Core Exec

Privacy Policy

How CoreExec collects, uses, stores and discloses personal information

Business
CoreExec (partnership of Ethan Phil and Samuel Stephen)
ABN
39 859 348 089
Location
Brisbane, Queensland, Australia
Last updated
8 September 2026

Privacy commitment

CoreExec handles business, candidate, contractor and website information in connection with remote staffing and operational support. Because some roles may involve NDIS, health or other sensitive information and may involve personnel located in the Philippines, CoreExec applies confidentiality, access-control and cross-border information-handling measures appropriate to its operations.

Table of contents

1. About this Privacy Policy

This Privacy Policy explains how CoreExec, ABN 39 859 348 089, collects, holds, uses, discloses and protects personal information. It applies to website visitors, prospective and current Clients, Client personnel and contacts, job applicants, Executive Assistants and other contractors, suppliers and other individuals who interact with CoreExec.

CoreExec intends to manage personal information transparently and in accordance with applicable Australian privacy, confidentiality and data-protection requirements. Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to a particular activity, CoreExec will handle personal information consistently with those requirements.

2. What personal information we may collect

The information CoreExec collects depends on the relationship and the services being provided. It may include:

  • Identity and contact details, such as name, business name, job title, email address, phone number, location and other contact information.
  • Client and business information, including ABN, role requirements, workflow information, systems used, organisational information, service history and communications.
  • Billing and transaction information, including invoices, payment status and payment-related identifiers. CoreExec generally relies on Stripe and other payment providers to process card or payment details.
  • Candidate and contractor information, including CVs, work history, skills, qualifications, references, interview information, assessments, availability, identity or verification information, payment details and other information reasonably required to assess or administer an engagement.
  • System, productivity and work information, which may include tasks, time records, attendance, workflow status, activity information, communications, review notes and related operational information from platforms such as Hubstaff or ClickUp.
  • Website and technical information, such as IP address, device/browser information, cookies, pages visited, enquiry source, analytics information and interactions with online forms.
  • Marketing and enquiry information, such as contact details, campaign source, booking information, interests and communications preferences.

3. Sensitive and regulated information

Some Client roles may involve access to sensitive information, including NDIS participant information, health or disability information, care-related records, financial information or other information requiring a higher level of protection. CoreExec will seek to limit access to what is reasonably necessary for the assigned role and will require such information to be handled subject to applicable confidentiality, privacy, security and Client instructions.

CoreExec does not ask Clients to provide sensitive information unless it is reasonably necessary for the engagement. Clients are responsible for ensuring that they have lawful authority to provide or permit access to personal or sensitive information and for configuring role-appropriate access within their own systems.

4. How we collect information

CoreExec may collect information directly from you when you use the website, make an enquiry, book a call, complete an intake or onboarding process, enter into an agreement, communicate with CoreExec, submit an application, participate in an interview or assessment, or use CoreExec-managed systems.

CoreExec may also receive information from Clients, referees, recruitment sources, contractors, service providers, publicly available professional sources, analytics tools, payment providers, scheduling platforms or other third parties where collection is lawful and reasonably related to CoreExec’s functions.

5. Why we collect and use information

CoreExec may collect, use and disclose information for purposes including:

  • responding to enquiries and arranging calls or meetings;
  • understanding Client operational requirements and defining roles;
  • sourcing, vetting, assessing, matching and presenting candidates;
  • contracting, onboarding, integrating and supporting Executive Assistants;
  • delivering agreed managed services and operational support;
  • tracking tasks, time, workflow, accountability and service performance where applicable;
  • billing, payment processing, accounting and financial administration;
  • communicating with Clients, candidates, contractors and service providers;
  • security, fraud prevention, incident response, auditing and dispute resolution;
  • improving services, systems, processes, website performance and Client experience;
  • legal and regulatory compliance; and
  • marketing CoreExec services where permitted, including follow-up with relevant enquiries and business contacts.

6. Executive Assistants and access to Client information

A CoreExec Executive Assistant may be given access to Client systems and information where that access is required for the assigned role. The level of access depends on the Client’s instructions and role requirements. CoreExec expects Clients to apply least-privilege access principles and to remove access promptly when it is no longer required.

CoreExec requires its contractors to handle Client information confidentially and to use it only for authorised work. Access may be reviewed, changed or withdrawn where a security, privacy, performance or compliance concern arises.

7. Overseas access and disclosure

CoreExec currently sources Executive Assistants from the Philippines. Accordingly, personal information and Client information may be accessed by, or disclosed to, authorised contractors located in the Philippines where reasonably necessary to perform the agreed services.

CoreExec may also use technology and service providers that process or store information outside Australia. The location may depend on the provider, account configuration and hosting arrangements. CoreExec will take reasonable steps appropriate to the circumstances to protect information involved in cross-border processing or disclosure and to impose contractual, access and confidentiality controls where appropriate.

