Legal
Privacy Policy
Last updated: May 28, 2026
1. Who We Are
Hermes Local ("we", "us", "our") is a
Canadian sole proprietorship providing self-hosted AI
agent consulting, setup, and maintenance services for
small and local businesses.
Website:
hermeslocal.work
Email:
hello@hermeslocal.work
2. What Information We Collect
In the course of providing server setup and maintenance
services, we may collect and store the following:
-
SSH private keys — for secure
remote access to servers we manage on your behalf
-
Sign-in credentials (usernames,
passwords) — held temporarily during setup,
migration, or support sessions
-
Server connection details — IP
addresses, hostnames, and port configurations
-
Service notes — technical
documentation necessary for ongoing maintenance
We do not collect credit card numbers,
banking details, social insurance numbers, or any
information beyond what is required to deliver our
services.
3. Why We Collect It
We collect this information solely to perform the
services you have engaged us for:
-
Setting up and configuring your self-hosted AI
infrastructure
-
Performing migrations, updates, and troubleshooting
-
Maintaining secure, ongoing access to infrastructure
we manage
- Providing technical support when you request it
We do not use your credentials or personal
information for any purpose beyond delivering the
services you've requested. We do not sell, rent, or
share your information with any third party.
4. How It's Stored
All credentials are stored in a
self-hosted Bitwarden vault — an
open-source, zero-knowledge encrypted password manager.
-
Self-hosted — your data never
leaves infrastructure we control. It is not stored
on any third-party cloud service.
-
Zero-knowledge encryption — the
vault is encrypted at rest using AES-256. Even we
cannot access it without the master password.
-
Two-factor authentication — vault
access requires a second authentication factor.
-
No plaintext storage — credentials
are never written to plain text files, emails, chat
messages, or unencrypted notes.
5. Temporary Credentials
Sign-in credentials you provide for setup, migration, or
support are treated as temporary:
-
Deleted from our vault within
7 days of the task being completed
-
We recommend you
rotate any passwords shared with us
after our work is complete
-
SSH keys retained for ongoing management are kept
only for the duration of our service agreement
6. Who Has Access
Only the principal operator of Hermes Local has access
to stored credentials. No employees, contractors, or
third parties are granted access unless explicitly
authorised by you in writing.
7. Retention & Deletion
-
SSH keys: retained for the duration
of our active service agreement
-
Temporary sign-in credentials:
deleted within 7 days of task completion
-
Upon service termination: all
credentials and access data deleted within 30 days
-
Deletion confirmation provided in
writing upon request
8. Your Rights Under PIPEDA
Under Canada's
Personal Information Protection and Electronic
Documents Act
(PIPEDA), you have the right to:
-
Access — request a copy of all
personal information we hold about you
-
Correct — request correction of any
inaccurate information
-
Withdraw consent — at any time,
subject to legal or contractual obligations
-
Request deletion — ask us to delete
your data, and we will comply within 30 days
-
File a complaint — with the Office
of the Privacy Commissioner of Canada at
www.priv.gc.ca
To exercise any of these rights, contact us at
hello@hermeslocal.work. We will respond within 30 days.
9. Security Safeguards
We take reasonable steps to protect your information
against unauthorized access, disclosure, or misuse:
-
Self-hosted, open-source password vault (Bitwarden)
— no third-party cloud dependency
- AES-256 encryption at rest
- Two-factor authentication on vault access
-
Temporary credentials deleted promptly after use
-
No credentials stored in plaintext or unencrypted
formats
-
Regular review of stored credentials to remove
entries no longer needed
10. Data Breach Response
In the unlikely event of a security breach involving
your credentials, we will:
-
Notify you within 72 hours of
discovering the breach
-
Provide details of what information was affected
-
Take immediate steps to contain and remediate the
breach
-
Report to the Privacy Commissioner of Canada if the
breach poses a real risk of significant harm, as
required under PIPEDA
11. Children's Privacy
Our services are intended for business clients. We do
not knowingly collect personal information from
individuals under the age of 18.
12. Changes to This Policy
We may update this privacy policy from time to time.
Material changes will be communicated via our website.
The "Last updated" date at the top reflects the most
recent revision.