PPS Privacy & Data Governance

Privacy Policy and Energy Data Handling

How PPS collects, uses, protects and manages personal information, electricity bills, interval data, website submissions and connected energy data.

Entity Practical Power Solutions Pty Ltd — ABN 68 694 093 591; ACN 694 093 591
Effective date 7 August 2026
Version 2.0

Privacy in practical terms

PPS uses customer information to understand a property’s energy position, prepare assessments and quotations, deliver and support energy systems, and meet legal and safety obligations. PPS does not sell personal information. Electricity bills and connected energy data are not used for unrelated advertising, and customers remain able to ask questions, correct information and request deletion where the law permits.

View policy contents

This document is written for publication on the PPS website. A short collection notice must also appear at the point where a visitor enters personal information or uploads a bill. Where a Consumer Data Right connection is offered, the separate CDR consent process and the applicable accredited provider’s CDR policy also apply.

Section 01

Scope of this policy

Practical Power Solutions Pty Ltd, trading as Practical Power Solutions (PPS, we, us or our), respects the privacy of customers, prospective customers, website visitors, authorised representatives, contractors and other people whose information we handle.

This policy applies to personal information handled through:

  • the PPS website, online forms, bill-upload facility, customer portal and energy-assessment tools
  • telephone, email, meetings, site inspections and referrals
  • quotations, system designs, contracts, finance, rebates, installation and commissioning
  • manufacturer monitoring platforms, technical support, warranty and after-sales services
  • any Consumer Data Right (CDR) connection or other consented energy-data service offered by PPS.

This policy explains our usual handling of personal information. A specific collection notice, contract, finance consent, CDR consent or manufacturer platform notice may give more detailed information for a particular service. Where a specific legal regime applies to particular data, that regime may impose additional or different requirements.

Section 02

Privacy framework and our commitment

PPS handles personal information in accordance with applicable Australian privacy, consumer, communications and data-protection laws. To the extent the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) apply, PPS complies with them. As a matter of policy, PPS applies the APP framework to all personal information it handles, even where an exemption might otherwise be available.

Where PPS offers a CDR service, CDR data is also governed by the Competition and Consumer Act 2010 (Cth), the CDR Rules, the privacy safeguards, the written arrangement with the accredited CDR principal and that principal’s CDR policy. This general policy does not replace the applicable CDR policy or consent dashboard.

Separate notice at collection

A privacy policy is not a substitute for telling people, at or before collection, what information is being collected, why, the usual disclosures, the consequences of not providing it and how to access the full policy. PPS therefore uses a short collection notice beside the bill-upload and assessment form.

Section 03

Who we are and how to contact us

Legal entity
Practical Power Solutions Pty Ltd
ABN / ACN
ABN 68 694 093 591 | ACN 694 093 591
Postal address
1B Seaview Avenue, Middleton SA 5213
Privacy contact
Privacy Officer — info@practicalpowersolutions.com.au
Recommended email subject
Privacy request, Privacy complaint or Data deletion request

A person may also request a copy of this policy in an accessible or alternative form by contacting the Privacy Officer.

Section 04

What personal information and energy data we collect

The information PPS collects depends on the person’s interaction with us and the service requested. It may include:

Identity, contact and authority information

  • name, preferred name, signature, email address, telephone number and postal address
  • property or installation address, billing address and business details
  • whether the person is an owner, tenant, account holder, joint account holder, authorised representative or business contact
  • records of identity or authority where reasonably required for a contract, access request, finance, rebate, account transfer or CDR process.

Electricity account, bill and usage information

  • electricity retailer, plan name, account number, National Metering Identifier (NMI), meter number and service-point details
  • billing periods, usage, exports, feed-in credits, tariffs, time-of-use periods, controlled loads, demand charges, discounts, supply charges, fees and GST
  • interval or smart-meter data, load shapes, seasonal patterns, maximum demand and electricity import/export timing
  • bill balances, payment status, concession or hardship indicators and other information appearing on a bill, although PPS does not seek unrelated financial or sensitive information.

