ABS TWIN

Acceptable Use Policy

Version 0.9 · Effective date: on publication · Applies to: every Studio subscribing to ABS Twin and the conduct of its Authorised Users, and every configuration, prompt, template, catalogue entry, FAQ, campaign or message created or sent through ABS Twin; incorporated by reference into the Master Subscription Agreement and forming part of the documented method of use of the Service.

Plain-language summary

This summary is written for a studio owner. It is not part of the operative text, and if it differs from the numbered clauses below, the numbered clauses govern.

ABS Twin is a booking and customer-communications system for your own studio's clients. It is not a general-purpose AI assistant, and it must not be used as one — that is not a style preference, it is what keeps your WhatsApp channel alive.

The eight rules that matter most:

  1. Only message people who agreed to hear from you, and keep the proof. We do not hold your consent records for you.
  2. Honour "stop" immediately, in one step, however the person says it — not only when they use a keyword — and never re-add someone without fresh permission.
  3. Do not put medical records, card numbers, Emirates ID numbers or biometrics into ABS Twin. If you are a licensed clinic or medi-spa, talk to us first — you need a separate agreement.
  4. The Assistant must not give medical, cosmetic-suitability, legal or financial advice. It defers to your specialists. Do not configure it to do otherwise.
  5. Do not switch off the AI disclosure or the call-recording announcement. Recording or transcribing someone in the UAE without their consent is a criminal matter, not a paperwork matter — which is why the announcement is built to run before anything is captured, and why you cannot switch it off. The date from which we commit that nothing is captured behind a missing announcement is stated at clause 7.1.2B; clause 7.1.2C says what is captured until then, and your own obligations under clause 7.2 and under the law apply in the meantime.
  6. Keep a human reachable. Every automated conversation must have a route to a person, and that route must actually be staffed.
  7. Do not break the platforms' rules — Meta/WhatsApp, Twilio and our AI providers all impose rules that flow through us to you. Their enforcement lands on your number.
  8. Do not attack, copy or probe the Service, and do not work around the guardrails we build in.

If you break these rules, we will normally warn you first and give you time to fix it. Where the risk is urgent — unlawful activity, a security threat, restricted data, or a platform demanding action — we may act immediately. We aim to use the smallest step that solves the problem, and we will keep your access to your data and to export wherever we reasonably can, and consistent with the reason for the step (clause 13.4).

One thing we will never claim: using ABS Twin does not make your studio compliant. Our guardrails are conveniences, not legal advice, and they do not move your legal obligations onto us.


1. What this Policy is, and who it binds

1.1 Purpose

1.1.1 This Acceptable Use Policy ("Policy", "AUP") sets out the rules for using ABS Twin. It defines the documented method of use of the Service: the way ABS Twin is designed, tested, supported and lawfully operated.

1.1.2 The Policy exists for three reasons, and stating them plainly is deliberate: (a) some of the rules are imposed on Carnelian by Platform Providers and must be passed on to every Studio, failing which Carnelian's own access to those platforms is at risk; (b) some of the rules reflect UAE law that applies to the Studio's own activity — messaging, marketing, recording, health information — where Carnelian supplies the tool and the Studio remains the responsible party; and (c) some of the rules protect the Service, other Studios, and the Guests who talk to the Assistant.

1.1.3 Use of ABS Twin contrary to this Policy is use contrary to its documented method of use, with the consequences set out in clause 14.

1.2 Incorporation and status

1.2.1 This Policy is incorporated by reference into the Master Subscription Agreement and forms part of the Agreement between Carnelian and the Studio. It is also published at https://abstwin.com/legal/acceptable-use so that it is readable before, and independently of, acceptance.

1.2.2 Where a term used here is capitalised but not defined here, it has the meaning given in the Master Subscription Agreement. This Policy does not redefine any term defined in that Agreement.

1.2.3 Order of precedence. The rule of precedence for the Studio's contract stack is clause 2.2.1 of the Master Subscription Agreement, which is the single source for it, and which applies the order in which the documents are listed at clause 2.1.1 of that Agreement subject to its clauses 2.2.2 to 2.2.4. For convenience, and without varying it, that order is:

(1) Order Form — only for the commercial variables and negotiated terms it actually addresses, and subject to clause 1.6 of the Order Form, so that a clause of the Order Form that merely restates a term of the Master Subscription Agreement does not prevail over that Agreement; (2) Restricted / Health Data Addendum — its subject matter only; Parts I, II and IV always (Mode A binds every Studio automatically, signed or not), and Part III only under clause 18 of that Addendum; (3) Data Processing Agreement — data-protection subject matter only; (4) AI & Communications Addendum — artificial-intelligence and communications subject matter and no other; (5) Master Subscription Agreement; (6) Billing Terms & Tax Invoice Template; (7) Refund & Cancellation Policy — only to the extent it states the Studio's refund, cancellation and fee-relief rights, and only on the basis that where that Policy gives the Studio a better right on that subject matter, that Policy applies; (8) Public Sub-processor List — as the operative sub-processor list only, its statements taking contractual effect through the Data Processing Agreement; (9) Service Level Agreement & Support Policy; (10) this Policy; (11) AI & Recording Disclosure — Parts C, D and E only; (12) Staff App Privacy Notice — for the single purpose only, being the notice the Studio must serve under clause 7.8.3 of the Master Subscription Agreement; (13) the Service Description, Documentation and Known Limitations Annex; (14) any Country Addendum — for the jurisdiction it addresses only, except to the extent it gives effect to a mandatory requirement of that jurisdiction's law.

1.2.3A Two rules qualify that order and must be read with it. First, under clause 2.2.2 of the Master Subscription Agreement, each of the Data Processing Agreement, the AI & Communications Addendum and the Restricted / Health Data Addendum prevails over that Agreement only on the subject matter it addresses — data protection, artificial intelligence and communications, and Restricted Data respectively — and on no other. Second, under clause 2.2.2A of that Agreement, no document listed at its clause 2.1.1 varies the limitation of liability at clause 20 of that Agreement unless it says so expressly and is signed by an authorised representative of each party. If the restatement in clause 1.2.3 differs from clauses 2.1.1 and 2.2.1 of the Master Subscription Agreement, that Agreement governs.

1.2.4 Where this Policy states a prohibition and the AI & Communications Addendum states a corresponding warranty or indemnity, the two are complementary: this Policy defines the conduct, the Addendum allocates the consequence. Neither displaces the other.

1.2.5 Carnelian's obligations under this Policy, and any liability arising from them, are subject to clause 20 (limitation of liability) and clause 22 (force majeure) of the Master Subscription Agreement. Nothing in this Policy varies clause 20 of that Agreement.

1.3 Who is bound

1.3.1 This Policy binds the Studio.

1.3.2 The Studio is responsible for compliance with this Policy by each of its Authorised Users as if their acts and omissions were its own, whether or not the Authorised User was invited, provisioned or de-provisioned through the Console.

1.3.3 The Studio must make its Guests aware of the rules in this Policy that affect them — in particular the rules on messaging consent, on recording and AI disclosure, and on what the Assistant will not do. Carnelian provides Guest-facing notice wording in the AI & Recording Disclosure and, for opt-in capture, in the templates annexed to the AI & Communications Addendum.

1.3.4 The Studio must not permit any person who is not an Authorised User to access or use the Service, and must not make the Service available to any third party by resale, sublicence, service-bureau arrangement, shared login, or otherwise.

1.4 Platform Provider terms sit above this Policy

1.4.1 ABS Twin operates over services supplied by Platform Providers — including Meta Platforms / WhatsApp, Twilio, telephony carriers and SIP providers, AI model providers, hosting providers, app stores and payment processors. Their terms bind Carnelian, and several of them bind the Studio directly.

1.4.2 The Studio must accept and comply with the applicable Platform Provider terms as they change from time to time, including the WhatsApp Business Terms, the WhatsApp Business Messaging Policy and the Meta Commerce Policy. Carnelian will make current links to those terms available in the Console, and the Studio is bound by a change to them from the earlier of (a) Carnelian's notification of the change and (b) the Studio's actual knowledge of it. Where a Platform Provider's terms require an action, Carnelian may take that action, including an action described in clause 13. Where a change under this clause is materially adverse to the Studio, clause 16.2A applies.

1.4.3 Platform Providers may change their policies, pricing, approvals, categorisations, quality ratings, rate limits and enforcement practice at any time and without notice to Carnelian. Those changes are outside Carnelian's control, are not a breach by Carnelian, and may require changes to this Policy under clause 16.

1.5 What this Policy is not

1.5.1 This Policy is not legal advice, and ABS Twin does not make the Studio compliant. The guardrails, disclosures, opt-out handling, sending-window controls, consent prompts and audit tooling described in this Policy are product conveniences. They do not constitute advice, do not guarantee compliance with any law or platform policy, and do not transfer any of the Studio's own legal or regulatory obligations to Carnelian.

1.5.2 The Studio remains responsible for obtaining its own advice on the laws applicable to its business, including licensing, advertising, marketing, telecommunications, consumer-protection and data-protection requirements.

1.5.3 Clause 14.3 (savings) applies to this clause 1.5.

1.5.4 No agent may speak for Carnelian. No agent, reseller, introducer, referral partner or other third party has authority to make any representation, warranty, commitment, price, discount, timeline or product claim on Carnelian's behalf. Only the documents listed in clause 2.1.1 of the Master Subscription Agreement, and terms agreed in writing under clause 2.3 of that Agreement, bind Carnelian.

1.6 Operating outside the United Arab Emirates

1.6.1 Where the Studio operates, or messages Guests, outside the United Arab Emirates, additional or different rules apply to consent, direct marketing, permitted hours, health data and cross-border transfers. The Studio remains responsible for identifying and complying with them, and Carnelian may require a country addendum before enabling a channel or feature for that jurisdiction.


