Privacy Policy and Data Handling in Allo Messaging
Learn what data Allo processes, how messages travel over the local radio mesh, and how to contact the Allo team with privacy questions.
Allo is designed with a clear separation between radio mesh traffic — the messages your team exchanges in the field — and the management data that flows through the Allo web dashboard. Understanding that separation helps you assess how Allo fits within your organisation's data governance and privacy obligations.
This page provides a plain-language overview of Allo's data practices. For the complete and legally authoritative statement of how Allo collects, processes, stores, and protects personal data, refer to the official Allo Privacy Policy, available at allo-messaging.com. In the event of any conflict between this page and the official policy, the official policy takes precedence.
What data Allo processes
Allo processes data in two distinct contexts: account and management data handled through the dashboard, and radio mesh traffic that stays on-device and on-network.
Account and management data
When an organisation is set up in Allo and users are invited, the following personal data is processed:
- User account information: name, email address, and the organisation handle (username) assigned to each user
- Device identifiers: unique identifiers assigned to each Allo client device and repeater provisioned to your organisation
- Invitation records: records of invitations sent, accepted, and revoked, including timestamps
- Dashboard access logs: records of administrator login sessions and actions taken in the dashboard
- Group membership: which users belong to which groups within your organisation
This data is stored in Allo's cloud infrastructure and is accessible to authorised administrators through the web dashboard.
Message metadata and delivery records
For the purposes of delivery confirmation and post-exercise reporting, Allo records metadata about message transmission events. This may include:
- The sender and intended recipient(s) of a message (identified by device and user handle)
- The timestamp at which a message was sent and, where confirmed, delivered
- Delivery status (delivered, undelivered, pending)
This metadata is accessible to administrators through Reports and Logs in the dashboard and is used to evaluate communication performance during exercises and operational deployments.
Message content
Message content — the actual text of messages — is transmitted over the local radio mesh and does not pass through Allo's cloud servers. Messages travel directly between Allo client devices via radio. No copy of message content is routed to or stored by Allo's backend infrastructure during transmission.
Because messages travel over radio, they are subject to the physical characteristics of radio communication in the area where your team operates. Message content is not end-to-end encrypted in transit over the radio mesh in the same way that internet messaging may be — your organisation is responsible for defining what information is appropriate to send over any radio-based system.
Dashboard management data
The Allo web dashboard communicates with Allo's cloud servers to manage your organisation. Data that flows through the dashboard — including user invites, device provisioning, group configuration, and delivery logs — does transit Allo's infrastructure. This communication is protected by standard HTTPS encryption.
Administrators should be aware that actions taken in the dashboard (for example inviting a user, removing a user, changing group membership) are logged and may be visible to other administrators in your organisation.
Data retention
Allo retains account and management data for as long as your organisation's account remains active. Delivery log data is retained for a defined period to support post-exercise reviews. For specific retention periods and your rights under the GDPR (including the right to access, correct, or request deletion of your personal data), refer to the official Allo Privacy Policy.
Your rights under GDPR
Allo operates under Dutch and EU data protection law. As a data subject, you have the right to:
- Request access to the personal data Allo holds about you
- Request correction of inaccurate data
- Request deletion of your data, subject to legitimate retention requirements
- Object to or restrict certain processing activities
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated
Requests relating to individual user rights should be submitted through the contact details below.
Contacting the Allo team on privacy matters
If you have questions about how Allo handles personal data, want to exercise your data subject rights, or need to discuss data processing agreements for your organisation, contact the Allo team:
General privacy enquiries
Email the Allo privacy contact for questions about data handling, retention, or your rights under GDPR.
Official Privacy Policy
Read the full Allo Privacy Policy for the complete and authoritative description of data practices.
Organisations running Allo as part of a municipality or safety region pilot programme may have a separate data processing agreement (verwerkersovereenkomst) in place with Allo. Contact your Allo account manager or the privacy contact above to obtain or review your organisation's agreement.