Festivio

Data Processing Agreement

Last updated: 26 June 2026

This Data Processing Agreement ("DPA") forms an integral part of the Organizer Terms and governs the processing of personal data carried out by Agostini Lab S.r.l. ("Festivio", the "Processor") on behalf of the event organizer (the "Controller") in connection with the Festivio platform, pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). It applies whenever the organizer uses the platform to sell tickets or consumables and Festivio processes attendee and order personal data on the organizer's behalf. Where this DPA and the Organizer Terms conflict on data protection matters, this DPA prevails.

Roles of the Parties

For attendee and order personal data processed through the platform, the organizer is the data controller and Festivio is the data processor acting on the controller's documented instructions. Festivio acts as an independent controller for data it processes for its own purposes (account management, billing, platform security, fraud prevention, aggregate analytics, and product improvement); that processing is governed by the Festivio Privacy Policy and is outside the scope of this DPA.

Subject Matter, Duration, Nature and Purpose

Subject matter: the processing of personal data necessary to provide the platform services. Nature and purpose: hosting, storage, transmission, ticket and token issuance and redemption, order fulfilment, sending of transactional/service messages, generation of fiscal receipts where required, and related support. Duration: for the term of the organizer's use of the platform and until deletion or return of the data as set out below.

Categories of Data and Data Subjects

Categories of data subjects: attendees and buyers of the organizer's events. Categories of personal data: identification and contact details (email, first name, last name), purchase and order details, ticket/token and wallet-pass identifiers, age confirmation where required by the organizer, and limited device and session data. No special categories of data under Article 9 GDPR are intended to be processed; the organizer must not configure the platform to collect such data without a valid legal basis and prior agreement.

Processing on Documented Instructions

Festivio processes personal data only on the controller's documented instructions, including with regard to international transfers, unless required to do so by EU or Member State law, in which case Festivio informs the controller unless that law prohibits it. The Organizer Terms, this DPA, and the configuration choices made by the organizer in the platform constitute the controller's complete and final instructions. Festivio informs the controller if, in its opinion, an instruction infringes the GDPR or other data protection law.

Confidentiality

Festivio ensures that persons authorized to process the personal data are bound by an appropriate duty of confidentiality and process the data only as needed to provide the services.

Security Measures (Art. 32)

Festivio implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls and least-privilege access, hashed credentials, network and application hardening, logging, and regular backups. Measures may be updated provided the level of security is not diminished.

Sub-processors

The controller grants general authorization for Festivio to engage sub-processors to provide the services. Current sub-processors include Stripe (payments and Stripe Connect), Resend (transactional email), Hetzner (application, frontend, and database hosting, EU), Cloudflare / Amazon Web Services (object storage and content delivery), OpenAPI S.r.l. (transmission of electronic fiscal receipts to the Italian Revenue Agency where required), and Apple/Google for wallet-pass delivery. Festivio imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance. Festivio informs the controller of intended changes (additions or replacements) of sub-processors with reasonable notice, giving the controller the opportunity to object on reasonable data protection grounds.

Assistance with Data Subject Rights

Taking into account the nature of the processing, Festivio assists the controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the controller's obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection). If a data subject contacts Festivio directly regarding event data, Festivio routes the request to the relevant controller.

Breach Notification and Further Assistance

Festivio assists the controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available. Festivio notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, providing the information reasonably available to enable the controller to meet its own notification obligations to the supervisory authority and data subjects.

International Transfers

Where processing involves the transfer of personal data outside the European Economic Area (for example via sub-processors located in the USA), such transfers are made under appropriate safeguards pursuant to Chapter V GDPR, including the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework, together with supplementary measures.

Return and Deletion of Data

On termination of the services, and at the controller's choice, Festivio deletes or returns the personal data processed on the controller's behalf and deletes existing copies, unless EU or Member State law (including Italian fiscal-record retention obligations) requires storage. Backups are deleted on a rolling basis according to Festivio's retention schedule.

Audits

Festivio makes available to the controller information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates, subject to reasonable notice, confidentiality, and limits to protect the security and data of other customers. Festivio may satisfy audit requests by providing relevant documentation or third-party certifications where available.

Governing Law

This DPA is governed by Italian law, with exclusive venue in Padova, consistent with the Organizer Terms. For questions about this DPA, use the Contact page.