Privacy Policy

Hercules Automation LLC

Effective Date: June 12, 2026 | Last Revised: June 12, 2026

1. About This Policy

Hercules Automation LLC (“Hercules Automation,” “we,” “us,” or “our”) provides AI-powered voice agents, workflow automation, document processing, CRM integration, scheduling systems, inbox management, and related automation services to small and mid-size businesses. Our registered place of business is in New York, NY.

This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website (herculesautomated.com), contact us, or engage us to provide services. It also explains the rights you may have regarding your personal information.

If you are a business client, this Policy governs information about your representatives and contacts. The handling of your customers’ data processed through the automations we build for you is governed separately by the Data Processing Agreement (“DPA”) or Master Services Agreement (“MSA”) between us.

2. Contact Information

For any questions, requests, or concerns about this Policy or our privacy practices, please contact:

Hercules Automation LLC

Email: privacy@herculesautomated.com

Website: herculesautomated.com/contact

Location: New York, NY, United States

We will respond to all verifiable requests within 30 days (GDPR) or 45 days (CCPA), with one possible 45-day extension where reasonably necessary.

3. Information We Collect

3a. Information You Provide Directly

When you contact us, submit a form, book a discovery call, or engage our services, we may collect:

  • Identity information: name, business name, job title
  • Contact information: email address, phone number, mailing address
  • Scheduling information: calendar availability, meeting preferences
  • Project and scoping details: workflow descriptions, goals, pain points
  • Files and documents: samples, templates, or examples you share for scoping or delivery
  • Billing and payment details: invoicing information (we do not store payment card numbers)

3b. Website and Usage Data

When you visit our website, we and our service providers may automatically collect:

  • Technical data: IP address, device type, operating system, browser type and version
  • Usage data: pages visited, time on page, referring URL, links clicked, form interactions
  • Cookie and tracking data: see Section 7 (Cookies) below

3c. Call and Voice Data

If you or your business contacts interact with an AI voice agent we operate or have deployed, we may collect:

  • Call metadata: caller ID, call duration, time and date, call outcome
  • Call recordings and transcripts: subject to applicable consent and disclosure requirements (see Section 9)
  • Voice inputs: audio processed by our AI voice platform to generate responses

3d. Client Workflow Data

When we build or operate automations on your behalf, we may process business records, CRM data, customer communications, scheduling entries, documents, and other operational data you or your systems make available to us. We act as a data processor for this information; your privacy obligations to your own customers remain your responsibility and are addressed in your DPA with us.

4. How We Use Information and Our Legal Basis

We use personal information for the following purposes. Where GDPR applies, we identify the lawful basis for each:

  • Responding to inquiries and scheduling calls — Lawful basis: Legitimate interests / Pre-contractual steps
  • Evaluating automation opportunities and preparing proposals — Lawful basis: Pre-contractual steps
  • Providing, testing, monitoring, and improving contracted automation services — Lawful basis: Performance of contract
  • Sending invoices and managing billing — Lawful basis: Performance of contract / Legal obligation
  • Sending relevant service and business communications — Lawful basis: Legitimate interests
  • Sending marketing emails to prospects (with opt-out) — Lawful basis: Legitimate interests (or Consent where required)
  • Maintaining records and complying with legal obligations — Lawful basis: Legal obligation
  • Operating, securing, and improving our website — Lawful basis: Legitimate interests
  • Preventing fraud, abuse, or misuse of our systems — Lawful basis: Legitimate interests / Legal obligation

We do not use personal information for automated decision-making that produces legal or similarly significant effects without human oversight. If an automation we build for a client incorporates such decisions, this will be disclosed in the applicable SOW and DPA.

5. How We Share Information

We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.

