AI at Discontinue – Transparency
How we use artificial intelligence at Discontinue
As of: 2 September 2026
Discontinue is an AI-assisted operations platform for hotels. So that you can always understand how and where we use artificial intelligence (AI), we have put together this page. Transparency matters to us – and it is also required under the European AI Act (EU 2024/1689).
Which AI models we use
We currently use the Claude models from Anthropic via their API (contracting party for the EEA: Anthropic Ireland, Limited; the processing runs in the USA at Anthropic PBC). In addition, our platform may offer two AI processing routes (agent stacks) between which your hotel chooses: the processing route via the AI provider (currently Anthropic) and a self-hosted agent stack, on which the agents run on self-operated proprietary and open-source components in our own environment in the EU and model access takes place via the EU endpoint of an AI gateway (Eden AI, France). Which model providers can be used on the self-hosted stack is set out exhaustively in the register "Enabled model providers of the self-hosted agent stack" in our Sub-Processor List — with the legal entity, place of processing and undertakings of each provider. Every new provider is reviewed in advance and announced as a sub-processor before it is put into use.
Selection levels instead of model names. In the platform, you choose between selection levels for your agents and functions — performance classes that we name (e.g. by speed or capability) and whose prices we publish in our price overview. The name of a level tells you what it can do, not which model sits behind it — we can switch that at any time, as long as the level continues to serve its purpose and its safeguards remain the same. Which providers (legal entities) sit behind a level you can always see in the Sub-Processor List. Levels carrying an EU designation are assigned exclusively to providers that process your data exclusively in the EU.
How we use AI in the platform
AI helps you get to the analyses and workflows you need more quickly. Specifically, we use AI for four things:
- Reading data and acting: The Platform provides granular, configurable tools. By default the AI accesses your data from the connected systems (e.g. a property management system) read-only; write operations only after approval or explicit opt-in. Which tools an agent uses is determined by your configuration – we limit each agent to what its task requires.
- Structuring reports: From your data, the AI shapes clearly presented reports.
- Composing messages: Your agents compose their communications (e.g. by email or via chat/messaging services you have connected) in natural language.
- Configuring agents: You set up your reports and agents in natural language – the AI helps translate your description into a working configuration.
Important: the actual metrics (e.g. ADR, RevPAR, occupancy) are not “estimated” by the AI, but calculated deterministically in our KPI glossary – that is, according to fixed formulas in Python. The data values come from your connected source system (live data). The AI element lies in the structuring and wording, not in the figures themselves.
When the AI is involved – and when it is not: when you create something, the AI is involved; during a scheduled run it is not. When you set up or edit a report, the AI helps you do it; the scheduled run then simply executes the plan defined once – without AI and without any transfer to the AI provider. With agents, in chat and during validations, by contrast, the AI is involved in every run.
What our AI does NOT do
- No autonomous decisions in the standard configuration. In the standard configuration, the AI does not decide anything on its own about your operation, your guests or your employees; every write operation passes through a human approval. Where you expressly activate opt-in operation for an individual agent, that agent executes its write operations without individual approval – within the permissions you have set and under your responsibility (see the next point).
- No unauthorised alteration of your data. You determine what an agent may do in the first place: every permission (scope) and every tool is set separately in the permissions of the respective agent. By default, all write operations go through a human approval (approval queue). The customer may expressly specify per agent (opt-in) that that agent’s write operations are executed without individual approval; scope and control remain limited by the permissions (scopes) defined by the customer, and the customer may revoke the opt-in at any time. Every operation remains fully logged.
- No automated decision-making about persons. In the standard configuration, no automated individual decision within the meaning of Art. 22 GDPR takes place: write operations pass through human approval. Where you expressly activate opt-in operation for an agent, you are responsible as controller for assessing whether that agent's outputs constitute a decision with legal or similarly significant effect and for meeting the requirements of Art. 22 GDPR.
- No training with your data. Your data is not used to train AI models (see the next section).
- No evaluation of persons. We do not offer any templates that evaluate, rank or “score” guests.
Your data also remains strictly separated from that of other hotels (tenant isolation).
Dynamic model routing – explained simply
Our platform can, in principle, address different AI models and select the most suitable one in each case. This keeps us technically flexible.
The routing always chooses only between the providers of the processing route that applies to you: on the processing route via the AI provider, currently Anthropic; on the self-hosted agent stack, exclusively the providers listed in the register "Enabled model providers of the self-hosted agent stack" — and, within the providers assigned to a selection level, dynamically per request by availability, price and speed; never both routes at the same time in one run. Should a further provider be added in future, we review it carefully beforehand – in particular with regard to data protection and the guarantees described below – and add it properly to our list of sub-processors before it is put into use. This may include locally or self-hosted models or other providers. A change of model or model version within a provider already listed is not a change of provider. Such a switch does not change your safeguards (no training with your data, limited storage or equivalent).
