This register identifies service providers that may process Restaurant Data on behalf of Fiest Oy under the Data Processing Agreement. A provider processes data only for the services in which it is used. Fiest applies data minimization and does not send every category of Restaurant Data to every provider.
Fiest will notify affected Controllers at least fourteen (14) days before adding a sub-processor that will process Restaurant Data. Questions or objections may be sent to info@fiest.io.
Payment providers selected or contracted by a Restaurant may process data under the Restaurant's agreement and the provider's own legal role. They are not Fiest sub-processors where they act independently or directly for the Restaurant.
A payment provider engaged to process Restaurant Data solely on Fiest's behalf will be added to this register before that processing begins.
Where a provider processes Restaurant Data outside the EEA, Fiest relies on an applicable adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism and applies supplementary safeguards where required.
New sub-processors are added to this register before they begin processing Restaurant Data and are subject to the notice and objection process in the DPA. Editorial corrections and changes concerning providers that do not process Restaurant Data may be published without sub-processor notice.