Discontinue
Legal ·Sub-Processor List · Version 9.10 · Effective: 2 September 2026

Sub-Processor List

Annex 1 to the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

discontinue.dev MAS GmbH · AI operations platform for hotels

Version 9.10 · As of: 2 September 2026

This list names the sub-processors engaged by discontinue.dev for the hotel data processed on behalf of the hotel customers from the connected systems (e.g. a property management system). It is a binding Annex 1 to the DPA.

Preliminary Remarks

(1) The Controller (hotel) grants a general authorisation pursuant to Art. 28(2) GDPR for the use of the sub-processors named below.

(2) discontinue.dev informs the Controller of any intended change regarding the addition, replacement or removal of sub-processors at least 14 days before it takes effect by email.

(3) The Controller may object for important data protection reasons within this period; details are governed by DPA Section 8(2). The objection must be made in text form and substantiated with specific reasons within the period; a mere preference for a different provider, general reservations unrelated to the specific processing, or purely commercial considerations do not suffice. Whether an important data protection reason exists and whether the level of protection is maintained is assessed under DPA Section 8(2) on the facts of the individual case. Upon a valid objection the parties endeavour to find an amicable solution; failing this, an extraordinary right of termination exists.

(4) All sub-processors are contractually obliged (by a data processing agreement or equivalent arrangement) to comply with the requirements of Art. 28 GDPR. In the case of third-country transfers, a valid basis pursuant to Art. 44 et seq. GDPR is ensured before use — an adequacy decision under Art. 45 or appropriate safeguards under Art. 46 GDPR; a Transfer Impact Assessment is carried out to the extent required by the basis chosen and the circumstances of the transfer (DPA Section 8(3)). The basis applicable to each transfer is set out in the "Transfer basis" column of the main table.

(5) This list is the authoritative source for the AI providers used. GTC Section 4(1) refers to it; the GTC themselves name no AI providers. For the self-hosted agent stack, this includes the register "Enabled model providers of the self-hosted agent stack" (below); it forms part of this Annex 1. For every AI provider listed here, the no-training undertaking as well as the applicable standard retention period and its exceptions are set out (see Note 4). An AI provider is added only after those undertakings have been given — contractually or through documented provider commitments (published provider documentation or product-side configuration forming part of the documented instructions) — and — where processing takes place in a third country — a valid transfer basis under Art. 44 et seq. GDPR is in place (see Note 3 and DPA Section 8(3)).

(6) Model and stack selection; conditionally engaged sub-processors. Where discontinue.dev offers the Controller a model or stack selection under GTC Section 4(10), Note 4 indicates which selection levels or AI processing routes (agent stacks) the respective AI provider is assigned to. Sub-processors marked as conditionally engaged in the main table are engaged only where the relevant AI processing route applies to the use in question (DPA Section 8(1a)); the processing routes are alternatives — in no individual AI run are the sub-processors of both routes engaged at the same time (Note 9). The Controller's choice of a level or of a processing route is not a change within the meaning of paragraph (2) and triggers no right of objection, because no additional legal entity is involved. Selection levels carrying an EU designation (GTC Section 4(10)) are assigned exclusively to the model providers listed in the register with an EU designation; within the providers assigned to a level, discontinue.dev selects dynamically per request by availability, price and speed (model routing between the approved recipients, DPA Section 5(8)) — a provider outside the register is not used in the process. Where a model or stack selection is offered, the Controller may restrict the selection levels and processing routes permitted for its workspace and thereby control which of the AI providers listed here are used for it. To the extent no selection is offered, discontinue.dev determines the providers used in accordance with GTC Section 4(8); the right of objection under paragraph (3) remains unaffected in every case.