We may share information in the following limited circumstances:

5a. Service Providers and Sub-processors

We use trusted third-party platforms to deliver our services. These providers process data on our behalf and are contractually required to protect it. Categories include:

  • Cloud hosting and infrastructure
  • Workflow automation platforms (e.g., n8n)
  • AI voice and telephony platforms (e.g., Retell AI)
  • AI language model providers
  • CRM and business management software
  • Email delivery and marketing platforms (e.g., Brevo)
  • Scheduling and calendar tools
  • Analytics and website performance tools
  • Accounting and invoicing platforms

Each provider operates under its own privacy and security terms. Upon request, we can provide a current list of key sub-processors.

5b. Legal Requirements and Protection

We may disclose information if required by law, regulation, court order, or governmental authority, or where necessary to protect the rights, property, or safety of Hercules Automation, our clients, or others.

5c. Business Transfers

If Hercules Automation is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice before personal information is transferred and becomes subject to a different privacy policy.

6. International Data Transfers

Hercules Automation is based in the United States. If you are located outside the US, please be aware that information you provide will be transferred to and processed in the United States, which may have data protection laws different from those in your country.

When we transfer personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland to third countries, we rely on appropriate safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission or UK equivalent mechanisms. You may request a copy of applicable safeguards by contacting us at privacy@herculesautomated.com.

7. Cookies and Similar Technologies

Our website uses cookies, pixels, and similar tracking technologies for the following purposes:

  • Strictly necessary: keeping the site functioning, remembering session state
  • Analytics and performance: understanding how visitors interact with our site (e.g., pages visited, traffic sources)
  • Marketing: measuring the effectiveness of outreach and improving our messaging

Non-essential cookies (analytics, marketing) are placed only with your consent where required by applicable law. A cookie consent banner on our website allows you to accept or reject non-essential cookies.

You may also control cookies through your browser settings. Disabling certain cookies may affect the functionality of parts of our website. For more information, visit allaboutcookies.org.

8. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy. Our general retention guidelines are:

  • Prospect and inquiry data: up to 24 months from last contact, then deleted or anonymized
  • Active client data: for the duration of the engagement plus 3 years for accounting and legal purposes
  • Call recordings and transcripts: 90 days, unless a longer period is required by law or agreed in writing
  • Website analytics data: up to 26 months (per standard analytics platform settings)
  • Financial and billing records: 7 years as required by US tax and accounting laws
  • Legal hold data: retained as required by applicable legal proceedings

When retention periods expire, we delete or de-identify personal information using reasonable technical measures.

9. Call Recording and AI Voice Agent Disclosures

Hercules Automation deploys AI-powered voice agents for inbound call handling on behalf of clients. The following disclosures apply:

Recording Consent

Calls handled by AI voice agents may be recorded and transcribed for quality assurance, training, and service delivery purposes. Callers are informed at the start of a call that they are speaking with an automated system and that the call may be recorded. Continued participation constitutes consent to recording under applicable one-party and two-party consent laws.

State-Specific Compliance

Call recording laws vary by state. In two-party (all-party) consent states — including California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington — all parties must consent to recording. Our voice agent scripts are configured to obtain affirmative consent in these states before recording begins. Clients are responsible for informing us of the jurisdictions in which their callers are located so we can configure disclosures appropriately.

TCPA Compliance

Our inbound voice agents respond to calls initiated by end users and do not place unsolicited outbound calls using auto-dialers. If outbound calling campaigns are scoped as an add-on service, a separate TCPA compliance addendum will govern that engagement.

AI Disclosure

Callers are informed at the beginning of each interaction that they are communicating with an automated AI system, not a human agent. This disclosure is provided clearly and before any personal information is requested.

10. Data Security

We implement reasonable administrative, technical, and organizational security measures designed to protect personal information from unauthorized access, disclosure, loss, misuse, alteration, or destruction. These measures include encryption in transit, access controls, vendor security assessments, and periodic review of our practices.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Data Breach Notification

In the event of a data breach that affects personal information and triggers notification obligations under applicable law, we will notify affected individuals and relevant supervisory authorities within the timeframes required by law (e.g., 72 hours for GDPR supervisory authority notification; applicable US state law timeframes for individual notification).

