Home » Privacy Policy
This Nexo Privacy Policy (the "Privacy Policy") governs the privacy relations between you ("Client" or "you") and any holding company, subsidiary or entity belonging to the Nexo group of companies ("Nexo" or "we"), in regard to how we process and protect your personal data as you use the Nexo Services provided on any Nexo website, including https://nexo.com/ (the "Website"), mobile application(s), Nexo application programming interfaces ("APIs") or third party applications relying on our API (together, our "Apps"), and any other official Nexo communication channel, including the content and services made available on or through the same, and any updates, upgrades, and versions thereof, and constitutes a legally binding agreement (the "Agreement") between Nexo and you. We encourage you to seek out and read the Privacy Policy to understand how the information that we collect about you is used and protected.
The Privacy Policy is reviewed regularly to ensure that any new services or updates, as well as any changes to our business model and practices are taken into consideration. We will alert you of material changes by, for example, placing a notice on the Website, the Nexo Platform and/or by sending you an email. Your continued use of the Nexo Platform after we make changes is deemed to be acceptance of those changes, so please review the Privacy Policy periodically for updates.
Unless stated otherwise herein, references shall be made to the Nexo Terms of Service, Nexo Cookies Policy, Nexo Chat Terms of Service, Straight Arrow Card Provider General Terms and Conditions,and any other terms and conditions governing the use of the Nexo Platform and the Nexo Services (jointly the "Nexo General Terms"). All capitalised terms not defined herein, shall have the same meaning as the one given to them in the Nexo General Terms, as the case may be.
Nexo may collect the following types of Personal Data when you visit the Website, the Apps, register on the Nexo Platform, use the Nexo Services, and when you interact and communicate with Nexo on the Website or through the Apps:
When you visit the Nexo Platform, we automatically collect the following information:
Nexo may receive Personal Data about you from third parties such as payment processors, compliance service providers assisting with anti-money laundering (AML), fraud, and security matters, and information that can be lawfully accessed from public sources. For example:
Nexo receives Personal Data from third parties for the purposes of compliance with its legal obligations, and the provision of contractual obligations in relation to the requested services. These third parties may collect Personal Data on behalf of Nexo, or act as Controllers in accordance with their own privacy policies. Some of these third parties may have obtained your data from publicly daccessible sources.
Please note that if you refuse to provide Personal Data when requested, especially where we need to collect it by law, or under the terms of a contract we have or are looking to enter into with you, we may not be able to perform the relevant contract, including the ability to offer or continue to provide the Nexo Services to you.
Nexo processes Personal Data only in accordance with applicable Privacy Laws and this Privacy Policy. Nexo collects and processes your Personal Data in a legitimate and transparent manner under the Privacy Laws, and namely:
The table below sets out the processing purposes, their legal justification, and the categories of Personal Data involved.
| Why we process your personal data | Legal justification | Categories of personal data |
| Identification & Verification - to process onboarding applications, verify identity (including the level of due diligence) through onboarding checks, and evidence identity authentication. | Performance of Contract; Legal Obligations. | Identification information; Biometric data. |
| Provision of New Services - to deliver the Nexo Services as described in the Nexo General Terms. | Performance of Contract. | Identification information; Contact and communication information; Financial information. |
| Service Functionality & Improvements - to maintain and enhance the Nexo Platform, ensure quality and security, analyse performance, debug, and conduct research, audits, and reporting. | Legitimate Interests (service improvement and security). | Technical/usage data. |
| Personalisation - to tailor the Client experience, content, and service offerings. | Legitimate Interests; Consent (where applicable). | Contact and communication information; Financial information. |
| Legal & Regulatory Compliance - to meet obligations under Privacy Laws, AML, sanctions, tax, anti-terrorism financing, and other applicable laws. | Legal Obligations. | Identification information; Contact and communication information; Financial information. |
| Fraud & Security Monitoring - to detect, investigate, and prevent fraud, money laundering, terrorism financing, and other criminal or malicious activity. | Legal Obligations; Legitimate Interests. | Identification information; Financial information; Contact and communication information. |
| Communications - to contact you about your Nexo Account, the Nexo Platform, updates to the Nexo Services, or changes to our contractual relationship. | Performance of Contract; Legitimate Interests. | Contact and communication information. |
| Marketing - to provide information on Nexo products and Nexo Services via permitted communication channels (with opt-out options). | Consent. | Contact and communication information; Technical/usage data. |
| Consent-based Purposes - for specific activities explicitly agreed to by individuals, with the right to withdraw at any time. | Consent. | Categories depend on the consent obtained. |
| Other Compatible Uses - for purposes reasonably aligned with the above, or where required or permitted by Privacy Laws. | Legal Obligations; Legitimate Interests. | Categories depend on the related purpose. |
Automated decision-making refers to decisions made solely by technological means without human involvement, including profiling. Nexo may rely on automated decision-making in certain processes because it:
Automated decision-making may occur in:
Automated decisions may be based on:
Nexo may disclose Personal Data to carefully selected third parties outside of Nexo, but only where such disclosure is lawful, limited to the necessary scope, and subject to appropriate safeguards. Any such disclosure is made in accordance with applicable Privacy Laws, this Privacy Policy, and the Nexo General Terms.
Nexo may share Personal Data with the following categories of external third parties:
In certain cases, third parties to whom Nexo discloses Personal Data may act as independent data controllers for specific processing activities (e.g., card-issuing partners, banks, or governmental authorities). In such cases, those third parties are responsible for their own compliance with applicable Privacy Laws.