Property, solar, battery and technical information

  • existing solar, battery, inverter, meter and electrical-system details
  • phase configuration, switchboard and backup requirements, roof or installation-space information, equipment photographs and site-inspection notes
  • serial numbers, commissioning records, firmware, system settings, monitoring data, alerts, faults, service history and warranty records
  • household or business energy requirements, including expected future loads such as an electric vehicle, electric hot water, heating or cooling.

Financial, transaction and service information

  • quotation selections, deposit and invoice status, payment references and transaction confirmations
  • finance enquiries, consent to refer to a finance provider and application status received from that provider
  • STC, rebate, VPP, retailer-plan and network-connection information relevant to the proposed service
  • customer-service records, complaints, feedback, consents, opt-outs and communications.

PPS does not ask customers to provide full payment-card credentials or online banking passwords through the energy-assessment form. Where a third-party payment or finance provider processes information, its own privacy policy and terms also apply.

Website, device and analytics information

  • internet protocol (IP) address, browser and device type, operating system, referring page and approximate location derived from technical data
  • pages viewed, buttons used, form progress, dates and times, errors and security events
  • cookie preferences, analytics identifiers and information generated by essential, functional or optional website technologies.

Derived or inferred information

PPS may create new information from supplied or connected data, such as an energy profile, reconstructed load estimate, tariff comparison, battery-sizing range, solar-recharge estimate, likely load-shifting capacity, projected savings, payback assumptions, system recommendation, suitability flag or data-quality note. These outputs may be personal information where they relate to an identifiable customer or property.

Sensitive or unnecessary information

PPS does not ordinarily need health information, government identity documents, tax file numbers, full bank or card details, religious or political information or other sensitive information for an energy assessment. An electricity bill may nevertheless contain concession, hardship or other personal details. Customers should redact unrelated information where practical. If PPS receives unsolicited information that is not reasonably necessary, it will take reasonable steps to delete or de-identify it where required and practical.

Section 05

Electricity bill uploads and energy-profile assessments

A visitor may be asked to upload one or more electricity bills, interval-data files, photographs or other documents so PPS can prepare a more accurate energy profile and assessment.

What PPS does with an uploaded bill

  1. Receives and securely stores the submitted file and the related form information.
  2. Extracts relevant fields such as account, tariff, billing period, charges, usage, exports and service-point information using manual review, optical character recognition, rules-based software or approved automated tools.
  3. Checks the extracted information for completeness, obvious inconsistencies and data-quality limitations.
  4. Uses the information to create a preliminary energy profile, tariff analysis, load estimate, battery or solar options, savings assumptions and quotation inputs.
  5. Retains or deletes the raw file and derived information in accordance with the retention section of this policy and any valid deletion request.

What the person uploading the file confirms

  • they are the account holder, an authorised joint account holder, an authorised representative or otherwise entitled to provide the information
  • they are requesting an assessment for the relevant property or business and have authority to do so
  • the file does not intentionally contain another person’s unrelated information, passwords, identity documents, full card details or material that is unlawful to disclose
  • the information is reasonably accurate and PPS may contact them to clarify missing or inconsistent details.

Never upload retailer login credentials

PPS does not ask a customer to provide a retailer password or online-account login through a bill-upload form. Where direct retailer data is available, PPS will use an authorised consent process such as the Consumer Data Right rather than asking for passwords or screen-scraping credentials.

PPS does not sell uploaded bills, use their contents for unrelated advertising or permit them to be used to train publicly available or general-purpose artificial-intelligence models. Any automated service used to process customer files must be approved for business use, subject to suitable privacy and security terms and limited to the purpose for which the information was collected.

Section 06

Consumer Data Right and connected retailer data

Where the website offers a “connect your retailer” or similar feature, PPS may provide that service through an accredited data recipient or under a formal CDR representative arrangement. The consent flow will identify the accredited provider, the categories of data requested, the purposes, the consent period, withdrawal options and the applicable CDR policy.

