whats-best.ai
Search Sign in

Payment

Novalnet

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Novalnet AG · www.novalnet.de

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Novalnet AG is a BaFin-supervised payment institution under the German ZAG, register number 122702, in Garching near Munich. Scores run highest on payment methods and settlement and reconciliation, both spanning 6 to 7: local methods are named country by country — TWINT and PostFinance for Switzerland, iDEAL|Wero for the Netherlands, paydirekt for Germany, Multibanco and MB Way for Portugal — and payouts run every three days, weekly, biweekly or monthly in 25 currencies, each with a transaction-level settlement file in CSV, XML, MT940 and IDoc. Recurring billing and licence and account terms sit at 6. Weakest is checkout and SCA at 4: the pages show an "SCA-kompatibel" badge and one line of AI-based fraud management, and no public information on 3-D Secure 2, exemptions or authorisation rates. Differences are narrow — sovereignty and pricing transparency each span 5 to 6. The payments engineer scored sovereignty 5, weighing a trust-page EU-processing guarantee against imprint entities in the UK, the US and India; on pricing, published per-method rates stop short of chargeback, refund, payout and conversion fees, leaving the effective fee uncomputable.

Report an error

Speaks for it

  • Local payment methods named market by market — TWINT and PostFinance for Switzerland, paydirekt for Germany, iDEAL|Wero for the Netherlands, Multibanco and MB Way for Portugal — with acceptance in over 125 currencies
  • Payouts every three days, weekly, biweekly or monthly in 25 currencies, each carrying a transaction-level settlement file itemising all cost items
  • A BaFin-supervised payment institution under the ZAG, register number 122702, with merchant funds in insolvency-protected trust accounts segregated from company assets
  • Per-method rates published — VISA and Mastercard at Tx 0,24€ + D 1,70%, SEPA at Tx 0,24€ + D 1,50% — alongside a 25€ monthly fee and no contract term
  • Sandbox dashboard and API keys from day one, with live payment processing stated for days 3 to 5

Report an error

Held against it

  • Strong customer authentication documented only as an "SCA-kompatibel" badge, with no public information on 3-D Secure 2 handling, exemptions or authorisation rates
  • The effective fee is not computable from the public pages — we found no public information on chargeback, refund or payout fees or a currency-conversion markup
  • We found no public information on reserve or rolling-hold conditions, termination notice periods, or a route to appeal a freeze
  • We found no public information on a process for exporting stored payment tokens to another provider
  • The EU-processing guarantee sits on a trust page, and we found no public information on a subprocessor list behind imprint entities in the UK, the US and India

Report an error

Best for

  • You sell into Germany, Switzerland, the Netherlands and Portugal and want locally named methods such as TWINT, PostFinance, paydirekt and iDEAL|Wero under a single contract
  • Your finance team closes months on transaction-level settlement files with scheduled exports in CSV, XML, MT940 or IDoc by email or SFTP
  • You run subscriptions on SEPA direct debit, card, PayPal or invoice and rely on automatic retries, dunning and an end-customer cancellation portal
  • You need a German, BaFin-supervised contracting entity with merchant funds in insolvency-protected trust accounts

Report an error

Avoid if

  • You need to build checkout against documented 3-D Secure 2, exemption or authorisation-rate behaviour — the captured pages go no further than an SCA-compatible badge
  • You must know your full effective cost before signing — the published rates leave chargeback, refund, payout and currency-conversion fees open
  • You want bad-day terms in writing — reserve conditions, freeze reasons, notice periods and appeal routes — before routing merchant funds through the provider
  • Your compliance review requires a subprocessor list or a data processing agreement standing behind the trust-page EU-processing statement

Report an error

The scores

Payment methods & local coverage

Show reasoning
How this is scored

Which methods a European customer can actually pay with — cards and wallets, SEPA Direct Debit, and the local methods that decide conversion per country — judged on the named list per market rather than on a method count.

0 — Cards only, or a method list with no statement of which countries and currencies each one covers.

3 — Major cards and wallets plus one or two European methods, with local coverage stated vaguely ("many local methods") and no SEPA Direct Debit.

