Version 1.1 · Effective 14 August 2026 · Altren Group Pty Ltd ABN 32 700 087 332 trading as Allvio
We take privacy seriously. This policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to everyone who visits allvio.com.au, uses the allvio platform, or interacts with us. It is written to meet our obligations under Australian privacy law.
allvio is operated by Altren Group Pty Ltd ABN 32 700 087 332, a technology company based in Melbourne, Victoria, Australia ("Allvio", "we", "us", "our"). We build and operate an all-in-one business management platform for Australian venue businesses, including restaurants, cafés, salons, and wellness centres.
For any privacy-related questions, requests, or complaints, please contact us at:
We aim to respond to all privacy enquiries within 5 business days.
Because allvio is a platform used by businesses to manage their own customers, we handle personal information in two distinct ways. Understanding which applies to your situation helps you know who to contact with any privacy concern.
| Situation | What this means |
|---|---|
| When we are the primary handler | When we collect and use information about the businesses and individuals who subscribe to allvio, including account holders, trial users, website visitors, and people who contact us. We decide why and how that information is collected and used. Most of this policy describes this situation. |
| When we act on a business's instructions | When a business using allvio stores data about their own customers through the platform (for example, a restaurant's reservation records or a salon's client profiles). In that situation, the business is responsible for that personal information and we handle it on their behalf. If you are a customer of a business that uses allvio, see Section 13. |
If you are an end customer of a business that uses allvio (for example, you made a reservation at a restaurant that runs on our platform), your privacy concerns about that data should be directed to that business in the first instance. We will cooperate with reasonable requests from businesses to help them meet their own obligations under the Privacy Act 1988 (Cth).
We collect different categories of personal information depending on your relationship with us.
We automatically collect:
We collect the information needed to set up and manage your account and to deliver our services. This includes:
We collect only what is reasonably necessary to create and manage your account. The specific fields required may vary depending on the services you sign up for.
We collect information generated by your use of the platform and its modules. This includes:
As we add new modules and features to the platform over time, we may collect additional categories of information relevant to those features. Where a new module involves the collection of materially different personal information, we will update this policy and notify you.
We collect:
We collect:
We may receive information about you from:
Under the Australian Privacy Principles, we may only collect and use personal information for purposes that are reasonably necessary for our functions and activities, and we must handle it in a way that is fair and not unreasonably intrusive. The table below sets out the main reasons we collect and use personal information and the APP that applies. Where we also have customers or users in the European Economic Area, we have noted the relevant GDPR basis as well.
| Purpose | What we do | Australian Privacy Principle (and GDPR basis if applicable) |
|---|---|---|
| Providing the platform | Creating and managing your account, processing transactions, delivering all platform features | APP 3 (reasonably necessary for our functions); GDPR Art. 6(1)(b) |
| Processing payments | Charging subscription fees, hardware payments, and other fees | APP 3 and APP 7; GDPR Art. 6(1)(b) |
| Delivering hardware | Fulfilling hardware orders and coordinating delivery | APP 3 (reasonably necessary); GDPR Art. 6(1)(b) |
| Customer support | Responding to your questions, resolving issues, providing onboarding assistance | APP 3 (reasonably necessary); GDPR Art. 6(1)(b) |
| Platform security | Detecting and preventing fraud, abuse, and security threats | APP 11 (security obligations); GDPR Art. 6(1)(f) |
| Product improvement | Analysing usage patterns to improve the platform, fix bugs, and develop new features using anonymised or aggregated data | APP 3 (reasonably necessary); GDPR Art. 6(1)(f) |
| Communications | Sending service updates, security notices, and product announcements | APP 3 (reasonably necessary); GDPR Art. 6(1)(f) |
| Marketing | Sending promotional content about our products and services (only with your consent under the Spam Act 2003 or where otherwise permitted) | APP 7 (direct marketing); GDPR Art. 6(1)(a) |
| Legal compliance | Meeting our obligations under Australian tax law, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and other applicable regulations | APP 11 (security and retention); GDPR Art. 6(1)(c) |
| Enforcing our agreements | Pursuing unpaid debts, enforcing our Terms, defending legal claims | APP 11 (reasonably necessary for enforcement); GDPR Art. 6(1)(c)(f) |
We collect only the personal information that is reasonably necessary for the purposes described above. We do not collect personal information just because it might be useful in the future. If you are located in the EEA or UK, you also have rights in relation to the lawful bases noted in the table above, including the right to object to processing based on legitimate interests (see Section 8).