2. Definitions used in this Policy

2.1 Capitalised terms not defined below have the meaning given in the Master Subscription Agreement, and that catch-all governs whether or not a term appears in the list that follows. The list is given for the reader's convenience and is not exhaustive: Carnelian, ABS Twin, the Service, the Agreement, Studio (= Customer), Guest, Authorised User, Customer Data, Guest Data, Personal Data, Applicable Data Protection Law, Sub-processor, Platform Providers, Order Form, Fees, Assistant, Console, Staff App, Documentation / Service Description, Marketing Message, Utility Message, Business Day. UAE Telemarketing Regime has the meaning given in clause 1.5 of the AI & Communications Addendum, and references in this Policy to "the UAE telemarketing regime" mean the UAE Telemarketing Regime.

2.2 Restricted Data has the meaning given in clause 2.2 of the Restricted / Health Data Addendum, which is the master text of that definition across the Agreement. Clause 1.1.25 of the Master Subscription Agreement is to be read as conformed to it; where the two differ, clause 2.2 of the Restricted / Health Data Addendum prevails for the subject matter of Restricted Data, both for the prohibition in clause 4.1 of this Policy and for Carnelian's rights in clause 4.3. This Policy does not vary the definition.

2.2.1 The following list is illustrative of that definition, is not exhaustive, and is not itself a definition. It is set out so that a Studio reading this Policy can recognise the categories in practice. Restricted Data typically includes: (a) health data as defined by the UAE federal law concerning information and communications technology in health fields (as amended, supplemented or replaced) and by any health authority having jurisdiction, including any information revealing a person's medical condition, symptom, diagnosis, treatment, procedure, medication, allergy, contraindication, adverse reaction, pregnancy, disability, mental-health status or health status generally; (b) clinical, diagnostic or treatment records, prescriptions, referral letters, laboratory or imaging results, and clinical photography; (c) biometric identifiers; (d) payment card data, including card numbers, card verification values, and any other cardholder data; (e) government identification numbers, including Emirates ID numbers, passport numbers, visa numbers and driving-licence numbers; and (f) any other special-category or sensitive personal data, except to the extent that the particular item is objectively necessary to book, schedule or deliver the specific service the Guest has requested, and is limited to what that purpose objectively requires. That exception is an objective test; it does not reach limbs (a) to (e).

2.2.2 Where this list and clause 2.2 of the Restricted / Health Data Addendum differ, that clause governs.

2.3 Compliance Controls means the product behaviours Carnelian operates to support lawful use, including: the opt-out classification and the suppression flags; the marketing sending-window and frequency controls; the entitlement chain that gates campaign lanes; the deferral behaviour on medical or suitability topics; the catalogue-only pricing rule; the live-availability rule; the deterministic discount engine; the prompt-injection classifier and the treatment of Guest messages as data rather than instructions; and the daily automated transcript audit.

2.3.1 Compliance Controls are descriptions of the current design of the Service. They are not warranties, are not service levels, and are not commitments to maintain any particular control, and they may change in accordance with clause 16. Subject to clause 2.3.1A, nothing in this Policy — and no description of a Compliance Control, or of any other product behaviour described in this Policy, in it — is a representation that a control or behaviour will operate on any occasion, will continue to be offered, or is sufficient for the Studio's own compliance; clause 1.5 applies to each of them.

2.3.1A Clause 2.3.1 does not apply to clauses 7.1.1A, 7.1.2 and 7.1.2A, which are given as obligations of Carnelian and not as descriptions of design. Clause 16 does not permit a change to this Policy that removes or weakens any of them.

2.3.2 Clause 2.3.1 does not permit the Studio to circumvent a Compliance Control. Clause 11.1(i) continues to apply to every control described in this Policy, and to the AI disclosure and any recording announcement, whether or not Carnelian is obliged to maintain it.

2.3.3 Where "Compliance Controls" lives. This clause 2.3 is the only definition of Compliance Controls in the document set, and it is the definition the Agreement uses: clause 18.1(d1) of the Master Subscription Agreement indemnifies Carnelian against a breach of this Policy, "including a breach of any Compliance Control as that term is defined in clause 2.3 of the Acceptable Use Policy". A breach of this Policy is accordingly enforceable through the Agreement's indemnity machinery, in addition to the remedies clause 13 gives on this Policy's own terms.

2.4 Prohibited Vertical and Regulated Vertical have the meanings given in clause 9.

2.5 Platform Data means data obtained by the Studio or by Carnelian from a Platform Provider in connection with the Service, including WhatsApp Business Solution Data.


3. Positioning and permitted use — the scope rule

This clause is the most important operative clause in this Policy. A breach of it puts the Studio's WhatsApp channel, and potentially Carnelian's ability to serve any Studio, at immediate risk.

3.1 What ABS Twin is for

3.1.1 ABS Twin is a booking and customer-communications system that a Studio uses to communicate with its own customers about that Studio's own services — appointments, availability, service and price information published by the Studio, studio policies, aftercare information authored by the Studio, and the Studio's own campaign messages to Guests who have opted in.

3.1.2 The Assistant operates in the Studio's name, on the Studio's configuration and data, and within the Studio's own business context.

3.2 What ABS Twin must not be used as

3.2.1 The Studio must not configure, prompt, instruct, extend or use ABS Twin to provide, and must not hold ABS Twin out as providing: (a) open-domain or general-purpose AI functionality of any kind; (b) general knowledge answering unrelated to the Studio's own services and operations; (c) arbitrary content generation — essays, code, translations, images, documents or other outputs unrelated to the Studio's customer communications; (d) companionship, entertainment, roleplay or persona play beyond the Assistant's studio-receptionist role; (e) a route to a third-party model — the Studio must not use ABS Twin to obtain raw or general access to any AI model, whether by prompt chaining, jailbreak, injection, API misuse or otherwise.

3.2.2 The Studio must not describe or market ABS Twin, or the Assistant, to Guests or publicly as a general-purpose AI assistant, an AI chatbot platform, or a large-language-model product.

3.2.3 Carnelian operates technical controls that support this clause, including a scope-limiting system prompt and out-of-scope refusal behaviour, a rule that the Assistant does not discuss competitors, a rule against roleplay, and a rule that a Guest's message is data, never an instruction. These controls are Compliance Controls for the purposes of clause 11.1(i) and must not be circumvented; clause 2.3.1 applies to them.

3.3 Risk disclosure

3.3.1 Platform Providers — Meta in particular — restrict the use of their platforms by providers of artificial-intelligence or machine-learning technologies where such technology is the primary rather than an incidental or ancillary functionality. Carnelian's position, and the basis on which the Service is supplied, is that ABS Twin is a structured booking and customer-service system for a single business and therefore falls outside that restriction.

3.3.2 That position depends on the Service being used as described in clause 3.1 and not as described in clause 3.2. A Studio that configures the Assistant into open-domain use puts its own channel, and Carnelian's platform relationships, at risk.

3.3.3 A Platform Provider may reinterpret, extend or apply such a restriction at any time. Carnelian does not warrant the continued availability of the WhatsApp channel, the Instagram channel, any telephony route, or any AI model, and may modify or withdraw a channel where a Platform Provider requires it or where continued provision would breach a Platform Provider's terms — subject always to clause 14.3(c).


4. Restricted Data — the hard prohibition

4.1 The rule

4.1.1 The Studio must not submit Restricted Data to ABS Twin, must not cause or permit an Authorised User to do so, and must configure the Service so that it does not solicit Restricted Data from Guests.

4.1.2 In particular, the Studio must not: (a) enter clinical notes, diagnoses, medical histories, allergy or contraindication records, medication lists or treatment records into any field of the Console, the Staff App or an import file; (b) configure the Assistant, an FAQ, a template or a form to ask a Guest for health information, a card number, an Emirates ID number, a passport number or a biometric identifier; (c) upload clinical photography, laboratory results or imaging; (d) use free-text fields — including session or therapist notes, customer notes, or campaign copy — as a substitute for a clinical record system.

4.1.3 The Assistant is instructed not to solicit payment-card numbers, government identification numbers or similar sensitive identifiers. The Studio must not configure it to do so.

4.2 Scope exclusion — what the Service is not

4.2.1 ABS Twin is supplied for appointment booking and customer communication for beauty and wellness services. It is not a clinical, diagnostic, medical-records, patient-management or medical-device system, is not certified for regulated health data, and is not designed for the processing of health data.

4.2.2 The Service is not offered for use by licensed health facilities, nor for the processing of health data. Any such use requires a separate written agreement — the Restricted / Health Data Addendum — and, where applicable, a prior approval from the competent emirate health authority. Absent an executed Restricted / Health Data Addendum, health-facility use is outside the scope of the licence granted under the Master Subscription Agreement.

4.2.3 The Studio represents on the Order Form, and must keep current, (a) the categories of treatment it offers, and (b) whether it holds a licence issued by the Dubai Health Authority, the Department of Health – Abu Dhabi, the Ministry of Health and Prevention or any other health regulator. A change in either must be notified to Carnelian without undue delay.

4.3 What Carnelian may do on discovery

4.3.1 Where Carnelian becomes aware, or reasonably suspects, that Restricted Data has been submitted to ABS Twin, Carnelian may, acting reasonably and proportionately: (a) notify the Studio and require its removal within a stated period; (b) restrict access to the affected record, field or export; (c) quarantine or delete the affected data; (d) suspend the affected feature or channel in accordance with clause 13; and (e) where the volume, sensitivity or persistence of the data warrants it, suspend the account or terminate the Agreement in accordance with the Master Subscription Agreement.

4.3.1A How that right is exercised. Carnelian will exercise 4.3.1(b) or (c) only after giving the Studio the opportunity under 4.3.1(a), unless continued retention would itself be unlawful or would create a material risk of harm to any person. Action under this clause is subject to the Data Processing Agreement, and in particular to its clauses 18.9 and 18.9A: Carnelian will act on notice to the Studio, will consult the Studio first where it is practicable and lawful to do so, will give the Studio an opportunity to export the affected records before deletion except where continued processing would be unlawful, and will not delete data it is required to retain by law, by a regulator, or under a litigation or regulatory hold notified to it.