Distinction: Sub-Processor vs. Software Component

What is a sub-processor? Only a party that processes personal hotel/guest data on behalf of discontinue.dev and to which processing is (partly) outsourced qualifies as a sub-processor. The following do not qualify as sub-processors:

  • self-hosted software components where no data is transmitted to a further third party not already named in this list — this includes the component that provides the consent banner (see Note 2),
  • services in which discontinue.dev acts as an independent controller and without hotel/guest data (e.g. Google Analytics, see Note 2), and
  • service providers that process no hotel/guest data from the connected systems but exclusively data arising from the contractual and billing relationship between discontinue.dev and the customer (see the section “Further service providers outside the processing of hotel/guest data on behalf”).

Main Table of Sub-Processors

Sub-Processor Service Data processed Location Transfer basis
Oracle Cloud Infrastructure (Oracle Corporation) — Role: sub-processor (processing on behalf of the Controller) Hosting, database, object storage, backup, email delivery of reports and notifications All platform data processed on behalf, including data retrieved from the connected systems (reservations, guest names) and, for the email delivery, the recipient addresses and the contents of the reports/notifications sent (may contain guest names if so configured). The account data of the platform users, which Oracle hosts outside this processing on behalf, is shown separately in the section “Further service providers outside the processing of hotel/guest data on behalf” Frankfurt, Germany (EU) Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs pursuant to the Oracle Cloud Services Agreement incl. DPA
Anthropic Ireland, Limited (contracting party and direct sub-processor) — conditionally engaged: only where the processing route via the AI provider applies (Note 9) AI model (Claude API) and managed agent environment for agent runs (agent harness, orchestration, session management and session execution environment) Content from builder sessions, agent runs, chat and validations – no transfer for scheduled report runs; may include reservation data incl. guest names, salutation, email, stay data and special requests as well as, for agents, run traces reused across runs; for agent runs additionally the session history (event history) kept for each agent as well as any task resources (working files, memory stores) Contracting party: Dublin, Ireland (EU). The processing of the AI requests and the managed agent environment run in the USA at Anthropic PBC and further group/infrastructure companies as sub-processors of the Irish entity (chain: Note 6) Direct flow to the Irish contracting entity: in that respect, no third-country transfer. Third-country element through the onward transfer to the USA within the Anthropic chain — this is carried out by Anthropic Ireland as data exporter, itself directly bound by Art. 44 et seq. GDPR, with contractual flow-down of the protection obligations in the chain (Anthropic DPA Section C; Anthropic remains liable); confirmation of the Art. 46 instrument specifically used by Anthropic Ireland for the US chain has been requested from the provider (see TIA Step 2). As a precaution, the SCCs incorporated in the Anthropic DPA are deemed executed (“deemed executed”, to the extent required; for hotel data Module 3 — processor-to-processor; Art. 46(2)(c) GDPR, Implementing Decision (EU) 2021/914) + TIA; no-training contractually agreed (Commercial Terms); retention periods according to the provider's published retention documentation (verified 29 July 2026): stateless functions max. 30 days (abuse detection; exceptions where flagged: up to 24 months / classification scores up to 7 years); session history and task resources of the managed agent environment exempt from the standard retention period — stored until deleted by discontinue.dev, which takes place when the agent is deleted; see TIA
Eden AI SAS — conditionally engaged: only where the self-hosted agent stack is selected (Note 9) AI gateway (EU endpoint): forwarding of the AI requests of the self-hosted agent stack to the model providers listed in the register "Enabled model providers of the self-hosted agent stack" Content from builder sessions, agent runs, chat and validations of the self-hosted agent stack – no transfer for scheduled report runs; may include reservation data incl. guest names, salutation, email, stay data and special requests as well as, for agents, run traces reused across runs. According to the provider's documentation, inputs and outputs are not stored (zero data retention); limited technical metadata remains for billing and security Villeurbanne, France (EU); for selection levels carrying an EU designation, processing via the EU endpoint api.eu.edenai.run/v3; according to the provider's documentation, processing, hosting and routing of that endpoint take place exclusively in the EU, with no fallback to the global endpoint. At present, only selection levels carrying an EU designation are assigned (register); a model provider without an EU designation is used only after inclusion in the register and notification under DPA Section 8(2) Processing in the EU, no ongoing third-country transfer on this leg; Eden DPA (Art. 28 GDPR) with a no-training undertaking and transient processing (no storage of inputs and outputs). For the case — not envisaged according to the provider's documentation — of processing in a third country, a valid basis under Art. 44 et seq. GDPR is put in place before use (DPA Section 8(3)). For the downstream model providers, the legal entity, chain, place of processing, undertakings and transfer basis per provider are set out in the register "Enabled model providers of the self-hosted agent stack"
Cloudflare, Inc. — role: sub-processor (transport) Reverse proxy, TLS termination and protection against attacks and overload (WAF/DDoS) for the website, the platform and the API Connection and request data (IP address, time, requested address, user agent, status code). The content of requests and responses — which may contain hotel data including guest names — is processed in transit but not stored at the edge: dynamic responses of the platform are not cached (see Note 8) Global edge network; contracting party established in the USA Adequacy decision under Art. 45 GDPR (EU-US Data Privacy Framework; certification verified on 29 July 2026). In addition, the Cloudflare DPA incorporates the EU Standard Contractual Clauses as a fallback should the decision cease to apply (DPA Section 8(3)). No transfer impact assessment is required on this basis