We keep your personal information only for as long as it is reasonably necessary for the purpose for which it was collected, or as required or authorised by Australian law. The Privacy Act does not prescribe specific retention periods, but the following guidelines reflect our practice and our obligations under tax, financial, and other legislation:
| Category | Retention period |
|---|---|
| Account and subscription data | Duration of your subscription plus 7 years (to meet Australian tax and financial record-keeping obligations) |
| Transaction and financial records | 7 years from the date of the transaction (required under Australian tax law) |
| Support communications | 3 years from the date of the last communication |
| Website usage data and cookies | 13 months from collection (analytics) or as set out in the cookie settings |
| Marketing consent records | Until consent is withdrawn, plus 3 years as evidence of consent |
| Data after account closure | 90 days from account closure, then permanently deleted (unless a longer period is required by law) |
| Hardware order records | 7 years from the date of purchase or final instalment |
| Job application data (if applicable) | 2 years from the date of application if unsuccessful |
At the end of the applicable retention period, we securely delete or anonymise your personal information. If you request deletion before the end of the retention period, we will comply to the extent permitted by law (see Section 8).
We do not sell your personal information. We share it only in the following circumstances:
We use third-party service providers to help us deliver the platform and our services. Under APP 11, we take reasonable steps to ensure that personal information disclosed to these providers is protected. Our providers can only use your personal information for the purpose we engage them for and are contractually bound to protect it. Our current categories of service providers include:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting, storage, and computing services (servers located in Australia and/or other jurisdictions with adequate protection) |
| Payment processing | Processing subscription fees and hardware payments securely |
| Email and communications | Delivering transactional emails, notifications, and support communications |
| Analytics | Anonymised usage analytics to help us improve the platform |
| Customer support tools | Help desk and live chat software |
| Accounting and invoicing | Internal financial management |
| Monitoring and security | Error tracking, uptime monitoring, and security alerting |
A current list of our service providers is available on request at privacy@allvio.com.au.
If Allvio is involved in a merger, acquisition, sale of assets, or other business transition, your personal information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
We may disclose your personal information if required to do so by law, court order, or other legal process, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of Allvio, our customers, or the public. We will notify you of any such disclosure where permitted by law.
We may share your information with third parties in other circumstances where you have given us your explicit consent to do so, such as agreeing to be featured in a case study or reference.
Where your business was referred to us by one of our channel partners, we disclose to that partner the fact that you became a customer, your business name, and the subscription value used to calculate their commission. We do not disclose your contact records, your operational data, or how you use the platform. Partners access this information through a secure partner portal and we do not send it to them by email. Partners are bound by confidentiality obligations under their agreement with us.
Some of our service providers are located overseas. Under APP 8 of the Privacy Act 1988 (Cth), before we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient will handle the information in a way that is consistent with the Australian Privacy Principles.
The countries where our service providers are based may include the United States, the United Kingdom, and other countries with established privacy frameworks. We manage overseas disclosure by:
By using allvio, you consent to the disclosure of your personal information to overseas service providers in the circumstances described above. If you do not consent, please contact us at privacy@allvio.com.au before using the platform.
For users in the European Economic Area or United Kingdom: we take additional steps where required, including entering into standard contractual clauses with service providers in countries without an adequacy decision under the GDPR. You have the rights described in Section 8 and may direct complaints to your local supervisory authority.
The Privacy Act 1988 (Cth) gives you the right to access and correct your personal information. We also make additional commitments that go beyond what Australian law strictly requires, because we believe they reflect good practice. We will respond to any privacy request within 30 days. Users in the EEA or UK have additional rights under the GDPR, noted below.
| Right | What this means |
|---|---|
| Access (APP 12) — your right under Australian law | You can ask us for a copy of the personal information we hold about you and how we use it. We will provide this within 30 days. We may charge a small fee if the request is complex or voluminous, and will tell you in advance. |
| Correction (APP 13) — your right under Australian law | You can ask us to correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to correct it within 30 days. |
| Deletion — our commitment beyond the law | You can ask us to delete your personal information. Australian law does not provide a general right to erasure, but we will comply with deletion requests where we are not required by law to keep the information or where we no longer need it. We will explain if we cannot delete. |
| Data export — our commitment beyond the law | You can ask us to provide your data in a machine-readable format (such as CSV or JSON) so you can take it with you. We provide built-in export tools in the platform for this purpose. |
| Opt out of direct marketing (APP 7) | You can ask us to stop sending you marketing communications at any time. We will stop within 5 business days. |
| Withdraw consent | Where we rely on your consent, you can withdraw it at any time. This does not affect anything we did based on your consent before you withdrew it. |
| Automated decisions | We do not make decisions that significantly affect you based solely on automated processing. If we introduce such processing in the future, we will notify you. |
| Complain to the regulator | You can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or call 1300 363 992. EEA and UK users may complain to their local supervisory authority (see Section 16). |
| Additional GDPR rights (EEA / UK users) | If you are in the EEA or UK, you also have the right to restrict processing, object to processing based on legitimate interests, and rights related to profiling. Contact us at privacy@allvio.com.au to exercise these. |
To exercise any of these rights, contact us at privacy@allvio.com.au. We may ask you to verify your identity before we process your request. Access and correction are free of charge unless a request is voluminous or complex, in which case we will agree a reasonable fee with you in advance. We will never charge a fee just for lodging a request.