4.3.2 Carnelian will tell the Studio what it has done and why, unless prohibited by law or by a lawful instruction from a regulator or Platform Provider.

4.3.3 The Studio must not reinstate data removed under this clause.

4.4 Product commitments that make this clause credible

4.4.1 Carnelian will maintain, and document, mechanisms that help a Studio keep Restricted Data out of the Service. Today these include: clinical service flags that are locked and read-only to the Studio; a classification step that forces the Assistant to defer rather than answer a medical or suitability question — on messaging as a classification step; on voice only as an instruction in the prompt, so the classifier capable of producing an automated finding runs on messaging only; and the detection-and-response path committed at clauses 18.9 and 18.9A of the Data Processing Agreement. No field-level guidance in the Console exists today — it is a build commitment listed at clause 4.4.2, and nothing in this clause states or implies otherwise. The classifier is a control on output, not a filter on input: it does not prevent a Guest from typing or speaking health information, does not scan every stored record, and does not detect every instance. Carnelian does not represent that Restricted Data will be detected. Clause 2.3.1 applies to the mechanisms described in this clause.

4.4.2 The following are build commitments, not descriptions of the current build, and must not be represented to any Studio as available until they ship: a configurable health-term detection or redaction control; a "sensitive topic → escalate to a human and do not persist" path; retention minimisation for voice transcripts; an option to disable transcript storage; field-level guidance in the Console — helper text at free-text, import and template-authoring fields on keeping Restricted Data out of the Service; and tooling for the steps in clause 4.3.1(b) and (c) — restriction, quarantine, deletion, and export of an affected record before deletion. Until that tooling ships, a step under clause 4.3.1(b) or (c) is performed manually, and clause 4.3.1A applies to it unchanged.


5. How the Assistant may and may not be used

5.1 No medical or clinical output

5.1.1 The Studio must not configure, prompt or use the Assistant to provide, and the Assistant must not be relied on to provide: (a) medical, diagnostic, therapeutic, dermatological, injectable or aesthetic-procedure, dental, nutritional, pharmaceutical or mental-health advice; (b) a determination of a Guest's suitability for a treatment, or of a contraindication, allergy risk or patch-test outcome; (c) triage of a symptom, condition or adverse reaction; or (d) any statement that a treatment is safe, appropriate or effective for a particular individual.

5.1.2 Deferral, not pre-send review. Where a Guest raises such a topic, the Assistant defers: it declines to advise and offers to arrange a consultation with the Studio's own qualified people. The Studio must staff that route. The Assistant must not be configured to produce clinical output that reaches a Guest without review by a suitably qualified person of the Studio, and the Studio must not attempt so to configure it. Clauses 6.2 and 6.3 of the AI & Communications Addendum govern this subject matter.

5.1.3 The Studio must not use the Assistant to give legal, financial, tax or insurance advice.

5.2 No false or unsubstantiated claims

5.2.1 The Studio must not use ABS Twin — in prompts, FAQ content, service catalogue entries, aftercare text, message templates, campaign copy or the Assistant's persona configuration — to make or imply: (a) health, medical-efficacy, cosmetic-efficacy, anti-ageing or weight-loss claims that the Studio cannot substantiate; (b) claims about the expected results of a treatment that are not supported by evidence the Studio holds; (c) claims of a certification, accreditation, award or quality mark that the Studio does not hold; (d) any statement that is misleading as to price, terms of contracting, warranty, after-sale service or the nature of the service; or (e) any statement or implication that Carnelian endorses, verifies, approves or is responsible for the Studio's services, treatments, practitioners or clinical claims.

5.2.2 Where the Studio makes a quantitative or outcome claim through ABS Twin, it must hold a substantiation file for that claim and produce it to Carnelian, a Platform Provider or a regulator on request.

5.3 Beauty and wellness content rules

5.3.1 The Studio must not use ABS Twin to send, publish or store: (a) before-and-after imagery, body-transformation imagery, or close-ups of body parts presented so as to reinforce insecurity; (b) content presenting diet, weight-loss, weight-gain or health products so as to create negative self-perception; (c) promotion of, or transactions in, medical devices, ingestible supplements, or pharmaceutical or prescription products; (d) content that is discriminatory, sexually explicit, obscene, harassing, threatening or defamatory.

5.3.2 These rules apply to catalogue content and template content as well as to messages, because a Platform Provider reviews both.

5.4 Identity and voice

5.4.1 The Assistant speaks as the Studio. The Studio must not configure it to impersonate another business, a public figure, a regulator, a health professional, or any individual, and must not misrepresent the Assistant as a human being.

5.4.2 The Studio must not use, request or upload a cloned or imitated voice of any identifiable individual without that individual's documented written authorisation, and must not use ABS Twin to misappropriate any person's voice or likeness.

5.5 Emergency limitation

5.5.1 ABS Twin is not an emergency service. The Assistant cannot contact emergency services, cannot summon medical assistance, and must not be relied on to detect or respond to an emergency.

5.5.2 The Studio must not deploy ABS Twin as the only line of contact for urgent medical, safety or security matters, and must not present it to Guests as such.

5.5.3 The Studio must not use the Service to place calls to emergency numbers, to test emergency lines, or to route or direct traffic to any emergency service — including a public-safety answering point, an emergency call centre, a police, ambulance, civil-defence or fire service, a hospital emergency department, or any paging or emergency dispatch service.

5.6 Accuracy of what the Studio configures

5.6.1 The Assistant's outputs depend on the Studio's configuration. The Studio must provide and keep current its services, durations, prices, opening hours, holiday closures, branch details, staff and roster data, policies (including its cancellation policy), and FAQ content.

5.6.2 The Studio is responsible for statements the Assistant makes in its name where those statements are correct given the configuration the Studio supplied. Carnelian is not responsible for an output that is correct given incorrect input.

5.6.3 Carnelian operates controls that limit improvisation: prices are spoken only from the Studio's own catalogue and an absent price stays unspoken; availability is never asserted without a live check in the same conversation; a booking is confirmed only against a real tool result; and where the Studio has left an offer or policy field blank, the relevant lane is skipped and logged rather than invented. Clause 2.3.1 applies to the controls described in this clause.

5.7 No manipulation of the Assistant

5.7.1 The Studio and its Authorised Users must not attempt to bypass, override or subvert the Assistant's instructions, guardrails or refusal behaviour, whether through prompt injection, hidden instructions in FAQ or catalogue text, adversarial inputs, or otherwise.

5.7.2 Carnelian applies a write-time guard to FAQ content the Studio submits for use as Assistant knowledge, and screens inbound Guest messages with a prompt-injection classifier that records a security event and returns a safety response. These are Compliance Controls.

5.8 What the Assistant's output is, and is not

5.8.1 The Assistant is built on probabilistic AI models. Its outputs may be incomplete, inaccurate or wrong, including where the Studio's configuration is correct, and must not be relied on as a statement of fact, as professional advice, or as a substitute for the Studio's own judgement. The Studio must verify anything on which it, or a Guest, would materially rely.

5.8.2 The Assistant acts autonomously on the channels described in Annex 1 to the AI & Communications Addendum: it confirms bookings, reschedules and cancels appointments and sends messages without a human approving each one. Nothing in this Policy represents otherwise, and no clause in it is to be read as saying that the Assistant's outputs are merely suggestions awaiting staff review. The Studio's oversight duty, and the allocation of risk for autonomous operation, are set out in clauses 5 and 9 of the AI & Communications Addendum.


*This clause states the rules. The corresponding warranties, indemnities and evidence obligations sit in the AI & Communications Addendum; they are not repeated here.*

6.1 Opt-in

6.1.1 The Studio may only send a message through ABS Twin to a person who (a) gave the Studio their number or messaging identity, and (b) gave the Studio permission to receive messages of that kind.

6.1.2 Consent must be specific to the subject matter. Separate permission is required for separate categories of message — at minimum, transactional booking messages, appointment reminders, and Marketing Messages. Consent to one is not consent to another.

6.1.3 The consent moment must tell the person, in a language they understand: who is asking (the Studio, by name), how their number or messaging identity will be used, what the messages will be about, and that an AI assistant may handle the conversation.

6.1.4 Carnelian supplies opt-in wording templates (English and Arabic) as an annex to the AI & Communications Addendum. A Studio that writes its own wording is responsible for it.

6.2.1 The Studio's obligation to obtain, record and retain evidence of each consent — including the method, the date and time, the wording shown, the categories consented to, the integrity of the record, and the retention period — is set out in clause 15.7 of the AI & Communications Addendum and is not restated here. That Addendum governs it.

6.2.2 Carnelian does not hold the Studio's consent records. Where consent is captured outside ABS Twin — on the Studio's booking page, a walk-in card, a social profile or a paper form — the record exists only with the Studio.

6.2.3 The Studio must produce its consent records to Carnelian on request, including where a Platform Provider or a regulator requires evidence, within the period stated in clause 15.8 of the AI & Communications Addendum.

6.2.4 Within ABS Twin, on the messaging channels and where enabled, the Assistant may invite a Guest to opt in to marketing once, after a booking confirmation, and only where no opt-in or suppression state has been recorded for that Guest. The invitation itself is recorded, so an unanswered invitation counts as made and is not repeated. A decline sets a suppression flag. The Studio must not work around this behaviour.

6.2.4A The voice channel does not capture marketing consent. The Assistant does not ask for marketing opt-in on a call, and nothing said on a call sets or changes a Guest's marketing preference.

6.2.4B The Assistant's invitation does not, by itself, constitute the documented consent the Studio is required to hold under clause 6.1 and warrants under the AI & Communications Addendum, for any other channel or purpose. It is a description of design, not a warranty, and clause 2.3.1 applies to it. The Studio remains responsible for obtaining and evidencing consent under clause 6.1 and clause 15.7 of the AI & Communications Addendum.

