Calexi (ACT) Pty Ltd
ABN 68 683 960 054
Website: https://www.calexi.com.au
Last Updated: 31 August 2026
1. About this policy
Calexi (ACT) Pty Ltd (Calexi, we, us or our) respects the privacy of individuals whose personal information we collect, hold, use, disclose or otherwise handle.
This Privacy Policy explains how Calexi manages personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to personal information handled across Calexi’s business, including through our website, managed IT services, cybersecurity services, professional services, recruitment, employment, business development and corporate activities.
2. Personal information we collect
The personal information Calexi collects depends on the nature of our relationship with an individual and the services or activities involved.
We may collect and hold information including:
- names and contact details
- work and personal email addresses
- telephone numbers
- residential or business addresses where required
- job titles, employers and organisational relationships
- employment history, qualifications, professional experience and memberships
- information about projects, contracts and previous engagements
- technology responsibilities, preferences and experience
- correspondence, meeting notes and other business communications
- quotations, contracts and commercial information
- support requests and service records
- account and identity information
- device, network and system information
- IP addresses
- authentication and access records
- system, application and security logs
- browsing and website information
- recruitment and employment information
- financial, payroll, taxation and superannuation information
- government-related identifiers where reasonably necessary
- information required for security, regulatory or Defence-related purposes
- other information reasonably necessary to conduct our business or provide our services.
We seek to collect only information that is reasonably necessary for our functions and activities.
3. Sensitive information
Calexi may collect sensitive information where reasonably necessary for our functions or activities and where permitted by law.
Depending on the circumstances, this may include:
- health information relevant to workplace health and safety
- criminal history information
- security clearance and security vetting information
- citizenship information
- racial or ethnic origin where relevant to authorised security screening or vetting processes
- professional memberships
- biometric information used for identity verification, authentication or access control.
Where required, Calexi obtains consent to collect sensitive information unless collection is otherwise permitted or required by law.
Calexi may use biometric technologies, including facial, eye and fingerprint recognition, to support identity verification, device authentication and physical or logical access control.
Some biometric authentication systems may process or retain biometric information locally on a device or within a third-party platform rather than providing the underlying biometric information to Calexi.
4. How we collect personal information
Calexi may collect personal information:
- directly from an individual
- from an individual’s employer or prospective employer
- from our customers
- from IT systems and devices
- through cybersecurity monitoring and security systems
- from cloud platforms and applications
- through website forms and analytics
- through email, telephone calls, meetings and other communications
- through recruitment and employment processes
- from recruiters and employment platforms
- through security clearance and vetting processes
- from social media and professional networking services
- from publicly available information
- from government bodies and authorised security organisations
- from third parties where reasonably necessary for our business activities.
We may also receive unsolicited personal information. Where this occurs, we will determine whether we could have lawfully collected the information. Where appropriate and permitted by law, information that is not required will be destroyed or de-identified.
5. Information handled on behalf of our customers
As a provider of managed IT, cybersecurity and professional services, Calexi personnel and systems may have extensive technical access to information contained within customer systems.
This may include personal information, sensitive information, intellectual property, business information, communications, files and other information controlled by the customer.
Technical access to customer information does not mean Calexi collects or uses that information for its own purposes.
Calexi personnel are authorised to access customer information only where required to provide contracted services, undertake authorised activities, protect systems or information, investigate security events, meet contractual requirements or comply with legal, regulatory and security obligations.
The scope of access is governed by applicable contracts, scopes of work, network access authorisations, security requirements and Calexi’s internal access controls.
6. Cybersecurity monitoring and technical information
Providing cybersecurity and managed IT services requires Calexi to collect, process and analyse technical information.
Depending on the services provided, this may include:
- usernames and user identifiers
- device and computer names
- IP addresses and network information
- authentication and login events
- websites and URLs
- application and process execution
- files and file metadata
- file hashes
- system and security events
- system configurations
- software information
- email security events
- administrative activity
- user actions
- file access
- removable media and USB activity
- security alerts
- other telemetry generated by customer or Calexi systems.
This information is used for purposes including security monitoring, threat detection, investigation, incident response, compliance, auditing, system administration and evidentiary requirements.
Security telemetry is generally retained for up to 12 months. Information associated with significant security events, investigations, compliance requirements, legal obligations or evidentiary requirements may be retained for longer.
7. Why we collect, hold, use and disclose personal information
Calexi may collect, hold, use and disclose personal information for purposes including:
- providing managed IT and cybersecurity services
- providing consulting and professional services
- administering customer systems
- account and identity management
- authentication and access control
- cybersecurity monitoring
- threat detection and response
- backup and disaster recovery
- incident investigation
- compliance and audit activities
- maintaining evidence and security records
- managing contracts and customer relationships
- billing and financial administration
- recruitment and employment
- workplace health and safety
- personnel security
- security vetting and clearances
- meeting Defence, government, regulatory and contractual obligations
- business development
- managing prospective customer relationships
- direct marketing where permitted
- maintaining professional relationships
- improving our systems, services and business operations
- protecting Calexi, our customers and other individuals from security threats, fraud or unlawful activity
- complying with Australian laws, court or tribunal orders and lawful government requirements.
