AI Assistant & Data Processing Notice (Human-in-the-Loop)

1) Transparency (AI interaction)

Our website uses an AI-powered assistant to support enquiries, provide information, and route requests efficiently. You will be clearly informed when you are interacting with an AI system. We label that AI Agents with the label AIA in the right corner in the bottom of each AI Agent.

2) Human oversight, escalation, and accountability

We operate a human-in-the-loop control model:

  • The AI assistant is used to accelerate communication and improve service responsiveness.

  • A qualified human is always available and will review/take over where the request is contractual, compliance-related, risk-sensitive, or unclear.

  • The AI assistant does not make binding decisions on our behalf; final accountability remains with our team.

(These transparency expectations are reflected in EU guidance and Article 50 transparency obligations for AI systems that interact with people.)

3) What data may be processed in the AI channel

Depending on what you submit, we may process:

  • Chat messages and the information you provide (e.g., enquiry details, contact information)

  • Interaction metadata (e.g., timestamps, routing tags, conversation references)

  • Technical/security data where necessary to protect the service (e.g., abuse prevention)

Please do not share special category data (e.g., health data), banking credentials, or confidential third-party information via the chat unless we explicitly request it through a secure channel.

4) Systems used (processors and infrastructure)

To operate the AI-assisted workflow, we use:

  • CRM: HubSpot (for enquiry management and customer communications)

  • Workflow automation: n8n, self-hosted on EU-based servers under our administrative control (for orchestration and routing)

  • AI tooling/provider: Sintra.ai (to support AI capabilities used in the assistant)

We engage service providers under appropriate contractual terms and security obligations.

5) International transfers

Where any provider processes data outside the EEA, we apply recognized safeguards (e.g., Standard Contractual Clauses and appropriate technical/organizational measures). For example, HubSpot documents SCC-based transfer mechanisms in its legal materials.

6) Purpose and legal basis (GDPR)

We process chat-related data to:

  • Respond to enquiries and provide support

  • Route requests internally and follow up

  • Maintain quality assurance, security, and compliance oversight

Legal basis typically includes legitimate interests (efficient, secure communications) and/or steps prior to entering into a contract / performance of a contract, depending on the request.

7) Retention and security

We retain chat data only as long as necessary for service delivery, auditability, dispute handling, and compliance requirements, after which it is deleted or anonymized in line with our retention rules. We apply access controls, logging, and need-to-know handling.

8) Operator details and contact

 

Terminbuchung