5 — Cards, Apple Pay and Google Pay, SEPA Direct Debit, and the main local methods for DACH and Benelux (iDEAL or Wero, Bancontact, Klarna or invoice) listed by name with the countries they serve.

8 — Broad EU coverage named per country — including methods such as BLIK, TWINT, Przelewy24, EPS and Wero — multi-currency acceptance with settlement currencies stated, and which methods support refunds and recurring charges documented per method.

10 — Coverage is documented as a matrix a merchant can plan against: every method with its countries, currencies, refund, partial-capture and recurring support, and the provider's own acquiring versus third-party routing stated per method.

Report an error

The Finance Lead

The method list is genuinely per-country and named: SEPA Direct Debit, iDEAL|Wero for the Netherlands, TWINT and PostFinance for Switzerland, paydirekt for Germany, Multibanco for Portugal, alongside cards, Apple Pay, Google Pay and over 125 acceptance currencies with 25 payout currencies. What stops me planning against it as a matrix: I found no public information on refund support per method, recurring support is documented only for SEPA, PayPal, invoice and cards, and methods such as BLIK, Przelewy24 and EPS are not named. 2 6 7 9

Report an error

The E-Commerce Lead

This is a named list, not just a count: paydirekt for Germany, iDEAL|Wero for the Netherlands, TWINT and PostFinance for Switzerland, Multibanco and MB Way for Portugal, plus SEPA direct debit, cards and wallets, with acceptance claimed in over 125 currencies and payouts in 25. Coverage across my markets is uneven — Belgium, Austria, Poland and the Nordics appear only inside a country list and I found no public information naming a method for them — and refund and recurring support is documented only for SEPA, PayPal, invoice and card rather than per method. 1 6 7 9 11

Report an error

The SaaS Founder

Coverage is named country by country — TWINT and PostFinance for Switzerland, iDEAL|Wero, paydirekt, Multibanco and MB Way, SEPA direct debit and credit transfer, on top of cards, Apple Pay and Google Pay — with payouts in 25 currencies. What holds it back is that recurring support is documented only for a handful of methods, and we found no public information on refund or recurring support per local method, nor on BLIK, Przelewy24 or EPS even though the countries are listed. 6 7 9 2 13

Report an error

The Payments Engineer

The payment-methods pages are specific per market — TWINT and PostFinance for Switzerland, iDEAL|Wero for the Netherlands, paydirekt for Germany, Multibanco and MB Way for Portugal, SEPA Direct Debit with a payment guarantee, plus cards and wallets, with acceptance in over 125 currencies and payouts in 25. What I cannot plan against is the per-method fine print: we found no public information on refund or partial-capture support per method, so coverage is a named list, not a matrix. 7 6 1 13 11

Report an error

The Compliance Officer

Cards, Apple Pay, Google Pay and SEPA Direct Debit are confirmed, and local methods are named with their countries — paydirekt and invoice purchase for Germany, iDEAL|Wero for the Netherlands, TWINT and PostFinance for Switzerland, Multibanco and MB Way for Portugal — across a European country list and acceptance in over 125 currencies. A merchant planning country by country still has gaps: we found no public information on a named Belgian method, on Polish, Austrian or Finnish methods, or on refund support documented per method. 1 6 7 9

Report an error

The Skeptic

Cards, wallets and SEPA Direct Debit are named, and the local list is real — iDEAL|Wero, paydirekt, TWINT, PostFinance, Multibanco and MB Way each tied to their country — but I found no public information on Bancontact for Belgium, or BLIK, Przelewy24 or EPS for Poland and Austria. The 150-method headline is a count, not a matrix a merchant can plan against: refund support is undocumented per method and recurring support is stated only for card, SEPA, PayPal and invoice. 1 6 7 9

Report an error

Checkout, SCA & fraud

Show reasoning
How this is scored

The path from basket to authorised payment under PSD2: hosted and embedded checkout options, 3-D Secure and SCA exemption handling, fraud screening, and what the provider documents about keeping legitimate payments from failing.

0 — A single redirect page with no statement on 3-D Secure, SCA or fraud screening.

3 — Hosted checkout with 3-D Secure 2 mentioned, fraud screening as an unexplained add-on, and no word on exemptions or declined-payment handling.

