Skip to content

Your data & hosting

Festivals trust Festinato with artist contracts, volunteer rosters, payout details and attendee push tokens. This page explains — in plain language — where that data lives, how it's protected, and how you get it out again.

Hosted in Switzerland

Everything Festinato runs on — the back-office, the portals, the websites, the databases, the uploaded files and the backups — is hosted by Infomaniak in data centres in Switzerland. There is no Hetzner, no Cloudflare, no AWS in the serving path: your festival's data does not leave Swiss infrastructure to be stored or served.

Infomaniak is a Swiss company, so hosting is governed by Swiss law and the revised Swiss Federal Act on Data Protection (revFADP). For festivals with EU participants, Festinato is also operated to satisfy the GDPR — see the privacy notice and the DPA.

The only data that leaves Switzerland is what technically must:

  • Push notifications are delivered through Apple (iOS) and Google (Android) — that's how phones receive push. Only the anonymous device token and the message you composed travel; both transfers are covered by EU–US safeguards.
  • Payments (subscriptions, box office, donations) are processed by the payment provider's own secure checkout — card numbers and bank details never touch Festinato's systems at all.

One festival, one database

Every festival on the platform has its own database. Your artists, volunteers and finances are never in the same database as another festival's — there is no shared table a bug or a query could leak across. The mobile apps, the portal and the Ops app follow the same rule: everything is scoped to one festival at a time.

How it's protected

  • Encrypted in transit — every connection uses TLS ("https"), from an attendee's phone to the back-office.
  • Encrypted at rest — databases, uploaded files and backups sit on encrypted storage.
  • Daily backups — taken automatically and kept for 30 days, stored in Switzerland like everything else.
  • Two-factor authentication — enforced on back-office admin accounts by default, and available for every other role. Artists, volunteers and venue coordinators sign in with single-use magic links, so there are no participant passwords to leak in the first place.
  • Access reviews — who can reach production systems is reviewed quarterly.

Getting your data out

Your data stays yours:

  • Export any time — editions, artists, venues, schedule, news, sponsors, fundraising and volunteers, from the back-office. See Configuration → Data export.
  • After cancellation — the back-office goes read-only and your data is kept for 90 days so you can export or change your mind. After that, the database, uploads and backups are permanently deleted. See Pricing → Stopping or downgrading.
  • Immediate deletion — on request to privacy@festinato.app.

Questions

For anything data-protection related — a data-subject request from an artist, a question from your board, a security concern — mail privacy@festinato.app. The full legal texts are the privacy notice and the Data Processing Agreement on the main site.