Privacy Policy
Version in force as of: March 31, 2026
Introduction
This Privacy Policy describes the way in which the Company NexusTok (SAS), publisher of the nexus-tok.com Platform (hereinafter “NexusTok”, “we” or “the Company”), collects, uses, stores and protects the personal data of Users, in accordance with the General Regulations on <span translate="no">Data Protection (EU) 2016/679 of April 27, 2016 (hereinafter “GDPR”) and French law no. 78-17 of January 6, 1978 as amended relating to data processing, files and freedoms (Informatique et Libertés law).
Article 1 — Identity of the Data Controller
Data controller: NexusTok (SAS) Head office: 173 rue de Courcelles, 75017 Paris, France SIRET: 103 737 623 00019 Share capital: €300 DPO / Confidentiality email: contact@nexus-tok.com
Article 2 — Personal Data Collected
As part of the operation of the Platform, NexusTok collects and processes the following categories of personal data:
| Category | Data collected |
|---|---|
| Account data | Email address, password (hashed with a secure bcrypt-type algorithm, never stored in clear text). |
| Broadcast data | TikTok public pseudonym of the content creator (username). |
| Viewer data | Pseudonym TikTok of the viewer who interacted (gave a gift, liked, commented, followed), type and amount of the event. This data is processed in an ephemeral and transient manner to trigger in-game events and is not stored permanently. |
| Technical data and logs | IP address, browser type and version, operating system, connection and interaction timestamps. Stored between 30 and 90 days for security purposes. |
| Transactional data | Subscription history (subscribed offer, dates, amounts). Credit card numbers and sensitive payment data are never stored by NexusTok — they are processed exclusively by Stripe. |
| Usage data | Triggers configurations, overlay settings, anonymized usage statistics via <span translate="no">Vercel Analytics</span> for the website and via Aptabase for the software application (thick client). |
NexusTok does not collect so-called “sensitive” data within the meaning of Article 9 of the GDPR (data relating to health, ethnic origin, religious beliefs, etc.).
Article 3 — Purposes and Legal Basis of Processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Creation and management of user account | Execution of the contract (Art. 6.1.b) |
| Provision and improvement of the Service | Execution of the contract (Art. 6.1.b) |
| Payment processing and subscription management | Execution of the contract (Art. 6.1.b) |
| Triggering in-game events (ephemeral processing of viewer data) | Performance of the contract / Legitimate interest (Art. 6.1.b and 6.1.f) |
| Platform security and fraud prevention | Legitimate interest (Art. 6.1.f) |
| Sending transactional emails (confirmation, notifications) | Execution of the contract (Art. 6.1.b) |
| Sending commercial communications | Consent (Art. 6.1.a) — opt-in |
| Compliance with legal obligations (accounting, taxation) | Legal obligation (Art. 6.1.c) |
| Anonymized statistical analyzes (<span translate="no">Vercel Analytics</span> and Aptabase) | Legitimate interest (Art. 6.1.f) |
Article 4 — Shelf Life
| Data category | Shelf life |
|---|---|
| Account data (email, hashed password) | For the entire duration of the account + 3 years after deletion (legal requirements) |
| Streaming data (pseudonym TikTok) | For the duration of the active account |
| Viewer data (ephemeral) | Not permanently stored — real-time processing only |
| Technical logs (logs, IP) | 30 to 90 days |
| Transactional data | 10 years (accounting obligation — art. L. 123-22 of the Commercial Code) |
| Navigation and usage data (<span translate="no">Vercel Analytics</span> and Aptabase) | According to Vercel and Aptabase policies — anonymized data |
Article 5 — Recipients and Subcontractors
As part of the provision of the Service, NexusTok uses the following subcontractors and third-party service providers. Each of them has been selected for the guarantees it presents in terms of personal data protection and acts solely on the instructions of NexusTok:
5.1 — Stripe (Traitement des paiements)
Stripe Payments Europe, Ltd. — C/O A&L Goodbody, 25-28 North Wall Quay, Dublin 1, Ireland. Website: https://stripe.com/fr — Privacy policy: https://stripe.com/fr/privacy Purpose: secure processing of bank card payments, management of recurring subscriptions. PCI-DSS level 1 certified. NexusTok does not store any credit card data.
5.2 — Neon.tech (Hébergement base de données)
Neon, Inc. — 2261 Market Street #4059, San Francisco, CA 94114, United States. Website: https://neon.tech — Privacy policy: https://neon.tech/privacy-policy Purpose: hosting the PostgreSQL relational database. <span translate="no">Neon.tech</span> offers instances hosted on AWS with encryption at rest and in transit. ISO/IEC 27001, ISO/IEC 27701, SOC 2 and SOC 3 certified, and GDPR compliant. Standard contractual clauses (SCCs) are applied to govern the transfer of data to the United States.
