Privacy Policy

Effective: to be set upon publication  ·  Version: 0.2 (Draft)

Applies to Lattice Crest, Pawa IT's email signature and brand-banner management platform for Google Workspace.

At Pawa IT, the privacy of our users is one of our main priorities. This Privacy Policy explains how personal data is collected, processed, stored, and protected by Lattice Crest, our email signature and brand-banner management application for Google Workspace organisations (“the Platform”).

This policy applies only to data processed through the Platform. It does not cover information collected offline or via other channels — general enquiries about pawait.io are covered by Pawa IT's corporate privacy policy.

Consent: by authorising Lattice Crest to integrate with your Google Workspace organisation, and by using the Platform, you consent to this policy. For Customer Users, the subscribing organisation (the data controller) has accepted these terms on their behalf.

1. Product Overview

Lattice Crest is a B2B SaaS application that enables organisations using Google Workspace to manage branded email signatures at scale.

Template Design
Design branded corporate email signature templates using a visual editor.
Automated Deployment
Automatically deploy signatures to every user's Gmail account across the organisation.
Targeting
Target deployments to specific users, groups, or organisational units (OUs).
Directory Sync
Manage signature licence entitlements and sync the Google Workspace user directory for personalisation.

2. Governance and Roles

Pawa IT
Processor
Processes Customer User data on behalf of the organisation, following administrator instructions.
Pawa IT
Controller
Relates to Pawa IT's own staff accounts and customer organisation-level contact data collected during onboarding.
Customer Organisation
Controller
Owner of employee profile data, original signatures, and Google Workspace structures.

3. Information Collection

Data collected via Google APIs:

User Profile Data
Email, name, title, phone, and photo URL. We do not collect passwords or security credentials.
Workspace Structure
Group and OU names/paths, used solely for deployment targeting.
Original Signatures
Existing user signatures captured once, to enable restoration if a licence is later removed.
Contact Data
Primary contact and Super Admin email addresses collected during onboarding.
Data we do not collect: passwords, security credentials, email message content, calendar data, or Drive content. We do not knowingly collect personal data from individuals under the age of 18.

4. How We Use Personal Data

  1. Operate the Platform and maintain essential services;
  2. Personalise email signatures by substituting template placeholders with each user's profile data;
  3. Deploy signatures to users' Gmail accounts via the Gmail API;
  4. Manage and restore original signatures when a user's licence is removed;
  5. Target signature deployments to specific users, groups, or organisational units;
  6. Maintain an audit trail of deployment activity for compliance and dispute resolution;
  7. Communicate regarding account status, updates, and licence management;
  8. Detect and prevent fraud or misuse of the Platform.

Pawa IT does not use this data to train AI or machine-learning models, does not use it for advertising, and does not sell it to third parties.

5. Legal Basis for Processing

Under Kenya's Data Protection Act 2019, we process personal data on the following bases:

  1. Contractual necessity — processing required to deliver the Services under our agreement with your organisation;
  2. Consent — the Domain-Wide Delegation your Super Administrator grants in the Google Admin Console, and any marketing communications you opt into;
  3. Legitimate interests — platform security, fraud prevention, and audit logging;
  4. Legal obligation — where we are required to retain or disclose data under applicable law.

6. Domain-Wide Delegation and Google API Scopes

Lattice Crest uses Google Workspace Domain-Wide Delegation (“DWD”) to act on behalf of users. This is a deliberate act performed by the Customer's Super Admin in the Google Admin Console and can be revoked at any time — Pawa IT cannot grant itself this access. Revoking DWD immediately stops all Google API calls Lattice Crest makes for that domain.

Lattice Crest requests only the following scopes:

gmail.settings.basic
Read and write Gmail signature settings.
gmail.settings.sharing
Update signatures for send-as aliases.
admin.directory.user
Sync user profiles and apply approved updates.
admin.directory.group.readonly
List groups for deployment targeting.
admin.directory.orgunit.readonly
List OUs for deployment targeting.

We do not access email messages, calendar events, Drive files, or any Google service beyond Gmail signature settings and the Directory API.

7. Audit and Storage

Signature HTML content is not written to logs. Detailed user PII in logs is limited to email addresses in structured log fields. All data is stored in Google Cloud Firestore, encrypted at rest using AES-256; brand assets are stored in Google Cloud Storage. Stored data includes:

  1. User profile fields: email, name, title, phone, photo URL, suspension status, licence assignment status, and current and original signature HTML;
  2. Customer organisation details: domain, organisation name, primary contact information, brand configuration, and DWD authorisation status;
  3. Signature templates: HTML content with merge-tag placeholders (no real user data is stored in templates themselves);
  4. Deployment audit logs: per-deployment records including target users and outcomes;
  5. Licence records: assignment events, quota change requests, and billing plan;
  6. Signature images: logos and brand assets uploaded by administrators (these should not contain personal data).

