Privacy Policy — Hermes Layer
Version: 1.0
Last updated: 14 June 2026 Language: English international version
Reference language: French
This English version is provided for international users. The operator of Hermes Layer remains a French business, and the French version remains the reference version in case of inconsistency, unless mandatory law provides otherwise.
This Privacy Policy explains how Hermes Layer collects, uses, retains, protects and shares personal data in connection with the website, the SaaS application, access control, billing, support, hosted Hermes Agent workspaces, backups, Managed AI credits and related processing activities.
Hermes Layer is a professional service published by:
M LOUE XAVIER, individual entrepreneur under French law
Address: 3 Impasse Denis Papin, 44310 Saint-Philbert-de-Grand-Lieu, France
SIREN: 891 108 615
Intra-community VAT number: FR37 891108615
General email: [email protected]
Support email: [email protected]
Privacy / data protection email: [email protected]
For processing activities that Hermes Layer determines for its own purposes, the publisher acts as data controller. For certain processing activities performed in a hosted Hermes Agent workspace on behalf of a professional customer, Hermes Layer may act as the customer’s processor within the meaning of Article 28 of the GDPR; those processing activities are governed by the Hermes Layer Data Processing Addendum.
1. Scope
This Policy applies to:
- visitors to
hermes-layer.com; - persons who create an account or log in to Hermes Layer;
- customers and authorized users of a hosted Hermes Agent workspace;
- persons who contact Hermes Layer through the public contact form or authenticated support;
- data subjects whose data is imported, entered, generated, transmitted, backed up or processed in a Hermes Agent workspace by a customer.
The service is primarily intended for professional users. It is not intended for minors or consumers acting exclusively for personal purposes, unless specifically accepted in writing by the publisher.
2. Roles of Hermes Layer
2.1 Hermes Layer as data controller
Hermes Layer acts as data controller in particular for:
- management of the public website and contact requests;
- account creation and management;
- authentication, sessions, security and abuse prevention;
- commercial management, billing, subscriptions, Stripe payments, Stripe Tax and payment disputes;
- customer support and transactional communications;
- audit logs, contractual evidence, delivery evidence and defense materials in the event of a Stripe dispute;
- internal operations, administration, observability and security.
2.2 Hermes Layer as the customer’s processor
Hermes Layer acts as processor when the customer uses the service to host, transmit, back up or restore content, files, prompts, outputs, logs, project data, secrets, connectors or other information belonging to the customer or to its own users, employees, collaborators or third parties.
In that case, the customer remains responsible for the lawfulness, quality, notices and legal bases relating to the data it introduces into its Hermes Agent workspace. The applicable terms are set out in the Data Processing Addendum.
3. Data collected
Hermes Layer collects only the data necessary for operation, security, billing, support, reasonable improvement and proof of the service.
3.1 Public visit and contact data
When a person uses the public website or the contact form, Hermes Layer may process:
- name;
- email address;
- company or organization;
- request category;
- subject;
- message;
- browser language;
- user-agent;
- referring URL;
- hashed IP address used for rate limiting and spam prevention;
- deterministic moderation signals, not based on an AI automated decision;
- message date and status.
The anti-spam “honeypot” field, where present, is used only to detect automated submissions.
3.2 Account and authentication data
When creating and using an account, Hermes Layer may process:
- name;
- email address;
- password in hashed form;
- account role: user, support or administrator;
- account creation and update dates;
- hashed session tokens;
- CSRF tokens;
- password reset requests in the form of hashed tokens;
- audit logs relating to registration, login, profile update, password change and role changes;
- information required to limit login attempts, including hashed IP address and hashed email.
Session cookies are used to maintain authentication. The session cookie is configured as HttpOnly; a separate CSRF cookie is used to protect sensitive requests.
3.3 Payment, subscription and tax data
Hermes Layer uses Stripe Checkout, Stripe Customer Portal, Stripe Tax and signed Stripe webhooks. The data processed may include:
- selected plan: Launch, Build, Operate or Dedicated;
- subscription status: active, trialing, past_due, unpaid, canceled, incomplete or equivalent;
- Stripe identifiers: customer, checkout session, subscription, invoice, payment intent, charge, event, dispute;
- amount, currency, taxes, discounts and information needed to calculate VAT or applicable taxes;
- billing address, name and email provided during payment;
- VAT number or tax identifier if provided through Stripe;
- payment evidence: receipt, invoice, 3D Secure status, CVC/AVS checks, card brand, last four digits, card country, Radar risk level where available;
- history of payment, refund, subscription and dispute webhooks.
