Fiskil

Consumer Data Right (CDR) · Australia. Full regulatory disclosures, consent model, and data handling.

“We partner with licensed providers so you always know exactly who is authorised to access your data and under what rules.”
- The BankSync Team

Penny's provider boundary

Fiskil may operate under its own terms, regulatory duties, security controls, AI settings, retention rules, and incident processes. BankSync protects data inside the BankSync Boundary, but independent provider acts and incidents sit outside that boundary unless caused by BankSync.
🇦🇺

Fiskil Pty Ltd

Consumer Data Right (CDR) · CDR Open Banking (ACCC)

Live
ACCC CDR Accreditation
ADRBNK000246
Jurisdiction
Australia
Registered Address
Australia
Public Register
ACCC CDR Register
External Dispute Resolution
Australian Financial Complaints Authority (AFCA) via Fiskil, and the Office of the Australian Information Commissioner (OAIC)

About this Provider

Fiskil Pty Ltd is an Accredited Data Recipient (ADR) under Australia's Consumer Data Right regime, accredited by the ACCC (registration ADRBNK000246). Fiskil provides a CDR Representative platform that allows downstream software companies to access CDR data without holding their own accreditation.

BankSync's Relationship with this Provider

BankSync is appointed as a CDR Representative of Fiskil Pty Ltd under CDR Rule 1.10AA. Fiskil acts as our CDR Principal, collecting and disclosing CDR data on our behalf under Fiskil's CDR Policy, which BankSync adopts. BankSync holds no CDR accreditation of its own and accesses CDR data only through this arrangement.

This provider is an independent third-party service where it acts under its own terms, authorisation, regulatory role, account relationship, or legal obligations. BankSync is not responsible for that provider's independent compromise, breach, outage, use, disclosure, retention, deletion, product improvement, AI use, model training, sale, or sharing, except to the extent directly caused by BankSync's breach of its Terms, fraud, wilful misconduct, or a non-excludable legal obligation.

Consent & Access

How consent is collected

Consent is collected through Fiskil's hosted consent screen, where you authenticate directly with your bank. BankSync never handles your banking credentials.

Consent duration

12 months maximum (CDR Rule 4.14). You receive advance notice before expiry.

How to revoke

You may revoke consent at any time through your bank's CDR consent portal, via Fiskil's consent dashboard, or by contacting BankSync support. Revoking consent immediately disables sync and queues deletion of your connection data.

Data Handling

Stored by BankSync

  • Account metadata (institution name, account type)
  • Consent record (status, purpose, data categories, expiry date)
  • Encrypted OAuth tokens (AES-256 at rest)
  • Sync timestamps and audit log of state-changing actions

Pass-through by default

  • Transaction history (amounts, dates, descriptions, categories)
  • Account balances
  • Account holder details

Pass-through data moves through an edge worker sync step spawned in the region closest to you and is forwarded to your connected destination. Data may be stored where you enable a BankSync-managed feature, such as future BankSync Tables, or where needed for support, security, compliance, backups, or legal requirements.

No Secondary Use

CDR data accessed through Fiskil is used to provide the service you request. Within the BankSync Boundary, BankSync does not sell CDR data, use it for advertising or data brokerage, disclose identifiable CDR data for another party's independent commercial exploitation, or use customer CDR data to train AI or machine-learning models. Independent providers and customer-selected destinations may have their own terms and legal obligations.

Regulatory Disclosures

  1. 1BankSync accesses Australian CDR data as a CDR Representative of Fiskil Pty Ltd (CDR Registration ADRBNK000246) under CDR Rule 1.10AA. BankSync holds no CDR accreditation of its own; Fiskil acts as our CDR Principal and collects and discloses CDR data on our behalf under Fiskil's CDR Policy, which BankSync adopts.
  2. 2Fiskil Pty Ltd is listed on the ACCC's public CDR Register as an Accredited Data Recipient (ADRBNK000246). CDR Representatives are disclosed under their Principal's accreditation rather than holding a separate register entry.
  3. 3Consent is collected through Fiskil's hosted consent screen. Maximum consent duration is 12 months (CDR Rule 4.14). You receive advance notice before expiry.
  4. 4CDR data is used to provide the service you request. Within the BankSync Boundary, BankSync does not sell CDR data, use it for advertising or data brokerage, disclose identifiable CDR data for another party's independent commercial exploitation, or use customer CDR data to train AI or machine-learning models.
  5. 5Financial data obtained under CDR is pass-through by default. It is stored only where you enable a BankSync-managed feature that requires storage, such as future BankSync Tables, or where needed for support, security, compliance, backups, or legal requirements.
  6. 6Upon account deletion or consent revocation, all active CDR consents are immediately withdrawn and connection data is queued for deletion.
  7. 7CDR complaints can be directed to Fiskil Pty Ltd or to the Australian Financial Complaints Authority (AFCA) and the Office of the Australian Information Commissioner (OAIC). Applicable laws include the Privacy Act 1988 (Cth), Competition and Consumer Act 2010 (Cth), and the Consumer Data Right Rules.

Know Who Holds Your Data

Every licensed provider, fully disclosed. Regulated frameworks, consent you control.

14-day free trial • Cancel anytime