Legal & policies

Plain English, written properly.

Privacy Policy

Last updated 6 October 2026

We collect what we need to connect, run and bill your nbn service, and to meet the law. We don’t sell it, we don’t have advertisers, and our website doesn’t track you. Your account data is stored in Australia on systems we run. As an internet provider we must keep some connection records for 2 years — never the content of your communications or your browsing history. You can ask to see or correct what we hold at any time, for free.

01Who we are and what this policy covers

APP 1 WARP Internet is a trading name of The IT Dept Pty Ltd (ABN 12 665 405 505), based in NSW, Australia. When this policy says “we”, “us” or “our”, it means The IT Dept Pty Ltd. We are a carriage service provider, so as well as the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), we are bound by Part 13 of the Telecommunications Act 1997 (Cth) and the data retention rules in Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (Cth). The APP numbers are tagged beside each section so you can check our work.

This policy covers everything we do with personal information: our website, the account portal, ordering, billing, support, complaints and our network. It is free to read here, and we’ll send you a copy in another format (for example, as a PDF, in large print, or read out over the phone) if you ask.

Questions about privacy go to our privacy officer at hello@warp.net.au or 02 4398 7081 (call). See section 19 for all the ways to reach us.

02Dealing with us anonymously or under a pseudonym

APP 2 You don’t have to tell us who you are to browse this website, check plans, read these documents or ask us a general question — a first name or no name at all is fine.

Once you order a service, anonymity isn’t practicable. We have to know who we’re supplying, where the service is, and how to bill and contact you, and the law requires us to keep accurate subscriber records (see section 9). So we need your real name and details to connect you.

03What we collect

APP 3 We collect only what we need to supply, support and bill your service and to meet our legal obligations:

  • Identity and contact details — your name, email address, mobile number, date of birth and service address, and your business name and ABN if the service is for a business.
  • Service details — your nbn location ID, the connection technology at your address, your AVC ID (nbn’s identifier for your connection), and the IP addresses we allocate to you (a public IPv4, or a shared IPv4 with its ports, and an IPv6 range), with when each was assigned and released.
  • Network records — when your connection sessions start and end, authentication logs (records of your router obtaining its address), usage counters (how much data was uploaded and downloaded, not what it was), and the results of line tests we run when you report a fault.
  • Payment records — invoices, payments, refunds and credits, and the brand and last four digits of your card. Your full card number is held by our payment processor, Stripe, and never reaches our systems.
  • Communications with us — emails, SMS messages, notes of phone calls, support requests, complaints and requests for help, so you don’t have to repeat yourself.
  • Account and website records — your portal sign-in (your password is stored only as a one-way hash, so no one here can read it) and standard server logs of requests to our website and portal, such as IP address, browser type and time, which we use for security and to fix problems.

We don’t ask for sensitive information such as health details, religious or political beliefs, or biometrics. Sometimes you might choose to tell us something sensitive — for example that you’re unwell, that you’re in financial hardship, or that you’re experiencing domestic, family or sexual violence — so we can help you. With your consent we record only what we need to give you that help, and we restrict who can see it.

04How we collect it

APP 3 & 5 We collect information in four ways:

  • From you — when you check your address, order, use the portal, pay, or contact us. This is how we collect almost everything.
  • From nbn and our wholesale access provider — when you check an address, what you type is sent to our wholesale access provider to find matching nbn locations. During service qualification they tell us whether the address can be connected, which technology it uses and what speeds the line supports. While your service is running they send us connection, appointment and fault information.
  • From our own network — we operate our own network and broadband gateway, which automatically records the session, address allocation and usage information described in section 3.
  • From others, with your authority — for example a financial counsellor, advocate or family member you’ve authorised to deal with us, the Telecommunications Industry Ombudsman (TIO) when it refers a complaint to us, and Stripe, which tells us whether a payment succeeded.

When we collect information from you we tell you why, what happens if you don’t provide it (usually, that we can’t connect or support the service), and where to find this policy. If we receive personal information we didn’t ask for and couldn’t lawfully have collected, we destroy or de-identify it as soon as practicable.

