Privacy Policy

Effective Date: 28 September 2026

1. About This Policy

SipTel Pty Ltd (ABN 51 652 932 922) ("SipTel", "we", "us" or "our") is committed to protecting your personal information. We handle it in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth) and, for telecommunications information, Part 13 of the Telecommunications Act 1997 (Cth).

This policy explains what personal information we collect, how we use and share it, how we keep it secure, and how you can access it or make a complaint. It covers our website and all of our services, including business VoIP, cloud phone systems (3CX), internet services (NBN and OptiComm), mobile numbers, our SMS Gateway and messaging portal, Microsoft Teams calling, and our WhatsApp Business integration.

2. Information We Collect

Customer and account information

  • Your name, business name, ABN, job title and contact details (phone, email, postal address).
  • Billing and service addresses.
  • Payment details: card and bank payments are processed by Stripe. If you choose to save a payment method, it is stored by Stripe, not by SipTel. We do not store full card or bank account numbers.
  • Details needed to transfer your services, such as your account number with your previous provider.
  • Identity checks: before we transfer a number or make important changes to your account, we confirm who you are, for example by checking your ABN or sending a one-time code to your phone or email. We do not ask you to send us copies of identity documents such as a driver licence, and we do not store them.
  • The names, extensions and contact details of your staff who use our services, provided by your business.

Service and usage information

  • Call records, such as the numbers called, date, time and duration.
  • SMS and messaging records, including message content sent or received through our SMS Gateway, messaging portal or WhatsApp integration.
  • Voicemail messages and call recordings, where these features are enabled on your service. Depending on your service, these are stored on SipTel's systems or on your business's own 3CX phone system.
  • Technical information such as IP addresses, service identifiers, device and phone system settings, and network diagnostics.
  • Records of your support requests and communications with us.

Website information

  • Enquiry forms: the details you enter, such as your name, company, email, phone number and message. These are emailed to our team and a confirmation is emailed to you. They are not stored in a database on our website.
  • Server logs: like most websites, our web server records each visit, including your IP address, browser type, the pages you view and the time. We use these logs for security and to count visits, and delete them after at most 14 days.
  • No tracking cookies: our website does not use advertising or analytics cookies. Our YouTube page shows video thumbnails loaded from YouTube, and clicking a video takes you to YouTube, which has its own privacy policy.

3. How We Collect Information

We collect personal information:

  • directly from you, when you enquire, sign up, use our services or contact our support team;
  • from your business, when it sets up services or users on your behalf;
  • automatically, as our network and systems carry your calls, messages and data; and
  • from third parties where needed to provide your services, such as your previous provider during a transfer, or NBN Co and OptiComm when checking or repairing a connection.

4. How We Use Your Information

We use personal information to:

  • provide, connect, maintain and support your services;
  • route calls and deliver messages;
  • transfer phone numbers to and from other providers;
  • bill you and manage your account;
  • respond to enquiries and quote requests;
  • detect and prevent fraud, misuse and security threats, including toll fraud;
  • improve our network, systems and services; and
  • meet our legal and regulatory obligations.

We do not sell personal information, and we do not run credit checks on our customers.

5. SMS, Messaging and WhatsApp Services

When you use our SMS Gateway, messaging portal or WhatsApp Business integration, we process the phone numbers of senders and recipients, message content, timestamps and delivery status in order to deliver messages and show your message history.

WhatsApp messages are carried by the WhatsApp Business Platform, operated by Meta Platforms, Inc. Meta may process message data under its own terms and privacy policy. Messages sent through 3CX are also processed by 3CX as part of your phone system.

We do not access the content of your messages, calls, voicemails or recordings except where needed for technical support or troubleshooting, or where the law requires it.

If you use our messaging services to contact your own customers, your business is responsible for having their consent where required, including under the Spam Act 2003 (Cth).