Register: Enabled Model Providers of the Self-Hosted Agent Stack

For the self-hosted agent stack (GTC Section 2), execution and orchestration run in the environment controlled by discontinue.dev (Note 1 and Note 3); session histories remain there, and no agent environment managed by the AI provider is used. Model access takes place via the AI gateway (Eden AI SAS, main table), which forwards the requests to the model providers listed below; for selection levels carrying an EU designation, exclusively via its EU endpoint (GTC Section 2). The model providers are sub-processors of Eden AI SAS. Which model providers may be used in the process is set out exhaustively in this register; it forms part of this Annex 1. Within the providers assigned to a selection level, discontinue.dev selects dynamically per request by availability, price and speed (Preliminary Remarks, paragraph 6). A model provider is added only after its legal entity, place of processing, no-training and retention/deletion undertakings and — where relevant — its transfer basis have been reviewed and documented; the basis for this is the gateway's published provider data policies (training, zero data retention, retention per provider; as at 27 August 2026, evidence document) and the documentation of the respective provider. The addition of a new legal entity is notified in accordance with DPA Section 8(2) (14 days, right of objection). The EU designation (GTC Section 4(10)) is granted only to a provider whose legal entity processes personal data exclusively within the EU/EEA; mere "EU availability" of a model does not suffice. Where a provider's legal entity processes personal data outside the EU/EEA or the transfer is subject to a third-country basis, this is set out here per provider. The content transmitted is the same as to the AI gateway (main table, Eden AI SAS row); for all providers below, inputs and outputs are, according to the provider data policies, not stored (zero data retention) and not used for training (no-training).

