Legal · Compliance

Cookie Policy

PawaHR Limited  ·  Last updated: June 07, 2026
Governed by the Kenya Data Protection Act, 2019 (No. 24 of 2019)  ·  Pursuant to Article 31 of the Constitution of Kenya, 2010

What are cookies
Small data files stored on your device by your browser when you visit our website or use our application.
What we use
Strictly necessary cookies only — for authentication, session security, and CSRF protection. No advertising or tracking cookies.
Third-party cookies
None placed by default. If you opt in to analytics, Umami — a cookieless, privacy-first analytics service processed in the EU (Germany) — measures aggregate page views. We never serve advertising networks.
Your controls
Manage preferences in your browser settings or via the cookie preferences panel. Email privacy@pawahr.com with questions.
Table of Contents
  1. What Are Cookies and Similar Technologies?
  2. Legal Basis for Cookie Use
  3. How PawaHR Uses Cookies — Categories and Purposes
  4. Cookie Inventory — Detailed Register
  5. Third-Party and Sub-Processor Cookies
  6. Cookies We Do Not Use
  7. Session Storage and Local Storage
  8. Progressive Web App (PWA) Service Worker Cache
  9. Cross-Border Considerations for Cookie Data
  10. Managing and Withdrawing Consent
  11. Do Not Track and Global Privacy Control
  12. Cookies and Children
  13. Retention and Deletion of Cookie Data
  14. Changes to This Cookie Policy
  15. Contact and Complaints

What Are Cookies and Similar Technologies?

A cookie is a small text file that a website or web application asks your browser to store on your device when you visit. Cookies are widely used to make websites function correctly, remember your preferences, and gather analytics about how services are used.

Beyond conventional cookies, web applications also rely on similar technologies that serve comparable purposes:

This policy covers all of these technologies, collectively referred to as "cookies" throughout this document for readability. It explains which of these PawaHR uses, why, and how you can control them.

PawaHR's approach: We minimise cookie use to what is strictly required for the secure, functional operation of our HR and payroll platform. We do not use advertising cookies, behavioural tracking cookies, social media tracking pixels, or device fingerprinting on any part of our platform.

Legal Basis for Cookie Use

Under the Kenya Data Protection Act, 2019 (No. 24 of 2019) ("DPA"), the processing of personal data — including data derived from cookies — must have a lawful basis. [DPA s.30]

PawaHR relies on the following legal bases for its cookie use:

Strictly Necessary Cookies — Legitimate Interests / Contractual Necessity

Cookies required for authentication, session management, and security are necessary to deliver the services you have contracted with us for. These cookies are set without consent because they are essential to the operation of the platform. Blocking them will prevent the application from functioning. Our legitimate interest in securing the platform and preventing fraud is documented in our Data Protection Impact Assessment (DPIA) and is not overridden by your rights in this context. [DPA s.30(1)(b), s.30(1)(d)]

Optional Cookies — Freely Given, Specific, Informed Consent

Where PawaHR sets any non-essential cookie or analytics technology — currently limited to optional, cookieless analytics via Umami (processed in the EU) — we obtain your freely given, specific, informed, and unambiguous consent through our cookie preferences panel before any such cookie is set. Consent is recorded with a timestamp and may be withdrawn at any time with the same ease as it was given. [DPA s.30(1)(a); DPA General Regulations 2021 r.5]

PawaHR does not rely on implied or bundled consent for cookies. Continued use of the site, scrolling past a banner, or clicking away from a cookie notice does not constitute consent to optional cookies.

Where cookie data constitutes personal data, the processing is additionally governed by our Privacy Policy.

How PawaHR Uses Cookies — Categories and Purposes

PawaHR operates two distinct surfaces — the public marketing website at pawahr.com and the authenticated HR/payroll application at app.pawahr.com. Cookie usage differs between these surfaces.