05Why we collect and use it

APP 6 We use your information to:

  • check whether we can connect your address, and connect it;
  • run your service — allocate your addresses, route your traffic, and find and fix faults;
  • bill you, take payment and issue refunds;
  • confirm it’s really you before making changes to your account (section 6);
  • give you support, handle complaints and provide financial hardship or family violence assistance;
  • send you service messages: invoices, payment reminders, outage and maintenance notices, price change notices and anything else we must tell you;
  • protect our network and customers from fraud, abuse and security threats; and
  • meet our legal and regulatory obligations.

We don’t use your information for anything else unless you agree, or the law requires or allows it. We don’t profile you, and we don’t use your data to target advertising.

06Checking it’s you

APP 9 When you order, we ask for your name, date of birth and contact details so we know who holds the account. Before a high-risk change — changing your contact details or card, cancelling or moving your service, transferring the account, or giving out information about your account — we confirm we’re dealing with you or someone you’ve authorised. We do that with a one-time code sent to the mobile number or email address already on your account, or by you acting from inside the signed-in portal. If those contact details are no longer safe or available to you, tell us and we’ll verify you another way.

If we ever need to see a government identity document, we record only that we checked it and what type it was. We never keep a copy, and we never use a government identifier (such as a driver’s licence or Medicare number) as your customer number or to link records about you.

07Who we share it with

APP 6 We share your information only where we need to in order to supply your service, or where the law requires or allows it:

  • nbn and our wholesale access provider — your service address, location ID, contact name and number, and appointment and fault details, so they can connect, maintain and repair the service.
  • Stripe — your name, email, card details (which you enter directly into Stripe’s form) and payment amounts, to process payments and refunds and to prevent card fraud.
  • Our email provider — the emails we send you and receive from you pass through it.
  • People you authorise — such as a financial counsellor or advocate acting for you.
  • Regulators and the ombudsman — the TIO, the Australian Communications and Media Authority (ACMA) and the Office of the Australian Information Commissioner (OAIC), when they deal with a complaint about us or require information from us.
  • Law enforcement and security agencies — only where the law requires or authorises it (section 8).

We never sell, rent or trade your personal information. We have no advertisers and no data partners, and we don’t give your details to anyone for their own marketing.

08The extra telecommunications rules

Part 13 of the Telecommunications Act 1997 makes it an offence for us to use or disclose information about your communications, the services we supply you, or your personal particulars, except in narrow circumstances the Act sets out. In practice we use or disclose it only:

  • to supply, maintain and bill your service;
  • with your consent, or where you’d reasonably expect it;
  • where we reasonably believe it’s necessary to prevent or lessen a serious threat to someone’s life or health;
  • where the law requires or authorises it — for example, under a warrant, or an authorisation from a law enforcement or security agency under the Telecommunications (Interception and Access) Act 1979; or
  • to assist the TIO or ACMA in performing their functions.

We check every request from an agency to make sure it’s lawful before we act on it, we disclose only what it covers, and we keep a record of each disclosure as section 306 of the Act requires. The content of your communications can only be accessed under a warrant that specifically allows it.

09Data retention: what the law makes us keep

As an internet provider, Part 5-1A of the Telecommunications (Interception and Access) Act 1979 requires us to keep a defined set of records — often called “metadata” — so that authorised agencies can request them. For your service, that means:

  • Subscriber and account details — your name, address, contact details, billing and payment records, and the services you have with us. Kept while your account is open and for 2 years after it closes.
  • Connection records — when each connection session started and ended, the type of service, the service address, and how much data was uploaded and downloaded. Kept for 2 years from when each record is made.
  • IP address records — the IP addresses allocated to your service, and when each was assigned and released. Kept for at least 2 years after the address stops being assigned to your service.

We do not keep the content of your communications, and we do not keep your browsing history — which websites you visit or which addresses you communicate with on the internet. The law doesn’t require it, and we don’t do it. Retained data is encrypted, stored in Australia, and disclosed only to agencies with a lawful basis to ask for it (section 8). When the retention period ends and we don’t otherwise need the records, we delete them.

10Marketing, and the Spam Act

APP 7 We’ll only send you marketing — news about our own plans, features or offers — with your consent, and we never send marketing on anyone else’s behalf. Under the Spam Act 2003, every marketing message identifies us as the sender and includes a working way to unsubscribe. You can also opt out by telling us at any time. We act on an opt-out within 5 working days, and it costs you nothing.