Hermes Layer does not store full bank card numbers. Full card data is processed by Stripe under Stripe’s own terms and policies.
3.4 Hermes Agent workspace, runtime, files and backup data
When a user accesses a hosted Hermes Agent workspace, Hermes Layer may process, host or transmit:
- workspace identifiers, workspace status, provisioning state and runtime health;
- settings, preferences, profiles, sessions, scheduled tasks, kanban, working files, agent logs, application logs, AI provider settings and WebUI configurations;
- content, prompts, instructions, outputs, imported files, code, Git repository data, terminal data and generated results;
- secrets or secret references required for connectors or providers selected by the customer;
- data required for backups, exports and restores: manifest, checksums, volume archive, runtime version, date, status, size, validation and restore state.
Runtimes are isolated by account or workspace. Raw runtime ports, internal URLs, runtime API keys, container names, local paths, S3 keys and secrets are not exposed to the customer’s browser.
3.5 Managed AI data and prepaid credits
When the customer uses Managed AI credits, Hermes Layer may process:
- credit balance in EUR cents;
- credits purchased, granted, spent, refunded and temporarily held;
- Stripe payment reservations linked to top-ups;
- provider routing, billing conversion, generation identifier, token count and usage metadata;
- prompts, messages and payloads transmitted to OpenRouter or to a model provider available through OpenRouter;
- workspace OpenRouter key or encrypted references when the Managed AI gateway is used;
- payment and usage evidence associated with top-ups.
Before each Managed AI request, Hermes Layer checks access rights, active subscription and prepaid balance. If the balance is insufficient, the request is rejected before contacting the AI provider.
3.6 Support and customer relationship data
Hermes Layer may process:
- support tickets;
- ticket categories;
- subjects and messages;
- replies from the support team;
- redacted excerpts sent by transactional email;
- status, timestamps and audit logs;
- attachments and information voluntarily provided by the customer.
Email notifications normally contain only a limited excerpt and a link to the authenticated support area.
3.7 Administration, observability and Stripe evidence data
Hermes Layer may process technical logs and events relating to:
- public funnel events such as pricing view, signup start, checkout start and contact submission;
- checkout creation;
- checkout synchronization;
- subscription status changes;
- agent openings;
- provisioning, suspension, resumption or runtime errors;
- backups, exports and restores;
- purchases, consumption and refunds of Managed AI credits;
- support tickets;
- Stripe disputes;
- administrator actions.
For Stripe disputes, Hermes Layer may retain a frozen evidence snapshot at the time of payment, including plan information, payment details, receipt, payment method, security checks, access evidence, integrity hash, timestamp and applicable contractual policy. A full IP address, when retained for dispute defense, is minimized, HMAC-correlated and encrypted.
4. Purposes and legal bases
Hermes Layer processes data for the following purposes and legal bases.
| Purpose | Main legal basis |
|---|---|
| Account creation and management | Performance of the contract or pre-contractual steps |
| Authentication, sessions, CSRF and security | Performance of the contract and legitimate interest in security |
| Provision of the workspace, WebUI, runtime, backups, support and Managed AI | Performance of the contract |
| Billing, taxes, accounting and receipts | Legal obligation and performance of the contract |
| Stripe Checkout, Customer Portal, webhooks and access activation | Performance of the contract |
| Fraud prevention, abuse prevention, rate limiting and spam prevention | Legitimate interest |
| Dispute handling, chargebacks, delivery evidence and defense of legal claims | Legitimate interest and legal obligation depending on the case |
| Customer support and transactional communications | Performance of the contract and legitimate interest |
| Observability, audit, reliability and operational supervision | Legitimate interest |
| Strictly necessary cookies | Legitimate interest or ePrivacy exemption depending on the case |
| Non-necessary cookies, marketing or non-exempt analytics | Consent |
| Response to privacy requests and exercise of rights | Legal obligation |
5. Recipients and processors
Data may be accessible, as needed, to the following categories:
- authorized Hermes Layer staff or contractors, only according to their role;
- Stripe, for payments, billing, Stripe Tax, Customer Portal, refunds and disputes;
- SendGrid or an equivalent transactional email provider, for account, support, payment or notification emails;
- OpenRouter and AI providers available through OpenRouter, only when Managed AI is used;
- AI providers or connectors configured by the customer in its own Hermes Agent workspace;
- hosting provider, dedicated server or VM, database, S3-compatible storage, observability and network services used for production;
- advisors, experts, authorities, courts or payment intermediaries where necessary for compliance, collection, fraud prevention or defense of rights.
