Consumer Data Right Policy
This CDR Policy is separate from our general Privacy Policy. It explains how we intend to manage CDR data and service data used in HEC's business-financial workflow.
1. Our CDR role
Innoca Tech intends to obtain read-only banking data through Fiskil under the CDR access model agreed with Fiskil. If Innoca Tech operates as a CDR representative, we will adopt and comply with the CDR representative principal's CDR policy for service data, and this policy will operate as a supplementary HEC notice. We will update this page before live activation if the final legal role or arrangement differs.
2. CDR data we may handle
For the initial service, we will only request data reasonably necessary for internal business financial management:
- business account and account-holder information required to identify the account;
- account identifiers and account details;
- current and available balances;
- transaction history, transaction descriptions, dates, amounts and references.
We do not intend to collect payment credentials or use CDR data to initiate payments.
3. Why we use CDR data
CDR data will be used only for the purposes authorised in the consent arrangement, including:
- matching incoming payments to HEC invoices and projects;
- identifying paid, unpaid and overdue invoices;
- stopping payment-reminder workflows after confirmed payment;
- cash-flow, receivables, income and expenditure visibility;
- internal profitability and management reporting.
We will not use CDR data for credit underwriting, lending, direct marketing, customer advertising, sale of data, or general research in the initial service.
4. Storage and security
CDR data will be stored and processed in Australian-hosted infrastructure in the OVHcloud Sydney region. The CDR environment is designed to use dedicated data storage, role-based access, unique user identities, multi-factor authentication for personnel access, encryption in transit and at rest, audit logging, restricted administrative privileges, security patching, vulnerability management and controlled backups.
Live CDR data will not be enabled until the required controls have been implemented and verified.
5. External service providers and disclosure
The initial CDR architecture is limited to:
- Fiskil — CDR access, consent and banking-data connectivity;
- OVHcloud — Australian hosting and encrypted backup infrastructure in Sydney.
We do not intend to disclose raw CDR data to Gmail, Microsoft 365, Dropbox, marketing platforms, analytics SaaS products, ChatGPT, Claude, Gemini or other external AI services. We do not sell CDR data or insights derived from it.
6. Overseas storage and disclosure
The initial CDR service is designed so that CDR data is stored in Australia. We do not intend to store or disclose CDR data overseas. Any future change involving an overseas processor or storage location will require security, privacy and CDR review before implementation and an update to this policy where required.
7. Consent and withdrawal
Consent will be obtained and managed through the applicable CDR consent process. A consumer may withdraw consent through the available consent-management process. Withdrawal stops future collection and may prevent HEC from providing CDR-powered payment matching and financial insights. Data that becomes redundant will be deleted or de-identified as required by the applicable CDR rules and arrangement.
8. Access and correction
You may ask what CDR data we hold about you or your business, and you may ask us to correct HEC records or derived information that is inaccurate. Where the underlying source data came from a bank or another CDR participant, we may need to refer the correction to that source or explain the appropriate correction pathway.
Requests can be made by email or telephone using the contact details below. We may need to verify identity or authority before providing access or making a correction.
9. Notifications
Where required by the CDR rules, our CDR arrangement or applicable law, we will notify the relevant consumer or business about material events concerning the collection, use, disclosure, correction, deletion or security of CDR data.
10. Complaints
A CDR complaint may be made if you believe we have not met our CDR obligations or have mishandled CDR data. Please provide your name, contact details, the business or account involved, a description of the issue, relevant dates and the outcome you seek.
We aim to acknowledge a CDR complaint within 2 business days, complete an initial assessment within 10 business days and provide a final response within 30 calendar days where reasonably possible. If more time is required, we will explain why and provide an updated timeframe.
Possible remedies include correction of HEC records, deletion where permitted and required, explanation, apology, changes to controls or workflow, and other appropriate remediation. You may also raise a privacy complaint with the Office of the Australian Information Commissioner at oaic.gov.au. Where an external dispute resolution scheme applies through our CDR principal or arrangement, its details will also be made available in the live consent/service experience.
11. Contact
CDR and Privacy Contact — Innoca Tech Pty Ltd / House Energy Certified
Email: paul@houseenergycertified.com
Phone: 02 9130 2898
12. Copies and review
This policy is available free of charge online. On request, we will provide an electronic copy and, where reasonably practicable, a hard copy. We review this policy at least annually, before live CDR activation, and whenever our CDR role, service, subprocessors, storage location or legal obligations materially change.
