Privacy
Last updated: July 30, 2026
1. Data controller
Sestaro, operated by LaFactory, is the controller of the personal data described in this policy. For any question, contact us at the address shown on lafactory.online.
2. Data concerned
Two categories: on one hand our customers' account data (name, email, purchase and unlock history); on the other hand the B2B professional data in our prospecting database (name, job title, company, professional email and phone, public profile).
3. Sources of B2B data
Professional data is sourced from public and professional sources. Every email is technically verified before being made available. We do not process sensitive data.
4. Legal basis and purposes
Processing of B2B data relies on legitimate interest: enabling commercial prospecting between professionals. Account data relies on the performance of the service contract.
5. Recipients
A contact record is only disclosed to an identified customer who spent a sestaro to unlock it. We do not resell bulk lists and never publish any data publicly.
6. Retention
Account data is kept for as long as the account is active. B2B data is updated or deleted when it becomes obsolete or upon an objection request.
7. Your rights
You have the right to access, rectify, erase, restrict and object. To exercise the right to object, use the Remove my data form: your contact will no longer be unlockable. You may also lodge a complaint with your supervisory authority.
8. Technical device fingerprint and fraud prevention
To prevent the bulk creation of free accounts aimed at harvesting our database, we compute a technical fingerprint of the device used at sign-up and at unlock: graphics rendering characteristics, hardware configuration reported by the browser, IP address. Only hashed fingerprints are stored, never the underlying attributes, and they are used solely to detect that one device is opening an abnormal number of accounts. The legal basis is legitimate interest (service security and protection of our data), and the purpose is strictly fraud prevention: no reuse for analytics, advertising or commercial profiling. Retention: up to 180 days after the device was last active, and any new activity restarts that period from zero. A device left inactive for 180 days is deleted entirely. We keep only a minimal register: a one-way hash, a count of accounts and the dates of first and last activity. The technical detail attached to each event, including the IP address, is deleted after 4 days.
See every tracker in detail on the Cookies and trackers page

