Data Processing Addendum — Hermes Layer
Version: 1.0
Last updated: 14 June 2026 Language: English international version
Reference language: French
This English version is provided for international users. The operator of Hermes Layer remains a French business, and the French version remains the reference version in case of inconsistency, unless mandatory law provides otherwise.
This Data Processing Addendum, or DPA, supplements the Terms of Use and Terms of Sale of Hermes Layer where a customer uses the service to process personal data on behalf of third parties or in a context where the customer determines the purposes and means of processing.
1. Parties
Processor:
M LOUE XAVIER, individual entrepreneur under French law, operating Hermes Layer
Address: 3 Impasse Denis Papin, 44310 Saint-Philbert-de-Grand-Lieu, France
SIREN: 891 108 615
VAT: FR37 891108615
Privacy email: [email protected]
Customer / Controller:
The professional natural or legal person subscribing to Hermes Layer and using the service to process personal data in its own business context.
The Customer and Hermes Layer are together the “Parties”.
2. Subject matter
This DPA defines the conditions under which Hermes Layer processes personal data on behalf of the Customer in connection with the service.
It applies in particular to processing activities relating to:
- hosting of the Hermes Agent workspace;
- the authenticated WebUI gateway;
- prompts, files, outputs, logs, configurations, secrets and data introduced into the workspace;
- backups, exports and restores;
- support where the Customer communicates personal data;
- Managed AI requests when the Customer chooses this mode;
- connectors or providers selected by the Customer, to the extent Hermes Layer technically participates in their transmission or hosting.
This DPA does not apply to processing activities for which Hermes Layer acts as an independent controller, including account, billing, security, tax, Stripe, payment evidence, disputes, legal compliance, Hermes Layer’s own commercial communications or internal administration.
3. Contractual hierarchy
In case of inconsistency:
- this DPA prevails for personal data processing carried out on behalf of the Customer;
- the Terms of Sale prevail for price, payment, refund and subscription matters;
- the Terms of Use prevail for usage rules;
- the Privacy Policy describes processing activities where Hermes Layer acts as data controller.
4. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, “sub-processor” and “supervisory authority” have the meanings given by the GDPR where it applies.
Customer Data means data, content, files, prompts, outputs, logs, configurations or information processed in the service on behalf of the Customer.
Customer Personal Data means Customer Data that constitutes personal data.
5. Customer instructions
Hermes Layer processes Customer Personal Data only on documented instructions from the Customer, including:
- the Terms of Use;
- the Terms of Sale;
- this DPA;
- account settings;
- user actions in the service;
- support requests;
- provider, model, connector, backup and Managed AI configurations;
- any written instruction accepted by Hermes Layer.
If Hermes Layer believes that an instruction infringes applicable law, it informs the Customer to the extent permitted by law. Hermes Layer may refuse an illegal, dangerous, technically impossible or security-incompatible instruction.
The Customer acknowledges that use of connectors, BYOK AI providers, repositories, external tools or Managed AI constitutes an instruction to transmit or make certain data available to those providers.
6. Description of processing
The detailed description of processing is set out in Annex 1.
7. Customer obligations
The Customer warrants that it:
- has a legal basis for processing Customer Personal Data;
- informs data subjects;
- obtains required consents where necessary;
- does not import prohibited, unlawful or excessive data;
- does not use Hermes Layer for high-risk uses without an appropriate framework;
- complies with applicable laws, including GDPR, ePrivacy, local data protection laws, AI rules and sectoral obligations;
- correctly configures its providers, keys, connectors and prompts;
- limits data introduced into the service to what is necessary;
- responds to data subject requests, unless assistance is requested from Hermes Layer.
The Customer must not use Hermes Layer to process health data, biometric identification data, criminal offense data, minors’ data or other sensitive data at scale without a written agreement and appropriate measures.
8. Confidentiality
Hermes Layer ensures that persons authorized to process Customer Personal Data are subject to an appropriate confidentiality obligation.
Internal access is limited to operational, support, security, maintenance, compliance or legal defense needs.
9. Security measures
Hermes Layer implements technical and organizational measures appropriate to the risk, including those described in Annex 2.
The Customer acknowledges that security also depends on:
- the strength of its passwords;
- the confidentiality of its API keys;
- the configuration of its connectors;
- permissions granted to its users;
- the data it imports;
- third-party providers it chooses;
- its own organizational measures.
10. Sub-processors
The Customer authorizes Hermes Layer to use sub-processors to provide the service, provided that Hermes Layer imposes data protection obligations on those sub-processors that are substantially equivalent to those of this DPA.
