Effective 1 August 2026 · Version 1.0 · Altren Group Pty Ltd ABN 32 700 087 332 trading as Allvio
We take privacy seriously. This policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to everyone who visits allvio.com.au, uses the allvio platform, or interacts with us. It is written to meet our obligations under Australian privacy law.
allvio is operated by Altren Group Pty Ltd ABN 32 700 087 332, a technology company based in Melbourne, Victoria, Australia ("Allvio", "we", "us", "our"). We build and operate an all-in-one business management platform for Australian venue businesses, including restaurants, cafés, salons, and wellness centres.
For any privacy-related questions, requests, or complaints, email privacy@allvio.com.au. We aim to respond to all privacy enquiries within 5 business days.
Because allvio is a platform used by businesses to manage their own customers, we handle personal information in two distinct ways.
If you are an end customer of a business that uses allvio (for example, you made a reservation at a restaurant that runs on our platform), your privacy concerns about that data should be directed to that business in the first instance. We will cooperate with reasonable requests from businesses to help them meet their own obligations under the Privacy Act 1988 (Cth).
3.1 When you visit our website we automatically collect your IP address and approximate location, browser type, operating system and device type, pages visited and referring URLs, and cookies and similar tracking technologies (see Section 10).
3.2 When you create an account or start a trial we collect identity and contact information (name, email, phone), business information (name, type, location, ABN/ACN), billing and payment information (processed securely by our payment provider; we do not store full card numbers), and anything else you choose to provide during registration. We collect only what is reasonably necessary to create and manage your account.
3.3 When you use the platform we collect operational data generated by the modules you use (sales, orders, reservations, financial records, staff records, inventory), usage data (features accessed and when), device and session information, support and communications data, and any feedback or testimonials you provide voluntarily. As we add new modules over time, we may collect additional categories relevant to those features, and will update this policy where the difference is material.
3.4 When you order hardware we collect your delivery address, contact name and phone number, and payment details for the purchase or instalment plan.
3.5 When you contact us we collect your name, email, any information in your message, and the record of our correspondence.
3.6 From third parties we may receive information from payment processors, identity verification services, and public sources such as ASIC (to verify ABNs and business details).
Under the Australian Privacy Principles, we may only collect and use personal information for purposes that are reasonably necessary for our functions and activities, handled fairly and without being unreasonably intrusive. The main reasons we collect and use personal information:
We collect only the personal information that is reasonably necessary for the purposes above, never on the chance it might be useful later. If you are in the EEA or UK, you also have the right to object to processing based on legitimate interests (see Section 8).
We keep personal information only as long as reasonably necessary, or as required by Australian law. Our practice:
At the end of the applicable retention period, we securely delete or anonymise your personal information. If you request deletion earlier, we will comply to the extent permitted by law (see Section 8).
We do not sell your personal information. We share it only with:
6.1 Our service providers: cloud infrastructure (hosting/storage/compute), payment processing, email and communications, analytics (anonymised), customer support tools, accounting and invoicing, and monitoring/security. Providers may only use your information for the purpose we engage them for and are contractually bound to protect it. A current list is available on request at privacy@allvio.com.au.
6.2 Business transfers: if Allvio is involved in a merger, acquisition or sale of assets, your information may transfer as part of that transaction. We will notify you before it becomes subject to a different privacy policy.
6.3 Legal requirements: where required by law, court order, or to protect the rights, property or safety of Allvio, our customers or the public, notifying you where permitted.
6.4 With your consent: for example, agreeing to be featured in a case study or reference.
Some service providers are located overseas (potentially including the United States and the United Kingdom). Under APP 8, before disclosing information overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles: contractual protections consistent with the APPs, only engaging providers in jurisdictions with comparable protection, and limiting shared information to what is strictly necessary. By using allvio you consent to this; if you do not, contact privacy@allvio.com.au before using the platform. EEA/UK users: we use standard contractual clauses where required and you may direct complaints to your local supervisory authority.
We respond to any privacy request within 30 days.
To exercise any of these rights, contact privacy@allvio.com.au. We may ask you to verify your identity first. Access and correction are free unless a request is voluminous or complex, in which case we will agree a fee with you in advance. We never charge just for lodging a request.
Our security measures include encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 or equivalent), logical isolation of customer data within our multi-tenant architecture with row-level security, role-based access controls, multi-factor authentication for staff accessing production systems, regular independent security assessments and penetration testing, staff security awareness training, a defined incident response plan, and regular tested backups.
No security system is impenetrable. Under the Notifiable Data Breaches scheme we are required to notify you and the OAIC as soon as practicable after a breach likely to cause serious harm; we aim to notify within 72 hours as good practice.
We use essential cookies (required for the site/platform to function), analytics cookies (anonymised usage patterns), preference cookies (remembering settings across sessions), and marketing cookies (only with your consent). You can set your preferences via the cookie settings link in our footer, or disable cookies in your browser, though this may affect functionality. Some cookies are set by third parties such as analytics providers, and we have contractual controls limiting how they use your data.
The allvio platform and website are intended for businesses and adults. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently done so, contact privacy@allvio.com.au and we will delete it as quickly as possible.
We only send marketing communications where we have your consent or a legitimate interest (for example, related products for existing customers). Every marketing email includes an unsubscribe link; you can also opt out by emailing privacy@allvio.com.au or updating your account preferences. We process opt-outs within 5 business days. Opting out of marketing does not affect transactional communications like invoices, security alerts and service updates. We comply with the Spam Act 2003 (Cth).
If a business using allvio collected your personal information through our platform (for example, your reservation details at a restaurant), that business is the data controller and we process it on their behalf. Direct any access, correction or deletion request to that business; we will cooperate to help them respond. If you cannot reach the business, or they direct you to us, contact privacy@allvio.com.au and we will assist where reasonably possible.
Our website and platform may link to third-party websites, services and integrations. This policy applies only to allvio; we are not responsible for third-party privacy practices, so review their policies before providing your information.
We may update this policy from time to time. For a material change, we will notify you by email at least 30 days before it takes effect and post the updated policy at allvio.com.au/privacy with a new effective date. If a change requires your consent, we will ask for it first.
This policy is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Notifiable Data Breaches scheme, and the Spam Act 2003 (Cth), and applies the GDPR/UK GDPR where relevant. If we haven't resolved your concern to your satisfaction:
Privacy Officer: privacy@allvio.com.au · General enquiries: hello@allvio.com.au · Support: support@allvio.com.au · 1300 556 527
We are committed to resolving privacy concerns promptly and transparently, and aim to respond to all privacy enquiries within 5 business days.