PPS will not seek or handle CDR data unless the required written arrangement, registration, consent process, dashboard, security, deletion and complaint controls are in place.

CDR data may include

  • customer and account information
  • electricity plan and tariff information
  • billing transactions, charges and invoices
  • service-point, premises, meter and distributed-energy-resource information
  • interval usage, import and export data for the period selected by the consumer.

CDR consent and control

  • Consent must be voluntary, express, informed, specific to purpose, time-limited and easy to withdraw.
  • The consumer actively selects the data types and uses. PPS does not rely on a pre-ticked box or a general website acceptance as CDR consent.
  • A CDR consent will not exceed the maximum period permitted by the CDR Rules, generally 12 months.
  • The consumer can view and manage the consent through the applicable dashboard and may withdraw it at any time.
  • Withdrawing consent stops future collection and use subject to the CDR Rules, required records and any deletion choice made through the dashboard.

PPS’s default position is not to use CDR data for unrelated direct marketing, sale, general research or disclosure to another party. Any permitted disclosure or marketing use would require a separate, valid consent and would be clearly explained before the consumer agrees.

Where Fiskil Pty Ltd is the accredited CDR provider, its name, accreditation details, CDR policy and consent dashboard will be shown in the live consent journey. If another accredited provider is used, that provider will be identified instead.

Section 07

How we collect information

PPS may collect information:

  • directly from the person through the website, upload form, customer portal, app, telephone, email, meeting, site inspection, contract, survey or support request
  • from an account holder, spouse, family member, business, landlord, tenant, authorised representative, referrer or professional adviser who is authorised to provide it
  • from an accredited CDR provider or electricity retailer after the consumer completes the applicable consent process
  • from installers, electricians, engineers, suppliers, manufacturers, monitoring platforms, network operators, metering providers, finance providers, STC or rebate agents and VPP providers involved in delivering or supporting a service
  • automatically through website logs, essential cookies, analytics, fraud-prevention and security technologies
  • from public registers or other lawful sources where reasonably necessary for verification, licensing, property or business purposes.

Where PPS collects personal information from someone other than the individual, PPS will take reasonable steps to ensure the individual is aware of the collection where required and appropriate.

Section 08

Why we collect, hold, use and disclose information

PPS may handle personal information for the following purposes:

  • responding to enquiries and verifying the identity or authority of the person requesting a service
  • receiving, reading and validating electricity bills, interval data and other assessment inputs
  • creating an energy profile and analysing consumption, tariffs, exports, controlled loads, seasonal patterns and load-shifting opportunities
  • modelling solar, battery, inverter, backup, retailer, Solar Sharer Offer and VPP options
  • preparing recommendations, savings estimates, quotations, proposals, contracts and customer communications
  • checking equipment, installer, STC, rebate, finance, network and program eligibility
  • arranging finance, payment, equipment supply, installation, commissioning, connection, certification and handover
  • creating or administering monitoring access, system settings, technical support, fault diagnosis, warranty and after-sales service
  • maintaining records, managing complaints, resolving disputes and exercising or defending legal rights
  • meeting electrical-safety, tax, consumer, licensing, insurance, CDR, privacy, communications and regulatory obligations
  • preventing fraud, spam, misuse, cyber incidents and unauthorised access
  • improving PPS services, calculators and operations using appropriately controlled data and, where practical, de-identified or aggregated information
  • sending service messages and, where permitted, marketing communications that the person can opt out of.

PPS will not use personal information for a materially unrelated purpose unless the individual has consented or the use is otherwise authorised or required by law.

Section 09

Automated extraction, profiling and recommendations

PPS may use software, algorithms, optical character recognition, data-matching, statistical methods and artificial-intelligence-assisted tools to extract information, identify patterns and create preliminary assessment outputs.