5 — Hosted and embedded checkout options, 3-D Secure 2 with SCA handled by the provider, configurable fraud rules, and the resulting PCI DSS scope for each integration type stated.

8 — SCA exemptions (low value, transaction risk analysis, merchant-initiated) applied and documented, fraud tooling with rules and risk scores exposed to the merchant, network tokens or account updater, and liability shift explained per flow.

10 — Authorisation is engineered and shown: exemption strategy documented, soft-decline retry handled, authorisation-rate reporting by method and issuer country, and a checkout the merchant can run in their own domain while staying at the lowest PCI scope.

Report an error

The Finance Lead

Checkout comes in inline, overlay and redirect forms with branding and country-specific method display, hosted in a PCI DSS Level 1 environment that relieves the merchant of own PCI compliance, and the strongest SCA statement I found is an "SCA-kompatibel" badge next to a one-line "KI-basiertes Betrugsmanagement". I found no public information on 3-D Secure 2, exemption handling, configurable fraud rules, liability shift or authorisation-rate reporting, so the authorisation path is asserted rather than shown. 1 8 9 11

Report an error

The E-Commerce Lead

The checkout is what I sell with: the form shows embedded, overlay or redirect, the buyer stays on my page, Novalnet stays invisible during payment, and the form is brandable and responsive with country-specific method selection. PSD2 depth is thin for that strength — strong customer authentication appears only as a certification line, fraud management is one sentence of AI-based tooling, and I found no public information on exemption handling, challenge logic, soft declines or authorisation rates. 1 8 9 11

Report an error

The SaaS Founder

Hosted, inline, overlay and redirect checkout options, one-click tokenised repeat purchases, and PCI DSS Level 1 hosting that relieves the merchant of its own compliance is a good default position. But the captured pages go no further than a 'SCA-kompatibel' badge: we found no public information on 3-D Secure 2 handling, SCA exemption strategy, soft-decline retries or liability shift, and the AI-based fraud management is not explained to the merchant. 9 8 1 11

Report an error

The Payments Engineer

Checkout comes in inline, overlay and redirect form, and the hosted payment form is documented as running in a PCI DSS Level 1 environment that takes the merchant out of PCI scope — the statement I want to see. But the entire PSD2 story is one certification badge reading "SCA-kompatibel" plus an AI-based fraud management claim; we found no public information on 3-D Secure 2 handling, exemption strategy, soft-decline behaviour, authorisation-rate reporting, or fraud rules exposed to the merchant. 9 1 11 8

Report an error

The Compliance Officer

Hosted, inline, overlay and redirect checkout are documented, with the payment form hosted in a PCI DSS Level 1 environment that relieves the merchant of PCI compliance, and a homepage claim of being SCA-compatible. We found no public information naming 3-D Secure 2, SCA exemption handling, configurable fraud rules or declined-payment handling; fraud screening appears only as AI-based fraud management with no merchant-facing controls, and PCI scope is stated only for the hosted form while a Direct API integration is also offered. 1 8 9 11

Report an error

The Skeptic

Hosted, inline, overlay and redirect checkout are real options, and the payment form is hosted in a PCI DSS Level 1 environment that relieves the merchant of own PCI compliance — but I found no public statement on 3-D Secure, SCA exemptions or declined-payment handling, only a homepage claim of being SCA-compatible. Fraud screening is one line about AI-based fraud management, with no rules or risk scores exposed to the merchant. 1 8 9 11

Report an error

Subscriptions & recurring payments

Show reasoning
How this is scored

Charging the same customer again: card-on-file and merchant-initiated transactions, SEPA mandates, subscription logic and dunning — and whether the stored payment credentials can leave with the merchant.

0 — No stored payment methods; every charge needs the customer to pay again.

3 — Card-on-file tokens for repeat charges, but no SEPA mandate handling, no subscription logic, and failed-payment handling left entirely to the merchant.

5 — Stored cards and SEPA Direct Debit mandates, merchant-initiated transactions documented, and basic subscription plans with scheduled charges and failed-payment notifications.

8 — Subscription billing with trials, proration and plan changes, smart retries and dunning, card account updater, mandate management with pre-notification, and a documented process for exporting payment tokens to another provider.

