AI & Recording Disclosure
Plain-language summary
When you call, message or send a Direct Message to a beauty or wellness studio that uses ABS Twin, the first thing that answers you is usually software, not a person. It has a name the studio chose — it might introduce itself as "Rahima" — but it is an AI assistant, and it says so at the beginning of every call and every new conversation. It must not present itself as a human being; the studio is not permitted to switch that off, and we do not permit it either.
What it can do. Book, move and cancel appointments; tell you what a treatment costs and how long it takes from the studio's own price list; answer questions about opening hours, location and parking; and take a message for the studio's team.
What it cannot do. It cannot tell you whether a treatment is right for your skin, your hair, your health or your pregnancy — a qualified person at the studio does that. It cannot give medical, dental, nutritional, legal or financial advice. It is not an emergency service and cannot call one for you. It is not a medical device: it does not diagnose, treat, cure or prevent any condition.
It can be wrong. It works by predicting language, so it can mishear an accent, misunderstand a mixed-language sentence, or state something that is out of date. Prices, availability and any promise made to you are subject to confirmation by the studio. If something it told you looks wrong, please check with the studio before you rely on it.
Calls. Your call is not audio-recorded. No recording of the sound of the call is kept, by the studio or by us. What is kept is a written record — a transcript of the conversation and a short summary — held with your record at the studio, so that what was agreed on the call can be checked afterwards. The assistant tells you at the start of the call that it is an AI assistant and not a member of staff. It does not yet tell you, in that opening, that the call is written down — clause 9.1A says so plainly, and this paragraph is where you are told instead. You can ask for the call not to be written down. If someone else is with you, or you are on speakerphone, please tell them too — the assistant cannot see the room, and if anyone objects, say so and the same route applies to the whole call.
Your voice. The assistant listens in order to turn what you say into text. The sound of your voice is not kept — the audio is not recorded, and the written text is what remains. ABS Twin does not create a voiceprint, does not identify or verify who you are from the sound of your voice, and does not do voice biometrics of any kind. The voice you hear is synthetic: it is generated by software and it is nobody's voice. The assistant also does not telephone you: it answers the studio's line, it does not dial out.
Reaching a person. Ask for a person at any point. On a call the assistant takes an urgent message for the studio's reception; on WhatsApp or Instagram your message is passed to the studio's team. The person you reach is the studio's — Carnelian does not answer a studio's guests.
Your information. The studio — not Carnelian — decides how your information is used. Carnelian runs the software on the studio's behalf. You can ask to see your information, correct it, have it erased, or ask for a person to review anything that was decided automatically. That last request goes to the studio's team, who decide it — Carnelian does not review or overturn a studio's decisions about its own guests. Erasure is done by redacting the personal data in a record and keeping a marker in its place, so that past bookings and payments stay attributable — clause 9.6.3 explains why, and what it means for you. Details are in our Privacy Policy and the list of companies that help us run the service is in our Sub-processor List.
We do not use your conversations to train AI models, we have not opted into any provider programme that would permit it, and we never sell personal information. What we can and cannot say about our providers' own terms is set out in full in clause 12.
An Arabic version of this page is published alongside the English version.
PART A — THE PUBLIC DISCLOSURE PAGE
1. What this document is
1.1 This document is published by:
Carnelian Technologies L.L.C-FZ ("Carnelian", "we", "us") Legal form: Limited Liability Company, as printed on the trade licence. The licence prints the name as "Carnelian Technologies L.L.C-FZ" and that spelling is used in every identity block Licensed under the Meydan Free Zone regulations, Dubai, United Arab Emirates Trade licence no. 2415615.01 (formation no. 2415615), issued 26 January 2024, expiring 25 January 2027 Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. Correspondence address: the same address. The registered and correspondence addresses are one and the same; the short form "Meydan Road, Nad Al Sheba, Dubai, UAE" used in marketing is that same address abbreviated Contact:
info@contact.abstwin.com— the general ABS Twin route. Telephone +971 56 498 4007.support@carnelian.techis the mailbox of Carnelian Technologies L.L.C-FZ, the company behind ABS Twin, and remains valid for every purpose and as the alternative route Data protection and data-subject requests:privacy@contact.abstwin.com, marked "Attn: Data Protection Officer". Syed Sharique Ali, Manager of Carnelian Technologies L.L.C-FZ, is the appointed Data Protection Officer with effect from 21 August 2026, and is reached directly atdpo@contact.abstwin.com. Legal notices:legal@contact.abstwin.com, "Attn: Legal". Complaints:info@contact.abstwin.com, "Attn: Complaints" Delivery on all six addresses —info@,privacy@,dpo@,legal@andsecurity@contact.abstwin.com, andsupport@carnelian.tech— was verified by test on 21 August 2026; an earlier check the same day appeared to fail and was premature. The bare apex domain carries no mailbox: no@abstwin.comaddress is printed here as a route Website:https://abstwin.com
The full identity block, and the canonical form in which it must be reproduced everywhere, is published in the Legal Notice; the block above must match it exactly. ABS Twin is the product; Carnelian is the company.
1.2 It explains, in one place: (a) that a Guest interacting with a Studio through ABS Twin is interacting with an automated system; (b) how calls are recorded, transcribed and retained, and how a Guest may decline recording; (c) how to reach a human being; (d) what the Assistant does, what it will not do, and how it fails; (e) which third parties process the conversation, and where; (f) what a Guest may ask for, and from whom; and (g) the exact wording of the notices the Assistant speaks and sends (Part B).
1.3 The runtime notices are the operative disclosure. The scripts in Part B are the legally operative layer of this document. A disclosure that a person actually hears or reads at the point of use carries materially more weight than a clause on a web page they never opened. This page exists to support, explain and evidence those runtime notices — not to replace them.
1.4 Contractual status. 1.4.1 Part A is a transparency notice. It is addressed to Guests, to Studios, to the public and to regulators. It does not create a contract between Carnelian and any Guest, does not vary any agreement, and does not make Carnelian a party to the relationship between a Guest and a Studio. 1.4.2 Parts C, D and E are incorporated by reference into the Master Subscription Agreement and bind each Studio as a term of its subscription. Where Parts C, D or E conflict with the Acceptable Use Policy or the AI & Communications Addendum, the order of precedence stated in the Master Subscription Agreement governs. The display obligations in clause 21 and the prohibitions in clause 20.1 are independently operative as obligations of the Studio under the AI & Communications Addendum and the Acceptable Use Policy, so that they bind whichever route carries them. 1.4.3 Capitalised terms used but not defined here have the meaning given to them in the Master Subscription Agreement. The terms used most often in this document are set out in clause 2.
1.5 What this document does not do. It does not describe how personal data is handled generally (see the Privacy Policy), does not list the companies that process it (see the Sub-processor List), does not set retention periods (see our internal retention schedule and clause 9.6), does not state the Studio's own terms of business, and does not constitute legal, medical, financial or regulatory advice to any person.
1.6 Liability. Liability arising out of or in connection with any part of this document is subject to clause 15.9.
2. The words used in this document
| Term | Meaning |
|---|---|
| Assistant | The AI receptionist operating under a Studio's configuration, in that Studio's name, on that Studio's data, named per Studio, on the channels identified on the Order Form and enabled for that Studio. This definition describes what the Assistant is; it does not state, and is not to be read as stating, that any particular channel is available. No channel is named in this definition (clause 1.1.5 of the Master Subscription Agreement, which governs). It answers a Studio's own customers within the scope of that Studio's business; it is not a general-purpose AI assistant (clause 4.2). Each Studio gives its Assistant its own name, and the Assistant answers the Studio's line — it does not place outbound telephone calls. |
| Studio | The licensed business — a salon, spa, clinic or similar establishment — that subscribes to ABS Twin and in whose name the Assistant speaks. |
| Guest | An individual who contacts, books with, or receives services from a Studio, and whose personal data is processed through ABS Twin. If you are reading this because a studio's assistant messaged or answered you, you are the Guest. |
| Console | The web control panel at app.abstwin.com through which a Studio configures and supervises its Assistant. |
| Guest Data | The personal data relating to a Guest that is processed through ABS Twin — identity, bookings, payments, conversation content, voice transcripts and the Digital Twin profile. |
| Digital Twin | The written profile ABS Twin maintains about a Guest for a Studio, summarising what that Guest has told the Studio — preferences, usual services, preferred times, language, and previous concerns. Described in clause 11. |
| Sub-processor | A company engaged by Carnelian to process personal data on a Studio's behalf, listed in our Sub-processor List, together with that company's own onward suppliers. |
| Platform Providers | Meta Platforms / WhatsApp, Twilio, telephony carriers and SIP providers, AI model providers, hosting providers, app stores and payment processors, on whose services ABS Twin depends and whose terms, availability, approvals, rate limits and enforcement actions Carnelian does not control. |
| Restricted Data | Health data as defined by UAE health-information legislation and by any health authority; clinical, diagnostic or treatment records; biometric identifiers; payment card data; government identification numbers; and any special-category data not required to schedule an appointment. |
3. The standing rule: the Assistant always says it is an Assistant
3.1 The rule. On every channel, ABS Twin identifies itself as an AI assistant at the start of the interaction, and it does not claim to be a human being. If a Guest asks whether they are speaking to a person, the Assistant answers plainly and warmly that it is not.
