Legal

Privacy policy

Book Lab handles health information, so we hold ourselves to a simple standard: collect the minimum, pass it straight to your practice, and keep nothing. This policy explains exactly what that means.

1. Who we are

Book Lab ("Book Lab", "we", "us") is a New Zealand company that provides online booking pages for healthcare practices. A patient uses a practice's booking page to choose an appointment time and enter their details, and Book Lab delivers that booking into the practice's own practice management software.

We are an agency under the Privacy Act 2020, and because booking details are health information, we handle them in accordance with the Health Information Privacy Code 2020. Our privacy officer is Dominic Zolezzi, who can be reached at [email protected].

This policy covers three situations: booking an appointment through a practice's Book Lab booking page, being a practice that uses Book Lab, and visiting this website. It describes all of our data handling practices; there are no others.

2. The short version

  • Booking details are validated and passed to your practice. We do not store them. There is no Book Lab database of patients or bookings.
  • Your medical record lives in your practice's own system, where it always has. Book Lab cannot read it back, and has no feature that could.
  • All of our processing happens in New Zealand.
  • We never use personal information for advertising, profiling, analytics about you, or training AI models, and we never sell it. Nothing is stored, so there is nothing to use.
  • This website sets no cookies and runs no analytics or trackers.

3. If you book an appointment through a booking page

What we collect. Only what the practice needs to create your appointment: your first and last name, mobile number, email address, the service you chose, the appointment time you chose, an optional note from you, and your date of birth where the practice requires it to match or create your record correctly. The booking page tells you at the point of collection what is collected and where it goes.

Why we collect it. For exactly one purpose: to create your booking in your practice's practice management software. We do not use it for anything else. Collection is from you directly, and providing it is your choice; if you prefer not to book online, you can always phone the practice.

What happens to it. Your details are checked for obvious errors, screened by an automated abuse check, and forwarded immediately and securely to your practice's practice management software, which is and remains the authoritative record. Once the booking is delivered, Book Lab keeps no copy. Your information exists in our system only for the seconds it takes to process your request. Appointment confirmations and reminders are sent by your practice's own system, not by Book Lab.

To show you available times, our server reads appointment slot information from your practice's system. That information is used only to work out which times are free, and is not retained.

If something goes wrong. If your booking cannot be delivered, for example because the practice's system is temporarily unavailable, you are shown a message asking you to phone the practice. We do not hold your details and retry later, because holding them would break the no-storage rule this policy is built on.

What we never do with booking information: store it, build a database of it, use it for marketing or analytics, profile you, train AI or machine learning models on it, share it with anyone other than the practice you chose to book with, or send it overseas.

4. Where your information is processed

Book Lab's processing runs on Microsoft Azure in the New Zealand North region (Auckland), in our own environment, with New Zealand residency enforced by technical policy rather than by promise alone. Two infrastructure providers are involved in handling a booking in transit:

  • Microsoft Azure hosts the booking pages and the booking service, in New Zealand. It stores no booking information, because our service stores none.
  • Cloudflare sits in front of our services to protect them from attack and to verify that a booking comes from a person, not a bot. Booking traffic passes through Cloudflare's network, normally its Auckland point of presence. Cloudflare's security logs record technical request metadata; we have deliberately not enabled the setting that would let its firewall capture form contents.
  • Your practice's practice management software receives the booking. From that point the practice is the agency responsible for it, under its own privacy policy and its vendor's safeguards.

Microsoft and Cloudflare are overseas-headquartered companies operating New Zealand infrastructure, and each holds independent international security certifications. No other third party, and no analytics platform, advertising service or AI service, has access to booking information.

5. If your practice uses Book Lab

We hold ordinary business information about the practices we work with: contact names, roles, email addresses and phone numbers, correspondence, agreements and invoices. We use it to provide and support the service, and we keep it for the life of our relationship and for seven years afterwards, in line with normal business record keeping. We do not hold your patient list, your appointment book or your clinical records; those stay in your own systems.

6. If you visit this website

This website sets no cookies, runs no analytics, and includes no third-party trackers, scripts or advertising. We do not collect information about your visit.

If you use the contact form, we ask for your name, practice name, email address, practice management software, and optionally a phone number and message. That information is sent to our mailbox as an email so we can reply to you, and is not stored by the website or used for any other purpose. We use a New Zealand-suitable email delivery provider (SMTP2GO) to carry that one email. If you would rather not use the form, you can email us directly.

7. Logs

Our systems keep operational logs so we can run the service securely and diagnose faults. These logs are engineered not to contain personal information: they record outcomes, such as which practice a request was for, whether it succeeded, and a machine reason if it did not, and they never record names, contact details, dates of birth or the contents of what you typed. Operational logs are kept for up to 12 months and then deleted.

8. Security

Booking information is encrypted in transit at every step, and the service is protected by layered controls including attack protection at the network edge, rate limiting, strict server-side validation, and automated abuse checks, with independent security testing as part of our programme. There is more on our approach on the security page, and a detailed confidential security statement, with verification evidence, is available on request to practices, insurers, auditors and privacy officers with a legitimate need to assess it.

Our strongest safeguard is structural: we do not store patient information, so there is no Book Lab database of patient data to breach.

9. Your rights: access and correction

Under the Privacy Act 2020 and the Health Information Privacy Code 2020 you have the right to access the personal and health information an agency holds about you, and to ask for it to be corrected.

Because Book Lab does not retain booking information, your booking and your medical record are held by your practice, and the fastest way to see or correct them is to contact the practice directly. You are equally welcome to contact us at [email protected]: we will respond within 20 working days, tell you honestly what we hold, which for patients is normally nothing, and help you reach the right place.

10. If something goes wrong

If we become aware of a privacy breach involving information we handle, we will contain it, assess it against the notification threshold in the Privacy Act 2020, and where the breach is notifiable, notify the Office of the Privacy Commissioner and the people and practices affected without undue delay.

If you have a concern about how we have handled your information, please contact our privacy officer first at [email protected]; we take complaints seriously and will respond promptly. You also have the right to complain to the Office of the Privacy Commissioner: privacy.org.nz or 0800 803 909.

11. Changes to this policy

If our data handling practices change, we will update this policy before the change takes effect, and the current version will always live at this page. We will not change the fundamentals quietly: collecting the minimum, storing nothing, and processing in New Zealand are design commitments, not preferences.

This policy was last updated on 28 September 2026.

Questions

Anything unclear?

Privacy questions get straight answers here. Ask us anything about how booking information is handled.

Or email [email protected]