10 — Recurring revenue is a first-class product: usage-based and invoice-based billing, dunning with measurable recovery, token migration in and out documented with a stated timeline and format, and recurring support stated for every local method that allows it.

Report an error

The Finance Lead

Subscription logic is real: an API taking interval, period and tariff parameters, predefined plans with trial periods, pause and cancel, intelligent retries on failed charges, dunning with automatic reminders, and an end-customer cancellation portal, with recurring documented for SEPA Direct Debit, PayPal, invoice and cards. I found no public information on SEPA mandate pre-notification, card account updater, proration, or any documented process for exporting stored tokens to another provider — and token portability is exactly what I need in writing. 9 10 11

Report an error

The E-Commerce Lead

Subscriptions are a real product: an API with tariff, interval and period parameters, plans configured in the merchant portal with trial periods and runtime, pause and cancel, automatic retries with intelligent retry logic, dunning, and an end-customer portal for cancellations. Recurring support is stated for SEPA direct debit, PayPal, invoice and credit card only, and I found no public information on SEPA mandate pre-notification, an account updater, or a documented process for exporting payment tokens to another provider. 9 11

Report an error

The SaaS Founder

Subscription plans with interval, amount, trial period and runtime configurable in the portal or via API, recurring charges against tokenised SEPA mandates, cards, PayPal and invoice, plus intelligent retry logic and automatic dunning — that is the machinery a subscriber business lives on. The gaps that matter to me: we found no public information on proration for mid-cycle plan changes, SEPA mandate pre-notification, a card account updater, or any documented process for exporting payment tokens to another provider, which is the difference between owning a customer base and renting it. 11 9

Report an error

The Payments Engineer

Recurring billing is clearly a real product: a subscription API with tariff, interval and period parameters, predefined plans with trial period and runtime, free trials, pause and cancel, intelligent retry logic with email notification, dunning and reminders, an end-customer cancellation portal, and recurring support named for SEPA, PayPal, invoice and card. We found no public information on proration, a card account updater, SEPA mandate pre-notification, or any process for exporting stored payment tokens to another provider. 11 9

Report an error

The Compliance Officer

Tokenised recurring charges are documented for SEPA Direct Debit, PayPal, invoice and card, with a subscription API (tariff, interval, period), predefined plans including trial periods, intelligent retry on failed payments, dunning with automatic reminders, pause and cancel, and an end-customer portal for cancellation. We found no public information on proration, a card account updater, SEPA mandate management with pre-notification, or a documented process for exporting payment tokens to another provider. 9 10 11

Report an error

The Skeptic

Recurring is genuinely built: tokenised charges across SEPA Direct Debit, card, PayPal and invoice, a subscription API with interval and tariff parameters, trials and tiered pricing, intelligent retries with dunning, and an end-customer cancellation portal. But I found no public information on SEPA mandate pre-notification, proration, card account updater, or — the one I always look for — any process for exporting payment tokens to another provider. 9 11

Report an error

Settlement, reconciliation & API

Show reasoning
How this is scored

Getting the money and knowing what it was: payout cadence and currencies, fee itemisation per transaction, reports that match a bank statement, and an API and webhooks a team can build finance processes on.

0 — Payouts on an unstated schedule, one net amount per payout, and no API or report beyond an on-screen list.

3 — A stated payout schedule and CSV exports, but fees netted invisibly into payouts and an API with thin documentation.

5 — Payout frequency and delay stated, per-transaction fee breakdown in reports, a documented REST API with webhooks and a test mode, and exports that link each payout to its transactions.

8 — Configurable payout schedules and settlement currencies, reconciliation reports that match bank lines, accounting integrations or exports named, a versioned API with idempotency and published rate limits, and a public status page with incident history.

10 — Finance can close the month from the provider's data: interchange and scheme fees itemised per transaction, automated reconciliation to the ledger, a deprecation policy for the API, and full historical data exportable after the contract ends.