The kinds of personal information used may include contact and property details, bill data, interval usage, tariff information, existing system information, customer preferences and derived energy-profile information. The system may produce or assist with:

  • bill-field extraction and classification
  • load reconstruction, usage-pattern and tariff analysis
  • battery, inverter and solar sizing ranges
  • preliminary savings, bill-impact and payback estimates
  • data-quality warnings, missing-information requests and suitability flags
  • prioritisation of follow-up or referral for human review.

Automated outputs are estimates and decision-support tools. They may be affected by incomplete bills, meter changes, seasonal variation, tariff changes, unusual household behaviour, future equipment use and modelling assumptions. PPS does not make a final binding contract, credit, rebate-entitlement or installation-safety decision solely through an automated output. A person may ask PPS to explain or review the information and assumptions used in their assessment.

Accuracy and human review

Customers should review the assessment and tell PPS about errors or changed circumstances. A PPS representative should review material outputs before a final quotation, contract or design is issued.

Section 10

What happens if information is not provided

A person can browse most public website content without identifying themselves. However, PPS may be unable to provide a property-specific energy profile, accurate recommendation, quotation, finance referral, installation or support service without the relevant contact, property, bill, usage or technical information.

Providing information for marketing is optional and is not a condition of receiving an assessment. A person may choose not to use a CDR connection and instead provide a bill or other permitted information, although the available assessment detail may differ.

Section 11

Who we may disclose information to

PPS limits disclosure to what is reasonably necessary for the relevant purpose. Recipients may include:

  • authorised PPS personnel, contractors and professional advisers
  • licensed electricians, accredited installers, engineers, inspectors and other delivery contractors
  • equipment suppliers, distributors, manufacturers, monitoring-platform providers and warranty service providers
  • electricity retailers, network operators, metering providers, VPP providers and accredited CDR providers
  • Clean Energy Regulator processes, STC agents, rebate administrators and government or industry program operators
  • finance, payment, banking, insurance and debt-recovery providers where relevant and authorised
  • website, hosting, cloud-storage, email, customer-management, e-signature, analytics, cybersecurity, file-scanning, OCR and approved automated-processing providers
  • accountants, lawyers, auditors, insurers, regulators, courts, tribunals, law-enforcement and emergency services where required or permitted
  • a prospective purchaser, investor or successor under confidentiality protections in connection with a genuine business restructure or sale.

Service providers must only handle information for the agreed purpose and subject to appropriate confidentiality, privacy and security requirements. PPS does not sell or rent personal information or customer lists.

Section 12

Overseas storage and disclosure

PPS aims to keep core customer and energy-assessment records in Australia where practical. Some website, cloud, software, support and manufacturer-monitoring providers operate globally and may store, process or provide support access from outside Australia.

Depending on the service and equipment used, overseas recipients are likely to include providers or related entities in the United States and China, and may include other countries in which the relevant provider operates. For example, website infrastructure may involve United States processing, and some manufacturer monitoring and support may involve China. The collection notice, contract, service-provider register or third-party policy may give more specific information for a particular service.

Before disclosing personal information overseas, PPS will take reasonable steps appropriate to the circumstances to assess the provider, contract, security and data location. Where Australian privacy law makes PPS accountable for an overseas recipient, PPS will take reasonable steps to ensure the information is handled consistently with applicable requirements.

CDR data is handled under the applicable CDR policy and data-localisation arrangements. The live CDR consent flow will identify the accredited provider and relevant storage and disclosure information.

Section 13

Website cookies, analytics and tracking technologies

The PPS website may use:

  • essential cookies required for security, form operation, session management and website functionality
  • functional cookies that remember preferences
  • analytics technologies that help PPS understand page use, errors and conversion performance
  • optional marketing or embedded-content technologies where enabled and appropriately notified.

The site should provide a cookie or privacy choice mechanism where non-essential technologies are used. A visitor can also use browser controls to limit cookies, although some functionality may be affected.

