Privacy

Privacy Policy

This policy describes the technical processing and data used in the current pre-launch version of CornerEngine.

1

Account data

Administrative or test accounts may retain an internal identifier, username, email address, hashed password, role, account status, creation date and last sign-in date. CornerEngine does not store passwords in plain text and does not collect card details at this stage.

2

Session and authentication

After authentication, a strictly necessary session cookie is used. It stores only identifiers and technical information required for authentication, roles and CSRF protection. The email address is loaded from server-side storage when required and is not placed in the session cookie.

3

Security and IP address

An IP address may be processed temporarily to limit sign-in attempts and protect the platform against abusive access. The limiter operates in application memory within a maximum 15-minute window and does not create a marketing profile of the visitor.

4

Logs and administrative audit

CornerEngine retains technical logs and administrative events for error diagnosis, security and traceability. Values such as passwords, tokens, cookies, sessions and API keys are automatically masked before being written to structured logs.

5

Retention periods

An authenticated session lasts for a maximum of 8 hours. Temporary sign-in rate-limiting data is retained for no longer than 15 minutes. Technical logs older than 30 days are removed when the web process starts, while the administrative audit is limited to 12 months and a maximum of 1,000 events. Account data is retained while the account is required or until its justified deletion.

6

Providers and external resources

The interface currently uses Bootstrap and Bootstrap Icons resources delivered through cdn.jsdelivr.net. When these resources load, the browser may transmit ordinary technical data to the provider, such as the IP address, browser type, date and requested resource. CornerEngine does not currently use advertising services or behavioural analytics tools on the public website.

7

Rights of data subjects

Subject to applicable law, data subjects may request access, rectification, restriction, objection, portability or deletion of their data. Official operator details and the dedicated request channel will be completed before the commercial launch.

Pre-launch document

The operator's final legal identity, detailed legal bases and official contact details will be completed and verified before commercial services are activated.