Cookie Inventory — Detailed Register

The following table is our complete cookie register. We review and update this register whenever we add or change cookie use. [DPA General Regulations 2021 r.27 — Records of processing activities]

Cookie Name Provider Category Purpose Duration Basis
pawahr_session PawaHR Strictly Necessary Stores the authenticated session token (JWT) in an HTTP-only, Secure, SameSite=Strict cookie when the user logs in. Required for all authenticated API calls. Session (expires on logout or after 24 hours of inactivity) Contractual necessity / Legitimate interest
pawahr_csrf PawaHR Strictly Necessary CSRF (Cross-Site Request Forgery) protection token. Validated server-side on all state-changing requests (POST, PATCH, DELETE). Prevents malicious third-party sites from submitting requests on behalf of an authenticated user. Session Legitimate interest (security)
__cf_bm Cloudflare Strictly Necessary (Security) Cloudflare Bot Management cookie. Distinguishes automated traffic (bots, scrapers) from legitimate human visitors. Placed by Cloudflare's WAF on all proxied requests to api.pawahr.com and pawahr.com. Does not track users across sites. 30 minutes Legitimate interest (security)
_cfuvid Cloudflare Strictly Necessary (Security) Cloudflare rate-limiting cookie. Used to apply rate limits to visitors sharing the same IP address, while distinguishing between individual users. Placed only when rate-limiting is triggered. Session Legitimate interest (security)
cf_clearance Cloudflare Strictly Necessary (Security) Set after a visitor successfully passes a Cloudflare CAPTCHA or challenge. Prevents the visitor from being challenged again for a period. Only present when a challenge has been presented. 30 minutes – 24 hours Legitimate interest (security)
Umami analytics script Umami Software, Inc. Performance (Optional) If you consent to analytics, a JavaScript snippet measures page views, referral sources, and aggregate visitor counts. Umami is cookieless by design — it does not set a cookie or use local storage for tracking. It transmits anonymised request metadata (page URL, referrer, approximate geography at country level, browser type) to Umami Cloud servers located in the EU (Germany). Visitor identifiers are hashed and rotate daily; no personal identifiers are transmitted or stored. Data is aggregated and not used for profiling. No cookie stored. Script loads per page view. Consent

Cookie names prefixed with __ (double underscore) are typically set by infrastructure providers and not directly by PawaHR application code. Their presence reflects our use of Cloudflare as a security and CDN layer.

Cookie register accuracy: We maintain this register in good faith and review it on a rolling basis. If you observe a cookie not listed here on any PawaHR surface, please report it to privacy@pawahr.com so we can investigate and update this register promptly.

Third-Party and Sub-Processor Cookies

PawaHR uses a small number of third-party sub-processors whose infrastructure may set cookies or process cookie-derived data as part of delivering our service. We require all sub-processors to handle personal data in accordance with the DPA 2019 and our Data Processing Agreements.

Cloudflare, Inc.

PawaHR's domain (pawahr.com and api.pawahr.com) is protected by Cloudflare's CDN and WAF. Cloudflare processes HTTP request metadata — including IP address and request headers — for the purpose of security (bot mitigation, DDoS protection, rate limiting). Cloudflare sets the __cf_bm, _cfuvid, and cf_clearance cookies described in Section 4. These are security infrastructure cookies, not marketing cookies.

Cloudflare is a global service with servers in multiple jurisdictions. Data processed by Cloudflare's network may transit non-Kenyan infrastructure. Cloudflare is subject to Standard Contractual Clauses and is compliant with applicable international data transfer frameworks. See our Privacy Policy §8 for cross-border transfer details.

Cloudflare's own privacy notice: cloudflare.com/privacypolicy

Umami Software, Inc. (Optional Analytics)

Where you have consented to analytics, PawaHR uses Umami Cloud — a privacy-first, cookieless analytics service. Umami does not set cookies and does not use browser storage for tracking. It processes anonymised, aggregated usage data (page URL, referrer, country-level geography, browser and device type). Visitor identifiers are hashed and rotated daily, and no personal identifiers are stored.

Analytics data is processed and stored exclusively within the European Union (Germany), a jurisdiction whose data protection framework (GDPR) provides safeguards equivalent to or exceeding those of the Kenya Data Protection Act 2019. The analytics script loads only after you grant consent via our cookie banner, and consent may be withdrawn at any time. See our Privacy Policy §8 for cross-border transfer details.

Umami's own privacy notice: umami.is/privacy

Railway (Backend Hosting)

PawaHR's backend API runs on Railway. Railway does not set first-party cookies on your browser. HTTP requests to api.pawahr.com are proxied through Cloudflare before reaching Railway's infrastructure. Railway processes server-side request logs (IP addresses, request paths, timestamps) for operational purposes. No user-facing cookies are set by Railway directly.

Vercel (Frontend Hosting)

PawaHR's frontend application is hosted on Vercel. Vercel does not set first-party advertising or analytics cookies. Vercel may set infrastructure cookies (e.g. edge routing) as part of serving pages — these are transparent infrastructure cookies with no personal data significance. Vercel's privacy notice: vercel.com/legal/privacy-policy.

