Data breach response
What we’ll do if something goes wrong — when we’ll tell you, when we’ll tell the regulator, and what we’ll do to fix it.
What counts as a data breach
A data breach is any event where personal information NestWise holds is accessed, disclosed, or lost without authorisation. Examples:
- An attacker gets into our database or an admin’s laptop and can read profile data
- A subprocessor (Supabase, Stripe, Wych, Resend, Vercel, Anthropic) notifies us they’ve had a breach affecting our data
- A NestWise bug exposes one user’s data to another user (RLS regression)
- A physical device holding secrets is lost or stolen
- Someone tricks a staff member into handing over credentials (phishing)
Our commitment: timing
The Australian Privacy Act ’s Notifiable Data Breach (NDB) scheme gives organisations up to 30 days to assess whether a suspected breach is likely to cause serious harm, then notify affected people + the OAIC. Our commitment is to move faster than the statutory ceiling:
- Within 24 hours of confirming a breach: internal incident channel spun up; scope contained (rotate keys, revoke tokens, freeze impacted systems)
- Within 72 hours: initial assessment of who is affected + what data is at risk
- Within 7 days: notify affected users by email with what happened, what data was involved, what we’re doing, what they should do
- Within 30 days: NDB report lodged with the Office of the Australian Information Commissioner (OAIC) where the breach meets the “likely to cause serious harm” threshold. Earlier if we can
- Within 60 days: public post-mortem published on the blog covering what happened, why it happened, and what we’ve changed to stop it happening again (redacted only for security-sensitive detail)
Additional obligations under the CDR
If the breach touches data received via the Consumer Data Right (bank connection data via Wych), CDR notification rules also apply. In addition to the NDB steps above, we’ll notify:
- The ACCC and the OAIC (joint CDR regulators)
- The CDR-registered data recipient (Wych) who helped facilitate the connection, so they can notify the source bank
- Affected consumers, with clear instructions on how to revoke consent + delete the affected data
See /consent/bank-connection for the full CDR consent + revocation flow.
What we tell you
Every affected-user notification is written in plain English and covers:
- What happened + when we detected it
- Which data types were affected (income, ATI, kids, care fees, etc.) — and which were NOT
- What we’re doing to contain + fix it
- What you should do (e.g. rotate any shared passwords, watch for phishing attempts)
- Where to go for more (this page + a real human at hello@nestwise.net.au)
Notifications go to the email on your NestWise account. If we don’t have a working email for you, we’ll notify by in-app banner instead.
What NestWise never stores
The best defence against a breach is not to hold the data in the first place. NestWise deliberately DOESN’T store:
- Your Tax File Number (TFN)
- Your Medicare number
- Your Centrelink Reference Number (CRN)
- Your full credit card number (Stripe holds this, not us)
- Any government-issued identity document (passport, driver licence)
Any future feature that would need one of these will get its own consent screen + a specific breach-risk assessment first.
How to report a suspected breach
If you think NestWise has leaked or lost your data — even if you’re not sure — email hello@nestwise.net.au with “Suspected data incident” in the subject line. We treat every report seriously, respond within 24 hours (usually faster), and never retaliate against good-faith reports.
You can also complain directly to the Office of the Australian Information Commissioner at oaic.gov.au/privacy/privacy-complaints.
Data retention schedule
The other side of “minimise breach damage” is: don’t keep data longer than you need it. Our retention rules by data type:
| Data category | Kept for | Where |
|---|---|---|
| Profile + household + kids + entitlement inputs | Life of account. Purged within 30 days of deletion request. | Supabase Sydney |
| Bank transactions from a statement you upload (CSV) | Life of account for YoY comparison. Deletable per-txn or in bulk from the cashflow page any time. | Supabase Sydney |
| Bank transactions from a bank connection (CDR) | While the connection is active. Deleted, with anything worked out from them, within 24 hours of the connection ending (disconnected, withdrawn at your bank, or expired). | Supabase Sydney |
| Inbox attachments (bills, letters, statements) | Life of account. Purged within 30 days of deletion request. | Supabase Storage (private, Sydney) |
| Audit log (staff impersonation, admin actions) | 7 years (regulator obligation window). | Supabase Sydney |
| Daily copies of your records | A fresh copy every day; the last 7 days are kept. Anything you delete is gone from the copies within a week. (Scans and documents you upload live in their own locked vault instead.) | Supabase |
| Product analytics events | 24 months rolling; anonymised (no dollar figures ever). | Supabase Sydney |
| Payment records (Stripe) | 7 years (tax + accounting law). | Stripe (PCI-DSS L1) |
| Guide-chat questions | 24 months rolling for guide improvement; anonymised. | Supabase Sydney |
| Bank-connection consent records (CDR) | 7 years post-consent-expiry (CDR record-keeping rules). | Supabase Sydney |
“Life of account” means: while your NestWise account is open, we keep it because you might come back to it. Delete your account (email hello@nestwise.net.au) and everything except audit + payment records is purged within 30 days.
Version 1.0 · Published 24 August 2026. Reviewed at least annually; updated in-place if our commitments strengthen. Prior versions available on request. The detailed internal incident playbook (roles, forensic + legal contacts, exact comms templates) is not published for operational security but is available under NDA on request from a regulator, insurer, or serious commercial partner.
Related: Privacy Policy · Terms of Service · Bank connection consent