Report an error

The Finance Lead

Payouts run on a stated and configurable cadence — 3-day, weekly, biweekly or monthly — in 25 currencies, with a choice between gross payout and separately billed fees or net deduction, and each payout carries a transaction-level settlement file itemising the cost positions; reports span reconciliation and chargeback statistics and export in CSV, XML, XLSX, JSON, SOAP, IDoc and MT940 on daily, weekly or monthly schedules into accounting software. What I could not find: any public word on webhooks, API versioning, idempotency, rate limits or a status page with incident history. 11 12 13

Report an error

The E-Commerce Lead

Payouts run every 3 days, weekly, biweekly or monthly in 25 currencies, gross or net, and each payout carries a transaction-level settlement file that itemises the cost positions. Reporting is strong for a finance team — reconciliation and chargeback reports, up to 75 selectable fields, exports in formats including MT940 with scheduled delivery by email or SFTP. The build layer is the gap: beyond a sandbox and a RESTful API mention, I found no public information on webhooks, API versioning, idempotency, rate limits or a public status page with incident history. 11 12 13

Report an error

The SaaS Founder

Payout cycles selectable from every three days to monthly, a transaction-level settlement file per payout with all cost positions, up to 75 configurable report fields, exports in CSV, XML, MT940 and SAP IDoc with scheduled SFTP delivery, plus immediate sandbox and API keys — my finance team could close a month on that. Holding it back: we found no public information on webhooks, API versioning and idempotency, published rate limits, or a public status page with incident history. 13 12 9 11

Report an error

The Payments Engineer

Payouts run on a stated cycle of every three days, weekly, biweekly or monthly in 25 currencies, each payout carries a settlement file with a transaction-level breakdown of all cost items, and reports export in CSV, XML, MT940 and IDoc on a schedule via email or SFTP — finance can build on that. My integrator's hygiene list is empty though: we found no public information on webhooks, API versioning, idempotency keys, published rate limits, or a public status page with incident history; the sandbox dashboard with API keys on day one is the one engineering positive. 13 12 11 1

Report an error

The Compliance Officer

Payout cycles are stated (3-day, weekly, biweekly, monthly) with payout in 25 currencies, each payout carries a settlement file with a transaction-level breakdown of all cost positions, and the merchant can choose gross or net payout, assign per-transaction IDs for accounting, and receive reconciliation reports and exports in CSV, XML, IDoc and MT940 on a schedule by e-mail or SFTP. We found no public information on webhooks, a versioned API with idempotency and rate limits, a public status page, or interchange and scheme fee itemisation, which leaves the API side of finance automation thin next to the reporting side. 11 12 13

Report an error

The Skeptic

Payout cycles from a 3-day rhythm to monthly, 25 payout currencies, a gross-or-net payout choice, and a settlement file per payout with a transaction-level breakdown of all cost positions — that is the itemisation a finance team needs, plus MT940, IDoc and SOAP exports for SAP-class accounting and scheduled reports by email or SFTP. The gaps: I found no public information on webhooks, idempotency, rate limits or a public status page, and the delay between transaction and payout is not stated. 9 12 13

Report an error

Licence, risk & account terms

Show reasoning
How this is scored

Who holds the merchant's money under which licence, and what the contract lets the provider do on a bad day: freezes, reserves, termination, chargebacks. Scored on what the terms and the imprint state, not on reputation.

0 — No regulated entity named; terms allow freezing funds and terminating the account at any time with no notice, reason or timeline.

3 — A licence mentioned without the entity, supervisor or register number, and terms that permit reserves and holds with no stated limits.

5 — The regulated entity named with its supervisor and licence type, safeguarding of merchant funds stated, chargeback fees and dispute process published, and a notice period for ordinary termination.

8 — Entity, supervisor, register number and passporting stated per country; reserve and rolling-hold conditions defined with limits and release timelines; freeze and termination terms with reasons and a route to appeal; PCI DSS level and attestation published.

10 — The bad day is written down: every regulated entity in the chain named with register links, reserve calculation disclosed, funds release timelines after termination committed, a documented complaint route to the supervisor, and exit terms that include handing back payment tokens and transaction history.