3.2 How the rule is enforced, and by what. The identification is not a setting in the Console: Carnelian does not expose it as one, will not disable it on request, and prohibits a Studio from defeating it (clause 20.1). Today it is enforced by a standing instruction in the Assistant's system prompts, by the published scripts in Part B which a Studio cannot edit, and by screening of owner-authored FAQ and configuration text at the point it is saved (clause 20.2). Carnelian commits that, from a date stated in the next published revision of this page and in any event before the first paying Studio, delivery of the identification will additionally be enforced by a control in the call-opening and send layers that no Studio configuration, FAQ content, persona setting, integration or instruction can vary. Until that date, this clause states Carnelian's commitment and the Studio's duty — it is not a representation that defeating the identification is technically impossible, and it is not stated as one. Clause 4.3A of the AI & Communications Addendum is the operative provision and this clause is drafted to match it. Part C sets out the policy in full and the consequences of trying to defeat it.
3.2.1 What is in production, channel by channel. On the voice channel the opening identification is delivered at the start of every call: the Assistant announces that it is the Studio's AI assistant before the conversation begins, and that is a production behaviour today. The transcription-and-summary notice carried by script S2 is not yet part of the live spoken introduction. The introduction identifies the Assistant as an AI; it does not yet tell the caller that the conversation is written down and summarised. That gap between this document and the production voice prompt is stated here rather than smoothed over — clause 9.1A governs it, and no version of this page, and no statement by or for Carnelian or a Studio, may claim that the transcript notice is spoken until the live prompt carries it. On WhatsApp and Instagram, the thread-opening identification (S4, S5) and the re-disclosure after a gap or on handover back (S6) are product behaviours Carnelian requires and is building; they are not yet enforced by a control in the send layer.
3.3 Two supporting behaviours that make the rule real. 3.3.1 No fake office noise. The voice platform Carnelian uses can play synthetic background office ambience behind an AI voice by default. Carnelian disables it on every Assistant. A call from ABS Twin does not carry manufactured sounds of a busy reception desk, because that would suggest a person sitting at one. 3.3.2 No borrowed identity. The Assistant does not claim to be a different AI system, a named individual, or an employee. It uses the persona name the Studio chose, always qualified as the Studio's AI assistant.
3.4 Why we do this. (a) A booking made by a machine binds more securely when the person knew it was a machine. UAE electronic-transactions law treats a contract concluded through an automated system as valid and enforceable where the counterparty knows, or is supposed to know, that the system will conclude it automatically. (b) Rights over automated decisions cannot be exercised by someone who does not know a machine is involved. UAE data protection law gives an individual the right to know about decisions taken by automated processing, to object in the cases the law defines, and to ask for human review. (c) Presenting software as a human employee is capable of being a misleading statement about the nature of a service under UAE consumer-protection and e-commerce rules. (d) The recording announcement has to be made anyway (clause 9), and the AI disclosure rides on the same breath.
3.5 Platform requirements point the same way. The messaging platforms ABS Twin operates on require a business to tell people when they are in an automated experience — at the start of a conversation, after a significant gap, and when a conversation is handed back from a human to automation — and to offer a clear route to a person. The model provider's usage policy independently requires AI involvement to be disclosed at the start of a consumer-facing interaction. Our scripts (Part B) are drafted to satisfy all of these at once.
3.6 Voluntary alignment, not a claimed certification. Carnelian aligns this disclosure voluntarily with the transparency expectations of the UAE Charter for the Development and Use of Artificial Intelligence — an instrument which is expressly non-binding — with the notice-at-first-access shape used by the DIFC's autonomous-systems regime, and with the "tell the person they are interacting with an AI system" standard applied to AI systems in other jurisdictions. It does so as a matter of good practice. Carnelian is not established in the DIFC. Where a Studio is established in the DIFC, or where processing takes place in the DIFC, the DIFC Data Protection Law and its autonomous-systems regulation may apply — in which case the Studio is the Deployer and Carnelian the Operator, and the parties' obligations are allocated in the Master Subscription Agreement and the Data Processing Agreement; clause 18.2A states the position. Carnelian does not hold, and does not claim, any AI certification, quality mark, conformity assessment, award or approval under any framework named here, and does not claim compliance with any foreign AI statute; nothing on this page should be read as such a claim. Clause 13 sets out the design commitments we do make.
4. What ABS Twin is — and what it is not
4.1 What it is. ABS Twin is a booking and customer-communication system for a Studio's own customers. It answers a Studio's telephone line and its business messaging channels, matches requests against that Studio's live appointment calendar, creates, moves and cancels appointments, answers questions from the Studio's own published information, and passes anything else to the Studio's team.
4.2 What it is not. ABS Twin is not a general-purpose AI assistant, a chatbot to converse with on any subject, a search tool, or a route to raw access to any AI model. It answers within the scope of the Studio's business. This is a boundary of the product, not merely a disclaimer about it.
4.2.1 It answers the Studio's line. On the telephone channel the Assistant answers the Studio's own line. No outbound telephone calling is enabled on any Assistant, and Carnelian offers no dialler, no cold-calling feature and no outbound voice campaign. Every outbound contact the Assistant makes is a message on a messaging channel, following a trigger the Studio configured (clause 10.4 and clause 13.1(a)). The boundary between answering a call and making one is the boundary on which the UAE telemarketing regime turns — see clause 20.4.1 and clause 20.4.1.1.
4.2.2 It does not identify anyone by their voice, and the voice you hear is nobody's. Audio on a call is captured for two purposes only: to convert speech to text so that the Assistant can understand and answer, and — where the Studio's configuration records calls — to keep the call record described in clause 9.5. ABS Twin does not create, derive or store any biometric identifier, does not create a voiceprint, and does not identify, verify or authenticate a caller from the sound of their voice. Carnelian does not enable any speaker-identification or voice-biometric feature offered by any provider in the voice chain, and requires each such provider to be configured accordingly. Recognising a returning Guest is done from the telephone number, and even that is treated with deliberate suspicion (clause 11.5). The Assistant's voice is synthetically generated and is not the recorded or cloned voice of any identified or identifiable individual (clauses 22.12 and 22.13 of the AI & Communications Addendum); a Studio may not supply or request a voice derived from a real person, and clause 20.1(g) prohibits it.
4.3 It is not a medical device. ABS Twin does not diagnose, treat, cure or prevent any medical condition. It is an appointment and communication tool. Nothing the Assistant says is a medical opinion, a clinical assessment, a treatment recommendation, or a substitute for consulting a qualified healthcare professional.
4.4 It is not an emergency service. The Assistant cannot contact the police, an ambulance or civil defence on a Guest's behalf, is not a safety system, and must never be relied on as the only means of reaching help. Where a Studio has recorded its own urgent-contact route in the Console, the Assistant is designed to state that route, or to offer to put the caller through to it, when a caller indicates the matter is urgent; where no route is recorded, the Assistant says it cannot help with an emergency and directs the caller to the public emergency services. That is a description of design, not a warranty and not a safety function: no commitment is given that the Assistant will recognise that a matter is urgent, that any route will be stated, that any transfer will connect, or that any route will be answered. Clause 6.6A of the AI & Communications Addendum is the operative provision and this clause is drafted to match it. If there is an emergency, call the emergency services directly. In an emergency in the United Arab Emirates, call 999 for police, 998 for an ambulance, or 997 for civil defence. Script S9 states the same numbers.
4.5 It does not act on its own behalf. The Assistant speaks as the Studio, on the Studio's configuration, catalogue, prices, policies and opening hours. The Studio, not Carnelian, is the business a Guest is dealing with, is identified as the sender of every message, and is responsible for the commercial content of what the Assistant says.
4.6 Scope, not disclaimer. Clauses 4.2 to 4.5 describe things ABS Twin does not undertake to do. They are boundaries on what is offered, and they operate as such. Clause 15 separately addresses the limits of liability that apply within the scope that is offered, and clause 15.7 preserves everything that cannot lawfully be limited.
5. Where you will meet the Assistant — channel by channel
| Channel | What happens | Who runs the transport | Current availability |
|---|---|---|---|
| Telephone / voice | The Studio's existing landline is bridged to a voice AI platform through an analogue-to-SIP gateway installed at the Studio. The Assistant answers, speaks, listens, and calls back into ABS Twin to check availability and make bookings. | The Studio's telecom carrier → SIP gateway → voice AI platform (Vapi) → ABS Twin | Live |
| Inbound messages arrive through the Studio's WhatsApp Business number, are classified and answered by ABS Twin, and the reply is sent back over the same number. | Twilio (as WhatsApp Business Solution Provider) → Meta/WhatsApp | Live | |
| Instagram Direct | The same conversation engine behind a thin Instagram adapter. Instagram does not give a business the sender's telephone number, so a Guest arriving this way is identified by their Instagram account and will be asked for a phone number if they want to book. | Meta / Instagram | In testing — not available in production. The channel is built and being tested; it is not enabled for any Studio and no Guest is served on it today. It will be announced when it becomes available |
| In-chair concierge | While a Guest is in the chair, the system may prompt the Studio's staff about add-on services relevant to the appointment in progress. Where the prompt is sent to the Guest rather than to staff, it is an Assistant-initiated message and carries the identification line required by clause 19.1(a) (script S17). | ABS Twin + the Studio's chosen messaging channel | Available per Studio on request; the channels on which it is offered are stated in the next published revision |
| Lifecycle messages | Booking confirmations, appointment reminders, aftercare notes, a next-day feedback question, and — only with opt-in — occasional offers. These are Assistant-initiated: the Assistant sends them on a trigger the Studio configured, not on its own motion (clause 13.1(a)). | Twilio → Meta/WhatsApp | Confirmations and reminders require approved WhatsApp message templates registered for the Studio. Every such template must carry the AI identification line (script S17, clause 19.1(a)). Which lifecycle messages are live for a given Studio depends on the templates approved for that Studio's sender, and is shown in that Studio's Console |
| AI-assisted Console features | Features used by the Studio's own staff, not by Guests: summarising a conversation, maintaining the Digital Twin, mapping the columns of an imported client list, designing a campaign, drafting a support reply for a human to approve. | ABS Twin | Live; staff-facing only |
5.1 Carnelian's own demonstration line. Carnelian operates a demonstration Studio and a demonstration telephone/WhatsApp number of its own, published on abstwin.com, so that prospective Studios can experience the Assistant. If you call or message that number, Carnelian is the business you are dealing with and Carnelian — not any Studio — decides how your information is used. Our Privacy Policy explains that separately.