6.3 Imported and acquired contacts

6.3.1 A spreadsheet is not consent. Contacts imported into ABS Twin are never automatically enrolled in marketing; the import path does not set marketing consent or suppression, and the Studio must not attempt to set consent in bulk to circumvent clause 6.1. Clause 2.3.1 applies to the import behaviour described in this clause.

6.3.2 The Studio must not upload, import or message purchased, rented, scraped or otherwise acquired contact lists.

6.3.3 The Studio must be able to state, for any contact it messages, where the contact data came from, and must disclose that source to a regulator or Platform Provider on request.

6.4 Opt-out

6.4.1 The Studio must honour an opt-out immediately.

6.4.2 Opt-out must be single-step and easy. Two separate layers handle it, and they sit in different places: (a) At the carrier layer, the messaging carrier recognises and acts on the standard stop keywords it publishes — including STOP, STOPALL, UNSUBSCRIBE, OPTOUT, CANCEL, END, REVOKE and QUIT. That behaviour is the carrier's, is set and changed by the carrier, and is not operated or guaranteed by Carnelian. (b) In the Service, the Assistant additionally classifies a Guest's message as an opt-out where the Guest asks in free text to stop receiving marketing messages, and sets a suppression flag on that Guest. This is a Compliance Control and clause 2.3.1 applies to it.

6.4.2A A request to stop must be honoured however it is expressed — in any language, in the Guest's own words, and whether or not it uses a keyword the carrier recognises. The Studio must not treat a plain-language request to stop as ineffective because it was not phrased as a keyword.

6.4.2B The Studio must not introduce non-standard or obfuscated opt-out phrasing, and must not require a Guest to call, email or log in to opt out.

6.4.2C Known limitation — language coverage. The Service's opt-out classification operates on the message text as the Service receives it. Voice transcription is presently English-only pending an Arabic pass, and the Service maintains no multilingual keyword list. The Studio must not rely on the Service to recognise an opt-out expressed in a language the Service does not process; clause 6.4.1 remains the Studio's obligation however the request reaches it.

6.4.3 After an opt-out, at most one confirmation message may be sent. Nothing further may be sent to that person in the relevant category without fresh consent.

6.4.4 Marketing templates, and the first message sent in any messaging programme, must carry unsubscribe wording or an opt-out affordance, and that affordance must be wired to suppression that actually takes effect.

6.4.5 Suppression flags and blocks are carried forward when Guest identities are merged; they are combined, never overwritten. The Studio must not merge, re-import or re-create a record in order to clear a suppression.

6.5 Sending windows

6.5.1 Marketing Messages may be sent only between 10:00 and 18:00 Gulf Standard Time (GST — the time zone of the United Arab Emirates; the same label is used in clauses 16.3 and 16.4 of the AI & Communications Addendum). That window is the stricter overlap of the window applicable to marketing communications within the scope of the UAE Telemarketing Regime (09:00–18:00) and the Service's own start-of-window rule (from 10:00). It is the window this Policy imposes.

6.5.1A Carnelian will configure the Service's send layer to permit Guest-facing Marketing Message sends only within the window stated in clause 6.5.1.

6.5.1B What may not be said until the gate is closed. Until Carnelian has performed clause 6.5.1A, neither this Policy nor any customer-facing copy, sales material or statement by or for Carnelian may describe the window in clause 6.5.1 as a window the Service enforces. Clause 6.5.1 states the rule this Policy imposes on the Studio in either case, and clause 1.5 applies to it.

6.5.2 Utility Messages tied to a specific appointment are not subject to the marketing window: a reminder may be generated outside that window, so that a two-hour reminder for a 09:00 appointment can be produced at 07:00. A Guest-facing send is nevertheless held until 09:00 GST — utility is not a licence to wake someone. Messages addressed to the Studio's own owner or staff on their own devices, including an operational briefing, are not subject to either window. This clause states the same rule as clause 16.4 of the AI & Communications Addendum.

6.6 Frequency and volume

6.6.1 The product limits Marketing Messages to one touch per Guest per 14 days. That limit is acquired at the point of sending, fails closed, and is released if a send fails. The Studio must not work around it by using multiple lanes, numbers, branches or accounts. Clause 2.3.1 applies to that control.

6.6.2 Platform Providers impose their own per-user marketing frequency limits, message volume tiers and quality-based throttles. These are set by the Platform Provider, are region-specific, change without notice, and are not guaranteed by Carnelian subject always to clause 14.3(c).

6.7 Message classification

6.7.1 Marketing Message and Utility Message have the meanings given in the Master Subscription Agreement. In practice: a message tied to a specific transaction or appointment and containing no promotional content is a Utility Message; a message whose purpose is promotional — offers, discounts, win-back, newsletters, upsell — is a Marketing Message. That description is illustrative; where it and the Master Subscription Agreement differ, that Agreement governs.

6.7.2 A reminder that also upsells is a Marketing Message. The Studio must not classify a promotional message as utility, or submit a promotional template in a non-marketing category, in order to avoid consent, window, frequency or pricing rules.

6.7.3 No authentication traffic. The Studio must not use ABS Twin to send one-time passcodes, verification or authentication codes, login or transaction confirmation codes, or any equivalent traffic, and must not submit a template in an authentication category. Such traffic is outside the purpose stated in clause 3.1, carries its own Platform Provider category, format rules, pricing and enforcement posture, and is not supported by the Service.

6.8 Templates and the service window

6.8.1 Business-initiated messages outside the platform's service window may only be sent using an approved template, used for the purpose for which it was approved.

6.8.2 A Platform Provider may review, pause, re-categorise or reject any template at any time and may change the category that determines its price. Carnelian gives no warranty that a template will be approved, will remain approved, or will retain its category, and is not liable for lost bookings, revenue or campaign outcomes arising from a Platform Provider's decision — without limiting clauses 17, 20 and 22 of the Master Subscription Agreement, and subject always to clause 14.3(c).

6.8.3 Free-form replies are permitted only inside the platform's service window following the Guest's own message.

6.8.4 Known limitation — templates and the campaign engine. As at the date of this version, no approved templates are registered for any Studio, and the reminder and campaign engine is accordingly not operational in production. Nothing in this Policy, and no customer-facing copy, may describe campaigns or reminders as live for a Studio until templates are approved and registered for that Studio. Delivery in a sandbox does not establish it.

6.9 Sender identity

6.9.1 The sender identified to the Guest must be the Studio that holds the consent. The Studio must not send on behalf of another business, and must not permit another business to send through its account.

6.9.2 The Studio must not spread identical or similar traffic across multiple numbers, senders, subaccounts or accounts to evade filtering, volume limits or quality measurement ("snowshoeing").

6.9.3 Messaging senders provisioned by Carnelian are read-only in the Console. The Studio must not attempt to change, port, re-register or re-use such a sender outside the Service without Carnelian's written agreement.

6.9.3A A line the Studio connects itself. Where the Studio connects its own existing telephone line to the Service under clause 7.5.1 of the Master Subscription Agreement, that line remains the Studio's throughout and after the term. Carnelian controls only the SIP, gateway and routing configuration applied to it, and clauses 5.2.2 and 13.9.3 of that Agreement govern the position, including on exit. Clause 6.9.3 does not apply to such a line.

6.9.4 Originating number and caller identity — voice. On any call carried over a line or route connected to or provided through the Service, the Studio must not: (a) manipulate, spoof, alter or conceal the originating number; (b) present a caller identity, calling-line identification or display name other than the Studio's own; (c) present false or misleading information as to who is calling or on whose behalf; or (d) defeat, degrade or attempt to defeat any carrier or Platform Provider mechanism for authenticating or displaying caller identity. The Studio must not ask Carnelian to do any of these things, and a request to do so will be refused.

6.10 Human escalation

6.10.1 Every automated conversation must have a prompt, clear and direct route to a human being — transfer to a person, a phone number, an email address, a web support route, or an in-person visit.

6.10.2 The Studio must staff that route. Providing an escalation path that nobody answers does not satisfy this clause and breaches the applicable Platform Provider policy.

6.10.3 The Service provides message-taking and escalation tools for this purpose, including a take-a-message capability that covers anything outside the Assistant's tools — expressly including "the caller wants to speak to a person" — and an independent watchdog that produces an apology to the Guest and a staff alert where a turn is not answered. These are descriptions of design. They are not service levels, not targets and not commitments; clause 2.3.1 applies to them, and clause 9.6 of the AI & Communications Addendum states the same position for the watchdog.

6.11 Instagram

6.11.1 Where the Instagram channel is enabled for a Studio, the Studio must not use, and must not ask Carnelian to use, the platform's human-agent message tag or any equivalent extended-window mechanism for AI-generated messages. Those mechanisms exist for a live human agent's response and never for an automated sequence or for promotional content.

6.11.2 Instagram Guests are identified without a phone number. The Studio must not attempt to obtain a Guest's phone number from the platform, and must not treat an Instagram identity as verified for the purposes of releasing personal information or booking history.

6.11.3 Known limitation — channel status. As at the date of this version the Instagram channel is gated behind a feature flag and is not enabled in production. This clause 6.11 applies where the channel is enabled for a Studio; no customer-facing copy may state that the channel is live until it is.

6.12 Confidentiality of conversations

6.12.1 The Studio must not forward, publish or disclose the content of one Guest's conversation to another Guest, and must not configure the Assistant to do so.

6.12.2 The Studio must not publish Guest conversations, transcripts or recordings, or use them in marketing, without the Guest's documented consent and a lawful basis.

6.13 Outbound messaging and telemarketing

6.13.1 ABS Twin's receptionist function is inbound: it answers Guests who contact the Studio. Where the Studio uses any outbound messaging feature — promotional reminders, campaigns, win-back or upsell broadcasts — the Studio is solely responsible for compliance with the UAE Telemarketing Regime and any equivalent law that applies to it.

