Loading workspace...
Please wait
Where your data lives, how it is protected, and what happens when something goes wrong · Altren Group Pty Ltd ABN 32 700 087 332 trading as Allvio
Allvio holds your takings, your bookings, your staff records and your customers' details. This page sets out plainly where that data lives, how it is protected, and what happens when something goes wrong. No jargon, and no badges we have not earned.
Platform data is hosted on Microsoft Azure in Australia East (Sydney), with a replica in Australia Southeast (Melbourne). Your trading records, staff records, payroll and tax information stay in Australia.
Traffic to Allvio uses TLS 1.2 or above. Stored data and backups are encrypted at rest with AES-256.
It is yours, not ours. We process it to run the service and nothing else. We do not sell it, and we do not use it to train AI models without your consent.
A contractual target, not a marketing line, with service credits if we miss it. Our current status is always public.
We run a live replica between two Australian regions, back up daily, and keep those backups for a month.
Card details are captured by our payment provider, not by Allvio. We never see or store full card numbers, and we never store CVVs or PINs.
Production data is stored in Azure Australia East, in Sydney. A live replica and the daily backups are held in Azure Australia Southeast, in Melbourne. Both are Australian regions.
Allvio is multi-tenant. Every record is scoped to a business, and separation is enforced by row-level security in the database, so one business cannot reach another's data.
TLS 1.2 or above in transit. AES-256 at rest, including backups and object storage.
Changes are reviewed before release and can be rolled back. Releases that affect availability are scheduled into a maintenance window with notice.
Want more detail? Email support@allvio.com.au and we will come back to you.
Available on Allvio accounts, and mandatory on every internal system we use that supports it.
Access inside your business is set by role, so a floor staff login is not an owner login. You can give your accountant a scoped, read-only view of just the finance areas.
Nobody at Allvio holds standing access to your business data. Where a support request needs it, access is granted for that request, logged, and removed when the request closes.
Activity in your business is recorded, so you can see what changed and who changed it.
99.9% monthly uptime for paid subscriptions, set out in Schedule 1 of the Customer Agreement, with service credits if we fall short.
We reserve Tuesday and Thursday nights, 11 pm to 1 am AEST, for maintenance, and in most weeks we do not use them. You get at least 48 hours notice before any planned downtime, and planned maintenance does not count against the uptime target.
We post to our status page before we start diagnosing, and keep updating until it is fixed. For a critical outage we contact affected venues directly.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Our Privacy Policy sets out what we collect and why.
When a diner books or orders with your venue, that information is yours. You decide how it is used; we process it on your behalf to deliver the service.
Payments are processed by our payment provider using their hosted payment fields. Allvio does not see, transmit, or store full card numbers, and we never store CVVs or PINs.
Some suppliers handle information on our behalf, and a few of them operate overseas. A current list of those suppliers, what they handle and where they operate, is available on request from privacy@allvio.com.au.
We have a written breach response process aligned to the Notifiable Data Breaches scheme. If your data is involved, we tell you, and we tell you what we know rather than waiting until we know everything.
Ask us for an export of your data at any time and we will provide it within 10 business days, as Excel files, at no charge. Because an export can contain payroll, tax and banking details, we confirm that the person asking is an authorised contact on the account, we send the file in an encrypted archive through a secure link that only that person can open and which expires, and we send the password separately by text message to a mobile number already on the account. We do not email the file as an attachment.
We keep your data for 90 days after your subscription ends so you can still request an export. After that it is deleted.
We would rather you stayed because Allvio works than because your data is stuck in it.
Independent penetration testing is scheduled before we process any customer's live data, and at least annually after that. We would rather tell you what is committed than imply it is already done. Once the first test is complete, this section will name the month, the firm, and how findings are tracked.
Automated dependency and vulnerability scanning is being introduced into our build pipeline before launch, so that a known weakness in a component we rely on is caught before it reaches you.
Documented testing of backup restoration is scheduled before we process any customer's live data, and at least twice a year after that. We describe these three separately from the measures above so you can tell what is already running from what is committed.
Found something, or think you have? Email security@allvio.com.au. We will acknowledge within 24 hours, and we will not pursue anyone who reports a genuine issue in good faith.
Questions, access requests, or a complaint: privacy@allvio.com.au. We respond within 5 business days.
Email support@allvio.com.au or call 1300 556 527, and we will come back to you.
Altren Group Pty Ltd · ABN 32 700 087 332 · Melbourne, Victoria, Australia