Your information

How we protect your data

The safest customer record is the one we never create. We collect what we need to run your service, and we leave the rest alone.

Data we never take

We protect your data by not collecting it

A stolen driver’s licence, passport or date of birth is exactly what a thief wants. Those details do not connect an NBN service, provision a SIP trunk or fix a phone fault. So we do not ask for them.

Some providers collect identity documents, biometrics and “secret questions” as a matter of course. We do not. If a field is useful to a hacker and useless for running your service, we do not collect it in the first place.

Encryption and locked cabinets matter. Collecting less matters more.

Network operations and monitoring
We do not collect

Identity data we have no business holding

We will not ask you for the following in order to become or remain a customer.

📄

Driver’s licence

Licence numbers and scans are a gift to identity thieves. We do not need them to supply phone or data services.

✈

Passport and government ID

No passport, Medicare card, proof of age or other government identification.

🎂

Date of birth

Your birthday is a common account-recovery key. We do not collect it.

👤

Biometrics

No facial recognition, fingerprints, voiceprints or other biometric data.

❓

Security questions

No mother’s maiden name, first pet or other questions that double as identity keys.

🔒

Anything we do not need

If it is not required to provision, bill or support your service, we do not take it.

Australian account support
What we do collect

Only what it takes to run your service

Typical records we hold are the ones needed to connect, bill and support you:

  • Contact name, phone and email
  • Company name and ABN
  • Service and billing addresses
  • Service and usage records needed to operate the network and your account
  • Bank account details used only to process direct debit billing
  • Correspondence between you and us

We do not sell, rent or trade personal information. Direct marketing from us only happens if you have opted in. Bank details are not used for any other purpose.

How we look after what we hold

Over 20 years, no data breach

We have never been exposed to a data breach in more than 20 years of operation. The systems that hold your customer records are not internet-facing.

Not on the public internet

Customer data sits on systems that are not internet-facing. They are not sitting on the public web waiting to be scanned.

Need-to-know access

Staff see customer records only when their job requires it. We confirm who you are before we discuss an account.

100% Australian owned

You deal with the same Australian team that looks after your services, not an offshore ticket queue. Website forms and logins use HTTPS.

Please treat any login and password as you would a key to the office. Do not share them. If you think someone else has used an account, call us on (02) 8228 7777.

Sharing of data

We do not sell your information. We share only to run the service, or when the law requires it.

This is the policy to send a bank or finance team that asks how customer data is disclosed.

We do not sell or trade

We do not sell, rent or trade personal information. We do not give it to other businesses for their marketing. We do not publish customer lists.

Bank details stay on the debit

Account details are used only to process a direct debit you have authorised, through the Bulk Electronic Clearing System with your financial institution. They are not used for anything else.

Partners get only what they need

Network partners (for example nbn and wholesale carriers) receive only what is required to provision, connect or support your service.

We may also disclose information to:

  • Credit providers or credit reporting agencies, where a business credit check applies
  • Legal advisors
  • Regulators, complaint bodies or law-enforcement agencies when Australian law requires or permits it
  • The Integrated Public Number Database (IPND), which telecommunications law requires for directory and emergency-service use

Anyone we give information to is expected to protect it under the Privacy Act 1988 or equivalent obligations.

Direct debit protections

A bank-account direct debit is a regulated Australian payment, with rights you control at your bank

It is as well protected as a card payment, and in one practical way it is better: reporting a problem does not force a new account number and break every other recurring payment.

Cancel at your bank

ASIC’s MoneySmart and the Banking Code of Practice are clear: you can tell your bank to stop a bank-account direct debit. The bank must process that request. You do not have to ask us first. A credit-card recurring payment usually has to be cancelled with the merchant first.

Dispute an unauthorised debit

If an amount was not authorised, or does not match the Direct Debit Request, contact your bank. They must take the claim and must not send you to us first. Under BECS, claims made within 12 months of the debit get a 5-business-day response from our bank. Older claims still get a response, within a month.

Longer window than a card chargeback

Banks that subscribe to ASIC’s ePayments Code (which covers direct debits) must accept a report of an unauthorised transaction for 6 years from when you became aware of it, or should reasonably have become aware. Card-scheme chargebacks are often measured in months, not years.

Why the account number stays put

If you report a problem with a credit card, the issuer commonly cancels that card number and issues a new one. Every other recurring charge stored against the old number then fails: insurance, software, subscriptions, utilities. You spend days updating merchants, and some services simply stop.

A bank account number does not work that way. Reporting an unauthorised direct debit does not force your bank to issue you a new BSB and account number. Your other direct debits keep running. That is why many businesses treat bank-account direct debit as the more stable, and in this respect safer, way to pay.

You can also ask your bank for a list of direct debits on the account (banks that follow the Banking Code will provide up to the previous 13 months). If a debit still comes out after you have asked the bank to cancel, the bank cannot charge you overdraft fees to cover that debit.

Cancelling a debit does not cancel the service or the amount owing. Direct debit is a condition of our service for new customers. If you ever need to change banks, tell us the new account details so billing continues. Official guidance: moneysmart.gov.au/banking/direct-debits.

Incident response and breach notification

If an incident ever happened, we would contain it, assess it, and notify you when the law requires

We have never been exposed to a data breach in more than 20 years of operation. This is the process we would follow.

1. Contain

Stop further unauthorised access, disclosure or loss where we can, and secure the affected systems.

2. Assess

Decide within 30 days whether it is an eligible data breach under the Privacy Act: unauthorised access, disclosure or loss that is likely to cause serious harm, and that we cannot prevent with remedial action.

3. Notify

If it is an eligible breach, we notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, as required by the Notifiable Data Breaches scheme.

A notification will say what happened, what information was involved, what we are doing about it, and what you can do. If we cannot reach affected people directly, we would publish a statement as the Act allows. After that we remediate the cause and review our controls.

If you reasonably suspect your information with us has been misused or exposed, contact us immediately on (02) 8228 7777 or info@nationalphone.com.au.

Mandatory and business retention

How long we keep records

We keep information only as long as we need it to provide the service, or as long as Australian law requires. When it is no longer needed and no law requires us to keep it, we take reasonable steps to destroy it or de-identify it.

  • Account, service and correspondence: while you are a customer, and for a reasonable period afterwards to bill, support, handle disputes and meet legal duties.
  • Telecommunications data the law requires a provider to keep under Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (still in force): generally two years from when the record is created. Subscriber and account information that the same Part covers is kept for the life of the account and for two years after the account is closed. This is metadata used to operate the service (for example who communicated, when, and how), not the content of calls, messages or web browsing. The Telecommunications Act 1997 still applies to how we run as a provider. It does not set that two-year period.
  • Billing and financial records, including direct debit authorities: at least five years, in line with Australian tax and business-record rules, or longer if a dispute or legal hold applies.

We do not keep driver’s licences, passports, dates of birth or other identity documents, because we do not collect them.

National Phone & Data records and account management
Your rights

Ask us what we hold

You can ask for access to the personal information we hold about you, or ask us to correct it, by calling (02) 8228 7777. We may need to refuse a request in limited cases, for example where it would affect someone else’s privacy or an investigation.

The Privacy Policy (PDF) is the document to forward to a bank or finance team. It covers sharing, incident response, breach notification and retention.

Privacy Policy (PDF)

Talking with a National Phone & Data specialist

Questions about your information?

Call the same team that looks after your services.

(02) 8228 7777