Transparency,
in black and white.
Legal notice, privacy, terms of use, GDPR and security. Everything that protects you, written clearly — without needless jargon.
Legal notice
Last updated: 11 August 2026
Publisher
The website available at nexeuro.com is published by:
NexEuro SAS
Simplified joint-stock company (SAS) with share capital of €350,000
Registered office: 75001 Paris, France [full address to be confirmed before final publication]
Paris Trade & Companies Register: registration in progress
Intra-EU VAT number: pending
Publication director: Sacha S.
Email: contact@nexeuro.com
Legal address: legal@nexeuro.com
Regulatory status
NexEuro SAS is developing a technology solution intended to facilitate certain uses relating to European payments.
As at the date of this version, NexEuro SAS does not itself carry on the activity of a payment institution and does not provide the public with regulated payment services under its own licence. NexEuro SAS must not be presented as a licensed payment institution.
NexEuro SAS is preparing the regulatory steps necessary to carry on the envisaged activities. No payment-institution or electronic-money-institution licence should be considered obtained until it has actually been granted by the competent authority and published in the applicable official registers.
When the regulated services are actually offered, NexEuro will clearly indicate the entity legally responsible for providing them, its regulatory status, its supervisory authority and, where applicable, its licence or registration number. Where a service is provided through a partner payment institution, electronic-money institution, credit institution or other regulated provider, the identity and status of that institution will be communicated before any subscription to the service concerned.
Presentation of features
The features, demonstrations, interfaces, simulations and descriptions on the site may correspond to features currently in testing, in development, or intended to be offered later. On their own, they do not constitute proof of the current availability of a regulated payment service.
The technical characteristics, pricing, limits, countries covered, execution times and terms of use presented on the site are subject to change. Presenting a future feature is not a guarantee of availability or launch.
Unless expressly stated otherwise and legally verified, no funds are entrusted to NexEuro SAS under a regulated payment service and no regulated payment account is opened with NexEuro SAS.
Hosting and technical providers
The site and the technical services used by NexEuro are hosted by the providers actually selected by NexEuro, on infrastructure located in the European Union:
- Database and authentication: Supabase (servers located in the European Union). The provider Supabase Inc. is a company incorporated under US law; a data-processing agreement (DPA) with the Standard Contractual Clauses (SCCs) approved by the European Commission is in place.
- Content delivery network and security: Cloudflare (European data centres; US-law provider — SCCs and additional measures in place).
The technical providers and sub-processors that may process personal data, their role, the location of the data and any international transfers are detailed in the Privacy Policy.
Intellectual property
All content on the nexeuro.com website and in the NexEuro app — text, images, logos, trademarks, source code, design — is the property of NexEuro SAS or of their respective owners and is protected under the provisions of the French Intellectual Property Code (articles L111-1 et seq.).
Except with prior written authorisation or a mandatory legal provision to the contrary, any reproduction, representation, modification, publication, adaptation, extraction or exploitation of all or part of the site's elements is prohibited. NexEuro and the associated distinctive signs may constitute protected trademarks or signs; no licence to use them is granted merely by accessing the site.
Hyperlinks
The site may contain links to services operated by third parties. NexEuro SAS does not necessarily control these sites and cannot be held responsible for their content, availability or practices. The presence of a link does not constitute a recommendation of the third-party site concerned.
Contact
General questions: contact@nexeuro.com
Legal questions: legal@nexeuro.com
Post: NexEuro SAS, 75001 Paris, France
Governing law
This legal notice is governed by French law, subject to any mandatory provisions that may apply to the consumer by reason of their place of residence.
Privacy Policy
Last updated: 11 August 2026
This policy explains how NexEuro SAS ("NexEuro", "we") collects, uses, retains and protects the personal data processed in connection with the nexeuro.com website, the NexEuro app and the associated services. The data controller is NexEuro SAS, 75001 Paris, France.