Model provider (legal entity) Chain and place of processing Undertakings Transfer basis EU designation
Amazon Web Services EMEA SARL (Luxembourg) — Amazon Bedrock Sub-processor of Eden AI SAS; processing in the AWS region eu-west-1 (Ireland). The models offered on Bedrock are operated by AWS; the respective model developer receives no data No-training; zero data retention (inputs and outputs are not stored) Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs under the AWS Data Processing Addendum; Amazon Web Services, Inc. additionally certified under the EU-US Data Privacy Framework yes
Google Cloud EMEA Limited (Dublin, Ireland) — Vertex AI Sub-processor of Eden AI SAS; processing in Google Cloud regions of the EU (EU multi-region) No-training; zero data retention Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs under the Google Cloud Data Processing Addendum; Google LLC additionally certified under the EU-US Data Privacy Framework yes
Microsoft Ireland Operations Limited (Dublin, Ireland) — Azure AI (EU Data Zone) Sub-processor of Eden AI SAS; processing in Azure regions of the EU (EU Data Zone) No-training; zero data retention Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs under the Microsoft Products and Services Data Protection Addendum; Microsoft Corporation additionally certified under the EU-US Data Privacy Framework yes
Mistral AI SAS (Paris, France) Sub-processor of Eden AI SAS; processing in the EU (hosting by Mistral AI in the EU) No-training; zero data retention Processing in the EU, no third-country transfer yes
OVH SAS (Roubaix, France) — OVHcloud AI Endpoints Sub-processor of Eden AI SAS; processing in OVHcloud data centres in France/EU No-training; zero data retention Processing in the EU, no third-country transfer yes
Scaleway SAS (Paris, France) — Generative APIs Sub-processor of Eden AI SAS; processing in Scaleway data centres in France (Paris)/EU No-training; zero data retention Processing in the EU, no third-country transfer yes
Nebius B.V. (Amsterdam, Netherlands) — Nebius AI Studio Sub-processor of Eden AI SAS; processing in Nebius data centres in the EU (EU-region routing of the AI gateway) No-training; zero data retention Processing in the EU, no third-country transfer yes
TensorX Ltd. (Dublin, Ireland) Sub-processor of Eden AI SAS; processing in Dublin and Helsinki (EU) in ephemeral execution environments; hosting sub-processors of TensorX per its published list (EU regions) No-training (contractually, TensorX Data Processing Agreement, as of July 2026); zero data retention (prompts and completions are not stored) Processing in the EU, no ongoing third-country transfer; for TensorX sub-processors with a third-country element (support and email services, not the inference) SCCs under the TensorX DPA yes
Databricks, Inc. (San Francisco, USA) — Model Serving Sub-processor of Eden AI SAS; processing in Databricks regions of the EU (EU-region routing of the AI gateway) No-training; zero data retention Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs under the Databricks Data Processing Addendum yes

Further Service Providers Outside the Processing of Hotel/Guest Data on Behalf

The service providers listed below are not sub-processors under this DPA: they process no hotel/guest data from the connected systems, but exclusively data arising from the contractual and billing relationship between discontinue.dev and the customer, or technical operating data of the platform. They are shown here for completeness and for a clear delineation of roles.

Service provider Service Data processed Location Role / transfer basis
Stripe Payments Europe Ltd. Billing / payment processing Exclusively billing data (platform account, invoice line items, payment method); no guest data or data from the connected systems Dublin, Ireland (EU); group affiliation with Stripe Inc. (USA) Processor for discontinue.dev with regard to the billing data; for the payment processing itself, Stripe is in that respect partly an independent controller. Primary processing in the EU; SCCs for group access; Stripe DPA
Oracle Cloud Infrastructure (Oracle Corporation) Hosting of the account data of the platform users Account data of the platform users; no hotel/guest data from the connected systems Frankfurt, Germany (EU) Processor for discontinue.dev, which is the independent controller in this respect (second sphere of the Oracle row in the main table). Processing in the EU, no ongoing third-country transfer; for any group/support access from third countries, SCCs pursuant to the Oracle Cloud Services Agreement incl. DPA
Functional Software, Inc. d/b/a Sentry Error and operations monitoring of the website and the platform Two forms. (1) Status record on every page view (health diagnostics): a randomly generated session identifier that is not stored on the terminal equipment, the time, the software release in use, the environment and the browser identifier (user agent). (2) Error event data where an error occurs: Technical error data (error type or class, call sequence in the program code including the source code excerpt of the affected location, fixed diagnostic labels authored in the program code), timestamp, tenant and workspace identifier (platform only) and identifier of the triggering operation. Hotel and guest data are technically excluded by an allow-list of the fields transmitted: error messages are removed before transmission unless they are diagnostic labels fixed as literals in the program code (enforced by an automated test); request payloads and user data are removed, and no recording of screen content takes place. In addition, the transmission of default personal fields is disabled (send_default_pii = false; in particular no IP address as a data field), no usage trail (breadcrumbs) is recorded (max_breadcrumbs = 0), and the sample rates for session and error replay are each set to 0 (configuration verified on 1 September 2026). Retention of event data at the provider: 90 days (standard), thereafter automatic deletion Storage in the EU (European Union region); contracting party established in the USA Processor for discontinue.dev, which is the independent controller in this respect. Adequacy decision pursuant to Art. 45 GDPR: Functional Software, Inc. is certified under the EU-US Data Privacy Framework (certification, legal entity and coverage of non-HR data verified on 29 July 2026). In addition, the EU Standard Contractual Clauses under the Sentry DPA (Module 2 – controller-to-processor) apply as a fallback; no transfer impact assessment is required on this basis