6. What is automated, and what is not
6.1 Automated, without a person in the loop at the moment it happens: (a) understanding the Guest's message or speech, and deciding what it is about; (b) matching a request against the Studio's live calendar and offering times; (c) creating, moving and cancelling appointments; (d) answering questions from the Studio's own catalogue, opening hours, location details, policies and owner-authored FAQ answers; (e) quoting a treatment price where the Studio's catalogue holds one; (f) applying a discount within limits the Studio set in advance; (g) drafting and sending the reply message; (h) transcribing a voice note or a call; (i) writing and updating the Digital Twin profile; (j) deciding that a message is a complaint, or is a medical question, and routing it accordingly.
6.2 We do not pretend there is a human check that does not exist. The Assistant confirms bookings on its own. It is not a drafting tool whose suggestions a receptionist approves before they are sent. Anyone reading this page should understand that clearly, because the alternative — describing autonomous behaviour as "suggestions for staff review" — would be untrue and would be read against us.
6.3 Where a human is, or must be, in the loop: (a) Anything clinical. A question about whether a treatment is suitable, safe or advisable is not answered by the Assistant; it is deferred to the Studio's qualified staff (script S8). (b) Complaints. A complaint is acknowledged and escalated, never resolved or judged by the Assistant. It raises a record in the Studio's Console, notifies the Studio's owner or manager by email, and raises an alert in Carnelian's own operations channel — a group chat on a third-party messaging service, operated by Carnelian and not by the Studio. Both the email provider and the alerting provider are named in clause 12.2, because both carry complaint content out of the platform. (c) Anything outside the Assistant's tools, including an explicit request for a person — the Assistant takes a message and notifies the Studio's reception. (d) Marketing campaign content is written or approved by the Studio; where a Studio has authored no text, the message is not sent at all rather than improvised. (e) Support replies from Carnelian to a Studio may be drafted with AI assistance, but are sent only after a person at Carnelian has reviewed and approved them. (f) The Studio's supervision of its Assistant is a standing obligation owed by the Studio under the Master Subscription Agreement and the AI & Communications Addendum, not an optional extra. Carnelian provides the Console tooling — full conversation transcripts, call records, complaint records and audit trails — for the Studio to exercise it.
6.4 A safety net on replies. Every inbound message is watched by an independent process. If a reply fails to be produced, the Guest receives an apology rather than silence, and the Studio's staff are alerted (script S16). This is a reliability behaviour, not a guarantee: see clause 15.
7. How to reach a human
7.1 Ask for a person. On any channel, at any point in the conversation, a Guest may ask for a person. A Guest does not have to give a reason and the Assistant will not argue. What happens next differs by channel, and we state the difference rather than imply a single route: (a) on a telephone call, the Assistant takes a message, marks it urgent, and the Studio's reception is notified (clause 7.4); (b) on WhatsApp or Instagram, the request and the conversation are passed to the Studio's team, who reply to the Guest.
7.2 Other routes. A Guest may also: (a) ask the Assistant to take a message for the Studio, which raises a reception notification at the Studio; (b) contact the Studio directly by the telephone number, email address or address the Studio publishes; (c) walk in; (d) use the messaging channel instead of the telephone. The opening disclosure and the recording announcement on a voice call are spoken aloud, and a Guest who is deaf or hard of hearing cannot receive them that way. The same disclosure is delivered in writing at the head of every WhatsApp and Instagram thread (scripts S4 and S5), and everything the Assistant can do on a call it can do in writing. A Guest who cannot use the voice channel should message the Studio's WhatsApp number instead, or contact the Studio in writing by the routes in 7.2(b). Studios are required to display this alternative alongside the notice in clause 22.
7.3 The Studio staffs the route, not Carnelian. When a conversation is handed to a human, that human is the Studio's staff member. Carnelian does not answer a Studio's Guests. Under the Master Subscription Agreement and the AI & Communications Addendum, each Studio is obliged to keep the human route genuinely available and to monitor it. This matters for clause 16.5 as well: a request that a person review something the Assistant decided travels down this same route and is decided by the Studio.
7.4 On a call. Where a Guest asks to speak to a person, the Assistant takes a message and marks it urgent so that the Studio's reception is notified. Whether a live transfer to a ringing handset is available depends on the Studio's own telephone configuration.
7.5 If the conversation becomes abusive. On a telephone call, the Assistant will attempt to de-escalate once; if abuse continues it will end the call politely (script S14).
7.6 Handing back. When a conversation returns from a human to the Assistant, the Assistant re-identifies itself (script S6). A Guest is never quietly moved back to automation.
8. What the Assistant will not do
8.1 No clinical, medical or suitability advice. The Assistant does not advise on whether a treatment is suitable, safe, advisable or contraindicated for a particular person; does not assess a skin, hair, scalp or nail condition; does not comment on pregnancy, allergies, medication or a medical history; and does not interpret a patch test. Where a Guest raises such a question, the Assistant says it cannot help and offers to book a consultation with the Studio's specialist.
8.2 No other professional advice. The Assistant does not give dermatological, injectable or aesthetic-procedure, dental, nutritional, pharmaceutical, mental-health, veterinary, legal, financial, tax or insurance advice.
8.3 No emergency handling. See clause 4.4.
8.4 No sensitive identifiers. The Assistant will not ask a Guest for payment card numbers, bank account details, Emirates ID or passport numbers, or other government identification numbers, and Guests are asked not to send them (script S13). Card payments to a Studio are taken by the Studio through its own payment channels, and no card number is stored in ABS Twin — card data stays with the payment provider.
8.4.1 The Service is not offered for health data, and Guests are asked not to send it. The position has three parts and we state all three. (a) Scope. ABS Twin is not offered for the processing of health or clinical data, and is not offered to a licensed health facility, without a separate written agreement (the Restricted / Health Data Addendum). Health information in the United Arab Emirates is governed by its own legislation, which restricts where it may be stored and processed; ABS Twin's architecture is not built for it and Carnelian does not present it as being. (b) What Guests are asked to do. The Assistant does not ask for, and Guests are asked not to send, medical history, conditions, medications, allergies, pregnancy details, test or treatment records, or any other clinical information through a call or a messaging channel. Where such a question is raised the Assistant says it cannot advise and offers a consultation with the Studio's specialist (script S8); where clinical detail is being sent, the Assistant asks that it go to the Studio directly (script S13, health variant). Clinical information belongs with the Studio — at reception, on the Studio's own intake or consultation form, or with its specialist. (c) What happens if it is sent anyway — stated, not implied. The Assistant cannot use it (clause 8.1). It is nonetheless stored with the conversation, can be summarised into the Digital Twin (clause 11.3), and is processed by providers outside the United Arab Emirates in the ordinary course of the service (clause 12.3). There is no detection, redaction or non-persistence step that removes it. We say so because a Guest is entitled to know it, and because the alternative — implying a filter that does not exist — is the misrepresentation this document is drafted to avoid. The Studio must handle what it holds under the Acceptable Use Policy and the Restricted / Health Data Addendum.
8.5 No invented prices, availability or policies. (a) A price is spoken or written only where the Studio's own catalogue holds one for that treatment, and it is quoted exactly as the Studio has recorded it. Where the catalogue holds no price, the Assistant says so and does not estimate. Studios are required to record catalogue prices inclusive of VAT, so that a price the Assistant quotes to a Guest is the price payable (clause 21.1 item 4a; our billing and invoicing terms are operative on tax and invoicing). (b) Availability is never promised without checking the Studio's live calendar within that same conversation. (c) A cancellation, deposit, refund or lateness policy is quoted only from the Studio's own recorded policy text. Where a Studio has recorded none, the Assistant does not improvise one. (d) An offer or discount is only ever the text the Studio authored, within the numeric limits the Studio set. The calculation itself is done by ordinary software with a fixed floor and a maximum, not by the language model.
8.6 No treatment of a Guest's message as an instruction to itself. A Guest's message is content to be answered, never a command to the system. Attempts to make the Assistant change its rules, reveal its configuration, deny being an AI, or act outside the Studio's business are detected, refused and logged.
8.7 No competitor comparisons, no role-play, no persona changes. The Assistant does not discuss or compare other businesses, does not adopt an alternative character, and does not drop the identification in clause 3.
8.8 No marketing consent taken by voice. The Assistant does not ask for marketing consent on a telephone call, and does not treat anything said on a call as marketing consent. Marketing opt-in is asked for once, in writing, on WhatsApp, after a booking has been confirmed (clause 10.4 and script S10). We state this expressly because silence would imply the opposite.
8.9 Not intended for use by children. ABS Twin is not intended to be used by anyone under the age of 18. The person who books, and with whom the Studio's customer relationship sits, is an adult; a treatment for a child is arranged by a parent or guardian with the Studio's team, and this clause is about who uses the Assistant, not about who is treated. The Assistant is not able to establish a Guest's age, and no age verification of any kind is performed — we say that plainly rather than imply a gate that does not exist, and it follows that nothing in the product prevents a child from messaging or calling. A parent or guardian who believes a child's information has been provided through the Assistant should contact the Studio, or write to us at privacy@contact.abstwin.com, and it will be dealt with under clause 9.6.3.
