Fiskil

Consumer Data Right (CDR) · Australia. Full regulatory disclosures, consent model, and data handling.

“We partner with licensed providers so you always know exactly who is authorised to access your data and under what rules.”
- The BankSync Team

Penny's provider boundary

Fiskil may operate under its own terms, regulatory duties, security controls, AI settings, retention rules, and incident processes. BankSync protects data inside the BankSync Boundary, but independent provider acts and incidents sit outside that boundary unless caused by BankSync.

Draft — BankSync has not been appointed as a CDR Representative

This page is a draft. BankSync has not been appointed as a CDR Representative of Fiskil Pty Ltd, and no CDR connectivity is live. Details below describe the intended arrangement and may change before launch.

🇦🇺

Fiskil Pty Ltd

Consumer Data Right (CDR) · CDR Open Banking (ACCC)

Draft
ACCC CDR Accreditation
ADRBNK000246
Jurisdiction
Australia
Registered Address
Australia
Public Register
ACCC CDR Register
External Dispute Resolution
Australian Financial Complaints Authority (AFCA) via Fiskil, and the Office of the Australian Information Commissioner (OAIC)

About this Provider

Fiskil Pty Ltd is an Accredited Data Recipient (ADR) under Australia's Consumer Data Right regime, accredited by the ACCC (registration ADRBNK000246). Fiskil provides a CDR Representative platform that allows downstream software companies to access CDR data without holding their own accreditation.

BankSync's Relationship with this Provider

BankSync has not been appointed as a CDR Representative of Fiskil Pty Ltd. CDR connectivity is not live, and no CDR data is currently being collected or disclosed to BankSync. The intended arrangement, once executed, would be a CDR Representative appointment under CDR Rule 1.10AA, with Fiskil acting as our CDR Principal under Fiskil's CDR Policy. Until that appointment is signed and published on the ACCC's public CDR Register, none of the disclosures on this page are operative.

This provider is an independent third-party service where it acts under its own terms, authorisation, regulatory role, account relationship, or legal obligations. BankSync is not responsible for that provider's independent compromise, breach, outage, use, disclosure, retention, deletion, product improvement, AI use, model training, sale, or sharing, except to the extent directly caused by BankSync's breach of its Terms, fraud, wilful misconduct, or a non-excludable legal obligation.

Consent & Access

How consent is collected

Consent is collected through Fiskil's hosted consent screen, where you authenticate directly with your bank. BankSync never handles your banking credentials.

Consent duration

12 months maximum (CDR Rule 4.14). You receive advance notice before expiry.

How to revoke

You may revoke consent at any time through your bank's CDR consent portal, via Fiskil's consent dashboard, or by contacting BankSync support. Revoking consent immediately disables sync and queues deletion of your connection data.

Data Handling

Stored by BankSync

  • Account metadata (institution name, account type)
  • Consent record (status, purpose, data categories, expiry date)
  • Encrypted OAuth tokens (AES-256 at rest)
  • Sync timestamps and audit log of state-changing actions

Pass-through by default

  • Transaction history (amounts, dates, descriptions, categories)
  • Account balances
  • Account holder details

Pass-through data moves through an edge worker sync step spawned in the region closest to you and is forwarded to your connected destination. Data may be stored where you enable a BankSync-managed feature, such as future BankSync Tables, or where needed for support, security, compliance, backups, or legal requirements.

No Secondary Use

CDR data accessed through Fiskil is used to provide the service you request. Within the BankSync Boundary, BankSync does not sell CDR data, use it for advertising or data brokerage, disclose identifiable CDR data for another party's independent commercial exploitation, or use customer CDR data to train AI or machine-learning models. Independent providers and customer-selected destinations may have their own terms and legal obligations.

Regulatory Disclosures

  1. 1This page is a draft. BankSync has not been appointed as a CDR Representative of Fiskil Pty Ltd, holds no CDR accreditation of its own, and is not currently authorised to access CDR data under the Consumer Data Right regime.
  2. 2The intended arrangement is for BankSync to be appointed as a CDR Representative of Fiskil Pty Ltd (CDR Registration ADRBNK000246) under CDR Rule 1.10AA, with Fiskil acting as our CDR Principal and collecting and disclosing CDR data on our behalf under Fiskil's CDR Policy. None of this is in effect today.
  3. 3BankSync does not currently appear on the ACCC's public CDR Register as a CDR Representative. The disclosures below describe the proposed model and will only become operative if and when that appointment is executed and published.
  4. 4Consent is collected through Fiskil's hosted consent screen. Maximum consent duration is 12 months (CDR Rule 4.14). You receive advance notice before expiry.
  5. 5CDR data is used to provide the service you request. Within the BankSync Boundary, BankSync does not sell CDR data, use it for advertising or data brokerage, disclose identifiable CDR data for another party's independent commercial exploitation, or use customer CDR data to train AI or machine-learning models.
  6. 6Financial data obtained under CDR is pass-through by default. It is stored only where you enable a BankSync-managed feature that requires storage, such as future BankSync Tables, or where needed for support, security, compliance, backups, or legal requirements.
  7. 7Upon account deletion or consent revocation, all active CDR consents are immediately withdrawn and connection data is queued for deletion.
  8. 8CDR complaints can be directed to Fiskil Pty Ltd or to the Australian Financial Complaints Authority (AFCA) and the Office of the Australian Information Commissioner (OAIC). Applicable laws include the Privacy Act 1988 (Cth), Competition and Consumer Act 2010 (Cth), and the Consumer Data Right Rules.

Know Who Holds Your Data

Every licensed provider, fully disclosed. Regulated frameworks, consent you control.

14-day free trial • Cancel anytime