Discontinue
Legal ·Privacy Policy · Effective: 3 September 2026

Privacy Policy

discontinue.dev MAS GmbH
As of: 3 September 2026

This Privacy Policy applies to our entire online offering: Part A for visiting the discontinue.dev website, Part B for using the logged-in “Discontinue” platform. Part C contains the provisions applicable to both parts (your rights, complaints, amendments). The specific cookies set and their retention periods can be found in the cookie tables in Section A2 (website) and Section B7 (platform); you can change your choice at any time via the “Cookie settings” link.

1. Controller

discontinue.dev MAS GmbH, Bruno-Marek-Allee 5, 1020 Vienna, Austria. Managing Director: Stefan Starflinger (authorised to represent the company individually).

  • General enquiries: [email protected]
  • Contact for data protection enquiries: [email protected]

There is no statutory requirement to appoint a data protection officer; for all data protection matters you can reach us at [email protected].

Part A – Visiting the discontinue.dev website

A1. Data When Visiting the Website

When you access our website, our hosting provider processes technically necessary server log files:

  • truncated IP address
  • date and time of access
  • page accessed / referrer URL
  • browser type and operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stable and secure operation of the website). Retention period: 30 days, thereafter automatic deletion.

Error and operations monitoring (Sentry). To detect and remedy faults on the website, we use Sentry (Functional Software, Inc. d/b/a Sentry). On every page view a technical status record is transmitted: a randomly generated, non-recognisable session identifier, the time, the software release in use and your browser identifier (user agent); if an error occurs, technical error data in addition. No consent is required for this, because no information is stored on, or read from, your terminal equipment in the process (Section 165(3) TKG 2021 does not apply in this respect). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning and error-free operation of the website). Protective measures: the software module used transmits no additional personal details such as IP address, cookie contents or user identifiers; no usage trail (breadcrumbs) of your clicks and page changes is recorded; error messages are removed before transmission unless they are diagnostic labels fixed as literals in the program code; no recording of screen content (session replay) takes place. Storage takes place in the EU; the event data is retained there for 90 days. For the recipient and transfer basis, see A4.

A2. Cookies and Web Analytics

On our website we use two cookie categories:

  • Necessary – technically necessary cookies (session management, authentication, storage of your language selection) – required for operation and cannot be deselected; no consent is required for this (Section 165(3) TKG 2021).
  • Statistics – analytics cookies/technologies (Google Analytics 4) – exclusively after your consent.

The consent banner is provided via a consent manager hosted by ourselves. It runs exclusively on our own infrastructure, does not embed any third-party services and does not transmit any data to third parties. Your choice is stored exclusively locally in your browser (localStorage, keys with the prefix stcm.consent.) and is transmitted neither to us nor to third parties; we do not keep a server-side consent record. Prior to consent, no analytics cookies are set and no analytics data is transmitted: we use Google Consent Mode in basic mode, meaning Google Analytics is only loaded after your consent; before that, no communication with Google takes place at all.

Google Analytics 4 (GA4) – provider Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – helps us understand the use of our website. Processed data includes pseudonymous client/session identifiers, pages and events accessed, time spent, referrer, approximate location (based on the truncated IP), device, browser and operating system information. Protective measures: collection only after opt-in; IP addresses used only temporarily and not stored in plain text (IP anonymisation effective by default); no linking with Google advertising services for personalised advertising, “Google Signals” disabled; GA4 data retention limited to 14 months.

Legal basis: your consent (Art. 6(1)(a) GDPR, Section 165(3) TKG 2021). You can change or withdraw your consent at any time via the cookie settings – also by rejecting in the banner or via the browser add-on for disabling Google Analytics (https://tools.google.com/dlpage/gaoptout).

Recipients / third-country transfer: the provider is Google Ireland Limited; processing by Google LLC (USA) is possible. Google LLC is certified under the EU-US Data Privacy Framework (DPF) (adequacy decision (EU) 2023/1795); in addition, EU Standard Contractual Clauses apply within the Google data processing terms, and a data processing agreement exists with Google. There is no recipient for consent management: the consent manager is hosted by ourselves, and your consent decision does not leave your browser.