1. Data collected
Depending on the features used, the following categories may be processed:
Identification data
- Phone number (used as the user identifier)
- Full name (for display)
- Email address (for notifications and account recovery)
- Information needed to verify identity where regulation requires it
Payment-related data
When regulated services are actually provided and their processing is legally applicable:
- Account references or bank details
- Transaction information (amount, date and time, payee or payer, transaction status)
- Information needed to prevent and detect fraud
Technical data
- IP address (for security and anti-fraud)
- Technical identifiers and device type
- Connection data (timestamp, system, browser)
2. Purposes and legal bases
| Purpose | Possible legal basis |
|---|---|
| Account creation and management | Performance of the contract (art. 6.1.b GDPR) |
| Providing a requested service | Performance of the contract |
| Account security, fraud prevention | Legitimate interest and/or legal obligation |
| Identity verification (KYC) / AML-CFT | Legal obligation where applicable |
| Payment notifications | Consent or performance of the contract, as the case may be |
| Accounting | Legal obligation |
| Usage statistics | Consent or legitimate interest depending on the setup |
| Marketing | Consent or another legally applicable basis |
The exact legal basis is determined according to the processing concerned and the regulatory framework actually applicable.
3. Data retention
NexEuro retains data only for as long as necessary for the purpose for which it is processed, subject to legal obligations requiring longer retention. By way of indication:
- AML-CFT supporting documents (identity, due diligence): 5 years from the end of the business relationship (art. L. 561-12 of the French Monetary and Financial Code), where these obligations apply.
- Accounting records and transaction documents: 10 years (art. L. 123-22 of the French Commercial Code).
- Account identification data: the duration of the relationship, then archiving in line with applicable obligations.
- Connection logs: a duration set according to their security purpose.
Exact durations are set out in an internal data-retention policy. Deleting an account does not necessarily result in the immediate erasure of all data where its retention is required by law or necessary for the establishment, exercise or defence of legal claims.
4. Recipients and data sharing
NexEuro never sells your personal data. Data may be accessible, to the extent necessary, by:
- Technical providers: Supabase (database, EU servers) and Cloudflare (network, security, EU data centres) — bound by GDPR processing agreements and Standard Contractual Clauses (SCCs).
- Identity-verification and fraud-prevention providers, where implemented.
- Partner payment providers or regulated institutions, where they are involved in providing a payment service.
- Administrative, judicial or regulatory authorities where the law requires it.
5. Transfers outside the EU
Data is hosted on servers located in the European Union. As some of our sub-processors (Supabase Inc., Cloudflare Inc.) are companies incorporated under US law and potentially subject to extraterritorial laws (Cloud Act, FISA 702), any transfer or access from a third country is governed by the transfer mechanism under Chapter V of the GDPR applicable to the case concerned — in particular the Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional measures (encryption at rest, access segmentation) where necessary. NexEuro does not present a transfer as compliant merely because SCCs exist: each transfer is assessed according to the service's actual architecture.
6. Your rights
Under the GDPR (articles 15 to 22), you have the following rights:
- Right of access: obtain a complete copy of your data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request the deletion of your account and your data
- Right to portability: export your data in a machine-readable format
- Right to object: object to processing based on legitimate interest
- Right to restriction: request the temporary suspension of a processing operation
To exercise your rights: contact@nexeuro.com. We may ask for additional information to verify your identity where necessary and proportionate.
7. Security and data breaches
NexEuro implements appropriate technical and organisational measures to protect data against unauthorised access, destruction, loss, alteration or unauthorised disclosure. In the event of a data breach likely to result in a risk to your rights and freedoms, NexEuro applies its internal incident-management procedure and, where notification is legally required, informs the supervisory authority within the timeframes provided by the GDPR.
8. "Personal data" contact point
For any question about the protection of your data: contact@nexeuro.com
Post: NexEuro SAS — Data Protection, 75001 Paris, France
9. Supervisory authority
If you believe your data is being processed in breach of the GDPR, you may lodge a complaint with the competent supervisory authority. For France: the CNIL (Commission Nationale de l'Informatique et des Libertés) — cnil.fr · 3 Place de Fontenoy, 75007 Paris · Tel.: +33 1 53 73 22 22.
10. Changes
This policy may be amended to reflect changes in the service, the regulations or our organisation. The date of the last update appears at the top of this policy.
Terms of Use
Last updated: 11 August 2026
Article 1 — Purpose
These Terms of Use ("Terms") govern access to and use of the nexeuro.com website, the digital interfaces and, where available, the NexEuro app (hereinafter "the Service"), published by NexEuro SAS.
These Terms do not constitute a framework contract for payment services. Regulated payment services, when they are actually offered, will be subject to specific contractual terms communicated to the user before any subscription.
