HermesLayerHermesLayer
HomePricingFAQBlogContactSign inOpen Agent
languageFRexpand_more
ENEnglishFRFrench
auto_awesomeAgent
HermesLayer
home
Home
Hosted AI agent workspace
dns
Hermes hosting
Hosted Hermes Agent and WebUI
account_tree
AI automation
Workflow automation workspace
payments
Pricing
Plans and hosted capacity
help_outline
FAQ
Published answers and help
article
Blog
Product and operations notes
mail
Contact
Sales, security and support
login
Sign in
Access your account
languageFRexpand_more
ENEnglishFRFrench
auto_awesomeOpen Agent
Legal

Data Processing Addendum — Hermes Layer

Data processing terms for customer personal data processed through Hermes Layer.

Version
1.0
Last updated
14 June 2026
Language
English international version
Reference
French

Data Processing Addendum — Hermes Layer

Version: 1.0
Last updated: 14 June 2026 Language: English international version
Reference language: French

This English version is provided for international users. The operator of Hermes Layer remains a French business, and the French version remains the reference version in case of inconsistency, unless mandatory law provides otherwise.

This Data Processing Addendum, or DPA, supplements the Terms of Use and Terms of Sale of Hermes Layer where a customer uses the service to process personal data on behalf of third parties or in a context where the customer determines the purposes and means of processing.


1. Parties

Processor:
M LOUE XAVIER, individual entrepreneur under French law, operating Hermes Layer
Address: 3 Impasse Denis Papin, 44310 Saint-Philbert-de-Grand-Lieu, France
SIREN: 891 108 615
VAT: FR37 891108615
Privacy email: [email protected]

Customer / Controller:
The professional natural or legal person subscribing to Hermes Layer and using the service to process personal data in its own business context.

The Customer and Hermes Layer are together the “Parties”.


2. Subject matter

This DPA defines the conditions under which Hermes Layer processes personal data on behalf of the Customer in connection with the service.

It applies in particular to processing activities relating to:

  • hosting of the Hermes Agent workspace;
  • the authenticated WebUI gateway;
  • prompts, files, outputs, logs, configurations, secrets and data introduced into the workspace;
  • backups, exports and restores;
  • support where the Customer communicates personal data;
  • Managed AI requests when the Customer chooses this mode;
  • connectors or providers selected by the Customer, to the extent Hermes Layer technically participates in their transmission or hosting.

This DPA does not apply to processing activities for which Hermes Layer acts as an independent controller, including account, billing, security, tax, Stripe, payment evidence, disputes, legal compliance, Hermes Layer’s own commercial communications or internal administration.


3. Contractual hierarchy

In case of inconsistency:

  1. this DPA prevails for personal data processing carried out on behalf of the Customer;
  2. the Terms of Sale prevail for price, payment, refund and subscription matters;
  3. the Terms of Use prevail for usage rules;
  4. the Privacy Policy describes processing activities where Hermes Layer acts as data controller.

4. Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, “sub-processor” and “supervisory authority” have the meanings given by the GDPR where it applies.

Customer Data means data, content, files, prompts, outputs, logs, configurations or information processed in the service on behalf of the Customer.

Customer Personal Data means Customer Data that constitutes personal data.


5. Customer instructions

Hermes Layer processes Customer Personal Data only on documented instructions from the Customer, including:

  • the Terms of Use;
  • the Terms of Sale;
  • this DPA;
  • account settings;
  • user actions in the service;
  • support requests;
  • provider, model, connector, backup and Managed AI configurations;
  • any written instruction accepted by Hermes Layer.

If Hermes Layer believes that an instruction infringes applicable law, it informs the Customer to the extent permitted by law. Hermes Layer may refuse an illegal, dangerous, technically impossible or security-incompatible instruction.

The Customer acknowledges that use of connectors, BYOK AI providers, repositories, external tools or Managed AI constitutes an instruction to transmit or make certain data available to those providers.


6. Description of processing

The detailed description of processing is set out in Annex 1.


7. Customer obligations

The Customer warrants that it:

  • has a legal basis for processing Customer Personal Data;
  • informs data subjects;
  • obtains required consents where necessary;
  • does not import prohibited, unlawful or excessive data;
  • does not use Hermes Layer for high-risk uses without an appropriate framework;
  • complies with applicable laws, including GDPR, ePrivacy, local data protection laws, AI rules and sectoral obligations;
  • correctly configures its providers, keys, connectors and prompts;
  • limits data introduced into the service to what is necessary;
  • responds to data subject requests, unless assistance is requested from Hermes Layer.

The Customer must not use Hermes Layer to process health data, biometric identification data, criminal offense data, minors’ data or other sensitive data at scale without a written agreement and appropriate measures.


8. Confidentiality

Hermes Layer ensures that persons authorized to process Customer Personal Data are subject to an appropriate confidentiality obligation.

Internal access is limited to operational, support, security, maintenance, compliance or legal defense needs.


9. Security measures

Hermes Layer implements technical and organizational measures appropriate to the risk, including those described in Annex 2.

