This Privacy Policy explains how quantumSCALE Institute OÜ, a private limited company registered in Estonia under registry code 16075477 ("we", "us", "the Service Provider"), collects, uses, and protects personal data in connection with the Hermes Calendar Automation Application, its dashboard, and the website at hermes.quantum-scaling.com (together, "the App").
1. Our Role: Controller and Processor
Depending on the data involved, we act in two capacities:
- As controller for the personal data of our clients and their authorized users — account details, login credentials, billing information, and usage data.
- As processor for prospect and recipient personal data (such as names, email addresses, and invitation responses) that clients upload to or connect with the App. For that data, the client is the controller and determines the purposes of the processing. If you are a prospect or invitation recipient and wish to exercise your rights over that data, please contact the organization that invited you; we will assist them in responding.
2. Data We Collect
2.1 Account and billing data (we are controller)
- Name, business email address, company name, and role (Executive or Assistant user)
- Login credentials and permission settings
- Subscription tier, billing records, and payment status
- Support communications
2.2 Connected account data (via integrations)
- Google Workspace / Google Calendar: with your authorization via Google OAuth, the App accesses your calendar to create and send calendar invitations from your connected sending domains, manage invitation queues, and read invitation response status.
- WebinarGeek / Zoom: registration and attendance signals used to automatically log "YES" and "MAYBE" prospect responses.
- Custom sending domains: domain names and technical configuration required to send invitations.
If a Google Workspace administrator connects the workspace itself, additional read-only permissions may be granted so that sending mailboxes can be listed and sending limits applied correctly. The exact permissions requested at any given time — and what each one is used for — are set out in What Skarpe Accesses. We link it rather than listing the scopes here, because a list copied into this page would silently stop matching what is actually requested. You can review and withdraw every granted permission at myaccount.google.com/permissions.
2.3 Prospect and campaign data (we are processor)
- Recipient names and email addresses uploaded or synced by the client
- Invitation delivery status and responses (Yes / No / Maybe)
- Campaign performance metrics shown in the dashboard
2.4 Technical and usage data
- Log data such as IP address, browser type, timestamps, and actions taken in the App, used for security, troubleshooting, and service improvement
- In-app navigation within the embedded Calendar Automation screen. Calendar Automation runs inside the App as an embedded view provided by our sub-processor Skarpe (section 5). As you move between its pages, that view reports the page path back to the App — for example /dashboard/campaigns?status=active — so that the App can keep the browser address bar in step and your back button and bookmarks work. It tells us which screen you are on; it does not carry any contact, recipient, or campaign content.
3. Google User Data and Limited Use
Limited Use disclosure. Hermes' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, regarding data accessed through Google APIs (including Google Calendar data):
- We only use Google user data to provide and improve the App's user-facing calendar automation features — creating, sending, queuing, and tracking calendar invitations, and displaying campaign metrics to you.
- We do not transfer Google user data to third parties except as necessary to provide the App's features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising purposes.
- We do not allow humans to read Google user data unless (a) you have given explicit permission, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
You can revoke the App's access to your Google account at any time from your Google Account security settings at myaccount.google.com/permissions.
4. Why We Process Data and Legal Bases
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the App — sending invitations, syncing responses, displaying dashboards | Performance of a contract (Art. 6(1)(b)) |
| Billing and account administration | Performance of a contract; legal obligation (Art. 6(1)(b), (c)) |
| Security, abuse prevention, enforcing sending limits | Legitimate interests (Art. 6(1)(f)) |
| Service improvement and troubleshooting | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance, accounting, and dispute resolution | Legal obligation; legitimate interests (Art. 6(1)(c), (f)) |
| Processing prospect data in campaigns | On the client's documented instructions (Art. 28) — the client is responsible for its own legal basis |
5. Sharing and Sub-Processors
We do not sell personal data. We share data only with:
- Integrated platforms you connect: Google (Workspace / Calendar), WebinarGeek, and Zoom, strictly as required to operate your campaigns.
- The sub-processors named below, each bound by a data processing agreement.
- Professional advisers and authorities where required by law or to protect our legal rights.
