festivos.io

Data Processing Agreement (DPA)

How festivos.io processes personal data under the GDPR (art. 28): roles, sub-processors, transfers and security. It complements the Privacy policy and the API Terms.

1. Roles and scope

2. Sub-processors

To deliver the service we rely on the following processors/sub-processors:

We will announce additions or changes of sub-processors with reasonable notice, allowing the customer to raise a reasoned objection.

3. International transfers

Processing in the EU/EEA is preferred. Where a sub-processor involves transfers outside the EEA, these rely on valid mechanisms: an adequacy decision or Standard Contractual Clauses (SCC) with supplementary measures where appropriate.

4. Security measures (art. 32)

5. Duration and end of processing

The public API does not start a processor relationship. If a separate integration had a DPA, that agreement would define its duration and the deletion or return of data.

6. Signed DPA and contact

If a separate integration requires processing personal data on behalf of another entity, asigned data processing agreement can be requested before that processing starts. Contact: privacidad@festivos.io.

Last updated: August 2026.

Privacy and cookies →