1. About this policy
This CDR Policy is published by Allwis Pty Ltd (ABN 14 689 039 343) ("Allwis", "we", "us", "our") in accordance with Privacy Safeguard 1 and CDR Rule 7.2 of Australia's Consumer Data Right (CDR) regime, administered by the Australian Competition and Consumer Commission (ACCC) under Part IVD of the Competition and Consumer Act 2010 (Cth).
Allwis intends to act as a CDR Representative of an ACCC-accredited Data Recipient (our "Principal"), rather than as an Accredited Data Recipient in our own right. This means our Principal collects CDR data from data holders (such as your bank) on our behalf, under consents you give us, and discloses that data to us so we can provide you with the service you've asked for. Our Principal's own CDR policy also applies to CDR data handled under this arrangement, and we will link to it here once our Principal is confirmed.
This policy applies to CDR data handled through the Allwis platform. It does not cover other personal information Allwis collects about you as a general customer of our business software — that is covered by our Privacy Policy.
2. The CDR service we provide
Once available, Allwis's CDR-powered feature lets a business customer connect their bank account(s) to Allwis so that account and transaction data can be imported automatically. We use that data to power:
- Automated bank reconciliation against the customer's invoices, bills, and recorded payments;
- AI-assisted transaction categorisation and general ledger account suggestions; and
- Cash-flow and balance reporting within the customer's own Allwis account.
3. Kinds of CDR data we collect and hold
Subject to your consent, we collect and hold the following categories of banking CDR data:
- Account data — account name, type, and balance;
- Transaction data — transaction amount, date, and description.
We only collect the specific data you consent to, for the specific purpose you consent to, consistent with the Data Minimisation Principle under the CDR Rules.
4. How we collect and hold CDR data
CDR data is collected by our Principal from your bank (as a CDR data holder) once you give a valid consent, and disclosed to us as "Service Data" under our CDR Representative arrangement. We do not collect CDR data directly from data holders ourselves.
CDR data is stored in our production database, hosted in Australia (AWS ap-southeast-2, Sydney), and is protected by encryption at rest and in transit, and strict per-customer access controls. Full detail of our security practices is set out in our Information Security Policy, available on request.
5. Purposes of collection, use, and disclosure
We collect, hold, use, and disclose your CDR data only:
- to provide the specific service you've consented to (reconciliation, categorisation, and reporting);
- to comply with our obligations under the CDR Regime, including record-keeping and reporting to our Principal; and
- where otherwise required or authorised by law.
We do not use or disclose your CDR data for marketing, and we do not sell your CDR data or any insights derived from it.
6. Disclosure to outsourced service providers
We disclose limited CDR data (or data derived from it) to the following outsourced service providers, solely to operate the service described above:
- Supabase (database hosting) — stores CDR data in Australia (AWS ap-southeast-2, Sydney);
- Anthropic, PBC (United States) — receives only a transaction's description and amount, for transient AI-assisted categorisation. This data is not retained by Anthropic for model training.
Overseas disclosure. Anthropic, PBC is located in the United States. No other overseas disclosure of CDR data is currently made. If this changes, we will update this policy to name the relevant countries.
7. Accessing and correcting your CDR data
You can access the CDR data we hold about you at any time within your Allwis account. If you believe any CDR data we hold is inaccurate, out of date, incomplete, irrelevant, or misleading, you can ask us to correct it by emailing privacy@allwis.ai. We will respond within a reasonable time, ordinarily within 30 days, at no charge.
8. Withdrawing consent and deleting data
You can withdraw your consent for us to collect or use your CDR data at any time from within your Allwis account, or by emailing privacy@allwis.ai. Once consent is withdrawn or expires, we will delete or de-identify your CDR data as soon as practicable, in accordance with CDR Rule 1.18 and Privacy Safeguard 12, unless we are required to retain it under Australian law or because it relates to current or anticipated legal proceedings.
9. Complaints
If you think we have mishandled your CDR data or breached the CDR Rules, contact our Privacy Officer at privacy@allwis.ai. We will acknowledge your complaint and aim to resolve it within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992, or to the Australian Financial Complaints Authority (AFCA) where applicable, or to the ACCC.
10. Contact us
Allwis Pty Ltd (ABN 14 689 039 343)
Privacy Officer — privacy@allwis.ai
This CDR Policy is free to access and will be reviewed and updated as our CDR Representative arrangement progresses. Last updated 27 July 2026.