Transparency on the use of Artificial Intelligence
Last updated: 21 August 2026
This page is a translation provided for convenience only. In case of any discrepancy, the Spanish version prevails and is the only legally binding version.
1. Purpose and scope
This page implements the transparency obligations of article 50 of Regulation (EU) 2024/1689 (hereinafter, the "AI Act") in relation to Lueira's conversational assistant ("AI Assistant"), already mentioned in section 9 of the Terms and Conditions and in sections 3 and 5 of the Privacy Policy.
This policy does not cover internal artificial intelligence tools used exclusively by Lueira's staff or by its customers' staff (for example, internal business administration tools). Such tools do not interact directly with natural persons outside the organization and are therefore not subject to the transparency obligation under article 50 of the AI Act.
2. Roles under the AI Act: provider and deployer
The AI Act distinguishes roles that are different from the data controller and data processor roles you already know from the Privacy Policy and the DPA. These should not be confused: the same entity can be a data processor for GDPR purposes and, at the same time, a provider or deployer for AI Act purposes.
- MALADETA STUDIO, S.L. acts as the provider of the AI system: it develops it and makes it available to its customers under the Lueira brand.
- The Lueira customer that activates the AI Assistant to serve its own end customers acts as the deployer towards those end customers.
3. Plain-language description of the system
The AI Assistant is a conversational assistant reachable via WhatsApp and via a chat widget that can be embedded on the Lueira customer's website. Among other functions, the AI Assistant:
- Answers enquiries using each Lueira customer's own knowledge base (see section 9).
- Calculates prices for the available activities, rentals or services.
- Can generate payment links.
- Can create or manage bookings on the user's behalf.
- Hands the conversation off to a member of staff when it cannot resolve the request or when the user asks to (see section 6).
The AI Assistant does not do the following:
- It does not make medical, legal or safety-critical decisions about people.
- It does not perform biometric identification or emotion recognition.
- It does not analyze voice for biometric identification purposes: voice notes received via WhatsApp are only transcribed to text so the enquiry can be processed.
4. The right to information under article 50 of the AI Act
Article 50 of the AI Act recognizes the right to know that you are interacting with an artificial intelligence system. The AI Assistant identifies itself as an automated assistant at the start of the conversation, both on WhatsApp and in the web chat widget.
This right to information is distinct from the right not to be subject to automated decisions with significant effects without human intervention, already regulated under the GDPR in section 9 of the Terms and Conditions and in section 6 of the Privacy Policy. Both rights are complementary and coexist.
5. Risk classification of the system
The AI Assistant is not a prohibited practice under article 5 of the AI Act: it does not perform subliminal manipulation, social scoring, or biometric categorization of people.
Nor is it a high-risk system under Annex III of the AI Act: it is not used for employment or recruitment decisions, creditworthiness assessment, biometric identification, management of critical infrastructure, education or academic assessment, or for access to essential services within the meaning of Annex III. Managing bookings for leisure and active tourism activities does not fall within any of the high-risk cases listed in that annex.
Accordingly, the AI Assistant is subject to the transparency obligation under article 50 ("limited risk" system), which is met through the assistant's self-identification as an automated system (section 4) and the human oversight mechanism described below.
6. Human oversight
The user has the right to request the intervention of a person at any time, as described in section 9 of the Terms and Conditions and in section 6 of the Privacy Policy.
7. AI infrastructure providers
The AI Assistant runs on general-purpose artificial intelligence models provided by specialized external providers. In the current configuration, these providers are OpenAI (responses from the specialist sub-agents, the safety guardrail against manipulation of the assistant, voice-note transcription, and knowledge-base search) and OpenRouter (the model used by the supervisor agent that composes the final reply). Lueira may change these providers over time to optimize the system's performance; the up-to-date list of sub-processors that process personal data through the AI Assistant is available in the Data Processing Agreement (DPA).
8. Lueira does not train its own models with customer data
As detailed in section 5 of the Privacy Policy, Lueira does not use its customers' data to train its own artificial intelligence models.
9. The assistant's knowledge base
The AI Assistant answers using the help content published by each Lueira customer, not generic internet content. This means responses are grounded in the information the customer itself has made available to the assistant.
10. Limitations of the system
The AI Assistant includes safeguards to prevent incorrect commitments (for example, confirming a booking or payment that has not actually been made), but, like any artificial intelligence system, it may occasionally produce inaccurate responses. We recommend always verifying booking or payment confirmations through the corresponding official channel.
11. Processing of personal data
The processing of personal data arising from the use of the AI Assistant is governed by Lueira's Privacy Policy.
12. Restrictions on the public API, MCP and similar functionality
Access to LUEIRA's public API, its MCP (Model Context Protocol) server, or any other feature, tool or integration offered by LUEIRA does not grant the user any right to use such access to replicate, clone, recreate or develop, whether directly or through third parties, products or services that reproduce or are substantially similar to LUEIRA, to its functionality, whether past, present or future, or to its distinctive elements. Any use of LUEIRA's public API, MCP server or any other functionality for the direct or indirect purpose of building a competing or functionally equivalent solution to LUEIRA is expressly prohibited.
Breach of this clause will entitle LUEIRA to immediately suspend or cancel the infringing user's access to the API, the MCP server and the remaining services, without prejudice to any legal action LUEIRA may be entitled to take.
13. Changes to this policy
Lueira may update this policy to adapt it to regulatory or case-law changes, or changes to how the AI Assistant works. When changes are significant, we will notify you through a notice on the platform or by email at least 30 days in advance.
We recommend that you review this policy periodically. The date of the last update always appears at the bottom of this page.
14. Contact
For any query about how the AI Assistant works, you may contact us through:
- Email: support@lueira.com
- Email (data protection): rgpd@maladetastudio.com