Privacy policy
HERA CREATIVES — Privacy Policy
Effective date: 16 September 2026
Last updated: 16 September 2026
HERA CREATIVES (“HERA,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit https://heracreatives.com, contact us, request a consultation, purchase services or merchandise, or otherwise interact with us.
1. Who We Are
HERA CREATIVES is a brand strategy and marketing agency providing creative services, custom design, branding, marketing, digital presence, brand strategy, and branded merchandise.
For applicable data protection laws, HERA CREATIVES is the data controller responsible for personal data collected through our website and ordinary business activities.
Legal entity: [Full legal entity name and legal form]
Registered or business address: 7435 North Figueroa Street, Eagle Rock, CA, USA
Privacy contact: [Privacy contact name or department]
Email: info@heracreatives.com
Website: https://heracreatives.com
When HERA processes personal data on behalf of a client as part of a marketing, branding, or creative project, the client may be the data controller and HERA may act as a processor. In those circumstances, the applicable client agreement or data processing agreement may govern the processing.
2. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
2.1 Information You Provide Directly
This may include:
- Name, job title, company name, and business contact details;
- Email address, telephone number, postal address, and social media details;
- Information provided when requesting a consultation or submitting an inquiry;
- Project briefs, brand information, preferences, feedback, and communications;
- Information contained in documents, images, files, or other materials you send to us;
- Billing, transaction, delivery, and account information where relevant;
- Marketing preferences and consent records; and
- Information provided when applying for employment, collaboration, or partnership opportunities.
Please avoid sending sensitive personal data through website forms or ordinary email unless it is necessary and we have provided a secure method for doing so.
2.2 Information Collected Automatically
When you use our website, we may collect technical and usage information, including:
- IP address and approximate location;
- Browser type, operating system, device type, and language settings;
- Website pages visited, links clicked, referring website, and access times;
- Website performance, diagnostic, and security information; and
- Cookie identifiers and similar online identifiers.
Some of this information may constitute personal data under applicable law.
2.3 Information from Other Sources
We may receive personal data from:
- Business partners, professional advisers, or service providers;
- Publicly available business or professional sources;
- A client or another person who is authorized to provide information;
- Scheduling, consultation, hosting, account-management, or communication platforms; and
- Social media platforms or other third-party services, where permitted by your settings and applicable law.
3. How We Use Personal Data
We may use personal data to:
- Respond to inquiries and provide requested information;
- Schedule, administer, and conduct consultations;
- Prepare proposals, quotations, contracts, invoices, and project documentation;
- Provide branding, marketing, design, strategy, merchandise, and other services;
- Communicate about projects, accounts, orders, and business relationships;
- Customize and improve our services, website, and customer experience;
- Manage our business operations, accounts, records, and internal administration;
- Send marketing communications where permitted by law;
- Maintain website security, prevent fraud, and investigate misuse;
- Comply with legal, regulatory, tax, accounting, and professional obligations;
- Exercise or defend legal rights and resolve disputes;
- Evaluate or manage a merger, acquisition, financing, restructuring, or sale of assets; and
- Use appropriate technology, including artificial intelligence tools, to support creative ideation, administration, data organization, and workflow management.
We will not use personal data for a new purpose that is incompatible with the purpose for which it was collected unless permitted or required by law. Where required, we will provide additional notice or obtain consent.
4. Legal Bases for Processing
Where the GDPR, UK GDPR, or a similar law applies, we generally rely on one or more of the following legal bases:
Where we rely on legitimate interests, we consider whether those interests are proportionate and whether they are overridden by your privacy rights.
You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Artificial Intelligence and Automated Tools
HERA may use artificial intelligence and other automated tools to help:
- Generate creative ideas, concepts, outlines, or draft content;
- Organize, summarize, or classify business information;
- Support project administration and workflow management;
- Improve internal efficiency and service delivery;
- Assist with research, analysis, and quality control; and
- Identify technical, security, or operational issues.
AI tools are used as support systems and do not replace professional judgment. We apply human review to material outputs before relying on them for client-facing or significant business purposes.
We aim to:
- Use data minimization and provide only information reasonably necessary for the relevant task;
- Avoid submitting sensitive personal data to AI tools unless there is a lawful and necessary reason to do so;
- Configure providers, where available, not to use submitted data to train publicly available models;
- Use contractual, technical, and organizational safeguards appropriate to the risk;
- Review AI-generated content for accuracy, confidentiality, bias, and suitability; and
- Maintain appropriate records of material AI-related processing.
