House Energy Certified

Consumer Data Right Policy

Innoca Tech Pty Ltd trading as House Energy Certified (HEC) · Version 1.0 · Effective 17 September 2026

Pre-live status: Innoca Tech does not currently receive live Consumer Data Right (CDR) banking data. This policy records the controls and practices that apply before and from activation of live CDR access. Live CDR processing must not begin until the relevant Fiskil arrangement and the HEC CDR go-live control checklist are complete.

This CDR Policy is separate from our general Privacy Policy. It explains how we intend to manage CDR data and service data used in HEC's business-financial workflow.

1. Our CDR role

Innoca Tech intends to obtain read-only banking data through Fiskil under the CDR access model agreed with Fiskil. If Innoca Tech operates as a CDR representative, we will adopt and comply with the CDR representative principal's CDR policy for service data, and this policy will operate as a supplementary HEC notice. We will update this page before live activation if the final legal role or arrangement differs.

2. CDR data we may handle

For the initial service, we will only request data reasonably necessary for internal business financial management:

We do not intend to collect payment credentials or use CDR data to initiate payments.

3. Why we use CDR data

CDR data will be used only for the purposes authorised in the consent arrangement, including:

We will not use CDR data for credit underwriting, lending, direct marketing, customer advertising, sale of data, or general research in the initial service.

4. Storage and security

CDR data will be stored and processed in Australian-hosted infrastructure in the OVHcloud Sydney region. The CDR environment is designed to use dedicated data storage, role-based access, unique user identities, multi-factor authentication for personnel access, encryption in transit and at rest, audit logging, restricted administrative privileges, security patching, vulnerability management and controlled backups.

Live CDR data will not be enabled until the required controls have been implemented and verified.

5. External service providers and disclosure

The initial CDR architecture is limited to:

We do not intend to disclose raw CDR data to Gmail, Microsoft 365, Dropbox, marketing platforms, analytics SaaS products, ChatGPT, Claude, Gemini or other external AI services. We do not sell CDR data or insights derived from it.

6. Overseas storage and disclosure

The initial CDR service is designed so that CDR data is stored in Australia. We do not intend to store or disclose CDR data overseas. Any future change involving an overseas processor or storage location will require security, privacy and CDR review before implementation and an update to this policy where required.

7. Consent and withdrawal

Consent will be obtained and managed through the applicable CDR consent process. A consumer may withdraw consent through the available consent-management process. Withdrawal stops future collection and may prevent HEC from providing CDR-powered payment matching and financial insights. Data that becomes redundant will be deleted or de-identified as required by the applicable CDR rules and arrangement.

8. Access and correction

You may ask what CDR data we hold about you or your business, and you may ask us to correct HEC records or derived information that is inaccurate. Where the underlying source data came from a bank or another CDR participant, we may need to refer the correction to that source or explain the appropriate correction pathway.

Requests can be made by email or telephone using the contact details below. We may need to verify identity or authority before providing access or making a correction.

9. Notifications

Where required by the CDR rules, our CDR arrangement or applicable law, we will notify the relevant consumer or business about material events concerning the collection, use, disclosure, correction, deletion or security of CDR data.

10. Complaints

A CDR complaint may be made if you believe we have not met our CDR obligations or have mishandled CDR data. Please provide your name, contact details, the business or account involved, a description of the issue, relevant dates and the outcome you seek.

We aim to acknowledge a CDR complaint within 2 business days, complete an initial assessment within 10 business days and provide a final response within 30 calendar days where reasonably possible. If more time is required, we will explain why and provide an updated timeframe.

Possible remedies include correction of HEC records, deletion where permitted and required, explanation, apology, changes to controls or workflow, and other appropriate remediation. You may also raise a privacy complaint with the Office of the Australian Information Commissioner at oaic.gov.au. Where an external dispute resolution scheme applies through our CDR principal or arrangement, its details will also be made available in the live consent/service experience.

11. Contact

CDR and Privacy Contact — Innoca Tech Pty Ltd / House Energy Certified
Email: paul@houseenergycertified.com
Phone: 02 9130 2898

12. Copies and review

This policy is available free of charge online. On request, we will provide an electronic copy and, where reasonably practicable, a hard copy. We review this policy at least annually, before live CDR activation, and whenever our CDR role, service, subprocessors, storage location or legal obligations materially change.

Important: Once the formal Fiskil CDR access arrangement is executed, this policy will be reviewed against that arrangement and, if Innoca Tech is a CDR representative, the principal's CDR policy will govern service data as required by the CDR Rules.