The Nexo Platform may contain links to third-party websites, plug-ins, or applications. Clicking on such links may allow third parties to collect or share Personal Data. Nexo does not control these third-party websites and is not responsible for their processing of Personal Data. We encourage you to review the privacy notices of each third-party website you visit.
When transferring Personal Data, we are committed to ensuring that the data importer maintains materially similar security measures for storage and Processing of Personal Data as we do. Your Personal Data may be processed, stored and transferred to third parties in the manner and amount as provided in this Privacy Policy, the contract(s) concluded between you and us, and consents you give to us from time to time.
Locations outside your home jurisdiction may be used for processing (including storing) the data we collect about you. The information we transfer may be shared with our service providers. It may include such processes as processing a payment, data analysis (including fraud, risk and compliance checks), collecting data on the use of our websites and services, for advertising purposes (including behavioural advertising), or offering support for your service or product needs. We take all reasonable action to ensure the safety of your Personal Data in agreement with this Privacy Policy and applicable local and international legislation. The legal basis for international data transfers depends on your home jurisdiction. If Personal Data of individuals located in the European Economic Area (EEA) or the United Kingdom (UK) is transferred to a country that does not provide a level of data protection equivalent to that of the EU/EEA or the UK, Nexo will ensure that the data is appropriately protected by using contractual arrangements with strict data protection safeguards or other lawful transfer mechanisms recognised under applicable Privacy Laws. For more information, you can contact Nexo's Data Protection Officer (DPO) at dpo@nexo.com.
Subject to applicable Privacy Laws, Nexo may from time to time send direct marketing communications about the Nexo Services and related offerings to existing Clients, or to individuals who have subscribed to receive updates. Such communications may be sent by email, push notifications, or other electronic means, in accordance with applicable Privacy Laws.
You may opt out of receiving marketing communications at any time:
If you opt out, Nexo will retain your contact details on a suppression list to ensure that you do not receive further marketing communications, except where you have expressly opted back in.
Personal Data collected by Nexo through the Nexo Platform or otherwise is stored on secure servers, hosted in a cloud environment in the European Union (EU). Nexo is certified under ISO/IEC 27001 and SOC 2 Type 2 and implements appropriate technical and organisational measures designed to protect Personal Data against accidental loss, unauthorised access, alteration, or disclosure. These measures include, among others, network safeguards such as firewalls and encryption, regular malware scanning, and continuous monitoring of systems.
Access to Personal Data is strictly limited to employees, contractors, and authorised third parties who require such access to perform their duties or comply with legal obligations. All such individuals are subject to confidentiality obligations and receive regular training on data protection and information security. Access rights are carefully screened, granted on a need-to-know basis, and periodically reviewed.
In the event of a personal data breach resulting in the destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, Nexo will, where required under applicable Privacy Laws, notify the competent data protection authority and affected individuals without undue delay. Such notification will include sufficient information to enable affected individuals to take protective measures. For additional details about Nexo's security practices, please visit the security panel on the Nexo Website.
To help maintain security, Clients are responsible for keeping their Nexo Account credentials confidential. Nexo employees will never ask for passwords or authentication codes. Clients should also exercise caution when accessing their Nexo Account from shared or unsecured devices.
Nexo retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or to comply with legal, regulatory, or contractual obligations. When Personal Data is no longer required, Nexo will securely delete it or anonymise it so that individuals can no longer be identified.
Depending on the context, Personal Data may be retained for different reasons, including:
In some cases, Nexo may need to retain Personal Data beyond the periods outlined above, for example where deletion is not possible for legal, regulatory, or technical reasons. In such cases, Nexo will continue to ensure that the Personal Data is appropriately safeguarded.
Nexo will respond to any request to exercise your rights as a Data Subject without undue delay, and in any case within the timeframes required by applicable Privacy Laws (normally within one month, extendable by two further months where necessary). You may exercise the following rights to the extent permitted by applicable Privacy Laws:
To protect your privacy, Nexo may need to verify your identity before responding to your request. We will make reasonable attempts to promptly investigate, comply with, or otherwise respond to your requests as may be required by applicable Privacy Laws. Depending upon the circumstances and the nature of the request, Nexo may not be permitted to provide access to certain Personal Data or may be unable to fully comply; for example, producing your information may reveal the identity of another individual.
You will not have to pay a fee to exercise the rights listed above. However, requests that are manifestly unfounded or excessive may be refused or subject to a reasonable fee, in accordance with applicable Privacy Laws. Please note that any request concerning Personal Data which is publicly available should be submitted directly to the third-party supplier of that information.
Nexo values your privacy. If you have any comments or questions about this Privacy Policy, Nexo's handling of your Personal Data, a possible Personal Data Breach, or if you wish to exercise your rights, please contact Nexo's DPO at dpo@nexo.com.
When submitting a request, please include the following information to help Nexo process it efficiently:
Nexo treats all requests and complaints with confidentiality and will make reasonable efforts to respond in line with applicable Privacy Laws.
If you believe that Nexo has not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority. For individuals located in the EEA, a list of supervisory authorities is available on the website of the European Data Protection Board (EDPB).
Nexo Services are not directed to individuals under the age of 18 or under the legal age required to enter into a binding contract with Nexo, whichever is higher ("Children"). Nexo does not knowingly collect or process the Personal Data of Children.
If Nexo becomes aware that it has inadvertently collected Personal Data from a Child, Nexo will take legally permissible steps to delete that data and close the associated account.
If you are a parent or guardian and believe that a Child has provided Personal Data to Nexo, please contact Nexo's DPO at dpo@nexo.com.