These are the cookies we set on the website (logged-out area):

Name Provider Purpose Category Retention period
PARAGLIDE_LOCALE discontinue.dev (set by us) Stores the language you selected Necessary persistent, until deleted in your browser
_ga Google Distinguishes returning visitors (GA4) Statistics approx. 2 years
_ga_S1RWKYPJFP Google Session state of the GA4 property Statistics approx. 2 years

Your consent decision itself is not stored in a cookie but in your browser's localStorage (see above). The cookies of the logged-in area are listed in Section B7.

A3. Contact and Demo/Waiting-List Requests

If you contact us via the contact form, by email, via a demo request or the waiting list, we process the data you provide (name, email, company, message content) to handle your request and, where applicable, to initiate a contractual relationship.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Retention period: until your request has been finally processed, at most 24 months, unless a contractual or statutory retention obligation exists.

A4. Recipients and Hosting

Our website is hosted in Frankfurt (Germany) on the Oracle Cloud Infrastructure (region eu-frankfurt-1). Upstream of this sits Cloudflare, Inc. as a reverse proxy: Cloudflare receives your request, terminates the transport encryption, repels attacks and overload and forwards the request to our server. In doing so, Cloudflare processes your IP address, the time, the address requested, your browser and the status code of the response; content is processed in transit and is not stored at Cloudflare. The connection logs generated in the process are short-lived technical logs; we use the standard configuration without extended log retention (no Logpush), Cloudflare deletes them in line with the retention periods published in its documentation, and Discontinue itself does not store these logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an available operation protected against attacks). Cloudflare, Inc. is established in the USA and is certified under the EU-US Data Privacy Framework (adequacy decision (EU) 2023/1795); in addition, the EU Standard Contractual Clauses from the Cloudflare DPA apply. Recipients of data are also Functional Software, Inc. d/b/a Sentry for error and operations monitoring (see A1), – subject to your consent – Google (analytics), and our email service provider when responding to enquiries. Sentry stores data in the EU (European Union region); the contracting party is Functional Software, Inc., established in the USA, so access from the USA cannot be ruled out. The transfer relies on adequacy decision (EU) 2023/1795 (EU-US Data Privacy Framework, Art. 45 GDPR); in addition, the EU Standard Contractual Clauses from the Sentry DPA apply as a fallback. There is no recipient for consent management; the consent manager is hosted by ourselves. Transfers to third countries take place only in the cases described above — to Cloudflare, to Sentry and, subject to your consent, to Google — on the legal basis stated in each case.

Part B – Using the “Discontinue” platform

B1. Overview and Allocation of Roles

This part informs you about how Discontinue processes personal data when you use the Platform. We comply with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

The Platform is an AI-supported operations platform for hotels that builds on the connected source systems. Hotel operators independently configure reports and agents that access their own data from the connected systems. This results in a dual role:

Processing Discontinue’s role Governing document
Hotel data (data from the connected systems and guest data) as well as approval and execution data, processed on behalf of the hotel Processor (Art. 4(8) GDPR) – the hotel is the controller Data Processing Agreement (DPA)
Account, usage and billing data of platform users and product analytics Controller (Art. 4(7) GDPR) this Privacy Policy

Approval and execution data (time, approving person, decision and result of write operations that were approved or executed autonomously under the opt-in) arise in the course of carrying out the processing on behalf and are, to that extent, processed as customer data under the DPA, even where they name the approving platform user; the hotel is the controller in this respect. They do not form part of the usage data for which Discontinue is an independent controller (B2.3).

For the data processed on behalf of the hotel, data subjects (e.g. guests) generally direct their requests to the respective hotel as the controller.

B2. What Data We Process

B2.1 Account data of platform users (Discontinue = controller)

  • Name and email address of the platform user (hotel staff)
  • Password (stored exclusively as a cryptographic hash; bcrypt/Argon2)
  • Role and permissions within the Platform
  • Time of the last activity in a session (to secure sessions and end inactive ones automatically)
  • Evidence of the electronic conclusion of the contract: time of acceptance, IP address and browser identifier at the time of acceptance, and the document versions accepted (evidentiary purpose)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing, securing and billing the contractually owed platform service to the customer company). The contracting party is the hotel as the customer company; the individual platform users are not themselves parties to the contract. Art. 6(1)(b) GDPR applies only where the data subject is itself a party to the contract (e.g. sole traders).

