Data Protection Compliance
Privacy and data-protection controls built into Wiacom
Wiacom helps venues, property operators, educational organisations, enterprises and service providers collect and use first-party data while managing privacy and data-protection obligations throughout the WiFi identity, onboarding, access, analytics and engagement lifecycle.
Privacy notices, consent management, consent evidence, data minimisation, retention controls, user-rights workflows and communication preferences are built into the platform.
Wiacom’s consent-management functionality is available by design and cannot be disabled at platform level. Customers can configure the appropriate privacy and consent journey according to their processing purposes, lawful basis and applicable jurisdiction.
Wiacom’s privacy framework and technical mechanisms have also been independently reviewed by external data-protection counsel.
View the independent data-protection compliance assessment
International data-protection framework
Wiacom can be configured to support requirements and principles arising from:
- European Union: Regulation (EU) 2016/679 — the General Data Protection Regulation
- United Kingdom: UK GDPR and the Data Protection Act 2018
- United States: California Consumer Privacy Act, including the CPRA amendments, and applicable state-specific privacy requirements
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data
- DIFC and ADGM: Applicable data-protection requirements for deployments within the relevant financial free zones
- Asia-Pacific: Core transparency, collection-limitation, purpose, security, access and accountability principles reflected in the APEC Privacy Framework
The exact requirements depend on the customer’s location, role, processing purposes, lawful basis and deployment configuration. Wiacom provides configurable controls that help organisations implement the appropriate privacy journey for each venue and jurisdiction.
UK Information Commissioner’s Office registration
FREE WIFI SYSTEM SRL is registered with the UK Information Commissioner’s Office as a data controller.
The official ICO register identifies WIACOM and wiacom.ai as other names associated with FREE WIFI SYSTEM SRL.
- Registration reference: ZC106901
- Data controller: Free Wifi System SRL
- Other registered names: WIACOM and wiacom.ai
View the official ICO register entry
Download the ICO registration certificate
The current registration status and validity period can be confirmed directly through the live ICO register.
Privacy notices and consent management
Each Wiacom deployment can present privacy information appropriate to the organisation, venue, processing purposes and applicable jurisdiction.
The platform supports:
- Configurable privacy notices and terms
- Clear identification of the relevant venue or data controller
- Multiple languages
- Separate service-related and marketing choices
- Explicit marketing opt-in where required
- Recording of consent and communication preferences
- Evidence of when and where a choice was made
- Consent withdrawal and audience-suppression controls
- Updated acceptance when relevant policies change
- Venue-specific forms, purposes and retention settings
Access to a WiFi service does not need to be conditional on accepting marketing communications. Service-related acceptance and optional marketing consent can be managed separately.
Data minimisation and registration-free access
Wiacom allows each customer to determine which information is genuinely required for its use case.
Available onboarding methods include:
- Registration-free Splash Page access
- Email registration and verification
- Telephone number and OTP verification
- Social or identity-provider authentication
- Guest Connect through a URL or QR code
- PMS, booking, resident or membership-system onboarding
- Mobile application and SDK onboarding
- External API-based onboarding
A registration-free Splash Page can be configured without collecting registration or marketing identifiers such as a person’s name, email address or telephone number.
Technical identifiers required for connectivity, security, authentication or network operation may still constitute personal data. Their processing therefore remains subject to applicable privacy and data-protection requirements.
Data-subject rights and preferences
The Wiacom User Portal and administrative workflows can support applicable data-subject rights and requests, including:
- Access to personal information
- Correction of inaccurate information
- Deletion requests
- Withdrawal of marketing consent
- Communication-preference management
- Objection and suppression
- Data export and portability workflows
- Restriction of further marketing use
The availability and handling of each right depend on the applicable law, the organisation’s role and any lawful retention requirements.
Retention, deletion and access lifecycle
Retention periods can be configured according to the customer’s purposes and applicable legal requirements.
Wiacom supports:
- Configurable retention rules
- Deletion and anonymisation workflows
- Marketing-suppression records
- Access expiry and credential revocation
- Guest, resident, student and membership lifecycle management
- Automatic access changes linked to check-out, move-out or membership termination
Customers remain responsible for selecting retention periods appropriate to their processing purposes and legal obligations.
First-party data and audience activation
Wiacom can create consent-aware first-party audience segments from physical WiFi interactions and other approved data sources.
Depending on the customer’s configuration and applicable law, eligible audiences can be prepared for CRM, CDP, marketing and advertising activation through secure exports or API integrations.
Controls can include:
- Audience eligibility based on consent status
- Suppression following withdrawal or opt-out
- Hashed identifiers where supported by the destination platform
- Purpose-specific segmentation
- Controlled access for authorised agencies and partners
- Audit information for data exports and activation workflows
The customer remains responsible for ensuring that every destination platform and activation purpose is covered by an appropriate lawful basis, privacy notice and contractual arrangement.
Security of personal data
Wiacom applies technical and organisational measures designed to protect information processed through the platform, including:
- Encryption in transit and at rest where applicable
- Role-based access control
- Multi-factor authentication
- Pseudonymised dashboard presentation where configured
- Authentication and operational logging
- Access and credential lifecycle controls
- Incident-management procedures
- Security monitoring and risk management
- Employee privacy and information-security training
FREE WIFI SYSTEM SRL, the company that develops and operates Wiacom, maintains an Information Security Management System certified according to ISO/IEC 27001:2022 by CERTIND.
