Skip to content
Kingdom
Finance

Consumer Data Right (CDR) policy

The Consumer Data Right is the Australian regime that gives you the right to tell your bank to share your own data with whoever you choose. This policy explains what we do with that data, and what you can require of us at any time.

Updated 25 August 2026.

1. The authority we operate under

Banking data reaches us through Fiskil, a CDR gateway accredited by the ACCC as an Accredited Data Recipient. Kingdom Finance ([legal entity name not yet set — see SUBMISSION.md], ABN [ABN not yet set]) receives the data under Fiskil's arrangement and is bound by the same handling, retention and deletion obligations set out in the Competition and Consumer (Consumer Data Right) Rules 2020.

That is not an administrative detail: it means your bank will only release data to an authorised participant, that the authorisation is auditable, and that you have a formal complaints path — set out at the end of this page.

2. What we ask for, and why

We ask for the minimum the dashboard needs. Each kind of data below exists because a specific screen depends on it; nothing is collected for resale, profiling or advertising.

  • Identification and details of the accounts you choose to share — to list them and to split them between personal and business.
  • Balances and limits — for net worth, the emergency fund and debt tracking.
  • Transaction history — for cash flow, categorisation and the Kingdom allocation.
  • Merchant name and category code, when the bank sends them, plus the transaction's own date, amount and description — matched first against your household's own rules and, for whatever those do not recognise, offered to Amazon Bedrock for a suggestion from your household's own list of categories — so a category is waiting for you to confirm or correct when you review the transaction, rather than a blank you have to fill in yourself. If you press “Categorize with AI” on the Cash Flow screen, the same descriptor may also be sent to Tavily, a web search provider, as a search query — see section 7.

3. What sharing never allows

Access is read-only. No payment, transfer, withdrawal or change to your accounts is possible with what you authorise here — the CDR does not grant that power and we do not ask for it.

Your internet banking password is typed on your own bank's site during authorisation, never in this application and never at the gateway. We do not see it, do not receive it, and would have nowhere to keep it.

4. How long a consent lasts

A CDR consent lasts at most twelve months, and you choose the duration within that when you authorise. When it expires the bank simply stops sending data — there is no automatic renewal, by design of the regime.

The dashboard warns you when a consent is nearing its end, while the connection still works, so you can decide to renew before the numbers go stale. Renewing means granting a new authorisation at your bank; the old one cannot be extended.

5. How to stop sharing

On the Accounts screen, every connected bank carries a “Stop sharing” action. It takes effect immediately and is passed on to your bank: no new data arrives from that moment.

You can also stop it from your own bank's data sharing dashboard, without coming here at all. Either way the result is the same, and this dashboard then shows the connection as ended.

6. What happens to data already received

Stopping the sharing halts new data; it does not by itself erase what has already been imported, because your history is what the dashboard is built on and deleting it unasked would destroy your own record.

When you do want it gone, use “Delete banking data” in Settings, or write to contact@kingdomfinance.app. Accounts and transactions received through the CDR are then deleted or irreversibly de-identified, and the same request is passed to the gateway.

If you delete your Kingdom Finance account, all of this happens automatically, with nothing to ask for separately.

7. Who the data is shared with

With the people you yourself invite into your household in the app, in the roles you give them — and with nobody else.

We do not sell, rent or trade CDR data, use it for advertising or credit scoring, or hand it to any provider for a purpose of their own. The one processing beyond our own instructions: a transaction your household's own rules do not recognise may be sent to Amazon Bedrock — under this product's own AWS account, not a separate company — for a category suggestion drawn only from your household's own list; see our Privacy Policy, section 5, for exactly what that involves. It is never used to train a model, Amazon's or anyone else's. If you press "Categorize with AI" yourself, a second, genuine third party is reached: Tavily, a web search provider, and only ever with a search query built from that one transaction's own description — never an account number, a balance, or anything else this product holds. That same button is also the only place a category your household does not have yet may be proposed, drawn from nothing but the transaction in front of it; a proposal is written to your category list exactly as one you added by hand would be, yours to rename or remove at any time. Tavily is never given anything to train a model on either.

8. Where the data lives, and how it is protected

CDR data is stored in the Australian region of our cloud infrastructure, encrypted in transit and at rest, with access limited to what each part of the system needs to run. The one exception to where it is processed is the category suggestion described in section 7: that single request to Amazon Bedrock may be answered from anywhere inside its Asia-Pacific region — Sydney, Tokyo, Seoul, Osaka, Mumbai or Singapore — never outside it, and never stored there; only the category it returns is written back to your ledger, which stays in ap-southeast-2. A search "Categorize with AI" runs is a second exception: Tavily is not asked to store anything, and this product does not control where it answers from the way it controls where Bedrock is asked to.

Each household sees only its own records: the separation is enforced by the server on every read and every write, not by the interface.

9. Your rights

At any time you may: see which consents are active and when they expire; end any of them; request a copy of the data we hold about you; request correction of anything wrong; and request deletion or de-identification of CDR data.

None of these requests costs anything, and none of them depends on your explaining why.

Complaints

If something about the handling of your CDR data is not right, we want to know — and you have a formal path that does not depend on our goodwill.

  1. Write to contact@kingdomfinance.app describing what happened. We acknowledge receipt within 7 days.
  2. We investigate and reply in writing within 30 days, saying what we found and what we will do about it.
  3. If that reply does not resolve it, you can take the complaint to the CDR gateway acting as the Accredited Data Recipient, whose channel we name in our reply.

At any time, and without exhausting the steps above, you may complain directly to the Office of the Australian Information Commissioner (OAIC), the CDR's privacy regulator, at oaic.gov.au — or to the Australian Financial Complaints Authority (AFCA), at afca.org.au, through [to be confirmed once the CDR Representative arrangement is signed]'s AFCA membership.