6.13.1A The Service does not place outbound calls. ABS Twin does not place outbound voice calls to Guests. The voice layer answers calls made to the Studio's line; it does not dial, call back, cold-call, or place a marketing, reminder, survey, collection or win-back call, and Carnelian does not supply a feature that does. The Studio must not use ABS Twin, and must not request, configure or procure that it be configured, to place any outbound call. Clause 14.2A of the AI & Communications Addendum governs. Where the Studio wishes to reach a Guest by telephone it does so by its own people using its own line, and clauses 6.9.4 and 6.13.2B apply to that activity.

6.13.2 The Studio's obligations for outbound activity under clause 6.13.1 — including any prior approval required from the competent authority, use of senders registered to its own commercial licence, screening against the Do Not Contact Register, holding and evidencing opt-in consent with the method and date, sending only within the permitted hours, identifying itself and the purpose at the outset, observing the applicable frequency restrictions, maintaining the required records, being able to disclose the source of the person's contact data, training its staff, and honouring every opt-out and objection — are set out in clause 18.2 of the AI & Communications Addendum and are not restated here. That Addendum governs them.

6.13.2A A limb that depends on a Service behaviour. Where a limb of clause 18.2 of the AI & Communications Addendum depends on a behaviour of the Service that Carnelian controls — including the sender-registration limb at clause 18.2.2A of that Addendum, and any duty to record a communication or to give a notice the Service delivers — the Studio must not use the relevant outbound feature unless Carnelian has confirmed that the Service performs that behaviour. Carnelian will confirm the position on request.

6.13.2B The Studio's own calling, outside the Service. Where the Studio conducts outbound calling using its own people and its own line — including a line connected to the Service under clause 7.5.1 of the Master Subscription Agreement — the UAE Telemarketing Regime applies to that activity in full, including the permitted calling hours and any mandatory call-recording and start-of-call notification requirement. Carnelian supplies no part of that activity and gives no control over it.

6.13.3 Carnelian does not screen the Do Not Contact Register on the Studio's behalf, does not maintain a central suppression register across Studios, and does not verify a Studio's consent records.

6.13.4 The Studio must not use ABS Twin for cold outbound contact to persons with whom it has no relationship and from whom it holds no consent.

6.14 Known limitation — blocking a Guest

6.14.1 Blocking a Guest in the Console today marks the Guest as blacklisted and refuses further bookings. It does not, at present, stop the Assistant from replying to that Guest's messages. A Studio that needs a Guest to receive no further communication must contact Carnelian at the abuse address in clause 18.2. On such a request Carnelian will apply a manual suppression for that Guest, and will use reasonable endeavours to do so within one (1) Business Day of receiving the request.


7. Voice, recording, transcription and monitoring

7.1 Disclosure is not optional

7.1.1 Voice. On a voice call, the Assistant opens by identifying the Studio and stating that it is the Studio's AI assistant. It is instructed never to present itself as a human being, and to confirm plainly that it is an AI whenever a Guest asks. It does not simulate background office or human ambience. These are fixed product behaviours.

7.1.1A Messaging. On the messaging channels, the Assistant is instructed never to present itself as a human being, and to confirm plainly that it is the Studio's AI assistant whenever a Guest asks. Carnelian will in addition ensure that the Assistant identifies itself as the Studio's AI assistant in the first message of a new messaging thread.

7.1.1B Commencement of the start-of-thread limb. The final sentence of clause 7.1.1A takes effect on the Messaging Disclosure Commencement Date stated in the version of this Policy published under clause 16.4. No such date is stated in this version, so that sentence has no operation today. Until that date is stated Carnelian makes no representation as to start-of-thread self-disclosure on the messaging channels, and neither Carnelian nor the Studio may represent to any Guest or third party that one is made. This Policy will not be published with a Messaging Disclosure Commencement Date already past.

7.1.2 Recording and capture. Where a call is recorded or its audio is otherwise captured, no capture will occur unless an announcement has been made before it, in the Guest's conversation language where available. Carnelian will not capture or persist call audio, or a transcription of it, except behind that announcement.

7.1.2A For the purposes of this Policy, a call is "recorded or otherwise captured" where any part of the conversation audio, or any transcription of it, is captured, retained or persisted by any means — including real-time or streamed transcription, a stored transcript, and a summary generated from either. Transcription is not treated as an alternative to recording, and the fact that the underlying audio is discarded does not take the capture outside this clause.

7.1.2B Commencement. Clauses 7.1.2 and 7.1.2A take effect on the Capture Commencement Date stated in the version of this Policy published under clause 16.4. No such date is stated in this version, so those clauses have no operation today. Until that date is stated Carnelian does not represent that a Capture announcement is made on any channel, and the Studio must not represent to any Guest that one is. This Policy will not be published with a Capture Commencement Date already past.

7.1.2C What is captured today. The Service does not record call audio. No audio recording of a voice call is made, stored or retained, at the voice provider or anywhere else. What the Service does persist, on every voice call, is a written transcript of the conversation and a summary generated from that transcript, which are kept as the record of what was communicated between the Assistant and the Guest and are accessible to the Studio. Under clause 7.1.2A that is capture: the absence of audio recording does not take the transcript or the summary outside clause 7.1.2A, and nothing in this clause is to be read as saying that a call which is not audio-recorded is not captured. The announcement required by clause 7.1.2 therefore applies to every call from the Capture Commencement Date, and not only to a call on which audio recording might be enabled. The Studio's own obligations under clause 7.2 and under applicable law apply to that capture in the meantime.

7.1.3 The Studio must not disable, suppress, shorten, delay, obscure or circumvent the AI disclosure or any recording announcement, and must not configure, instruct or ask Carnelian to remove or weaken either. A request to remove either will be refused. Clause 2.3.1 does not qualify clauses 7.1.1A, 7.1.2 or 7.1.2A.

7.1.4 The UAE treats the recording of a conversation without the consent of all parties as a criminal matter, not merely a civil one. A contractual indemnity does not protect any individual from criminal liability. The announcement is therefore designed as a non-defeatable behaviour rather than a configurable option.

7.2 No covert capture

7.2.1 The Studio must not use ABS Twin to record, intercept, transcribe or monitor any person covertly, or to monitor its own staff, without the notices and consents required by law.

7.2.2 The Studio must not use the Service for surveillance, location tracking, or the compilation of information about an individual for a purpose unrelated to serving that individual as a Guest.

7.3 Transcripts

7.3.1 The Studio must not disclose a call transcript, message history or recording to a third party without a lawful basis, and must not instruct Carnelian to do so.

7.3.2 Transcripts and recordings may contain information a Guest volunteered about their health. That does not make the Service a health-data system, and it does not relieve the Studio of clause 4.

7.4 Traffic integrity and fraud

7.4.1 The Studio must not generate, permit or benefit from artificially inflated traffic, toll fraud, traffic pumping, robocalling, autodialling into number ranges, or any scheme that generates call or message volume for revenue or disruption.

7.4.2 Inbound traffic is not stopped automatically. Unless the Studio sets a limit where the Service offers one, the Studio remains responsible for the consumption its traffic generates, including AI voice minutes and per-message platform charges, in accordance with the Master Subscription Agreement, the Order Form and the Billing Terms.

7.4.3 Carnelian may throttle, rate-limit or suspend voice or messaging where volume is abnormal, where fraud is suspected, or where continued traffic creates a risk to Carnelian's platform or carrier relationships. Clause 13 applies.


8. Prohibited content

8.1 The Studio must not use ABS Twin to create, store, send or solicit content that: (a) is unlawful, or facilitates unlawful activity; (b) infringes any third party's intellectual property, image or personality rights; (c) is defamatory, insulting, obscene, sexually explicit, threatening, harassing or abusive; (d) is discriminatory, or targets a person on the basis of a protected attribute; (e) promotes terrorism, violent extremism or organised crime; (f) contains malware, harmful code, or links intended to defraud or phish; or (g) offends against public order or the religious values, customs and traditions of the United Arab Emirates.

8.2 The Studio must not use ABS Twin to make eligibility decisions about individuals in relation to employment, housing, credit, insurance or benefits.


9. Prohibited and regulated verticals; restricted parties

9.1 Prohibited Verticals

9.1.1 ABS Twin must not be used to promote, sell, transact in or communicate about any of the following (each a Prohibited Vertical): firearms, ammunition, explosives or weapons; illegal or recreational drugs and drug paraphernalia; endangered species or products derived from them; human body parts or fluids; multi-level marketing or pyramid schemes; payday, predatory or unlicensed lending; adult products or services; counterfeit goods; or any service that is fraudulent, deceptive or exploitative.

9.2 Regulated Verticals

9.2.1 Over-the-counter medicines, alcohol, tobacco and nicotine products, gambling and gaming, and any other vertical a Platform Provider or applicable law treats as regulated (each a Regulated Vertical) may only be the subject of communications through ABS Twin where the Studio: (a) holds every licence and approval required; (b) complies with the applicable industry code; (c) never sends such a communication to a person under 18 (see clause 9.5); (d) uses no commerce or catalogue features in connection with that vertical; and (e) is permitted by the applicable Platform Provider to communicate about that vertical in the relevant country, and holds any prior approval that Platform Provider requires.

9.2.2 Aesthetic, injectable and prescription-adjacent treatments, supplements and ingestible wellness products, and weight-management programmes are Regulated Verticals for the purposes of this Policy, and are additionally subject to clauses 4 and 5.

9.3 Political, governmental and security use

9.3.1 ABS Twin must not be used by or on behalf of a political party, politician, candidate, campaign, political consultancy or voting-system vendor.

9.3.2 ABS Twin must not be used by or on behalf of a law-enforcement, military, defence or intelligence agency, or for a law-enforcement, defence, intelligence or surveillance purpose.

9.4 Sanctions and restricted parties

9.4.1 The Studio must ensure that neither it, nor any person that owns or controls it, is subject to trade or economic sanctions administered by the United Arab Emirates, the United Nations, the United States, the United Kingdom or the European Union, and must not use ABS Twin in or for the benefit of a comprehensively embargoed territory. The Studio must not knowingly permit an Authorised User who is a restricted or sanctioned party to use the Service. The corresponding mutual warranty is at clause 28.2 of the Master Subscription Agreement.