PPS does not intentionally send electricity-bill contents, assessment answers, NMI, account numbers or derived energy profiles to advertising platforms. Tracking pixels or advertising scripts must not be configured to capture bill-upload fields, uploaded documents or customer-portal content.

Third-party websites, embedded services and social platforms have their own privacy practices. PPS is not responsible for information a person provides directly to those third parties.

Section 14

Direct marketing and service communications

PPS may send quotations, appointment information, installation updates, support messages, warranty notices and other service communications that are reasonably necessary for the customer relationship.

Marketing emails, SMS or other direct marketing will only be sent where permitted. Messages will identify PPS, provide accurate contact information and include a simple unsubscribe method. PPS will action an electronic unsubscribe request within the period required by the Spam Act, generally within five working days.

Withdrawing marketing consent does not prevent PPS from sending a necessary service, legal, safety, warranty or transaction message. PPS will not use CDR data for direct marketing unless a separate and valid CDR direct-marketing consent is obtained.

Section 15

How we hold and protect information

PPS takes reasonable steps appropriate to the nature, sensitivity, volume and risks of the information to protect it from misuse, interference, loss and unauthorised access, modification or disclosure.

Measures are designed to include, as appropriate:

Secure handling

secure transmission and storage, including encrypted connections

Strong identity controls

multi-factor authentication and strong credential controls for systems holding customer data

Restricted access

role-based access, least-privilege permissions and periodic access review

Data separation

separation of public website content from private customer files and assessment records

Security operations

malware scanning, logging, backups, patching and security monitoring

Provider review

contract and privacy due diligence for service providers

People and reporting

staff and contractor confidentiality, training and incident reporting requirements

Documented procedures

documented retention, deletion, breach-response and business-continuity procedures.

No electronic transmission or storage method is completely secure. PPS cannot guarantee absolute security, but it will continuously improve controls and respond to identified risks.

Section 16

Retention, deletion and de-identification

PPS retains personal information only for as long as reasonably required for the purpose for which it was collected, a permitted related purpose, warranty and support, record keeping, legal obligations, dispute resolution and security. The periods below are operational guides and may be adjusted where the circumstances or law require.

Typical PPS retention approach
Record category Typical retention approach
Initial enquiries and contact forms where no customer relationship follows Usually up to 24 months after the last meaningful contact.
Raw electricity bills, interval files and assessment uploads for a prospect Usually up to 12 months after the assessment or last meaningful contact, unless the file becomes part of an active customer record, is required for a dispute or legal obligation, or the individual asks for earlier deletion and no exception applies.
Derived energy profile, preliminary assessment and quotation records Usually up to 24 months after the last meaningful contact; longer where the individual becomes a customer or the record is needed to explain a recommendation.
Customer contracts, invoices, installation, certification, finance, STC/rebate and compliance records For the customer relationship and generally at least 7 years after completion or the end of the relationship, or longer where required by law, warranty, insurance or a dispute.
Equipment, serial number, commissioning, monitoring, fault and warranty-support records For as long as reasonably required to support the installed system and applicable warranty, then generally up to 7 years after the final service interaction or notification that PPS support is no longer required.
CDR service data Only for the period permitted by the consumer’s consent and the CDR Rules. Active consent will not exceed the permitted maximum (generally 12 months). Data is deleted or de-identified when required by the CDR principal or applicable CDR process. Required consent, audit and complaint records may be retained separately for statutory periods.
Marketing preferences and unsubscribe records Until consent is withdrawn or marketing is no longer undertaken. A minimal suppression record may be retained so the opt-out is respected.
Security logs and incident records Usually up to 24 months, and longer where required to investigate or respond to an incident.
De-identified or aggregated information May be retained for longer, including indefinitely, where it is no longer about an identifiable or reasonably identifiable individual.

When personal information is no longer required, PPS will take reasonable steps to delete it or de-identify it. Deletion may take time to flow through secure backups and third-party systems. PPS may retain a minimal record of a deletion request, consent withdrawal or unsubscribe so the request can be honoured and demonstrated.