6. Who We Share Information With

We share personal information only as needed to provide our services or where the law requires or allows it, including with:

  • upstream carriers and wholesale providers, such as NBN Co, OptiComm, SIP trunk providers and mobile network providers;
  • other telecommunications providers, when transferring phone numbers or services;
  • technology providers that form part of your services, such as 3CX, Meta (WhatsApp) and Microsoft (Teams);
  • service providers that support our business, such as cloud hosting, email delivery, payment processing (Stripe), and our professional advisers;
  • the Integrated Public Number Database (see Section 7);
  • emergency services, when you call 000 or 112;
  • law enforcement, national security and regulatory agencies, where required or authorised by law; and
  • the Telecommunications Industry Ombudsman or the Office of the Australian Information Commissioner, when handling a complaint.

We require our service providers to keep personal information confidential and to use it only to provide their services to us.

7. Integrated Public Number Database

As a telecommunications provider, we, or our wholesale provider on our behalf, are required by law to give your name, address, phone number and service details to the Integrated Public Number Database (IPND), an industry database managed by Telstra. The IPND is used to help emergency services locate callers, and for other purposes permitted by law, such as public directories. If you do not want your number listed in public directories, ask us to make it a silent (unlisted) number.

8. Overseas Disclosure

Our phone system and SMS platforms, and our website, are hosted in Australia. Some of our other technology and service providers store or process information outside Australia, including Meta (WhatsApp), Microsoft (email and Teams) and Stripe (payments), which may process information in the United States and other countries. Where we disclose information overseas, we take reasonable steps to ensure it is protected consistently with the Australian Privacy Principles.

9. Data Storage and Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, including:

  • encrypted connections (TLS) for our website and services;
  • hosting our phone system, SMS platforms and website in secure data centres in Australia;
  • role-based access, so staff can only see what they need;
  • authentication and password protection; and
  • firewalls, network monitoring and fraud detection.

10. How Long We Keep Information

We keep personal information only for as long as we need it to provide our services, resolve disputes and meet our legal obligations. Some telecommunications records must be kept for a minimum period by law, and business records such as invoices are kept for tax purposes. When information is no longer needed, we securely delete it or de-identify it.

11. Data Breaches

A data breach happens when personal information we hold is accessed or disclosed without authorisation, or is lost in circumstances where that could happen.

If we suspect a data breach, we will:

  • take immediate steps to contain it and limit any harm;
  • assess it promptly, and within 30 days, to decide whether it is likely to result in serious harm to anyone affected;
  • if serious harm is likely, notify the people affected and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with the Notifiable Data Breaches scheme under the Privacy Act 1988; and
  • tell the people affected what happened, what information was involved, and what steps we recommend they take to protect themselves.

If it is not practicable to contact each person directly, we will publish a notice on our website.

Where we handle personal information on behalf of a business customer, such as messages and call data processed through 3CX or WhatsApp, we will also tell that customer promptly so they can meet their own obligations. We will also notify any other regulator where the law requires it.

If you think your personal information or your SipTel account may have been compromised, contact us straight away on 1300 399 747.

12. Marketing

We do not currently send marketing emails or messages. If we start, we will do so in line with the Spam Act 2003 (Cth), and every marketing message will include a way to unsubscribe. We will still send you messages about your account and services.

13. Access, Correction and Deletion

You can ask for a copy of the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. You can also ask us to delete it, subject to any legal, regulatory or contractual reasons we need to keep it. We will respond within 30 days. If we refuse a request, we will tell you why.

14. Dealing With Us Anonymously

You can ask general questions without identifying yourself. To provide telecommunications services, however, we need to know who you are.

15. Privacy Complaints

If you have a concern about how we have handled your personal information, please contact us using the details below. We will acknowledge your complaint within 2 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can contact:

  • the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au or 1300 363 992; or
  • the Telecommunications Industry Ombudsman (TIO): www.tio.com.au or 1800 062 058.

16. Changes to This Policy

We may update this policy from time to time. The current version is always published on this page with its effective date.

17. Contact Us

For privacy questions, requests or complaints, contact our Privacy Officer:

SipTel Pty Ltd

PO Box 5440, Minto NSW 2566

Phone: 1300 399 747

Email: info@siptel.net.au