5.1 Named sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Skarpe | The calendar automation platform behind Hermes: it stores your contact lists and campaigns, connects to your Google accounts, and sends the invitations. Its documents are linked in 5.2. | Hungary (EU) |
| Render Services, Inc. | Application and API hosting | United States |
| Supabase, Inc. | Database and authentication for the platform | EU / United States |
| Resend (Plus Five Five, Inc.) | Transactional email — invitations, password resets, and internal notifications | United States |
| Whop Inc. | Subscription billing and payment processing | United States |
We will give you at least 30 days' notice before adding or replacing a sub-processor, so that you have a reasonable opportunity to object before the change takes effect. Notice is given by email to your account's billing contact and by updating this page.
5.2 Skarpe's own documents
Because Skarpe processes your contact and campaign data on our instruction, its terms are the ones that apply to that data at the platform level. We link them rather than reproducing them here, so that what you read is always current rather than a copy of ours that has quietly gone out of date:
- What Skarpe Accesses — plain-English detail of exactly what is reached in a connected Google account, and what happens to an uploaded list.
- Skarpe Data Processing Addendum — the GDPR Article 28 terms, security measures, and its own authorized sub-processors. This is the document to give your legal team.
- Skarpe Privacy Policy
Your contact and campaign data is not shared with any other client of ours or of Skarpe: each account is isolated at the database level. It is not sent to any AI or machine-learning provider, and is not used to train models.
6. International Transfers
We are established in Estonia (EU/EEA). Where personal data is transferred outside the EU/EEA — for example to service providers in the United States — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified).
7. Retention
- Account data: retained for the duration of your subscription and up to 7 years afterwards where required for accounting and legal obligations.
- Campaign and prospect data: retained while your subscription is active. After termination, data is available for export for 30 days and then deleted or anonymized, unless the client instructs otherwise or law requires retention.
- Google user data: retained only as long as needed to provide the App's features; deleted promptly when you disconnect your Google account or delete your Hermes account.
- Log data: retained for up to 12 months for security purposes.
Contact and campaign data physically lives on the Skarpe platform (section 5). Rather than restate its retention and access rules here — where a copy would drift out of date without anyone noticing — see What Skarpe Accesses for the authoritative detail. Where the two differ, the shorter of the two retention periods is what we will apply to your data.
8. Security
We apply technical and organizational measures appropriate to the risk, including encrypted connections (TLS), access controls with distinct Executive and Assistant permission levels, credential management, and monitoring of sending activity. No system is completely secure; we will notify affected parties and authorities of personal data breaches where required by law.
9. Your Rights
If you are in the EU/EEA or a jurisdiction with similar laws, you have the right to request access to, rectification of, or erasure of your personal data; restriction of or objection to processing; and data portability. Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, contact us using the details below. You also have the right to lodge a complaint with a supervisory authority — in our case, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) — or with the authority in your country of residence.
If you are a prospect or invitation recipient, the organization that invited you is the controller of your data; please direct requests to them, and we will support their response as processor.
9.1 Who answers a request about campaign data
So that nobody is passed back and forth:
- Requests about your own account — your name, email, login, billing — come to us at the address in section 13.
- Requests about people on your lists are yours to answer: you decide who is contacted, so you are the controller of that data. You can do it yourself in the App — individual contacts, whole lists, and campaigns can be deleted at any time, and removing a recipient also adds them to your suppression list so a later import cannot reintroduce them.
- If a recipient contacts us directly, we will pass the request to you rather than acting on your data unilaterally, and we can suppress the address immediately so that no further invitations reach them while you respond.
10. Cookies
The App uses strictly necessary cookies and similar technologies for authentication, session management, and security. We do not use advertising or cross-site tracking cookies on the App.
11. Children
The App is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the App or by email before they take effect. The effective date at the top of this page indicates the latest revision.
13. Contact
quantumSCALE Institute OÜ
Registry code: 16075477
Narva mnt 5, Kesklinna linnaosa
Tallinn, Harju maakond 10117, Estonia
Email: privacy@quantum-scaling.com