Dealer-grade security, built for Australia

What we do with your dealership’s data, how we protect it, and exactly what happens when you leave. The whole story, on one page — no fine print.

01 · Data residency

Hosted in Australia. Full stop.

All data is hosted in Australia (Supabase AU region). It is never transferred offshore, and it is never used for AI training outside your dealership’s context — your customer data trains nothing.

02 · Encryption & isolation

Locked in transit, at rest, and between dealers

  • Encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Database access restricted by row-level security per dealership — no cross-dealership data exposure is architecturally possible
  • Credentials never stored in plaintext

03 · ACMA + Privacy Act

Compliance is enforced in code, not in a manual

  • Mandatory opt-out on every first message
  • Contact hours enforced server-side: Mon–Fri 9am–8pm, Sat 9am–5pm, no Sundays
  • DNC register check before every voice call
  • Complete audit trail of every message, call, opt-out, and compliance event — exportable for ACMA queries in minutes
  • Independent AU legal review of disclosure standards (ACL s18 + Privacy Act)

04 · AI transparency

Your customers always know it’s an AI

Every first message identifies as a virtual assistant — “Hi, this is [Salesperson]’s virtual assistant from [Dealership]…” The disclosure is hardcoded and validated before every send; it cannot be bypassed by configuration. Customers always know they’re talking to an AI, and can be connected to a human at any point.

This satisfies Australian Consumer Law s18 (no misleading conduct) and Privacy Act obligations. Reviewed by an AU lawyer.

05 · Your data is yours

Leave whenever you like — and take everything

  • Month-to-month, cancel anytime
  • Full CSV export on cancellation, delivered within 7 days
  • All data deleted from our systems within 30 days of cancellation
  • No vendor lock-in, no exit fees, no contract

06 · Founder accountability

A person answers for this, not a ticket queue

  • Founder personally responsible for security incidents
  • Direct contact: hello@revlos.com.au
  • Response within 24 hours for security concerns

Still have questions? Ask the founder.

Security questions deserve straight answers from the person accountable for them — not a support queue.