Technical businesses: 21 days free. No card required.

Start
Back to Corexa
Privacy at Corexa

Privacy Policy

Clear information about what Corexa collects, why it is needed and how personal and operational data is protected.

Last updated 14 August 2026

Purpose limited

Information is used to operate and improve Corexa.

Role controlled

Workspace access follows organisation roles and permissions.

No data sales

Corexa does not sell or rent personal information.

Section 1

Who we are and how to contact us

Corexa is operated by Renee Sue Hastings trading as Corexa (ABN 84 428 247 369), Queensland 4151, Australia. In this policy, ‘Corexa’, ‘we’, ‘us’ and ‘our’ refer to that business unless a written enterprise agreement identifies another contracting entity.

Our Privacy Officer can be contacted at support@corexa.com.au or through the Corexa contact page. Privacy requests should include enough information for us to understand the request and verify the requester where necessary.

Section 2

Scope of this policy

This Privacy Policy explains how Corexa handles personal information when people visit our website, create an account, use a Corexa workspace, contact us, import records or interact with connected services.

Corexa supports technical service businesses, multi-site operators, equipment owners, manufacturers and suppliers. An organisation may provide us with information about its staff, customers, contractors, technicians or site contacts so that it can use the platform.

Section 3

Information we collect and receive

We may collect account and contact details, organisation and role information, authentication records, support communications, subscription and transaction information, and device or usage information.

The platform may also store operational information entered by users, including customer and site details, equipment records, serial numbers, service histories, jobs, service notes, images, documents, parts, quotes, invoices, approvals, messages, maintenance information and connected integration data.

Information may be provided directly by an individual, by an organisation using Corexa, through an enabled integration, or through records an authorised user imports such as spreadsheets, service reports, email exports, message or WhatsApp exports, images and other business documents.

Corexa seeks to collect and retain only information that is reasonably necessary for the platform’s functions, security, support, legal obligations and features chosen by a user or organisation. Imported material can contain unrelated or additional personal information that Corexa did not specifically request. Where information is not needed, cannot lawfully be retained, or is not selected for an operational record, Corexa may delete or de-identify it where lawful and reasonable.

Section 4

How we use information

We use information to create and manage accounts, provide role-based workspaces, process service activity, support collaboration, deliver notifications, operate subscriptions, respond to support requests, maintain platform security and keep accurate customer, site and equipment records.

We may also use aggregated or de-identified information to understand feature performance, improve reliability and develop the platform. We do not sell or rent personal information.

Section 5

Organisation and customer data

When an organisation uses Corexa, it controls who is invited to its private workspace and what organisation-private information those users can access. Workspace administrators are responsible for assigning appropriate roles and ensuring they have authority to upload or share information about staff, customers, suppliers, technicians and site contacts.

Corexa may act as a service provider to an organisation for some information while also maintaining platform-level identity and shared operational records described below. People should contact the relevant organisation first where a request relates to information controlled exclusively by that organisation, and may also contact Corexa where the request concerns Corexa’s own matching, shared-history or platform processing.

Section 6

Identity matching, canonical records and access

To reduce duplicate records and preserve equipment history, Corexa may compare information such as serial numbers, equipment brand and model, customer or organisation names, ABNs, email addresses, phone numbers, site names and addresses with records already held in Corexa.

Where Corexa can safely identify the same real-world customer, site or equipment, it may link the new record to an existing canonical identity instead of creating another physical identity. Identity matching by itself does not establish a right to see another organisation’s information and does not remove an existing organisation’s relationship.

Cross-organisation operational history is made available only where Corexa can establish an Authorised Relationship through a permitted mechanism, such as equipment or site ownership, SiteGrid membership or authority, an explicit share or invitation, a verified service engagement or job relationship, or an in-product relationship confirmation in which an authorised user expressly confirms their authority to link the record. Merely knowing a serial number, customer name, email address or site address is not sufficient authority to access another organisation’s shared history.

Where information is conflicting or the match is not sufficiently reliable, Corexa may hold the record for review rather than automatically linking or creating it. Users and affected individuals can ask us to review or correct an incorrect identity match.

Section 7

Shared operational service history

Where an Authorised Relationship exists, relevant organisations may be able to view operational service history for the same equipment or site. This can include completed service dates, service provider and technician name, reported faults, diagnosis or work performed, service notes, parts fitted and quantities, maintenance outcomes, equipment lifecycle events and service evidence where appropriate.

Shared operational records are intended to preserve the factual service and maintenance history of equipment and sites. Corexa limits shared information to operational fields and does not intentionally expose another organisation’s supplier cost, sell price, margins, labour or call-out rates, private scheduling comments, internal management notes, private staff comments or other organisation-only commercial information.

