← Back to home

Consumer Data Right readiness statement

Last updated: 2 August 2026

1. Responsible entity and status

Saia da Teoria is operated by GPF IT SOLUTIONS PTY LTD (ABN 57 638 578 140). We are evaluating a production arrangement with an accredited provider for consent-based bank connectivity. The accredited principal, our precise CDR role and all required disclosures will be named here only after the arrangement is formally approved and registered.

2. Intended data scope

If the feature is approved and launched, we intend to request only the account data needed to provide bank feeds: account name, type and details, balances, and transaction details. Identity, contact, payee and other banking data will not be requested unless it becomes necessary for a clearly disclosed feature and is permitted by the final arrangement.

3. Intended purpose

The proposed feature would use bank data to import balances and posted transactions into the user’s private workspace, reduce manual entry and produce factual budgeting summaries. We do not intend to use it for financial product advice, third-party advertising, data brokerage, credit or eligibility decisions, or unrelated profiling.

4. Consent and control

No connection will begin without the user completing an approved consent flow that identifies the provider, data requested, purpose and consent duration. The production experience must allow users to review and withdraw consent in accordance with the applicable CDR rules and arrangement. Saia da Teoria will never ask for or store an online-banking password.

5. Providers and disclosure

We do not sell financial data. The production disclosure chain, accredited principal and any outsourced service providers will be identified before launch. References to technology being evaluated do not mean that any provider, principal or regulator has approved Saia da Teoria.

6. Technical preparation

The pilot implementation keeps provider credentials server-side, uses encrypted transport, validates signed webhook events, scopes records to a customer workspace and records security-relevant events. These controls support readiness but do not replace accreditation, registration, contracts, testing or regulatory approval.

7. Retention, withdrawal and deletion

Before launch, retention and deletion behaviour will be aligned with the approved access model, CDR Rules and Privacy Safeguards. The intended design stops new collection when consent expires or is withdrawn and deletes or de-identifies CDR data when required, subject to any lawful exception. User-entered product records remain covered by our Privacy Policy.

8. Questions and complaints

Until live CDR access is enabled, questions about this readiness work or our handling of ordinary personal information can be sent to contact@saiadateoria.com. Do not email banking credentials. If CDR access launches, this section will provide the approved participant’s complaint process and escalation details. Consumers can also read the OAIC’s CDR complaints guidance.

9. How to verify our status

Before connecting an account, users should verify Saia da Teoria and the disclosed accredited provider in the Australian Government’s current provider register. If the approved arrangement is not visible there, live CDR connectivity will not be offered.

10. Updates before launch

This readiness statement will be replaced or materially updated before live CDR access is enabled. The production version will reflect the registered access arrangement, actual data practices, consent model, complaint pathway and applicable regulatory obligations.