Hermes Calendar Automation

Privacy Policy

Effective date: 11 August 2026 · quantumSCALE Institute OÜ

This Privacy Policy explains how quantumSCALE Institute OÜ, a private limited company registered in Estonia under registry code 16075477 ("we", "us", "the Service Provider"), collects, uses, and protects personal data in connection with the Hermes Calendar Automation Application, its dashboard, and the website at hermes.quantum-scaling.com (together, "the App").

1. Our Role: Controller and Processor

Depending on the data involved, we act in two capacities:

2. Data We Collect

2.1 Account and billing data (we are controller)

2.2 Connected account data (via integrations)

If a Google Workspace administrator connects the workspace itself, additional read-only permissions may be granted so that sending mailboxes can be listed and sending limits applied correctly. The exact permissions requested at any given time — and what each one is used for — are set out in What Skarpe Accesses. We link it rather than listing the scopes here, because a list copied into this page would silently stop matching what is actually requested. You can review and withdraw every granted permission at myaccount.google.com/permissions.

2.3 Prospect and campaign data (we are processor)

2.4 Technical and usage data

3. Google User Data and Limited Use

Limited Use disclosure. Hermes' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, regarding data accessed through Google APIs (including Google Calendar data):

You can revoke the App's access to your Google account at any time from your Google Account security settings at myaccount.google.com/permissions.

4. Why We Process Data and Legal Bases

PurposeLegal Basis (GDPR)
Providing the App — sending invitations, syncing responses, displaying dashboardsPerformance of a contract (Art. 6(1)(b))
Billing and account administrationPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Security, abuse prevention, enforcing sending limitsLegitimate interests (Art. 6(1)(f))
Service improvement and troubleshootingLegitimate interests (Art. 6(1)(f))
Legal compliance, accounting, and dispute resolutionLegal obligation; legitimate interests (Art. 6(1)(c), (f))
Processing prospect data in campaignsOn the client's documented instructions (Art. 28) — the client is responsible for its own legal basis

5. Sharing and Sub-Processors

We do not sell personal data. We share data only with:

5.1 Named sub-processors

Sub-processorRoleLocation
Skarpe The calendar automation platform behind Hermes: it stores your contact lists and campaigns, connects to your Google accounts, and sends the invitations. Its documents are linked in 5.2. Hungary (EU)
Render Services, Inc. Application and API hosting United States
Supabase, Inc. Database and authentication for the platform EU / United States
Resend (Plus Five Five, Inc.) Transactional email — invitations, password resets, and internal notifications United States
Whop Inc. Subscription billing and payment processing United States

We will give you at least 30 days' notice before adding or replacing a sub-processor, so that you have a reasonable opportunity to object before the change takes effect. Notice is given by email to your account's billing contact and by updating this page.

5.2 Skarpe's own documents

Because Skarpe processes your contact and campaign data on our instruction, its terms are the ones that apply to that data at the platform level. We link them rather than reproducing them here, so that what you read is always current rather than a copy of ours that has quietly gone out of date:

Your contact and campaign data is not shared with any other client of ours or of Skarpe: each account is isolated at the database level. It is not sent to any AI or machine-learning provider, and is not used to train models.

6. International Transfers

We are established in Estonia (EU/EEA). Where personal data is transferred outside the EU/EEA — for example to service providers in the United States — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified).

7. Retention

Contact and campaign data physically lives on the Skarpe platform (section 5). Rather than restate its retention and access rules here — where a copy would drift out of date without anyone noticing — see What Skarpe Accesses for the authoritative detail. Where the two differ, the shorter of the two retention periods is what we will apply to your data.

8. Security

We apply technical and organizational measures appropriate to the risk, including encrypted connections (TLS), access controls with distinct Executive and Assistant permission levels, credential management, and monitoring of sending activity. No system is completely secure; we will notify affected parties and authorities of personal data breaches where required by law.

9. Your Rights

If you are in the EU/EEA or a jurisdiction with similar laws, you have the right to request access to, rectification of, or erasure of your personal data; restriction of or objection to processing; and data portability. Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact us using the details below. You also have the right to lodge a complaint with a supervisory authority — in our case, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) — or with the authority in your country of residence.

If you are a prospect or invitation recipient, the organization that invited you is the controller of your data; please direct requests to them, and we will support their response as processor.

9.1 Who answers a request about campaign data

So that nobody is passed back and forth:

10. Cookies

The App uses strictly necessary cookies and similar technologies for authentication, session management, and security. We do not use advertising or cross-site tracking cookies on the App.

11. Children

The App is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from minors.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the App or by email before they take effect. The effective date at the top of this page indicates the latest revision.

13. Contact

quantumSCALE Institute OÜ
Registry code: 16075477
Narva mnt 5, Kesklinna linnaosa
Tallinn, Harju maakond 10117, Estonia
Email: privacy@quantum-scaling.com