1. Introduction & scope
This Privacy Policy describes how Northfast Limited (“Northfast,” “we,” “us”), operating the Paswad platform, collects, uses, discloses, and protects personal data. It applies to our websites, dashboards, the developer console, our APIs and SDKs, and the authentication and verified-identity services we provide (the “Service”).
This policy covers personal data of individuals who create a Paswad identity, end users who sign in to applications through Paswad, developers who integrate with us, and visitors to our websites. Where a developer uses Paswad to authenticate their own users, that developer is the controller of the personal data they collect in their application; this policy explains the role Paswad plays in that flow. Please also read our Terms of Service and Cookie Policy.
2. Who we are
The data controller responsible for personal data processed through the Paswad Service is Northfast Limited, a company incorporated under the laws of the Republic of Kenya, reachable at northfast.co.ke. For privacy questions, you can contact our privacy team at [email protected]. Where we process personal data on behalf of a developer customer (for example, end-user authentication data), we act as a processor for that customer.
3. Information we collect
We collect only what we need to operate a secure identity service. We do not collect or store passwords (we have none), passkey private keys (these are generated and held on your device by your operating system and never transmitted to us), or your biometrics (your face or fingerprint never leaves your device — we receive only the result of a successful local check).
The categories of personal data we do collect include:
- Account data. The information needed to create and manage your Paswad identity, such as your name or display name and account settings.
- Verified contacts. The email address and/or WhatsApp phone number you confirm at signup through one-time passcodes, used for security alerts and recovery.
- Passkey / credential metadata. The public key of each registered passkey, credential identifiers, authenticator attributes, and timestamps. We never receive the private key.
- Web passport / identity-verification data. Where you establish a verified identity, the attributes and supporting information processed to confirm your identity and the resulting verified-identity record you may present to relying applications.
- Device & log data. Information such as IP address, approximate location derived from it, device and browser characteristics, the application involved, and timestamps — used for your audit log, security alerts, and fraud detection.
- Developer data. For developers, application configuration, redirect URIs, API usage and billing data, and contact details.
- Cookies & similar technologies. A minimal set described in our Cookie Policy, primarily to keep you signed in and protect forms.
- Communications. Information you provide when you contact support or correspond with us.
4. How we use information
We use personal data to:
- authenticate you and operate “Sign in with Paswad” for relying applications;
- verify your contacts at signup and support account recovery;
- establish and maintain your web passport where you choose to use it;
- send security alerts about new sign-ins, new devices, unusual activity, and account changes;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- provide, maintain, troubleshoot, and improve the Service, including measuring usage;
- communicate with you about the Service and respond to your requests;
- process billing for paid plans; and
- comply with legal, regulatory, and law-enforcement obligations.
We do not sell your personal data, and we do not use it for cross-context behavioural advertising.
5. Legal bases for processing
Where data-protection laws such as the Kenya Data Protection Act and the EU/UK GDPR apply, we rely on the following legal bases:
- Performance of a contract — to provide the Service you or your organisation requested, including authentication, recovery, and billing.
- Legitimate interests — to secure the Service, prevent fraud and abuse, send security alerts, and improve our products, balanced against your rights.
- Consent — where we ask for it, for example for optional analytics cookies or certain identity-verification steps; you may withdraw consent at any time.
- Legal obligation — to comply with laws, including identity, anti-fraud, tax, and record-keeping requirements.
8. International data transfers
We and our service providers may process personal data in countries other than the one in which you are located, including Kenya and other jurisdictions where our infrastructure or subprocessors operate. Where we transfer personal data across borders, we put in place appropriate safeguards required by applicable law, such as standard contractual clauses or equivalent mechanisms, and we take steps to ensure your data receives an adequate level of protection.
9. Data retention
We retain personal data only for as long as needed to provide the Service, to fulfil the purposes described in this policy, and to meet legal, accounting, security, or reporting obligations. Account and passkey metadata is kept while your Account is active. Security and audit-log data is retained for a limited period for fraud prevention and investigation. Identity-verification records are retained only as long as required by applicable law and then deleted or anonymised. When data is no longer needed, we delete or anonymise it.
10. Security
We protect personal data using technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, monitoring, and a passwordless architecture. Because there is no password database, the most common cause of mass credential breaches simply does not exist here, and we never hold passkey private keys or biometrics. No system is perfectly secure; you also play a role by protecting your devices, maintaining recovery methods, and keeping your Verified Contacts current.
11. Your rights
Subject to applicable law (including the Kenya Data Protection Act and the EU/UK GDPR), you may have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data in certain circumstances;
- Port your data to another provider where applicable;
- Restrict or object to certain processing, including processing based on legitimate interests; and
- Withdraw consent at any time where we rely on it.
You can manage your passkeys, connected applications, and activity log at any time from your Paswad dashboard. To exercise other rights, contact [email protected]; we may need to verify your identity before responding. We will respond within the timeframes required by law. You also have the right to lodge a complaint with your data-protection authority — in Kenya, the Office of the Data Protection Commissioner.
12. Children’s privacy
The Service is not directed to children, and we do not knowingly collect personal data from children below the age required to consent under applicable law. If you believe a child has provided us personal data, contact us at [email protected] and we will take appropriate steps to delete it.
13. Automated decisions
We use automated systems to detect fraud and abuse and to protect accounts — for example, flagging unusual sign-in activity. These systems may restrict access or require additional verification. We do not use solely automated decision-making that produces legal or similarly significant effects without a lawful basis and appropriate safeguards, including, where required, the ability to request human review.
14. Third-party links
The Service may link to or interoperate with third-party websites and applications, including the relying applications you sign in to. We are not responsible for the privacy practices of those third parties. Their handling of your data is governed by their own privacy notices, which we encourage you to review.
15. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, notify you through the Service or a Verified Contact. Your continued use of the Service after the effective date constitutes acknowledgement of the updated policy.
16. Contact & Data Protection Officer
For privacy questions or to exercise your rights, contact the Paswad Privacy Office at [email protected], or write to Northfast Limited via northfast.co.ke. Our Data Protection Officer can be reached at [email protected]. You may also reach us through our contact page.