5.3 — Cloudflare (Sécurité et CDN)
Cloudflare, Inc. — 101 Townsend St, San Francisco, CA 94107, United States. European entity: Cloudflare Ltd., 6th Floor, One Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Website: https://www.cloudflare.com/fr-fr — Privacy policy: https://www.cloudflare.com/fr-fr/privacypolicy Purpose: application firewall (WAF), protection against DDoS attacks, content distribution network (CDN), DNS management. ISO 27001 certified. Cloudflare acts as a data processor within the meaning of the GDPR for data passing through its network.
5.4 — Vercel (Hébergement frontend et analytiques)
Vercel, Inc. — 440 N Barranca Avenue #4133, Covina, CA 91723, United States. Website: https://vercel.com — Privacy policy: https://vercel.com/legal/privacy-policy Purpose: hosting of the Next.js web application and collection of anonymized usage data via @vercel/analytics. Vercel does not resell usage data. SCCs are applied for transfers outside the EU.
5.5 — Resend (Envoi d’e-mails transactionnels)
Resend, Inc. — 2261 Market Street #4059, San Francisco, CA 94114, United States. Website: https://resend.com — Privacy policy: https://resend.com/legal/privacy-policy Purpose: routing of transactional emails (password reset, notifications). Resend does not resell the transmitted data. Standard contractual clauses (SCCs) are applied to govern the transfer of data to the United States.
5.6 — Render.com (Hébergement de l'API)
Render, Inc. — 525 Brannan St #300, San Francisco, CA 94107, United States. Website: https://render.com — Privacy policy: https://render.com/privacy Purpose: hosting of the backend infrastructure and API. Render is SOC 2 Type 2 certified and implements industry-standard security measures. Data is hosted in secure data centers (AWS/GCP). Standard contractual clauses (SCCs) are applied for transfers outside the EU.
5.7 — Aptabase (Analytiques logicielles)
Aptabase — 51 Bracken Road, Sandyford Dublin D18 CV48, Ireland. Website: https://aptabase.com/ — Infrastructure: eu.aptabase Purpose: collects analytics data for the software application only. The data is hosted in the European Union (EU).
Article 6 — Cookies and Tracking Technologies
The Platform uses cookies and similar technologies. In accordance with the CNIL deliberation of September 17, 2020 and the applicable guidelines, the placement of cookies that are not strictly necessary is subject to your prior consent.
| Cookie type | Purpose |
|---|---|
| Technical/essential cookies | Necessary for the operation of the Service (session, authentication). Not subject to consent. |
| Analytical cookies (<span translate="no">Vercel Analytics</span>) | Anonymized audience measurement. Subject to consent or configuration in privacy-first mode. |
| Third-party cookies (Stripe) | Secure management of payment forms. Deposited only during a transaction. |
You can configure your browser to refuse all or some cookies. Refusing technical cookies may alter the operation of the Service.
Article 7 — Rights of Data Subjects
In accordance with the GDPR (articles 15 to 22), you have the following rights regarding your personal data: Right of access: obtain a copy of the data concerning you. Right of rectification: correct inaccurate or incomplete data. Right to erasure (“right to be forgotten”): request the deletion of your data in the cases provided for by the GDPR. Right to restriction of processing: request temporary suspension of the processing of your data. Right to portability: receive your data in a structured and machine-readable format. Right to object: object to the processing of your data based on legitimate interest. Right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out before withdrawal. To exercise your rights, send your request by e-mail to contact@nexus-tok.com. NexusTok undertakes to respond to you within one (1) month of receipt of your request, a period which may be extended by an additional two (2) months in the event of a complex request. If you believe that your rights are not respected, you can lodge a complaint with the National Commission for Information Technology and Liberties (CNIL): CNIL — National Commission for Information Technology and Liberties 3, Place de Fontenoy — TSA 80715 — 75334 PARIS CEDEX 07 Website: https://www.cnil.fr Telephone: +33 (0)1 53 73 22 22
Article 8 — Data Security
NexusTok implements appropriate technical and organizational measures to guarantee the security, integrity and confidentiality of personal data, in particular: Encryption of data in transit via the TLS/HTTPS protocol. Encrypting data at rest in the database. Password hashing with a robust algorithm (bcrypt). Strict access control to hosting systems. ProDDoS protection and application firewall via Cloudflare. Logging and monitoring system access. In the event of a personal data breach likely to create a risk for the rights and freedoms of the persons concerned, NexusTok undertakes to notify the CNIL within 72 hours in accordance with article 33 of the GDPR, and to inform the persons concerned if the risk is high.
Article 9 — Changes to the Privacy Policy
This Confidentiality Policy may be updated at any time, particularly in the event of legal or regulatory changes, changes to the services offered or changes in subcontractors. The current version is always accessible at https://nexus-tok.com/privacy. In the event of a substantial modification, Users will be informed by e-mail with at least 15 days' notice before the new provisions come into force.
Article 10 — Contact
For any questions relating to this Privacy Policy or the processing of your personal data, you can contact the Company: By email: contact@nexus-tok.com By post: NexusTok (SAS) — 173 rue de Courcelles, 75017 Paris, France