Who is the controller
The controller and official details are published in the Legal Notice. Personal-data requests must use only the address shown on this page and the Contact page.
Version: pre-launch Β· Last updated: β
The controller's identity and official contact channel must be completed before public data collection or commercial launch.
The controller and official details are published in the Legal Notice. Personal-data requests must use only the address shown on this page and the Contact page.
Depending on enabled features, processed data may include username, email address, password hash, internal account identifiers, role and status, authentication data, security and administration logs, language and theme preference, technical request data and the content of requests sent to the operator.
Account data is used to create and perform the user relationship; security data and logs are processed for the legitimate interests of protecting the platform, preventing abuse and evidencing operations; certain data may be retained for legal obligations. Consent will be used only where legally required, for example for optional technologies.
Data is provided directly by the user, generated through platform use or produced by security and audit controls. CornerEngine does not buy personal-data lists or create advertising profiles.
Access is limited to authorised persons and necessary technical providers such as hosting, infrastructure, email or security providers, according to their role and contractual duties. The public interface loads Bootstrap and Bootstrap Icons through cdn.jsdelivr.net; the browser connects directly to this third-party provider to receive those files. CornerEngine does not currently use advertising services or behavioural analytics tools. Personal data is not sold.
If a provider processes data outside the European Economic Area, the controller must document the applicable legal mechanism and safeguards before enabling that service.
The authenticated session has a configured maximum duration of 8 hours. Temporary authentication rate-limit data is kept for no more than 15 minutes. Technical logs older than 30 days are removed under the operational policy, while administrative audit data is limited to 12 months and at most 1,000 events. Account data is kept while the account is active and afterwards only as necessary for closure, legal claims or legal duties. Logs and audit records are deleted or anonymised when no longer needed.
Passwords are stored as hashes, the session cookie is HttpOnly and SameSite=Lax, Secure is required in production, forms use CSRF protection and authenticated pages use no-store. The IP address may be processed temporarily by the authentication rate limiter for no more than 15 minutes, without creating a marketing profile. No measure can eliminate risk completely.
Data-subject rights. Subject to the GDPR, you may request information, access, rectification, erasure, restriction, portability, objection and withdrawal of consent where applicable. You may also complain to the competent data-protection authority. In Romania, the supervisory authority is ANSPDCP.
Sports scores are automated, but they do not produce legal effects on individuals. CornerEngine does not use account data for automated decisions with legal or similarly significant effects.
Betting-related content is 18+. The platform is not designed to intentionally collect data from children.
Requests must allow identity verification without requiring more data than necessary. Material policy changes will be published with a new version and date.
These sources explain transparency obligations and data-subject rights. They do not replace configuration of CornerEngine's real controller identity.
Source check for Step 10J: 17 Aug 2026. The 'LEGAL READY' state remains separately controlled by real operator data and confirmation of legal review.