CDR Policy
How we handle your data under Australia's Consumer Data Right (CDR) when you connect a bank account to ReconLink — what we collect, why, how you consent and withdraw, and how we delete or de-identify it.
Effective 23 July 2026 · Innovious Group Pty Ltd · ABN 59 637 038 754
Innovious Group Pty Ltd (ABN 59 637 038 754) (“ReconLink”, “we”, “us”, “our”) operates a bank reconciliation and bookkeeping platform for Australian accounting practices. This CDR Policy explains how we handle data shared with us under the Consumer Data Right when you connect a bank account to the ReconLink automated bank feed. It sits alongside our Privacy Policy, which governs personal information more broadly.
We access CDR data through Fiskil Pty Ltd, an Accredited Data Recipient (ADRBNK000246) under the CDR regime, which operates the consent flow and connects to your bank on our behalf. You will see Fiskil and the Consumer Data Right branding on the consent screen when you connect. Fiskil’s own handling of CDR data as the Accredited Data Recipient is set out in its CDR Policy.
1What CDR data we collect
With your express consent, we collect the following CDR data for the bank accounts you choose to connect:
- Account details (account name, type and identifiers);
- Account balances;
- Transactions (dates, amounts, descriptions and counterparties).
We request only the data necessary to provide the bookkeeping Service and, consistent with the CDR data-minimisation principle, no more.
2Why we collect it and how we use it
We use your CDR data solely to provide the bookkeeping and reconciliation services you or your accounting practice have engaged us for, including:
- Importing and categorising your bank transactions;
- Reconciling your accounts;
- Preparing BAS, profit-and-loss and cash-flow reports.
We do not sell your CDR data, use it for marketing, or use it for any purpose beyond the services described above. We do not use CDR data for any direct-marketing purpose.
3Your consent
Sharing under the CDR is always based on your consent, which is:
- Voluntary — you choose whether to connect a bank feed;
- Express — given through Fiskil’s consent screen;
- Informed — the consent screen tells you what data is shared and why before you agree;
- Specific — limited to the bookkeeping purpose above; and
- Time-limited — typically up to 12 months, after which you are asked to re-consent to continue the feed.
4Who we disclose CDR data to
We disclose CDR data only as necessary to provide the Service:
- Fiskil Pty Ltd (Accredited Data Recipient) — retrieves the data from your bank and passes it to us under your consent;
- Your accounting practice — the practice you have engaged, which uses the data to perform your bookkeeping;
- Infrastructure providers — our hosting and database providers, engaged under contracts requiring them to protect the data. Our primary database is hosted in AWS Sydney (ap-southeast-2) for Australian data residency.
We do not sell, rent or trade CDR data, and we do not disclose it to any other third party except where required or authorised by law.
5Managing and withdrawing your consent
5.1How to withdraw
You can withdraw your consent at any time:
- from within ReconLink (Client → Bank feeds → Disconnect);
- by asking your accounting practice; or
- by emailing info@reconlink.com.au.
5.2What happens when you withdraw
When you withdraw your consent (or it expires), we stop collecting your bank data immediately and instruct Fiskil to revoke the CDR consent arrangement. Your existing reports and previously imported transactions remain available to your accounting practice unless you also ask for them to be deleted (see section 6), subject to the record-keeping obligations below. There are no fees for withdrawing your consent.
6Retention, deletion and de-identification
We retain CDR data only while your consent is active and for as long as it is needed for the bookkeeping purpose it was collected for. When your consent is withdrawn or expires, or the data is no longer needed for that purpose, we delete or irreversibly de-identify the CDR data we hold, except where we are required to retain records by Australian tax or other law (for example, the five-year ATO record-keeping period). Deleting a client in ReconLink also deletes the associated Fiskil end-user.
7Notifications
We (through Fiskil and the ReconLink application) keep you informed about your consent, including when consent is given, when data is collected, and when consent is withdrawn or expires. You can review the current status of a bank feed at any time in ReconLink.
8Security
We protect CDR data with the same controls we apply to all sensitive financial data — encryption in transit and at rest, strict multi-tenant isolation, least-privilege access and audit logging. See our Security page for detail.
9Complaints and disputes
If you have a concern or complaint about how we have handled your CDR data, please contact us at info@reconlink.com.au and we will acknowledge it promptly and respond within 30 days. If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
10More information
For more about your rights under the Consumer Data Right, see the official CDR website. For how Fiskil handles CDR data as the Accredited Data Recipient, see Fiskil’s CDR Policy.
11Changes to this policy
We may update this CDR Policy from time to time. The current version is always available at reconlink.com.au/cdr-policy and the effective date is stated at the top of this page.
12Contact
Innovious Group Pty Ltd · Attention: Privacy Officer
Email: info@reconlink.com.au