Unless separately disclosed and legally permitted, HERA does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals. If such processing is introduced, we will provide the information and safeguards required by applicable law, including information about the logic involved and the right to request human intervention where applicable.
Where an external AI provider processes personal data, that provider may act as a processor or independent controller depending on the service and the relevant arrangement. The current provider information may be requested from us at [Privacy email address]. We will update this Policy when there is a material change to our AI-related processing.
6. Third-Party Service Providers
We may disclose personal data to trusted service providers that process data on our behalf or provide services necessary for our operations. These providers may include:
6.1 HelloBonsai
We may use HelloBonsai to assist with consultation scheduling, client administration, project-related communications, proposals, contracts, invoicing, or related business processes, depending on the features we use.
Information shared with HelloBonsai may include your name, contact details, company information, consultation details, project information, and transaction-related information.
HelloBonsai may process personal data under its own privacy policy and contractual terms. You should review the applicable HelloBonsai privacy information for details about its processing.
6.2 GoDaddy
We use GoDaddy for website hosting, domains, hosting-related services, business accounts, and associated technical or administrative services.
GoDaddy may process information such as IP addresses, technical logs, account details, domain information, email-related data, and information submitted through hosted services.
GoDaddy may process data under its own privacy policy and contractual terms. You should review GoDaddy’s privacy information for details about its processing and international transfer practices.
6.3 Other Service Providers
Other recipients may include:
- Website, cloud storage, email, communications, scheduling, and information-technology providers;
- Payment processors, accounting providers, insurers, and professional advisers;
- Printing, production, shipping, and merchandise fulfillment partners;
- Analytics, security, and fraud-prevention providers;
- Government bodies, regulators, courts, or law-enforcement authorities where required; and
- A purchaser, successor, or adviser involved in a corporate transaction.
We do not sell personal data for monetary consideration. We do not disclose personal data to third parties for their independent direct marketing unless permitted by law and, where required, with your consent.
7. International Data Transfers
Some service providers may process personal data in countries outside your country of residence, including countries that may not provide the same level of data protection.
Where required by applicable law, we use an appropriate transfer mechanism, which may include:
- A decision that the destination country provides adequate protection;
- Standard contractual clauses or equivalent contractual safeguards;
- Approved certification mechanisms; or
- Another lawful transfer exception.
You may request further information about applicable transfer safeguards by contacting us at info@heracreatives.com.
8. Cookies and Similar Technologies
Our website may use cookies, pixels, local storage, and similar technologies.
8.1 Types of Cookies
Cookies may be used for the following purposes:
- Strictly necessary cookies: Required for website operation, security, session management, and basic functionality;
- Preference cookies: Remember settings and choices;
- Analytics cookies: Help us understand website use and improve performance; and
- Marketing or advertising cookies: Used, where applicable, to measure campaigns or deliver more relevant communications.
Strictly necessary cookies may be used where permitted without consent. We will request consent before placing or using non-essential cookies where applicable law requires consent.
8.2 Managing Cookies
You may manage optional cookies through our cookie banner or settings tool, where available. You may also adjust your browser settings to block or delete cookies. Disabling certain cookies may affect website functionality.
Cookie duration and provider information may vary depending on the technologies active on the website. Our cookie notice or settings tool may provide additional details.
Where third-party services are embedded in the website, those services may place their own cookies or similar technologies. Their use of such technologies is governed by their own policies and applicable consent requirements.
9. Marketing Communications
We may send information about HERA’s services, projects, events, offers, or related business updates where permitted by law.
You may unsubscribe from marketing emails at any time by:
- Clicking the unsubscribe link in the communication;
- Contacting us at [Privacy email address]; or
- Using any available communication-preference tool.
Unsubscribing from marketing communications will not prevent us from sending essential service, contractual, account, security, or legal notices.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to meet contractual, legal, accounting, tax, insurance, dispute-resolution, and security requirements.
Retention periods may include:
- Inquiries and consultation records: Generally for up to 24 months after the last meaningful interaction, unless a longer period is reasonably necessary;
- Client, project, contract, billing, and transaction records: For the duration of the relationship and thereafter for the period required by applicable legal, accounting, tax, or dispute-resolution requirements;
- Marketing preferences and suppression records: Until you withdraw consent or object, after which limited information may be retained to ensure that your preference is respected;
- Website security and technical logs: For a period reasonably necessary for security, troubleshooting, fraud prevention, and legal purposes;
- Cookie data: For the period stated in the relevant cookie information or until consent is withdrawn, where applicable;
- AI prompts, outputs, and workflow records: Only for as long as reasonably necessary for the relevant business purpose, subject to the settings and retention terms of the applicable provider; and
- Privacy-rights requests: For a period reasonably necessary to document and demonstrate compliance.
