Background information
2.1These Terms of Use govern access to and use of the Qornerstone Platform, which includes its various modules and applications such as Qommunity+, Qommunity Manager+, Q.Ops and Qornerstone leasing, strata, maintenance and finance modules. They apply to the Subscriber, to every Authorised User and to every End User, in each case from the moment of first access.
2.2The Provider. The Qornerstone Platform is supplied by one of two companies:
UEN 199902557C · 140 Paya Lebar Road, #10-11, AZ @ Paya Lebar, Singapore 409015 — where the Subscriber holds an Enterprise Licence.
UEN 201907560Z · 140 Paya Lebar Road, #10-11, AZ @ Paya Lebar, Singapore 409015 — where the Subscriber holds a Subscription Licence.
2.3IBASE owns all Intellectual Property Rights in the Qornerstone Platform. Qornerstone Pte Ltd holds a licence from IBASE to market, distribute and sub-license the Platform to Subscription Licence customers. In relation to QuickPay, IBASE holds the operating rights under its contract with our appointed payment partner and confers those rights on Qornerstone Pte Ltd.
2.4Your contract or subscription names the Provider for a given Subscriber. In these Terms, "we", "us" and "our" mean that Provider, and "you" means the Subscriber unless the context indicates an Authorised User or End User.
2.5Where a Subscriber holds both an Enterprise Licence and a Subscription Licence, these Terms apply separately to each, and each Provider is responsible only for what it supplies.
Definitions
- "Authorised User"
- An individual authorised by the Subscriber to access the Platform in an administrative, management, finance, operations or site role, including employees, officers and agents of the Subscriber and of a Managed Property.
- "Data"
- All data and content uploaded to or generated on the Platform by or for the Subscriber, an Authorised User or an End User.
- "End User"
- An individual who accesses the Platform in a non-administrative capacity, including but not limited to a tenant, employees of the tenant, subsidiary proprietor, member of the household, council or management committee member, a third party contractor or its personnel, including a contractor issued with an electronic permit to work.
- "Enterprise Licence"
- A server-instance licence to the Platform granted by IBASE under a contract or subscription, permitting the Subscriber to onboard an unlimited number of Managed Properties subject to these Terms, and continuing for so long as the recurring fees are paid.
- "Managed Property"
- A property onboarded to the Platform by the Subscriber, including a strata development, commercial or industrial building, mall or single asset.
- "Modules"
- The functional components of the Platform listed in your contract or subscription.
- "PDPA"
- The Personal Data Protection Act 2012 and its subsidiary legislation.
- "Personal Data"
- Has the meaning given in the PDPA.
- "Platform" or "Qornerstone Platform"
- The Qornerstone property management software platform and all Modules, applications, portals and documentation forming part of it, including Qommunity Manager, the Qommunity resident application, technician and contractor applications, the QuickPay payment service, and any white-labelled application or portal developed or maintained by us for a Subscriber.
- "Provider"
- Has the meaning given in clause 2.2.
- "Services"
- The provision of access to the Platform together with the maintenance, support and hosting services described in your contract or subscription.
- "Subscriber"
- The entity named as customer in your contract or subscription, whether a managing agent, integrated facilities management company, management corporation, building owner or other party.
- "Subscription Licence"
- A monthly, per-property, per-Module licence granted by Qornerstone Pte Ltd under a contract or subscription.
Licence and permitted use
4.1We grant you a non-exclusive, non-transferable right to access and use the Platform and the Modules identified in your contract or subscription, for the roles available to your licence type, for the term of your contract or subscription.
4.2Enterprise Licence. An Enterprise Licence comprises three entitlements, which are provided together and end together:
- a licence to use the Platform, granted on a per server instance basis;
- software maintenance and support, comprising bug fixes, security patches, functional improvements, new releases and the support service in section 8, for the maintenance and support periods stated in your contract or subscription; and
- cloud hosting, comprising the hosted environment described in clause 7.2.
The licence in (a) continues for so long as the recurring fees for (b) and (c) are paid. It is not a perpetual licence. If those fees are not paid, the Enterprise Licence terminates in accordance with clause 4.4.
4.3Subscription Licence. A Subscription Licence is granted per Managed Property and per Module, for a monthly term that renews unless cancelled. Adding a Managed Property or a Module requires a new or amended subscription license and attracts additional fees.
