Privacy policy
Last updated: 27 September 2026
This privacy policy explains how we process personal data when you visit sostolabs.com, when you become a customer of Sosto Labs Captive Portal, and when guests use a Wi-Fi portal that one of our customers operates with our service. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP / nLPD) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Who we are
The controller for the processing described in sections 2 and 3 is:
Sosto Labs, a brand ofLALU Solutions di Luca Lafranchi
Via ai Saleggi 11
6600 Locarno
Switzerland
VAT CHE-260.962.346
Contact form
2. Visiting this website
This website is a static site. It does not use analytics, advertising or tracking tools, and it does not set cookies of its own.
- Server logs. Our hosting provider records technical data for each request (IP address, date and time, requested page, browser and referrer) to deliver the website and keep it secure. Logs are kept for a short period and then deleted.
- Localised prices. On the pricing section, the website loads Paddle.js from Paddle to show prices in your local currency. For this, your IP address is transmitted to Paddle, which estimates your country. Paddle processes this data under its own privacy policy.
- Fonts and assets are served from our own domain; no third-party font services are used.
- Contact form and e-mail. If you write to us, we use your name, e-mail address, the optional company or portal name and your message only to answer your request, and keep them as long as needed for that and for our business records. The form sends your message to us by e-mail; to limit abuse, we keep a short-lived, hashed record of the sending IP address for one hour.
3. Customers
When you start a trial or subscribe, we process the data needed to provide the service, manage your account and meet our legal obligations: name, company, e-mail address, country, language, the plan and usage of your subscription (for example the number of sites, access points and monthly guests), technical logs and our correspondence with you.
Payments are handled by Paddle.com Market Limited, our reseller and Merchant of Record. Paddle collects your payment and billing details directly; we do not receive or store your full card details. We receive from Paddle the information needed to manage your subscription (for example status, plan and country).
Legal bases: performance of the contract, compliance with legal obligations (for example accounting and tax records, generally kept for 10 years under Swiss law) and our legitimate interest in operating and securing the service.
4. Wi-Fi guests of our customers
When a guest signs in to a Wi-Fi portal run with Sosto Labs Captive Portal, the organisation offering the Wi-Fi (our customer) is the controller of the guest's personal data. We process that data only on the customer's behalf and on its instructions, as a processor.
Depending on how the customer configures its portal, this may include first and last name, e-mail address, the device's MAC address, the sponsor's e-mail address, a voucher code, the language, session times and traffic volumes, the version of the privacy notice accepted and, if the guest opts in, the marketing consent. The customer sets how long this data is kept; after that period it is anonymised automatically.
Guests who wish to exercise their rights should contact the organisation that offers the Wi-Fi, whose privacy notice is shown on the portal. If a request reaches us, we forward it to that organisation.
5. Hosting and service providers
We use carefully selected providers that process data on our behalf:
- Infomaniak Network SA, Switzerland — hosting of the website and of the service, e-mail delivery. Guest data is stored in Switzerland.
- Paddle.com Market Limited, United Kingdom — reseller and Merchant of Record for orders, payments, invoices and taxes.
Customers can choose to send guest e-mails through their own mail server; in that case their mail provider is involved under their responsibility.
When data is transferred outside Switzerland (for example to Paddle in the United Kingdom), it is transferred only to countries with adequate data protection according to the Swiss Federal Council, or on the basis of appropriate safeguards such as standard contractual clauses.
6. Security
We use appropriate technical and organisational measures, including encrypted connections (HTTPS), encryption of credentials at rest, access control with optional two-factor authentication for administrators, and separation of customer data.
7. Retention
We keep personal data only as long as necessary for the purposes described above or as required by law. Account data is deleted or anonymised after the end of the contract, unless legal retention obligations apply.
8. Your rights
Subject to the applicable law, you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, to data portability and, where processing is based on consent, to withdraw your consent at any time. You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
To exercise your rights, use our contact form or write to the e-mail address given in our imprint.
9. Changes
We may update this privacy policy when our services or the law change. The current version is always available on this page.