Report an error

The Finance Lead

The regulated chain is properly written down: Novalnet AG supervised by BaFin under the ZAG with register number 122702, the Handelsregister München entry, enumerated licences covering the full flow to payout, and merchant funds in insolvency-protected trust accounts under §13 ZAG a.F. and §17 ZAG n.F. with banks holding no set-off or lien rights, plus a published PCI DSS Level 1. For the bad day I found no public information on rolling-reserve conditions with limits and release timelines, termination notice periods, freeze reasons or an appeal route, and no chargeback fee figure. 4 9 13 14

Report an error

The E-Commerce Lead

Licensing transparency is the best part: BaFin register number 122702, the full catalogue of ZAG licences per service line, Handelsregister München HRB 167381, and merchant money in escrow accounts under the ZAG that are insolvency-protected and segregated from company assets. The bad day is not written down: I found no public information on reserve or rolling-hold conditions and limits, termination notice periods, chargeback fees, or a route to appeal a freeze or termination. 4 13 14

Report an error

The SaaS Founder

The licence story is unusually well documented: a BaFin-supervised payment institution with register number 122702, the full list of ZAG services, escrow accounts protected against insolvency under §17 ZAG n.F., Bundesbank and BaFin reporting, a published commercial register entry, and PCI DSS Level 1 stated. What the pages do not show is the bad day: we found no public information on reserve or rolling-hold conditions, freeze and termination timelines with a route to appeal, or published chargeback fees and a merchant dispute process. 14 4 13 9

Report an error

The Payments Engineer

The licence picture is unusually complete: Novalnet AG is a BaFin-supervised payment institution with register number 122702 and its ZAG services itemised service by service, merchant funds sit in trust accounts under ZAG insolvency protection and segregated from company assets, and PCI DSS Level 1 is published. The bad-day text is what I cannot find: no passporting stated per country, and we found no public information on reserve or rolling-hold conditions with limits and release timelines, on freeze or termination reasons with a route to appeal, or on chargeback fees — even though a chargeback hotline with a 17-digit transaction number lookup exists. 14 4 13 9 2

Report an error

The Compliance Officer

Novalnet AG is named with BaFin supervision under the ZAG, register number 122702, the licensed services listed with their statutory basis, commercial register HRB 167381 München, audits by auditors, the Deutsche Bundesbank and BaFin, and merchant funds in insolvency-protected trust accounts under §13 ZAG a.F. and §17 ZAG n.F. The bad day is what we cannot see: we found no public information on reserve or rolling-hold conditions, freeze and termination terms with reasons or an appeal route, chargeback fees, or a notice period for ordinary termination beyond the statement 'Keine Vertragslaufzeit'. 2 4 13 14

Report an error

The Skeptic

The licence side is unusually clear: BaFin register number 122702, the full ZAG licence catalogue with its statutory paragraphs, escrow accounts under §13 and §17 ZAG that are insolvency-protected with banks holding no set-off or pledge rights, and regular Bundesbank and BaFin reporting. But the bad day is silent — I found no public information on reserve or rolling-hold conditions, termination notice periods, chargeback fees, or any route to appeal a freeze. 4 9 13 14

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Who the contracting and regulated entity is, and where transaction and cardholder data are processed and stored. Independently sourced by the sovereignty pipeline. The card schemes are US-based for every provider, so the scheme layer is not held against any one vendor; the part the vendor controls is.

0 — Non-EU contracting entity, no statement on where payment data is processed, and subprocessors unnamed.

3 — An EU licensed entity contracts, but payment and customer data is processed outside the EU by default without an explained safeguard, or the subprocessor list is absent.

5 — EU contracting and regulated entity, EU processing stated for core payment data, but the group parent or significant parts of the chain (fraud scoring, support, analytics) are non-EU without a stated safeguard.

8 — EU entity and EU licence, payment and cardholder data processed and stored in the EU on named infrastructure, subprocessor list published with locations, and a DPA covering the processing the provider does as processor versus as controller.

10 — Sovereign end to end and evidenced: European ownership, EU entity and licence, every processing location and subprocessor European, European rails (SEPA, Wero or national schemes) offered alongside cards, and certifications published.

