1. Who Is Responsible for Your Data
Paza Social, Inc., a Delaware corporation is the primary controller of personal information processed for PAZA's own Services, except where another party is identified as the controller or where PAZA acts only on a customer's documented instructions.
PAZA operates internationally and has operational activity in Nairobi, Kenya. Where Kenyan data protection law applies, including the Data Protection Act, 2019 and applicable regulations, PAZA processes personal data subject to those requirements. Other privacy laws may apply depending on a person's location and the processing involved.
2. Information We Collect
2.1 Account, Identity, and Organization Data
Name, email address, phone number, authentication data, account role, company or brand information, workspace membership, profile details, country, preferences, and information used to verify an account or authority to act for an organization.
2.2 Creator and Brand Profile Data
Creator bios, channels, handles, portfolio materials, capabilities, working style, audience information, public metrics, content categories, prior work, and related profile information. Brand data may include products, services, category, market, objectives, identity, voice, creator preferences, and campaign interests.
2.3 Collaboration and Marketplace Data
Campaigns, projects, jobs, proposals, Showcase projects, openings, tasks, messages, approvals, submitted files, deliverables, access requests, collaboration terms, verification evidence, disputes, support conversations, and related activity.
2.4 Intelligence Inputs and Public-Source Data
Product, service, category, market, competitor, keyword, audience, or research inputs submitted to PDE or Social Listening. PAZA may also process information available from public websites, public social profiles, posts, comments, reviews, communities, search results, public business listings, licensed data providers, authorized APIs, or connected services. This can include public usernames, profile metadata, post text, URLs, timestamps, engagement signals, and other information exposed by the source.
2.5 Derived Intelligence and Inferences
PAZA may derive or infer themes, demand environments, Jobs-to-Be-Done, pain points, motivations, triggers, friction, switching signals, communities, creator relevance, authority signals, intent or demand-stage indicators, evidence scores, classifications, summaries, and other analytical outputs from source data.
2.6 Companion and Event Data
Event registrations, check-ins, QR/NFC/URL entry activity, questions, responses, offer claims, voucher activity, referrals, sponsor interactions, consent records, follow-up activity, measured actions, and messages exchanged through Companion or supported messaging channels.
2.7 Outreach and Business Contact Data
Business contact details, company information, public professional profiles, outreach history, message status, opt-out status, enrichment results, and related evidence obtained from users, public business sources, or authorized data providers.
2.8 Payment and Verification Data
Transaction amount, currency, transaction or payout identifiers, payment status, processor references, refunds, chargebacks, billing details, and limited payout-account metadata. Licensed payment providers may separately collect identity documents, bank details, card data, mobile-money information, tax information, or other KYC/KYB data under their own privacy notices. PAZA does not intentionally store full payment-card numbers when payment entry is hosted or tokenized by the payment provider.
2.9 Verification Evidence
Where a user voluntarily submits them, PAZA may process screenshots, analytics exports, receipts, transaction evidence, timestamps, tracking links, redemption codes, uploaded files, or similar evidence used to confirm a collaboration or activation. We do not access private financial accounts unless the user expressly connects or submits information through an enabled feature.
2.10 Technical, Device, and Usage Data
IP address, browser and device information, operating system, cookie or session identifiers, authentication events, page and feature activity, logs, diagnostics, performance data, security signals, approximate location derived from technical data, and similar information needed to operate and secure the Services.
3. Where Information Comes From
We collect information directly from users; from Brands, Creators, collaborators, event organizers, or workspace administrators; from public sources; from licensed or contracted data providers; from payment, messaging, analytics, identity, and infrastructure providers; from connected third-party accounts and APIs authorized by a user; and from our own observations and derived analysis of activity within the Services. PAZA does not treat the mere fact that information is publicly accessible as permission to use it for any unlawful purpose.
4. How We Use Information
- create, authenticate, verify, administer, and secure accounts and workspaces;
- provide PDE, Social Listening, creator discovery, campaigns, Showcase, Job Board, Companion, outreach, and other Services;
- match or surface relevant creators, Brands, communities, opportunities, or evidence;
- generate analytical, statistical, AI-assisted, and derived intelligence outputs;
- support campaign, task, deliverable, event, and activation verification;
- facilitate communications, customer support, notifications, and permitted outreach;
- coordinate payment flows with licensed payment providers and reconcile transaction status;
- detect fraud, manipulation, abuse, security threats, and violations of our policies;
- debug, measure, maintain, personalize, and improve the Services;
- create aggregated or de-identified statistics and product insights;
- comply with law, enforce agreements, establish or defend legal claims, and respond to lawful requests; and
- send marketing communications where permitted, subject to applicable consent and opt-out rights.
5. Legal Bases
Where a law requires a legal basis, PAZA relies as appropriate on performance of a contract; steps requested before entering a contract; legitimate interests such as providing and improving business services, protecting security, preventing fraud, conducting proportionate business intelligence, and communicating with business contacts; compliance with legal obligations; consent where required; and the establishment, exercise, or defense of legal claims. Where we rely on legitimate interests, we consider the nature of the information, reasonable expectations, necessity, and potential impact on individuals.