4.4Termination for non-payment of recurring fees. If the recurring fees for maintenance and support, or for hosting, are not paid, we will give the Subscriber written notice. If the fees remain unpaid 30 days after that notice, the Enterprise Licence terminates, including the licence in clause 4.2(a). On termination the Subscriber must cease using the Platform, we cease hosting the instance, and section 19 governs export of Data. The one-time Enterprise licence fee and other one-time charges are not refundable on a termination under this clause. This clause does not limit our right to suspend under clause 20.1 or to terminate under clause 20.4.
4.5We may make the Platform available under a demonstration account for up to 30 days. These Terms govern that access. Demonstration accounts carry no service levels and no data retention commitment.
4.6You must not, and must not permit any person to:
- resell, sub-license, rent or make the Platform available to a third party other than an Authorised User or End User in connection with a Managed Property;
- copy, modify, decompile or reverse engineer any part of the Platform;
- use the Platform to build a competing product;
- circumvent access controls, usage limits or transaction identifiers;
- upload malicious code or content that is unlawful, defamatory or infringing; or
- use automated means to extract data at a scale that degrades performance for other users.
Users
5.1The Subscriber is responsible for the acts and omissions of its Authorised Users and, in relation to a Managed Property, for provisioning and de-provisioning access as roles change.
5.2End Users access the Platform under these Terms. By registering for or using a resident, tenant, council or contractor account, an End User accepts these Terms and the Qornerstone Privacy Policy. Where an End User does not accept them, that End User must not use the Platform.
5.3Accounts are personal. Credentials must not be shared. Each of you must notify us without delay, and in any event within 24 hours, of any actual or suspected unauthorised access or compromise of credentials.
5.4We may suspend an individual account that we reasonably believe is compromised, is being used in breach of these Terms, or presents a security risk. We will tell the Subscriber where we do so.
5.5The Subscriber warrants that it is authorised to onboard each Managed Property and to grant access to the Authorised Users and End Users associated with it. Where the Subscriber acts as agent for an owner or a management corporation, the Subscriber warrants that it holds that principal's authority.
5.6Which provisions apply to whom. These Terms bind both Subscribers and individuals, but not every provision applies to every reader:
- All users, including Authorised Users and End Users, are bound by: clause 4.6 (prohibited use), section 5 (users and accounts), section 12 (confidentiality), section 13 (intellectual property), section 16 (limitation of liability), section 18 (AI features), section 21 (changes) and section 23 (governing law), together with the QuickPay Terms of Use where they use QuickPay.
- The Subscriber alone is bound by: section 6 (Subscriber obligations), section 9 (fees), clause 10.2 (Data licence), clause 11.3 (notification and consent), clause 15.1 (Subscriber indemnity), section 19 (export and migration) and section 20 (suspension and termination). An End User is not liable for the Subscriber's fees or its indemnity obligations.
- Rights we grant the Subscriber, including the service levels in section 8, the rebates in clause 8.4, the audit right in clause 11.8, the indemnity in clause 15.2 and the export rights in section 19, are exercisable by the Subscriber only and not by an Authorised User or an End User.
- Where a provision refers to "you", it means the Subscriber unless the context indicates an Authorised User or End User.
Subscriber obligations
6.1You must use the Platform for lawful business purposes connected with the management of your Managed Properties, and in accordance with these Terms and applicable law.
6.2You are responsible for the accuracy, completeness and legality of Data you upload, and for the decisions you take on the basis of the Platform's output. Financial reports, ledgers and statements generated by the Platform are a record of what has been entered into it.
6.3You must maintain your own reconciliation and review controls. Do not treat the Platform as the sole record of receipt of funds; reconcile against bank statements.
6.4You must not attempt to undermine the security or integrity of our systems, or probe, scan or test them without our prior written consent.
Our obligations
7.1We will provide the Services with reasonable skill and care and in a professional manner, and will take reasonable steps to protect the Platform against unauthorised access, malicious code and tampering.
7.2We host the Platform on Microsoft Azure with servers located in Singapore.
7.3We maintain an information security management system certified to ISO 27001 by an independent third party auditor.
7.4We will retain Data for at least three calendar months from the date it is uploaded, and for the period stated in clause 11.9.
Service levels
8.1We target availability of the hosted Services of at least 99.5% in each calendar month, measured excluding scheduled maintenance, emergency maintenance and Force Majeure Events.
8.2We classify incidents by Business Impact Level and respond as follows:
| Business Impact Level | Response | Workaround | Resolution |
|---|---|---|---|
| Level 1 — users unable to perform business functions | Within 1 working day | Within 2 working days | Within 4 working days |
| Level 2 — a process is affected and a workaround exists | Within 3 working days | Within 4 working days | Within 7 working days |
8.3We give at least two working days' notice of scheduled preventive maintenance. Emergency maintenance for critical issues is carried out as soon as possible, with notice given where practicable.