The initial list of known categories and sub-processors appears in Annex 3.
Hermes Layer may replace or add a sub-processor. Where the change is material, Hermes Layer may inform the Customer by email, notification or publication. The Customer may object on reasonable data protection grounds within 15 days. If no reasonable solution is possible, the Customer may terminate the affected service in accordance with the Terms of Sale.
Providers chosen directly by the Customer in its workspace, including BYOK keys, models, connectors, Git repositories, external APIs or MCP tools, are not necessarily Hermes Layer sub-processors; they may be Customer providers under the Customer’s responsibility.
11. International transfers
Hermes Layer may process or transfer Customer Personal Data outside the European Economic Area where necessary for the service, including through Stripe, SendGrid, OpenRouter, AI providers, hosting, storage or support.
Where the GDPR applies and a transfer outside the EEA is not covered by an adequacy decision, Hermes Layer relies on an appropriate transfer mechanism, including the European Commission Standard Contractual Clauses and, where necessary, additional measures.
The Customer authorizes Hermes Layer to enter into the applicable modules of the Standard Contractual Clauses with the relevant sub-processors.
12. Assistance to the Customer
Taking into account the nature of the processing, Hermes Layer reasonably assists the Customer to:
- respond to access, rectification, erasure, restriction, objection or portability requests;
- provide information necessary for a data protection impact assessment;
- notify and document a personal data breach;
- satisfy security obligations;
- demonstrate processing compliance.
This assistance may be charged if it exceeds standard support, unless a contrary legal obligation applies or Hermes Layer is at fault.
13. Data subject requests
If Hermes Layer directly receives a request relating to Customer Personal Data for which the Customer is controller, Hermes Layer may:
- invite the person to contact the Customer;
- forward the request to the Customer if the Customer is identifiable;
- respond directly where the request concerns Hermes Layer’s own processing as controller.
Hermes Layer does not substantively respond to a request concerning Customer Personal Data without the Customer’s instruction, unless legally required.
14. Personal data breaches
Hermes Layer informs the Customer without undue delay after becoming aware of a breach of Customer Personal Data affecting the service.
The notification contains, to the extent available:
- the nature of the breach;
- categories of data and data subjects concerned;
- likely consequences;
- measures taken or proposed;
- contact details;
- any information useful for possible notification to an authority or to data subjects.
Hermes Layer may provide information in stages if all information is not immediately available.
The Customer remains responsible for determining whether notification to the supervisory authority or data subjects is required.
15. Audits and compliance information
Hermes Layer makes available information reasonably necessary to demonstrate compliance with this DPA.
The Customer may request a reasonable audit, subject to:
- reasonable written notice;
- a scope limited to the relevant service;
- confidentiality;
- no risk to other customers, secrets, security or infrastructure;
- a reasonable number of audits;
- reimbursement of reasonable costs if the audit exceeds standard information.
Hermes Layer may refuse any audit that would require access to secrets, keys, other customers’ data, raw runtime, internal infrastructure, non-public source code or sensitive security information.
16. Return and deletion of data
At the end of the contract or upon an applicable Customer request, Hermes Layer deletes or returns Customer Personal Data within a reasonable period, subject to:
- legal obligations;
- technical backups;
- purge periods;
- payment evidence, disputes, tax or security;
- data necessary for defense of rights;
- data processed as an independent controller.
The Customer must export its data and backups before access ends.
Data present in backups may remain until expiry of their retention cycle, then be deleted or overwritten according to technical processes.
17. Processing as independent controller
Hermes Layer remains an independent controller in particular for:
- user account;
- authentication;
- security logs and rate limits;
- billing and Stripe;
- tax and accounting;
- customer support;
- disputes, chargebacks, payment evidence;
- service security;
- internal administration;
- operational communications;
- compliance with legal obligations.
These processing activities are described in the Privacy Policy.
18. U.S. privacy laws
Where U.S. privacy laws apply to the Customer, including CCPA/CPRA or similar state laws, Hermes Layer undertakes, for Customer Personal Data processed as processor or service provider:
- to process data only to provide the service;
- not to sell Customer Personal Data;
- not to share it for cross-context behavioral advertising;
- not to use it for Hermes Layer’s own commercial purposes incompatible with the service;
- to reasonably assist the Customer in complying with applicable rights;
- to impose appropriate obligations on sub-processors.
19. Liability
Hermes Layer’s liability under this DPA is subject to the limitations set out in the Terms of Use and Terms of Sale, unless a mandatory provision provides otherwise.
No limitation applies where liability cannot legally be limited.