9.4.2 The Studio must not use ABS Twin in breach of any applicable export-control law.

9.5 Minors

9.5.1 ABS Twin is not designed for use by children. Authorised Users must be adults.

9.5.2 The Service does not verify age. ABS Twin has no age-verification capability, and the Assistant does not determine, and does not attempt to determine, whether the person it is speaking to is an adult. Where the Studio's service catalogue records a minimum age for a treatment, enforcing it is the Studio's responsibility and is not performed by the Assistant.

9.5.3 The Studio must not use ABS Twin to communicate with, take a booking from, or market to a person it knows or reasonably suspects to be under 18 years of age, otherwise than through a parent, guardian or other accompanying adult acting for that person. A Guest record for a person under 18 may only be created by, and messaged through, the parent or guardian's contact details.

9.5.4 Where the Studio knows or reasonably suspects that a Guest is under 18, it must instruct Carnelian to suppress Guest Profile generation for that Guest, and must not configure or request any inference, scoring, segmentation or marketing targeting in respect of that Guest. A Marketing Message must not be sent to such a Guest.

9.5.5 Clause 9B of the AI & Communications Addendum governs this subject matter and this clause 9.5 states the same rules.


10. Data, profiling and platform data

10.1 No profiling of platform users

10.1.1 The Studio must not use ABS Twin, or data obtained through it, to track, build or augment profiles of individual WhatsApp or Instagram users beyond the Studio's own service relationship with that person.

10.1.2 In particular, the Studio must not: build behavioural scores, lookalike audiences or advertising segments from Platform Data; or enrich a record derived from Platform Data with data from a data broker, an advertising platform, or another business's messaging data.

10.1.2A Inferred Guest profiles. The Service generates, from a Guest's own conversations, an inferred profile of that Guest — including a narrative profile, communication style and personality notes, price sensitivity, upsell receptiveness, stated interests, ongoing concerns and conversion opportunities (the "Guest Profile", which is the Digital Twin as defined in clause 4.1 of the Privacy Policy and clause 2.1 of the Data Processing Agreement; "Digital Twin" is used thereafter wherever this Policy refers to the same thing). The Guest Profile is inferred data, not data the Guest supplied, and it is the most sensitive output the Service produces. The Studio must use, retain and disclose it only to serve that Guest within the Studio's own service relationship with them, and must not: (a) export a Guest Profile, or any score or inference drawn from it, to an advertising platform, a data broker, an analytics platform or any third party; (b) use a Guest Profile to build an advertising segment, a lookalike audience or a behavioural score; (c) use a Guest Profile to make or inform a decision about a person other than the delivery of the Studio's own services to that Guest, including any decision within clause 8.2; (d) disclose a Guest Profile to the Guest's employer, insurer, family member or any other person, other than as required by law or with the Guest's own documented consent; or (e) retain a Guest Profile after it ceases to serve that Guest, beyond the retention that applies to the underlying Guest Data under our internal retention and deletion schedule.

10.1.2B Clause 10.1.2A binds the Studio. It does not reduce the Studio's own obligations as controller in respect of the Guest Profile under the Data Processing Agreement, our internal data-subject rights procedure and applicable data-protection law, including on transparency, lawful basis and data-subject rights.

10.1.3 Carnelian's position — recorded so that it can be relied on and audited — is that a Studio building a customer record about its own customer, for its own service delivery, is not the profiling activity the platform restriction targets. That position is an interpretation, not a safe harbour, and clauses 10.1.2 and 10.1.2A mark its boundary.

10.1.4 This restriction survives termination of the Agreement.

10.2 No training on platform data; no cross-tenant training

10.2.1 Neither the Studio nor Carnelian may use Platform Data, including WhatsApp Business Solution Data, to create, develop, train or improve any machine-learning or artificial-intelligence system.

10.2.2 The Studio must not use ABS Twin, its outputs, its Assistant voices, its transcripts or its data to build or train a competing product, model or dataset, to benchmark or performance-test the Service without Carnelian's prior written consent, or to generate datasets for machine-learning purposes. Carnelian will not unreasonably refuse a request to benchmark or performance-test under agreed conditions.

10.3 Carnelian's own position on training and sale

10.3.1 For completeness, and because Studios ask: Carnelian does not use Customer Data or Guest Data to train AI models, and does not train any model across tenants. Carnelian does not sell Personal Data.

10.3.2 The position of each AI and voice provider in the chain, including where a provider's own default behaviour differs, is stated in the Privacy Policy, the Sub-processor List and the AI & Communications Addendum. This Policy does not restate it, so that a single source stays authoritative.

10.4 Tenant isolation

10.4.1 The Studio must not attempt to access, and must not attempt to cause the Service to disclose, any data belonging to another Studio or its Guests, and must not combine data derived from the Service with another Studio's data.

10.4.2 The Studio must not attempt to re-identify any aggregated or de-identified data made available to it.


11. Service integrity and security

11.1 The Studio and its Authorised Users must not:

(a) Reverse engineer — decompile, disassemble, reverse engineer, or attempt to derive the source code, models, prompts, algorithms or underlying structure of ABS Twin, except to the extent that restriction is unenforceable under applicable law; (b) Create derivative works from, copy, or republish the Service or the Documentation, except as expressly permitted by the Master Subscription Agreement; (c) Probe or test security — conduct penetration testing, vulnerability scanning, fuzzing, load testing or any security assessment of the Service or any Platform Provider's systems, without Carnelian's prior written authorisation. Carnelian will not unreasonably refuse a request for authorised testing by a recognised assessor under agreed conditions; (d) Circumvent controls — bypass or attempt to bypass authentication, authorisation, tenant scoping, rate limits, usage quotas, entitlement gates, billing controls or any security mechanism; (e) Introduce harmful code — upload or transmit malware, worms, trojans, or any code designed to disrupt, damage or gain unauthorised access; (f) Interfere — impose an unreasonable or disproportionate load on the Service, or take any action that impairs or is intended to impair the availability or integrity of the Service for others; (g) Scrape — use any crawler, scraper, bot or automated means to extract data from the Service, other than through an interface Carnelian documents and authorises for that purpose; (h) Share credentials — share a login, permit shared or generic accounts, or fail to de-provision an Authorised User promptly when their role ends. Each Authorised User must have their own credentials, and the Studio is responsible for credential security within its organisation; (i) Circumvent Compliance Controls — disable, suppress, defeat, work around or misuse any Compliance Control, or configure the Service so that a Compliance Control does not operate as designed. This limb applies to the AI disclosure and any recording announcement, the opt-out handling and suppression flags, the sending-window and frequency controls, the entitlement gates, the medical deferral behaviour, the catalogue-price rule, the live-availability rule, the discount floors and caps, and the injection guardrails; (j) Remove notices — remove, obscure or alter any proprietary notice, or frame or mirror the Console or the Staff App without written permission; (k) Misrepresent identity — create an account using false information, use the Service under a name or licence that is not the Studio's own, or impersonate any person or business or misrepresent affiliation; or (l) Misuse the telecommunications path — use ABS Twin, or any number, route or connection made available through it: (i) to provide, offer, resell or hold out a voice, telephony or voice-over-IP service to any person, whether or not for charge, without holding every authorisation required under UAE telecommunications law; (ii) to bypass, refile, reoriginate or otherwise misroute international call or message traffic, or to disguise its origin, in order to avoid or reduce a carrier's, licensee's or regulator's charges or to evade an applicable settlement arrangement; or (iii) to circumvent, or assist any person to circumvent, any lawful content filtering, blocking or access-management measure applied by a UAE licensee or required by the competent authority.

11.2 Where a Compliance Control, or the AI disclosure or a recording announcement, supports an obligation the Studio owes on messaging consent and opt-out, on recording and AI disclosure, or on Restricted Data, circumventing that control is a breach of the underlying obligation as well as of clause 11.1(i), and carries the same consequence as breaching that underlying obligation, including any warranty or indemnity given in the Master Subscription Agreement or the AI & Communications Addendum in respect of it. A Studio that observes the letter of a rule while defeating the mechanism that makes compliance observable is in breach of the rule.


12. Reporting, cooperation and investigation

12.1 The Studio's duty to report

12.1.1 The Studio must notify Carnelian without undue delay on becoming aware of: (a) a breach or suspected breach of this Policy by any person; (b) a compromise of an Authorised User's credentials; (c) a notice, warning, restriction, suspension or enforcement action from a Platform Provider, a carrier or a regulator; (d) a Guest complaint alleging unlawful messaging or recording; (e) the presence of Restricted Data in the Service; or (f) a personal data breach, or a suspected personal data breach, affecting Guest Data or Customer Data processed through the Service — notification of which is additionally governed by the Data Processing Agreement and by our internal data breach response procedure, and which carries its own regulatory clock.

12.1.2 Notification is to the addresses in clause 18.

12.2 Cooperation

12.2.1 The Studio must cooperate reasonably with any investigation by Carnelian, a Platform Provider or a regulator into use of the Service under the Studio's account, and must provide the records reasonably required — in particular the consent evidence under clause 15.7 of the AI & Communications Addendum and the substantiation files under clause 5.2.2.

12.2.2 Carnelian may disclose the Studio's identity and the records relevant to the matter to a Platform Provider, carrier or regulator: (a) where required by law or by a lawful request; or (b) where a Platform Provider requires it in order to investigate or remedy a suspected breach of its terms in connection with the Studio's traffic, including where a complaint or enforcement action is directed at Carnelian as the technical sender. Carnelian will limit disclosure to what is required and will inform the Studio unless prohibited from doing so. Any disclosure of Personal Data under this clause is subject to the Data Processing Agreement and to Applicable Data Protection Law. Carnelian will not disclose the content of a Guest conversation, a transcript, a recording or a Guest Profile under this clause except where compelled by law or by a regulator.

