Trust & privacy

CDR Privacy Policy

This page explains how AI2Fin (2Fin) handles data received under Australia's Consumer Data Right (CDR) — your banking accounts, balances and transaction history, shared only with your explicit consent. It supplements the main Privacy Policy, which covers everything else (your email, name and preferences).

Status: AI2Fin is finalising its CDR Representative arrangement with an ACCC-accredited data recipient. Direct bank connections launch once that accreditation process completes; this policy describes how your CDR data is handled from the moment you connect. Until then, the same standards below already govern transaction data you import yourself.

What Fin receives — and what it never does

When you connect a bank, Fin receives only what you authorise: the accounts you select (name, type, BSB, account number, balance), their transaction history for the period you approve, and updates for as long as your consent lasts.

Fin never receives your bank login credentials — consent happens through the accredited provider's flow, directly with your bank. Accounts you don't authorise are never visible, and connections are read-only by design.

Why, and how it's protected

CDR data is used solely to power your features: categorising transactions, detecting recurring bills, estimating tax deductions, budgeting insights and ATO export files. Processing is purpose-bound — never marketing, never profiling for sale, never training models offered to other customers on identifiable data.

  • Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM), with field-level encryption on sensitive values.
  • Hosted in Sydney, Australia — CDR data does not leave Australia in the primary data path.
  • If you enable intelligent categorisation, transaction descriptions may be sent to a model provider with identifying details stripped; you can turn this off any time in Settings → Intelligent Features.
  • Error and analytics tooling never receives raw CDR data; banking screens are excluded from session replay.
  • Every access to CDR data is audit-logged, with logs retained for 7 years — exceeding the CDR 6-year minimum (Rule 9.3(5)).

How long data is kept

DataRetention
Active CDR data while your consent is in effectLife of consent (default 12 months from grant; extendable only with your explicit re-consent)
CDR data after you withdraw consentDeleted or de-identified within 90 days
Audit logs of CDR data access7 years (internal policy; the CDR minimum under Rule 9.3(5) is 6 years)
Backups containing CDR dataUp to 30 days rolling; deletion propagates

Your rights, always one click away

View

See what CDR data is held about you (Settings → Data → Download Export).

Withdraw consent

Disconnect your bank in one click (Settings → Privacy → Disconnect Bank) — effective immediately.

Request deletion

Have stored CDR data deleted (Settings → Privacy → Delete CDR Data) — completed within 90 days.

Correct

Fix inaccurate information via Settings → Profile or support.

Complain

Raise a concern without any penalty to your service — see the complaints section below.

Questions or complaints

  1. Contact Fin's team first: [email protected] — you'll hear back within 5 business days.
  2. If unresolved, escalate to the accredited provider named in your consent flow.
  3. You can always contact the Office of the Australian Information Commissioner (1300 363 992) or the ACCC.

Raising a concern never affects your service. If a data breach likely to cause serious harm ever involves your CDR data, you and the OAIC will be notified promptly with what happened, what it means and what's being done.

Contact

Privacy: [email protected] · Security: [email protected] · Support: [email protected]

This policy is updated when CDR rules, subprocessors or data flows change — with email notice at least 14 days before material changes. Current version: 1.0 (July 2026). The latest version always lives at ai2fin.com/privacy/cdr.