Remedial massage that changes how you move through the day.

Privacy Policy

as of 24th July 2026

Yes&Plus Pty Ltd t/a Rebooter

ABN: 39600623845

Version: 2.0   Last reviewed: 11th August 2026

Rebooter is a company committed to providing quality massage therapy services. This policy explains how we collect, hold, use, and disclose personal information, in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). A copy of the Australian Privacy Principles can be accessed from the website of The Office of the Australian Information Commissioner (OAIC) at http://www.oaic.gov.au/.

This policy applies to all clients, prospective clients, and visitors to our website or clinic.

Our main functions and activities involving personal information are:

  • providing massage therapy services and other associated manual therapies covered under the Association of Massage Therapists (AMT)
  • managing client records, bookings and payments
  • operating our website
  • sending appointment reminders, follow-up care information, or occasional marketing communications where you have opted in to receive them.

If you have a concern about how we have handled your information, contact me first using the contact details at the end of this policy.

 

Summary

  • We collect personal information, including health information, to provide massage therapy services to you safely and effectively.
  • We also collect sensitive information via an AI transcription tool ("Splose AI") used during consultations if you consent to this. Audio recordings and AI-generated notes are stored by splose AI, and any recordings are automatically deleted by 5pm the same day as the treatment. 
  • We keep your information secure and only share it with others (like your GP or another health professional) if you ask us to, or if the law requires it.
  • We store your information using data encrypted via SSL in transit and encrypted at rest using industry-standard AES-256 encryption.
  • Data is stored in Australia in line with Government regulations.
  • All data is stored redundantly at AWS data centres to ensure availability, and is backedup hourly.
  • You can ask to see or correct your information at any time.

 

What information we collect

Depending on how you interact with me, we collect:

Personal information

  • Full name, date of birth, contact details (phone, email, postal address)
  • Emergency contact details
  • Payment and billing information for invoicing purposes. We do not store full card details.
  • Booking history and appointment preferences.

Sensitive information (health information)

We collect more detailed health information because it is necessary to provide safe and effective treatment. This includes:

  • relevant medical history, current injuries, conditions, medications, allergies, and pregnancy status
  • details you provide during consultations about symptoms and treatment goals
  • clinical notes we make during and after your treatment. With consent, some clinical notes are generated with the assistance of an AI scribe tool, which transcribes and/or summarises our consultation
  • referrals or reports from other health practitioners where relevant and with your consent.

We only collect health information that is relevant to providing you with safe treatment. We will not ask for more than we need.

 

How we collect personal and sensitive information

We collect information directly from you through:

  • online or phone bookings
  • intake/consultation forms
  • conversations during consultations and treatment
  • email or text message correspondence
  • our website.

We also collect information indirectly, for example:

  • via a referring health practitioner, if you’ve asked them to share relevant information with me
  • via a third-party booking platform Splose.

We will always try to collect information directly from you unless it is unreasonable or impractical to do so.

When we collect personal information, we will explain why we are collecting it and how we plan to use it, unless it is already clear from the context

 

How we hold and protect your information

Storage

We store your personal information using

  • Splose
  • Paper intake forms, kept in a locked filing cabinet at our clinic

Audio recordings and AI-generated notes are stored by Splose, which has its own security measures. Recordings are automatically deleted by 5pm the same day.

When your personal information is no longer needed for the purpose it was collected, we will take reasonable steps to destroy or permanently de-identify it. However, your personal information will be retained in your client file for a minimum of 7 years after your last appointment, in line with health record-keeping requirements.

 

Security

We take reasonable steps to protect your information from misuse, loss, unauthorised access, or disclosure, including:

  • password-protecting digital devices and software accounts, including multi-factor authentication
  • storing paper records in a securely locked location, not accessible to the public
  • limiting access to your information to the treating practitioner only, who is bound by confidentiality obligations
  • using reputable software providers with their own security safeguards.

 

How we use your personal and health information

We use your personal and health information to:

  • assess your suitability for treatment and identify any contraindications
  • provide, plan, and tailor your treatment
  • manage bookings, reminders, and rescheduling
  • process payments and issue invoices/receipts
  • communicate with you about appointments, follow-up care, or relevant business updates, where you haven’t opted out
  • comply with our legal, insurance, and professional association obligations (for example. record-keeping requirements).

We do not use or disclose your health information for marketing purposes without your express consent.

 

Who we share your information with

We only share your information with the following third parties and only in the circumstances stated below:

  • other health practitioners involved in your care but only with your consent (e.g. providing a report to your GP if you ask me to)
  • our accountant or bookkeeper, limited to information necessary for invoicing and tax purposes
  • our professional indemnity insurer, if a claim arises
  • relevant authorities, if required by law (e.g. a court order, or mandatory reporting obligations).

 

Overseas disclosure

We use Splose to manage bookings and clinical records. Splose stores or processes data on servers located in Australia in line with Government regulations. See https://splose.com/resources/security for more details

We may use Splose AI during consultations to record and process what is discussed for the purpose of generating clinical notes. Audio recordings and transcripts are stored in servers located in New South Wales, Australia. We have taken reasonable steps to confirm that Rebooter has appropriate privacy and security safeguards in place.

We do not send or disclose your personal information to recipients located outside Australia.

 

Accessing and correcting your information

You can ask to access the personal information we hold about you, or ask me to correct it if it is inaccurate, out of date, or incomplete. To make a request, you can contact me using the details at the end of this policy. We will respond within a reasonable time (usually within 30 days).

There is no charge for requesting access or correction. If producing a copy involves significant time or cost, we may charge a small administrative fee. We will also require identification from you before releasing any requested information.

 

How to make a complaint

If you believe we have breached your privacy or mishandled your personal information, please contact me first using the details below. We will:

  • acknowledge your complaint within a reasonable time
  • investigate the issue and respond with an outcome, generally within 30 days
  • take reasonable steps to resolve the matter.

If you are not satisfied with our response, you can escalate your complaint to the Office of the Australian Information Commissioner.

 

Contact details

For any questions, access/correction requests, or complaints about this policy:

Eric Vigo

Yes&Plus Pty Ltd t/a Rebooter

Phone: +61 431 749 550

Email: info@rebootergroup.com.au

Postal address: Level 3, 22 George Street, North Strathfield NSW 2137 Australia

Changes to this policy

We will update this policy to reflect changes in our practices or legal obligations. The most current version will always be available at https://rebootergroup.com.au/privacy or on request. This policy was last reviewed on 11/08/2026

Loading...
Verified by MonsterInsights