Use of the Service implies full and complete acceptance of these Terms.
Article 2 — Regulatory status
NexEuro is currently in a development and regulatory-preparation phase. Unless expressly stated otherwise in the applicable contractual documents, NexEuro SAS does not currently provide any regulated payment service under its own licence. The demonstrations and features presented on the site may correspond to features in development or to envisaged services.
Article 3 — Access to the service
Certain features may be reserved for:
- Adult individuals (18 years or older)
- Legal entities lawfully incorporated in the European Union
- Residents of the area covered by the service
Certain features may require registration or participation in a testing programme. NexEuro may modify, suspend or temporarily interrupt all or part of the Service for technical, security, maintenance or compliance reasons.
Article 4 — Description of features
NexEuro is developing, in particular, the following features:
- Peer-to-peer payments by phone number
- Payment QR codes (ephemeral and permanent)
- Custom payment links
- Group pots: a feature under study, whose launch will depend on the analysis of the applicable framework (payment services, crowdfunding within the meaning of Regulation (EU) 2020/1503) and, where applicable, any additional authorisations required.
- Analytics dashboard for professionals
Presenting a future feature is not a commitment to launch it. Features may be modified, delayed, geographically limited or removed for regulatory, technical, commercial or security reasons.
Article 5 — Pricing
| Service | Indicative price |
|---|---|
| Payments between individuals | Free |
| Professional acceptance (QR, link) | 0.5% per transaction |
| Pro plan — analytics dashboard | €9.99/mo incl. tax |
| Business plan — advanced features | €24.99/mo incl. tax |
| Enterprise plan — bespoke integration | Custom quote |
Where a framework contract for payment services applies, any price change will be notified on a durable medium at least two (2) months before it takes effect, in accordance with article L. 314-13 of the French Monetary and Financial Code, the user being able to terminate free of charge before that date.
Article 6 — Obligations and prohibited uses
The user undertakes to provide accurate information, to keep their credentials confidential and to report any unauthorised use without delay. In particular, it is prohibited to:
- use the Service for fraudulent or unlawful purposes
- impersonate another person
- circumvent security mechanisms or carry out penetration testing without authorisation
- introduce malware or deliberately disrupt the infrastructure
- extract data in bulk without authorisation
- use the Service to circumvent legal sanctions or restrictions
Article 7 — Payments and liability
Regulated payment transactions are subject to the specific contractual terms of the provider legally responsible for executing them; these Terms do not replace those terms. The regime for unauthorised or improperly executed transactions is determined by the applicable regulations (in particular the French Monetary and Financial Code) according to the exact role of NexEuro and of the regulated providers involved in the payment chain.
NexEuro is liable for the damage for which it is legally responsible. No clause in these Terms is intended to exclude or limit any liability that cannot lawfully be excluded or limited. NexEuro cannot, however, be held liable for damage resulting from fraudulent use of the account by a third party, an event of force majeure, or an error in identifying the recipient attributable to the user.
Article 8 — Availability and security
NexEuro does not guarantee permanent, error-free availability of the Service. Interruptions may occur for maintenance, updates, security or circumstances beyond NexEuro's control. No security measure can guarantee absolute security; users must also protect their devices, passwords and authentication methods.
Article 9 — Suspension and termination
The user may request the closure of their account at any time via the interface or by contacting contact@nexeuro.com. NexEuro may suspend or restrict access where necessary to ensure security, prevent fraud, comply with a legal obligation or enforce these Terms. Closing the account does not necessarily delete data whose retention is required by law.
Article 10 — Data, cookies and intellectual property
The processing of personal data is governed by the Privacy Policy and the use of trackers by the Cookie Policy. The intellectual property rights relating to the Service and its content belong to NexEuro or to their respective owners; any unauthorised use is prohibited.
Article 11 — Governing law and mediation
These Terms are governed by French law, subject to the mandatory protective provisions applicable to consumers. For any consumer dispute, the user may use mediation free of charge under the conditions described in the "Mediation" section. The official list of approved mediators can be found at economie.gouv.fr/mediation-conso.
GDPR compliance
Last updated: 11 August 2026
NexEuro SAS complies with the General Data Protection Regulation (GDPR — EU Regulation 2016/679 of 27 April 2016) across all of its personal-data processing. This section provides summary information; the detailed information is set out in the Privacy Policy.