The provision of a name and email address is necessary in order to set up access; without this information no user account can be provided. Providing further information is voluntary.

Where user accounts are created by an administering person at the hotel, the name and email address originate from that creation by the hotel.

B2.2 Hotel data from the connected systems (Discontinue = processor)

Access takes place via the connection of the source system established by the hotel itself (OAuth), which the hotel can revoke at any time. On behalf of the respective hotel, we process the following data categories:

  • Reservation data (booking number, check-in/-out, status)
  • Guest master data (salutation, first and last name)
  • Contact data of guests, where stored in the source system (in particular email address)
  • Room/unit data, length of stay, rate, special requests
  • Folios, refunds, invoices, revenue information
  • Approval and execution data: time, approving person (name/identifier of the platform user), decision and result of write operations that were approved or executed autonomously under the opt-in

Discontinue processes this data exclusively on the documented instructions of the hotel, acting as a processor (Art. 28 GDPR). The legal basis for the processing is determined by the hotel as the controller; Art. 28 GDPR is not itself a legal basis. Approval and execution data arise in the course of carrying out the processing on behalf and are, to that extent, processed as customer data under the DPA, even where they name the approving platform user.

B2.3 Usage data of the Platform (Discontinue = controller)

  • Times of platform usage
  • Platform usage (which reports created, which agents configured)
  • Browser and device information (user agent)

Approval and execution data do not form part of this usage data; they are processed as customer data on behalf of the hotel (B2.2), the hotel being the controller in this respect.

B2.4 Product analytics with Google Analytics 4 (Discontinue = controller)

To improve and stabilise the Platform, we analyse product usage with the help of Google Analytics 4 (GA4). The usage behaviour of the platform users (hotel staff) is recorded, e.g. functions accessed, click and navigation events, approximate location (based on the truncated IP), device and browser information, and pseudonymous identifiers (client/session IDs). Important limitations:

  • Data is collected exclusively after your consent via the consent banner (consent mechanism as in Part A: self-hosted consent manager, Google Consent Mode in basic mode). Without consent, no analytics cookies are set and no analytics data is transmitted to Google.
  • No data from the connected systems and no guest data is transmitted to Google. The product analytics relate solely to the behaviour of the logged-in staff users in operating the Platform, not to content from the connected systems.
  • GA4 uses IP addresses only temporarily (including for rough location determination) and does not store them; IP anonymisation is effective by default in GA4.
  • There is no cross-device profiling for advertising purposes and no linking with Google advertising services; the “Google Signals” function is disabled.

Legal basis: your consent pursuant to Art. 6(1)(a) GDPR and – for the storage of and access to information on the terminal device – Section 165(3) TKG 2021. You can withdraw your consent at any time with effect for the future via the consent settings.

Recipients / third-country transfer: the provider is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland); processing by Google LLC (USA) is possible. Google LLC is certified under the EU-US Data Privacy Framework (DPF) (adequacy decision (EU) 2023/1795); in addition, EU Standard Contractual Clauses apply within the Google data processing terms.

Retention period: the retention period for user and event data in GA4 is limited to 14 months; after this, automatic deletion/aggregation takes place. Your consent decision remains exclusively in your browser's localStorage until you change or delete it there.

B2.5 AI processing and run traces (Discontinue = processor)

For the platform’s AI functions – the builder (creating and editing reports and agents), agent runs, chat and validations – hotel data is transmitted to the AI model used in each case, insofar as this is necessary for the report or agent configured by the controller. The platform may offer alternative AI processing routes (agent stacks) for this purpose, between which the hotel chooses: a self-hosted agent stack (execution and orchestration in the environment controlled by Discontinue; model access via the EU endpoint of an AI gateway to the model providers listed in the register of the Sub-Processor List) and the processing route via the AI provider (currently the Claude API by Anthropic — contracting party: Anthropic Ireland, Limited, Dublin; the processing runs in the USA at Anthropic PBC and further group/infrastructure companies); where no stack selection is offered, the processing route via the AI provider is used. Which AI providers are used on each processing route is set out in the Sub-Processor List (Annex 1 to the data processing agreement), with identity, location and transfer basis; it is available at [email protected]. A new AI provider is announced at least 14 days before it is used. Within a processing route, the hotel may choose per function or agent between selection levels (performance classes); levels carrying an EU designation are assigned exclusively to providers which, according to the Sub-Processor List, process exclusively within the EU/EEA. The designation of a level does not name the underlying model; which provider (legal entity) is involved follows from the Sub-Processor List. Depending on the configuration, the transmitted content may include personal guest data including salutation, first and last name as well as contact, reservation and stay data.

