Privacy Policy
Compliant with the General Data Protection Regulation (GDPR — EU 2016/679)
Last updated: 6/22/2026
1. Data Controller
Controller: NeuraAPI SAS
Registered office: 12 Rue de la Paix, 75002 Paris, France
SIRET: To be completed
Data Protection Officer (DPO):
12 Rue de la Paix, 75002 Paris, France
2. Data Collected
In the course of our services, we collect the following categories of data:
Identification Data
- First and last name
- Email address
- Password (encrypted)
- Username
Billing Data
- Billing address
- Payment information (processed by Stripe, we do not have access to card numbers)
- Transaction history
Usage Data
- API keys (encrypted)
- API call history (prompts, responses, timestamps)
- Usage statistics (number of calls, credits consumed)
- Performance and diagnostic data
Connection Data
- IP address
- Browser type and operating system
- Login date and time
- Pages visited and actions performed
3. Purpose of Processing
Your data is processed for the following purposes:
- Account management: Creation, management and authentication of user accounts
- Service provision: API access, template delivery, credit management
- Invoicing: Invoice issuance, payment tracking, reminders
- Customer support: Response to requests and problem resolution
- Service improvement: Usage statistics, performance optimization
- Security: Fraud prevention, abuse detection, attack protection
- Communication: Sending important service-related notifications
- Legal obligations: Retention of accounting and tax data
4. Legal Basis for Processing
Each data processing operation is based on a legal basis:
- Contract performance (Art. 6.1.b GDPR): Service provision, account management, invoicing
- Legitimate interest (Art. 6.1.f GDPR): Service security, improvement, fraud prevention
- Legal obligation (Art. 6.1.c GDPR): Retention of accounting and tax data
- Consent (Art. 6.1.a GDPR): Non-essential cookies, marketing communications
5. Data Retention Period
Your data is retained for the following periods:
- Account data: For the duration of the contractual relationship, then 3 years after the last login
- Billing data: 10 years (legal accounting obligation)
- API call history: 12 months after the last call
- Connection data: 12 months
- Cookies: Maximum 13 months
- Prospecting data: 3 years after the last contact
Upon expiry of these periods, data is deleted or irreversibly anonymized.
6. Data Recipients
Your data may be shared with the following categories of recipients:
- Technical providers: Vercel (hosting), Stripe (payments), Vercel Analytics (statistics)
- Payment providers: Stripe Inc. — secure payment processing
- Competent authorities: In the event of a legal obligation or judicial request
These providers are subject to contractual obligations guaranteeing the protection of your data in accordance with the GDPR. We never sell your data to third parties.
7. Transfers Outside the European Union
Some of our providers are located outside the European Union (notably in the United States). These transfers are governed by:
- Standard contractual clauses (SCCs) compliant with the European Commission's implementing decision
- The Privacy Shield (for certified providers)
- Additional appropriate safeguards in accordance with Articles 46 and following of the GDPR
8. Your Rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Obtain a copy of your data
- Right of rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): Request the deletion of your data
- Right to restriction of processing (Art. 18): Restrict the processing of your data
- Right to data portability (Art. 20): Receive your data in a structured format
- Right to object (Art. 21): Object to the processing of your data
- Right to withdraw consent: At any time, without affecting the lawfulness of prior processing
To exercise your rights, contact us at: dpo@neuraapi.com
You also have the right to lodge a complaint with the CNIL: www.cnil.fr
9. Cookies
Our website uses cookies in accordance with current regulations. For more information, please consult our Cookie Policy.
You can manage your cookie preferences via the consent banner displayed during your first visit.
10. Data Security
We implement the following technical and organizational measures to protect your data:
- TLS/SSL encryption for all communications
- Encryption of sensitive data at rest
- Multi-factor authentication (MFA) available
- Encrypted and securely managed API keys
- Restricted data access (principle of least privilege)
- Access logging and monitoring
- Regular security audits
11. Contact
For any questions relating to the protection of your personal data:
We commit to responding to your request within one month.