Live environment — real market prices, 24/7
Legal

Privacy Policy

NexoBot SAS — Paris, FranceLast updated: March 2026

This policy explains what personal data NexoBot collects, why we collect it, how long we keep it and the rights you have over it. It applies to the NexoBot website and platform and complies with the EU General Data Protection Regulation (GDPR).

01Who is responsible for your data

The data controller is NexoBot SAS, a French simplified joint-stock company with its registered office in Paris, France. You can reach our data protection officer (DPO) at [email protected] or by post at NexoBot SAS, Paris, France.

02Data we collect

We collect the minimum data needed to run the platform and keep it secure:

CategoryExamplesSource
Account dataEmail address, display name, password (hashed), language preferenceYou provide it
Usage dataBot configurations, orders, order history, platform interactionsGenerated by your use
Technical dataIP address, device and browser type, timestamps, crash logsCollected automatically
Communication dataSupport requests and our repliesYou provide it
Billing dataPlan, subscription status, transaction references from our payment processorProcessor / your use

In the preview environment we do not collect identity documents and we do not process know-your-customer (KYC) data. We never see or store your payment credentials: card and crypto payment details are handled exclusively by our payment processor.

04How we use your data

  • Provide, operate and personalize the platform.
  • Execute your strategies and keep an accurate history of your account.
  • Protect accounts, funds and infrastructure against fraud and attacks.
  • Answer your support requests and inform you about the service.
  • Analyze usage in aggregate to improve features.
  • Comply with legal, tax and regulatory obligations.

We do not sell your personal data, and we never use it for third-party advertising.

05Cookies and similar technologies

We use a small number of cookies and browser storage entries:

  • Session cookie — keeps you signed in; strictly necessary.
  • Preference storage — remembers your language and interface choices.
  • Analytics — privacy-respecting, aggregate audience measurement, only with your consent where required.

You can block or delete cookies from your browser settings. Strictly necessary cookies cannot be disabled if you want the platform to work.

06Who we share data with

We share personal data only with the service providers that keep NexoBot running, each bound by a data processing agreement:

  • Cloud hosting provider — servers located in the European Union.
  • Payment processor — billing and subscription management.
  • Email provider — transactional messages (account, security, service notices).
  • Analytics provider — aggregate, privacy-respecting measurement.

We may also disclose data when the law requires it, or to protect our rights, your safety or the security of the platform.

07International transfers

Your data is hosted in the European Union. If a provider processes data outside the European Economic Area, the transfer is protected by an adequacy decision of the European Commission or by standard contractual clauses (SCCs), as the GDPR requires.

08How long we keep your data

  • Account and usage data — kept while your account is active, then deleted within 30 days of closure.
  • Backups — purge automatically within 90 days.
  • Billing records — kept as long as French law requires (up to 10 years for invoices).
  • Support correspondence — kept for 24 months to handle follow-ups.

09Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data, subject to legal retention duties.
  • Restrict or object to certain processing.
  • Receive your data in a portable, structured format.
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with a supervisory authority.

To exercise any of these rights, email [email protected]. We respond within one month. Under French law, you also have the right to give instructions about the fate of your data after your death.

10Security

We protect your data with encryption in transit (TLS 1.2+) and at rest (AES-256), hashed passwords, two-factor authentication options, least-privilege access for staff and 24/7 infrastructure monitoring. In the event of a personal data breach, we notify the supervisory authority within 72 hours and inform you without undue delay where the risk is high.

11Changes to this policy

We may update this policy as the product or the law evolves. Material changes are announced by email or a prominent notice at least 30 days in advance. The date at the top of this page is always the reference.

12Contact and complaints

For any question about your data, contact our DPO at [email protected] or NexoBot SAS, Paris, France.

You can also lodge a complaint with the CNIL — the French data protection authority — at 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or with the supervisory authority of your country of residence.

Questions about this document?

Our legal team reads every message and replies within two business days.

Email us
Privacy Policy — NexoBot · NexoBot