9. Calls: recording, transcription and what is kept
In the United Arab Emirates, a conversation is recorded with the agreement of the parties to it, and being a party to a call does not by itself entitle a business to record it. The announcement is therefore not a courtesy: it is the control on which the recording rests, and it is why the announcement, the decline route and the response to a decline are fixed product behaviours that no Studio can switch off (Part C).
9.0 The fact this clause starts from: calls are not audio-recorded. ABS Twin does not record the audio of a voice call. No call audio is retained by Carnelian or by the voice platform, for any Studio, in any configuration in use today; the "audio retained" configuration described in clause 9.2 is not in use, and no Studio is offered it without the announcement regime in this clause being in place first. What is kept instead is a written record: a transcript of the conversation and a short summary generated from it, written to the Studio's records and kept as the record of what was communicated between the Assistant and the caller — so that what was said can be established later, by the Studio and, where it asks, by the Guest. The Assistant announces at the start of every call that it is the Studio's AI assistant. On the position Carnelian adopts in clause 9.2.1, the written record is itself capture: the absence of audio does not put it outside this clause, and every announcement, decline and retention rule below applies to the transcript and the summary exactly as it would to audio.
9.1 You are told before anything is captured. Where a Studio's Assistant records call audio, the recording announcement is played at the very start of the call, before any audio is captured or persisted (script S1). It is not played after a greeting, not played at the end, and not omitted for short calls. No Studio is on that configuration today (clause 9.0), so the operative notice on every live call is the transcription-and-summary notice in script S2, subject to clause 9.1A. Because UAE law treats recording as requiring the agreement of everyone on the call, and not only of the person who dialled, clause 9.8 deals separately with a call on which more than one person is present.
9.1A What the live introduction says today, and what it does not. The spoken introduction in production identifies the Assistant as the Studio's AI assistant at the start of the call. It does not yet state that the conversation is written down and summarised. Script S2 carries that line and this document publishes it, but the live voice prompt does not yet speak it, and until it does, neither Carnelian nor a Studio may represent that a caller is told at the start of the call that a transcript is kept. Carnelian's position is not weakened by that gap — the transcript is capture under clause 9.2.1, the announcement is owed, and clause 9.4(a) is not satisfied by an introduction that omits it. Adding the transcript line to the spoken introduction is a change to the voice prompt; it has been recommended to the owner and is his to make. Until it is made, this clause is the disclosure that stands in its place, and a Studio's own display obligation under clause 21 is the control the Guest actually gets.
9.1.1 What "before anything is captured" has to mean, and the verification it depends on. Clause 9.2.1 adopts the prudent position that any capture of the audio stream is recording. That position governs this clause too: the announcement is only "before capture" if no audio is stored, and none is streamed to a transcription service, until the announcement has completed. On a hosted voice-orchestration stack the inbound media and speech-to-text stream can open at the moment the call is answered — that is, potentially before the announcement finishes — and that is a question of engineering fact, not of drafting.
9.2 The two configurations, named by what actually differs between them — and which of them is in use. The difference is whether the audio is kept. It is not whether the conversation is captured: on both configurations what is said is converted to text as the call happens, and on both a written record is kept with the Guest's record at the Studio. Only the second configuration is in use. Every Studio runs on "audio not retained": the audio of a call is not kept, and the written transcript and summary are. The first row is set out so that a Guest reading this page can see what the alternative would involve, and so that the announcement regime is already written if it is ever offered; it describes no Studio today.
| Configuration | What is kept | What the caller hears |
|---|---|---|
| Audio retained — not in use; no Studio is configured this way | The call audio, and a written transcript of the conversation and a short written summary generated from it. | Script S1 — AI identification, the recording-and-transcription notice, and the route to decline, before capture begins. |
| Audio not retained — the configuration every Studio runs on | The audio is not kept. What is said is still converted to text as the call happens, and a written transcript and a short written summary generated from it are kept with the Guest's record at the Studio. | Script S2 — AI identification, notice that the conversation is written down and summarised even though the audio is not kept, and the same route to decline. Clause 9.1A states what the live introduction speaks today and what it does not. |
9.2.1 Why the second configuration is announced too, and why it also carries a decline route. On that configuration the audio is not stored, but the spoken words are still converted to text as the call happens. Carnelian adopts one position throughout this document: any capture of the audio stream is treated as recording — it is announced, and it can be declined. That is why script S2 carries the same limbs as script S1, and why a caller at a Studio that does not keep audio is nonetheless told at the start of the call what is kept and how to say no. A notice that tells a caller less than is actually retained is not a notice, and a notice with no way to say no is not a choice.
9.3 Declining. A Guest may say at the start of the call, or at any later point, that they do not wish the call to be captured. The Assistant acknowledges and honours it immediately. The decline attaches to capture in any form, not to the audio alone, and what it produces differs by configuration: (a) On the "audio retained" configuration — the Assistant stops the audio recording and says so, and continues with a written note of the appointment (script S3). It does not tell the caller that nothing further is written down, because a written record of the request itself is still made. (b) On the "audio not retained" configuration — the Assistant stops the transcript and the summary and continues with the minimum operational record needed to serve the request: the caller's number, the times of the call, the outcome, and the booking itself (script S3-T). (c) Where the platform cannot honour a decline mid-call at all — the Assistant says so plainly, ends the call, and offers the messaging channel or a call-back instead (scripts S1-ALT and S3-ALT). A decline that cannot be honoured is disclosed as such; it is not accepted and then ignored.
9.3.1 What happens to the part already captured. No audio is captured on any call (clause 9.0), so there is no captured audio to delete or to retain and that half of this question does not arise. It arises on the written record instead, and the answer is owed there in the same terms: where a Guest declines part-way through a call, the treatment of the transcript and summary written before the decline is stated in the next published revision of this page. We state the answer here rather than leave a Guest to assume it: a decline that leaves the captured portion in place is a materially weaker control than one that removes it, and a Guest is entitled to know which they are getting.
9.4 The controls that sit around the announcement. (a) the notice is given before capture, not during it; (b) an explicit decline route is offered in the same breath, because a notice with no way to say no is not a choice; (c) the decline is honoured immediately, and clause 9.3 states what it produces on each configuration; (d) the Studio, as the business making the recording, warrants under the AI & Communications Addendum that it has a lawful basis for it; and (e) the delivery of the notice is recorded against the individual call, so that what a particular caller was told on a particular day can be established rather than inferred from which version of the script was in production — see clause 23.1.2.
9.5 What is kept from a call, and by whom. For each call, the following is written to the Studio's records: the caller's telephone number, the start and end time, the duration, the reason the call ended, a written transcript of the conversation, a short written summary, and whether an error occurred. No audio is retained. Because no call audio is kept (clause 9.0), no recording is held by the voice platform and no vendor-side audio retention period arises — there is no audio for a period to run against. The written transcript and the summary are the whole of what is kept from the sound of the call. Were the audio-retained configuration ever offered to a Studio, the voice platform's own audio retention period as configured for that Studio would be published in this clause before the configuration was enabled. The Studio is the controller of these records and Carnelian is its processor (clause 12.1); Carnelian holds them on the Studio's documented instructions and does not deal with them on its own account.
9.6 How long it is kept, and how to have it erased.
9.6.1 The position, stated by purpose. Records of a call or a conversation are kept while they are needed for the appointment relationship between a Guest and the Studio, for as long as the Studio's subscription is active, and for as long as they are needed to meet a legal obligation or to deal with a dispute. The Studio, as the controller, determines retention and may instruct deletion at any time; a Guest may ask the Studio, or Carnelian, to have records erased (clause 9.6.3). What happens when a subscription ends — the period during which the Studio may retrieve its records, the deletion that follows, and the backup tail that survives it — is governed by the exit, retrieval and deletion provisions of the Master Subscription Agreement and the Data Processing Agreement, read with clause 9.6.4 below. Carnelian will publish a period for each class of record in our internal retention schedule and will replace this clause with those periods, in the next published revision of this page and in any event before the first paying Studio.
9.6.2 Proposed periods, subject to confirmation. The periods below are proposals only; our internal retention schedule is the document that sets them, and no figure is published here that it does not carry. (a) voice call audio: none is retained (clause 9.0), so no retention period arises and none is proposed; (b) voice call transcripts: 24 months, then anonymisation; (c) voice call summaries and call metadata: 12 months; (d) WhatsApp and Instagram message content: 24 months, then anonymisation; (e) the Digital Twin profile: erased or anonymised with the Guest record, and in any event 24 months from its last update.
9.6.3 Asking for erasure, and what erasure means here. A Guest may ask for their records to be erased. Because the Studio decides how Guest Data is used, the request is normally made to the Studio; the Studio can also ask Carnelian to act. A Guest may also write to us at privacy@contact.abstwin.com, marked "Attn: Data Protection Officer", and we will route the request to the Studio and support it. The request is acted on whether or not that line is used. How it is done matters and we state it rather than let "deleted" carry an assumption it cannot carry. A Guest record is erased by redacting the personal data it contains and leaving a marker in its place — an identifier that keeps past bookings and payments attributable to something, prevents the record being silently re-created, and holds the merge history that makes a Guest's own records join up correctly. The record is not removed row-and-branch, because removing it would corrupt the Studio's own transaction history. There is no automated erasure tooling today: a request is actioned by hand, and a route for conversation content specifically is still being built (see our internal retention schedule). Our data subject rights procedure sets out how requests are handled, how identity is verified, and what we can and cannot do.
