LEGAL

Privacy Policy

Effective: to be set upon publication  ·  Version: 0.3 (Draft)

How Pawa IT Solutions Limited collects, uses, stores, and protects personal data through the Lattice Customer Portal.

Pawa IT Solutions Limited (“Pawa IT,” “we,” or “us”) operates the Lattice Customer Portal at customers.pawait.io. This policy explains how we collect, use, store, and protect personal data through the Portal.

This policy does not cover Lattice Crest, our separate Google Workspace Marketplace signature product, which has its own privacy policy at crest.pawait.io/privacy.

1. Who This Policy Covers

This policy describes how Pawa IT handles personal data through the Lattice Customer Portal, a platform that lets organisations using Google Workspace manage their corporate email signatures, employee directory, licence assignments, billing, and support in one place. It applies to:

  • Customer Users — employees of a subscribing organisation whose Google Workspace directory data and Gmail signature may be processed through the platform
  • Customer Admins — employees of a subscribing organisation who log in to the Portal to manage templates, directory, licences, billing, and support tickets
  • Pawa IT Staff — our own employees (@pawait.co.ke accounts) who operate our internal Management Portal to onboard and support customers, including as a Google Workspace reseller

2. What Lattice Customer Portal Does

The Portal allows a subscribing organisation to:

  • Design branded email signature templates and automatically deploy them to employees' Gmail accounts, targeted by user, group, or organisational unit
  • Sync and browse the organisation's Google Workspace directory (users, groups, organisational units)
  • Let employees request profile changes (name, title, phone), subject to admin approval
  • Manage signature licence assignment and view billing/invoice history derived from their Google Workspace subscription
  • Raise, track, and reply to support tickets (Section 5)

3. Data We Collect and Where It Comes From

3.1 From Google Workspace — Directory and Gmail

Once your organisation's Super Administrator authorises us (Section 4.1), we read the following:

Name, email, title, phone, photo URL
Displaying your directory, personalising signature templates
Account suspension status
Excluding suspended accounts from deployments
Group / org-unit membership
Targeting signature deployments
Existing Gmail signature (read once)
Restoring your original signature if your licence is later removed

We do not read your email messages, drafts, attachments, calendar, Drive files, contacts, or any Google service other than Gmail's signature settings and the Directory API through this mechanism. See Section 4.1 for the exact permissions requested.

3.2 From You Directly

  • Account/profile update requests — if you submit a request to change your name, title, or phone number through the Portal
  • Support tickets you raise, including the message content and any file attachments (Section 5)
  • Comments and notes you add to licence change requests

3.3 From Your Organisation's Admin

  • Signature template designs and brand assets (logos, colours, social links)
  • Licence assignment decisions and billing plan selection
  • Contact details (name, email) provided when your organisation is onboarded

3.4 From Pawa IT's Google Workspace Reseller Relationship

If your organisation purchases its Google Workspace subscription through Pawa IT as its reseller, we also receive, via Google's Cloud Channel API, your organisation's customer record, subscription plan, and SKU/seat counts, and billing and invoicing data derived from that subscription. This is organisation-level data — we do not process payment card or bank account details through this platform.

3.5 Automatically, When You Use the Portal

  • Session data — an authentication cookie that keeps you signed in
  • Usage analytics — see Section 8

4. Google Workspace Access — Two Separate Mechanisms

We access Google Workspace data through two distinct mechanisms, established differently and covering different data. It's important these aren't conflated.

4.1 Domain-Wide Delegation (DWD) — for Signatures and Directory Sync

We cannot access your directory or deploy signatures until your organisation's Super Administrator explicitly authorises our service account via Domain-Wide Delegation in the Google Admin Console. This is a deliberate, manual action, specific to your organisation — we cannot grant ourselves this access, and it is not implied by any other relationship you have with Pawa IT.

We send the Super Administrator a link that pre-fills our service account's Client ID and the exact scopes below, so they can review and approve (or decline) with full visibility of what is being requested.

gmail.settings.basic
Read and write only the signature field of your “send as” settings
gmail.settings.sharing
Write the signature field to your other verified, same-domain aliases
admin.directory.user
Read directory profiles for sync; write profile fields only when your admin approves a change you requested
admin.directory.group.readonly
List groups and members, to target deployments
admin.directory.orgunit.readonly
List your OU structure, to target deployments
admin.directory.customer.readonly
Look up your organisation's name and identifier for account setup

We request no DWD scope covering Gmail messages, Calendar, Drive, Contacts, Chat, or any other Google service.

Revocation: Your Super Administrator can revoke this authorisation at any time from the Google Admin Console (Security → API Controls → Domain-wide Delegation). Revocation takes effect immediately — every subsequent signature/directory API call from us fails.

4.2 Reseller Administrative Access — for Subscriptions and Billing

Separately, if Pawa IT is your organisation's Google Workspace reseller of record, Google's Workspace Reseller Program gives us certain administrative capabilities over your subscription as a function of that commercial relationship — including the ability to view your subscription, plan, and seat counts, which we use to populate the billing and invoice information shown in the Portal. This access is established by the reseller relationship itself, not by a separate per-feature consent screen in the Portal.

If you did not purchase your Workspace subscription through Pawa IT, this mechanism does not apply to your organisation, and we hold no reseller-level access to your data.

We do not currently generate or display Workspace usage/activity reports (e.g. email, Drive, or Meet activity) to customers. If we introduce this as a feature in the future, we will update this policy and notify administrators before it goes live.

5. Support Tickets (Freshdesk)

When you raise a support request through the Portal, it is created as a ticket in Freshdesk, a third-party helpdesk platform operated by Freshworks Inc. This includes the subject, description, and your email address; any file attachments you include; the full reply conversation between you and our support team; and any email addresses you choose to CC or add as watchers.

