How we protect your data
The safest customer record is the one we never create. We collect what we need to run your service, and we leave the rest alone.
We protect your data by not collecting it
A stolen driver’s licence, passport or date of birth is exactly what a thief wants. Those details do not connect an NBN service, provision a SIP trunk or fix a phone fault. So we do not ask for them.
Some providers collect identity documents, biometrics and “secret questions” as a matter of course. We do not. If a field is useful to a hacker and useless for running your service, we do not collect it in the first place.
Encryption and locked cabinets matter. Collecting less matters more.
Identity data we have no business holding
We will not ask you for the following in order to become or remain a customer.
Driver’s licence
Licence numbers and scans are a gift to identity thieves. We do not need them to supply phone or data services.
Passport and government ID
No passport, Medicare card, proof of age or other government identification.
Date of birth
Your birthday is a common account-recovery key. We do not collect it.
Biometrics
No facial recognition, fingerprints, voiceprints or other biometric data.
Security questions
No mother’s maiden name, first pet or other questions that double as identity keys.
Anything we do not need
If it is not required to provision, bill or support your service, we do not take it.
Only what it takes to run your service
Typical records we hold are the ones needed to connect, bill and support you:
- Contact name, phone and email
- Company name and ABN
- Service and billing addresses
- Service and usage records needed to operate the network and your account
- Bank account details used only to process direct debit billing
- Correspondence between you and us
We do not sell, rent or trade personal information. Direct marketing from us only happens if you have opted in. Bank details are not used for any other purpose.
Over 20 years, no data breach
We have never been exposed to a data breach in more than 20 years of operation. The systems that hold your customer records are not internet-facing.
Not on the public internet
Customer data sits on systems that are not internet-facing. They are not sitting on the public web waiting to be scanned.
Need-to-know access
Staff see customer records only when their job requires it. We confirm who you are before we discuss an account.
100% Australian owned
You deal with the same Australian team that looks after your services, not an offshore ticket queue. Website forms and logins use HTTPS.
Please treat any login and password as you would a key to the office. Do not share them. If you think someone else has used an account, call us on (02) 8228 7777.
We do not sell your information. We share only to run the service, or when the law requires it.
This is the policy to send a bank or finance team that asks how customer data is disclosed.
We do not sell or trade
We do not sell, rent or trade personal information. We do not give it to other businesses for their marketing. We do not publish customer lists.
Bank details stay on the debit
Account details are used only to process a direct debit you have authorised, through the Bulk Electronic Clearing System with your financial institution. They are not used for anything else.
Partners get only what they need
Network partners (for example nbn and wholesale carriers) receive only what is required to provision, connect or support your service.
We may also disclose information to:
- Credit providers or credit reporting agencies, where a business credit check applies
- Legal advisors
- Regulators, complaint bodies or law-enforcement agencies when Australian law requires or permits it
- The Integrated Public Number Database (IPND), which telecommunications law requires for directory and emergency-service use
Anyone we give information to is expected to protect it under the Privacy Act 1988 or equivalent obligations.
A bank-account direct debit is a regulated Australian payment, with rights you control at your bank
It is as well protected as a card payment, and in one practical way it is better: reporting a problem does not force a new account number and break every other recurring payment.
Cancel at your bank
ASIC’s MoneySmart and the Banking Code of Practice are clear: you can tell your bank to stop a bank-account direct debit. The bank must process that request. You do not have to ask us first. A credit-card recurring payment usually has to be cancelled with the merchant first.
Dispute an unauthorised debit
If an amount was not authorised, or does not match the Direct Debit Request, contact your bank. They must take the claim and must not send you to us first. Under BECS, claims made within 12 months of the debit get a 5-business-day response from our bank. Older claims still get a response, within a month.
Longer window than a card chargeback
Banks that subscribe to ASIC’s ePayments Code (which covers direct debits) must accept a report of an unauthorised transaction for 6 years from when you became aware of it, or should reasonably have become aware. Card-scheme chargebacks are often measured in months, not years.
Why the account number stays put
If you report a problem with a credit card, the issuer commonly cancels that card number and issues a new one. Every other recurring charge stored against the old number then fails: insurance, software, subscriptions, utilities. You spend days updating merchants, and some services simply stop.
A bank account number does not work that way. Reporting an unauthorised direct debit does not force your bank to issue you a new BSB and account number. Your other direct debits keep running. That is why many businesses treat bank-account direct debit as the more stable, and in this respect safer, way to pay.
You can also ask your bank for a list of direct debits on the account (banks that follow the Banking Code will provide up to the previous 13 months). If a debit still comes out after you have asked the bank to cancel, the bank cannot charge you overdraft fees to cover that debit.
Cancelling a debit does not cancel the service or the amount owing. Direct debit is a condition of our service for new customers. If you ever need to change banks, tell us the new account details so billing continues. Official guidance: moneysmart.gov.au/banking/direct-debits.
If an incident ever happened, we would contain it, assess it, and notify you when the law requires
We have never been exposed to a data breach in more than 20 years of operation. This is the process we would follow.
1. Contain
Stop further unauthorised access, disclosure or loss where we can, and secure the affected systems.
2. Assess
Decide within 30 days whether it is an eligible data breach under the Privacy Act: unauthorised access, disclosure or loss that is likely to cause serious harm, and that we cannot prevent with remedial action.
3. Notify
If it is an eligible breach, we notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, as required by the Notifiable Data Breaches scheme.
A notification will say what happened, what information was involved, what we are doing about it, and what you can do. If we cannot reach affected people directly, we would publish a statement as the Act allows. After that we remediate the cause and review our controls.
If you reasonably suspect your information with us has been misused or exposed, contact us immediately on (02) 8228 7777 or info@nationalphone.com.au.
How long we keep records
We keep information only as long as we need it to provide the service, or as long as Australian law requires. When it is no longer needed and no law requires us to keep it, we take reasonable steps to destroy it or de-identify it.
- Account, service and correspondence: while you are a customer, and for a reasonable period afterwards to bill, support, handle disputes and meet legal duties.
- Telecommunications data the law requires a provider to keep under Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (still in force): generally two years from when the record is created. Subscriber and account information that the same Part covers is kept for the life of the account and for two years after the account is closed. This is metadata used to operate the service (for example who communicated, when, and how), not the content of calls, messages or web browsing. The Telecommunications Act 1997 still applies to how we run as a provider. It does not set that two-year period.
- Billing and financial records, including direct debit authorities: at least five years, in line with Australian tax and business-record rules, or longer if a dispute or legal hold applies.
We do not keep driver’s licences, passports, dates of birth or other identity documents, because we do not collect them.
Ask us what we hold
You can ask for access to the personal information we hold about you, or ask us to correct it, by calling (02) 8228 7777. We may need to refuse a request in limited cases, for example where it would affect someone else’s privacy or an investigation.
The Privacy Policy (PDF) is the document to forward to a bank or finance team. It covers sharing, incident response, breach notification and retention.