Privacy Policy
This Policy explains how Alder handles personal information, telecommunications information, account and billing data, managed-network telemetry, support records and information used by My Alder.
1. Purpose, scope and legal framework
This Policy applies to personal information handled by Alder in connection with our website, My Alder, NBN and internet services, mobile services, managed Wi-Fi, Alder Protect / Family Safe, billing, support and related operations. We manage information in accordance with applicable Australian privacy and telecommunications confidentiality requirements, including the Privacy Act 1988 and Australian Privacy Principles where they apply, Part 13 of the Telecommunications Act 1997, the Notifiable Data Breaches scheme where applicable, and telecommunications-specific confidentiality, identity, data-retention and disclosure rules relevant to our services.
Some telecommunications information is subject to additional statutory restrictions even where general privacy law would otherwise permit a use or disclosure. We treat those telecommunications confidentiality obligations as an additional control rather than a substitute for privacy governance.
2. Categories of information we collect and hold
| Category | Examples |
|---|---|
| Identity and contact | Name, email, phone, service address, billing address, business name, ABN, authorised-user details and account roles. |
| Service and provisioning | Plan, NBN location/qualification, service identifiers, activation and transfer information, mobile number, SIM/eSIM status, equipment and appointment information. |
| Billing and payment | Invoices, payment status, account balance, payment-assistance records, transaction references and limited card metadata such as brand and last four digits. |
| Network and technical | Router/gateway identifiers, IP addresses, MAC addresses, connected-device identifiers, access-point information, signal levels, WAN health, packet loss, latency, throughput and usage volumes. |
| Security and filtering | Protection profile settings, filtered categories, blocked domains, threat/security events, account-security events and fraud indicators. |
| Support and communications | Tickets, complaints, chat/messages, appointment records, call information where applicable, emails, notes and troubleshooting history. |
| Digital-service information | Login activity, browser/device information, app telemetry, cookies, security logs and interaction data. |
3. Sensitive information
Alder does not seek sensitive information unless it is reasonably necessary and lawful for the relevant purpose. A customer may disclose sensitive information in connection with payment assistance, accessibility, safety, domestic/family/sexual violence support, medical or critical-service considerations or a complaint. We restrict access to this information and only use or disclose it for the purpose for which it was collected or another purpose authorised by law.
We do not require a person affected by domestic, family or sexual violence to provide unnecessary details of abuse. Our Safe Support statement describes additional protections.
4. How we collect information
We collect information directly from customers and authorised representatives through orders, forms, My Alder, support interactions, telephone, email and other communications. We also collect information automatically from supported network equipment, My Alder and website interactions where necessary for operation, security and support.
Information may also come from NBN-related systems, Wholesale Suppliers, mobile network providers, payment processors, identity/porting verification processes, network/security vendors, service partners, public registers, regulators or other third parties where collection is lawful and reasonably necessary.
If you do not provide information reasonably required to supply a Service, verify authority, process a port, investigate a fault or comply with law, we may be unable to complete the relevant request.
5. Purposes for which we collect, use and disclose information
- assessing service availability and NBN qualification;
- creating and administering customer accounts and authorised-user permissions;
- provisioning, transferring, maintaining and supporting internet and mobile services;
- operating managed Wi-Fi, connection-health, Alder Protect / Family Safe and network-security functions;
- billing, taking payments, administering credits/refunds and providing payment assistance;
- responding to enquiries, faults, complaints, safety issues and service requests;
- detecting and preventing fraud, account takeover, malicious activity and network abuse;
- communicating outages, planned maintenance, billing, security and regulatory information;
- maintaining audit, security and compliance records;
- improving service quality, product design and operational performance;
- meeting lawful telecommunications, emergency, law-enforcement, national-security, court, regulator and recordkeeping requirements; and
- marketing Alder products where permitted, subject to applicable consent and opt-out rules.
6. Managed-network and Alder Protect information
Where you use an Alder-managed router, gateway, access point or supported managed-network service, we may collect technical telemetry needed to configure, monitor, secure and troubleshoot that environment. This may include device names/identifiers, IP and MAC addresses, signal quality, connection type, network usage, access-point association and service-health measurements.