Freshdesk tickets are also visible to and manageable by Pawa IT support staff and agents. Freshdesk processes this data under its own privacy policy as our sub-processor; see Freshworks' Privacy Policy for how Freshdesk itself handles data on our behalf.

Please avoid including sensitive personal data (e.g. passwords, payment details) in a support ticket unless specifically requested by our support team.

6. Internal Notes

Pawa IT staff may keep short internal notes against your organisation's account — for example, context from a support call or an account-management observation — to help us serve your organisation consistently across our team. These notes are authored by staff, not visible to Customer Admins or Users, and are not used for any purpose beyond internal account management and support continuity.

7. How We Use Data

We use the data described above to:

  • Operate the Portal and its features (directory sync, signature deployment, licence and billing management, support)
  • Personalise signature templates with your name, title, phone, and photo
  • Maintain an audit trail of deployments, directory/licence changes, and support interactions for compliance and service continuity
  • Respond to support requests and profile update requests
  • Detect and prevent misuse of the platform
We do not: use your data to train AI or machine-learning models; use your data for advertising or ad targeting; sell or license your data to third parties; or build behavioural profiles of you beyond what is needed to personalise your signature and manage your licence.

8. Google Analytics

We use Google Analytics (GA4) to understand how the Portal is used — which pages are visited and how often — so we can improve it.

What is excluded

Usage by our own staff (@pawait.co.ke accounts) is never sent to Google Analytics — this exclusion is enforced in the application itself, keyed off the signed-in account, before any analytics request leaves your browser.

What is included

Page views and navigation within the Portal by Customer Admins and Customer Users. Google Analytics may set its own cookies to distinguish sessions and visits; see Google's Privacy Policy for how Google itself processes this data.

Session cookie

Separately from analytics, the Portal sets a strictly-necessary authentication cookie to keep you signed in. This cookie is required for the Portal to function and is not used for tracking or advertising.

9. Data Storage, Security, and Retention

9.1 Storage

Platform data is stored in Google Cloud Firestore, encrypted at rest (AES-256) and in transit (TLS/HTTPS). Signature images and logos are stored in Google Cloud Storage. Subscription and licence records used for billing analysis are also processed through Google BigQuery. Support tickets are stored in Freshdesk.

9.2 Security Measures

  • Service account credentials are managed via keyless impersonation through GCP IAM — no private key file is stored in our code or configuration
  • Every request to the Portal's API is checked against a permission-scope model — access to a customer's data requires both a valid session and the correct scope for that action
  • Pawa IT staff can only access a customer's directory/signature data via DWD if that customer has an active, unrevoked authorisation
  • Access by Pawa IT staff is restricted to @pawait.co.ke accounts and separately scoped from customer-facing permissions
  • Certain licence and subscription change events trigger an internal alert to Pawa IT staff via Google Chat, for operational awareness — this is an internal notification only and does not involve a third party outside Google

9.3 Retention

Directory profile data, signatures
Life of contract, plus 90 days
Signature templates, brand assets
Life of contract, plus 90 days
Deployment / licence audit logs
3 years from the event date
Support tickets
Per Freshdesk's retention settings and our support data-retention procedure
Billing/invoice records
As required by applicable tax and business-record law

We delete or anonymise data beyond these periods except where we are legally required to retain it for longer.

10. Data Sharing and Sub-Processors

We share data only as necessary to provide the service:

  • Google LLC — Directory API, Gmail API, and Cloud Channel API calls, under Google's own terms, the Google Workspace Reseller Program terms, and the Google API Services User Data Policy
  • Google Cloud Platform — Firestore, Cloud Storage, BigQuery, IAM, and Secret Manager, for hosting, analysing, and securing platform data
  • Freshworks Inc. (Freshdesk) — for support ticket handling
  • Any email-delivery provider we use to send transactional notifications (e.g. DWD authorisation requests)

We do not sell your data, and we do not share it with third parties for their own marketing purposes.

11. Data Controller and Processor Roles

  • For Customer User personal data (name, email, title, phone, photo, and signature) — Pawa IT acts as a processor, acting on the instructions of your employer (the subscribing organisation) or under the Google Workspace Reseller Program, as applicable. Your employer is generally the controller.
  • For Pawa IT staff accounts and organisation-level contact/billing data collected at onboarding — Pawa IT acts as controller.
  • For support tickets — Pawa IT is the controller of the support relationship; Freshdesk processes ticket data on our behalf as our sub-processor.

If you are a Customer User and want to exercise a data-subject right, we recommend contacting your organisation's admin first, since they control what data is synced and how it is used. We will support your organisation in fulfilling that request.

12. Your Rights

Subject to applicable law — including Kenya's Data Protection Act 2019, and the GDPR where it applies to you — you may have the right to:

  • Access the personal data we (or your organisation, through us) hold about you
  • Request correction of inaccurate data
  • Request erasure of your data, subject to our legitimate retention needs
  • Request a copy of your data in a portable format
  • Object to certain processing

To exercise these rights, contact us using the details in Section 14, or your organisation's admin if the request concerns directory data they control.

13. Changes to This Policy

We may update this policy from time to time. For material changes, we will provide at least 30 days' notice via email to the administrator account on record, or via a notice within the Portal. Continued use after that date constitutes acceptance of the revised policy.

14. Contact

Data protection & privacy
General enquiries
Technical support
Pawa IT Solutions Limited
1st Floor, George Padmore Ridge
George Padmore Road, Nairobi, Kenya
P.O. Box 1805 – 00606
Tel: +254 111 055 950  ·  Email: info@pawait.co.ke

© 2026 Pawa IT Solutions Limited. All rights reserved.