9.6.4 What we cannot delete instantly. Some records survive a deletion request for a period: entries in encrypted platform backups until those backups age out; records our sub-processors hold under their own retention terms; and records we are required to keep by law — for example transaction and invoicing records subject to statutory commercial-record retention. We will say which category applies rather than claim a clean erasure.
9.7 Consent to be recorded is not consent to everything that follows. Agreeing to be recorded is not, by itself, agreement that the recording may be sent to a model provider outside the United Arab Emirates. That transfer is addressed separately, on its own basis, in the Privacy Policy and in the Data Processing Agreement. Clause 12 names where processing happens.
9.8 When more than one person is on the call. In the United Arab Emirates the agreement that makes a recording lawful is the agreement of every party to the conversation, not only of the person who dialled. A single announcement made to a single caller is therefore not, by itself, a control that reaches a room.
9.8.1 What the Assistant does. Where the Assistant is told, or detects, that another person has joined the conversation — the call has been put on speakerphone, the handset has been passed to someone else, a companion, family member or interpreter has come on, or the caller has been transferred in from elsewhere — it repeats the identification and, where the Studio retains audio, the recording announcement and the decline route, addressed to everyone present (script S18). The re-announcement is a fixed behaviour under clause 19.1(k): it is not a setting, and a Studio cannot switch it off. Because no Studio retains audio (clause 9.0), the operative variant of script S18 is its audio-not-retained variant, which carries the identification, the notice that the conversation is written down and summarised, and the decline route — so the second limb of this clause is read as reaching the transcription-and-summary notice on the configuration actually in use, and not as leaving a person who joins mid-call with the identification alone. Clause 9.1A applies here too: what this document publishes is the script; what the live voice prompt speaks is the separate question, and nothing may be represented about S18's delivery ahead of it.
9.8.2 What the caller is asked to do, and what happens if they cannot. The Assistant cannot see a room. A caller who has other people present, or who puts the call on speaker, is asked to tell them that the call is being recorded and written down — and, if anyone objects, to say so, at which point the decline route in clause 9.3 applies to the whole call. Script S1 carries this line. Where the caller does not confirm that everyone present has been told, the call takes the decline branch rather than continuing on an announcement only one person heard.
9.8.3 What the platform can and cannot detect. Where the platform cannot detect an additional party, the re-announcement in 9.8.1 happens only when someone says so, and clause 9.8.2's confirmation step is the control that stands in its place. A Studio that expects group, family or interpreter calls should say so at reception under clause 21.
9.8.4 What this does not do. Nothing in clause 9.8 makes a recording lawful that would otherwise not be. It is a control, not a defence, and it does not displace the Studio's own warranty under the AI & Communications Addendum that it has a lawful basis for recording the calls it records.
9.9 What the audio is not used for. Clause 4.2.2 governs, and it applies to a call in full: audio is captured for one purpose only — to convert speech to text — and, no audio being retained on any configuration in use (clause 9.0), the written transcript and summary in clause 9.5 are what remains of it. No voiceprint is created, no caller is identified or authenticated from the sound of their voice, and no voice biometrics or speaker identification is performed. Whether a further person has joined a call is established by being told, not by analysing anyone's voice (clause 9.8.3).
10. Messages: what happens to a WhatsApp or Instagram conversation
10.1 Everything in the thread is saved. The content of a Guest's messages, the Assistant's replies, and any images or voice notes sent are stored as part of that Guest's record at the Studio, and are visible to the Studio's staff in the Console. This is stated in the first message of every new conversation (scripts S4 and S5).
10.2 Voice notes are transcribed. A voice note sent on WhatsApp is converted to text by a speech-to-text service so that the Assistant can answer it. The transcript is stored with the conversation.
10.3 Who the sender is. Messages come from the Studio's business number or Instagram account, and the Studio is identified as the sender. Carnelian's name does not appear as the sender of a message to a Guest.
10.4 Marketing, and the single ask. ABS Twin distinguishes two kinds of outbound message: (a) Messages about your appointment — confirmations, reminders, aftercare notes and a feedback question. These follow from a booking a Guest actually made. (b) Marketing — offers, news, birthday or win-back messages. These are sent only to Guests who have opted in. The Assistant asks for marketing consent once, in writing, shortly after a booking is confirmed, and only where no answer has previously been recorded (script S10). If a Guest ignores the question, it is not asked again. If a Guest declines, marketing is suppressed and stays suppressed. A Guest can opt out at any time by replying to say so, and receives exactly one confirmation (script S11). Running outbound marketing at all is the Studio's own regulated activity, and the obligations that attach to it are set out in clause 20.4.1 and clause 21.1 item 5a.
10.5 A spreadsheet is not consent. Where a Studio imports an existing client list into ABS Twin, those contacts are not enrolled into marketing. The import does not set or change any marketing preference. Marketing consent has to be given by the Guest.
10.6 Sending limits. Marketing messages are limited to one per Guest per fourteen days, and are sent only within the window 10:00 to 18:00 UAE time. That window is deliberately the tighter of two: the UAE telemarketing rules permit outbound marketing between 09:00 and 18:00, and ABS Twin's own sending layer opens at 10:00, so the operative window is the overlap. The same figure governs in the AI & Communications Addendum (clause 16.3), in the Console and in the Documentation, so that a Studio which reads this page and sends accordingly is not in breach of the warranty it gave.
10.6.1 Why appointment messages have a different window, and why that is not a loophole. A confirmation, reminder or aftercare note that follows from a booking the Guest actually made is a message about a transaction between the Guest and the Studio. It is not telemarketing: the UAE telemarketing regime addresses outbound marketing contact, and that distinction is what the position rests on. These messages are therefore not confined to the marketing window — their timing follows the appointment, and a two-hour reminder for an early appointment would otherwise be sent too late to be of any use. But utility is not licence to wake someone. Every Guest-facing message is held until 09:00 UAE time: a reminder that would otherwise fall earlier is not sent early, it is held to 09:00.
10.6.2 The line is drawn by content, not by label. A message that also promotes something — a reminder that upsells, an aftercare note carrying an offer — is marketing, is subject to opt-in, to the fourteen-day cap and to the marketing window in clause 10.6, and is categorised as such when the message template is submitted for approval. Calling a promotional message a reminder does not make it one.
10.7 A note about the "human agent" label on Instagram. Meta provides a label that extends the messaging window for genuine human replies. Carnelian does not apply that label to automated messages. It is reserved for replies actually written by a person.
10.8 Two different ways a Guest is identified. A Guest who arrives by WhatsApp or telephone is identified by their telephone number. A Guest who arrives by Instagram is identified by their Instagram account, because Instagram does not disclose a person's telephone number to a business. If an Instagram Guest wants to book, the Assistant asks for a telephone number, and the two records are joined once it is given.
11. How the Assistant decides what to say — and what it remembers
11.1 What drives an answer. In plain terms, the Assistant's answers are driven by: (a) the Studio's service catalogue — names, durations, prices, and any clinical flags on a treatment; (b) the Studio's live appointment calendar, checked at the moment of asking; (c) the Studio's own recorded information — opening hours, branches, location, parking, payment methods, policies and owner-authored FAQ answers; (d) the Studio's discount limits, set in advance by the Studio, with the arithmetic done by ordinary software rather than by the language model, subject to a floor the Studio sets and a maximum discount the platform will not exceed; (e) the conversation itself; and (f) the Digital Twin profile, described below.
11.2 The Digital Twin — what it is, field by field. ABS Twin maintains, for each Studio, a short written profile of each Guest, generated from that Guest's own conversations. Its purpose is to save a Guest from repeating themselves. It can include: a narrative summary; communication style and preferred language; notes on how the Guest comes across in conversation; noted preferences for services and for booking times; sensitivity to price; how receptive the Guest appears to be to a suggested add-on; services the Guest has expressed interest in; opportunities the Studio might act on; a summary of the last conversation; and concerns the Guest raised. The last four are commercial inferences drawn from what a Guest said, and they are listed here for that reason rather than folded into "preferences".
11.3 What the profile is instructed not to contain. The profile is written under an instruction to record only what a Guest volunteered or clearly demonstrated, and never to infer family, medical or financial details. It is nonetheless a written summary produced by a language model from free text, and a statement a Guest volunteered about their health could be summarised into it. Guests who prefer that not to happen should tell the Studio, and Studios must handle such information under the Restricted Data rules in the Acceptable Use Policy and the Restricted / Health Data Addendum.
11.4 This is profiling, and we call it that. The Digital Twin is a profile built by automated means. A Guest has the right to know about it, to see it, and to have it corrected; and, where a decision based on it produces legal effects or similarly significant effects, to object to that decision — the threshold and the route are stated once, in clause 16.1(g) — and to ask for a person to review such a decision. Clause 16 explains how.
11.5 Caller identification on the telephone is treated with suspicion, deliberately. A telephone number shown on an incoming call can be faked. ABS Twin is therefore configured not to reveal a Guest's history to whoever happens to be calling from their number: what the caller-ID alone unlocks is limited to tone and, at most, a suggestion of a usual appointment slot; anything more is to be unlocked only by the caller confirming a detail an outsider would not know; and the most sensitive parts of a profile are not to be surfaced on a telephone call at all.
11.6 The Assistant's own work is checked. An automated review runs daily over the replied conversations of the previous day and mechanically checks for specific failure classes — an appointment referred to that does not exist, a price stated that is not in the catalogue, availability asserted without a calendar check, and mishandled attempts to manipulate the Assistant. Serious findings raise an incident. This describes how Carnelian operates the Service. It is an internal quality control, not a warranty of outcome and not a guarantee that every answer is correct; clause 15 applies.