8. Third-party service providers

CoreExec uses third-party platforms to operate and deliver services. These may include ClickUp, Hubstaff, Deel, Stripe, Xero, WhatsApp and Calendly, as well as email, hosting, analytics, security and other technology providers. Information may be shared with these providers where reasonably necessary for the service they provide to CoreExec.

Third-party providers may have their own privacy policies, security practices and data locations. CoreExec does not control every aspect of a third party’s systems, but will select and use providers on a reasonable business basis and will limit disclosures to what is reasonably necessary.

9. Cookies, analytics and website technologies

The CoreExec website uses cookies and may use analytics, security and marketing technologies. Cookies are small files or identifiers used to remember settings, support website functionality, understand usage, improve performance, measure campaigns and help protect the website.

Depending on the final website configuration, analytics or advertising providers may collect technical and usage information. You can usually control cookies through your browser settings, although disabling some cookies may affect website functionality.

10. Marketing communications

CoreExec may use relevant business contact details to respond to enquiries, provide service information and send marketing or business-development communications where permitted. You can ask CoreExec to stop sending marketing communications at any time by using an unsubscribe option where provided or contacting CoreExec.

Operational or service-related messages may still be sent where they are reasonably necessary to administer an active enquiry, contract, payment, security issue or Client engagement.

11. Case studies, testimonials and Client logos

Where permitted under the applicable Client agreement, CoreExec may use a Client’s business name, logo, testimonial, non-confidential feedback or non-sensitive engagement outcomes for marketing or case-study purposes. CoreExec will not intentionally publish participant information, health information, confidential business information or other sensitive personal information as part of marketing without appropriate permission.

12. Storage and security

CoreExec takes reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, account permissions, authentication, confidentiality obligations, secure third-party services, role-based access, process controls and restricting access to personnel who reasonably need the information.

No method of electronic transmission, cloud storage or online communication is completely secure. CoreExec therefore cannot guarantee absolute security. If CoreExec becomes aware of a suspected data incident, it will assess and respond to the incident in accordance with applicable legal and contractual obligations.

13. Retention and deletion

CoreExec retains information for as long as reasonably necessary for the purpose for which it was collected, to deliver services, manage records, resolve disputes, meet accounting or legal requirements, maintain legitimate business records or protect legal rights. When information is no longer reasonably required, CoreExec may delete, destroy or de-identify it, subject to legal, technical and backup-retention requirements.

14. Access and correction

You may contact CoreExec to request access to personal information CoreExec holds about you or to ask for inaccurate, out-of-date, incomplete, irrelevant or misleading personal information to be corrected. CoreExec may need to verify your identity before acting on a request and may refuse or limit a request where permitted by law, in which case CoreExec will provide an explanation where required.

15. Privacy complaints

If you have a privacy question, concern or complaint, contact CoreExec at coreexec99@gmail.com. Please provide enough detail for CoreExec to understand and investigate the issue. CoreExec will aim to acknowledge and respond within a reasonable period.

If applicable privacy law gives you a right to escalate a complaint to a regulator, you may do so after giving CoreExec a reasonable opportunity to address the issue.

16. Client responsibilities for data and system access

  • Only provide information and system access that the Executive Assistant reasonably needs for the role.
  • Use individual user accounts where reasonably possible rather than shared credentials.
  • Apply appropriate permissions, multi-factor authentication and internal approvals for high-risk systems.
  • Inform CoreExec promptly if an Executive Assistant’s access should change or be removed.
  • Maintain lawful authority, notices and consents required for information the Client shares with CoreExec or permits an Executive Assistant to access.
  • Avoid sending unnecessary sensitive information through informal channels where a more appropriate secure system is available.

17. Candidate and contractor privacy

CoreExec may collect and use candidate and contractor information to assess suitability, verify information, match candidates to Client roles, present relevant candidate information to prospective Clients, administer contracts, process payments through Deel, monitor service delivery and maintain records.

CoreExec will not intentionally provide a prospective Client with more candidate information than is reasonably necessary for assessment and placement. Contractors may be asked to provide identity, work history, references, skills, assessment, payment or compliance information appropriate to the role and contractor arrangement.

18. Children

CoreExec’s website and commercial staffing services are directed to businesses and adults. CoreExec does not knowingly seek to collect personal information directly from children through the website. Information about minors may nevertheless appear in Client systems or records, including in regulated or care-related sectors, where the Client has lawful authority and the information is necessary for the assigned role.

20. Changes to this Privacy Policy

CoreExec may update this Privacy Policy as services, systems, legal requirements or information-handling practices change. The current version will be published on the CoreExec website and identified by the “Last updated” date.

21. Contact us

Privacy enquiries and requests

Email: coreexec99@gmail.com

General business enquiries

Email: admin@coreexec.com.au

CoreExec

ABN 39 859 348 089

Brisbane, Queensland, Australia

Website: www.coreexec.com.au