ISO 27001 Certified Security Management ISO 27001 Certified Security Management ISO 27001
SOC 2 Type 2 Attested SOC 2 Type 2 Attested SOC 2
OpenID Connect Certified Identity Provider OpenID Connect Certified Identity Provider OpenID
Legal

Privacy Policy

Effective 20 July 2026 · Last updated 20 July 2026

Avion Software Pty Ltd (“Avion”, “we”, “us” or “our”) respects your privacy and is committed to handling personal information responsibly, transparently and securely.

This Privacy Policy explains how we collect, use, disclose and protect personal information when you visit our websites, contact us, use our customer support services, attend our events or otherwise interact with Avion.

1. Who we are

Avion develops and operates Avalon, an enterprise engagement platform, and provides digital platform implementation, managed Azure hosting and application management services.

Legal entity: Avion Software Pty Ltd
Registered address: Level 25, 100 Mount Street, North Sydney, NSW 2060
Privacy contact: privacy@avionsoftware.com

2. Scope of this policy

This policy applies to personal information handled through our public websites; sales, marketing and business-development activities; customer and technical-support interactions; events, briefings and demonstrations; supplier and partner relationships; and recruitment activities.

Where Avion processes personal information within Avalon or another managed service on behalf of a customer, that customer generally determines how and why the information is processed. Questions about information held in a customer-controlled system should ordinarily be directed to that customer. Our contractual data-processing and security obligations apply to those services.

3. Personal information we collect

Contact and business information

  • Name, job title and organisation

  • Business email address and telephone number

  • Country or region

  • Information included in an enquiry or meeting request

Customer and support information

  • Account and organisation details

  • Support requests and correspondence

  • Technical, diagnostic and incident information

  • Records of demonstrations, meetings and service interactions

Website and technical information

  • IP address

  • Device and browser information

  • Pages visited and interactions with our website

  • Referral source

  • Approximate location derived from network information

  • Cookie and consent preferences

Marketing information

  • Communication preferences

  • Event attendance and content downloads

  • Responses to campaigns and communications

Recruitment information

  • Résumé or curriculum vitae

  • Employment history and qualifications

  • Professional references

  • Information provided during recruitment

Please do not provide sensitive information unless it is necessary and we have requested it.

4. How we collect information

We collect personal information directly from you; through website forms, email, telephone and meetings; through customer and support portals; from your organisation; from authorised partners and service providers; from publicly available professional sources; and through cookies, analytics and similar technologies where permitted.

5. Why we use personal information

We may use personal information to respond to enquiries; arrange discovery conversations and tailored demonstrations; provide, operate and support our products and services; manage customer, supplier and partner relationships; investigate incidents and maintain service security; improve our website, products and customer experience; provide requested content and communications; conduct appropriate business-to-business marketing; meet legal, regulatory, audit and contractual obligations; establish, exercise or defend legal claims; assess employment applications; and prevent fraud, misuse and security threats.

Where applicable, we rely on consent, performance of a contract, compliance with legal obligations, legitimate business interests or another lawful basis available under relevant law.

6. Cookies and similar technologies

Our website uses cookies and similar technologies for security, essential functionality and analytics that help us understand and improve website performance. Strictly necessary technologies operate automatically because they are required for the website to function.

Where consent is legally required for optional analytics or marketing technologies, we will provide appropriate consent controls. You can also manage or disable cookies through your browser settings, though some features may not function correctly if certain cookies are disabled.

7. Marketing communications

We may send relevant business communications where you have requested them or where otherwise permitted by law. You may unsubscribe using the link in a marketing email or contact us at privacy@avionsoftware.com. We may retain limited information to ensure that your opt-out preference is respected.

8. How we disclose information

We may disclose personal information to Avion related entities and regional operations; hosting, cloud, security and technology providers; communications, analytics and marketing providers; professional advisers, auditors and insurers; authorised implementation and delivery partners; government authorities, courts or regulators where required; and a purchaser or successor in connection with a proposed or completed corporate transaction.

We require service providers to handle personal information only for authorised purposes and with appropriate safeguards. We do not sell personal information.

9. International processing

Avion operates across Australia, Singapore, Malaysia and the UAE and uses technology and service providers that may process information in other locations. Where personal information is transferred internationally, we take reasonable steps to ensure appropriate contractual, organisational and technical safeguards apply, as required by relevant law.

10. Security

We use administrative, physical and technical measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These measures include access controls, security monitoring, encryption where appropriate, incident-management processes and supplier-security assessment.

No method of transmission or storage is completely secure. If we identify a data breach, we will investigate and provide notifications where required by law.

11. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to satisfy legal, contractual, accounting, security and audit requirements. Information that is no longer required is deleted, destroyed or de-identified where appropriate.

12. Your rights

Depending on your location and applicable law, you may have rights to request access or correction; request deletion or restriction; object to certain processing; withdraw consent; opt out of marketing; request information about international transfers; or lodge a privacy complaint. These rights may be subject to legal limitations or exceptions.

To make a request, contact privacy@avionsoftware.com. We may need to verify your identity before responding.

13. Automated decisions

Avion does not use personal information collected through this public website to make solely automated decisions that have a significant legal or similarly significant effect on individuals. If this practice changes, we will update this policy and provide any notice required by law.

14. Children

Our public website and enterprise services are not directed to children. We do not knowingly collect children’s personal information through this website without appropriate authority or consent.

15. Privacy complaints

Privacy Officer
Avion Software Pty Ltd
Level 25, 100 Mount Street, North Sydney, NSW 2060
privacy@avionsoftware.com

Please describe your concern and provide sufficient information for us to investigate it. We will acknowledge and respond within a reasonable period. If you are not satisfied with our response, you may have the right to contact the privacy or data-protection regulator in your jurisdiction, including the Office of the Australian Information Commissioner.

16. Changes to this policy

We may update this Privacy Policy to reflect changes to our practices, technologies or legal obligations. The current version will be published on this page with its effective date. Material changes may also be communicated through an additional notice where appropriate.