Privacy Policy
The IT Dept Pty Ltd, trading as Underlay Networks. ABN 12 665 405 505
What this policy covers
This policy explains how Underlay handles personal information in its wholesale and direct-business network, voice and engineering services and on this website. We deal with business customers and their authorised users, staff and contractors of MSPs, ISPs, service providers, suppliers and data-centre operators. We also receive some information relating to end-customer connections because that is necessary to aggregate and operate telecommunications services.
Information we collect
We may collect business contact details, account and billing information, authorised-user details, support conversations, service addresses, connection identifiers, technical logs, IP addressing and routing information, network telemetry, equipment details, call records, voicemail and call recordings for voice services, and records needed to order or support a service.
For nbn and other access services, an order can include information associated with the service location or end customer. We receive that information because we are part of the delivery chain. It does not turn the end customer into a sales lead for us or for our related retail business, Warp.
We collect information from you or your authorised representatives, from providers ordering services for their customers, from suppliers involved in delivery, and from operating and supporting the network. We hold it in our service platforms and business records with access limited according to role. You can make a general enquiry anonymously where practical, but identifying and service information may be necessary to supply a service, check authority, bill or investigate an account-specific issue.
Why we use it
We use information to quote, provision, operate, monitor, secure, support and bill services; communicate with our customers and authorised contacts; maintain network and business records; prevent abuse and fraud; meet legal and regulatory obligations; and improve the operation of the services we supply. We also handle information needed to assess payment assistance, respond to complaints and arrange safe customer contact. We seek only information relevant to that purpose and restrict access to sensitive support records.
We do not use end-customer connection information obtained through a wholesale relationship to market to or solicit that end customer, including for Warp (warp.net.au), our related retail business, which runs on the Underlay network.
Who we disclose information to
We disclose information where reasonably necessary to deliver or support a service, including to access-network operators, carriers, data-centre operators, cross-connect providers, payment and business-system providers, professional advisers and authorities where disclosure is required or authorised by law.
We aim to disclose only what the recipient needs for the relevant purpose. Suppliers that process information for us are expected to handle it appropriately for their role.
Where information is held
Our service and business data is held in Australia. We do not currently arrange overseas storage or routine overseas disclosure of personal information to our service and business-system suppliers. International calls and internet traffic can pass through overseas networks to reach their destination; that carriage is different from the location of our stored customer records. We review supplier arrangements when they change and update this policy if overseas disclosures become likely, including the countries where practicable.
Network and service logs
Operating a network produces logs and telemetry. These can include source and destination addresses, session metadata, device identifiers, routing events, test results and timestamps. We use operational data for network management, security, troubleshooting, capacity planning, billing where relevant and legal obligations. We do not describe this metadata as anonymous when it can reasonably be connected to a person or service. For voice services, call records (numbers, times and durations) are used to operate, support and bill the service and to meet legal retention obligations. Voicemail and recordings are kept only as the service is configured.
Website information
Our website may receive ordinary server logs such as IP address, browser information, requested pages and timestamps. The public website does not currently embed third-party analytics or advertising trackers. Its fonts are served from our website. Following an external link takes you to a separate service with its own privacy practices.
Security
We use technical and organisational controls appropriate to a network operator, including access control, authentication, logging and limiting access to people who need information for their work. No system is immune from failure, so we also maintain processes for investigating and responding to security incidents.
Retention
We keep information for as long as it is reasonably needed for the service, support, billing, security, dispute, accounting or legal purpose for which it is held. Different records have different useful and legally required retention periods. We remove or de-identify information when it is no longer reasonably required, subject to lawful retention obligations and backup cycles.
Access and correction
If you want access to personal information Underlay holds about you, or believe it is wrong, contact us. We may need to verify your identity and may be unable to provide material where an exception under applicable law applies. We will explain a refusal where required.
Privacy questions and complaints
Contact hello@underlay.au, call 02 4398 7080, or write to Privacy, Underlay Networks, The IT Dept Pty Ltd, 40 Woolana Ave, Budgewoi NSW 2262. Tell us what happened and what outcome you seek. We acknowledge, investigate and respond using our Complaints Policy; we aim to respond to a privacy complaint within 30 days, with any shorter applicable telecommunications complaint deadline preserved.
If you are dissatisfied with our response or have not received one within 30 days, you can complain to the Office of the Australian Information Commissioner. The OAIC can explain eligibility and whether an approved external dispute-resolution scheme, such as the TIO for eligible telecommunications complaints, should consider the issue first. OAIC enquiries: 1300 363 992.
Changes
We may update this policy as our systems, suppliers or legal obligations change. The current version published on underlay.au applies from its stated publication date.
Last updated 1 October 2026 · Version 2026-10-01.1