We generally use or disclose personal information for the purpose for which it was collected, a related purpose that an individual would reasonably expect or another purpose permitted or required by law.
8. Business development and prospective customers
Calexi may collect professional information about individuals associated with organisations that may have a legitimate interest in our services.
This information may be obtained from public sources, professional networks, social media, third parties and other lawful sources.
Information may include:
- name
- employer
- position
- professional contact details
- employment history
- relevant previous contracts or projects
- professional experience
- publicly available information about technology responsibilities or technology choices.
This information may be stored in our customer relationship management systems and associated with the organisation for which the individual works.
Calexi will comply with applicable privacy and electronic marketing requirements when using personal information for direct marketing. Individuals may request that Calexi stop using their personal information for direct marketing and may request information about the source of information used for that purpose where applicable.
Where Calexi operates subscription-based electronic marketing, we use a double opt-in process and provide a means to unsubscribe.
9. Website information, analytics and cookies
When an individual accesses a Calexi website, our systems may automatically collect technical information including IP address, browser information, device information, pages visited, timestamps and related website activity.
Calexi uses a self-hosted Matomo analytics platform to understand website usage, maintain website security, identify suspicious activity and improve our website.
Our Matomo environment may collect full IP addresses for legitimate security, monitoring and analytics purposes.
Our website may use cookies and similar technologies required for website operation, security, user preferences and analytics.
We do not currently use third-party advertising cookies for behavioural advertising.
Individuals may control cookies through their browser settings, although disabling some cookies may affect website functionality.
10. Artificial intelligence and automated decision-making
Calexi uses approved artificial intelligence, machine learning and automated systems to support some business activities.
Calexi personnel must use approved enterprise AI services for work purposes. Personal AI accounts are not authorised for Calexi business use.
Approved AI and automated systems may assist with:
- cybersecurity analysis
- security operations
- development of security rules
- system configuration
- technical analysis
- business administration
- information analysis
- recruitment and candidate assessment
- other authorised business processes.
Personal information may be processed by these systems where reasonably necessary for an authorised purpose and subject to applicable security, contractual and privacy controls.
Recruitment decisions
Calexi may use automated systems to analyse information about employment candidates.
Information used may include:
- CV and résumé information
- employment history
- qualifications
- skills
- professional experience
- stated capabilities
- information provided as part of an employment application.
Automated systems may assess this information and generate assessments, rankings or recommendations about a candidate’s potential suitability for an advertised position.
These automated assessments may be substantially and directly related to employment decisions that affect an individual’s interests.
Human review remains part of Calexi’s recruitment decision-making process. Calexi does not rely solely on an automated recommendation to make a final employment decision.
Calexi will review its use of automated decision-making systems and this policy as technologies and applicable legal requirements change.
11. Recruitment and employment information
Calexi collects personal and sensitive information necessary to recruit, employ, manage and protect our personnel and meet our employment, security and regulatory obligations.
This may include:
- identity and contact information
- employment history
- qualifications and experience
- references
- financial and payroll information
- taxation and superannuation information
- citizenship information
- government-related identifiers
- criminal history
- security clearance information
- health and safety information
- professional memberships
- performance and employment records.
Information relating to unsuccessful candidates will generally be retained for no more than 12 months after the candidate ceases actively engaging with Calexi, unless there is a legitimate or legal reason to retain it for longer.
Calexi may retain limited information about previous applicants where reasonably necessary to identify and associate them with future applications.
12. Government-related identifiers
Calexi may collect government-related identifiers where reasonably necessary for employment, taxation, security vetting, identity verification or other lawful purposes.
These may include tax file numbers, passport details, driver licence information and identifiers associated with government security processes.
Calexi does not use a government-related identifier as its own identifier of an individual unless permitted by law.
Access to government-related identifiers is restricted according to business need and applicable security requirements.
13. Recording meetings and conversations
Calexi may record meetings, interviews, support sessions or other business conversations where there is a legitimate business purpose.
Participants will be notified when a meeting or conversation is being recorded.
Recordings may contain personal information and are protected and retained according to their purpose, sensitivity and applicable legal requirements.
14. Disclosure of personal information
Calexi may disclose personal information where reasonably necessary to organisations including:
- customers
- authorised subcontractors
- IT and cloud service providers
- cybersecurity service providers
- telecommunications providers
- software and SaaS providers
- accountants and auditors
- insurers
- legal and professional advisers
- recruitment providers
- payroll and superannuation providers
- government agencies
- Defence and security vetting organisations
- law enforcement agencies
- regulators
- other parties where authorised or required by law.
We seek to limit disclosure to information reasonably necessary for the relevant purpose.
15. Overseas disclosure and processing
Calexi prefers Australian sovereign hosting and processing where this is reasonably available and appropriate.
Some cloud, SaaS, technology and professional service providers may store or process information outside Australia.
