Trust & privacy
CDR Privacy Policy
This page explains how AI2Fin (2Fin) handles data received under Australia's Consumer Data Right (CDR) — your banking accounts, balances and transaction history, shared only with your explicit consent. It supplements the main Privacy Policy, which covers everything else (your email, name and preferences).
Where this applies: this covers the bank connections Fin makes for you in Australia, which run on the Consumer Data Right. Open banking works differently in other markets — India uses the Account Aggregator framework, for example — and each is governed by its own regulator and provider, named in your consent flow before any data is shared. Everything else is covered by the main Privacy Policy.
Status: In Australia, bank connections will run on Consumer Data Right (CDR). AI2Fin is finalising a CDR Representative arrangement with Fiskil Pty Ltd as its CDR Representative Principal and accredited data recipient, accredited by the ACCC. Once that arrangement is in force, AI2Fin adopts and operates under Fiskil Pty Ltd's applicable CDR policy and retention requirements. Direct bank connections launch when it completes. This policy describes how your CDR data is handled from the moment you connect. Until then, the same standards below already govern transaction data you import yourself.
What Fin receives — and what it never does
When you connect a bank, Fin receives only what you authorise: the accounts you select (name, type, BSB, account number, balance), their transaction history for the period you approve, and updates for as long as your consent lasts.
Fin never receives your bank login credentials — consent happens through the accredited provider's flow, directly with your bank. Accounts you don't authorise are never visible, and connections are read-only by design.
Why, and how it's protected
CDR data is used solely to power your features: categorising transactions, detecting recurring bills, estimating tax deductions, budgeting insights and ATO export files. Processing is purpose-bound — never marketing, never profiling for sale, never training models offered to other customers on identifiable data.
- Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM), with field-level encryption on sensitive values.
- Hosted in Sydney, Australia — CDR data does not leave Australia in the primary data path.
- If you enable intelligent categorisation, transaction descriptions may be sent to a model provider with identifying details stripped; you can turn this off any time in Settings → Intelligent Features.
- Error and analytics tooling never receives raw CDR data; banking screens are excluded from session replay.
- Every access to CDR data is audit-logged, with logs retained for 7 years — exceeding the CDR 6-year minimum (Rule 9.3(5)).
How long data is kept
| Data | Retention |
|---|---|
| Active CDR data while your consent is in effect | Life of consent (default 12 months from grant; extendable only with your explicit re-consent) |
| CDR data after you withdraw consent | Deleted as soon as your consent is withdrawn, revoked or expires |
| Audit logs of CDR data access | 7 years (internal policy; the CDR minimum under Rule 9.3(5) is 6 years) |
| CDR data held in backups | The same rule as above — no separate retention window |
Your rights, always one click away
View
See what CDR data is held about you (Settings → Data → Download Export).
Withdraw consent
Disconnect your bank in one click (Settings → Privacy → Disconnect Bank) — effective immediately.
Request deletion
Have stored CDR data deleted (Settings → Privacy → Delete CDR Data) — actioned promptly, and no later than the deletion timing your consent requires.
Correct
Fix inaccurate information via Settings → Profile or support.
Complain
Raise a concern without any penalty to your service — see the complaints section below.
Questions or complaints
- Contact Fin's team first: privacy@ai2fin.com — you'll hear back within 5 business days.
- If unresolved, escalate to the accredited provider named in your consent flow.
- You can always contact the Office of the Australian Information Commissioner (1300 363 992) or the ACCC.
Raising a concern never affects your service. If a data breach likely to cause serious harm ever involves your CDR data, you and the OAIC will be notified promptly with what happened, what it means and what's being done.
Contact
Privacy: privacy@ai2fin.com · Security: security@ai2fin.com · Support: hi@ai2fin.com
This policy is updated when CDR rules, subprocessors or data flows change — with email notice at least 14 days before material changes. Current version: 1.0 (July 2026). The latest version always lives at ai2fin.com/privacy/cdr.