12.3 Reporting abuse to Carnelian

12.3.1 Anyone — a Guest, an Authorised User, a Studio, a Platform Provider or a member of the public — may report suspected misuse of ABS Twin. Reports should describe what happened, when, and the number or account involved, and should be sent to the abuse address in clause 18.

12.3.2 Security vulnerabilities should be reported to the security address in clause 18. Carnelian will acknowledge a good-faith report, will not pursue a reporter who acts in good faith, avoids privacy intrusion and data destruction, and gives Carnelian a reasonable period to remediate before disclosure — and clause 11.1(c) is not enforced against such a reporter. This is not authorisation to test the Service.

12.3.3 Carnelian does not undertake to investigate every report, or to inform a reporter of the outcome — subject always to clause 14.3(c).


13. Enforcement

13.1 Investigation

13.1.1 Carnelian may investigate a suspected breach of this Policy, including by reviewing configuration, templates, campaign definitions, audit records, and — where necessary and proportionate for the investigation — message metadata and the minimum message content required. Access to Customer Data for this purpose is subject to the Data Processing Agreement.

13.1.2 Carnelian operates an automated daily audit of replied conversation turns that checks for confirmations without a real booking, prices outside the Studio's catalogue, availability asserted without a live check, and mishandled injection attempts, and opens an incident on a severe finding. Findings may be used in an investigation under this clause. Clause 2.3.1 applies to that control.

13.2 The enforcement ladder

13.2.1 Where Carnelian determines, acting reasonably, that this Policy has been or is likely to be breached, it may take one or more of the following steps, normally in escalating order: (a) written warning and a request to remediate; (b) throttling of message or call volume; (c) pausing a campaign, template or lane; (d) restricting a feature; (e) placing the account in read-only mode, where that capability is available; (f) suspending a channel (messaging, voice, or a specific integration); (g) suspending the account; (h) terminating the Agreement in accordance with the Master Subscription Agreement.

13.2.2 Carnelian will use the least restrictive measure it reasonably considers sufficient to address the risk, and will move down the ladder as soon as the risk is addressed. References in this Policy to the least restrictive measure, and references in clause 11.2 of the Master Subscription Agreement to the least disruptive measure, describe the same duty.

13.3 Notice and cure

13.3.1 For a breach that is not urgent, Carnelian will give written notice describing the breach and allow the Studio ten (10) Business Days to cure it before taking a step beyond clause 13.2.1(a), unless the Studio has been notified of a breach of the same clause of this Policy within the preceding six months. Ten Business Days is the canonical cure period for this step across our documents, because Business Days is the more generous measure and is the one our Agent Agreement also uses.

13.3.2 Carnelian may act immediately, and without prior notice, where: (a) continued provision would be unlawful, or would create a material risk of harm to any person; (b) there is a security incident, a credential compromise, or fraudulent or abusive traffic; (c) Restricted Data is present in the Service and its continued processing would breach applicable law; (d) a Platform Provider, carrier or regulator requires it, or continued provision would breach a Platform Provider's terms or place Carnelian's platform relationships at material risk; or (e) the Studio's conduct is causing, or is likely imminently to cause, harm to another Studio, to a Guest, or to the Service.

13.3.3 Where Carnelian acts under 13.3.2 it will notify the Studio as soon as reasonably practicable, state the reason, and state what is required to restore service.

13.3A Representations and review

13.3A.1 The Studio may make written representations against any step taken or proposed under clause 13.2, including a step taken immediately under clause 13.3.2, within ten (10) Business Days of being notified of it. Representations are made to the address in clause 18.

13.3A.2 Carnelian will review the decision in light of the representations — so far as reasonably practicable by a person other than the person who took it — and will use reasonable endeavours to respond within ten (10) Business Days of receiving them, and in any event without undue delay, stating the outcome and the reasons for it.

13.3A.3 Where the representations are made out in whole or in part, Carnelian will lift the measure, or reduce it to the least restrictive measure that remains sufficient, without undue delay.

13.3A.4 Making representations does not suspend a measure taken under clause 13.3.2, and does not extend a cure period under clause 13.3.1. Where Carnelian is required to maintain a measure by law, by a regulator or by a Platform Provider, it will say so and the review is limited to the part of the decision that is Carnelian's own.

13.4 Continuity during enforcement

13.4.1 Carnelian recognises that suspending an AI receptionist silently drops a Studio's incoming Guest messages and calls. Accordingly, where Carnelian suspends, it will, so far as reasonably practicable and consistent with the reason for the suspension: (a) preserve the Studio's access to the Console and to its data, and provide the standard export described in clause 7.9.1 of the Master Subscription Agreement on the Studio's request; (b) preserve the Studio's ability to see inbound Guest contacts even where automated replies are stopped; and (c) restore service promptly on cure.

13.4.2 Carnelian will not withhold or delay the export described in clause 7.9.1 of the Master Subscription Agreement, or any other means by which the Studio obtains personal data held in the Service, in order to secure payment of a disputed sum, and will not gate the Studio's ability to meet its own data-protection obligations (including under the Data Processing Agreement and our internal data-subject rights procedure) on a commercial dispute. That export is provided on the Studio's request; clause 7.9.1 of the Master Subscription Agreement states how and in what formats.

13.5 Fees during suspension

13.5.1 Where a suspension results from the Studio's breach, Fees continue to accrue for the suspended period. Where a suspension does not result from the Studio's breach, the Studio is entitled to a pro-rata reduction in Fees for the affected period, in accordance with the Master Subscription Agreement.

13.5.2 Longstop. A suspension will not run indefinitely with Fees accruing. Where a suspension of the account, or of every Guest-facing channel, continues for thirty (30) consecutive days without the breach being cured: (a) Carnelian may terminate the Agreement on written notice; (b) the Studio may terminate the affected Service on written notice, where the suspension is not attributable to its own uncured breach; and (c) where the suspension is attributable to the Studio's own uncured breach, the Studio may nonetheless terminate on written notice, but that termination is treated as termination by the Studio for convenience for the purposes of the Master Subscription Agreement, and Fees for the balance of the then-current term fall due in accordance with that Agreement.

On a termination under this clause, Fees cease to accrue from the date of termination; Fees already accrued for the suspended period remain payable where the suspension resulted from the Studio's breach; and the exit, data-retrieval and deletion provisions of the Master Subscription Agreement and the Data Processing Agreement apply, including the retrieval window.

13.6 Effect and limits

13.6.1 Carnelian is not liable for loss suffered by the Studio as a result of a step taken in good faith and in accordance with this clause 13, on the information reasonably available to Carnelian at the time, to the fullest extent permitted by applicable law. A step taken because a Platform Provider, carrier or regulator required it is a step taken in accordance with this clause 13.

13.6.2 Clause 13.6.1 does not apply where Carnelian has acted unreasonably or in bad faith. Clause 14.3(c) applies to this clause 13.6.

13.6.3 Enforcement under this clause is without prejudice to any other right or remedy, including termination under the Master Subscription Agreement and any indemnity in that Agreement or in the AI & Communications Addendum. A failure or delay in enforcing this Policy is not a waiver. Any liability arising from a step taken under this clause 13 is in any event subject to clause 20 of the Master Subscription Agreement (clause 1.2.5), and nothing in this Policy varies it.


14. Consequences of use contrary to this Policy

14.1 Use of ABS Twin contrary to this Policy is use contrary to its documented method of use. Where damage results from such use, that damage arises from the Studio's own act and is outside the compensation Carnelian would otherwise owe, to the extent applicable law so provides.

14.2 The Studio's warranties and indemnities in respect of the matters covered by this Policy — messaging and consent, recording, Restricted Data, content and intellectual property, the acts of its Authorised Users and Guests, and regulatory fines passed through by a carrier, Platform Provider or regulator — are set out in the Master Subscription Agreement and the AI & Communications Addendum. They are not repeated here and are not limited by this Policy.

14.3 Savings. Nothing in this Policy: (a) transfers to Carnelian any obligation the Studio owes under applicable law; (b) makes Carnelian the controller of Guest Data where the Data Processing Agreement provides otherwise; (c) excludes or limits any liability, right or remedy that cannot lawfully be excluded or limited, including liability for fraud, for wilful misconduct or gross fault, or for death or personal injury caused by negligence; or (d) limits any obligation Carnelian owes under the Master Subscription Agreement, the Data Processing Agreement, the Service Level Agreement & Support Policy or the AI & Communications Addendum. This clause applies to every limitation, exclusion, disclaimer and allocation in this Policy, whether or not it is repeated there; and where any of them would otherwise be unenforceable, it applies to the fullest extent permitted by applicable law and no further.

14.4 If any provision of this Policy is held invalid or unenforceable, it is to be modified to the minimum extent necessary to make it valid and enforceable, and the remainder is unaffected.

14.5 Survival. The following clauses survive termination or expiry of the Agreement, however arising, and continue to bind the Studio: clause 6.12 (confidentiality of conversations), clause 10.1 including clauses 10.1.2A and 10.1.2B (profiling, Platform Data and Guest Profiles), clause 10.2 (no training on Platform Data; no competing product), clauses 11.1(a) and 11.1(b) (reverse engineering and derivative works), clause 12.2 (cooperation and investigation), and this clause 14. Survival under this clause is in addition to, and not limited by, the survival provisions of the Master Subscription Agreement.


15. Onboarding and ongoing declarations

15.1 At onboarding, and on renewal, the Studio must declare through the Order Form or the Console: (a) the categories of treatment it offers; (b) whether it holds a health-facility licence and, if so, from which authority, under what number and to what expiry; (c) whether it intends to use any outbound marketing feature; and (d) the identity of the person responsible for its messaging compliance.

15.2 The Studio must keep those declarations current and must notify Carnelian of a material change without undue delay.


16. Changes to this Policy

16.1 Carnelian may change this Policy. Except where 16.3 applies, Carnelian will give at least thirty (30) days' advance written notice of a change, to the Studio's registered contacts and in the Console.

