Current status. Allwis's bank feed and reconciliation service is in development and is not yet collecting CDR data from any customer. This policy describes how Allwis will manage CDR data once that service is live, and is published in advance as part of our onboarding as a CDR Representative. We are not yet a CDR Representative of any Accredited Data Recipient — once that arrangement is finalised, this policy will be updated with our principal's name and accreditation number, and with the date the service goes live.

1. About this policy

This CDR Policy is published by Allwis Pty Ltd (ABN 14 689 039 343) ("Allwis", "we", "us", "our") in accordance with Privacy Safeguard 1 and CDR Rule 7.2 of Australia's Consumer Data Right (CDR) regime, administered by the Australian Competition and Consumer Commission (ACCC) under Part IVD of the Competition and Consumer Act 2010 (Cth).

Allwis intends to act as a CDR Representative of an ACCC-accredited Data Recipient (our "Principal"), rather than as an Accredited Data Recipient in our own right. This means our Principal collects CDR data from data holders (such as your bank) on our behalf, under consents you give us, and discloses that data to us so we can provide you with the service you've asked for. Our Principal's own CDR policy also applies to CDR data handled under this arrangement, and we will link to it here once our Principal is confirmed.

This policy applies to CDR data handled through the Allwis platform. It does not cover other personal information Allwis collects about you as a general customer of our business software — that is covered by our Privacy Policy.

2. The CDR service we provide

Once available, Allwis's CDR-powered feature lets a business customer connect their bank account(s) to Allwis so that account and transaction data can be imported automatically. We use that data to power:

3. Kinds of CDR data we collect and hold

Subject to your consent, we collect and hold the following categories of banking CDR data:

We only collect the specific data you consent to, for the specific purpose you consent to, consistent with the Data Minimisation Principle under the CDR Rules.

4. How we collect and hold CDR data

CDR data is collected by our Principal from your bank (as a CDR data holder) once you give a valid consent, and disclosed to us as "Service Data" under our CDR Representative arrangement. We do not collect CDR data directly from data holders ourselves.

CDR data is stored in our production database, hosted in Australia (AWS ap-southeast-2, Sydney), and is protected by encryption at rest and in transit, and strict per-customer access controls. Full detail of our security practices is set out in our Information Security Policy, available on request.

5. Purposes of collection, use, and disclosure

We collect, hold, use, and disclose your CDR data only:

We do not use or disclose your CDR data for marketing, and we do not sell your CDR data or any insights derived from it.

6. Disclosure to outsourced service providers

We disclose limited CDR data (or data derived from it) to the following outsourced service providers, solely to operate the service described above:

Overseas disclosure. Anthropic, PBC is located in the United States. No other overseas disclosure of CDR data is currently made. If this changes, we will update this policy to name the relevant countries.

7. Accessing and correcting your CDR data

You can access the CDR data we hold about you at any time within your Allwis account. If you believe any CDR data we hold is inaccurate, out of date, incomplete, irrelevant, or misleading, you can ask us to correct it by emailing privacy@allwis.ai. We will respond within a reasonable time, ordinarily within 30 days, at no charge.

8. Withdrawing consent and deleting data

You can withdraw your consent for us to collect or use your CDR data at any time from within your Allwis account, or by emailing privacy@allwis.ai. Once consent is withdrawn or expires, we will delete or de-identify your CDR data as soon as practicable, in accordance with CDR Rule 1.18 and Privacy Safeguard 12, unless we are required to retain it under Australian law or because it relates to current or anticipated legal proceedings.

9. Complaints

If you think we have mishandled your CDR data or breached the CDR Rules, contact our Privacy Officer at privacy@allwis.ai. We will acknowledge your complaint and aim to resolve it within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992, or to the Australian Financial Complaints Authority (AFCA) where applicable, or to the ACCC.

10. Contact us

Allwis Pty Ltd (ABN 14 689 039 343)
Privacy Officer — privacy@allwis.ai

This CDR Policy is free to access and will be reviewed and updated as our CDR Representative arrangement progresses. Last updated 27 July 2026.