1. Purpose and scope
This Data Processing Agreement ("DPA") forms part of the agreement between Festina Technology d.o.o. ("Processor", "Festina") and the customer ("Controller") for the use of the Festina.ai platform (the "Service"). It applies to all processing of personal data by Festina on behalf of the Controller in connection with the Service, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Subject matter and details of processing
| Item | Description |
|---|---|
| Subject matter | Processing of personal data contained in or generated through Customer Content connected to, uploaded to, or processed by the Service. |
| Duration | For the term of the Service agreement, plus any retention period required by law or agreed for deletion/return. |
| Nature and purpose | Hosting, indexing, semantic search, retrieval, AI-assisted analysis and generation of answers with citations — solely to provide the Service as instructed by the Controller. |
| Categories of data subjects | Controller's employees, contractors, clients, partners and other individuals whose data appears in Customer Content. |
| Types of personal data | Determined by the Controller — typically identification and contact data, professional/employment data, and content of business documents and communications. |
| Special categories | Not intended, unless the Controller explicitly configures the Service to process them; in that case the Controller warrants it has a lawful basis. |
3. Obligations of the Processor
Festina shall:
- Process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required by EU or Member State law;
- Ensure that persons authorised to process personal data are bound by confidentiality obligations;
- Implement appropriate technical and organisational measures (Section 5) to ensure a level of security appropriate to the risk;
- Engage sub-processors only under the conditions in Section 6;
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection);
- Assist the Controller in ensuring compliance with obligations regarding security, breach notification, data protection impact assessments and prior consultations (Art. 32–36 GDPR);
- At the Controller's choice, delete or return all personal data upon termination of the Service, and delete existing copies unless EU or Member State law requires storage;
- Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.
4. Obligations of the Controller
The Controller warrants that it has a lawful basis for processing the personal data made available through the Service, that data subjects have been informed as required, and that its instructions to the Processor comply with applicable data protection law.
5. Security measures
Festina implements, at minimum, the following technical and organisational measures:
- Encryption of personal data in transit (TLS) and at rest (AES-256);
- Infrastructure hosted on Microsoft Azure, in the jurisdiction or region selected to align with the laws and regulatory requirements applicable to the Controller's organisation;
- Access control — permission-aware retrieval: each end user sees only content they are authorised to access, mirroring the Controller's source-system permissions; role-based access and SSO support;
- No training on customer data — Customer Content and personal data are never used to train public AI models;
- Audit logging of access and administrative actions;
- Personnel confidentiality commitments and least-privilege internal access;
- Backup and availability measures appropriate to the Service tier.
6. Sub-processors
The Controller grants Festina general authorisation to engage sub-processors, subject to the following: Festina shall impose data protection obligations on sub-processors no less protective than this DPA, remain fully liable for their performance, maintain a current list of sub-processors available on request, and notify the Controller of intended changes, giving the Controller the opportunity to object on reasonable data-protection grounds within 14 days.
Core sub-processor categories: cloud infrastructure (Microsoft Azure), large language model inference providers (under zero-retention / no-training configurations), and operational tooling (email delivery, monitoring).
7. International transfers
Personal data is processed primarily within the EU/EEA. Where processing involves a transfer to a third country, Festina ensures an adequate safeguard under Chapter V GDPR — typically EU Standard Contractual Clauses — and applies supplementary measures where required.
8. Personal data breach notification
Festina shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf. The notification shall describe the nature of the breach, likely consequences, and measures taken or proposed to address it.
9. Liability and term
Liability under this DPA is subject to the limitations agreed in the Terms of Service or the main customer agreement. This DPA applies for the duration of the Service agreement; obligations relating to confidentiality, deletion/return of data, and audits survive termination.
10. Governing law
This DPA is governed by the laws of the Republic of Croatia. The courts in Pazin, Croatia shall have jurisdiction, unless mandatory EU or Member State law provides otherwise.
Last updated: 26 July 2026 · For a countersigned copy or our current sub-processor list, contact contact@festina.ai.