6. AI, Automated Analysis, and Human Review
PAZA uses automated and AI-assisted systems for extraction, clustering, classification, summarization, relevance analysis, anomaly detection, fraud review, creator-brand fit, and other intelligence functions. These systems can make mistakes and their outputs are not treated as infallible facts.
PAZA does not intend to make decisions producing legal or similarly significant effects about an individual solely through automated processing where applicable law prohibits that practice without safeguards. Where required, users may request information about or human review of an eligible automated decision.
7. How We Share Information
We may disclose information to:
- other users and collaborators where information is intentionally shared through a profile, campaign, project, Showcase, proposal, job, Inbox, event, or other collaboration workflow;
- customers receiving intelligence outputs, subject to access controls and applicable law;
- service providers supporting hosting, databases, analytics, communications, email, AI processing, search, data acquisition, security, support, and other infrastructure;
- payment and financial-service providers that perform payment processing, KYC/KYB, fraud review, settlement, refunds, or payouts;
- connected platforms when a user directs or authorizes an integration;
- professional advisers, auditors, investors, acquirers, or financing parties subject to appropriate confidentiality and legal safeguards; and
- government, regulatory, law-enforcement, or judicial authorities where disclosure is legally required or reasonably necessary to protect rights, security, or users.
PAZA does not sell account-holder personal information for money. Some privacy laws define "sale" or "sharing" more broadly; where those definitions apply, PAZA will honor applicable opt-out and disclosure requirements.
8. Payment Providers and KYC/KYB
Payment providers are independent regulated entities and may act as separate controllers for information they are legally required to collect. When payment features are enabled, users may need to provide identity, business, sanctions, tax, bank, or payout information directly to the provider. PAZA may receive status, identifiers, risk outcomes, or limited account information needed to coordinate the platform workflow, but the provider's own privacy notice governs its independent processing.
9. International Data Transfers
PAZA and its service providers may process information in countries different from the country where the information was collected. Where required, we use appropriate safeguards for cross-border transfers, which may include contractual protections, recognized adequacy mechanisms, consent where specifically required, documented necessity grounds, or other measures permitted by applicable law. For transfers of personal data from Kenya, PAZA applies the safeguards and documentation required by the Kenya Data Protection Act and applicable regulations.
10. Retention
We keep personal information for as long as reasonably necessary for the purpose for which it was collected, including to maintain an account or collaboration record, provide intelligence and support, preserve security and audit history, comply with tax or financial-record obligations, resolve disputes, enforce agreements, and meet legal requirements. Retention varies by data type and context. We may retain aggregated or de-identified information where it no longer reasonably identifies an individual.
11. Security
PAZA uses technical and organizational safeguards designed to protect personal information, including access controls, authentication, secure transmission where appropriate, restricted administrative access, monitoring, logging, backups, and vendor controls. No service can guarantee absolute security. Users are responsible for protecting their credentials and promptly reporting suspected unauthorized access.
12. Your Privacy Rights
Depending on applicable law, you may have rights to access, obtain a copy of, correct, delete, or restrict personal information; object to certain processing; withdraw consent; request portability; object to or request review of certain automated decisions; and complain to a data-protection authority.
Residents of Kenya may exercise rights available under the Data Protection Act, 2019 and may complain to the Office of the Data Protection Commissioner. Individuals in other jurisdictions, including the EEA, United Kingdom, and applicable U.S. states, may have additional rights under local law.
To make a request, email legal@paza.social. We may need to verify the request and may deny or limit a request where permitted by law.
13. Public-Source Data Requests
If PAZA has processed personal information about you from a public or licensed source and you do not have a PAZA account, you may still contact us regarding applicable privacy rights. Include enough information for us to reasonably locate the relevant record without sending unnecessary sensitive information.
14. Marketing and Outreach Choices
You may unsubscribe from marketing emails using the provided unsubscribe method or by contacting us. Operational, transactional, security, support, and account notices may still be sent where necessary. Where consent is required for electronic marketing or messaging, PAZA or the user directing the outreach must obtain that consent before sending the communication.
15. Cookies and Analytics
PAZA may use cookies, local storage, pixels, or similar technologies for authentication, security, preferences, performance measurement, analytics, and permitted marketing. Browser controls may allow you to restrict some technologies. Where law requires consent for non-essential technologies, PAZA will use an applicable consent mechanism.
16. Children
PAZA accounts are intended for users aged 18 or older. PAZA does not knowingly create accounts for children or intentionally build commercial profiles about children. Public-source datasets may incidentally contain information about minors; where identified, PAZA applies appropriate safeguards and will honor applicable legal obligations regarding removal or restricted processing.
17. Third-Party Services
The Services may link to or integrate with third-party services. Their privacy practices are governed by their own notices. Connecting a third-party account authorizes PAZA to access the data and permissions presented in the connection flow. Disconnecting an integration stops future access to the extent supported, but does not automatically require deletion of information PAZA must or may lawfully retain.
18. Changes to This Policy
We may update this Privacy Policy as the Services, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice where required by law.
19. Contact
Paza Social, Inc., a Delaware corporation
Operational contact: Nairobi, Kenya
Email: legal@paza.social
Phone: +1 308 267 0234