AI processing takes place in the builder, during agent runs, in chat and during validations. A scheduled report run executes the plan defined in the builder deterministically; no AI processing and no transfer to the AI provider takes place in that step.

Function AI processing Transfer to the AI model of the selected processing route (Annex 1 to the DPA) Logging
Builder (creating/editing reports and agents) yes yes AI run trace
Scheduled report run and delivery no (deterministic execution of the plan defined in the builder) no deterministic run record
Agent run yes yes AI run trace
Chat yes yes AI run trace
Validation / agent self-check yes yes AI run trace

Self-hosted agent stack. Where the hotel selects the self-hosted agent stack for a workspace, agent execution and orchestration run on self-operated proprietary and open-source components in the environment controlled by Discontinue (Oracle Cloud Infrastructure, Frankfurt, EU); no additional service provider is engaged for this, and session histories remain in this environment. Model access takes place via the AI gateway Eden AI SAS (France), for selection levels carrying an EU designation exclusively via its EU endpoint; according to the provider's documentation, the processing, hosting and routing of that EU endpoint take place exclusively in the EU, with no fallback to a global endpoint, without storage of the transmitted inputs and outputs (zero data retention; limited technical metadata remains for billing and security) and without use of the data for training (no-training). The gateway forwards the request to one of the model providers listed in the register "Enabled model providers of the self-hosted agent stack" of the Sub-Processor List; within the providers assigned to a selection level, the assignment is made dynamically per request by availability, price and speed. For all providers listed in the register, zero data retention and no-training apply according to the gateway's published provider data policies. For selection levels carrying an EU designation, the entire AI chain (AI gateway and model providers) processes exclusively within the EU/EEA; on this route no third-country transfer takes place in the AI chain. The separately disclosed transport via Cloudflare (Section B6 item 4) remains unaffected. The details set out in the register per provider (legal entity, place of processing, undertakings, transfer basis) are authoritative.

Managed agent environment (processing route via the AI provider). On the processing route via the AI provider, agent runs take place in an agent environment managed by the AI provider (agent harness, orchestration, session management and session execution environment). There, a session history (event history) and any task resources (e.g. working files, memory stores) are stored for each agent; they may contain the processed hotel data including guest data. According to the provider's documentation, these stocks are exempt from the 30-day standard retention period; they exist for the operating life of the agent and are deleted by Discontinue when the hotel deletes the agent, at the latest at the end of the contract (DPA Section 10) — sessions and independently kept resources are each deleted separately. Deactivating an agent ends further runs but leaves the session history in place until the agent is deleted. The builder, chat and validations, by contrast, run statelessly; the 30-day standard retention period applies to them.

The following protective measures apply:

  • AI models are used exclusively via API.
  • The transmitted data is not used to train the AI models (no-training guarantee).
  • Storage at the AI provider: on the processing route via the AI provider, for the stateless functions (builder, chat, validations) storage is generally limited to a maximum of 30 days (solely for abuse detection), followed by automatic deletion. Under the terms of Anthropic, the provider used on that route, there are exceptions: if content is flagged by its automated abuse-detection systems, inputs and outputs may be retained for up to 24 months and associated classification scores for up to 7 years; statutory retention obligations and retention for dispute resolution likewise remain unaffected. Discontinue uses the AI provider’s standard business access; no special agreement on deviating retention periods (zero data retention) exists in that respect. For agent runs, the storage of the managed agent environment applies there (see above: session history and task resources until the agent is deleted). On the self-hosted agent stack, according to the provider data policies the AI gateway (Eden AI) and the model providers listed in the register do not store the transmitted inputs and outputs (zero data retention).
  • Multi-layered data minimisation: only the scopes released in the source system (read-only by default), granular and configurable tools with an allowlist per agent and tool/scope minimisation per task, tenant/integration scoping, and a run budget (€ cap).
  • Tenant isolation: each API call is restricted to the respective hotel tenant; identifiable data of several hotels is not consolidated for Discontinue's own purposes.
  • Transfer to the USA (only on the processing route via the AI provider): safeguarded under Art. 44 et seq. GDPR together with a Transfer Impact Assessment; confirmation of the Art. 46 instrument specifically used by Anthropic Ireland for the US chain has been requested from the provider. As a precaution, EU Standard Contractual Clauses are incorporated in the Anthropic DPA (“deemed executed”, to the extent required; pursuant to Implementing Decision (EU) 2021/914 and Art. 46(2)(c) GDPR); for hotel data processed on behalf of hotels, Module 3 (processor-to-processor) applies in that respect. Details: Section B6. On the self-hosted agent stack, for selection levels carrying an EU designation no transfer to a third country takes place in the AI chain (see above).
  • For every AI run, a complete internal run trace is created and retained for 90 days; at present it also contains the processed content. For scheduled report runs without AI involvement, a run record is kept without a system prompt and without a model reference (trigger, time, status, data sources, result, deliveries, errors).
  • Write operations to the connected systems by default pass through an approval queue with human approval; only with explicit per-agent opt-in without individual approval. The proposal, approver, decision and result are logged.

Longer storage of flagged content (processing route via the AI provider). If the AI provider’s automated abuse detection flags content, that content may remain stored there for longer than the 30 days that otherwise apply (inputs and outputs for up to 24 months, classification scores for up to 7 years). This serves to detect and prevent abusive use and thus the security of the AI provider’s services; the retention takes place within the processing on behalf. Discontinue cannot determine the duration of this storage. We expressly point this out to the hotel as controller so that it can meet its own information and accountability obligations.

Cross-run reuse for agents. An AI run trace is created for every agent run. For agents, the results of previous runs are drawn on again in subsequent runs — via the run trace and, on the processing route via the AI provider, via the session history kept in its managed agent environment — in order to validate and improve execution; in doing so, this content is again processed with AI support and, to that extent, transferred to or processed at the AI provider of the applicable processing route. Reuse takes place exclusively within the same tenant and the same agent; no cross-tenant analysis takes place. Discontinue's own run traces are retained for 90 days; the session history at the AI provider exists until the agent is deleted. The controller may deactivate or delete an agent at any time.

Because AI run traces and deterministic run records may contain the processed content, personal data contained in them continues to exist until the end of the retention period, even if it has already been deleted in the source system. Erasure requests concerning run records are handled in accordance with the data subject rights process.

Note on pseudonymisation: in operational use, Discontinue deliberately refrains from fully pseudonymising guest names, since operational hotel workflows (e.g. a “VIP arrivals briefing”) lose their function if the specific guest name is replaced by an anonymous identifier. Data minimisation is instead achieved through the multi-layered protective measures described above. Classic pseudonymisation is used where it is possible without loss of function (e.g. in aggregated statistical reports).

B2.6 Billing data (Discontinue = controller)

For contract and payment processing, we process company/invoice data, subscription and usage scope (plan/tier, agent slots, balance top-ups), and payment information via the payment service provider Stripe. No data from the connected systems and no guest data is processed in this context.

Insofar as Stripe processes payment data to fulfil its own statutory obligations (in particular anti-money-laundering) and for fraud prevention, Stripe acts as an independent controller in that respect; details are set out in Stripe’s privacy policy.

