, payment details) in a support ticket unless specifically requested by our support team.
Pawa IT staff may keep short internal notes against your organisation's account — for example, context from a support call or an account-management observation — to help us serve your organisation consistently across our team. These notes are authored by staff, not visible to Customer Admins or Users, and are not used for any purpose beyond internal account management and support continuity.
We use the data described above to:
We use Google Analytics (GA4) to understand how the Portal is used — which pages are visited and how often — so we can improve it.
Usage by our own staff (@pawait.co.ke accounts) is never sent to Google Analytics — this exclusion is enforced in the application itself, keyed off the signed-in account, before any analytics request leaves your browser.
Page views and navigation within the Portal by Customer Admins and Customer Users. Google Analytics may set its own cookies to distinguish sessions and visits; see Google's Privacy Policy for how Google itself processes this data.
Separately from analytics, the Portal sets a strictly-necessary authentication cookie to keep you signed in. This cookie is required for the Portal to function and is not used for tracking or advertising.
Platform data is stored in Google Cloud Firestore, encrypted at rest (AES-256) and in transit (TLS/HTTPS). Signature images and logos are stored in Google Cloud Storage. Subscription and licence records used for billing analysis are also processed through Google BigQuery. Support tickets are stored in Freshdesk.
@pawait.co.ke accounts and separately scoped from customer-facing permissionsWe delete or anonymise data beyond these periods except where we are legally required to retain it for longer.
We share data only as necessary to provide the service:
We do not sell your data, and we do not share it with third parties for their own marketing purposes.
If you are a Customer User and want to exercise a data-subject right, we recommend contacting your organisation's admin first, since they control what data is synced and how it is used. We will support your organisation in fulfilling that request.
Subject to applicable law — including Kenya's Data Protection Act 2019, and the GDPR where it applies to you — you may have the right to:
To exercise these rights, contact us using the details in Section 14, or your organisation's admin if the request concerns directory data they control.
We may update this policy from time to time. For material changes, we will provide at least 30 days' notice via email to the administrator account on record, or via a notice within the Portal. Continued use after that date constitutes acceptance of the revised policy.
© 2026 Pawa IT Solutions Limited. All rights reserved.