8. Sub-Processors

We use the following third-party sub-processors to deliver the Platform:

Google Cloud Firestore
Primary application database
Customer-specified GCP region
Google Cloud Storage
Storage of signature images and brand assets
Customer-specified GCP region
Google Cloud Secret Manager
Secure storage of credentials and API keys
Customer-specified GCP region
Google Cloud Run
Application compute / hosting
Customer-specified GCP region
Google Workspace APIs
Gmail API and Directory API access (see Section 6)
N/A

We do not sell, license, share, or transfer any customer or user data to third parties for advertising, profiling, or any purpose other than delivering the email signature management service. No third-party advertising networks are used on the Platform. A current list of sub-processors is available on request from privacy@pawait.co.ke.

9. Google API Services User Data Policy and Limited Use

The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Pawa IT does not:

  1. use Google user data for serving advertisements, including retargeting or interest-based advertising;
  2. sell or transfer Google user data to third parties such as advertising platforms or data brokers;
  3. use Google user data to determine creditworthiness or for lending purposes;
  4. use Google user data to train or improve a generalised AI or machine-learning model.

Human access to Google user data is restricted to circumstances permitted under the Google API Services User Data Policy: with your explicit consent, for security purposes, or to comply with applicable law. You can review or revoke Lattice Crest's access to your Google Workspace data at any time via the Google Admin Console (Security > API Controls > Domain-wide Delegation) as described in Section 6.

10. Data Retention

We retain personal data only for as long as necessary to deliver the Platform and meet legal obligations:

  1. User profile data and deployed signature data: for the duration of the contract, plus 90 days;
  2. Original Gmail signature (captured before first deployment): until cleared by the customer or contract end;
  3. Deployment audit logs: 3 years from the event date;
  4. Licence change request records: 2 years from the resolution date;
  5. Signature images: for the duration of the contract, plus 30 days.

Upon contract termination, Pawa IT will delete or return all personal data in accordance with applicable data protection law.

11. International Data Transfers

Where personal data is transferred outside Kenya, Pawa IT ensures appropriate safeguards are in place in accordance with the Data Protection Act 2019, including contractual clauses with sub-processors. Data is stored in a customer-specified or default GCP region; some Google Cloud services may route data through other regions for processing, governed by Google's own data residency commitments.

12. Security Measures

Encryption
HTTPS/TLS for data in transit; AES-256 for data at rest.
Credential Security
Secrets stored in GCP Secret Manager; no keys in source code.
Tenant Isolation
Strict API enforcement ensures customers only access their own organisation's data.
Access Control
Role-based access control (RBAC) with granular permission scopes.

13. Data Breach Notification

In the event of a personal data breach affecting data for which Pawa IT is the data controller, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach where required by law, and will notify affected individuals without undue delay where the breach is likely to result in high risk to their rights. For breaches involving Customer Data processed on behalf of a subscribing organisation, Pawa IT will notify that organisation without undue delay, and the organisation (as data controller) is responsible for notifying regulators and data subjects as required.

14. Your Rights

We are committed to ensuring you are fully aware of your data protection rights under Kenya's Data Protection Act 2019 and, where applicable, the EU General Data Protection Regulation (GDPR). Every user is entitled to:

  1. Access — request copies of your personal data (a reasonable fee may apply);
  2. Rectification — request correction of inaccurate or incomplete data;
  3. Erasure — request deletion of your personal data, under certain conditions;
  4. Restrict processing — request that we limit how we process your data, under certain conditions;
  5. Object to processing — object to our processing of your personal data, under certain conditions;
  6. Data portability — request that we transfer your data to another organisation, or to you directly, under certain conditions;
  7. Withdraw DWD consent — your organisation's Super Admin may revoke Domain-Wide Delegation at any time via the Google Admin Console, immediately terminating our access to your organisation's data.
If you make a request, we have one month to respond. For platform data, requests from individual Customer Users should be directed to the subscribing organisation as data controller; Pawa IT will assist organisations in responding in accordance with the Data Processing Agreement. To exercise your rights in respect of data held by Pawa IT directly, contact privacy@pawait.co.ke.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the email address associated with your Administrator Account or via a notice within the Platform at least 14 days before the change takes effect. The current version is always available at crest.pawait.io/privacy.

16. Contact

If you have additional questions or require more information about this Privacy Policy, contact us at privacy@pawait.co.ke.

Pawa IT Solutions Limited
1st Floor, George Padmore Ridge
George Padmore Road, Nairobi, Kenya
P.O. Box 1805 – 00606
Tel: +254 111 055 950