Legal

Privacy Policy

Effective 1 August 2026 · Version 1.0 · Altren Group Pty Ltd ABN 32 700 087 332 trading as Allvio

We take privacy seriously. This policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to everyone who visits allvio.com.au, uses the allvio platform, or interacts with us. It is written to meet our obligations under Australian privacy law.

1. Who we are

allvio is operated by Altren Group Pty Ltd ABN 32 700 087 332, a technology company based in Melbourne, Victoria, Australia ("Allvio", "we", "us", "our"). We build and operate an all-in-one business management platform for Australian venue businesses, including restaurants, cafés, salons, and wellness centres.

For any privacy-related questions, requests, or complaints, email privacy@allvio.com.au. We aim to respond to all privacy enquiries within 5 business days.

2. How we handle personal information

Because allvio is a platform used by businesses to manage their own customers, we handle personal information in two distinct ways.

  • When we are the primary handler: when we collect and use information about the businesses and individuals who subscribe to allvio, including account holders, trial users, website visitors, and people who contact us. We decide why and how that information is collected and used. Most of this policy describes this situation.
  • When we act on a business's instructions: when a business using allvio stores data about their own customers through the platform (for example, a restaurant's reservation records or a salon's client profiles). In that situation, the business is responsible for that personal information and we handle it on their behalf. If you are a customer of a business that uses allvio, see Section 13.

If you are an end customer of a business that uses allvio (for example, you made a reservation at a restaurant that runs on our platform), your privacy concerns about that data should be directed to that business in the first instance. We will cooperate with reasonable requests from businesses to help them meet their own obligations under the Privacy Act 1988 (Cth).

3. What personal information we collect

3.1 When you visit our website we automatically collect your IP address and approximate location, browser type, operating system and device type, pages visited and referring URLs, and cookies and similar tracking technologies (see Section 10).

3.2 When you create an account or start a trial we collect identity and contact information (name, email, phone), business information (name, type, location, ABN/ACN), billing and payment information (processed securely by our payment provider; we do not store full card numbers), and anything else you choose to provide during registration. We collect only what is reasonably necessary to create and manage your account.

3.3 When you use the platform we collect operational data generated by the modules you use (sales, orders, reservations, financial records, staff records, inventory), usage data (features accessed and when), device and session information, support and communications data, and any feedback or testimonials you provide voluntarily. As we add new modules over time, we may collect additional categories relevant to those features, and will update this policy where the difference is material.

3.4 When you order hardware we collect your delivery address, contact name and phone number, and payment details for the purchase or instalment plan.

3.5 When you contact us we collect your name, email, any information in your message, and the record of our correspondence.

3.6 From third parties we may receive information from payment processors, identity verification services, and public sources such as ASIC (to verify ABNs and business details).

4. How we use your information and our lawful basis

Under the Australian Privacy Principles, we may only collect and use personal information for purposes that are reasonably necessary for our functions and activities, handled fairly and without being unreasonably intrusive. The main reasons we collect and use personal information:

  • Providing the platform: creating and managing your account, processing transactions, delivering all platform features (APP 3; GDPR Art. 6(1)(b)).
  • Processing payments: subscription fees, hardware payments and other fees (APP 3 and 7; GDPR Art. 6(1)(b)).
  • Delivering hardware: fulfilling orders and coordinating delivery (APP 3; GDPR Art. 6(1)(b)).
  • Customer support: responding to questions, resolving issues, onboarding (APP 3; GDPR Art. 6(1)(b)).
  • Platform security: detecting and preventing fraud, abuse and security threats (APP 11; GDPR Art. 6(1)(f)).
  • Product improvement: analysing usage patterns using anonymised or aggregated data (APP 3; GDPR Art. 6(1)(f)).
  • Communications: service updates, security notices, product announcements (APP 3; GDPR Art. 6(1)(f)).
  • Marketing: promotional content, only with your consent under the Spam Act 2003 or where otherwise permitted (APP 7; GDPR Art. 6(1)(a)).
  • Legal compliance: obligations under Australian tax law, AML/CTF law and other regulation (APP 11; GDPR Art. 6(1)(c)).
  • Enforcing our agreements: pursuing unpaid debts, enforcing our Terms, defending legal claims (APP 11; GDPR Art. 6(1)(c)(f)).

We collect only the personal information that is reasonably necessary for the purposes above, never on the chance it might be useful later. If you are in the EEA or UK, you also have the right to object to processing based on legitimate interests (see Section 8).

5. How long we keep your information

We keep personal information only as long as reasonably necessary, or as required by Australian law. Our practice:

  • Account and subscription data: duration of your subscription plus 7 years (tax and financial record-keeping).
  • Transaction and financial records: 7 years from the transaction date.
  • Support communications: 3 years from the last communication.
  • Website usage data and cookies: 13 months, or as set out in cookie settings.
  • Marketing consent records: until withdrawn, plus 3 years as evidence of consent.
  • Data after account closure: 90 days, then permanently deleted, unless a longer period is required by law.
  • Hardware order records: 7 years from purchase or final instalment.
  • Job application data: 2 years from the application date if unsuccessful.

At the end of the applicable retention period, we securely delete or anonymise your personal information. If you request deletion earlier, we will comply to the extent permitted by law (see Section 8).