Section 17

Access, correction, deletion and consent withdrawal

A person may contact the Privacy Officer to:

ask what personal information PPS holds about them
request access to a copy of that information
request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading
request deletion or de-identification where PPS is not required or permitted to retain the information
withdraw an optional consent, monitoring permission or marketing preference
ask for an explanation or human review of a material automated assessment output.

PPS may need to verify identity and authority before providing access, making a correction or deleting information. PPS aims to respond within 30 calendar days. Access may be refused or limited where the law permits, including where access would unreasonably affect another person’s privacy, reveal commercially sensitive evaluative material, prejudice legal proceedings or be unlawful. PPS will explain any refusal where required.

A correction request is free. PPS will not charge for making an access request and will only impose a reasonable access cost where permitted and notified in advance.

Withdrawal of optional monitoring or data access may limit remote support, optimisation, fault diagnosis, VPP participation or the ability to update an assessment. PPS will explain the practical consequence before acting where possible.

CDR consent is managed through the applicable CDR dashboard. A CDR consumer may withdraw consent at any time and choose available deletion options under the CDR process.

Section 18

Privacy complaints

A privacy complaint should be sent to the Privacy Officer at info@practicalpowersolutions.com.au or by mail to 1B Seaview Avenue, Middleton SA 5213. The complaint should describe the concern, relevant dates and the outcome requested.

PPS will:

  • acknowledge the complaint promptly, ordinarily within five business days
  • investigate the issue fairly and keep appropriate records
  • seek additional information where required
  • aim to provide a substantive response within 30 calendar days, or explain any reasonable delay
  • identify corrective action, process improvements or remedies where appropriate.

If the person is not satisfied after giving PPS a reasonable opportunity to respond, they may complain to the Office of the Australian Information Commissioner (OAIC). A CDR complaint may also be handled under the accredited CDR provider’s internal dispute process and, where applicable, an external dispute-resolution scheme such as the Australian Financial Complaints Authority. The live CDR policy and consent journey will provide the applicable details.

OAIC privacy complaint information: www.oaic.gov.au/privacy/privacy-complaints

Section 19

Data breaches

PPS maintains a process to identify, contain, assess, remediate and review suspected data breaches. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, PPS will notify affected individuals and the OAIC as required. CDR incidents will also be escalated to the accredited CDR principal and handled under the applicable CDR and breach-response requirements.

Section 20

Anonymity, pseudonymity, children and authorised representatives

Anonymity and pseudonymity

A person may browse public website information without identifying themselves. PPS will allow anonymous or pseudonymous interaction where lawful and practical. A property-specific assessment, quotation, contract, finance process, installation, warranty service or CDR connection will generally require accurate identity, authority, property and account information.

Children

PPS energy-assessment and installation services are intended for adults and authorised business representatives. PPS does not knowingly collect personal information directly from children for these services. A parent, guardian or authorised adult should contact PPS if information about a child has been submitted inadvertently.

Joint accounts and representatives

A person providing another individual’s bill or account information must have appropriate authority. PPS may ask for evidence of that authority. Joint-account CDR data is subject to the data holder’s joint-account rules and the applicable consent process.

Section 21

Changes to this policy

PPS may update this policy when services, technology, providers, law or data practices change. The current version will be published on the PPS website with its effective date. PPS will provide additional notice where a material change significantly affects how existing customer information is handled.

PPS reviews this policy at least annually and before introducing a material new data source, automated assessment function, tracking technology, overseas provider or CDR arrangement.

Section 22

Privacy contact

Privacy Officer — Practical Power Solutions Pty Ltd

Email: info@practicalpowersolutions.com.au

Mail: 1B Seaview Avenue, Middleton SA 5213

Effective date: 7 August 2026

Version: 2.0 — Website, energy-data and bill-upload edition

Contact the Privacy Officer →