Alder Protect / Family Safe can generate information about security or filtering actions, including the domain or category associated with a blocked request, the relevant household profile or device, and the reason a request was allowed or blocked. Access is restricted to authorised users and staff with a legitimate support, security or operational need. We do not use managed-network access as a general means of inspecting the content stored on customer devices.
7. My Alder, household access and account security
My Alder stores account, service, billing, support and security information needed to provide the portal. We record security-relevant events such as authentication activity, verification and administrative changes where available. Household or guardian access is permission-scoped; being an authorised household user does not automatically grant billing, cancellation or account-holder powers.
We may use fraud and security signals to require additional verification, restrict a high-risk action or alert staff. Support PINs, authentication tokens and similar credentials are treated as security information and are not disclosed merely because a person knows basic account details.
8. Payments and financial information
Where card payments are enabled, Alder uses a payment processor such as Stripe. Alder does not intentionally store full card numbers or security codes in My Alder. We may retain payment-method identifiers, card brand, expiry information, last four digits, payment status, transaction references, surcharge information and consent/audit records needed to operate billing.
Payment-assistance information is used only for assessing and administering assistance, related complaints and legal/compliance purposes. We do not sell hardship or payment-assistance information or use it for unrelated marketing.
9. Mobile porting and identity-verification information
Mobile number transfer requests involve additional identity and anti-fraud requirements. We may collect and verify information required by the Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard or successor rules. Porting information is only used and disclosed for the transfer, fraud prevention, service administration and other lawful purposes.
If verification fails or fraud is suspected, we may pause or refuse the port and retain appropriate audit information about the attempt.
10. Automated systems, decision support and AI-assisted tools
Alder uses software to automate or support routine operational activities. Examples include NBN address matching and service qualification, calculation of network-health observations, security/threat classification, notification routing, account-access checks, payment-status processing and workflow prioritisation.
We may use AI-assisted tools to help staff summarise technical information, draft customer explanations or classify support requests. AI output is not treated as automatically correct and is subject to staff controls appropriate to the task.
We do not intend to make decisions that significantly affect an individual’s rights or interests—such as final payment-assistance decisions, DFSV safety decisions, complaint outcomes, involuntary cancellation or comparable high-impact decisions—solely by opaque automated means where human review or another safeguard is required. From 10 December 2026, where the automated-decision transparency provisions in APP 1 apply to Alder, this Policy is intended to identify the kinds of personal information used and the kinds of relevant decisions or decision-support activities used by our systems.
11. Disclosure to suppliers and other third parties
We may disclose information to parties that help us provide, administer or protect Services, including NBN/wholesale telecommunications providers, mobile carriers, cloud and hosting providers, payment processors, email and communications providers, customer-support systems, network-management platforms, security and filtering providers, professional advisers and contractors.
Examples of platforms used or capable of being used in Alder operations include the My Alder application platform (Base44/Wix), Stripe for card payments, Ubiquiti or other network-management systems, security/filtering providers, email/cloud providers and Aussie Broadband or other wholesale telecommunications providers. Supplier access is limited to what is reasonably required for their function and subject to contractual, technical or legal controls appropriate to the service.
We may also disclose information to a person you authorise, to another provider for a requested transfer, to the TIO or a regulator in connection with a complaint, or as otherwise authorised or required by law.
12. Overseas disclosures and processing
Some cloud, software, payment, security and network providers operate internationally. Depending on the supplier, configuration and subprocessor used, personal information may be disclosed to or processed in Australia, the United States, Israel, countries in the European Economic Area including Ireland, and other countries identified in a supplier’s current subprocessor or hosting arrangements.
Where it is practicable to identify a material new overseas destination, we update this Policy or related privacy information. Where Australian privacy law requires us to take reasonable steps in relation to an overseas recipient, we do so having regard to the nature of the information, the provider and the service involved.
