Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how Aiqon Limited (“Aiqon”, “we”, “us”, “our”), trading as Cornerly, collects, uses, shares and protects personal data. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Irish Data Protection Acts 1988–2018, and the ePrivacy Regulations 2011 (S.I. No. 336/2011).
Who we are. Aiqon Limited is a company registered in Ireland and is the data controller and contracting entity for the Cornerly platform. You can reach our privacy team at privacy@cornerly.ie.
1. Our two roles (controller and processor)
Cornerly has a two-sided model, so our role depends on whose data it is:
- We are the data controller for personal data about the business owners, managers and staff who use the Cornerly admin (account details, login credentials, billing and usage data) and about visitors to our marketing site.
- We are a data processor for the customer and order data that a business (our client, the “Merchant”) collects through its own Cornerly-powered storefront. The Merchant is the controller of that data; we process it strictly on the Merchant’s documented instructions to provide the Service, under a data processing agreement that forms part of our Terms of Service. If you are a customer of a Merchant, please also see that Merchant’s own privacy notice.
2. Personal data we collect
- Account data (controller): name, business name, email address, phone number, password (stored only as a salted hash, never in plain text), role, and contact details.
- Billing data (controller): subscription plan, invoices, and usage of metered add-ons. Card details are handled by our payment processor; we do not store full card numbers.
- Order data (processor): a customer’s name, phone number, email (if provided), order contents, pickup/collection time, loyalty activity, and payment status, submitted through a Merchant’s storefront.
- Communications: messages you send us (support, demo requests, sales enquiries) and our replies.
- Technical & usage data: IP address, device/browser information, and application logs needed to operate, secure and debug the Service.
- Cookies & similar technologies: see our Cookie Policy.
We do not sell personal data, we do not use it for third-party advertising, and we do not carry out profiling that produces legal or similarly significant effects.
3. Why we use your data and our legal bases
We rely on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)): to create and run your account, provide the Service, process orders, and take payment.
- Legal obligation (Art. 6(1)(c)): to keep accounting, tax and transaction records required by law.
- Legitimate interests (Art. 6(1)(f)): to secure, maintain, troubleshoot and improve the Service, prevent fraud and abuse, and respond to your enquiries. We balance these interests against your rights.
- Consent (Art. 6(1)(a)): for optional marketing emails and for any non-essential cookies. You may withdraw consent at any time.
4. Sharing and sub-processors
We share personal data only with trusted service providers that help us run Cornerly, each bound by a written contract and appropriate safeguards, and only as needed for their function. Our current categories of sub-processor are:
- Application hosting — Render
- Database — Neon (PostgreSQL, EU region)
- Transactional email — Resend
- Image/file storage — Cloudflare R2
- Payments (when enabled) — Stripe
- SMS / WhatsApp messaging (only where a Merchant enables the add-on) — our messaging provider
We may also disclose data where required by law, regulation, legal process, or to protect the rights, safety and property of Aiqon, our clients or others. We will tell controllers of any new sub-processor where required by our processing agreement.
5. International transfers
We host and process data within the EU/EEA where reasonably practicable. Where a provider processes personal data outside the EEA, we rely on a valid transfer mechanism — an EU adequacy decision or the European Commission’s Standard Contractual Clauses (SCCs), with supplementary measures where appropriate.
6. How long we keep data (retention)
- Account data: for as long as your account is active, then deleted or anonymised, except where we must retain records (e.g. invoices and tax records, typically kept for up to 6 years under Irish law).
- Order data (as processor): retained per the Merchant’s configuration and instructions, and deleted or anonymised when no longer needed for the purpose collected.
- Technical logs: kept for a limited period for security and troubleshooting, then deleted.
7. How we protect your data (security)
We implement appropriate technical and organisational measures, including: encryption of data in transit (TLS); passwords stored only as salted hashes; strict database-level tenant isolation so one business can never access another’s data; role-based access controls and least-privilege access for our team; and regular backups. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss or alteration.
8. Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours where required, and affected individuals and controllers without undue delay, in line with Articles 33–34 GDPR.
9. Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (“right to be forgotten”) (Art. 17);
- restrict our processing of your data (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time, where we rely on consent.
To exercise any of these, email privacy@cornerly.ie. We will respond within one month. If your request concerns data a Merchant controls (order data), we will forward it to, or ask you to contact, that Merchant. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
10. Marketing
We only send marketing emails where you have opted in or where permitted by law. Every marketing email includes an unsubscribe link, and you can opt out at any time by contacting us. Opting out of marketing does not affect service-related messages (e.g. billing or security notices).
11. Children
Cornerly is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new “last updated” date and, for material changes, take reasonable steps to notify you.
13. Contact
Data protection enquiries: privacy@cornerly.ie. Aiqon Limited, Ireland — data controller and contracting entity for Cornerly.