Report an error

The Finance Lead

The contracting entity is the German, BaFin-licensed Novalnet AG and the data-centre page is unusually concrete — facilities exclusively in Germany, redundant infrastructure within Europe, all transaction and personal data processed only within the EU, and certifications from ISO 27001 IT-Grundschutz through ISAE 3402 Type II. But the imprint also lists affiliated entities in the UK, US and India, and I found no public information on ownership, a subprocessor list with locations, or a data processing agreement standing behind the marketing-level EU guarantee. 4 5 14

Report an error

The E-Commerce Lead

The contracting and regulated entity is the German, BaFin-supervised Novalnet AG, with data centers exclusively in Germany and transaction and personal data stated as processed only within the EU, backed by a deep certification list for the German infrastructure. The group picture is murkier: the imprint lists entities in the United Kingdom, the United States and an Indian technology partner, and I found no public information on a subprocessor list with locations, on group ownership, or on safeguards covering what those entities process. 4 5 14

Report an error

The SaaS Founder

A German AG under BaFin supervision contracts, the trust page states all transaction and personal data is processed exclusively within the EU with data centres exclusively in Germany, and the certification stack runs from ISO 27001 IT-Grundschutz to ISAE 3402 Type II. Caveats that hold it back: the imprint lists affiliated entities in the United Kingdom, the United States and India including an India technology partner, and we found no published subprocessor list with locations or a data processing agreement in the captured pages. 5 4 14

Report an error

The Payments Engineer

The contracting entity is the German, BaFin-licensed Novalnet AG, and the trust pages state that all transaction and personal data is processed exclusively within the EU, in data centres exclusively in Germany with redundant infrastructure within Europe. That guarantee sits on a marketing page rather than a data processing agreement, the imprint names a UK entity and an India technology partner without any stated safeguard for what they touch, and we found no public information on a subprocessor list with locations. 4 5 14

Report an error

The Compliance Officer

The contracting and regulated entity is German, and the provider states that all transaction and personal data are processed exclusively within the EU and stored in Germany, in data centres exclusively in Germany with an extensive certification list including ISO 27001 (IT-Grundschutz, BSI) and PCI DSS. The data-residency guarantee sits on a trust page and the captured privacy policy shows only section headings with no storage details; we found no public information on a subprocessor list with locations or a data processing agreement separating processor from controller roles for payment data, and the imprint lists a UK, a US and an India technology-partner entity without a stated safeguard for the parts of the chain they touch. 3 4 5

Report an error

The Skeptic

The contracting entity is the German, BaFin-supervised Novalnet AG, data centres are exclusively in Germany with EU-only processing claimed, and a stack of ISO, PCI and IT-Grundschutz certifications is published. But the imprint also lists affiliated entities in the UK, the US and an India technology partner with no stated safeguard, and I found no subprocessor list, no ownership disclosure and no data processing agreement behind the marketing-page guarantee. 4 5

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a merchant can compute the effective fee for their own mix of cards, countries and methods — including cross-border and currency conversion markups, chargebacks, refunds, payouts and monthly fees — from public pages alone.

0 — No public prices at all; every rate is a sales conversation.

3 — A headline percentage exists, but it is unclear which cards and countries it covers, and cross-border, currency conversion or chargeback fees are unstated — the effective fee is unknowable.

5 — Rates published per main method with domestic and international cards distinguished, but at least one commonly incurred cost (currency conversion markup, chargeback fee, payout or monthly fee) is missing or "on request".

8 — Every method priced publicly, cross-border and currency conversion markups stated, chargeback, refund and payout fees listed, minimum monthly fees and contract term given, and whether the model is blended or interchange++ said plainly.

10 — Complete fee computability: the effective rate derivable for a given volume, card mix and country mix — interchange++ with the markup published or a blended rate with every exception listed — plus volume tiers, reserves and every ancillary fee on a public page.

Report an error

The Finance Lead

Rates are published per method — SEPA at 0,24€ + 1,50%, iDEAL|Wero at 0,28€ + 0,30%, VISA and Mastercard at 0,24€ + 1,70%, non-EU and commercial cards at 0,24€ + 2,90% — with a 25€ monthly fee, a 99€ setup fee, no contract term, and a volume tier from 25.000 EUR monthly turnover with individual prices. I still cannot compute an effective fee from public pages: currency conversion markup, chargeback, refund and payout fees are not stated, PayPal's rate of 0,24€ + 0,00 depends on revenue and industry, and restricted-category prices are on request. 2 13