6. Who we share your information with

We do not sell your personal information. We share it only with:

6.1 Our service providers: cloud infrastructure (hosting/storage/compute), payment processing, email and communications, analytics (anonymised), customer support tools, accounting and invoicing, and monitoring/security. Providers may only use your information for the purpose we engage them for and are contractually bound to protect it. A current list is available on request at privacy@allvio.com.au.

6.2 Business transfers: if Allvio is involved in a merger, acquisition or sale of assets, your information may transfer as part of that transaction. We will notify you before it becomes subject to a different privacy policy.

6.3 Legal requirements: where required by law, court order, or to protect the rights, property or safety of Allvio, our customers or the public, notifying you where permitted.

6.4 With your consent: for example, agreeing to be featured in a case study or reference.

7. Overseas disclosure of personal information

Some service providers are located overseas (potentially including the United States and the United Kingdom). Under APP 8, before disclosing information overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles: contractual protections consistent with the APPs, only engaging providers in jurisdictions with comparable protection, and limiting shared information to what is strictly necessary. By using allvio you consent to this; if you do not, contact privacy@allvio.com.au before using the platform. EEA/UK users: we use standard contractual clauses where required and you may direct complaints to your local supervisory authority.

8. Your privacy rights

We respond to any privacy request within 30 days.

  • Access (APP 12): ask for a copy of the personal information we hold and how we use it. We may charge a small fee if the request is complex or voluminous, told to you in advance.
  • Correction (APP 13): ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Deletion (our commitment beyond the law): Australian law does not provide a general right to erasure, but we will comply with deletion requests where we are not required by law to keep the information or no longer need it.
  • Data export (beyond the law): request your data in a machine-readable format (CSV or JSON); the platform also includes built-in export tools.
  • Opt out of direct marketing (APP 7): we will stop within 5 business days.
  • Withdraw consent: at any time, without affecting anything done based on it beforehand.
  • Automated decisions: we do not make decisions that significantly affect you based solely on automated processing; we will notify you if that changes.
  • Complain to the regulator: the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992. EEA/UK users may complain to their local supervisory authority.
  • Additional GDPR rights (EEA/UK): restrict processing, object to processing based on legitimate interests, and rights related to profiling: contact privacy@allvio.com.au.

To exercise any of these rights, contact privacy@allvio.com.au. We may ask you to verify your identity first. Access and correction are free unless a request is voluminous or complex, in which case we will agree a fee with you in advance. We never charge just for lodging a request.

9. How we protect your information

Our security measures include encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 or equivalent), logical isolation of customer data within our multi-tenant architecture with row-level security, role-based access controls, multi-factor authentication for staff accessing production systems, regular independent security assessments and penetration testing, staff security awareness training, a defined incident response plan, and regular tested backups.

No security system is impenetrable. Under the Notifiable Data Breaches scheme we are required to notify you and the OAIC as soon as practicable after a breach likely to cause serious harm; we aim to notify within 72 hours as good practice.

10. Cookies and tracking technologies

We use essential cookies (required for the site/platform to function), analytics cookies (anonymised usage patterns), preference cookies (remembering settings across sessions), and marketing cookies (only with your consent). You can set your preferences via the cookie settings link in our footer, or disable cookies in your browser, though this may affect functionality. Some cookies are set by third parties such as analytics providers, and we have contractual controls limiting how they use your data.

11. Children's privacy

The allvio platform and website are intended for businesses and adults. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently done so, contact privacy@allvio.com.au and we will delete it as quickly as possible.

12. Direct marketing

We only send marketing communications where we have your consent or a legitimate interest (for example, related products for existing customers). Every marketing email includes an unsubscribe link; you can also opt out by emailing privacy@allvio.com.au or updating your account preferences. We process opt-outs within 5 business days. Opting out of marketing does not affect transactional communications like invoices, security alerts and service updates. We comply with the Spam Act 2003 (Cth).

13. If you are a customer's customer

If a business using allvio collected your personal information through our platform (for example, your reservation details at a restaurant), that business is the data controller and we process it on their behalf. Direct any access, correction or deletion request to that business; we will cooperate to help them respond. If you cannot reach the business, or they direct you to us, contact privacy@allvio.com.au and we will assist where reasonably possible.

14. Links to other websites

Our website and platform may link to third-party websites, services and integrations. This policy applies only to allvio; we are not responsible for third-party privacy practices, so review their policies before providing your information.

15. Changes to this policy

We may update this policy from time to time. For a material change, we will notify you by email at least 30 days before it takes effect and post the updated policy at allvio.com.au/privacy with a new effective date. If a change requires your consent, we will ask for it first.

16. Applicable law and how to complain

This policy is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Notifiable Data Breaches scheme, and the Spam Act 2003 (Cth), and applies the GDPR/UK GDPR where relevant. If we haven't resolved your concern to your satisfaction:

  • Australia: Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992, or oaic.gov.au/privacy/privacy-complaints.
  • European Union: your local EU data protection supervisory authority (full list at edpb.europa.eu).
  • United Kingdom: Information Commissioner's Office (ICO), ico.org.uk, 0303 123 1113.

17. Contact us

Privacy Officer: privacy@allvio.com.au · General enquiries: hello@allvio.com.au · Support: support@allvio.com.au · 1300 556 527

We are committed to resolving privacy concerns promptly and transparently, and aim to respond to all privacy enquiries within 5 business days.