Technician and site-contact personal information is shared only to the extent reasonably needed for the operational record and the Authorised Relationship. Users should not place unrelated personal, sensitive, internal or commercial information in fields identified as shared Service Notes or operational history.

Section 8

AI-assisted and automated processing

Corexa uses deterministic parsing, matching and business rules where possible and may use AI-assisted services as a fallback where information is ambiguous, visual or unstructured. Examples can include interpreting imported documents or images, identifying relationships in service history, summarising records, suggesting actions or supporting diagnostics.

Automated matching may use personal information such as names, business contact details, site details, equipment identifiers and service context to determine whether records appear to refer to the same customer, site or equipment, whether a result requires review, and how operational records should be associated. Automated matching does not by itself establish an organisation’s authority to access another organisation’s shared records.

AI-assisted or automated outputs may be incomplete or incorrect and are checked against Corexa rules where applicable. Information that cannot be matched safely may be held for review rather than written automatically.

Where Corexa uses the OpenAI API, API inputs and outputs are not used by OpenAI to train its models by default. Corexa will not opt customer content into third-party general model training without clearly informing the affected organisation and obtaining any opt-in or consent required by law or the applicable agreement. Provider retention depends on the API feature and Corexa’s configured data controls.

Section 9

When information may be shared and overseas processing

We may disclose information to service providers that help us operate hosting, database, authentication, communications, analytics, payments, storage, support, security and AI-assisted features. We limit disclosures to what is reasonably required for those services and use contractual, technical and organisational safeguards where appropriate.

Information may also be shared with connected services at a user or organisation’s direction, with authorised members of the same workspace, or as part of shared operational history where an Authorised Relationship exists. Organisation-private and commercial information remains restricted to the relevant organisation unless that organisation directs or authorises a separate disclosure.

Corexa currently uses infrastructure that can process or store personal information outside Australia, including in the United States. Other countries may be involved depending on the region and services configured by a provider or integration. Where practicable, Corexa will keep this policy or related provider information updated as those arrangements materially change.

Section 10

Cookies, analytics and device data

Corexa may use essential cookies and similar technologies to keep users signed in, remember preferences, protect sessions and operate the platform. We may also collect limited analytics and performance information to diagnose faults and improve usability.

Browser or device settings can restrict some cookies, although doing so may prevent parts of the service from working correctly.

Section 11

Security, retention and deletion

We use reasonable technical and organisational safeguards designed to protect information from misuse, interference, loss and unauthorised access, modification or disclosure, including authenticated sessions, access controls, role-based permissions and secure service providers. No online system can guarantee absolute security.

Retention depends on the information and why it is held. Equipment identity and factual service events may be retained for the equipment lifecycle where reasonably necessary to preserve an accurate operational record. Personal identifiers attached to those records are retained only while reasonably needed for the relevant operational, legal or security purpose and may be minimised or de-identified where appropriate. Organisation-private records are retained according to workspace, contractual and legal requirements.

Files uploaded only for Smart Import or temporary processing are intended to be transient and may be removed after analysis. Relevant structured facts, source provenance and operational records can be retained where permitted. When personal information is no longer needed for a permitted purpose and no legal exception applies, Corexa takes reasonable steps to destroy or de-identify it.

Section 12

Access, correction and identity disputes

Users can update much of their account information within Corexa. An individual can request access to or correction of personal information about them, or dispute an incorrect customer, site, equipment, service-history or identity match, by contacting the Privacy Officer at support@corexa.com.au or through in-product support.

We may need to verify identity before providing access or making a correction. Where an operational record cannot appropriately be deleted because Corexa has a permitted reason to retain the factual service event, we will consider correction, annotation, access restriction, minimisation or de-identification as appropriate.

Section 13

Privacy complaints

If you believe Corexa has mishandled your personal information, please make a written complaint to the Privacy Officer at support@corexa.com.au and describe the issue and the outcome you seek. We will acknowledge and investigate the complaint, may ask for further information, and aim to provide a substantive response within a reasonable period, generally within 30 days.

If you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner (OAIC). Information about making a privacy complaint is available from the OAIC.

Section 14

Changes to this policy

We may update this policy as Corexa, applicable law or our information-handling practices change. Material updates will be published on this page with a revised date and may also be communicated through the platform where appropriate.

Before materially expanding the way Corexa links or shares personal information, we may update notices, permissions or other privacy controls where appropriate.

Have a privacy question?

Contact Corexa with the relevant account, organisation and request details so the issue can be directed correctly.

Contact Corexa