13. Government, emergency and lawful disclosures
Telecommunications information is subject to strict confidentiality rules as well as lawful disclosure regimes. Alder may be required or authorised to provide information in response to a valid court order, warrant, lawful request, emergency process, telecommunications legislation, national-security requirement, regulator request or other legal authority. We assess requests against applicable authority and do not disclose information merely because a third party asks for it.
14. Direct marketing
We may use permitted contact information to communicate relevant Alder products or services. Electronic marketing is managed in accordance with applicable spam and marketing laws. Where an opt-out is required, we provide one and action it within the required timeframe. Service, billing, security, outage and regulatory messages are not treated as marketing merely because they are sent electronically.
15. Children, household profiles and family features
My Alder can support household profiles for family-management purposes. Alder designs these features so a parent or guardian can manage a child/guest profile without requiring the child to have a separate customer login. We do not need a child’s exact date of birth for ordinary profile management and use coarse profile/age settings where sufficient.
The account holder or authorised guardian is responsible for choosing household settings. Family Safe features are protective controls and do not replace supervision or guarantee that harmful material will never be accessible.
16. Security of personal information
We use administrative, technical and physical measures appropriate to the information and service, which may include role-based access, least-privilege permissions, authentication controls, audit logging, encryption in transit, security monitoring, controlled supplier access, backups and incident-response procedures. Staff access to sensitive customer information is restricted by role and operational need.
No internet-connected system can be guaranteed risk-free. Customers also have a role in protecting account credentials, email accounts, mobile devices, SIMs and authentication codes.
17. Retention, archival and destruction
We keep information for as long as reasonably necessary for the purpose for which it was collected and to meet billing, tax, telecommunications, security, fraud, complaint, contract, dispute and legal obligations. Different categories have different retention periods. For example, active service/account records are retained while needed to supply and administer the service; financial and contractual records may be retained for statutory/accounting periods; complaint records are retained to meet telecommunications requirements; and certain telecommunications data may be subject to statutory retention requirements.
When information is no longer required and there is no legal or operational reason to retain it, we take reasonable steps to destroy or de-identify it. Backups may persist for a limited period until rotated through the normal backup lifecycle.
18. Data breaches and security incidents
We maintain incident-response processes to identify, contain, investigate and remediate suspected privacy or security incidents. Where the Notifiable Data Breaches scheme or another mandatory notification regime applies, we assess whether notification is required and notify affected individuals and the relevant authority within the applicable legal framework.
Customers should report suspected account compromise, SIM fraud, unauthorised porting or other security concerns promptly through Alder support.
19. Access and correction requests
You may request access to personal information Alder holds about you and ask us to correct inaccurate or out-of-date information. Requests can be made to [email protected] or by calling 03 4332 5184. We may verify your identity and authority before releasing information.
If access or correction is refused in whole or part, we will provide the reason where required and explain the available complaint pathway. We may redact information about another person or information we are legally prohibited from disclosing.
20. Privacy complaints
Privacy complaints may be lodged through the contact details below and are handled fairly and without charge. We will record and investigate the issue, keep you informed of material delays and explain the outcome. Depending on the issue, you may also be able to complain to the Office of the Australian Information Commissioner, the ACMA or the Telecommunications Industry Ombudsman.
Telecommunications service complaints can also be raised through Alder’s Complaints Handling Policy.
21. Website, My Alder, cookies and analytics
The website and My Alder may use cookies, local storage, session tokens and analytics to authenticate users, protect sessions, remember preferences, measure performance and understand service use. Essential technologies may be necessary for login, security or core functionality. Where non-essential analytics or marketing technologies require consent under applicable law, we will provide the relevant choice.
22. Changes to this Policy
We review this Policy at least annually and when a material change to law, service design, data practice or supplier arrangement requires it. We publish the current version on the Alder website and identify the effective date and version. Where a change materially affects how existing customer information is handled, we will provide additional notice where law or fairness requires it.
Email [email protected] or call 03 4332 5184. If you need this Policy in another accessible format, contact us and we will provide a reasonable alternative where practicable.
