Last updated: September 13, 2026

Privacy Policy — Hermes Gmail

This notice describes the processing of data when a personal Gmail account is connected to a Hermes profile.

[TO CONFIRM BEFORE GENERAL PUBLICATION] Legal entity, postal address, hosting country, processors, retention periods, encryption at rest, and deletion process.

1. Controller

[TO CONFIRM: legal entity name]. Contact: infos@amazonsellerconsulting.eu. Postal address and country: [TO CONFIRM].

2. Data we process

Depending on the Google permissions you grant, the service may process authorization data such as an OAuth token and, where returned by Google, your email address and a technical account identifier. If a read permission is enabled, it may process Gmail content and metadata, including sender, recipient, subject, date and labels. Attachments are processed only if a real product feature reads them. Security and diagnostic logs may also be processed.

3. Purpose and limited use

Google user data is used only to provide or improve user-facing features that you request, to maintain your Gmail connection, and to secure and diagnose the service. Gmail data is not sold, used for advertising or commercial profiling, or used for generalized model training.

4. Access, sharing and AI processing

You access your own data through your Hermes profile. Data may be processed by hosting infrastructure, necessary technical providers, and authorized personnel strictly within their responsibilities.

[TO CONFIRM] If Gmail content is sent to an AI model provider to fulfill a user request, this section must identify the provider or provider category, applicable safeguards, and purpose limitation before that use is enabled.

5. Storage and security

OAuth tokens must be isolated by user profile so that one user cannot access another user’s Gmail data or tokens. Data is encrypted in transit. Encryption at rest: [TO CONFIRM]. Access controls and profile separation are used to limit access.

6. Retention

[TO CONFIRM] Retention rules for tokens, logs, any content and backups must be documented. The intended rule is retention only while the connection is useful, with deletion on disconnect or account closure subject to documented backup-purge periods.

7. Revocation and deletion

You can revoke access through Google Account permissions. You can request deletion of your OAuth token and related data at infos@amazonsellerconsulting.eu. Process and timeline: [TO CONFIRM].

8. Your rights

Depending on applicable law, you may have rights of access, rectification, erasure, restriction, objection and portability, and a right to lodge a complaint with the appropriate authority. These rights must be adapted and legally reviewed for the applicable jurisdiction.

9. Updates

We may update this notice when the service or its data practices change. The “last updated” date will be revised and users will be notified where appropriate.