The Customer acknowledges that security also depends on:

  • the strength of its passwords;
  • the confidentiality of its API keys;
  • the configuration of its connectors;
  • permissions granted to its users;
  • the data it imports;
  • third-party providers it chooses;
  • its own organizational measures.

10. Sub-processors

The Customer authorizes Hermes Layer to use sub-processors to provide the service, provided that Hermes Layer imposes data protection obligations on those sub-processors that are substantially equivalent to those of this DPA.

The initial list of known categories and sub-processors appears in Annex 3.

Hermes Layer may replace or add a sub-processor. Where the change is material, Hermes Layer may inform the Customer by email, notification or publication. The Customer may object on reasonable data protection grounds within 15 days. If no reasonable solution is possible, the Customer may terminate the affected service in accordance with the Terms of Sale.

Providers chosen directly by the Customer in its workspace, including BYOK keys, models, connectors, Git repositories, external APIs or MCP tools, are not necessarily Hermes Layer sub-processors; they may be Customer providers under the Customer’s responsibility.


11. International transfers

Hermes Layer may process or transfer Customer Personal Data outside the European Economic Area where necessary for the service, including through Stripe, SendGrid, OpenRouter, AI providers, hosting, storage or support.

Where the GDPR applies and a transfer outside the EEA is not covered by an adequacy decision, Hermes Layer relies on an appropriate transfer mechanism, including the European Commission Standard Contractual Clauses and, where necessary, additional measures.

The Customer authorizes Hermes Layer to enter into the applicable modules of the Standard Contractual Clauses with the relevant sub-processors.


12. Assistance to the Customer

Taking into account the nature of the processing, Hermes Layer reasonably assists the Customer to:

  • respond to access, rectification, erasure, restriction, objection or portability requests;
  • provide information necessary for a data protection impact assessment;
  • notify and document a personal data breach;
  • satisfy security obligations;
  • demonstrate processing compliance.

This assistance may be charged if it exceeds standard support, unless a contrary legal obligation applies or Hermes Layer is at fault.


13. Data subject requests

If Hermes Layer directly receives a request relating to Customer Personal Data for which the Customer is controller, Hermes Layer may:

  • invite the person to contact the Customer;
  • forward the request to the Customer if the Customer is identifiable;
  • respond directly where the request concerns Hermes Layer’s own processing as controller.

Hermes Layer does not substantively respond to a request concerning Customer Personal Data without the Customer’s instruction, unless legally required.


14. Personal data breaches

Hermes Layer informs the Customer without undue delay after becoming aware of a breach of Customer Personal Data affecting the service.

The notification contains, to the extent available:

  • the nature of the breach;
  • categories of data and data subjects concerned;
  • likely consequences;
  • measures taken or proposed;
  • contact details;
  • any information useful for possible notification to an authority or to data subjects.

Hermes Layer may provide information in stages if all information is not immediately available.

The Customer remains responsible for determining whether notification to the supervisory authority or data subjects is required.


15. Audits and compliance information

Hermes Layer makes available information reasonably necessary to demonstrate compliance with this DPA.

The Customer may request a reasonable audit, subject to:

  • reasonable written notice;
  • a scope limited to the relevant service;
  • confidentiality;
  • no risk to other customers, secrets, security or infrastructure;
  • a reasonable number of audits;
  • reimbursement of reasonable costs if the audit exceeds standard information.

Hermes Layer may refuse any audit that would require access to secrets, keys, other customers’ data, raw runtime, internal infrastructure, non-public source code or sensitive security information.


16. Return and deletion of data

At the end of the contract or upon an applicable Customer request, Hermes Layer deletes or returns Customer Personal Data within a reasonable period, subject to:

  • legal obligations;
  • technical backups;
  • purge periods;
  • payment evidence, disputes, tax or security;
  • data necessary for defense of rights;
  • data processed as an independent controller.

The Customer must export its data and backups before access ends.

Data present in backups may remain until expiry of their retention cycle, then be deleted or overwritten according to technical processes.


17. Processing as independent controller

Hermes Layer remains an independent controller in particular for:

  • user account;
  • authentication;
  • security logs and rate limits;
  • billing and Stripe;
  • tax and accounting;
  • customer support;
  • disputes, chargebacks, payment evidence;
  • service security;
  • internal administration;
  • operational communications;
  • compliance with legal obligations.

These processing activities are described in the Privacy Policy.


18. U.S. privacy laws

Where U.S. privacy laws apply to the Customer, including CCPA/CPRA or similar state laws, Hermes Layer undertakes, for Customer Personal Data processed as processor or service provider:

  • to process data only to provide the service;
  • not to sell Customer Personal Data;
  • not to share it for cross-context behavioral advertising;
  • not to use it for Hermes Layer’s own commercial purposes incompatible with the service;
  • to reasonably assist the Customer in complying with applicable rights;
  • to impose appropriate obligations on sub-processors.

19. Liability

Hermes Layer’s liability under this DPA is subject to the limitations set out in the Terms of Use and Terms of Sale, unless a mandatory provision provides otherwise.

No limitation applies where liability cannot legally be limited.