16.1A Relationship to clause 27 of the Master Subscription Agreement. Changes to the Agreement and to the documents incorporated into it, including this Policy, are governed by clause 27 of the Master Subscription Agreement. This clause 16 states how that mechanism operates for this Policy; where clause 16 and clause 27 of that Agreement differ, clause 27 of that Agreement governs, save that clauses 16.2A, 16.4 and 16.5 apply in addition to it.

16.2 Changes are of three kinds: (a) non-material changes, changes required by law, and changes required for security — effective on the stated date; (b) material adverse changes — the Studio may terminate the affected Service without penalty before the change takes effect, and receive a pro-rata refund of prepaid Fees for the unused period. Carnelian will not treat continued use alone as acceptance of a material adverse change, and will seek a fresh acceptance in accordance with clause 27.5 of the Master Subscription Agreement; (c) changes required by a Platform Provider — effective on the notice period Carnelian itself receives from that Platform Provider, which may be shorter than thirty days or, exceptionally, immediate. Carnelian will give as much notice as it receives and will identify the Platform Provider requirement.

16.2A Exit right where a change is forced. Where a change under clause 16.2(c) or clause 16.3, or a change in a Platform Provider's terms falling within clause 1.4.2, is materially adverse to the Studio, the Studio may terminate the affected Service on written notice given within thirty (30) days of the change taking effect, and will receive a pro-rata refund of Fees prepaid for the unused period — whether or not the change took effect before that notice was given.

16.3 Where a change is required to stop unlawful activity or to comply with a binding instruction from a regulator or Platform Provider, it takes effect on notice. Clause 16.2A applies to such a change where it is materially adverse to the Studio.

16.4 Carnelian will maintain a dated archive of every published version of this Policy, and will record which version each Studio accepted. No published version is amended in substance without a new version number and a new effective date; a correction that does not change the substance of a provision may be made to the published version and is recorded in the archive. This clause states the same commitment as clause 27.3 of the Master Subscription Agreement.

16.5 No retrospective effect. The version of this Policy in force at the time of the relevant use governs that use. No change to this Policy applies retrospectively, and no change operates to make conduct a breach of this Policy, or use contrary to the documented method of use for the purposes of clauses 1.1.3 and 14.1, where that conduct was not a breach under the version in force when it occurred.


17. Language

17.1 This Policy is published in English. An Arabic version will be provided, alongside the English version at the URL in the header, and will not be published until it has been legally reviewed.

17.2 For the studio contract stack of which this Policy forms part, English is the language of the Agreement and of any proceedings, and the Arabic version is supplied as a non-binding translation. In the event of a conflict, the English version prevails to the fullest extent permitted by applicable law.

17.3 Where any provision is required by law to be made in Arabic, the Arabic text governs that provision to the extent so required.


18. Governing law, forum, and notices

18.0 A note to a reader who is not a Studio. This Policy is published publicly, but it forms part of the Studio contract stack and is incorporated into the Master Subscription Agreement. That is why this clause carries a DIFC governing-law and exclusive-jurisdiction opt-in and clause 17 carries an English-prevails rule, where the other public pages — the Privacy Policy, the Website Terms of Use, the Cookie & Tracking Notice, the Refund & Cancellation Policy and the Legal Notice — are governed by the federal law of the United Arab Emirates as applied in the Emirate of Dubai, with the courts of Dubai on a non-exclusive basis and the Arabic text prevailing. Nothing in this clause 18 or in clause 17 applies to a person who is not a Studio, and clause 18.1.5 preserves every mandatory right and forum in any event.

18.1 Governing law and forum

18.1.1 Governing law. This Policy, and any dispute, claim or obligation arising out of or in connection with it, its subject matter or its formation — including any non-contractual dispute, claim or obligation — is governed by and construed in accordance with the law of the Dubai International Financial Centre.

18.1.2 Jurisdiction — express opt-in. The parties specifically, clearly and expressly agree that the Courts of the Dubai International Financial Centre shall have exclusive jurisdiction to settle any dispute, claim or obligation (including any non-contractual dispute, claim or obligation) arising out of or in connection with this Policy, its subject matter or its formation. The parties make this agreement for the purposes of, and intending to satisfy the requirements of, Article 14(B) of Dubai Law No. 2 of 2025, or any successor provision, and confirm that they have chosen the DIFC Courts by express written opt-in notwithstanding that neither party may otherwise be connected to the DIFC. The parties may elect the DIFC Courts' Small Claims Tribunal in the Order Form.

18.1.2A Single source. Clause 30 of the Master Subscription Agreement is the single source for the governing law and forum of the Agreement and of every document incorporated into it, including this Policy. Clauses 18.1.1 and 18.1.2 restate it so that the position is readable on this published page; if they differ from clause 30 of that Agreement, clause 30 of that Agreement governs. Clause 16 does not permit a change to clause 18.1.1 or clause 18.1.2 that departs from clause 30 of that Agreement: the governing law and forum of the Agreement are changed under that Agreement, never under this Policy. The restatement is retained rather than reduced to a pointer because the opt-in in clause 18.1.2 must be specific, clear and express on its face, and this Policy is read before, and independently of, acceptance.

18.1.3 Data protection is a separate question from forum. The choice of law and forum above does not select the data-protection regime applicable to Personal Data. The UAE Personal Data Protection Law applies to the processing described in the Privacy Policy and the Data Processing Agreement, together with any other Applicable Data Protection Law that applies by reason of the Studio's establishment, the location of processing, or the residence of the data subjects. Where the Studio is established in a financial free zone with its own data-protection or autonomous-systems regulation, that regulation may impose direct obligations on both parties, and the parties will agree any addendum necessary to reflect them.

18.1.4 Pre-action step. Before commencing proceedings, a party must give written notice of the dispute to the other party's notice address and the parties must seek in good faith to resolve it for thirty (30) days. This does not prevent an application for urgent interim relief.

18.1.5 Nothing in this clause 18.1 excludes, limits or prejudices any mandatory right or forum available to a person under UAE law that cannot be excluded or varied by agreement.

18.2 Contact and notice addresses

PurposeAddress
General and legal noticeslegal@contact.abstwin.com, marked "Attn: Legal"
Reporting abuse of ABS Twinsecurity@contact.abstwin.com, marked "Attn: Abuse". A report is read whether or not the attention line is used; the line only speeds the routing
Reporting a security vulnerabilitysecurity@contact.abstwin.com, marked "Attn: Security"
General enquiriesinfo@contact.abstwin.com
Data-protection enquiries and data-subject requestsprivacy@contact.abstwin.com, marked "Attn: Data Protection Officer" — see the Privacy Policy, clauses 3.2 and 3.2.1. A request is acted on whether or not the attention line is used
Data Protection OfficerSyed Sharique Ali, Manager of Carnelian Technologies L.L.C-FZ, is the appointed Data Protection Officer, with effect from 21 August 2026. He is reached directly at dpo@contact.abstwin.com, and at privacy@contact.abstwin.com marked "Attn: Data Protection Officer"
Company contact and alternative routesupport@carnelian.tech — the mailbox of Carnelian Technologies L.L.C-FZ, the company behind ABS Twin. It is valid for any purpose in this table and is the route to use if an ABS Twin address is for any reason unavailable
PostalCarnelian Technologies L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. That is the registered address on the trade licence and the address for service under clause 18.3; there is no separate mailing address. Licensed under the Meydan Free Zone regulations, trade licence no. 2415615.01, expiring 25 January 2027
Telephone+971 56 498 4007

18.2A Which address, and why. Every address in the table above delivers. Inbound routing on the contact. subdomain was verified by test on 21 August 2026: info@, privacy@, dpo@, legal@ and security@contact.abstwin.com each received the test message, as did support@carnelian.tech. (An earlier check on the same day appeared to show that only support@carnelian.tech delivered; that check was made too early and the re-check corrected it. Nothing in this Policy relies on the earlier result.) Each row therefore names the ABS Twin route for its purpose, and support@carnelian.tech — the mailbox of Carnelian Technologies L.L.C-FZ — remains valid for every purpose and is the alternative route if an ABS Twin address is for any reason unavailable. The bare apex domain carries no mailbox: no @abstwin.com address may be printed as a contact route in this Policy, on any page, in any store listing or in any script — the routed domain is the contact. subdomain, and an ABS Twin address is to be written in the form name@contact.abstwin.com exactly as printed above. Where a row gives an attention line, using it speeds the routing; the message is read and acted on whether or not it is used.

18.3 Operational notices under this Policy may be given by email to the Studio's registered contacts and in the Console. Deemed receipt is governed by clause 26.3 of the Master Subscription Agreement: such a notice is deemed received on transmission if sent during business hours on a Business Day, and otherwise at the start of business hours on the next Business Day. Notices of termination and of formal breach must additionally be sent by courier or registered post to the postal address above, and are deemed received on the courier's record of delivery.


Version 0.9 · Effective date: on publication

Publisher: Carnelian Technologies L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. · Trade licence no. 2415615.01 (expires 25/01/2027) · Free zone: Meydan Free Zone · Telephone +971 56 498 4007

Contact: Legal notices: legal@contact.abstwin.com, "Attn: Legal" · Abuse: security@contact.abstwin.com, "Attn: Abuse" · Security: security@contact.abstwin.com, "Attn: Security" · General enquiries: info@contact.abstwin.com · Privacy and data-subject requests: privacy@contact.abstwin.com, "Attn: Data Protection Officer" · Company contact and alternative route: support@carnelian.tech. Delivery on all six addresses was verified by test on 21 August 2026 (clause 18.2A); no address on the bare apex domain abstwin.com is a contact route.

Data Protection Officer: Syed Sharique Ali, Manager, appointed 21 August 2026 · direct: dpo@contact.abstwin.com · or privacy@contact.abstwin.com, "Attn: Data Protection Officer"

Next review: at least annually, and on any change in law or in the platform rules — in particular on issuance of the PDPL Executive Regulations, on any change to the Meta WhatsApp Business Solution Terms, or on any change to the UAE Telemarketing Regime, whichever is earlier.