Policies
Clear terms for data, AI, and service use.
Review how Fsterbook handles personal information, customer responsibilities, AI-assisted drafts, retention, security, support, and account use.
Policies
Legal, privacy, AI, and data policies
These policies are written for an Australian booking software and AI notes platform. They are a practical launch set and should be reviewed by an Australian lawyer before production use.
Privacy Policy
Last updated: 18 June 2026. Fsterbook collects, uses, stores, and discloses personal information to provide booking, scheduling, reminders, client management, payments, support, and AI-assisted documentation services.
Information we may process includes account details, practitioner and staff details, patient or client contact details, appointment history, notes entered by authorised users, uploaded files, messages, invoices, payment status, device and log data, and support communications. Health information is treated as sensitive information where applicable.
We use this information to operate the service, secure accounts, send transactional appointment messages, support customers, improve reliability, meet legal obligations, and process AI-assisted drafts when enabled by an authorised user.
Customers are responsible for ensuring they have authority to enter patient or client information into Fsterbook and to configure their own privacy notices, consent flows, retention settings, and exports. Fsterbook does not sell patient or client information.
Individuals may request access, correction, export, or deletion through the relevant business or by contacting Fsterbook support where Fsterbook is the relevant account holder. Some records may need to be retained where required by law, professional obligations, billing, security, or dispute handling.
Terms of Service
Fsterbook provides software for online booking, calendar management, client records, reminders, billing workflows, and optional AI-assisted note drafting. It is not a medical provider and does not provide professional advice, diagnosis, treatment, emergency support, or professional supervision.
Customers must maintain their own professional registrations, insurance, consent processes, record obligations, billing terms, refund terms, and compliance with applicable Australian laws and professional standards.
Users must keep login credentials secure, only access information they are authorised to access, maintain accurate account details, and avoid using Fsterbook for unlawful, harmful, misleading, or unsafe purposes.
Fsterbook may update, suspend, or restrict parts of the service to protect security, reliability, legal compliance, or other users. Paid subscriptions, failed payment handling, trials, promotions, upgrades, downgrades, and cancellations are managed through the billing settings and payment provider terms.
AI Terms and AI Disclaimer
AI features generate draft content only. AI outputs can be incomplete, inaccurate, outdated, biased, or unsuitable for a particular patient, client, or professional context.
Practitioners must review, edit, verify, and approve all AI-generated content before it is saved, sent, copied into a patient record, or relied on. AI must not be used as the sole basis for diagnosis, treatment, triage, urgent care, referral decisions, or professional judgement.
Fsterbook does not diagnose patients, recommend treatment, or replace practitioner review. Customers remain responsible for professional decisions, record accuracy, patient or client communication, consent, and compliance with their professional obligations.
When AI is enabled, relevant prompts, source notes, generated drafts, user edits, timestamps, and audit events may be processed to provide the feature, investigate support issues, and improve safety and reliability where permitted by law and account settings.
Data Processing Agreement
For customer data, the customer is generally the controller or accountable service provider for the information it enters, and Fsterbook acts as a service provider processing data on the customer's instructions.
Fsterbook processes customer data to provide the subscribed services, support the account, maintain security, troubleshoot issues, create backups, meet legal requirements, and use approved subprocessors. Fsterbook will not use customer data for unrelated advertising or sale.
Fsterbook applies administrative, technical, and organisational measures designed to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Customers must configure user access, exports, retention, and client-facing notices appropriately.
On termination, customers may request export of available records. After the account closes, Fsterbook may retain backup, audit, billing, legal, or security records for limited periods before deletion or de-identification.
Cookie Policy
Fsterbook may use essential cookies or local storage for login sessions, security, preferences, and service operation. Optional analytics or marketing technologies should only be enabled with appropriate notice and consent where required.
Users can control many cookies through browser settings. Disabling essential cookies may prevent login, booking, account security, or preference features from working properly.
Security, Backup, and Disaster Recovery Policy
Fsterbook uses role-based access controls, authentication safeguards, audit records, monitoring, error logging, least-privilege access practices, and secure operational procedures.
Operational targets include daily database backups, periodic restore testing, local backup tooling for operators, incident review, and disaster recovery procedures designed to restore service after infrastructure, data, or deployment incidents.
No internet service can guarantee uninterrupted availability or perfect security. Fsterbook will investigate security incidents, take reasonable containment steps, and notify affected customers where required by law.
Data Retention, Deletion, and Portability Policy
Customer data belongs to the customer or the relevant patient/client as determined by applicable law, professional obligations, and the customer's own terms. Fsterbook does not claim ownership of customer records.
Customers can export supported patient, client, appointment, billing, and record data from available export tools or by support request. Export format and completeness may depend on the account plan, feature area, and technical availability.
Retention periods can vary by data type, account setting, legal requirement, backup cycle, billing history, audit need, and dispute risk. Deleted records may remain in backups for a limited period before cycling out.
If a customer terminates its account, the customer should export records before closure. Fsterbook may remove or de-identify inactive account data after required retention and recovery periods.
Subprocessor List
Fsterbook may use subprocessors for hosting, database, file storage, authentication, payments, email, SMS, AI processing, monitoring, analytics, support, and backup operations.
Current or planned categories include Supabase or equivalent database infrastructure, Cloudflare or equivalent hosting and edge services, Stripe for payments, Resend or equivalent email delivery, Twilio or ClickSend for SMS, OpenAI or equivalent AI services, and operational logging or support providers.
Subprocessor locations, services, and vendors may change as the product develops. Customers may contact support for the current list before entering regulated or sensitive production data.
Support, Refund, Cancellation, and Acceptable Use Policy
Support is provided through the in-app support tools or contact channels listed on the website. Response times may vary by plan, severity, timezone, and early-access status.
Subscriptions renew until cancelled. Cancellations usually take effect at the end of the current billing period unless stated otherwise. Refunds are assessed case by case, including duplicate billing, technical faults, or legal requirements. Prepaid fax credit does not expire and is non-refundable except where a refund is required by law.
Users must not upload unlawful material, misuse patient or client information, attempt unauthorised access, interfere with service operations, send spam, scrape the service, bypass usage limits, or use Fsterbook to create unsafe, discriminatory, deceptive, or abusive workflows.
SMS, Email, Trial, Failed Payment, and Promo Policy
Transactional appointment messages may be sent where configured by the customer and permitted by law. Marketing SMS or email requires appropriate consent and must include a functional unsubscribe process where required.
Customers are responsible for message templates, recipient consent, opt-out handling, sender identification, and ensuring appointment reminders do not disclose unnecessary sensitive information.
Trials, discounts, and promo codes may be limited by account, plan, region, time, and eligibility. Failed payments may result in retry attempts, service restrictions, downgrade, suspension, or cancellation after notice where practical.
Customer Questions
Who owns our data? Your business keeps ownership of customer records, subject to patient or client rights and applicable law.
What happens if we leave? Export your records before closure. After termination, remaining data may be deleted, de-identified, or retained only for backup, legal, billing, audit, or security reasons.
How often are backups run? The operational target is daily database backup with periodic restore testing.
Where are servers located? Hosting region depends on the production infrastructure selected for the account. Ask support for the current region before entering regulated production data.
Can we trust AI notes? AI notes are drafts only. A qualified practitioner must review and approve every note.
Can we export patient records? Yes, supported records can be exported through available tools or support request.
What if the service is down? Fsterbook monitors incidents and works to restore service using operational recovery processes. Customers should keep their own continuity procedures for urgent operations.