Corexa enterprise · Version 2026-08-14.v1
Corexa Enterprise Data Processing Addendum
Customer-data processing, privacy, subprocessor and incident-response schedule for enterprise arrangements.
1. Parties, scope and precedence
This Data Processing Addendum (DPA) supplements the agreement under which Corexa provides the Corexa platform to the enterprise customer. Corexa is operated by Renee Sue Hastings trading as Corexa (ABN 84 428 247 369), unless the applicable order form names another Corexa contracting entity.
The DPA applies to personal information and customer-controlled data processed by Corexa on behalf of the customer in providing the contracted services. Corexa may separately determine the purposes and means of processing for platform security, billing, legal compliance, fraud prevention, account administration, canonical identity integrity and other processing described in Corexa's Privacy Policy. To the extent of a direct inconsistency about customer-controlled processing, the executed enterprise agreement and this DPA prevail over standard online terms.
2. Customer instructions and authority
Corexa will process customer-controlled personal information to provide, secure, support and maintain the contracted services, follow documented configuration choices and instructions, comply with law and perform other processing expressly agreed in writing.
The customer is responsible for ensuring it has lawful authority for the personal information, workforce information, imported records, site information and other content it instructs Corexa to process, including any notices, consultation or consents required by applicable law.
3. Data and people covered
- Data subjects can include customer staff, technicians, contractors, site contacts, customers, suppliers and other authorised users or contacts.
- Data can include identity and contact information, organisation/role information, authentication and audit information, job/site/equipment records, service notes, communications, documents/media, location data during enabled tracking, commercial records and other data selected by the customer.
- Sensitive information should only be placed in Corexa where the relevant feature supports it and the customer has authority to do so.
4. Confidentiality and authorised personnel
Corexa will restrict access to customer-controlled data to personnel, contractors and service providers who need access for authorised purposes and who are subject to appropriate confidentiality obligations. Corexa will maintain role-based and technical access controls appropriate to the nature of the service.
5. Security
Corexa will maintain reasonable technical and organisational measures designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. The current enterprise security schedule forms part of this DPA when incorporated into the same executed agreement.
No security measure eliminates all risk. Security obligations are assessed having regard to the nature and sensitivity of the information, foreseeable harm, the service architecture and available safeguards.
6. Subprocessors and overseas processing
The customer gives general authorisation for Corexa to use subprocessors reasonably necessary to operate the service, subject to Corexa maintaining a current subprocessor/data-location register and applying appropriate contractual, privacy and security due diligence. Corexa remains responsible for its own selection, configuration and instructions to subprocessors to the extent required by applicable law and the executed agreement.
Corexa will make information about material subprocessors and known processing locations available through its maintained compliance register or another agreed channel. Where reasonably practicable, Corexa will provide advance notice of a material new subprocessor used for customer-controlled personal information so enterprise customers can raise legitimate privacy or security concerns.
7. Privacy requests and cooperation
Taking account of the nature of the processing, Corexa will provide reasonable assistance for access, correction, deletion, restriction or other privacy requests relating to customer-controlled data where the customer cannot reasonably fulfil the request through the platform itself. Corexa may require verification and may decline an instruction that would breach law, another person's rights or a legitimate retention requirement.
8. Security incidents and data breaches
Corexa will maintain an incident-response process and will notify the enterprise customer without undue delay after becoming aware of a confirmed security incident affecting customer-controlled personal information where notification is reasonably required for the customer to meet its legal obligations. Notice may be staged as investigation continues and will include available information about the nature of the incident, affected data, containment/remediation and relevant contact point.
Nothing in this clause prevents Corexa from notifying regulators or affected individuals directly where Corexa is legally required or entitled to do so.
9. Return, deletion and retention
On termination or a valid customer instruction, Corexa will provide reasonable mechanisms to export or delete customer-controlled data subject to technical capability, lawful retention obligations, backup lifecycle, fraud/security records and Corexa records that are independently required or permitted to be retained. Shared Operational Records and canonical identity integrity records are governed by the main agreement, Privacy Policy and applicable law rather than being automatically erased merely because one organisation terminates its account.
10. Audit information
Corexa will make reasonable information about its privacy and security controls available to an enterprise customer for legitimate due diligence. Any additional audit, penetration test participation or bespoke assessment is subject to reasonable scope, confidentiality, security restrictions, timing and cost arrangements so the audit does not compromise other customers or the platform.