Privacy policy

This policy explains how Neustral SAS processes personal data of platform users in accordance with Regulation (EU) 2016/679 (GDPR) and applicable French data-protection law.

1. Data controller

The data controller is Neustral SAS, 42 rue de la Victoire, 75009 Paris, France, SIREN 921 458 763.

General contact: contact@neustral.com.

Data Protection Officer (DPO) / GDPR contact point: dpo@neustral.com.

2. Purposes and legal bases

We process your data to: create and manage your account (contract performance); run the assistance journey and KYC (legal obligation / legitimate interest / contract); process Bitcoin payments and prevent fraud (contract / legitimate interest / legal obligation); contact you about your file (contract); secure the platform (legitimate interest); meet accounting and retention duties (legal obligation); and send marketing communications only with your consent where required.

You may withdraw consent at any time where processing is consent-based, without affecting prior lawfulness.

3. Categories of data collected

Depending on your use of the Service, we may collect: identity and contact data (name, email, address, date of birth, nationality); account data (credentials, language preferences, login logs); KYC documents and related information; payment data (amount, BTC receiving address, transaction hash, payment evidence); technical data (IP address, server logs, device type); and messages sent via support or the contact form.

Data is hosted and processed in the European Union on Neustral’s VPS infrastructure.

4. Biometric data (selfie)

The identity-verification selfie may constitute biometric data under Article 9 GDPR when used to uniquely authenticate or verify your identity.

This processing relies on your explicit consent collected during the KYC step. You may withdraw consent; withdrawal may prevent completion of verification.

Selfie retention period: 90 days after final KYC approval or final rejection, unless a longer legal retention duty applies or a dispute is pending.

5. Recipients

Data is accessible only to authorised Neustral staff (support, compliance, technical teams) on a need-to-know basis.

It may be disclosed, only where necessary: to administrative or judicial authorities upon lawful request; to advisers (lawyers, experts) in connection with a dispute; and to technical processors acting on Neustral’s instructions.

6. Processors and hosting

Neustral self-hosts the platform on VPS infrastructure located in the European Union. Technical providers may be used for transactional email or other strictly necessary functions, under appropriate contractual safeguards.

No transfer outside the EU is made without adequate safeguards (standard contractual clauses or equivalent) where applicable.

7. Retention periods

Active user account: duration of the contractual relationship.

KYC documents (excluding selfie): 5 years after the end of the relationship or final rejection, or longer if required by law.

Biometric selfie: 90 days after final KYC decision (see dedicated section).

Payment data / BTC hashes and accounting records: 10 years (accounting obligations).

Security technical logs: 12 months.

Contact messages: 24 months.

After these periods, data is deleted or anonymised.

8. Your rights

Under the GDPR, you have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent where applicable.

To exercise your rights: dpo@neustral.com. We may request proof of identity if reasonably necessary.

You may also lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority.

9. Cookies

We use cookies and similar technologies strictly necessary for website operation (session, authentication, security, language preference).

With your consent, audience-measurement cookies may be placed. You may accept, refuse or withdraw consent via the cookie banner or your browser settings.

Refusing non-essential cookies does not prevent access to core Service features.

10. Security

Neustral implements appropriate technical and organisational measures: access control, encrypted transport (HTTPS), logging, segregation of KYC files, and internal incident-response procedures.

No system is infallible; Users must also protect their credentials and devices.

11. Minors

The Service is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data to us, contact dpo@neustral.com so we can delete it.

12. Updates

This policy may be updated to reflect legal or technical changes. The applicable version is the one published on this page.

Last updated: 29 July 2026.

Contact: dpo@neustral.com — Neustral SAS, 42 rue de la Victoire, 75009 Paris, France.