Depending on the services involved, overseas recipients or processing locations may include the:
- United States
- United Kingdom
- Canada
- New Zealand
- European Union and European Economic Area.
Other countries may be involved where required by the architecture of an approved service or the circumstances of a particular engagement.
Where overseas processing or disclosure is necessary, Calexi takes reasonable steps appropriate to the circumstances to assess privacy, security, contractual and data sovereignty risks.
The location of information may also be subject to specific customer contracts, security requirements or service configurations.
16. Security of personal information
Calexi applies technical, administrative and physical safeguards appropriate to the nature and sensitivity of the information it handles.
Controls may include:
- multi-factor authentication
- least privilege and role-based access
- need-to-know access controls
- encryption in transit and at rest
- endpoint security
- security monitoring
- vulnerability and patch management
- backups and recovery controls
- logging and auditing
- privileged access monitoring
- access reviews
- personnel security
- security awareness and training
- data loss prevention
- information classification and sensitivity labelling
- secure disposal
- Essential Eight-aligned security controls.
Access to personal information is restricted according to an individual’s role, responsibilities and authorised work.
Access and privileged activity may be logged, monitored and reviewed.
No method of storing or transmitting information can eliminate all security risk. Calexi manages these risks using controls appropriate to the information and operating environment.
17. Retention, destruction and de-identification
Calexi retains personal information only for as long as it is reasonably required for the purpose for which it is held or where retention is required or authorised by law, contract, security requirements or legitimate business needs.
Many corporate and business records are retained for approximately five to seven years. Some records may require shorter or longer retention periods depending on their purpose and applicable requirements.
Specific retention periods may apply to security telemetry, recruitment information, employment information, financial records, contractual records, backups and evidence associated with security incidents.
Where practical, Calexi uses automated information governance and retention controls, including Microsoft Purview, to support retention and disposal.
When Calexi no longer requires personal information and is not required or authorised to retain it, we take reasonable steps to securely destroy or de-identify it.
18. Quality and correction of information
Calexi takes reasonable steps to ensure personal information it collects is accurate, up to date and complete and that information it uses or discloses is accurate, up to date, complete and relevant for its intended purpose.
Individuals should notify Calexi if they believe information we hold about them is inaccurate, incomplete or out of date.
19. Anonymity and pseudonymity
Individuals may interact with Calexi anonymously or using a pseudonym where this is lawful and practicable.
For example, an individual may generally browse our public website without identifying themselves.
It may be impracticable for Calexi to deal anonymously or pseudonymously with an individual where identity is reasonably required to provide services, administer accounts, provide technical support, enter into contracts, process employment applications, conduct security vetting, manage access or meet legal, regulatory, contractual or security obligations.
20. Access to personal information
Individuals may request access to personal information Calexi holds about them.
Requests should be sent to:
Calexi will require reasonable verification of identity before providing access to personal information.
We will respond to requests within a reasonable period and provide access in the manner requested where reasonable and practicable, subject to exceptions permitted by law.
If we refuse access, in whole or in part, we will provide reasons where required by law and information about available complaint mechanisms.
21. Correction of personal information
Individuals may request correction of personal information they believe is inaccurate, out of date, incomplete, irrelevant or misleading.
Requests should be sent to:
We will take reasonable steps to correct information where appropriate.
Where required, we may also take reasonable steps to notify relevant third parties of a correction.
22. Privacy complaints
Individuals who believe Calexi has not handled their personal information appropriately may make a privacy complaint by contacting:
Privacy Officer
Calexi (ACT) Pty Ltd
privacy@calexi.com.au
Privacy matters are ultimately overseen by Calexi’s Managing Director.
We will acknowledge and investigate privacy complaints and seek to respond within a reasonable period.
If an individual is not satisfied with our response, they may be able to make a complaint to the Office of the Australian Information Commissioner.
23. Data breaches
Calexi maintains incident response processes for identifying, containing, investigating and responding to suspected data breaches.
Where a suspected breach involves personal information, Calexi will assess the incident in accordance with applicable legal requirements.
Where an eligible data breach occurs, Calexi will notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme.
Calexi may also notify customers, regulators, government agencies or other parties where required by contract, law or applicable security requirements.
24. Children
Calexi’s services are not directed at children.
We do not knowingly collect personal information directly from children except where reasonably necessary or authorised or required in connection with our legitimate business, employment, security or legal activities.
Where information relating to a child is required, Calexi will consider the circumstances, sensitivity of the information and applicable consent requirements.
25. Changes to this policy
Calexi may update this Privacy Policy to reflect changes to our business, technology, information handling practices or legal and regulatory requirements.
The current version will be published on our website with its effective or last updated date.
We periodically review this policy to ensure it remains accurate and reflects how we manage personal information.
26. Contact us
Questions, requests or complaints about privacy or Calexi’s handling of personal information can be directed to:
Privacy Officer
Calexi (ACT) Pty Ltd
Email: privacy@calexi.com.au
Further information about Australian privacy law and the Australian Privacy Principles is available from the Office of the Australian Information Commissioner.