8.4If monthly uptime falls below target, the Subscriber may claim a rebate against the recurring fees for that month, on written request made within 30 days of the end of the month:
| Monthly uptime | Rebate |
|---|---|
| Below 99.5% | 10% of the monthly recurring fee |
| Below 99% | 20% of the monthly recurring fee |
| Below 95% | 50% of the monthly recurring fee |
For Enterprise Licence customers, the monthly recurring fee means one twelfth of the annual maintenance, support and hosting fee. Rebates are the sole remedy for failure to meet the service levels stated in this section.
8.5These service levels apply to the standard Platform. They do not apply to customised modules, reports or integrations developed for a particular Subscriber, to demonstration accounts, or to any period during which recurring fees are overdue.
8.6If a disruption cannot be resolved within two working days, we will provide a reasonable alternative means for the Subscriber to continue essential operations until service is restored.
Fees and payment
9.1Fees are set out in your contract or subscription and may comprise one-time licence fees, implementation and data migration fees, customisation fees, recurring maintenance, support and hosting fees, monthly subscription fees, optional add-on fees, and transaction charges for services such as QuickPay.
9.2All fees are exclusive of GST and other applicable taxes, which the Subscriber pays in addition.
9.3Monthly subscription fees are payable in advance. Invoices are issued electronically and are payable in full by bank transfer within 15 days of the invoice date, unless your contract or subscription says otherwise.
9.4Recurring maintenance, support and hosting fees under an Enterprise Licence are payable annually in advance on each anniversary of the commencement date, at the tier corresponding to the number of Managed Properties onboarded at the time of renewal.
9.5We may vary recurring fees by up to 10% on each twelfth-month anniversary of the service start date, on written notice. Variations above that require the Subscriber's agreement, and the Subscriber may terminate on 30 days' notice if it does not agree.
9.6Late payments accrue interest at 2% per month, accruing daily from the due date until payment. We may recover reasonable costs of collection.
9.7We may suspend access where fees remain unpaid 14 days after written notice. Suspension does not relieve the Subscriber of the obligation to pay.
9.8Card payment platform fee. Where card payments are enabled, we charge a platform fee of 0.3% of the value of each card transaction processed through the Platform. It is invoiced monthly in arrears and is exclusive of GST. It is charged in addition to the Card Partner's own charges under clause 14.7, which the Card Partner bills separately.
9.9Platform fees for PayNow collection through QuickPay are set out in the QuickPay Terms of Use. Card payments are not part of QuickPay.
Data ownership
10.1The Subscriber owns all Data, including all rights, title and interest in it. Nothing in these Terms transfers ownership of Data to us.
10.2The Subscriber grants us a non-exclusive licence to host, copy, transmit, store, back up, display and process Data to the extent necessary to provide the Services, to comply with law and to exercise our rights under these Terms.
10.3A Super Admin user from your organisation may export Data through the Control Panel in editable CSV format at any time during the term.
10.4We may compile anonymised and aggregated statistics derived from use of the Platform for the purposes of operating, securing, supporting and improving it. Such statistics must not identify the Subscriber, any Managed Property, any Authorised User or any End User, and must not be disclosed in a form from which any of them could reasonably be identified.
Personal data protection
11.1All parties must comply with the PDPA in connection with the Platform.
11.2Roles. The Subscriber is the organisation in respect of Personal Data contained in Data. We act as the Subscriber's data intermediary, processing that Personal Data on the Subscriber's behalf and on its instructions for the purpose of providing the Services. We act as an organisation in our own right in respect of (a) registration and account data collected by us directly from an End User, (b) the Subscriber's business contact and account data, and (c) our own support, security and billing records. Our collection and use of data in that capacity is described in the Qornerstone Privacy Policy at qornerstone.com/privacy-policy.
11.3Subscriber responsibilities. The Subscriber is responsible for notifying individuals and obtaining consent, or establishing that it may rely on deemed consent or an exception under the PDPA, for the collection, use and disclosure of Personal Data through the Platform. This applies to tenants and their employees, residents, unit owners, occupiers and their household members, council members, and third party contractors and their personnel. The Subscriber must not upload Personal Data that is not required for the management of a Managed Property.