Notes

  1. Run tracing in the provider’s own infrastructure; agent execution per processing route (no additional sub-processor). discontinue.dev keeps the internal AI/run tracing as its own record in its own environment at Oracle Cloud Infrastructure (Frankfurt, EU); the run traces and the deterministic run records remain there. Agent execution and orchestration run depending on the processing route (Note 9): on the self-hosted agent stack, in the environment controlled by discontinue.dev; on the processing route via the AI provider, in that provider's managed agent environment — there, the session history (event history) and any task resources are stored for each agent (main table and Note 4). Apart from the providers listed, no further, separate provider is engaged for this purpose; no additional sub-processor arises in this respect (see Note 3). Run traces may contain content from reports and runs including guest names and are subject to the retention rules in DPA Section 10. Cross-run reuse for agents: for agents, the results of previous runs are drawn on again in subsequent runs — via the run trace and, on the processing route via the AI provider, via the session history kept there — in order to validate and improve execution; in doing so, this content is again processed with AI support and, to that extent, transferred to the AI provider of the selected processing route — on the self-hosted agent stack via the AI gateway to a model provider listed in the register. Reuse takes place exclusively within the same tenant and the same agent; the provider's own run traces are retained for 90 days, while the session history exists until the agent is deleted.

  2. Google Analytics and consent management (not a DPA sub-processor). Insofar as discontinue.dev uses Google Analytics 4 to analyse the use of its own website and platform, discontinue.dev acts in this respect as an independent controller (not as a processor of the hotel). In doing so, Google processes no guest data or data from the connected systems, but measures exclusively the usage behaviour of platform users/website visitors. Google is therefore not a sub-processor under this DPA. The consent banner is provided by an open-source component self-hosted by discontinue.dev; the consent decision remains exclusively in the data subject's browser and is not transmitted to any third party. No service provider is engaged in this respect and no sub-processor arises (see the distinction above, first bullet). These notes serve as clarification; the processing is governed by the Privacy Policy (Google: consent, EU-US Data Privacy Framework + SCCs).

  3. Dynamic model routing / change of the framework. If a further AI provider is used in the future, it is reviewed in advance against no-training, limited retention or deletability at any time, or equivalent guarantees, and the existence of a valid transfer basis under Art. 44 et seq. GDPR (an adequacy decision or appropriate safeguards). Only thereafter is it added to this list as a sub-processor and announced to the Controllers at least 14 days before it takes effect. This applies accordingly to other API providers as well as to a change of the agentic/orchestration framework, insofar as a further legal entity processes personal data in the process. Where a model, a framework or another operating component — such as run tracing — is run exclusively within the environment controlled by discontinue.dev at the hosting sub-processor already listed (self-hosted), no additional legal entity is engaged for that purpose; no new sub-processor then arises, and no notification under paragraph (2) of the Preliminary Remarks is triggered by it. Such a step is a technical change under GTC Section 4(8). The change is an ordinary operational measure; the Controller’s data-protection right to object remains unaffected, and no extraordinary right of termination arises as a result; the rights of termination under GTC Section 16(2) and DPA Section 8(2) remain unaffected.

  4. AI providers: no-training, retention, model and stack selection. A contractual no-training undertaking and a limited retention period, or equivalent guarantees, apply to every AI provider used; the periods and exceptions applicable to each provider and — where a model or stack selection under GTC Section 4(10) is offered — the selection levels or AI processing routes assigned to it are set out below.

