Privacy Policy
Last updated: 26 June 2026
This Privacy Policy explains how Agostini Lab S.r.l. ("Festivio", "we") collects, uses, shares, and protects your personal data when you browse our site, create an account, or purchase tickets and consumables from event organizers using our platform. Data controller: Agostini Lab S.r.l., Via Montebello 3, 35141 Padova (PD), Italy, VAT no. IT04767140280.
Controller and Processor Roles
For purchases and event operations, the event organizer acts as the data controller of attendee and order data, and Festivio acts as data processor on their behalf under a Data Processing Agreement (Art. 28 GDPR). For your account, billing, platform security, fraud prevention, aggregate analytics, and product improvement, Festivio acts as an independent controller. Questions about attendee data for a specific event should be directed to the relevant organizer.
Categories of Data We Process
We may process: identification and contact details (email, first name, last name); account credentials (passwords are stored only in hashed form); billing and fiscal data (billing address, Italian Codice Fiscale, Partita IVA, PEC email, SDI code — collected only when needed for invoicing or fiscal receipts); purchase and order details (items, amounts, Stripe payment identifiers); attendee data (first name, last name, age confirmation — only when required by the organizer for the specific event); wallet pass identifiers and device push tokens (only if you add a pass to Apple/Google Wallet or enable notifications); social sign-in identifiers (only if you choose to log in with Google or Facebook); messages you send us via support or contact forms; and device and session data (IP address, browser, locale, last login timestamp) plus limited usage data needed to provide secure, reliable services.
Purposes of Processing
We use data to provide the platform, fulfill purchases, enable entry and redemption, issue wallet passes, send service and order notifications, generate fiscal receipts where required, support organizers, prevent fraud and abuse, secure our services, measure performance, improve user experience, and comply with legal obligations.
Legal Bases
Our processing relies on one or more lawful bases under Art. 6 GDPR: performance of a contract (e.g., fulfilling your order and providing your account); legal obligations (e.g., tax, invoicing, and fiscal-record keeping); legitimate interests (e.g., security, fraud prevention, and service improvement); and your consent (e.g., non-essential cookies and any marketing communications), which you may withdraw at any time.
Service Providers and Sub-processors
We use vetted providers that process data on our behalf or to which data is disclosed to deliver the service: Stripe (Stripe Payments Europe, Ltd., Ireland / Stripe, Inc., USA) — payment processing and Stripe Connect, the organizer being the merchant of record; Resend (Resend, Inc., USA) — transactional email; Hetzner (Hetzner Online GmbH, Germany, EU) — application, frontend, and database hosting; Cloudflare / Amazon Web Services (USA) — object storage and content delivery for images and pass assets; OpenAPI (OpenAPI S.r.l., Italy) — transmission of electronic fiscal receipts to the Italian Revenue Agency where required; Google (Google LLC, USA) — Google Wallet pass delivery and optional Google sign-in; Apple (Apple Inc., USA) — Apple Wallet pass delivery; Meta (Meta Platforms, Inc., USA) — optional Facebook sign-in; and the push delivery services of your browser or device vendor for web push notifications. Website analytics use a self-hosted Umami instance on our EU infrastructure, with no sharing to third-party analytics networks; IP-based country detection for the cookie banner uses a locally hosted database, with no transfer of your IP to a third party. These providers process data under contractual safeguards (including, where applicable, data processing agreements) consistent with this Policy.
International Data Transfers
Some providers are located outside the European Economic Area (in particular Stripe, Resend, Cloudflare/AWS, Google, Apple, and Meta in the USA). Where data is transferred internationally, we rely on appropriate safeguards under Chapter V GDPR, including the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where the provider is certified, the EU-US Data Privacy Framework, together with supplementary technical and organizational measures.
Data Retention and Security
We keep personal data only as long as necessary for the purposes above. Indicatively: account data is retained while your account is active and deleted or anonymized within 30 days of account closure; billing, invoicing, and transaction records are retained for 10 years as required by Italian fiscal law (Art. 2220 Civil Code; D.P.R. 633/1972 and 600/1973); attendee and order data tied to an organizer are retained according to the organizer's instructions and deleted when the organizer account is removed; aggregate analytics are kept in non-identifying form; security and server logs are kept up to 12 months; and backups rotate on a rolling basis up to 30 days. We apply technical and organizational measures including encryption in transit, access controls, and hashed credentials. In the event of a personal data breach, we notify the Garante per la protezione dei dati personali within 72 hours where required (Art. 33 GDPR) and affected individuals without undue delay where the breach is likely to result in a high risk (Art. 34 GDPR).
Your Rights and Complaints
Subject to applicable law, you have the rights to access, rectification, erasure, restriction, objection, and data portability, and to withdraw consent at any time (Arts. 15–22 GDPR). Submit requests through the Contact page; we respond within one month (Art. 12 GDPR). Where the event organizer is the controller of attendee data, we will route your request to them. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Cookies and Similar Technologies
We use cookies and similar technologies for essential functionality, preferences, analytics, and security. See Cookie Policy.
Contact
Questions or requests about privacy can be submitted via the Contact page.
Governing Law
Unless required otherwise by local law, this Policy is governed by Italian law and disputes are subject to the courts of Padova, Italy.