Service messages aren’t marketing. Invoices, payment reminders, outage and maintenance notices, price change notices and anything else we must tell you about your service will keep coming while you have a service with us, even if you’ve opted out of marketing.

11Cookies and our website

Our website and portal use only strictly necessary cookies: a sign-in session cookie (named warp_session, and other cookies prefixed warp_) that keeps you signed in and keeps your order moving. They aren’t used to identify you across other sites.

We don’t use advertising cookies, tracking pixels, social media trackers or analytics services. When you enter card details, the card form is loaded directly from Stripe, and Stripe may set its own cookies on that page to detect card fraud; those are covered by Stripe’s privacy policy. If we ever decide to add website analytics, we’ll update this policy before we do.

12Overseas disclosure

APP 8 Your account data and network records are stored in Australia on infrastructure we operate. Two of our suppliers may handle some of your information outside Australia:

  • Stripe, which processes payments, may store and process payment information in the United States and other countries where it operates.
  • Our email provider may store or route emails we exchange with you through servers outside Australia, including in the United States.

We choose suppliers that are bound by privacy and security obligations consistent with the APPs, and we remain responsible under the Privacy Act for how they handle the information we give them. No one else receives your information overseas.

13Keeping it secure

APP 11 We protect your information with encryption in transit, encryption of retained records, access controls and the principle of least privilege — people here see only what their job requires, and information about hardship or family violence is restricted further. Our systems are hosted in Australia on infrastructure we run ourselves, and we keep software patched.

No system is perfectly secure, which is why we collect as little as we can. You can help by using a strong, unique password for the portal and telling us straight away if you think someone else has accessed your account.

14If there’s a data breach

If we suspect a data breach, we contain it and assess it immediately, and in any case within 30 days. If it’s likely to cause serious harm to anyone, we notify the people affected and the OAIC as soon as practicable under the Notifiable Data Breaches scheme, and tell you what happened, what information was involved and what you should do. If the breach involves your service we’ll also tell you how to protect yourself — for example by changing your password or watching for scam messages.

15Keeping it accurate, and how long we keep it

APP 10 & 11 We take reasonable steps to keep your information accurate, up to date and complete. You can update your contact details at any time in your portal account, or ask us to.

We keep information only for as long as we need it or the law requires: data retention records for the periods in section 9, billing and payment records for 7 years for tax and company law, and complaint records for at least 2 years. Once we no longer need a record for any of those reasons, we securely delete or de-identify it.

16Seeing and correcting your information

APP 12 & 13 You can ask for a copy of the personal information we hold about you, and ask us to correct anything that’s wrong, out of date or incomplete. Email hello@warp.net.au or call 02 4398 7081. We’ll check it’s you (section 6) and respond within 30 days. Asking is free, and so is any correction.

We can only refuse access or correction on the grounds the Privacy Act allows — for example, where giving access would put someone else’s safety or privacy at risk, or where the law prevents it. If we refuse, we’ll tell you why in writing and how to complain. If we don’t agree that something needs correcting, you can ask us to attach a statement to your record saying you believe it’s wrong, and we will.

17Complaints about privacy

If you think we’ve mishandled your personal information, please tell us first so we can put it right. Contact us at hello@warp.net.au or 02 4398 7081. We handle privacy complaints under our Complaints Handling Policy: we acknowledge them within 2 working days and resolve them within 15 working days.

If you’re not satisfied with our response, or we haven’t responded within 30 days, you can complain to the Office of the Australian Information Commissioner:

  • Online: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

Because we’re a telco, the Telecommunications Industry Ombudsman can also deal with complaints about how we’ve handled your personal information: 1800 062 058 or tio.com.au. Both services are free.

18Changes to this policy

We’ll update this policy when the way we handle information changes, and change the date at the top. If a change is significant — for example, a new kind of information, a new supplier that receives your data, or a new overseas destination — we’ll email customers before it takes effect. The current version always lives at this address.

19Contact us

Our other policies — the Customer Terms, the Financial Hardship Policy and Domestic, Family and Sexual Violence Support — explain more about how we look after you.