When a customer chooses its own providers, API keys, connectors, models or Git repositories in the Hermes Agent workspace, those third parties are chosen by the customer and may process data under their own terms. The customer must ensure it has the necessary rights, contracts and notices to use them.
6. Transfers outside the European Union
Hermes Layer targets customers in Europe, the United States and Asia. Certain recipients may be located outside the European Economic Area.
Where personal data is transferred outside the EEA, Hermes Layer relies, as applicable, on:
- an adequacy decision of the European Commission;
- the European Commission Standard Contractual Clauses;
- additional security or minimization measures;
- the contract concluded with the customer;
- another applicable legal basis.
Processing entrusted by a professional customer is also governed by the Data Processing Addendum, which specifies the applicable transfer mechanisms.
7. Cookies, local storage and similar technologies
Hermes Layer uses cookies or similar technologies necessary for the operation of the service, including:
- session cookie
hl_session; - CSRF cookie
hl_csrf; - possible technical cookies related to security, navigation, Stripe Checkout or the Customer Portal;
- local storage strictly necessary for interface operation, where applicable.
These cookies are used to provide a service explicitly requested, secure access, maintain the session and prevent unauthorized requests.
Hermes Layer may record first-party, cookie-free public funnel events for internal statistics and operational monitoring. These events do not use GA4, Google Ads tags, retargeting pixels or a persistent browser identifier.
Hermes Layer must only place advertising, retargeting, social media or non-exempt analytics cookies after prior notice and consent where required by law. If an exempt audience measurement tool is used, it must be configured in a limited, proportionate, non-intrusive manner and in compliance with applicable requirements.
8. Retention periods
The periods below are maximum indicative periods, unless a contrary legal obligation, applicable deletion request, dispute, evidentiary retention or specific contractual configuration applies.
| Category | Indicative retention period |
|---|---|
| Active account | Duration of the account |
| Sessions | Up to 14 days, unless renewed or deleted earlier |
| Reset tokens | Limited validity, normally 60 minutes; tokens are stored in hashed form |
| Public contact data | Up to 3 years after the last exchange, unless dispute or contrary obligation |
| Authenticated support | Duration of the account, then reasonable archiving up to 3 years, unless dispute |
| Billing data, receipts, accounting and tax records | Up to 10 years where required by law |
| Stripe events, subscriptions and payment evidence | Period necessary for billing, audits, disputes and legal obligations |
| Stripe evidence, snapshots, litigation hold and defense materials | Duration of the dispute, chargeback periods and applicable limitation periods |
| Security logs and rate limits | Proportionate security period, generally no more than 12 months unless incident or dispute |
| ClickHouse / raw observability data | Configured period, by default up to 365 days for raw events |
| Flushed analytics outbox | Configured period, by default 7 days |
| Workspace, files, prompts, outputs, agent logs and configurations | Duration of the account or contract, then deletion or return according to the DPA and backup constraints |
| Scheduled backups | According to the plan or configuration retention policy; by default older scheduled backups may be pruned beyond the retained count |
| Manual backups or exports | Until deletion by the customer, end of contract or expiry of the applicable retention period |
| Managed AI credits and ledger | Period necessary for balance management, accounting, proof and refunds |
Data present in backups may remain for the technical retention period of the backups before final deletion.
9. Security
Hermes Layer implements appropriate technical and organizational measures, including:
- session-based authentication;
- CSRF protection;
- hashed passwords;
- rate limiting on login, reset and public forms;
- separation between SaaS control plane and tenant runtime;
- private runtime not directly exposed to the browser;
- workspace ownership verification;
- active subscription requirement for runtime access;
- encryption of secrets and certain artifacts;
- encrypted and validated backups;
- minimized, HMAC and/or encrypted storage of sensitive dispute evidence;
- role-based admin and support access;
- redaction of sensitive data in previews and notifications;
- audit logging;
- HTTPS in production.