When personal data is no longer required, we will securely delete it, anonymize it, or otherwise dispose of it in accordance with our retention practices.
11. Data Security
We use reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
These safeguards may include access controls, authentication, confidentiality obligations, secure service providers, backups, monitoring, staff awareness, and procedures for handling security incidents.
No method of transmission or storage is completely secure. You should use appropriate care when sending information online and contact us promptly if you believe your interaction with us may have been compromised.
Where required by applicable law, we will notify affected individuals and relevant authorities of a personal-data breach.
12. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
- Request access to personal data we hold about you;
- Request correction of inaccurate or incomplete personal data;
- Request deletion or erasure of personal data;
- Request restriction of processing;
- Object to processing based on legitimate interests;
- Object to direct marketing at any time;
- Request portability of personal data that you provided to us;
- Withdraw consent where processing is based on consent;
- Request information about automated decision-making and AI-related processing;
- Request human intervention where applicable;
- Complain to a data protection or privacy supervisory authority; and
- Challenge a decision relating to your privacy rights where permitted by law.
These rights are not absolute. We may lawfully retain or process certain personal data where necessary to comply with legal obligations, establish or defend legal claims, protect security, exercise freedom of expression, or satisfy another applicable legal exception.
13. How to Submit a Data Request
To exercise a privacy right, contact us using:
Email: info@heracreatives.com
Postal address: 7435 North Figueroa Street, Eagle Rock, CA, USA
Subject line: Privacy Rights Request
Your request should identify:
- Your name and contact information;
- The right you wish to exercise;
- The personal data or processing concerned; and
- Any information that will help us locate the relevant records.
We may request reasonable information to verify your identity and protect personal data from unauthorized disclosure. We will not request more information than reasonably necessary for verification.
We generally respond to valid requests within one month. Where a request is complex or numerous, the response period may be extended by up to two additional months where permitted by law. We will inform you of any extension and the reason for it.
14. Data Deletion and Right to Be Forgotten
You may request deletion of your personal data where applicable law provides a right to erasure. We will assess each request and determine whether deletion is required or permitted.
Our deletion process generally involves:
- Receiving and acknowledging your request;
- Verifying your identity where reasonably necessary;
- Identifying the relevant personal data and systems;
- Deleting, anonymizing, or restricting the data where legally required;
- Referring deletion instructions to relevant service providers where required;
- Retaining only information that is legally required or reasonably necessary for a permitted purpose; and
- Providing a written response explaining the outcome.
Some information may not be immediately removed from disaster-recovery backups. Where this occurs, the information will be isolated from ordinary use and deleted or overwritten in accordance with the applicable backup cycle.
We may refuse or limit deletion where retaining the information is necessary for legal compliance, contractual obligations, security, fraud prevention, legal claims, freedom of expression, or another applicable exception. If we cannot comply fully, we will explain the reason where legally permitted.
15. Children’s Privacy
Our website and services are directed primarily to businesses, professionals, entrepreneurs, and established brands. They are not directed to children.
We do not knowingly collect personal data from children below the age permitted by applicable law. If you believe that a child has provided personal data to us, please contact us at [Privacy email address]. We will assess the request and take appropriate steps where required.
16. Third-Party Websites and Links
Our website may contain links to third-party websites, platforms, social media pages, or services. We are not responsible for the privacy practices, content, security, or policies of third parties.
You should review the privacy policy of each third-party website or service before providing personal data.
17. Complaints
If you have a concern about our use of your personal data, please contact us first so that we can investigate and attempt to resolve the issue.
You may also lodge a complaint with the data protection or privacy supervisory authority in your country, place of residence, place of work, or the location where you believe a violation occurred.
Relevant supervisory authority: [Name and contact details of applicable data protection authority]
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal obligations, third-party providers, AI usage, cookies, or business practices.
The updated version will be posted on this page with a revised “Last updated” date. Where required, we will provide additional notice or obtain consent for material changes.
19. Contact HERA CREATIVES
For questions, concerns, privacy requests, or requests for additional information about our data practices, contact:
HERA CREATIVES
Legal entity: HERA Creatives LLC
Address: 7435 North Figueroa Street, Eagle Rock, CA, USA
Email: info@heracreatives.com
Website: https://heracreatives.com