Suiviro Legal
Security & Data Protection Policy
Last updated: 20 June 2026
Suiviro is committed to protecting customer, client and business information. This policy explains the security measures used to protect information stored within the Suiviro platform.
1. Scope
This policy applies to Suiviro accounts, client records, job records, staff records, uploaded files, photos, communications, integrations and billing information.
2. Security Principles
- Confidentiality
- Integrity
- Availability
- Accountability
- Least privilege access
3. Data Encryption
Data in transit
All communication between users and Suiviro is encrypted using HTTPS/TLS. This includes website traffic, mobile traffic, API requests and integrations.
Data at rest
Where supported by underlying infrastructure, stored data is encrypted at rest. This includes database records, uploaded files, photos and attachments.
4. Authentication
Suiviro protects access through secure passwords, session management, access controls and user permissions. Future enhancements may include multi-factor authentication, single sign-on and enterprise identity providers.
5. Role-Based Access Controls
Suiviro supports role-based permissions. Typical roles include Owner, Admin, Scheduler, Staff and Viewer. Permissions are limited according to business requirements. Users only access information required for their role.
6. Business Data Isolation
Each business account operates within its own data boundary. Users may only access businesses where they hold an approved membership. Cross-business access is prohibited unless explicitly authorised.
7. Audit Logging
Suiviro maintains activity records including login activity, job updates, client updates, permission changes, notification actions and integration activity. Audit records assist with accountability, troubleshooting and security investigations.
8. Backups
Suiviro maintains backups to support disaster recovery, service continuity and data restoration. Backup schedules and retention periods may vary. Backups are protected using industry-standard security practices.
9. Integrations
Suiviro may integrate with Xero, Google Calendar, Microsoft Outlook, payment providers, email providers and SMS providers. Access is limited to information required to provide functionality. Integration credentials are stored securely.
10. Client Communications
Communications may include emails, SMS, customer portal messages and file uploads. Communication history may be stored within client and job records. Businesses are responsible for ensuring communications comply with applicable laws.
11. File Uploads
Users may upload photos, documents and attachments. Files are associated with the relevant client, job or communication thread. Users are responsible for ensuring uploaded content is lawful.
12. Incident Response
In the event of a security incident, Suiviro may investigate the issue, restrict access, suspend affected services, notify affected users where appropriate, and restore services from backups where necessary.
13. Customer Responsibilities
- Maintaining secure passwords
- Managing user permissions
- Protecting devices used to access Suiviro
- Reviewing staff access regularly
- Reporting suspected security issues promptly
14. Third-Party Providers
Suiviro relies on third-party providers to deliver services. Examples include hosting providers, payment processors, email providers, SMS providers and integration providers. While Suiviro carefully selects providers, their services remain subject to their own security practices and policies.
15. Data Retention
Information may be retained while accounts remain active, for legal compliance, for operational purposes, and for backup and recovery. Retention periods may vary according to the type of information.
16. Security Reviews
Suiviro may periodically review access controls, integrations, security settings and platform vulnerabilities to improve protection of customer data.
17. Reporting Security Concerns
Security concerns should be reported immediately to admin@suiviro.com. Please include a description of the issue, date and time observed, steps to reproduce, and screenshots if available.
18. Changes to this Policy
This policy may be updated periodically. Material updates may be communicated through the platform or website. Continued use of Suiviro constitutes acceptance of the updated policy.
Questions about this document? Email admin@suiviro.com.