Trust & privacy
CDR Privacy Policy
This page explains how AI2Fin (2Fin) handles data received under Australia's Consumer Data Right (CDR) — your banking accounts, balances and transaction history, shared only with your explicit consent. It supplements the main Privacy Policy, which covers everything else (your email, name and preferences).
Status: AI2Fin is finalising its CDR Representative arrangement with an ACCC-accredited data recipient. Direct bank connections launch once that accreditation process completes; this policy describes how your CDR data is handled from the moment you connect. Until then, the same standards below already govern transaction data you import yourself.
What Fin receives — and what it never does
When you connect a bank, Fin receives only what you authorise: the accounts you select (name, type, BSB, account number, balance), their transaction history for the period you approve, and updates for as long as your consent lasts.
Fin never receives your bank login credentials — consent happens through the accredited provider's flow, directly with your bank. Accounts you don't authorise are never visible, and connections are read-only by design.
Why, and how it's protected
CDR data is used solely to power your features: categorising transactions, detecting recurring bills, estimating tax deductions, budgeting insights and ATO export files. Processing is purpose-bound — never marketing, never profiling for sale, never training models offered to other customers on identifiable data.
- Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM), with field-level encryption on sensitive values.
- Hosted in Sydney, Australia — CDR data does not leave Australia in the primary data path.
- If you enable intelligent categorisation, transaction descriptions may be sent to a model provider with identifying details stripped; you can turn this off any time in Settings → Intelligent Features.
- Error and analytics tooling never receives raw CDR data; banking screens are excluded from session replay.
- Every access to CDR data is audit-logged, with logs retained for 7 years — exceeding the CDR 6-year minimum (Rule 9.3(5)).
How long data is kept
| Data | Retention |
|---|---|
| Active CDR data while your consent is in effect | Life of consent (default 12 months from grant; extendable only with your explicit re-consent) |
| CDR data after you withdraw consent | Deleted or de-identified within 90 days |
| Audit logs of CDR data access | 7 years (internal policy; the CDR minimum under Rule 9.3(5) is 6 years) |
| Backups containing CDR data | Up to 30 days rolling; deletion propagates |
Your rights, always one click away
View
See what CDR data is held about you (Settings → Data → Download Export).
Withdraw consent
Disconnect your bank in one click (Settings → Privacy → Disconnect Bank) — effective immediately.
Request deletion
Have stored CDR data deleted (Settings → Privacy → Delete CDR Data) — completed within 90 days.
Correct
Fix inaccurate information via Settings → Profile or support.
Complain
Raise a concern without any penalty to your service — see the complaints section below.
Questions or complaints
- Contact Fin's team first: [email protected] — you'll hear back within 5 business days.
- If unresolved, escalate to the accredited provider named in your consent flow.
- You can always contact the Office of the Australian Information Commissioner (1300 363 992) or the ACCC.
Raising a concern never affects your service. If a data breach likely to cause serious harm ever involves your CDR data, you and the OAIC will be notified promptly with what happened, what it means and what's being done.
Contact
Privacy: [email protected] · Security: [email protected] · Support: [email protected]
This policy is updated when CDR rules, subprocessors or data flows change — with email notice at least 14 days before material changes. Current version: 1.0 (July 2026). The latest version always lives at ai2fin.com/privacy/cdr.