    • Processing route via the AI provider (Anthropic): the contracting party and direct sub-processor is Anthropic Ireland, Limited (Dublin, Ireland); the processing of the AI requests and the managed agent environment run in the USA at Anthropic PBC and further group/infrastructure companies as its sub-processors (Note 6). On this processing route, Anthropic serves all functions and, where a model selection is offered, all selection levels. Anthropic has contractually agreed in the Commercial Terms that content processed via the API is not used to train the models (“Anthropic may not train models on Customer Content from Services.”); for the content transmitted in the stateless functions (builder, chat, validations) the following applies according to the provider's published retention documentation (verified 29 July 2026): max. 30 days (abuse detection); exceptions where flagged: up to 24 months / classification scores up to 7 years. After expiry of the period the content is automatically deleted; statutory retention obligations and retention for dispute resolution under Section H of the Anthropic DPA remain unaffected. For agent runs, discontinue.dev uses the provider's managed agent environment (agent harness, orchestration, session management, session execution environment): according to the provider's documentation, the session history kept for each agent and any task resources are stateful, exempt from the standard retention period and from zero-data-retention arrangements, and exist until discontinue.dev deletes them; deletion takes place when the Controller deletes the agent, at the latest in accordance with DPA Section 10. Deleting a session does not automatically cover separately kept task resources; discontinue.dev deletes these via separate deletion routines. discontinue.dev uses Anthropic’s standard business access; no special agreement on deviating retention periods (zero data retention) exists in that respect. The direct flow to the Irish contracting entity is not a third-country transfer; the third-country element arises through the onward transfer within the Anthropic chain to the USA. Its data exporter is Anthropic Ireland — itself directly bound by Art. 44 et seq. GDPR; the protection obligations are contractually passed down to the sub-processors under Anthropic DPA Section C (Anthropic remains liable); confirmation of the Art. 46 instrument specifically used by Anthropic Ireland for the US chain has been requested from the provider. As a precaution — to the extent that the transmission would in an individual case qualify as a direct transfer by discontinue.dev to the USA — the SCCs incorporated in the Anthropic DPA are deemed executed (“deemed executed”, to the extent required; for hotel data Module 3 — processor-to-processor), together with the Transfer Impact Assessment; a DPF certification of Anthropic does not exist as verified on 5 July 2026 (dataprivacyframework.gov; see the TIA note and the evidence document).
    • Self-hosted agent stack (Eden AI SAS + register): model access takes place via the AI gateway; for selection levels carrying an EU designation, exclusively via its EU endpoint (api.eu.edenai.run/v3), which according to the provider's documentation forwards exclusively to providers cleared for processing in the EU and does not fall back to the global endpoint. According to the provider's documentation, Eden AI does not store the transmitted inputs and outputs (zero data retention; limited technical metadata remains for billing and security) and does not use the data for training (no-training); the basis is the Eden DPA (Art. 28 GDPR). Which model providers may be used and which undertakings, places of processing, transfer bases and EU designations apply per provider is set out exhaustively in the register "Enabled model providers of the self-hosted agent stack". Selection levels carrying an EU designation are assigned exclusively to providers with an EU designation; within the assigned providers, routing takes place dynamically per request (Preliminary Remarks, paragraph 6). For all providers in the register, no-training and zero data retention apply according to the gateway's provider data policies (as at 27 August 2026); no standard retention period exists there.
  5. Transfer Impact Assessment (USA). For the onward transfer to the USA within the Anthropic chain (contracting party: Anthropic Ireland, Limited), a Transfer Impact Assessment (TIA) pursuant to “Schrems II” (CJEU C-311/18) is in place. It can be requested at [email protected].

  6. Further sub-processors of the listed providers (the chain). Each of the sub-processors named in the main table engages sub-processors of its own. The authoritative and always current source is the list maintained by the respective provider; where it is published, it is named below. discontinue.dev makes the information required for that purpose available to the Controller on request and passes on any notified changes without undue delay (DPA Section 8(2)). Last reviewed: 29 July 2026.