20. Term
This DPA remains in force as long as Hermes Layer processes Customer Personal Data on behalf of the Customer.
Certain obligations, including confidentiality, security, deletion, evidence, reasonable audit and limitations, survive the end of the contract for as long as necessary.
Annex 1 — Description of processing
A. Subject matter
Provision of a hosted SaaS service allowing the Customer to use a managed Hermes Agent with WebUI, isolated runtime, authenticated gateway, backups, support, billing, Managed AI and configurable integrations.
B. Duration
Duration of the contract, then the period necessary for return, deletion, backups, legal obligations, disputes and defense of rights.
C. Nature of operations
Collection, receipt, hosting, storage, organization, consultation, transmission, proxying, backup, restore, export, deletion, encryption, logging, securing, support, technical analysis, rate limiting and contractual evidence.
D. Purposes
- provide the Hermes Agent workspace;
- authenticate access;
- verify active subscription;
- operate the WebUI and gateway;
- allow prompts, outputs, files, tasks, logs, connectors and agentic operations;
- manage backups and restores;
- transmit data to providers selected by the Customer;
- provide Managed AI if activated;
- provide support, maintenance, security and service evidence.
E. Categories of data subjects
Depending on the Customer’s use:
- Customer users;
- employees, contractors and collaborators;
- customers, prospects or contacts of the Customer;
- persons mentioned in files, prompts, outputs, tickets or imported data;
- account administrators and operators;
- third parties whose data is voluntarily processed by the Customer.
F. Categories of data
Depending on the Customer’s use:
- professional identity and contact data;
- technical identifiers;
- textual content;
- prompts and instructions;
- AI outputs;
- files, documents, code and repositories;
- agent and terminal logs;
- project data;
- configuration data;
- secrets, keys or secret references;
- support tickets;
- usage metadata;
- backup data;
- incidental personal data present in Customer Content.
G. Sensitive data
The service is not intended for processing sensitive or regulated data, unless a written agreement and appropriate framework are in place. If the Customer introduces such data without agreement, the Customer assumes responsibility.
Annex 2 — Technical and organizational measures
Hermes Layer implements, according to the state of the service and applicable plan:
- account authentication;
- secure session cookies in production;
- CSRF protection;
- hashed passwords;
- rate limiting on login, reset and contact;
- isolation by workspace;
- private runtime not directly exposed;
- authenticated gateway with active subscription and workspace ownership checks;
- separation between SaaS control plane and tenant runtime;
- PostgreSQL JSONB storage for control data;
- encryption of secrets and sensitive keys;
- encrypted and validated backups;
- manifest and checksums for exports;
- limitation of information exposed to the browser;
- role-based admin and support access;
- redaction of sensitive information in previews and emails;
- audit logs;
- minimized, HMAC and/or encrypted Stripe evidence;
- non-exposure policy for runtime URLs, Docker internals, keys and secrets;
- mandatory HTTPS in production;
- pinned runtime images and no
latestin production; - signed Stripe webhook;
- production configuration validation;
- S3-compatible storage for production backups;
- observability and evidence events with configured retention;
- billing-related suspension/resumption procedures;
- controlled restore mechanisms;
- access control for Stripe dispute actions.
Annex 3 — Sub-processors and providers
The list below reflects the providers and categories necessary for the current or planned service. It must be kept up to date in production.
| Provider / category | Role | Data concerned | Indicative location |
|---|---|---|---|
| Stripe | Payment, Checkout, Customer Portal, Stripe Tax, receipts, refunds, disputes | billing identity, payment, taxes, receipts, payment evidence | EU / United States / global |
| SendGrid / Twilio SendGrid | Transactional and support emails | email, name, limited excerpts, service links | United States / global |
| OpenRouter | Managed AI gateway and accessible models | prompts, messages, outputs, usage, costs, workspace keys | United States / global |
| AI providers selected by the Customer | BYOK, models, connectors | data sent by the Customer or its agent | according to provider |
| OVHcloud / OVH SAS | Application and runtime hosting | service and workspace data | France / European Union |
| PostgreSQL / production database | Control data | accounts, subscriptions, logs, support, evidence, metadata | according to infrastructure |
| S3-compatible storage | Encrypted backups | workspace archives, backups, manifests, checksums | according to provider |
| ClickHouse or equivalent observability | Observability and technical timelines | sanitized events, operational analytics, disputes | according to infrastructure |
| DNS / reverse proxy / network security | Service access | technical network metadata | according to provider |
Where another production storage, database, observability or network provider is later added, Hermes Layer must publish or communicate the corresponding information before full commercial launch.