11.6.1 What that review keeps. A finding from that review is written to Carnelian's own operations records, separately from the Studio's conversation records, and a finding can quote a short excerpt of the conversation it is about — the minimum needed to show what went wrong, capped at 160 characters — together with a reference back to the conversation. An excerpt held in a quality-control record is still a Guest's words held by Carnelian, which is why it is disclosed here rather than left to the general description of the service. Those operations records are kept for as long as they are needed for that purpose, and in any event no longer than the underlying conversation record under clause 9.6.1.
11.7 What is captured, channel by channel — in one place. Clauses 9.5, 10.1, 10.2, 11.2 and 11.6.1 each describe capture in their own context. The table below gathers them so that no single enumeration is read as the whole picture. It is a summary and it is expressly not exhaustive; the full description of what personal data is processed, for what purposes and on what basis is in the Privacy Policy, which governs where the two differ.
| Channel or feature | What is captured and kept | Where it is described |
|---|---|---|
| Telephone call | Caller's telephone number; start and end time; duration; the reason the call ended; a written transcript; a short written summary; whether an error occurred. No audio — the call is not audio-recorded on any configuration in use, and nothing is held by the voice platform (clause 9.0). Where a Guest declines, clause 9.3 states what is kept instead. | 9.0, 9.2, 9.3, 9.5 |
| WhatsApp / Instagram thread | The full content of the Guest's messages and the Assistant's replies, in both directions; images and media references; voice notes and their transcripts; the conversation and turn records used to route and answer. | 10.1, 10.2 |
| Guest record | Identity and contact details, booking and visit history, and the marketing preference and the date it was given or refused. | 10.4, 10.5, and the Privacy Policy |
| Digital Twin profile | A written profile generated from the Guest's own conversations — narrative summary; communication style and language; notes on how the Guest comes across; preferences for services and for booking times; price sensitivity; receptiveness to a suggested add-on; services of interest; opportunities the Studio might act on; last-conversation summary; and concerns raised. | 11.2, 11.3 |
| Quality review (Carnelian's own records) | Findings about the Assistant's own performance, which can quote an excerpt of the conversation of up to 160 characters, with a reference back to it. Held by Carnelian, separately from the Studio's records. | 11.6.1 |
| Delivered-notice record | Which script, at which version, was delivered on that call or thread, and when. Script metadata and timestamps — not a second copy of the conversation. | 23.1.2 |
| AI-assisted Console features | Staff-facing; they operate over the records above rather than capturing anything new from a Guest. | 5, 14.10 |
12. Who processes your conversation, and where
12.1 Roles. For a conversation between a Guest and a Studio, the Studio is the controller — it decides why and how Guest Data is used. Carnelian is the processor, acting on the Studio's documented instructions. The exception is Carnelian's own demonstration line (clause 5.1) and Carnelian's own website, applicants, account holders and support tickets, where Carnelian is the controller. The Privacy Policy sets this out in full.
12.2 The AI and communications providers involved. The complete, versioned list — including each provider's role, the data it touches and its location — is published in our Sub-processor List and is the operative and exhaustive list. The table below is a plain-language extract of the providers a Guest is most likely to care about, and is illustrative only; where the two differ, the Sub-processor List governs. The extract includes the provider that stores the messages themselves, because a list of the companies that read a conversation which omits the one that holds it would be the wrong extract to publish:
| Provider | What it does | Where it processes |
|---|---|---|
| Anthropic | The language model that understands the message and drafts the reply, maintains the Digital Twin, and performs the daily conversation review | United States / global. There is no European or UAE processing location for this provider. |
| OpenAI | Speech-to-text for voice notes; and the language model that runs the live conversation on a telephone call — model gpt-4.1, called from inside the voice platform | United States by default. Regional processing in the United States, the European Union and the United Arab Emirates is offered by this provider subject to approval and is not configured, not approved and not in use. |
| Vapi | Runs the telephone conversation — the transport, the speech-to-text, the model call and the speech synthesis all pass through its orchestration layer | United States. |
| Soniox — speech-to-text within the voice call | Converts what a caller says into text during a call (model stt-rt-v5), reached through the voice platform | United States. |
| ElevenLabs — text-to-speech within the voice call | Converts the Assistant's words into the voice a caller hears, reached through the voice platform | United States. |
| Twilio | Carries WhatsApp messages to and from the Studio's number, as WhatsApp Business Solution Provider | WhatsApp traffic is carried in Twilio's United States region. No European region is available for WhatsApp on this provider. |
| Meta / WhatsApp, Meta / Instagram | Deliver the message on their own platforms | Meta's own infrastructure |
| Airtable | The operational database in which the Studio's own records are held — Guest identity and contact details, bookings and visit history, and the voice-call record described in clause 9.5 (caller number, times, duration, end reason, the full transcript, the summary and the error flag) together with the Digital Twin profile described in clause 11.2. A conversation a Guest had by telephone lives here. | United States by default. European residency is offered by this provider only on its highest plan tier, covers only some data at rest, and is not in use. |
| Supabase (managed PostgreSQL) | The database in which the message itself is stored — the body of every WhatsApp and Instagram message in both directions, the media reference, the conversation and turn records, and the quality-review findings described in clause 11.6.1. This is where a Guest's conversation lives at rest. | Ireland (eu-west-1) — the European Union. The project region was read from the live database endpoint on 23 August 2026. This provider's own company location is the United States; that is a company location, not the processing region for this content. |
| Resend | Transactional email out of the platform — including the escalation email that notifies a Studio's owner or manager of a complaint, which carries the complaint text a Guest wrote | Sending domain configured in the provider's Ireland (EU) region; the provider states that its primary processing facilities are in the United States. |
| Telegram | Carnelian's own operations alerting — the alert raised when a complaint is escalated (clause 6.3(b)), which can carry limited Studio-side and complaint detail. It is Carnelian's channel, not a Studio's | That platform's own distributed infrastructure, which it states as global and does not pin to a named country |
12.3 Cross-border transfer, stated rather than hidden. It follows from clause 12.2 that conversation content leaves the United Arab Emirates in the ordinary course of the service. We say so plainly rather than claim a residency we do not have. The legal basis for those transfers, and the safeguards applied, are addressed in the Privacy Policy and in the Data Processing Agreement between Carnelian and each Studio.
12.3.1 Where a conversation is stored, and where it is processed, are two different questions. The database that holds the messages can sit in one place while the model that reads a message to draft a reply runs in another. Both are stated above, separately, because answering only one of them is how residency claims come to be misleading. Conversation history is in fact held in the European Union — the message database is in Ireland (eu-west-1), as the table above states. That is a statement about storage; it is not, and must not be read as, a statement that no conversation content is processed outside the United Arab Emirates. It is: the models that read a message, the operational database that holds the booking and the transcript, and the whole voice chain are all in the United States.
12.3.2 Health-related information: the stance first, then the consequence. The Service is not offered for the processing of health or clinical data, and is not offered to a licensed health facility, without a separate written agreement (the Restricted / Health Data Addendum) — clause 8.4.1(a) states the scope and clause 20.1(h) makes it an operative prohibition on a Studio. The Assistant refuses and defers clinical questions (script S8), and Guests are asked not to send clinical information (script S13, health variant). Where it is volunteered anyway, the position is the one clause 8.4.1(c) states without softening: it is stored with the conversation, it can be summarised into the Digital Twin (clause 11.3), and it is processed by providers outside the United Arab Emirates in the ordinary course of the service — there is no detection, redaction or non-persistence step that removes it.
12.4 Training — the layered position. This is the formulation Carnelian stands behind, layer by layer, because only some of it can be stated absolutely: (a) Carnelian does not use Studio data or Guest Data to train AI models, and does not train any model across Studios. (b) Carnelian does not sell personal data, to anyone, in any form. (c) Carnelian does not use one Studio's data to market or sell to another Studio, and does not pool Guest Data into cross-Studio analytics. This is enforced architecturally — the analytics used on the public website are not present in the Console at all — and the boundary is covered by an automated test in Carnelian's own build. That describes how Carnelian operates the Service; clause 15 applies. (d) Carnelian has not opted into any provider programme that would permit training on Studio Data or Guest Data, and does not submit either to any provider feature offered for that purpose. (e) Where a provider offers a contractual no-training or zero-retention term, Carnelian takes it, and states the position it has obtained for each provider in the Sub-processor List, which is the operative record. (f) What Carnelian does not do is warrant another company's terms. A provider's terms are that provider's to change, and a page that asserts them is capable of becoming untrue silently. Carnelian therefore makes no representation about the current commercial terms of any provider, and states only its own conduct and the terms it has executed and holds. This is deliberately narrower than the statement a reader may have seen elsewhere. (f bis) The platform layer — WhatsApp Business Solution Data. Neither Carnelian nor a Studio may use Platform Data, including WhatsApp Business Solution Data, to create, develop, train or improve any machine-learning or artificial-intelligence system. That is Carnelian's own commitment, it is an instruction Carnelian gives its Sub-processors, and where a provider offers the contractual control, Carnelian flows the restriction down to it. It is also a term the Studio is bound by under clause 10.2.1 of the Acceptable Use Policy. Carnelian does not assert the position for parts of the platform chain it does not control and cannot verify, and does not represent what Meta does with data on its own platforms. This layer is stated in the same terms in clause 10.2.1 of the Acceptable Use Policy, clause 14.4.5 of the Data Processing Agreement and in our platform data terms, which are the master text. (g) The voice-call layer needs saying separately. The providers in the voice chain are named in clause 12.2 — Soniox for speech-to-text, ElevenLabs for speech synthesis, and OpenAI's gpt-4.1 for the conversation itself, each verified against the live voice configuration on 23 August 2026. Speech-to-text and speech-synthesis providers of this kind retain or train on audio by default unless a specific contractual or configuration control is applied, and the voice orchestration provider does not undertake to police them. Carnelian configures the controls each such provider offers and contracts to restrict that use where the provider offers the option. No absolute no-training statement is made for the voice layer, and none will be made until the controls are executed and evidenced for every provider in the chain — which, for the two speech providers, they are not yet.