    • Anthropic (chain): the contracting party is Anthropic Ireland, Limited; processing takes place at Anthropic, PBC and AI Infrastructure OpCo, LLC (USA) as well as further group/infrastructure companies as its sub-processors; the group entities with access to customer data and the further sub-processors are published at trust.anthropic.com (FAQ and sub-processor list; retrieved 30 July 2026).
    • Eden AI SAS: published overview of the models and model providers available via the gateway at app.edenai.run/models as well as the provider data policies (training, zero data retention, retention per provider) at www.edenai.co/docs/v3/data-governance/provider-data-policies; for use by discontinue.dev, only the register "Enabled model providers of the self-hosted agent stack" of this Annex is authoritative. The model providers listed there are sub-processors of Eden AI SAS; their own chains follow from the lists each publishes (e.g. TensorX Ltd.: tensorx.ai/sub-processors) and are passed on upon request.
    • Oracle Cloud Infrastructure: the group and third-party service providers engaged follow from the Oracle DPA (Data Processing Agreement for Oracle Cloud Services, in Evidenz/Oracle-DPA_2026-07/); the current list is obtained from Oracle and passed on upon request.
    • Cloudflare, Inc.: published list at www.cloudflare.com/gdpr/subprocessors/.
  7. Support and group access at Oracle. According to the contractual and provider documentation reviewed as at 26 July 2026, support and group access at Oracle is limited to the EU; no third-country transfer takes place in this respect. The Standard Contractual Clauses shown in the respective rows remain in place as a precaution. For the listed providers’ own chains, see Note 6.

  8. The two third-country transfers differ fundamentally. At the level of the sub-processors engaged directly, there are two transfers to the USA, and they are not comparable. At Anthropic, content is processed substantively — the model reads it in order to respond — the transfer takes place as an onward transfer within the Anthropic chain (contracting party: Anthropic Ireland, Limited), relies on Standard Contractual Clauses and is backed by a transfer impact assessment; it arises only where the processing route via the AI provider applies (Note 9). At Cloudflare, the same content is merely transported: Cloudflare terminates the transport encryption, inspects the request as part of a technical security check (pattern matching against attacks) and passes it on — no substantive or AI-supported evaluation of the content takes place, and nothing is stored at the edge; dynamic responses of the platform are not cached. That transfer relies on an adequacy decision and therefore requires no transfer impact assessment. Where the other documents refer to the ongoing third-country transfer, they mean the substantive processing at Anthropic.

  9. Alternativity of the AI processing routes. The sub-processors marked as conditionally engaged in the main table (Anthropic Ireland, Limited; Eden AI SAS together with the model providers listed in the register) are engaged in the alternative: what is decisive is the AI processing route applicable to the use in question — the Controller makes the selection where a stack selection is offered (GTC Section 4(10); DPA Section 8(1a)); where no stack selection is offered, the processing route via the AI provider is used. In no individual AI run are the sub-processors of both routes engaged at the same time. The guarantees set out for each route apply to that route only: The undertakings of Eden AI and of the register's model providers (EU processing, zero data retention, no-training) do not apply to the processing route via Anthropic; conversely, the third-country transfer to Anthropic described in Note 8 does not arise on the self-hosted agent stack — for selection levels carrying an EU designation, the chain used there (AI gateway and model providers) processes exclusively in the EU (see the register); the transport route via Cloudflare described in Note 8 remains unaffected by this and exists on both routes. The AI provider's managed agent environment is used only on the processing route via the AI provider; on the self-hosted agent stack, execution and orchestration run in the environment controlled by discontinue.dev. A scheduled report run triggers no AI processing on either route.

For questions or to request further documents (DPA, TIA, TOMs): [email protected]

discontinue.dev MAS GmbH · [email protected] · As of: 2 September 2026

Sub-Processor List · Version 9.10 · Effective: 2 September 2026 · discontinue.dev MAS GmbH
Discontinue

Chat, reports, and AI agents for hotels.

Login Request access Documentation Contact Pricing Privacy Legal Notice AI Transparency Sub-processors