20. Term

This DPA remains in force as long as Hermes Layer processes Customer Personal Data on behalf of the Customer.

Certain obligations, including confidentiality, security, deletion, evidence, reasonable audit and limitations, survive the end of the contract for as long as necessary.


Annex 1 — Description of processing

A. Subject matter

Provision of a hosted SaaS service allowing the Customer to use a managed Hermes Agent with WebUI, isolated runtime, authenticated gateway, backups, support, billing, Managed AI and configurable integrations.

B. Duration

Duration of the contract, then the period necessary for return, deletion, backups, legal obligations, disputes and defense of rights.

C. Nature of operations

Collection, receipt, hosting, storage, organization, consultation, transmission, proxying, backup, restore, export, deletion, encryption, logging, securing, support, technical analysis, rate limiting and contractual evidence.

D. Purposes

  • provide the Hermes Agent workspace;
  • authenticate access;
  • verify active subscription;
  • operate the WebUI and gateway;
  • allow prompts, outputs, files, tasks, logs, connectors and agentic operations;
  • manage backups and restores;
  • transmit data to providers selected by the Customer;
  • provide Managed AI if activated;
  • provide support, maintenance, security and service evidence.

E. Categories of data subjects

Depending on the Customer’s use:

  • Customer users;
  • employees, contractors and collaborators;
  • customers, prospects or contacts of the Customer;
  • persons mentioned in files, prompts, outputs, tickets or imported data;
  • account administrators and operators;
  • third parties whose data is voluntarily processed by the Customer.

F. Categories of data

Depending on the Customer’s use:

  • professional identity and contact data;
  • technical identifiers;
  • textual content;
  • prompts and instructions;
  • AI outputs;
  • files, documents, code and repositories;
  • agent and terminal logs;
  • project data;
  • configuration data;
  • secrets, keys or secret references;
  • support tickets;
  • usage metadata;
  • backup data;
  • incidental personal data present in Customer Content.

G. Sensitive data

The service is not intended for processing sensitive or regulated data, unless a written agreement and appropriate framework are in place. If the Customer introduces such data without agreement, the Customer assumes responsibility.


Annex 2 — Technical and organizational measures

Hermes Layer implements, according to the state of the service and applicable plan:

  1. account authentication;
  2. secure session cookies in production;
  3. CSRF protection;
  4. hashed passwords;
  5. rate limiting on login, reset and contact;
  6. isolation by workspace;
  7. private runtime not directly exposed;
  8. authenticated gateway with active subscription and workspace ownership checks;
  9. separation between SaaS control plane and tenant runtime;
  10. PostgreSQL JSONB storage for control data;
  11. encryption of secrets and sensitive keys;
  12. encrypted and validated backups;
  13. manifest and checksums for exports;
  14. limitation of information exposed to the browser;
  15. role-based admin and support access;
  16. redaction of sensitive information in previews and emails;
  17. audit logs;
  18. minimized, HMAC and/or encrypted Stripe evidence;
  19. non-exposure policy for runtime URLs, Docker internals, keys and secrets;
  20. mandatory HTTPS in production;
  21. pinned runtime images and no latest in production;
  22. signed Stripe webhook;
  23. production configuration validation;
  24. S3-compatible storage for production backups;
  25. observability and evidence events with configured retention;
  26. billing-related suspension/resumption procedures;
  27. controlled restore mechanisms;
  28. access control for Stripe dispute actions.

Annex 3 — Sub-processors and providers

The list below reflects the providers and categories necessary for the current or planned service. It must be kept up to date in production.

Provider / categoryRoleData concernedIndicative location
StripePayment, Checkout, Customer Portal, Stripe Tax, receipts, refunds, disputesbilling identity, payment, taxes, receipts, payment evidenceEU / United States / global
SendGrid / Twilio SendGridTransactional and support emailsemail, name, limited excerpts, service linksUnited States / global
OpenRouterManaged AI gateway and accessible modelsprompts, messages, outputs, usage, costs, workspace keysUnited States / global
AI providers selected by the CustomerBYOK, models, connectorsdata sent by the Customer or its agentaccording to provider
OVHcloud / OVH SASApplication and runtime hostingservice and workspace dataFrance / European Union
PostgreSQL / production databaseControl dataaccounts, subscriptions, logs, support, evidence, metadataaccording to infrastructure
S3-compatible storageEncrypted backupsworkspace archives, backups, manifests, checksumsaccording to provider
ClickHouse or equivalent observabilityObservability and technical timelinessanitized events, operational analytics, disputesaccording to infrastructure
DNS / reverse proxy / network securityService accesstechnical network metadataaccording to provider

Where another production storage, database, observability or network provider is later added, Hermes Layer must publish or communicate the corresponding information before full commercial launch.

Hermes Layer

Hosted AI agent workspaces built around Hermes WebUI. Independent service; not affiliated with Nous Research or the Hermes WebUI maintainers.

Hermes hostingAI automationPricingFAQBlogContactHermes WebUI
PrivacyTerms of UseTerms of SaleRefundsDPALegal Notice