This policy sets out how long ProjectFund Pty Ltd (ABN 75 690 379 330) keeps information, how we delete or de-identify it when it is no longer needed, and the additional rules that apply to Open Banking data shared under Australia’s Consumer Data Right (CDR).
It applies to all production data held in the ProjectFund platform, including account, project, verification, support and billing records, and to backups of that data.
- Collect only what is needed for a stated purpose (data minimisation).
- Keep it only for as long as that purpose, or a legal obligation, requires.
- Delete or de-identify it once the purpose ends.
- Never retain banking credentials, one-time codes, or raw transaction feeds.
Unless a longer period is required by law, we apply the following:
- Account and profile records (name, email, phone, role, business details): for the life of the account, then deleted within 30 days of an account deletion request, except where records must be kept for tax or legal reasons.
- Project and verification records (project name, required amount, milestone dates, verification outcome and timestamp): 7 years from the last activity on the record, to support dispute resolution and business records obligations.
- Consent records (that a consent was given, when, for which request, and when it ended): 6 years, as required for CDR record-keeping.
- Audit and security logs of material production events: 6 years.
- Support tickets, contact form submissions and support assistant conversations: 24 months from closure.
- Email delivery logs: 12 months.
- Billing and subscription records, including invoices: 7 years, as required by Australian tax law.
- Banking credentials, passwords in plain text, one-time codes, raw transaction data: never retained.
The regulated data-sharing step is performed by our accredited provider, Fiskil. ProjectFund receives and retains only the verification outcome and the consent record — not the underlying transaction feed.
Any CDR-derived data we hold is deleted or de-identified promptly when: the consumer withdraws consent; the consent expires; the consumer elects deletion; or our accredited provider or the regulator directs deletion. When consent ends, scheduled re-checks stop immediately and the consumer is asked to reconnect if further checks are needed.
Deletion requests relating to CDR data are actioned within 5 business days of receipt, and the outcome is recorded in our audit log.
Deletion is a hard delete of the underlying database rows, not a hidden or flagged record. Related records are removed with the parent record through database-level cascading rules. Uploaded files, such as business logos, are removed from object storage at the same time.
Where a record must be kept for a legal obligation but no longer needs to identify a person, we de-identify it instead by removing personal identifiers and retaining only aggregate or non-identifying fields.
Encrypted backups of the production database are retained by our hosting provider on a rolling schedule and expire automatically. Deleted data may persist in a backup until that backup expires; it is not restored into production except as part of a full disaster-recovery restore, after which pending deletions are re-applied.
For each deletion request an administrator confirms that the target records return no results, that dependent records were removed, that any uploaded files are gone, and that the action was written to the audit log with the date, requester and scope.
You can delete or update most of your details in your account settings. To request deletion of your account or of a specific record, email support@projectfund.com.au or use our contact form. We respond within a reasonable period and will tell you if we are required to keep some information and why.
This policy is owned and approved by the Director of ProjectFund Pty Ltd and reviewed at least annually, or sooner if our systems, providers or legal obligations change.