Privacy Policy
Controller: Bizr Single-Member P.C., trading as hermespms, AFM TBD, Athens, Greece. Contact: [email protected].
This policy describes how Bizr processes personal data through the hermespms.com marketing site and the HERMES PMS service, in our capacity as controller of visitor and prospect data. For guest data that flows through a hotelier’s HERMES account, the hotelier is the controller and Bizr acts as a processor under our Data Processing Addendum.
1. Who we are
Bizr Single-Member P.C. is the legal entity that operates HERMES PMS. We are established in Greece and subject to GDPR (Regulation (EU) 2016/679) as supplemented by Greek Law 4624/2019. The Greek supervisory authority is the Hellenic Data Protection Authority (HDPA).
2. What data we collect on this website
| Purpose | Data | Legal basis |
|---|---|---|
You sign up for HERMES via the form on hermespms.com | Business name, contact email, intended domain, optional AFM / DOY / GEMI, plan choice, the IP address of the submitting browser | Pre-contract (Art. 6(1)(b) GDPR) — necessary to provision your tenant |
| You contact us ([email protected] or contact form) | Email address, message content | Legitimate interest (Art. 6(1)(f)) — responding to inbound enquiries |
| Anti-abuse rate limiting on signup endpoint | Source IP held for 60 seconds in Redis | Legitimate interest — protecting the service from spam signups |
| Server-side error tracking (Sentry) | Stack traces with PII scrubbed; request URL without query string | Legitimate interest — keeping the service reliable |
| Uptime monitoring (Better Stack) | HTTP status codes against public endpoints | Legitimate interest — keeping the service reliable |
We do not use Google Analytics, Facebook Pixel, or any other cross-site tracker on hermespms.com. The site sets one strictly-necessary session cookie when you complete signup; no consent banner is shown because no non-essential cookies are set.
3. What data we hold once you become a HERMES tenant
When you become a paying or trialing tenant, we additionally process:
- Account data: business name, billing email, slug, domain, plan, AFM / DOY / GEMI, Cloudflare zone ID, Resend domain ID, Stalwart domain ID, the Stripe customer ID returned on signup.
- Authentication data: the email and bcrypt-hashed password of users you create under your tenant; Sanctum API token hashes.
- Mailbox credentials: when we provision a mailbox we store its password encrypted-at-rest. The encryption key never leaves the Hetzner box.
- Service telemetry: application logs (Laravel), webhook payloads from Stripe / Channex / Resend (retained 30 days then expired by Better Stack).
We act as controller for all data in this section — it is necessary to provide HERMES to you as a customer.
4. Guest data (controller = hotelier, processor = Bizr)
When your guests interact with your HERMES instance — reservations, ledger entries, payments, mailbox messages, calendar events — Bizr processes that data on your instruction as your processor. The legal terms are in our DPA. In particular, Bizr will not access the personal data of your guests except to deliver the service, investigate a security incident, or comply with a legal obligation.
5. Where the data lives & who can see it
All HERMES production data lives in our Hetzner data centre in Falkenstein, Germany (EEA). The sub-processors below also see specific subsets — the full live list lives in our internal sub-processor register, with the canonical contents:
- Infrastructure (intra-EEA): Hetzner (compute + DB + mail), Backblaze B2 EU (encrypted off-site backup), Cloudflare (DNS only — your tenant site is not proxied).
- Payments (intra-EEA, tokenized): Stripe IE (HERMES subscription), Viva Wallet GR (guest payments).
- OTA bridge (UK GDPR-adequate): Channex.io — only when you connect an OTA channel.
- Outbound mail (EU region): Resend.com via
eu-west-1. - AI (US, EU SCCs, zero-retention): Anthropic — only when you enable AI-assisted drafting at the property level.
- Observability (mixed): Sentry (US, SCCs), Better Stack (CZ).
6. How long we keep it
| Data | Retention |
|---|---|
| Application logs (Sentry, Better Stack) | 30 days |
| OTA audit logs | 90 days (Channex / Booking.com requirement) |
| Marketing-site form submissions never converted to tenants | 12 months |
| Tenant account + guest data, while the tenant is active | For the life of the contract |
| Tenant account + guest data, after termination | 30 days in production (allows reactivation), then deleted; encrypted backups expire on a 35-day rolling schedule |
| AADE / myDATA invoice records (held by Elorus) | 5 years (Greek tax law) — Bizr does not control this retention |
| Stripe subscription + payment records | 7 years (Greek tax + accounting law) — Stripe controls retention |
7. Your rights
Under GDPR you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). You also have the right to lodge a complaint with the HDPA.
To exercise a right, email [email protected] with proof of identity. We respond within 30 days. For data held by a hotelier through HERMES, please contact the hotelier directly first; we will assist them in fulfilling the request.
We do not engage in solely-automated decision-making with legal or similarly significant effect (Art. 22 GDPR). AI-assisted draft messages are advisory and require the hotelier’s explicit send.
8. Security
HERMES production runs in a Coolify-managed Docker stack on Hetzner with TLS terminating at Traefik (Let’s Encrypt). Admin access is restricted to a WireGuard tunnel. Card data is never stored; payment forms tokenize client-side (PCI SAQ-A). Mailbox passwords and Elorus API tokens are stored encrypted-at-rest.
9. Changes to this policy
Material changes are announced ≥ 14 days in advance by email to all active tenants. Non-material changes (typos, link fixes) are made silently.
10. Contact
Bizr Single-Member P.C. Email: [email protected] Postal address: TBD — Athens, Greece.