11.4Our obligations as data intermediary. We will:
- process Personal Data only to provide the Services and as otherwise instructed by the Subscriber, and not sell, rent or use it for our own marketing;
- make reasonable security arrangements to protect it against unauthorised access, collection, use, disclosure, copying, modification, disposal and similar risks;
- ensure our personnel with access are bound by confidentiality obligations and are trained on data protection;
- not retain it longer than necessary for the purpose, or for legal, tax or regulatory retention; and
- not transfer it outside Singapore without the Subscriber's consent, and where a transfer is made, only on terms providing a standard of protection comparable to the PDPA.
11.5Sub-processors. We engage the following categories of sub-processor: cloud hosting (Microsoft Azure, Singapore); e-invoicing network access (InvoiceNow / Peppol); hardware vendors appointed by us to supply, operate, support or maintain smart access and smart visitor management solutions, including access control readers, intercom panels, kiosks, licence plate recognition cameras and, where an estate has enabled it, facial recognition access devices; and, where the Provider is Qornerstone Pte Ltd, platform operation and support by IBASE Technology Pte Ltd. We engage each sub-processor on terms that include data protection obligations no less protective than this section 11, and we remain responsible to the Subscriber for a sub-processor's processing of Personal Data on our behalf. A current list is available on request. We will give 30 days' notice before adding a sub-processor that will process Personal Data, and the Subscriber may object on reasonable data protection grounds. Our appointed payment partner, the Card Partner, and any other bank, payment institution, regulated financial institution or network operator with which the Platform interoperates are not our sub-processors. They receive Personal Data as recipients in their own right, act under their own licences and regulatory obligations, and determine their own purposes and means of processing it. We are not able to impose data protection or other obligations on them, we do not control them, and we are not responsible for their acts or omissions or for their handling of Personal Data. Their own terms and privacy notices govern that handling.
11.6Data breach. We will notify the Subscriber without undue delay, and in any event within 24 hours, of becoming aware of a data breach affecting Personal Data we process as data intermediary. The notification will contain the information reasonably available to us to enable the Subscriber to assess whether the breach is notifiable and to make any notification required to the Personal Data Protection Commission and to affected individuals within the timeframes prescribed under the PDPA. We will co-operate on assessment, containment and remediation, and will not notify affected individuals or make a public statement identifying a Subscriber or a Managed Property without first consulting the Subscriber, unless required by law or by a regulator.
11.7Access and correction. Where we receive an access, correction or withdrawal request from an individual relating to Personal Data we process as data intermediary, we will notify the Subscriber within 3 Business Days, will not respond substantively except to acknowledge and redirect the request, and will provide reasonable assistance to enable the Subscriber to respond within the statutory timeframe.
11.8Audit. Once in any 12-month period, on 30 days' written notice, the Subscriber may request evidence of our compliance with this section 11. We may satisfy the request by providing our current ISO 27001 certificate, a summary of our most recent independent security assessment and responses to a reasonable written questionnaire. An on-site audit may be conducted only where a regulator requires it or following a data breach affecting the Subscriber, during business hours, subject to confidentiality and at the Subscriber's cost.
11.9Return and deletion. On expiry or termination we retain Data for three months, during which the Subscriber may export it under clause 10.3. At the end of that period we delete or anonymise Personal Data, except to the extent retention is required by law, by a payment partner, or for the establishment or defence of legal claims. Retained data remains subject to this section 11 and section 12.
11.10Biometric data and facial recognition. This clause applies where a Managed Property enables facial recognition access or any other biometric processing through or alongside the Platform.
- The Subscriber, and the management corporation or owner on whose behalf it acts, decide whether to enable biometric processing at a property and for what purpose. We do not enable it without that instruction.
- Biometric data carries a higher risk of significant harm to the individual. The Subscriber must obtain the express, separate and informed consent of each individual before enrolment, must tell that individual what is collected, why, where it is held and for how long, and must offer a non-biometric alternative means of access. Consent to biometric enrolment must not be bundled with acceptance of these Terms or with any tenancy, employment or contractor engagement.
- Facial recognition templates are held in encrypted form on the access device by the hardware vendor engaged under clause 11.5. We do not hold biometric templates on the Platform.
- The Subscriber must ensure that a template is deleted on de-registration, on withdrawal of consent, and when the individual ceases to be an owner, occupier, employee or contractor at the property.
- An individual may withdraw consent to biometric processing at any time. The Subscriber must give effect to that withdrawal and provide the alternative means of access.
- Biometric data must not be used for any purpose other than access control and the security of the property, and must not be disclosed except as required by law.
- The Subscriber indemnifies us under clause 15.1(c) in respect of any claim arising from biometric processing at a Managed Property where the requirements of this clause were not met.