B3. Legal Bases

Processing Legal basis
Account administration (hotel staff access) Art. 6(1)(f) GDPR – legitimate interest in providing, securing and billing the contractually owed platform service to the customer company; Art. 6(1)(b) GDPR only where the data subject is itself a party to the contract
Hotel data (from the connected systems) Processing exclusively on the documented instructions of the hotel, acting as a processor (Art. 28 GDPR); the legal basis is determined by the hotel as the controller – Art. 28 GDPR is not itself a legal basis
Platform operation / security Art. 6(1)(f) GDPR – legitimate interest
Evidence of the electronic conclusion of the contract (time, IP address, browser, document versions) Art. 6(1)(f) GDPR – legitimate interest in evidence and the defence of legal claims
Product analytics (Google Analytics 4) Art. 6(1)(a) GDPR – consent; Section 165(3) TKG 2021
AI processing of hotel data As for hotel data: processing on the documented instructions of the hotel, acting as a processor (Art. 28 GDPR); the legal basis is determined by the hotel as the controller
Billing Art. 6(1)(b) GDPR where the data subject is itself a party to the contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in performing the contract with the customer company); Art. 6(1)(c) GDPR for the invoice details required by law
Statutory obligations (e.g. retention) Art. 6(1)(c) GDPR

B4. Retention Period

Type of data Retention period
Account data As long as the account is active; thereafter deletion within 30 days
Hotel data (from the connected systems) Only during active processing; no permanent mirroring of the connected system’s database
Report artefacts (rendered reports) and results of the runs 90 days; thereafter automatic deletion
Run traces and run records (execution records per run — as an AI run trace for AI runs, deterministic for scheduled report runs —, including the processed content; for agents, the traces of previous runs are drawn on again across runs to validate and improve execution and are processed with AI support again in the process) 90 days; when they are deleted, cross-run reuse via the provider's own traces also ends
Session history and task resources in the AI provider's managed agent environment (processing route via the AI provider only, see B2.5) For the operating life of the agent; deleted by Discontinue when the agent is deleted, at the latest at the end of the contract (DPA Section 10)
Delivery logs and approval decisions of the approval queue 90 days
Operating logs of the connectors 30 days
Log of granted access authorisations and connections 12 months
Evidence of contract acceptance (time, IP address, browser, accepted document versions) For the duration of the contractual relationship and thereafter for as long as claims may be asserted from it
Google Analytics data (GA4) 14 months
Consent decision (self-hosted consent manager) Remains exclusively in the data subject's browser (localStorage) until changed or deleted there; no server-side record
Invoice data 7 years (statutory retention obligation pursuant to Section 132 BAO – Austria)
Case documentation on data subject requests 3 years from the closure of the request (proof-of-identity documents are erased immediately after verification)
Record of personal data breaches 5 years from the closure of the incident (Art. 33(5) GDPR)

B5. Recipients and Sub-Processors

A complete sub-processor list with data categories and transfer basis is Annex 1 to the DPA and available on request at [email protected].

Recipient Purpose Location Role / transfer basis
Oracle Cloud Infrastructure Hosting of the Platform, database, backup, object storage and delivery of reports and notifications by email Frankfurt, Germany (EU) Processor; processing in the EU, no ongoing third-country transfer; SCCs pursuant to the Oracle DPA for any support access
Anthropic Ireland, Limited AI model (Claude API) and managed agent environment for agent runs, for processing hotel content in the AI functions (builder, agent runs, chat, validations); no transfer for scheduled report runs; conditional: only on the processing route via the AI provider Contracting party: Dublin, Ireland (EU); processing in the USA (Anthropic PBC and further group/infrastructure companies) Processor; onward transfer within the Anthropic chain (exporter: Anthropic Ireland, bound by Art. 44 et seq. GDPR; chain instrument requested from the provider; as a precaution, SCCs incorporated in the Anthropic DPA, for hotel data Module 3) + TIA, no training (contractual, Commercial Terms); stateless functions max. 30 days (abuse detection; exceptions where flagged: up to 24 months / classification scores up to 7 years); session history and task resources per agent until the agent is deleted (see B2.5)
Eden AI SAS and the model providers listed in the register of the Sub-Processor List (Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, Mistral AI SAS, OVH SAS, Scaleway SAS, Nebius B.V., TensorX Ltd., Databricks, Inc. — each processing in the EU) AI gateway (EU endpoint) of the self-hosted agent stack: forwarding of the AI requests to one of the model providers listed in the register (dynamic routing within the providers assigned to a selection level); no transfer for scheduled report runs; conditional: only where this processing route is selected Villeurbanne, France (EU); model providers: EU regions per the register Processor (model providers as sub-processors of Eden AI SAS); for selection levels carrying an EU designation, processing in the EU via the EU endpoint, according to the provider data policies without storage of inputs and outputs (zero data retention) and without training (no-training); for any group/support access of individual model providers from third countries, SCCs per the register; for the case, not envisaged, of processing in a third country, a basis under Art. 44 et seq. GDPR is put in place before use
Stripe Payments Europe Ltd. Billing and payment processing (no hotel/guest data) Dublin, Ireland (EU); group access USA via SCCs Processor; independent controller in respect of its own statutory obligations (in particular anti-money-laundering) and fraud prevention
Google Ireland Ltd. / Google LLC Product analytics (Google Analytics 4) – only after consent, no guest data Ireland (EU) / USA Processor for product analytics; EU-US DPF + SCCs
Cloudflare, Inc. Reverse proxy, transport encryption and defence against attacks for the website, the platform and the API; content is processed in transit and is not stored at Cloudflare Global edge network; established in the USA Processor; adequacy decision (EU-US Data Privacy Framework), in addition the EU Standard Contractual Clauses from the Cloudflare DPA
Functional Software, Inc. d/b/a Sentry Error and operations monitoring of the website (see A1) and the platform; hotel and guest data are technically excluded by an allow-list of the fields transmitted Storage in the EU; established in the USA Processor for discontinue.dev as the independent controller; adequacy decision (EU) 2023/1795 — Functional Software, Inc. is certified under the EU-US Data Privacy Framework; the SCCs from the Sentry DPA apply additionally

