Legal
Privacy Policy
Last updated: 31 August 2026
Magic is a product operated by ForeFront Labs Pty Ltd (ABN 89 698 420 263) ("ForeFront Labs", "we", "us" or "our"). This policy explains how we handle personal information through the Magic website, applications and services. It is designed to describe our practices under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. Other privacy rights may apply depending on a person's location and the business using Magic.
Your data is yours
A business retains ownership and control of the information it places in Magic. We do not sell, rent, broker or trade Customer Data, use it to advertise to that business's clients, or build client lists for another business. We do not separately commercialise Customer Data.
We process Customer Data only to provide, secure and support Magic for that business, carry out its instructions and enabled integrations, meet legal obligations, and prevent misuse. Limited operational information and aggregate statistics may be used to understand and improve Magic, but not to profile or target individual clients.
1. Scope and Data Ownership
"Customer Data" means information a business or its users enter, upload, create or collect through Magic. It includes client records, bookings, messages, notes, forms, photos, documents and business records. A business retains ownership of its Customer Data and gives us only the limited rights needed to operate Magic under our Terms of Service. Individual clients continue to have all privacy rights that apply to their personal information.
2. Information We Collect
We collect account and contact details, business profiles, team and permission records, client records, bookings, forms and responses, documents, photos, invoices, quotes, messages, automations, marketing preferences, integration settings, device and usage information, support requests, and payment status or provider references. Client records may include treatment information, allergies, intake answers or other health-related information a business chooses to record. We do not store full payment-card or bank-account numbers.
3. How We Collect Information
We collect information from account holders, authorised team members and people who use Magic-powered booking, inquiry, form, proposal, portal or payment pages. We also receive information from integrations a business connects, such as calendars, messaging services and payment providers. Where lawful and practical, a person may browse our public website without identifying themselves, but some information is necessary to create an account, make a booking, submit a form, receive a message or process a payment.
If we receive personal information we did not request, we assess whether we could lawfully have collected it. If not, we destroy or de-identify it where lawful and reasonable.
4. How We Use and Disclose Information
We use and disclose information to provide and secure Magic, authenticate users, process subscriptions and connected payments, run customer-requested workflows, deliver communications, provide support, troubleshoot errors, prevent fraud and misuse, maintain backups, comply with legal obligations, and resolve disputes. We disclose Customer Data only to the business that controls it, its authorised users, providers and integrations acting for the service, or another person where the business instructs us or the law permits or requires it.
For platform-level analysis, we may use limited operational data and statistics such as booking counts, feature events, delivery outcomes and system performance. Cross-customer trend reporting uses aggregate results designed not to identify an individual client. We do not use client names, contact details, messages, treatment notes, photos, form answers or health-related information to advertise to or profile individual clients, and we do not attempt to re-identify aggregate information.
5. Businesses Using Magic
A business using Magic decides what client information to collect and how to use it. The business is responsible for giving its clients any collection notices, obtaining consent where required, configuring access appropriately, and using information lawfully. If a business asks us to process its Customer Data, we act to provide Magic to that business. We separately control account administration, security, support, billing and our own consented website marketing.
6. Sensitive Information and Children
Health and treatment information is sensitive. A business should collect it only when reasonably necessary and with the individual's consent or another lawful basis. We process sensitive Customer Data only to provide the requested service and the business's configured workflows; we do not use it for our own direct marketing or cross-customer profiling. Magic business accounts are not intended for children. If a business collects information about a minor through Magic, it is responsible for obtaining any parent or guardian authority required for that service.
7. Booking and Form Progress
When someone actively starts a Magic-powered booking or inquiry form, Magic may save the steps reached, services explored, source information and a random session identifier so the business can understand where enquiries stop. Typed answers are not sent with an unfinished session until the person has entered an email address or phone number. We honour supported browser Do Not Track signals for this feature. The control below stops future unfinished-progress saving on this browser; a person can request deletion of unfinished progress using the contact details below. Information deliberately submitted to the business is still retained as a booking, inquiry or form response.
8. AI Assistance
When an authorised user chooses an AI-assisted feature, Magic may send the minimum relevant prompt and context to the configured business/API AI provider, such as OpenAI or Anthropic, to produce the requested draft, summary or structured result. Context can include recent message text or client details where they are necessary for the request. We limit and bound that context where practical. AI output is a suggestion for the business to review; it cannot independently send a client message or complete a write without the product's normal confirmation or action controls.
