Current version
Effective: 24 July 2026
This Data Processing Agreement (DPA) forms part of the agreement between the Restaurant or other business customer (Controller) and Fiest Oy, Business ID 3438254-5 (Processor), whenever Fiest processes personal data on the Controller's behalf to provide the Services.
The service agreement, order form, partnership agreement, or Terms of Service that incorporates this DPA is the Main Agreement. If this DPA conflicts with the Main Agreement on personal-data processing, this DPA controls. A separately signed data processing agreement controls over this online DPA.
The Controller determines the purposes and essential means of processing Restaurant Data. Fiest processes Restaurant Data only on the Controller's documented instructions, including the Main Agreement, the Restaurant's configuration and use of the Services, and other written instructions accepted by Fiest.
If the Controller enables an integration with a third-party service selected or connected for the Controller, that configuration is a documented instruction for Fiest to disclose, receive, and synchronize Restaurant Data within the enabled scope. A third-party service does not become Fiest's sub-processor solely because Fiest provides that technical connection on the Controller's instruction. If Fiest appoints a provider to process Restaurant Data on Fiest's behalf, Section 7 applies.
Fiest will inform the Controller if, in Fiest's opinion, an instruction infringes applicable data-protection law, unless law prohibits that notice. Fiest may process data where required by EU or Member State law, in which case Fiest will notify the Controller before processing unless the law prohibits notice.
Fiest's processing where it independently determines the purposes and means, including its own account administration, billing, security, service reliability, account and support communications, service-usage analysis and improvement, communications, marketing, and other purposes described in the Privacy Policy, is outside this DPA. Support work that requires access to Restaurant Data remains subject to this DPA.
Subject matter and purpose:
Duration:
Data subjects:
Data categories:
The Services are not intended to receive full card numbers, card security codes, payment authentication secrets, or special-category data unless the parties expressly agree otherwise.
On the Controller's instructions, Fiest may process pseudonymous transaction or payment references to provide Restaurant-specific aggregate and estimated repeat-visit analytics. Results may be approximate and will not be presented as exact counts of unique customers.
Restaurant-controlled data will remain scoped to the relevant Controller and accessible only to authorized users and personnel. Any materially different use requires documented instructions and the applicable roles, lawful basis, notices, and safeguards.
Fiest will ensure that persons authorized to process Restaurant Data are bound by confidentiality obligations and receive access only as needed for their duties.
Fiest will implement and maintain technical and organizational measures appropriate to the risk under GDPR Article 32, including as applicable:
Fiest may update safeguards as technology and risks develop, provided the overall level of protection is not materially reduced.
The Controller gives Fiest general written authorization to use sub-processors. The current register, including provider identity, purpose, and processing location, is published at https://fiest.io/en/subprocessors.
Fiest will notify the Controller at its registered contact address at least fourteen (14) days before a new sub-processor begins processing Restaurant Data. The Controller may object within that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection, modify the affected processing, or provide a reasonable alternative. If no reasonable solution is available, the Controller may terminate the affected Service by written notice before the change takes effect.
Fiest will impose data-protection obligations on each sub-processor that provide materially equivalent protection for the relevant processing. Fiest remains responsible for its sub-processors' performance of those obligations.
Taking into account the nature of the processing, Fiest will provide reasonable technical and organizational assistance for the Controller to respond to requests under GDPR Articles 12-22. Fiest will promptly forward a request received directly where the Controller can be identified and will not respond on the Controller's behalf unless instructed or legally required.
Fiest will notify the Controller through the Restaurant's registered account email or designated privacy or security contact without undue delay after becoming aware of a personal data breach affecting Restaurant Data.
The notice will include information available to Fiest that is reasonably required for the Controller's obligations. Fiest may provide information in phases and will reasonably cooperate with the Controller's investigation and notification obligations.
Taking into account the nature of processing and information available to Fiest, Fiest will provide reasonable assistance with security obligations, data-protection impact assessments, prior consultations, and supervisory-authority enquiries under GDPR Articles 32-36.
During the Main Agreement, Fiest will delete or return specified Restaurant Data on the Controller's documented instruction where technically feasible and subject to applicable retention requirements.
After termination, Fiest will delete or return Restaurant Data at the Controller's choice in accordance with the Main Agreement, unless applicable law requires retention. Data retained for a lawful purpose will be protected from use for incompatible purposes and deleted when the applicable period ends.
Restaurant-specific analytics are retained according to the Service configuration, the Controller's documented instructions, and applicable retention requirements.
Fiest will make available information reasonably necessary to demonstrate compliance with this DPA. The Controller or its independent auditor may conduct an audit on reasonable advance notice, during normal business hours, and subject to confidentiality, security, and non-disruption requirements.
Fiest may first satisfy an audit request with current certifications, third-party reports, security documentation, or a written questionnaire. On-site inspections are limited to cases where that information is reasonably insufficient or a material incident or authority requires further verification.
Fiest will not transfer Restaurant Data outside the European Economic Area unless the transfer is permitted by applicable data-protection law. Where required, Fiest will use an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism and supplementary safeguards appropriate to the risk.
This DPA remains effective while Fiest processes Restaurant Data under the Main Agreement and survives termination for as long as that processing continues.
Fiest may update this DPA to reflect changes in law, regulatory guidance, security practices, or the Services. For a material change affecting the Controller's rights or obligations, Fiest will email the Controller's registered address at least thirty (30) days before the change takes effect. The notice will identify the principal changes, reason, effective date, and new version. The Controller may terminate the affected Service before the effective date if it reasonably objects and the parties cannot resolve the objection. Sub-processor changes follow the fourteen-day process in Section 7.
No update will reduce the protections required by GDPR Article 28. Versioned copies are available at https://fiest.io/en/data-processing-agreement.
Fiest Oy
Business ID: 3438254-5
Sähkötalo, Kampinkuja 2, 00100 Helsinki
Data-protection enquiries may be sent to info@fiest.io. Controller instructions and operational requests may be sent to support@fiest.io.
Last updated: 24.07.2026