Last updated: July 16th 2026
Reconexa Privacy Policy
Nettfunder Pty Ltd (ABN 95 612 623 426) trading as Reconexa ("Reconexa", "we", "us", "our") is committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights individuals have in relation to their information. It applies to our website (reconexa.ai) and the Reconexa platform (the "Service").
1. Who this policy covers
This policy applies to:
- our business customers (clinics and healthcare teams) and their staff who use the Service ("Customer");
- individuals whose information is processed through the Service as part of a Customer's use of it (for example, information relating to a Customer's patients that appears in payment or remittance records); and
- visitors to our website.
Reconexa acts on behalf of Customer in processing information relating to Customer's patients or clients. Customer remains responsible, as the collector of that information, for its own obligations under the Privacy Act and any applicable health records legislation. This policy describes Reconexa's own handling of personal information as a service provider.
2. Personal information we collect
From Customer and its staff:
- Name, work email address, phone number, job title, and organisation details
- Account login and authentication details
- Billing and payment details for subscription fees
Processed through the Service (via Connected Systems such as Cliniko and Xero):
- Payment and remittance details connected to a Customer's clients or patients, which may include information that identifies an individual (such as a name associated with a payment record)
- We do not directly collect clinical or health treatment information; our access is limited to payment and reconciliation data made available through the Connected Systems Customer chooses to connect
From the website:
- Contact form submissions (name, work email, phone, organisation, message)
- Usage and analytics data collected via cookies and similar technologies (see section 9)
3. How we collect personal information
We collect personal information:
- directly from Customer, when an account is created or a form is submitted;
- automatically, through use of the Service and website (e.g. log data, analytics);
- via Connected Systems, when Customer authorises a connection to Cliniko, Xero, or another integrated system.
4. Why we collect and use personal information
We use personal information to:
- provide, operate, and maintain the Service, including remittance and reconciliation workflows;
- respond to enquiries and provide customer support;
- manage billing and subscriptions;
- maintain and improve the Service, including using de-identified and aggregated data for product development (see section 6);
- communicate with Customer about the Service, including updates to these terms or the Privacy Policy;
- comply with legal obligations.
We do not use personal information for automated decision-making. Reconexa's workflow is designed to surface information for human review — a person on Customer's team makes the relevant decisions; Reconexa's role is limited to organising and flagging information for that review.
5. Disclosure of personal information
We may disclose personal information to:
- service providers who help us operate the platform (such as hosting, infrastructure, and support tools), under contractual obligations to protect that information and use it only for the purposes we specify;
- Connected Systems, to the extent necessary to enable the integration Customer has authorised (e.g. syncing data back to Cliniko or Xero);
- regulators or authorities, where required by law;
- a purchaser or successor, in the event of a merger, acquisition, or sale of business assets, subject to this policy continuing to apply to the information transferred.
We do not sell personal information.
6. Data storage, hosting, and security
Personal information processed through the Service is stored on Amazon Web Services (AWS) infrastructure located in Australia. We do not currently store or transfer personal information overseas.
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include access controls, encryption of data in transit and at rest, and restricting internal access to personal information on a need-to-know basis.
De-identified and aggregated data (which does not identify Customer, its staff, or any individual patient) may be used to help us understand usage patterns and improve the Service.
7. Data retention and deletion
We retain personal information for as long as Customer's account is active, and for a period afterward as needed to meet legal, accounting, or reporting obligations, or as set out in our Terms of Service (currently a 30-day export window following termination, after which data may be deleted from our systems).
8. Access, correction, and deletion requests
Individuals may request access to, correction of, or deletion of personal information we hold about them. Where the information relates to a Customer's patient or client, we may direct the request to the relevant Customer, as they are usually best placed (and legally responsible) to manage that request; we will assist Customer as needed to respond.
To make a request, contact us using the details in section 12. We will respond within a reasonable timeframe and may need to verify identity before actioning a request. We will delete personal information where it is no longer needed for the purpose it was collected, where consent has been withdrawn, or where it was collected unlawfully, unless we are required or permitted by law to retain it.
9. Cookies and website analytics
Our website uses cookies and similar technologies, including Google Analytics, to understand how visitors use the site and improve its content and performance. This may involve information being processed by Google in accordance with its own privacy practices.
You can control or disable cookies through your browser settings. Disabling cookies may affect some website functionality.
10. Data breaches
If we experience a data breach that is likely to result in serious harm to an individual, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
11. Children's privacy
The Service is intended for business use by clinics and healthcare teams and is not directed at, or intended for use by, children.
12. Contact us and complaints
For any questions about this policy, or to make a request or complaint about how we handle personal information, contact our Privacy Officer:
Email: hello@reconexa.ai
We will investigate complaints and aim to respond within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the OAIC:
Office of the Australian Information Commissioner Website: www.oaic.gov.au Phone: 1300 363 992
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. Material changes will be notified via email or an in-product notice at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent version.