Legal

Trust and Security

Where your data lives, how it is protected, and what happens when something goes wrong · Altren Group Pty Ltd ABN 32 700 087 332 trading as Allvio

Allvio holds your takings, your bookings, your staff records and your customers' details. This page sets out plainly where that data lives, how it is protected, and what happens when something goes wrong. No jargon, and no badges we have not earned.

The short version

Your data stays in Australia

Platform data is hosted on Microsoft Azure in Australia East (Sydney), with a replica in Australia Southeast (Melbourne). Your trading records, staff records, payroll and tax information stay in Australia.

Encrypted in transit and at rest

Traffic to Allvio uses TLS 1.2 or above. Stored data and backups are encrypted at rest with AES-256.

You own your data

It is yours, not ours. We process it to run the service and nothing else. We do not sell it, and we do not use it to train AI models without your consent.

99.9% uptime target

A contractual target, not a marketing line, with service credits if we miss it. Our current status is always public.

Backups in a second Australian region

We run a live replica between two Australian regions, back up daily, and keep those backups for a month.

We handle as little card data as possible

Card details are captured by our payment provider, not by Allvio. We never see or store full card numbers, and we never store CVVs or PINs.

Hosting and infrastructure

Where your data actually lives

Production data is stored in Azure Australia East, in Sydney. A live replica and the daily backups are held in Azure Australia Southeast, in Melbourne. Both are Australian regions.

Separation between businesses

Allvio is multi-tenant. Every record is scoped to a business, and separation is enforced by row-level security in the database, so one business cannot reach another's data.

Encryption

TLS 1.2 or above in transit. AES-256 at rest, including backups and object storage.

Change management

Changes are reviewed before release and can be rolled back. Releases that affect availability are scheduled into a maintenance window with notice.

Want more detail? Email support@allvio.com.au and we will come back to you.

Access and accounts

Multi-factor authentication

Available on Allvio accounts, and mandatory on every internal system we use that supports it.

Roles, not blanket access

Access inside your business is set by role, so a floor staff login is not an owner login. You can give your accountant a scoped, read-only view of just the finance areas.

Our access to your data

Nobody at Allvio holds standing access to your business data. Where a support request needs it, access is granted for that request, logged, and removed when the request closes.

Audit trail

Activity in your business is recorded, so you can see what changed and who changed it.

Availability

Our target

99.9% monthly uptime for paid subscriptions, set out in Schedule 1 of the Customer Agreement, with service credits if we fall short.

Planned maintenance

We reserve Tuesday and Thursday nights, 11 pm to 1 am AEST, for maintenance, and in most weeks we do not use them. You get at least 48 hours notice before any planned downtime, and planned maintenance does not count against the uptime target.

When something breaks

We post to our status page before we start diagnosing, and keep updating until it is fixed. For a critical outage we contact affected venues directly.

View live status

Privacy and payments

Australian privacy law

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Our Privacy Policy sets out what we collect and why.

Your customers' data

When a diner books or orders with your venue, that information is yours. You decide how it is used; we process it on your behalf to deliver the service.

Card data

Payments are processed by our payment provider using their hosted payment fields. Allvio does not see, transmit, or store full card numbers, and we never store CVVs or PINs.

Suppliers who help us run Allvio

Some suppliers handle information on our behalf, and a few of them operate overseas. A current list of those suppliers, what they handle and where they operate, is available on request from privacy@allvio.com.au.

If a breach ever happens

We have a written breach response process aligned to the Notifiable Data Breaches scheme. If your data is involved, we tell you, and we tell you what we know rather than waiting until we know everything.

Getting your data out

While you are with us

Ask us for an export of your data at any time and we will provide it within 10 business days, as Excel files, at no charge. Because an export can contain payroll, tax and banking details, we confirm that the person asking is an authorised contact on the account, we send the file in an encrypted archive through a secure link that only that person can open and which expires, and we send the password separately by text message to a mobile number already on the account. We do not email the file as an attachment.

After you leave

We keep your data for 90 days after your subscription ends so you can still request an export. After that it is deleted.

We would rather you stayed because Allvio works than because your data is stuck in it.

Independent assurance

Penetration testing

Independent penetration testing is scheduled before we process any customer's live data, and at least annually after that. We would rather tell you what is committed than imply it is already done. Once the first test is complete, this section will name the month, the firm, and how findings are tracked.

Vulnerability scanning

Automated dependency and vulnerability scanning is being introduced into our build pipeline before launch, so that a known weakness in a component we rely on is caught before it reaches you.

Backup restoration testing

Documented testing of backup restoration is scheduled before we process any customer's live data, and at least twice a year after that. We describe these three separately from the measures above so you can tell what is already running from what is committed.

The documents

Talk to a person

Security

Found something, or think you have? Email security@allvio.com.au. We will acknowledge within 24 hours, and we will not pursue anyone who reports a genuine issue in good faith.

Privacy

Questions, access requests, or a complaint: privacy@allvio.com.au. We respond within 5 business days.

Anything else

Email support@allvio.com.au or call 1300 556 527, and we will come back to you.

Altren Group Pty Ltd · ABN 32 700 087 332 · Melbourne, Victoria, Australia