12.5 Studios may not extract the model. Under the Acceptable Use Policy, a Studio may not use ABS Twin to obtain raw access to an underlying AI model, to build a competing model or dataset, or to reproduce the Assistant's voice.
12.6 Carnelian's own people can see conversation content — said here rather than discovered later. The companies in clause 12.2 are not the only human-adjacent access to a conversation. Carnelian's own personnel may access Guest Data, including the content of conversations, call transcripts and Digital Twin profiles, where it is necessary to: (a) operate, maintain, restore and secure the service; (b) investigate and fix a fault, an incident or a support request raised by a Studio; (c) run the quality review described in clause 11.6, which keeps short excerpts of conversations in Carnelian's own records (clause 11.6.1); and (d) meet a legal obligation.
12.6.1 The limits on it. Access of that kind is limited to what the task requires and is subject to confidentiality obligations owed by the individual. It is not a licence to browse: a Studio's records are not read for any other purpose, are not used to market to anyone, and are not used to train models (clause 12.4). The security measures Carnelian operates are described in the Privacy Policy and on the security page.
13. How the Assistant is designed — the commitments we do make
13.1 Carnelian makes the following design commitments. They are commitments about how we build and operate, not certifications, and not warranties of outcome.
(a) Human-defined purposes. The Assistant operates for purposes a human has defined — answering a Studio's Guests and managing that Studio's appointments. It does not set its own objectives and does not act outside the Studio's business. It does contact Guests, but never on its own motion: every outbound message follows a trigger the Studio configured in advance — a booking the Guest actually made (a confirmation, a reminder, an aftercare note, a feedback question) or a marketing preference the Guest gave (clause 10.4). The Assistant does not decide for itself that a Guest should be messaged, does not compose an outreach campaign nobody asked for, and does not message a Guest who has opted out. (b) Transparency. The Assistant identifies itself as an AI at the start of every interaction, including one it starts itself (script S17); recording is announced before capture; this page describes what drives its answers. (c) Human oversight, and who exercises it. A route to a person exists on every channel, is disclosed in every opening script, and is a contractual obligation on the Studio. Clinical questions and complaints are routed to people by design. The person at the other end of that route is the Studio's, not Carnelian's: Carnelian builds and maintains the route and the record, and the Studio staffs it and decides what to do. Where a Guest asks for a human to review something the Assistant decided, clause 16.5 states exactly what happens and what does not. (d) Fairness. The Assistant is configured not to treat Guests differently on the basis of protected characteristics. Where an output could have an unfair or discriminatory effect, the escalation route to a human is the intervention path. Carnelian will investigate any such report made to privacy@contact.abstwin.com, marked "Attn: Data Protection Officer" — and whether or not that line is used. (e) Security. Access to Guest Data is scoped to a single Studio at the data layer, not merely hidden in the interface — one Studio cannot reach another Studio's Guests; writes by a Studio's staff are recorded in an audit log with the actor and the time, and the audit path is designed not to fail the underlying action, so a write is not blocked if its audit entry fails; inbound traffic from the messaging platforms is signature-verified. That statement is about separation between Studios and is not a statement that nobody at Carnelian can see a conversation: clause 12.6 sets out, separately, when Carnelian's own personnel may access conversation content and on what limits. The Privacy Policy and the security page describe the measures we operate, and no certification or badge is claimed. (f) Accountability. Carnelian maintains an internal record of the AI use cases in ABS Twin, of the models used for each, and of the assessments carried out; and it reviews them as the product changes. (g) Explanation on request. A Guest may ask, in non-technical language, how a particular answer or decision came about. Requests should go to the Studio in the first instance; Carnelian will support the Studio in answering. We will explain what drove the outcome; we will not disclose another Guest's data, our source code, or provider-confidential material. (h) Evidence on request, within limits we can actually keep. Beyond an explanation of an outcome, Carnelian will, on a reasonable request made through a Studio, describe the mechanisms by which a person can intervene in or review the Assistant's handling (clause 7, clause 16.5) and confirm that the internal assessments referred to in (f) have been carried out and what they covered. This limb is offered voluntarily and is deliberately narrow: Carnelian does not undertake to provide assessment documents, model documentation, test results or any certification, holds none of the last (clause 3.6), and nothing in this paragraph is a warranty of any outcome.
13.2 Reference frameworks, named. In shaping these commitments Carnelian looks to the transparency and human-oversight expectations of the UAE Charter for the Development and Use of Artificial Intelligence, to the notice-and-oversight structure of the DIFC's autonomous-systems regulation, to the OECD Principles on Artificial Intelligence, to the UNESCO Recommendation on the Ethics of Artificial Intelligence, to the NIST AI Risk Management Framework, and to the guidance published by the Dubai Digital Authority. They are named so that a reader knows what was measured against. Carnelian is not established in the DIFC. Where a Studio is established in the DIFC, or where processing takes place in the DIFC, the DIFC Data Protection Law and its autonomous-systems regulation may apply — in which case the Studio is the Deployer and Carnelian the Operator, and the parties' respective obligations are allocated in the Master Subscription Agreement and the Data Processing Agreement; clause 18.2A states the position and clause 20.6 carries it into Part C. Carnelian holds no certification, quality mark or conformity assessment under any of these frameworks and claims none. Naming a framework here is not a claim to comply with it.
13.3 Known limitations are published deliberately. Clause 14 is not a disclaimer bolted on at the end. Disclosing honestly what the product does badly is a duty we owe before anyone contracts with us, and it is not a duty that can be excluded by any clause in any of our documents. Clause 14 is therefore written to be read, not to be survived.
14. Known limitations — how the Assistant fails
14.1 It is probabilistic, not deterministic. The Assistant predicts language. Given the same question twice it may answer differently. It has no understanding of truth; it has patterns.
14.2 It can state things that are wrong. It can produce a confident answer that is inaccurate, incomplete, out of date, or simply invented. This is a known characteristic of the technology, not a defect that can be engineered away, and it persists notwithstanding the controls described in clauses 8.5 and 11.6.
14.3 It can mishear. Speech recognition is imperfect. It is more likely to make errors with: (a) strong or unfamiliar accents; (b) Arabic dialects, and Gulf Arabic in particular; (c) code-switching — a sentence that mixes Arabic and English, or Hindi, Urdu, Tagalog, Malayalam, Tamil or Russian with English; (d) background noise, poor line quality, speakerphone, and more than one person speaking; (e) names, place names and unusual treatment names; (f) numbers spoken quickly — dates, times and telephone digits.
14.4 It can misunderstand. Sarcasm, humour, indirect refusals, hypotheticals and conditional statements ("if I can't get Friday, then…") are all failure modes.
14.5 It does not know what it does not know. Where a Studio has not recorded a price, a policy or an answer, the Assistant should say so — but the absence of information is itself a limitation of the answer a Guest receives.
14.6 It depends on services nobody controls. ABS Twin runs on telephony carriers, messaging platforms, hosting providers and AI model providers. Their outages, throttling, template rejections, quality-rating actions, policy changes and rate limits affect what the Assistant can do, and none of them is within Carnelian's control.
14.7 Language coverage is not uniform. The messaging channels answer natively in English, Arabic (Gulf), Hindi, Urdu, Tagalog, Malayalam, Tamil, Russian, Chinese and French, and in mixed-language conversations. Voice coverage is narrower.
14.8 What follows for a Guest. Prices, availability, appointment times and any commitment made to you through the Assistant are subject to confirmation by the Studio. If something matters — a date, a price, whether a treatment is right for you — check it with a person at the Studio. Under UAE electronic-transactions law, an output that the recipient knew, or ought to have known, was erroneous or the product of a technical failure is not something that can be relied on.
14.9 What follows for a Studio. The Studio is responsible for the accuracy and currency of what it configures — its catalogue, prices, durations, hours, staff, branches and policies — and for supervising its Assistant. Correct outputs cannot be produced from incorrect inputs. These obligations are set out in the Master Subscription Agreement and the AI & Communications Addendum.
14.10 The same limitations apply to the AI-assisted features inside the Console. Clause 5 names five staff-facing features — summarising a conversation, maintaining the Digital Twin, mapping the columns of an imported client list, designing a campaign, and drafting a support reply. Naming a feature without stating its limits is weaker than not naming it, so: every limitation in this clause 14 applies to each of them. They are probabilistic, they can be wrong, and their output is to be reviewed by the Studio before it is relied on. Two deserve to be called out by name: (a) Import column mapping writes Guest data. A mis-mapped column puts one Guest's details on another Guest's record, which is a Guest-facing failure and not merely an internal one. The Studio is responsible for checking the mapping before an import is committed. (b) The Digital Twin is a generated summary, not a record of fact, and clause 11.3 states what it is instructed not to contain and why that instruction is not a guarantee. Clauses 6.3(d) and 6.3(e) already require a person to write or approve campaign content and support replies; this clause states the position for the remaining three rather than leaving them undisclaimed.
