Privacy Policy

Last updated: May 28, 2026

1. Who We Are

Hermes Local ("we", "us", "our") is a Canadian sole proprietorship providing self-hosted AI agent consulting, setup, and maintenance services for small and local businesses.

Website: hermeslocal.work
Email: hello@hermeslocal.work

2. What Information We Collect

In the course of providing server setup and maintenance services, we may collect and store the following:

  • SSH private keys — for secure remote access to servers we manage on your behalf
  • Sign-in credentials (usernames, passwords) — held temporarily during setup, migration, or support sessions
  • Server connection details — IP addresses, hostnames, and port configurations
  • Service notes — technical documentation necessary for ongoing maintenance

We do not collect credit card numbers, banking details, social insurance numbers, or any information beyond what is required to deliver our services.

3. Why We Collect It

We collect this information solely to perform the services you have engaged us for:

  • Setting up and configuring your self-hosted AI infrastructure
  • Performing migrations, updates, and troubleshooting
  • Maintaining secure, ongoing access to infrastructure we manage
  • Providing technical support when you request it

We do not use your credentials or personal information for any purpose beyond delivering the services you've requested. We do not sell, rent, or share your information with any third party.

4. How It's Stored

All credentials are stored in a self-hosted Bitwarden vault — an open-source, zero-knowledge encrypted password manager.

  • Self-hosted — your data never leaves infrastructure we control. It is not stored on any third-party cloud service.
  • Zero-knowledge encryption — the vault is encrypted at rest using AES-256. Even we cannot access it without the master password.
  • Two-factor authentication — vault access requires a second authentication factor.
  • No plaintext storage — credentials are never written to plain text files, emails, chat messages, or unencrypted notes.

5. Temporary Credentials

Sign-in credentials you provide for setup, migration, or support are treated as temporary:

  • Deleted from our vault within 7 days of the task being completed
  • We recommend you rotate any passwords shared with us after our work is complete
  • SSH keys retained for ongoing management are kept only for the duration of our service agreement

6. Who Has Access

Only the principal operator of Hermes Local has access to stored credentials. No employees, contractors, or third parties are granted access unless explicitly authorised by you in writing.

7. Retention & Deletion

  • SSH keys: retained for the duration of our active service agreement
  • Temporary sign-in credentials: deleted within 7 days of task completion
  • Upon service termination: all credentials and access data deleted within 30 days
  • Deletion confirmation provided in writing upon request

8. Your Rights Under PIPEDA

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access — request a copy of all personal information we hold about you
  • Correct — request correction of any inaccurate information
  • Withdraw consent — at any time, subject to legal or contractual obligations
  • Request deletion — ask us to delete your data, and we will comply within 30 days
  • File a complaint — with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

To exercise any of these rights, contact us at hello@hermeslocal.work. We will respond within 30 days.

9. Security Safeguards

We take reasonable steps to protect your information against unauthorized access, disclosure, or misuse:

  • Self-hosted, open-source password vault (Bitwarden) — no third-party cloud dependency
  • AES-256 encryption at rest
  • Two-factor authentication on vault access
  • Temporary credentials deleted promptly after use
  • No credentials stored in plaintext or unencrypted formats
  • Regular review of stored credentials to remove entries no longer needed

10. Data Breach Response

In the unlikely event of a security breach involving your credentials, we will:

  • Notify you within 72 hours of discovering the breach
  • Provide details of what information was affected
  • Take immediate steps to contain and remediate the breach
  • Report to the Privacy Commissioner of Canada if the breach poses a real risk of significant harm, as required under PIPEDA

11. Children's Privacy

Our services are intended for business clients. We do not knowingly collect personal information from individuals under the age of 18.

12. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via our website. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For any privacy-related questions or requests:

Hermes Local
Email: hello@hermeslocal.work
Web: hermeslocal.work