Report an error

The E-Commerce Lead

I can compute my card cost from the public page: VISA and Mastercard at Tx 0,24€ + D 1,70%, commercial and non-EU cards at Tx-Kosten 0,24€ + 2,90 %, SEPA Lastschrift at Tx 0,24€ + D 1,50%, iDEAL | Wero at Tx 0,28€ + D 0,30%, a 25€ monthly fee, 99€ setup fee and no contract term. The edges stay unknowable: I found no public information on currency conversion markups, chargeback, refund or payout fees, the pricing pages do not say plainly whether the model is blended or interchange++, and restricted-category prices are handled via sales contact. 2 13

Report an error

The SaaS Founder

Per-method rates are public — VISA and Mastercard at Tx 0,24€ + D 1,70% with non-EU and commercial cards at Tx 0,24€ + 2,90%, SEPA at Tx 0,24€ + D 1,50%, iDEAL|Wero at Tx 0,28€ + D 0,30% — alongside a 25€ monthly fee, a 99€ setup fee and no contract term. But I still cannot compute my effective fee: we found no public information on chargeback, refund or payout fees or currency conversion markups, Google Pay and most of the 150+ methods carry no published price, and PayPal's 'Tx 0,24€ + D 0,00' is conditioned on revenue and industry without the conditions shown. 2

Report an error

The Payments Engineer

Card and main-method rates are published per method — VISA and Mastercard at "Tx 0,24€ + D 1,70%", non-EU and commercial cards distinguished at "Tx-Kosten 0,24€ + 2,90 %", iDEAL|Wero at "Tx 0,28€ + D 0,30%" — alongside a stated "25€ Monatliche Gebühr", "99€ Einrichtungsgebühr" and "Keine Vertragslaufzeit". The effective fee still isn't computable: we found no public information on chargeback, refund or payout fees or a currency conversion markup, PayPal carries a 0,00% rate whose conditions depend on revenue and industry, restricted-category prices are said to deviate from the standard, and the pages don't say whether the model is blended or interchange++. 2

Report an error

The Compliance Officer

Per-method rates are published with the domestic and non-EU card distinction stated — VISA and Mastercard 'Tx 0,24€ + D 1,70%', the non-EU and commercial surcharge 'Tx-Kosten 0,24€ + 2,90 %', SEPA 'Tx 0,24€ + D 1,50%' — alongside '99€ Einrichtungsgebühr', '25€ Monatliche Gebühr' and 'Keine Vertragslaufzeit'. We found no public information on currency conversion markups, chargeback, refund or payout fees, or on whether the model is blended or interchange++, so the effective fee for a cross-border mix is not computable from the public pages. 2 13

Report an error

The Skeptic

The pricing page is refreshingly concrete: per-method transaction fee plus disagio, domestic versus non-EU and commercial card rates distinguished at 0,24€ + 2,90 %, a 25€ monthly fee, a 99€ setup fee and no contract term. But the effective fee is still not computable — I found no public information on a currency conversion markup despite 25 payout currencies, no chargeback, refund or payout fee, and PayPal's 0,00 % carries a footnote that conditions depend on revenue and industry. 2 13

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency EU only ⚠ unverified 3/3 pts 5 Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (15)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.novalnet.de Checked 22 Sep 2026 Details →
  2. 2 Pricing page www.novalnet.de Checked 22 Sep 2026 Details →
  3. 3 Privacy policy www.novalnet.de Checked 22 Sep 2026 Details →
  4. 4 Legal notice www.novalnet.de Checked 22 Sep 2026 Details →
  5. 5 Security / trust page www.novalnet.de Checked 30 Sep 2026 Details →
  6. 6 Payment methods & local coverage — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  7. 7 Payment methods & local coverage — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  8. 8 Checkout, SCA & fraud — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  9. 9 Checkout, SCA & fraud — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  10. 10 Subscriptions & recurring payments — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  11. 11 Subscriptions & recurring payments — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  12. 12 Settlement, reconciliation & API — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  13. 13 Settlement, reconciliation & API — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  14. 14 Licence, risk & account terms — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →
  15. 15 Licence, risk & account terms — found from sitemap www.novalnet.de Checked 1 Oct 2026 Details →