We do not use Customer Data to train our own general-purpose AI models and do not opt Customer Data into an AI provider's general model training. AI providers may process or retain limited information for service delivery, security and abuse prevention under their business/API terms.
9. Automated Features
Magic uses software to calculate booking availability, detect duplicates or abuse, apply business-configured booking, deposit, cancellation and no-show rules, trigger reminders and follow-ups, and prepare analytics or suggested actions. These processes may use client, booking, consent, service, payment-status and activity information. The business configures the relevant commercial rules and remains responsible for decisions about its clients and services. AI suggestions do not make final clinical, legal, employment or financial decisions for a person.
10. Service Providers, Integrations and Overseas Processing
Magic uses or may use Supabase and AWS for database and storage; Vercel and Cloudflare for application delivery and security; Stripe for payments; Resend, Twilio and WhatsApp for communications; PostHog and Sentry for limited analytics and diagnostics; OpenAI or Anthropic for enabled AI assistance; and Meta for consented marketing measurement. Some providers are active only when a business enables the related feature.
Information may be processed in Australia and the United States, and in another location made necessary by a business-selected integration or a provider's documented infrastructure. We assess providers and take reasonable steps appropriate to the service to protect personal information handled overseas. Payment details entered into a hosted payment form are processed by the payment provider rather than stored as full card or bank details by Magic.
11. Security and Data Breaches
We use measures including encryption in transit, provider-managed encryption at rest, workspace isolation, row-level security, role and capability checks, rate limits, audit and operational logging where available, data minimisation, redaction, backups, and least-privilege service access. No system can be guaranteed completely secure. We maintain a data-breach response process and will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.
12. Cookies, Analytics and Diagnostics
We use essential cookies and local storage for authentication, session continuity, security, form and booking progress, and product preferences. With a visitor's permission on our marketing website, Google Analytics, PostHog and Meta Pixel may collect page, campaign, device and interaction information so we can measure acquisition and understand which pages lead to early-access enquiries. We do not send the email address or phone number entered in the early-access form to those marketing analytics providers. A visitor can accept, decline or reopen their privacy choices; declining optional analytics does not affect essential site functions.
Optional analytics are off on this browser.
Within the authenticated service, we may record limited account, workspace, feature and performance events needed to operate, secure, support and improve Magic. Diagnostics are configured to minimise or redact personal information where practical. Product analytics and diagnostics are not used to advertise to a business's clients.
13. Marketing Communications
ForeFront Labs markets Magic to business account holders and people who ask to hear from us. A business using Magic is responsible for its own client marketing. Magic records marketing preferences and provides unsubscribe or STOP mechanisms for supported email and SMS workflows. Sensitive information is not used for direct marketing unless the individual has specifically agreed and the use is lawful. A person can withdraw marketing consent at any time without affecting service communications that are still required.
14. Access, Correction, Export and Deletion
A person may request access to or correction of personal information we hold about them. Account holders can access, correct, export or delete workspace data where product controls exist. If the information was collected by a business using Magic, contact that business first so it can action the request through its workspace; we will assist the business where needed. We may verify identity before providing access and aim to respond within 30 days. If we cannot fulfil a request, we will explain why where required and describe available complaint options.
15. Retention
We retain Customer Data while an account is active and for a limited period after closure so the business can recover or export it, followed by deletion or de-identification unless law, security, tax, billing, dispute-resolution or backup requirements justify longer retention. Unfinished booking and form progress is normally deleted after 180 days; a submitted booking, form response or inquiry follows the business's normal record lifecycle. Backup copies expire through the provider's normal backup lifecycle. We retain only the minimum records reasonably required after a deletion request or account closure.
16. Privacy Complaints
Email a written privacy complaint to ak@bridgetoai.com.au. Describe the issue and how we can contact you. We will acknowledge the complaint, investigate it fairly and aim to respond within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
17. Changes and Contact
We review this policy when our information-handling practices change and periodically as part of our privacy and security reviews. We will update the date above and notify account holders of significant changes by email or through Magic where appropriate. For privacy questions, requests, complaints or a copy of this policy in another accessible form, contact ak@bridgetoai.com.au.