Trust & privacy
CDR Privacy Policy
This page explains how AI2Fin (2Fin) handles data received under Australia's Consumer Data Right (CDR) — your banking accounts, balances and transaction history, shared only with your explicit consent. It supplements the main Privacy Policy, which covers everything else (your email, name and preferences).
Where this applies: this covers the bank connections Fin makes for you in Australia, which run on the Consumer Data Right. Open banking works differently in other markets — India uses the Account Aggregator framework, for example — and each is governed by its own regulator and provider, named in your consent flow before any data is shared. Everything else is covered by the main Privacy Policy.
Status: In Australia, bank connections will run on Consumer Data Right (CDR). AI2Fin is finalising its arrangement with a provider regulated by the ACCC; the provider is named in your consent flow before any data is shared. This policy describes how your CDR data is handled from the moment you connect. Today, you can bring your own connection through Fin's open connectors, or import transaction data yourself. Those flows are not CDR data, but Fin holds them to the same standards set out on this page.
What Fin receives — and what it never does
When you connect a bank, Fin receives only what you authorise: the accounts you select (name, type, BSB, account number, balance), their transaction history for the period you approve, and updates for as long as your consent lasts.
Fin never receives your bank login credentials — consent happens through the accredited provider's flow, directly with your bank. Accounts you don't authorise are never visible, and connections are read-only by design.
Why, and how it's protected
CDR data is used solely to power your features: categorising transactions, detecting recurring bills, estimating tax deductions, budgeting insights and ATO export files. Processing is purpose-bound — never marketing, never profiling for sale, never training models offered to other customers on identifiable data.
- Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM), with field-level encryption on sensitive values.
- Hosted in Sydney, Australia — CDR data does not leave Australia in the primary data path.
- Intelligent categorisation is on by default: your transactions are analysed in Australia, with no name, email or account number attached — the description and merchant are sent so the category can be worked out. You can switch it off at any time — account menu → Privacy Settings → AI-powered insights — and nothing further is analysed automatically. Features you trigger yourself, like asking Fin to categorise something on the spot, still run when you use them.
- Error and analytics tooling never receives raw CDR data. Banking screens are excluded from product-analytics session replay entirely; the separate error-diagnostic recording keeps all text masked.
- Every access to CDR data is audit-logged, with logs retained for 7 years — exceeding the CDR 6-year minimum (Rule 9.3(5)).
How long data is kept
| Data | Retention |
|---|---|
| Active CDR data while your consent is in effect | Life of consent (default 12 months from grant; extendable only with your explicit re-consent) |
| CDR data after you withdraw consent | Deleted from active systems as soon as your consent is withdrawn, revoked or expires — see the backups row below for what that means for immutable snapshots |
| Audit logs of CDR data access | 7 years (internal policy; the CDR minimum under Rule 9.3(5) is 6 years) |
| CDR data held in backups | Not a second retention window — deletion from active systems still happens immediately (row above). Backups are immutable snapshots, so a copy of an already-deleted record can remain on backup media until that snapshot expires, within 35 days. Backups are never queried to retrieve deleted data, and a restore re-applies recorded deletions before service resumes |
Your rights, and how to use them
View
Download everything held about you — account menu → Privacy Settings → Export data.
Withdraw consent
On the Connectors page, choose the bank connection you want to disconnect. Confirm once, then sharing stops immediately.
Request deletion
Account menu → Privacy Settings → Delete data… Choose what to remove, then type your email address to confirm — actioned promptly, and no later than the deletion timing your consent requires.
Correct
Edit the record in place, or email support and Fin will correct it for you.
Complain
Raise a concern without any penalty to your service — see the complaints section below.
Questions or complaints
- Contact Fin's team first: [email protected] — you'll hear back within 5 business days.
- If unresolved, escalate to the accredited provider named in your consent flow.
- You can always contact the Office of the Australian Information Commissioner (1300 363 992) or the ACCC.
Raising a concern never affects your service. If a data breach likely to cause serious harm ever involves your CDR data, you and the OAIC will be notified promptly with what happened, what it means and what's being done.
Contact
Privacy: [email protected] · Security: [email protected] · Support: [email protected]
This policy is updated when CDR rules, subprocessors or data flows change — with email notice at least 14 days before material changes. Current version: 1.0 (July 2026). The latest version always lives at ai2fin.com/privacy/cdr.