We implement technical and organisational security measures appropriate to the sensitivity of the personal information we hold. These measures are required by our Information Security Policy and our Secure Development and Change Policy. The measures in place are:
No security system is impenetrable. Under the Notifiable Data Breaches (NDB) scheme in the Privacy Act 1988 (Cth), we are required to notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable after becoming aware of a data breach that is likely to result in serious harm to you. We aim to notify within 72 hours as a matter of good practice, which is faster than the law requires.
In addition, the following are scheduled to be completed before we process any customer’s live data, and thereafter on a recurring basis: automated dependency and vulnerability scanning integrated into our development pipeline; independent penetration testing, repeated at least annually and after any material change to our architecture; and documented testing of backup restoration, repeated at least twice a year. We describe these separately from the measures above so that you can distinguish what is already in operation from what is committed.
No security measure eliminates risk entirely. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and we will notify the Australian Taxation Office immediately where the breach affects data covered by their requirements.
Our website and platform use cookies and similar technologies to make them work, to understand how they are used, and to improve your experience. A cookie is a small file placed on your device. We use:
When you first visit our website, we will ask for your consent to non-essential cookies. You can change your cookie preferences at any time through the cookie settings link in our website footer. You can also disable cookies in your browser settings, though this may affect the functionality of our website.
Some cookies are set by third parties we use, such as analytics providers. These third parties may collect information about your online activities across different websites over time. We have contractual controls in place to limit how these providers use your data.
The allvio platform and website are intended for use by businesses and adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@allvio.com.au and we will delete that information as quickly as possible.
We may send you marketing communications about our products, new features, events, and promotions. We will only do this where we have your consent or where we have a legitimate interest in doing so (for example, where you are an existing customer and we are communicating about related products or services).
Every marketing communication we send includes an easy way to unsubscribe. You can also opt out at any time by:
We will process your opt-out within 5 business days. Note that opting out of marketing does not affect transactional communications we send you in connection with your account or subscription (such as invoices, security alerts, and service updates).
We comply with the Spam Act 2003 (Cth) and do not send unsolicited commercial electronic messages.
If a business that uses allvio has collected your personal information through our platform (for example, your name and booking details at a restaurant that uses allvio's reservations system), that business is the data controller responsible for that data. We process it on their behalf.
In that case, you should direct any privacy requests (access, correction, deletion) to the business that collected your information. We will cooperate with that business to help them respond to your request. We will not use your personal information collected in this way for any purpose beyond what the business has instructed.
If you are unable to reach the business, or if the business directs you to us, you may contact us at privacy@allvio.com.au and we will assist where we reasonably can.
Our website and platform may contain links to third-party websites, services, and integrations. This Privacy Policy applies only to allvio. We are not responsible for the privacy practices of any third-party website or service, and we encourage you to read their privacy policies before providing your information.
We may update this Privacy Policy from time to time. When we make a material change, we will:
We encourage you to review this policy periodically. If a change affects how we use your personal information in a way that requires your consent, we will ask for it before the change takes effect.
This Privacy Policy is written to comply with Australian privacy law, primarily:
Where we handle personal information of individuals in the European Economic Area or United Kingdom, we also apply the GDPR and UK GDPR respectively as relevant.
If you have a concern about how we have handled your personal information and we have not been able to resolve it to your satisfaction, you can contact the relevant regulator:
| Jurisdiction | Regulator and contact |
|---|---|
| Australia (primary) | Office of the Australian Information Commissioner (OAIC) oaic.gov.au | 1300 363 992 Complaints can be made online at oaic.gov.au/privacy/privacy-complaints |
| European Union | Your local EU data protection supervisory authority (Full list at edpb.europa.eu) |
| United Kingdom | Information Commissioner's Office (ICO) ico.org.uk | 0303 123 1113 |
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please reach out:
We are committed to resolving privacy concerns promptly and transparently. We aim to respond to all privacy enquiries within 5 business days.