No security measure is absolute. Customers must also protect their credentials, API keys, connectors, secrets, repositories and imported data.
10. Sensitive data and prohibited content
Hermes Layer is not designed to process health data, biometric identification data, data concerning minors, criminal offense data, highly regulated secrets or other sensitive categories, unless a written agreement and an appropriate legal framework are in place.
The customer must not import sensitive data into Hermes Layer without an appropriate legal basis, information to data subjects, suitable security measures and, where applicable, a specific contractual agreement.
11. Minors
Hermes Layer is intended for adult professionals. The service is not intended for children or minors under 16 in the European Union or under 13 in the United States. Hermes Layer does not knowingly collect children’s data for commercial purposes.
If you believe that a minor has provided personal data without authorization, contact: [email protected].
12. AI, prompts, outputs and transparency
Hermes Layer enables the use of AI agents, BYOK providers and/or Managed AI via OpenRouter. Users are informed that they interact with AI systems or tools that may generate automated responses.
Prompts, files, instructions and outputs may be transmitted to AI providers chosen by the customer or to the Managed AI gateway. Outputs may be inaccurate, incomplete, biased or unsuitable. The customer must verify them before any external use or any decision that may affect persons.
When the customer publishes or transmits to third parties content generated or substantially modified by AI, the customer is responsible for complying with applicable transparency, labeling, disclosure or human review obligations, in particular where such content concerns matters of public interest or may be perceived as authentic.
13. Automated decisions
Hermes Layer does not, for its own purposes, make automated decisions producing legal effects or similarly significantly affecting a person within the meaning of the GDPR.
The contact form may use deterministic anti-spam moderation to classify a message as spam. This classification does not produce legal effects and may be reviewed by the team.
If a customer configures automated workflows in its Hermes Agent workspace that affect third parties, the customer remains responsible for their compliance.
14. Data subject rights
Depending on applicable law, you may have the following rights:
- access to your data;
- rectification;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent where the processing is based on consent;
- post-mortem instructions where French law applies;
- complaint with a supervisory authority.
To exercise your rights: [email protected].
Hermes Layer may request reasonable additional information to verify your identity. Where Hermes Layer acts as a customer’s processor, the request may need to be addressed to the customer acting as controller.
In France, you may lodge a complaint with the CNIL.
15. Additional information for California residents and certain U.S. states
Where applicable U.S. law provides for it, including the CCPA/CPRA if Hermes Layer meets the applicable thresholds, data subjects may have additional rights: to know the categories of data collected, to request access, deletion, correction, opt-out of sale or sharing, limit the use of certain sensitive data and not be discriminated against.
Hermes Layer does not sell personal data in the ordinary meaning of the term and does not share it for cross-context behavioral advertising, unless a future change is clearly announced and an applicable opt-out mechanism is provided.
Requests may be sent to: [email protected].
16. Additional information for Asia-Pacific
Hermes Layer may be accessible from certain Asian countries. Rights and obligations may vary depending on the country, including Singapore, Japan, South Korea, India, mainland China or other jurisdictions.
Where applicable local law requires it, Hermes Layer will handle requests relating to access, correction, deletion, withdrawal of consent, international transfers or complaints according to the applicable rules. Requests may be sent to: [email protected].
Customers who use Hermes Layer to process data subject to a specific local law must verify their own compliance and inform Hermes Layer if a processing activity imposes particular contractual or technical requirements.
17. Changes to this Policy
Hermes Layer may amend this Policy to reflect changes to the service, processing activities, providers or applicable law.
The applicable version is the version published at the time of use of the service, unless another version is contractually accepted. In the event of a material change, Hermes Layer may inform users by email, in-service notification or website notice.
18. Contact
For any question about this Policy or data protection:
Hermes Layer / M LOUE XAVIER
3 Impasse Denis Papin, 44310 Saint-Philbert-de-Grand-Lieu, France
Privacy email: [email protected]
General email: [email protected]