Resend (Transactional Email)

PawaHR uses Resend to deliver transactional emails (password resets, payslip notifications, leave approvals). Resend may embed a single transparent pixel in HTML emails to track whether an email was opened (email read receipt). This pixel is used only to monitor email deliverability and is not used for advertising profiling. If you prefer emails without tracking pixels, you can disable remote image loading in your email client. Resend's privacy notice: resend.com/legal/privacy-policy.

Safaricom M-Pesa (Daraja B2C)

PawaHR integrates with Safaricom's Daraja API for salary disbursement via M-Pesa. This integration is server-to-server (API call from PawaHR's backend to Safaricom's API) and does not involve any browser cookies. Safaricom does not set cookies on your browser through PawaHR's platform.

No advertising sub-processors: PawaHR does not engage Google Ads, Meta Ads, LinkedIn Marketing, TikTok for Business, or any advertising network as a sub-processor. No user data is shared with advertising platforms.

Cookies We Do Not Use

For clarity and to assist users in understanding PawaHR's data minimisation approach, the following cookie types are explicitly not used on any PawaHR surface:

Cookie Type PawaHR's Position
Advertising / Targeting cookies Not used. PawaHR does not run paid advertising retargeting campaigns on its application or public website.
Cross-site tracking cookies Not used. We do not track users across third-party websites.
Social media tracking pixels (Facebook, LinkedIn, Twitter/X, TikTok) Not used. No social network pixels are embedded on any PawaHR page.
Google Analytics / Google Tag Manager Not used. We do not use Google Analytics or any Google advertising product.
Hotjar, FullStory, or session recording tools Not used. We do not record or replay user sessions.
A/B testing platforms (Optimizely, VWO, etc.) Not used at this time.
Device fingerprinting Not used. We do not build probabilistic device identifiers from browser or hardware attributes.
Persistent advertising IDs Not used. We do not assign users advertising IDs.
Third-party chat or support widget cookies (Intercom, Drift, etc.) Not embedded. Customer support is provided via email and does not involve embedded third-party widgets.

Session Storage and Local Storage

In addition to cookies, PawaHR's application uses browser session storage and local storage for functionality that does not require server-side persistence. Although these technologies are not "cookies" in the strict sense, they are similar in that they store data in your browser.

Local Storage — What We Store

PawaHR's frontend application (React + Vite) uses browser local storage via the Zustand state management library for the following purposes:

Local storage data is stored on your device only and is not transmitted to PawaHR's servers. It is cleared when you log out or clear your browser data.

Important note on Incognito / Private Browsing: If you use PawaHR in your browser's private or incognito mode, local storage is cleared automatically when you close the private window. Your session will end as expected.

Session Storage

PawaHR does not currently use session storage for any persistent data. Certain in-flight form states (such as an unsaved leave request form) may be stored temporarily in React component state (in-memory only, not in the browser's sessionStorage API). These are not persisted beyond the current browser tab and contain no sensitive data.

No sensitive payroll data in browser storage: PawaHR does not store salary figures, statutory ID numbers (KRA PIN, NSSF No., SHA No.), bank details, or other sensitive payroll data in browser local storage or session storage. All sensitive data is fetched from the API on demand and held in React component state (memory only).

Progressive Web App (PWA) Service Worker Cache

PawaHR is a Progressive Web App (PWA), meaning it can be installed on your device and provides limited offline functionality. The PWA functionality is implemented using a service worker registered by the browser when you visit the application.

The service worker manages a browser cache (distinct from cookies) that stores the following:

The service worker cache is a performance and offline capability mechanism. It does not transmit any data to third parties and does not track user behaviour.

You can inspect and clear the service worker cache at any time via your browser's developer tools (Application tab → Cache Storage) or by clearing your browser's site data for pawahr.com.

Cross-Border Considerations for Cookie Data

Some data derived from cookies — specifically, Cloudflare security cookies — may be processed outside Kenya as part of Cloudflare's global network operations. Cloudflare operates data centres across Africa, Europe, and the Americas. HTTP request data (IP addresses, request headers, timing) associated with Cloudflare security cookies may transit or be stored on infrastructure outside Kenya. [DPA s.48 — Restriction on transfer of personal data outside Kenya]

PawaHR addresses this cross-border transfer as follows:

No other cookie data generated on PawaHR's platform is transferred outside Kenya.

Managing and Withdrawing Consent

You have several options for controlling cookie use on PawaHR. Note that disabling strictly necessary cookies will prevent you from logging in or using the platform.