The certified scope covers the design, development, delivery, operation and technical support of Wiacom’s cloud-based SaaS platform for WiFi identity management, user onboarding, secure network access, authentication, analytics, automation and operational intelligence.
View Wiacom’s ISO/IEC 27001:2022 certification
Global hosting and data residency
Wiacom uses Microsoft Azure and Google Cloud infrastructure and can deploy services in different geographic regions according to the customer’s location, operational requirements, applicable data-protection obligations and contractual arrangements.
Depending on the selected deployment, customer data may be hosted in the European Union, United Kingdom, United States or another available regional location. Customer-controlled hosting options may also be provided where required.
The selected hosting region, relevant subprocessors and applicable data-transfer arrangements are established for each deployment. Where personal data is transferred between jurisdictions, Wiacom and the relevant parties use appropriate contractual and legal mechanisms, which may include adequacy decisions, Standard Contractual Clauses or other recognised safeguards.
The use of global cloud infrastructure does not mean that customer data is automatically transferred between every available region. Data location and transfer requirements depend on the customer’s selected deployment.
Cloud infrastructure privacy documentation
Wiacom’s cloud infrastructure providers publish contractual, privacy and security information describing their data-processing obligations and international-transfer safeguards:
- Google Cloud and GDPR
- Google Cloud Data Processing Addendum
- Microsoft GDPR documentation
- Microsoft Products and Services Data Protection Addendum
These documents describe the commitments made by the respective cloud providers. The terms applicable to a particular Wiacom deployment depend on the selected infrastructure, region and contractual configuration.
Controller and processor responsibilities
For most customer deployments:
- The customer, venue or property operator acts as the data controller
- FREE WIFI SYSTEM SRL, through Wiacom, acts as a data processor
- Relevant infrastructure, messaging, CRM, advertising or integration providers may act as additional processors or independent controllers, depending on their services
Wiacom provides a Data Processing Agreement and supports customers with appropriate technical and operational controls.
Customers remain responsible for determining their processing purposes, lawful bases, collected data fields, retention periods, audience activation and third-party integrations.
Independent legal assessment
SCA Grecu & Associates provides data-protection legal assistance and Data Protection Officer services to FREE WIFI SYSTEM SRL.
On 25 April 2024, SCA Grecu & Associates issued a written compliance assessment addressing the privacy policies and technical mechanisms implemented within the Wiacom platform.
The assessment considers:
- The EU GDPR
- UK GDPR and the Data Protection Act 2018
- CCPA and CPRA transparency and control principles
- UAE data-protection legislation
- DIFC and ADGM requirements where applicable
- Core privacy principles relevant to the Asia-Pacific region
[View or download the independent data-protection compliance assessment]
The assessment is an external legal review issued on the stated date. It should not be described as an accredited product certification or as a guarantee covering every possible customer configuration.
Our continuing compliance approach
Data-protection compliance is an ongoing process. Wiacom maintains policies, governance, technical controls and documentation and reviews them as the platform, suppliers, processing activities and applicable requirements evolve.
These activities include:
- Periodic privacy and security assessments
- Review of data-processing agreements
- Subprocessor and supplier due diligence
- Employee privacy and security training
- Incident-management procedures
- Review of international data-transfer requirements
- Platform security and access-control improvements
- Support for customer compliance assessments
Frequently asked questions
Is Wiacom GDPR compliant?
Wiacom is designed and operated to support GDPR-compliant deployments through built-in privacy notices, consent management, consent evidence, data minimisation, retention controls, data-subject rights and security measures.
Compliance for a specific deployment also depends on the customer’s processing purposes, lawful basis, configuration, integrations and subsequent use of the collected data.
Does Wiacom support privacy requirements outside the European Union?
Yes. Wiacom provides configurable controls that can support UK GDPR, the UK Data Protection Act 2018, CCPA/CPRA, UAE data-protection legislation and core APEC Privacy Framework principles.
Requirements must be assessed and configured according to each applicable jurisdiction.
Can Wiacom provide WiFi without collecting registration data?
Yes. Wiacom Splash Page can be configured without collecting registration or marketing identifiers such as a name, email address or telephone number.
Technical network identifiers may still be processed for connectivity, authentication, security and operational purposes.
Is marketing consent required to access WiFi?
No. Wiacom can separate acceptance required to provide the connectivity service from optional consent for marketing communications, audience creation and advertising activation.
Who owns data collected through Wiacom?
Customer data processed through the platform remains under the customer’s control in accordance with the applicable agreement. Wiacom does not acquire independent ownership of customer first-party data.
Where is Wiacom customer data hosted?
Wiacom uses Microsoft Azure and Google Cloud and can select an appropriate geographic deployment according to customer location, operational requirements and contractual arrangements. Customer-controlled deployment options may also be available.
Does Wiacom transfer data internationally?
This depends on the selected hosting region, subprocessors, integrations and customer configuration. Where an international transfer occurs, the relevant parties must apply an appropriate legal transfer mechanism.
Is Wiacom ISO/IEC 27001 certified?
FREE WIFI SYSTEM SRL, the developer and operator of Wiacom, maintains an Information Security Management System certified according to ISO/IEC 27001:2022 by CERTIND.
The certification scope expressly covers the design, development, delivery, operation and technical support of the Wiacom cloud SaaS platform.