11. Your Privacy Rights

All Users

Regardless of your location, you may:

  • Request access to personal information we hold about you
  • Request correction of inaccurate personal information
  • Request deletion of personal information, subject to legal or contractual retention requirements
  • Unsubscribe from marketing emails via the unsubscribe link in any email or by contacting us

California Residents (CCPA / CPRA)

California residents have the following additional rights:

  • Right to Know: request details about the categories and specific pieces of personal information we have collected about you
  • Right to Delete: request deletion of personal information we collected from you
  • Right to Correct: request correction of inaccurate personal information
  • Right to Opt-Out: we do not sell personal information or share it for cross-context behavioral advertising, so no opt-out is currently required; however, you may direct any related request to us
  • Right to Limit Use of Sensitive Personal Information: to the extent we collect sensitive personal information (as defined by CPRA), you may request we limit its use to purposes permitted by law
  • Right to Non-Discrimination: we will not discriminate against you for exercising any CCPA/CPRA rights

To submit a California privacy rights request, contact us at privacy@herculesautomated.com. We will verify your identity before processing your request and respond within 45 days (with one possible 45-day extension).

EEA, UK, and Swiss Residents (GDPR / UK GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under applicable data protection law:

  • Right of access (Article 15 GDPR)
  • Right to rectification (Article 16 GDPR)
  • Right to erasure / right to be forgotten (Article 17 GDPR)
  • Right to restriction of processing (Article 18 GDPR)
  • Right to data portability (Article 20 GDPR)
  • Right to object to processing based on legitimate interests (Article 21 GDPR)
  • Right to withdraw consent at any time, where processing is based on consent
  • Right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, or your EU member state’s data protection authority)

To exercise any of these rights, contact us at privacy@herculesautomated.com. We will respond within 30 days, with a possible 60-day extension for complex requests.

12. Business Client Data Processing

When Hercules Automation processes personal data on behalf of a business client in the course of delivering automation services, we act as a data processor (under GDPR) or service provider (under CCPA). The client is the data controller / business.

Our data processing activities in this context are governed by the Data Processing Agreement (DPA) executed between us and the client, which includes:

  • Instructions for processing and permitted purposes
  • Technical and organizational security measures
  • Sub-processor disclosures and restrictions
  • Data subject rights assistance obligations
  • Breach notification procedures
  • Data deletion or return upon termination

Business clients are responsible for ensuring they have a lawful basis for sharing data with us and for complying with applicable privacy laws with respect to their own customers.

13. Healthcare and HIPAA

If Hercules Automation is engaged by a healthcare provider, medical clinic, or med spa client that requires handling of Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA), we will execute a Business Associate Agreement (BAA) with that client prior to processing any PHI. We offer HIPAA compliance configurations as a designated add-on service. This general Privacy Policy does not govern PHI; the BAA and applicable HIPAA rules govern that processing.

14. Children’s Privacy

Our website and services are directed to businesses and their professional representatives. We do not knowingly collect personal information from any individual under the age of 18. If you believe we have inadvertently received information from a minor, please contact us at privacy@herculesautomated.com and we will delete it promptly.

15. Third-Party Links and Integrations

Our website and automations may contain links to or integrations with third-party platforms (e.g., booking tools, CRM systems, payment processors). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our website or automations.

16. Do Not Sell or Share My Personal Information

Hercules Automation does not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising as defined under the California Privacy Rights Act (CPRA). If you have questions about this or wish to confirm your data has not been shared, contact us at privacy@herculesautomated.com.

17. Changes to This Policy

We may update this Privacy Policy from time to time as our services, technology, vendors, or legal obligations evolve. When we make material changes, we will update the “Last Revised” date at the top of this Policy and, where required by law or where we consider it appropriate, notify you by email or by a notice on our website.

We encourage you to review this Policy periodically. Continued use of our website or services after changes become effective constitutes acceptance of the revised Policy.

Version History

v1.0 — June 12, 2026 — Initial publication

Questions?

Contact us at privacy@herculesautomated.com.