B6. Data Transfer to Third Countries

  1. AI processing (Anthropic, USA — only on the processing route via the AI provider): the contracting party is Anthropic Ireland, Limited (Dublin, Ireland) — the direct flow to the Irish entity is not a third-country transfer; the processing runs as an onward transfer in the USA at Anthropic PBC and further group/infrastructure companies. Hotel data is transferred only where the processing route via the AI provider applies, and only in the context of the AI functions (builder, agent runs, chat, validations); a scheduled report run does not trigger a transfer. For agent runs, the processing at the AI provider is stateful: the session history kept for each agent exists there until the agent is deleted; Discontinue can delete it at any time (see B2.5). On the self-hosted agent stack, for selection levels carrying an EU designation no third-country transfer takes place in the AI chain (register of the Sub-Processor List; for any group/support access of individual model providers from third countries, SCCs per the register) (see B2.5); the separately disclosed transport route via Cloudflare (item 4) remains unaffected. The onward transfer to the USA is the responsibility of Anthropic Ireland as data exporter — itself directly bound by Art. 44 et seq. GDPR, with contractual flow-down of the protection obligations under the Anthropic DPA; confirmation of the Art. 46 instrument specifically used by Anthropic Ireland for the US chain has been requested from the provider; as a precaution, the SCCs are also incorporated in the Anthropic DPA (“deemed executed”, to the extent required; for hotel data Module 3 — processor-to-processor) pursuant to Art. 46(2)(c) GDPR – supplemented by a no-training guarantee (contractual, Commercial Terms) and a limited retention period according to the provider’s published retention documentation, transport encryption (TLS 1.2+), multi-layered data minimisation and tenant isolation. As regards the retention period: for the stateless functions (builder, chat, validations), storage at the AI provider is generally limited to a maximum of 30 days (solely for abuse detection), followed by automatic deletion. Under the terms of Anthropic, the provider used on that route, there are exceptions: if content is flagged by its automated abuse-detection systems, inputs and outputs may be retained for up to 24 months and associated classification scores for up to 7 years; statutory retention obligations and retention for dispute resolution likewise remain unaffected. Discontinue uses the AI provider’s standard business access; no special agreement on deviating retention periods (zero data retention) exists. For this transfer, a Transfer Impact Assessment (TIA) pursuant to “Schrems II” (CJEU C-311/18) is additionally available, which can be requested at [email protected].
  2. Product analytics (Google): processing by Google LLC in the USA may take place. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision (EU) 2023/1795); in addition, SCCs apply. The transfer only takes place after your consent.
  3. Stripe (billing): primary processing by Stripe Payments Europe Ltd. (Dublin); any group access to the USA is secured via SCCs.
  4. Reverse proxy (Cloudflare, USA): requests to the website, the platform and the API pass through Cloudflare, which processes connection data and transports content in transit without storing it; the inspection of requests is limited to a technical security check (pattern matching against attacks), and no substantive or AI-supported evaluation of the content takes place. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework; in addition, the EU Standard Contractual Clauses from the Cloudflare DPA apply.
  5. Error and operations monitoring (Sentry): storage takes place in the EU; the contracting party is Functional Software, Inc. (USA), so access from the USA cannot be ruled out. Functional Software, Inc. is certified under the EU-US Data Privacy Framework; the transfer relies on adequacy decision (EU) 2023/1795 (Art. 45 GDPR), and the EU Standard Contractual Clauses from the Sentry DPA apply additionally as a fallback. Hotel and guest data are technically excluded by an allow-list of the fields transmitted; event data is retained at the provider for 90 days.