A. Cookie Preferences Panel

On your first visit to pawahr.com, a cookie consent banner allows you to accept or decline optional performance cookies. You can revisit your preferences at any time by clicking "Cookie Preferences" in the website footer. Your consent choice is stored in local storage (not a cookie) with a timestamp and is valid for 12 months, after which you will be asked again.

B. Browser Settings

All major browsers allow you to view, manage, and delete cookies. Below are direct links to cookie management instructions for common browsers:

You may also configure your browser to block all third-party cookies or to notify you before any cookie is set. Be aware that blocking strictly necessary cookies from pawahr.com and api.pawahr.com will prevent authentication and platform access.

C. Cloudflare Cookie Opt-Out

Cloudflare's security cookies (__cf_bm, _cfuvid, cf_clearance) are set by Cloudflare's infrastructure rather than by PawaHR's application code. They cannot be disabled without disabling Cloudflare's security layer, which would expose the platform to security risks. These cookies are strictly necessary infrastructure cookies and do not require consent under DPA s.30.

D. Withdrawing Consent by Email

If you wish to withdraw previously given consent to optional analytics cookies and cannot access the preferences panel, you may email our DPO at privacy@pawahr.com with the subject line "Cookie Consent Withdrawal". We will update your preference record within 5 business days.

Withdrawal is without consequence: Withdrawing consent to optional cookies will not affect the quality of service you receive, your access to your account, or any of your rights under our Terms of Service. Only strictly necessary cookies are required for platform operation.

Do Not Track and Global Privacy Control

Some browsers allow you to send a Do Not Track (DNT) signal or a Global Privacy Control (GPC) signal to websites indicating that you do not wish to be tracked across sites. [DPA General Regulations 2021 — data subject rights]

PawaHR's response to these signals:

Cookies and Children

PawaHR is a professional HR and payroll platform designed exclusively for use by employers, HR professionals, and employees of organisations operating in Kenya and East Africa. PawaHR's services are not directed at, and should not be used by, persons under the age of 18.

We do not knowingly set cookies on the devices of children under 18 or process personal data of children. If you become aware that a person under 18 has accessed PawaHR, please contact us at privacy@pawahr.com so we can take appropriate action. [DPA s.34 — Processing of children's personal data]

Retention and Deletion of Cookie Data

The retention period for each individual cookie is set out in the cookie register in Section 4. As a summary:

You may delete all cookies associated with PawaHR at any time using your browser's site data management tools. Deleting your session cookie will log you out of the application.

When you delete your PawaHR account, any server-side session records are also purged. Browser-side cookies and local storage data on your devices must be cleared manually using your browser's settings, as PawaHR cannot remotely delete data stored on your device. [DPA s.26(1)(c) — Right to erasure]

Changes to This Cookie Policy

We may update this Cookie Policy when we introduce new features, change technology providers, or in response to changes in the DPA 2019 or ODPC guidance. Material changes to this policy will be communicated as follows:

For minor, non-material changes (corrections, updated hyperlinks, clarifications that do not alter cookie behaviour), the policy will be updated without prior notice. We recommend bookmarking this page and reviewing it periodically. The current version is always available at pawahr.com/cookie-policy.

Contact and Complaints

If you have any questions about this Cookie Policy, wish to exercise your rights in relation to cookie data, or believe PawaHR is setting a cookie not disclosed in this policy, please contact our Data Protection Officer:

CompanyPawaHR Limited
AddressNairobi, Kenya

We will acknowledge your enquiry within 7 days and aim to resolve it within 30 days. If you remain dissatisfied after engaging with our DPO, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) free of charge: [DPA s.56]

RegulatorOffice of the Data Protection Commissioner (ODPC)
Websiteodpc.go.ke
AddressTeleposta Towers, Kenyatta Avenue, Nairobi, Kenya

This Cookie Policy is governed by the laws of Kenya. Any disputes arising from this policy that cannot be resolved through the ODPC process shall be subject to the jurisdiction of the High Court of Kenya. [Constitution of Kenya, Article 165]


Version 1.0 — adopted by PawaHR Limited on June 07, 2026.

This Cookie Policy was prepared pursuant to the Kenya Data Protection Act, 2019 (No. 24 of 2019), the Data Protection (General) Regulations 2021, and the Data Protection (Complaints Handling Procedure and Enforcement) Regulations 2021. Section references marked [DPA s.X] refer to the Data Protection Act, 2019 unless otherwise stated.

Privacy Policy  ·  Terms of Service