Scope and our roles
This page explains how personal information about attendees and guests is shared between you, the organizer, and Festro when you run an event on Festro, and what each of us must do with it. It is part of, and additional to, the Terms of service and the Privacy policy; for paid ticketing and payouts, see the Organizer payments agreement. “Festro”, “we”, and “us” mean Festro Inc.; “you” means the organizer account and the people authorized to act for it.
For the attendee and guest-list information you receive through Festro, you and Festro are each an independent controller (under Quebec's Law 25, each of us is the enterprise responsible for the personal information in our own hands). We are not acting as your processor or mandatary for that data, and you are not acting as ours. Each of us decides its own purposes and means for the information it holds, and each of us is separately responsible for its own compliance — for meeting individuals' requests about the data it controls, for keeping that data secure, and for reporting its own confidentiality incidents.
This independent-controller split applies to the attendee data Festro shares with you to run your event. It does not change Festro's own role: for the Festro platform itself — accounts, the catalogue, analytics, fraud prevention, and payments — Festro remains the controller and uses its own sub-processors, as described in the Privacy policy.
Your obligations as a controller
Because you are an independent controller of the attendee data you receive, Quebec Law 25 (and any other privacy law that applies to you) makes you responsible for it. You agree that:
- Use it only to run the event. You may use attendee information only to deliver, manage, and provide support for the specific event they signed up for — admission, communications about that event, and your legal obligations as the host. You will not use it for an unrelated purpose.
- No spam beyond consent. You will not add attendees to a newsletter or send them marketing or promotional messages unless they have given you the consent the law requires (including Canada's anti-spam law, CASL). Buying a ticket is not consent to be marketed to.
- Honour access and deletion requests. If an attendee asks you to access, correct, or delete the personal information you hold about them, you will respond as the law requires. If the request concerns data Festro controls, point them to Festro's Privacy Officer (Section 6).
- Keep only what you need, for as long as you need it. Once the event is over and your legal and accounting obligations are met, securely destroy or anonymize the attendee data you exported.
- Report incidents. If you suffer a confidentiality incident affecting attendee data you received through Festro, you will notify Festro promptly (Section 4) and meet your own legal notification duties.
- Don't re-share it. You will not sell, rent, or disclose attendee data to a third party except a service provider acting on your behalf under an appropriate contract, or as the law requires.
- Transfers outside Quebec. If you move attendee data outside Quebec, you are responsible for assessing that it will receive adequate protection, as Law 25 requires.
These duties are yours alone as controller; Festro meets its own duties separately for the copy it holds. If you use Festro to collect extra information from attendees, you are responsible for telling them why, and for having a lawful basis to do so.
Security and confidentiality incidents
Each of us must protect the attendee data it holds with security measures appropriate to its sensitivity, as Law 25 requires. On Festro's side, that includes encryption in transit and at rest, access controls and least-privilege access for our team, secret management for keys, and platform protections such as App Check and rate limiting. We rely on Stripe for PCI-compliant card handling so that raw card numbers never reach Festro or your account.
On your side, you are expected to keep any exported guest list secure — limit who can see it, protect the devices and accounts that hold it, don't email it around or leave it on shared drives, and delete it when the event is done. The door check-in tools in Festro let your staff scan tickets without downloading the full list, which is the safer default.
If either of us has a confidentiality incident (a breach, loss, or unauthorized access or use) affecting shared attendee data, the affected party will notify the other promptly so we can each meet our own duties. Where an incident creates a risk of serious injury, Festro will notify the Commission d'accès à l'information du Québec (CAI) and affected individuals as the law requires for the data it controls, and keep a register of incidents; you must do the same for the data you control. Tell us about an incident through the Privacy Officer contact in Section 6.
Festro's sub-processors
To run the platform, Festro uses a small number of trusted service providers (sub-processors) that may process personal information on our behalf. The main ones are:
- Stripe — payment processing and payouts for paid tickets;
- Google Cloud / Firebase — hosting, databases, push notifications, and analytics;
- Twilio — SMS for phone-number verification;
- Postmark — transactional email (confirmations, reminders, receipts).
We hold each of these providers to appropriate data-protection terms and remain accountable for the data we entrust to them. Several operate in the United States or other countries; before transferring personal information outside Quebec, Festro assesses whether it will receive adequate protection, as Law 25 requires. The current list and details are maintained in our Privacy policy.
These are Festro's sub-processors, not yours. If you bring your own tools to handle attendee data (for example your own email or CRM tool), they are your sub-processors and your responsibility as an independent controller — see Section 3.
Attendee rights and the Privacy Officer
Attendees have rights over their personal information — including the right to access it, correct it, withdraw consent, and ask for deletion — under Quebec Law 25 and other privacy laws. Because you and Festro are independent controllers, each of us answers for the data it holds: an attendee can come to either of us, and we will handle requests about the data we control and point them to the other where needed.
Festro has designated a Person in charge of the protection of personal information (our Privacy Officer), as required by Law 25 — the same Privacy Officer named in our Privacy policy. For privacy questions, to report a confidentiality incident, or to raise a data-sharing concern, contact us through our contact form.
If an individual is not satisfied with how a request was handled, Quebec residents may contact the Commission d'accès à l'information du Québec (CAI) at www.cai.gouv.qc.ca, and other Canadians may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
Questions
Questions about how attendee data is shared or about your responsibilities as a controller? Reach our Privacy Officer through our contact form, or email [email protected]. For the full picture of how Festro handles personal information, see our Privacy policy; for fees and payouts, see the Organizer payments agreement.