For context: substantive processing in a third country takes place solely in the AI processing (number 1). At Cloudflare the same content is merely transported; at Sentry it is technically excluded.

A copy of the Standard Contractual Clauses can be requested at [email protected].

B7. Cookies and Tracking (Platform)

On the Platform we use:

  • Necessary – technically necessary cookies for session management and authentication as well as for remembering the email address last used in the sign-in form. These are required for operation and cannot be deselected (Section 165(3) TKG 2021 – no consent required).
  • Statistics – analytics cookies/technologies (Google Analytics 4) – exclusively after your consent via the consent banner (see B2.4).
  • Consent management: the consent banner is provided by a consent manager hosted by ourselves (see A2). Your choice is stored exclusively locally in your browser's localStorage; no cookie is set for this purpose and nothing is transmitted to us or to third parties.

These are the cookies we set in the logged-in area in addition to those listed in A2:

Name Provider Purpose Category Retention period
__session discontinue.dev (set by us) Authentication of the sign-in session (HttpOnly, Secure) Necessary Session-based; ends when you sign out
__account_roster discontinue.dev (set by us) Assignment of the accounts enabled for you (HttpOnly, Secure) Necessary Session-based; ends when you sign out
remember_email discontinue.dev (set by us) Remembers the email address last used in the sign-in form Necessary persistent, until deleted in your browser

In the standard configuration, no automated individual decision within the meaning of Art. 22 GDPR takes place: write operations pass through human approval. Where the customer expressly activates opt-in operation for an agent, it is responsible as controller for assessing whether that agent’s outputs constitute a decision with legal or similarly significant effect and for meeting the requirements of Art. 22 GDPR. No marketing/advertising cookies and no cross-device advertising profiling are used.

B8. Security of Processing

We take appropriate technical and organisational measures pursuant to Art. 32 GDPR (including encryption at rest with AES-256-GCM for sensitive data, TLS 1.2+ in transit, role-based authorisation concept, multi-tenant isolation, daily backups, audit trail of AI processing). Details are set out in the document TOMs (Art. 32).

Part C – Provisions applicable to both Part A and Part B

C1. Your Rights

As a data subject, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent given (Art. 7(3) GDPR), e.g. for product analytics – with effect for the future

Please direct requests to [email protected]; we respond within one month (Art. 12(3) GDPR). Insofar as Discontinue processes data as a processor (Part B, hotel data), we forward the request without undue delay to the respective hotel operator (controller).

C2. Right to Lodge a Complaint

You have the right to lodge a complaint with the Austrian Data Protection Authority (DSB): Barichgasse 40–42, 1030 Vienna, [email protected], https://www.dsb.gv.at/.

C3. Amendments to this Privacy Policy

We reserve the right to adapt this Privacy Policy as required. The current version is available on the website and in the Platform. We inform platform users of material changes to Part B (Platform) by email.

discontinue.dev MAS GmbH · [email protected] · As of: 3 September 2026

Privacy Policy · Effective: 3 September 2026 · discontinue.dev MAS GmbH
Discontinue

Chat, reports, and AI agents for hotels.

Login Request access Documentation Contact Pricing Privacy Legal Notice AI Transparency Sub-processors