Connecting a bank account
When you connect a bank account to NestWise, we go through the same Consumer Data Right (CDR) process the Big 4 banks operate under. This page tells you exactly what you’re agreeing to before you tap the button.
Who is doing the connecting
When you connect a bank account, a specialist called Wych does the connecting for us. Wych is accredited under the Consumer Data Right (CDR), and NestWise works under that accreditation as Wych’s CDR representative. So your bank information is looked after by the same strict rules from start to finish, and it only moves with your permission.
The aggregator is regulated under the CDR framework, which requires the same standards of encryption, storage and consent management as the Big 4 banks themselves.
What data is read
- Account balances for the accounts you tick during connection
- Transaction history for those accounts (typically last 12 months)
- Account metadata (bank name, account nickname, BSB, last 4 digits)
Not read: transactions on accounts you didn’t tick; anything from other people you share a joint account with beyond the shared account itself; your credit score; loan applications; anything outside the CDR data scope.
What we do with it
- Categorise transactions (utilities / groceries / dining / vehicle / etc) so your cashflow page shows real spend by category
- Reconcile actual spend against your planned budget so the “drift” number is honest, not projected
- Surface bank-fed items on the tax-hub review queue for possible deductions (you decide yes / no / partial)
- Update your account balances so the net-worth roll-up stays current
What we DON'T do
- Sell it. Ever. To anyone.
- Share it with lenders or credit bureaus.
- Initiate payments on your behalf. NestWise is read-only via CDR — we cannot move money.
- Make lending or credit decisions. We don’t score you and we don’t hand your data to anyone who does.
- Use it to advertise to you. NestWise runs no ads and shares no data with ad networks.
- Send $ figures or transaction detail to our AI assistant. The same discipline we already run on your other profile data.
How long we keep it
- Transaction categorisations and budget-vs-actual figures are kept for as long as your account is active, so you can see year-over-year comparisons.
- You can delete individual transactions or the entire imported history from the cashflow page at any time.
- Full account + all data is purged within 30 days of account deletion (email hello@nestwise.net.au).
- We keep a daily safety copy for a week, so anything you delete is gone from those copies within 7 days too.
How consent works
- Consent is per-connection — a Commonwealth Bank consent doesn’t authorise us to read your ANZ account.
- Consent is time-boxed — CDR rules cap it at 12 months. You’ll be asked to re-consent before that lapses.
- Consent is scoped — you tick which accounts and only those are read.
- Consent is revocable at any time (see below). Revoking stops collection immediately.
How to revoke
Two ways to switch off a bank connection:
- From NestWise — go to Money › Assets › Bank connections and tap “Disconnect”. This tells the aggregator to stop and revokes our access.
- From your bank — every AU bank must offer a CDR consent dashboard where you can revoke third-party access. Look for “Data sharing” or “Third-party access” in your bank’s app or Internet Banking.
Revoking stops collection immediately. Within 24 hours, NestWise deletes the transactions that connection brought in, and anything worked out from them, such as matched payments and subscription suggestions. Statements you uploaded yourself are not affected. The same happens when your consent expires, or if you withdraw it at your bank.
If something goes wrong
Complaints about the bank connection go through NestWise’s standard complaints process (email hello@nestwise.net.au — we respond within 5 business days).
If NestWise can’t resolve your complaint to your satisfaction, you can escalate to the Office of the Australian Information Commissioner (privacy issues) at oaic.gov.au, or to the ACCC’s CDR team for consent / data-handling issues at cdr.gov.au.
NestWise is not an AFSL holder and doesn’t provide financial advice, so the Australian Financial Complaints Authority (AFCA) doesn’t apply.
Data breach commitment
If a data breach occurs that meets the Notifiable Data Breach threshold under the Privacy Act, we will notify affected users and the OAIC within the statutory 30-day window — earlier if we can. Every incident triggers an internal review and, where appropriate, a public post-mortem.
Full commitment (specific hour + day windows, what we tell you, retention schedule): /legal/data-breach-response.
Version 1.0 · Published 24 August 2026. This page will be updated in-place when the open-banking integration ships and the specific aggregator’s full legal name + CDR accreditation number are locked in. Prior versions are available on request.
Related: Privacy Policy · Terms of Service · Data breach response