1. Data controller
NexEuro SAS, 75001 Paris, France
"Personal data" contact point: contact@nexeuro.com
2. Overview of the main processing operations
| Processing | Purpose | Legal basis | Duration |
|---|---|---|---|
| Account management | Identification, authentication | Contract | Account duration + 5 years |
| Payment processing | Execution of transfers | Contract (art. 6.1.b GDPR) — accounting obligation (art. L. 123-22 Commercial Code) and AML-CFT (art. L. 561-12 Monetary and Financial Code) | 5 years (AML-CFT) / 10 years (accounting records) |
| KYC/AML-CFT compliance | Regulatory identity verification | Legal obligation | 5 years after termination |
| Fraud prevention | Transaction security | Legitimate interest | 3 years |
| Usage statistics | Service improvement | Legitimate interest | 25 months |
| Marketing (opt-in) | Commercial communications | Consent | 3 years after last contact |
3. Technical security measures (article 32 GDPR)
- Data encryption at rest: AES-256
- Encryption in transit: TLS 1.3 minimum
- Authentication: multi-factor (MFA) for administrator access
- Password hashing: bcrypt with salt
- Pseudonymisation: of analytics and development data
- Hosting: exclusively on infrastructure located in the European Union
The concrete measures are adapted to the risks, the nature of the data and the evolution of the infrastructure. Any security certification displayed by NexEuro corresponds to a certification actually held, to its scope and to its period of validity; some applicable certifications may belong to the infrastructure providers, according to their own certification scope.
4. Sub-processors (article 28 GDPR)
| Sub-processor | Role | Country | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database, authentication | EU (servers) — US company | GDPR DPA + SCCs |
| Cloudflare Inc. | CDN, DDoS protection, security | EU + US | GDPR DPA + SCCs |
This list reflects the main sub-processors actually used and may change. Where a sub-processor uses a further sub-processor that may process personal data, the applicable GDPR requirements are taken into account.
5. Exercising your rights
You can exercise your GDPR rights by contacting our "personal data" contact point:
- Email: contact@nexeuro.com
- Response time: one month maximum, extendable under the conditions of article 12 GDPR
- Proof: an identity check may be requested where necessary and proportionate
6. Breach notifications (article 33 GDPR)
In the event of a data breach likely to result in a risk to your rights and freedoms, NexEuro will notify the CNIL within 72 hours and will inform you without undue delay if the risk is high.
7. Impact assessment (DPIA)
NexEuro carries out data protection impact assessments (DPIAs) in accordance with article 35 of the GDPR for all processing likely to result in a high risk, in particular for biometric processing and sensitive financial data.
Cookie Policy
Last updated: 11 August 2026
NexEuro uses cookies and similar technologies on its nexeuro.com website. This policy details their use in accordance with the ePrivacy Directive and the recommendations of the CNIL.
1. What is a cookie?
A cookie is a small text file placed on your device (computer, smartphone, tablet) when you visit a website. It allows the site to remember your actions and preferences for a set period.
2. Strictly necessary cookies
These cookies are essential for the Service to work. They cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
| nx_sess | Authentication session | Session |
| nx_csrf | Protection against CSRF attacks | Session |
| nx_lang | Remembering the chosen language | 1 year |
3. Audience-measurement cookies
These cookies let us measure our audience and improve our services. Depending on their configuration and purpose, they may require your prior consent; where consent is required, they are not activated before it is obtained.
| Cookie | Purpose | Duration | Consent |
|---|---|---|---|
| _nx_analytics | Audience measurement (page views, journeys) | 13 months | Depending on configuration |
| _nx_perf | Performance measurement (load times) | 13 months | Depending on configuration |
A tracker's lifetime (13 months for cookie retention, up to 25 months for the information collected) does not, on its own, exempt it from obtaining consent: the exemption conditions are checked tool by tool according to the CNIL's recommendations. The cookie table must correspond exactly to the trackers actually placed.
4. Managing your preferences
You can manage your cookie preferences:
- From the interface: Settings > Cookies on nexeuro.com
- Via your browser: every browser offers cookie-management options in its settings
- By email: contact@nexeuro.com
5. Retention period
In line with the CNIL's recommendations, no cookie exceeds a lifetime of 25 months. Beyond that, your consent is collected again.