Where we offer the hotel a model selection, the hotel can decide for itself which selection level is used for its reports and agents; the price per level is shown before the selection is made. Levels carrying an EU designation are assigned exclusively to providers that process in the EU; if a level uses a provider that processes data outside the EU, we flag that at the point of selection, and the hotel can restrict its workspace to levels carrying an EU designation. The same safeguards and the same labelling of AI-generated content apply to every level.
Your data: no training, limited storage
- No-training guarantee: Your data is not used to train AI models.
- Limited storage: The model provider stores content from the builder, chat and validations for a maximum of 30 days as a rule – exclusively to detect abuse – and deletes it automatically afterwards. For agent runs via the AI provider, the session history of your agent remains stored in its managed agent environment until you delete the agent — we then delete it there. On the self-hosted agent stack, according to the published provider data policies the AI gateway (Eden AI) and the model providers listed in the register do not store inputs and outputs at all (zero data retention).
- Exceptions where flagged (processing route via the AI provider): If the provider's automated abuse detection flags a piece of content, inputs and outputs may be retained for up to 24 months and the associated classification scores for up to 7 years. Statutory retention obligations and retention for dispute resolution likewise remain unaffected.
- No special arrangement (processing route via the AI provider): We use the AI provider's standard business access; no special agreement on deviating retention periods (zero data retention) exists in that respect.
For the transmission to Anthropic in the USA — it arises only on the processing route via the AI provider — we rely on the legal safeguards under Art. 44 et seq. GDPR — EU Standard Contractual Clauses (SCCs) agreed as a precaution — and a Transfer Impact Assessment; details are set out in our Privacy Policy. On the self-hosted agent stack, for levels carrying an EU designation no third-country transfer takes place in the AI chain (gateway and model providers); the transport via our reverse proxy (see the Privacy Policy) remains unaffected. You can find details in our Privacy Policy and in the Data Processing Agreement (DPA).
How we mark AI outputs
So that you always recognise AI content as such, we mark it at every relevant point. We deliberately describe the principle here rather than the exact wording: wording changes with the interface, the labelling as such does not.
- Before you talk to an AI, we tell you. In the chat interfaces — report generator, agent onboarding, agent editing — the notice is permanently visible at the input field, before your first input and throughout the conversation.
- AI-assisted outputs carry a visible notice. This applies to reports, whether by email, via a connected chat service or as a file, and to messages from agents. The notice states that AI was involved and asks you to verify important information.
- Previews of configurations arise in the chat window, which carries the labelling permanently in any case; they are therefore recognisable as AI-generated in context.
- Where the format allows, we additionally label machine-readably. In HTML outputs, the generated content carries a corresponding marking in the source.
One point that often causes confusion: the blueprint of a report comes about in conversation with the AI — the run itself then proceeds deterministically, without an AI model being involved. A scheduled report is therefore the result of an AI-created configuration and not of an AI run. Both are stated that way in our Privacy Policy: scheduled report runs transmit no data to the AI provider.
How you can inspect AI runs
For every run, we record what happened. For AI runs this is the complete trace: which data was read, which tools were called with which parameters, which model was used and how the result came about. For scheduled report runs we record the trigger, the time, the data sources, the result, the deliveries and any errors — there is no system prompt and no model there, because no model is involved. We keep the tracing as our own record in our own environment in the EU (Frankfurt) — on the infrastructure of our hosting provider Oracle; we do not engage a separate tracing provider. Agent execution itself runs depending on the processing route you select: on the self-hosted agent stack in our own environment, on the processing route via the AI provider in its managed agent environment — there, the provider keeps a session history for each agent, which remains in place until you delete the agent (we then take care of the deletion at the provider).
For agent runs, the run history can be inspected in the Platform (trigger, tool calls, result, consumption, deliveries, errors). Internal components — system prompts, tool definitions and orchestration steps — are not covered by this (GTC Section 14a(3)). We retain these traces for 90 days, after which they are deleted.
Agent memory: for agents, the results of previous runs are drawn on again in the next run – via our own traces and, on the processing route via the AI provider, via the session history of your agent kept there – so that the agent can check and improve its execution; this happens exclusively within your own tenant and the same agent. Our own traces are deleted after 90 days; the session history at the AI provider remains in place until you delete the agent.
AI can make mistakes – and here is how you report them
AI systems can be wrong, especially in structuring and wording. Please verify critical figures before basing important decisions on them. You recognise AI content by the markings described above, e.g. in the report footer or by the marking of agent messages.
Did you notice something? Feel free to report it to us – we follow up on every notice:
- Email: [email protected]
Data protection
How we handle personal data is explained in our Privacy Policy and the Data Processing Agreement (DPA). We answer questions about data protection at:
- Data protection: [email protected]
Contact
discontinue.dev MAS GmbH
Bruno-Marek-Allee 5, 1020 Vienna, Austria
Managing Director: Stefan Starflinger
- General enquiries: [email protected]
- Data protection: [email protected]
This page provides information about our use of AI within the meaning of the transparency obligations under Art. 50 of the AI Act (EU 2024/1689).
discontinue.dev MAS GmbH · As of: 2 September 2026