Handling complaints
Last updated: 11 August 2026
NexEuro attaches particular importance to handling complaints. A complaint is a statement recording dissatisfaction; a simple request for information or technical assistance is not necessarily a complaint.
1. How to file a complaint
Complaints can be sent:
- By email: contact@nexeuro.com
- By post: NexEuro SAS — Complaints, 75001 Paris, France
Please state your name and contact details, your account reference if any, the date and nature of the problem, the transactions concerned and any relevant documents. The complaints procedure is free.
2. Handling times
NexEuro acknowledges receipt of the complaint and communicates the information needed to handle it. Where a complaint concerns a regulated payment service, it will be handled within the applicable regulatory timeframes: as an indication, a reply within 15 business days, extended to a maximum of 35 business days in exceptional circumstances, with a reasoned holding reply in the meantime. Complaints not relating to payment services are handled within a reasonable time given their complexity.
3. Fraud
Any suspicion of fraud must be reported immediately. Secure your means of access, never share your authentication codes and follow the security instructions.
4. Recourse
If the reply does not satisfy you, you can use consumer mediation (see the "Mediation" section) where it applies. For complaints about data protection, you can refer the matter to the CNIL. Complaints are kept for as long as necessary to comply with the applicable legal obligations.
Consumer mediation
Last updated: 11 August 2026
NexEuro strives to resolve any difficulty amicably. Before referring a matter to a mediator, the consumer must send a written complaint to NexEuro or to the professional legally responsible for the service concerned (see the "Complaints" section).
1. Competent mediator
2. Referral conditions
The consumer may refer the matter to the mediator where the conditions provided for by the applicable texts are met, according to the procedures indicated by the mediator. Consumer mediation is free for the consumer, subject to the rules applicable to the procedure.
3. Payment services and legal action
Where the dispute concerns a regulated payment service, the specific complaint and mediation procedures applicable to payment services prevail. Mediation does not deprive the consumer of their right of access to the competent courts. The official list of approved mediators can be found at economie.gouv.fr/mediation-conso.
Security policy
Last updated: 11 August 2026
The security of systems, data and operations is a priority for NexEuro. NexEuro applies technical and organisational measures proportionate to the risks associated with its services. No security measure can, however, be presented as an absolute guarantee against any attack.
1. Encryption and data protection
- Encryption at rest: AES-256 for sensitive data
- Encryption in transit: TLS 1.3 for communications
- Password hashing: bcrypt with an adaptive cost factor
The exact algorithms, key lengths and configurations may change. NexEuro does not publish information likely to facilitate a compromise of its infrastructure.
2. Authentication and access control
- Multi-factor (MFA): for administrator access
- Biometric authentication: Face ID / Touch ID (iOS), processed locally by the device
- Principle of least privilege and removal of access that is no longer needed
- Anomaly detection: alerts in the event of an unusual login
3. Strong authentication (SCA)
When regulated payment services are provided and the regulations require it, strong customer authentication (SCA) will be applied in accordance with PSD2 and Delegated Regulation (EU) 2018/389, combining at least two independent factors (knowledge, possession, inherence). The mechanisms used may change according to the regulations, the risk level and the technology available.
4. Infrastructure, incident management and continuity
- Hosting: exclusively on infrastructure located in the European Union
- Monitoring and logging of relevant security events
- Vulnerability management according to their severity and impact
- Incident management (analysis, containment, remediation, recovery, notification where the regulations require it)
- Continuity and recovery adapted to the criticality of the services
Recovery objectives (RTO/RPO), certifications (ISO 27001…), penetration tests and disclosure programmes are only published when they correspond to measures actually in place; some certifications may belong to the infrastructure providers according to their own scope.
5. Reporting vulnerabilities
If you discover a vulnerability, report it responsibly to contact@nexeuro.com (description, environment, reproduction steps, potential impact). It is prohibited to exploit a vulnerability to access or modify data, disrupt a service or carry out extortion. NexEuro undertakes to handle responsible reports in good faith.
6. In the event of an incident on your account
If you suspect a compromise or a transaction you did not authorise, contact contact@nexeuro.com without delay. When a regulated payment service is provided, the rights to a refund of an unauthorised transaction will be determined by the applicable regulations (Monetary and Financial Code, PSD2).