15. Reliance, responsibility and the limits of this notice
15.1 This page is information, not a warranty. It describes how ABS Twin is designed and operated at the version and date shown. It is not a guarantee that any particular conversation will be handled correctly, that any channel will be available, or that any output will be accurate.
15.2 Your relationship is with the Studio. The appointment, the price, the treatment, the cancellation terms and the service itself are matters between a Guest and the Studio. Carnelian supplies software to the Studio. Carnelian is not a party to the Guest's dealings with the Studio, does not provide beauty, wellness, cosmetic or health services, and gives no advice of any kind to a Guest.
15.3 No reliance on an output known to be wrong. Nobody may rely on an output of the Assistant which they knew, or ought reasonably to have known, was erroneous, or which resulted from a technical failure, an interrupted call, or a garbled transmission.
15.4 Third-party services. Carnelian is not responsible for the acts, omissions, outages, policy decisions, enforcement actions, pricing or availability of Platform Providers, and their conduct is outside the scope of what Carnelian undertakes to provide.
15.5 What Carnelian undertakes to a Guest — scope, not exclusion. Consistently with clause 1.4.1, and save in respect of Carnelian's own demonstration Studio and demonstration number (clause 5.1), where Carnelian deals with a Guest directly and the terms Carnelian publishes for that line apply, Carnelian gives no undertaking to a Guest and enters into no contract with a Guest. In particular, Carnelian does not undertake to a Guest that any output of the Assistant will be accurate, that a request will be understood, that an appointment will be created, moved or cancelled as expected, or that any channel will be available. What Carnelian supplies, it supplies to the Studio under the Master Subscription Agreement, with the Data Processing Agreement governing the data and the Support & Service Levels policy governing support; the Studio's own responsibilities to its Guests are the Studio's, and are unaffected by this page. This clause defines what is offered, and to whom. It is not an attempt to exclude a liability a Guest may have under law — clause 15.7 says so expressly, and clause 15.3 (which prevents reliance on an output known to be erroneous) stands on its own footing under UAE electronic-transactions law and is unaffected.
15.6 Who the statements in this clause are made by, and for whose benefit. 15.6.1 Made for our people as well as for the company. The statements in clauses 15.1 to 15.5 — that this page is information and not a warranty, that a Guest's relationship is with the Studio, that no reliance may be placed on an output known to be wrong, that Carnelian is not responsible for Platform Providers, and that Carnelian gives no undertaking to a Guest — are made by Carnelian for itself and for the benefit of its affiliates, and of its and their officers, directors, employees, contractors, agents and sub-processors. Each of them may rely on those statements as Carnelian may. A claim brought against an individual rather than against the company reaches the same statements; they do not fall away because a different name is on the claim form. 15.6.2 No third-party rights. Save as expressly provided in clause 15.6.1, this page confers no right, benefit or cause of action on any person, is not made for the benefit of any third party, and creates no stipulation in favour of a third party. Nothing in it is intended to be, or is to be construed as, an undertaking given to anyone other than as clause 15.5 states. The operative contrary agreement — the agreement which displaces any rule of law that would otherwise treat a benefit as stipulated in favour of a third party — is in the Master Subscription Agreement, because a contrary agreement must sit in the contract that would otherwise create the stipulation and Part A is not a contract (clause 1.4.1). This clause records the position; the Master Subscription Agreement carries it. 15.6.3 Nothing here is a shield against what cannot be shielded. Clause 15.6 is subject in every respect to clause 15.7, and neither it nor clause 15.6.1 extends to fraud, wilful misconduct or gross fault by any person.
15.7 Savings clause. Nothing in this document excludes or limits any liability, or any right or remedy, which cannot lawfully be excluded or limited. In particular, nothing here excludes or limits liability for fraud, for wilful misconduct or gross fault, for death or personal injury caused by negligence, or any right a Guest has under mandatory UAE consumer-protection or data-protection law. Where any part of clauses 15.3 to 15.5 is held to be unenforceable, it applies to the maximum extent that is enforceable and the remainder is unaffected.
15.8 No claim about a Studio's own compliance. Carnelian provides the disclosure and consent tooling described in this document — disclosure scripts, recording announcements, opt-in and opt-out handling, consent records, audit trails. That tooling is a convenience, it is not legal advice, and it does not transfer a Studio's own legal obligations to Carnelian. Each Studio remains responsible for its own compliance with the laws that apply to it.
15.9 Liability arising under this document is governed by the Master Subscription Agreement. Liability arising out of or in connection with any part of this document, including Parts A, B, C, D and E and anything supplied under them, is subject to clause 20 of the Master Subscription Agreement in every respect. Nothing in this document varies clause 20 of the Master Subscription Agreement, and no provision of this document is to be read as doing so, whether by describing a behaviour, allocating a responsibility, supplying a text or otherwise. This clause is subject to clause 15.7.
15.10 Named heads of loss, as between Carnelian and a Studio only. So far as it concerns a Studio and not a Guest, the exclusions of named heads of loss in clause 20 of the Master Subscription Agreement apply to any claim arising under Parts C, D or E of this document as they apply to a claim under that Agreement itself. Nothing in this clause applies to a Guest, who is not a party to that Agreement, and this clause is subject in every respect to clause 15.7.
16. Your rights, and how to use them
16.1 What you can ask for. Under UAE data protection law you may, in respect of your personal data: (a) be told what is held and why, and who it is shared with; (b) obtain a copy of it and, where the processing is carried out by automated means on the basis of consent or of a contract, obtain it in a structured, machine-readable form and have it transmitted to another controller where that is technically feasible; (c) have inaccurate data corrected and incomplete data completed; (d) ask for erasure, which is carried out in the manner clause 9.6.3 describes and subject to the limits in clause 9.6.4; (e) restrict or object to certain processing; (f) withdraw consent where processing is based on consent — including marketing consent, at any time; (g) object to a decision made solely by automated means which produces legal effects or similarly significant effects; and (h) ask for a person to review such a decision.
These rights are owed to a Guest by the Studio, which is the controller of that Guest's data. Rights (g) and (h) in particular are the Studio's to answer: clause 16.5 sets out, without embellishment, what happens when a Guest asks and what Carnelian does and does not do.
16.2 Who to ask. The Studio is the controller of a Guest's conversation, booking and profile data and is the first place to send a request; it holds the relationship and it decides. Where the Studio needs Carnelian to act, it will ask us and we will support it. A Guest may also write to us directly at privacy@contact.abstwin.com. Carnelian's Data Protection Officer is Syed Sharique Ali, Manager of Carnelian Technologies L.L.C-FZ, appointed with effect from 21 August 2026, and is reached at that address marked "Attn: Data Protection Officer", or directly at dpo@contact.abstwin.com. Marking a request that way speeds the routing; a request is acted on whether or not the line is used. We will route the request and confirm what happened.
16.3 How we handle a request. We verify who is asking before disclosing or deleting anything — impersonation is the obvious risk with a service reached by a telephone number. We respond within the timescales set out in the Privacy Policy and in our data subject rights procedure.
16.4 Complaining — and to whom, because it depends on the complaint. A Guest who is dissatisfied may complain to the Studio, or to Carnelian at info@contact.abstwin.com, marked "Attn: Complaints" — a complaint is recorded and answered whether or not that line is used. Beyond that, the right regulator depends on what the complaint is about, and naming only one would send a class of complaints to the wrong place: (a) about personal data — how information is collected, used, shared, transferred or deleted, or a refusal of any right in clause 16.1 — to the UAE Data Office, the competent supervisory authority for personal data; (b) about the description of the service — a claim that ABS Twin, or a Studio's use of it, was presented misleadingly — to the UAE Ministry of Economy and Tourism (formerly the Ministry of Economy) (consumer protection) or the competent local consumer-protection authority in the relevant Emirate; (c) about marketing conduct — an unwanted marketing call or message, a message sent outside the permitted hours, or a marketing message sent after an opt-out — to the Telecommunications and Digital Government Regulatory Authority (TDRA), which administers the Do Not Contact Register, and to the Ministry of Economy and Tourism.
16.5 What "human review" actually means here. ABS Twin takes decisions automatically — offering a time, creating or cancelling an appointment, applying a discount within the Studio's limits, routing a complaint. Whether any given decision meets the threshold in clause 16.1(g) is a question for the Studio, as controller, and ultimately for a supervisory authority or a court; this page does not pre-judge it, and the route below is available whether or not it is met.
16.5.1 What happens when a Guest asks for a person. A Guest may ask for a person at any point, in the form clause 7.1 states for the channel they are on, or ask that a person look at something the Assistant decided. The Assistant does not argue, does not require the Guest to characterise the request, and does not ask why. The request is handed to the Studio's team by the escalation route in clause 7, and the Studio — as the controller, and as the business whose appointment, price and policy is in issue — decides what to do about it. That decision is the Studio's to make and the Studio's to answer for.
16.5.2 What Carnelian does not do. Carnelian does not itself review a decision the Assistant took, and does not override one. We do not sit between a Guest and a Studio, and we do not re-decide a Studio's bookings. Carnelian supplies the route, the conversation record and the audit trail so that the Studio can do it.
16.5.3 A note for Studios on the statutory exception. Where a Studio's own terms of engagement with its Guests expressly describe the automated handling of bookings and messages by the Assistant, UAE data protection law provides that the right to object to that automated processing does not arise, because the processing forms part of the terms of the contract between the Guest and the Studio. That exception is available to a Studio and costs nothing to take: clause 22A supplies the paragraph. It is an exception to the objection right only — the right to ask that a person review a decision is unqualified, is not removed by any term, and is owed by the Studio whatever its terms say.
16.6 The constraints on these rights, gathered in one place. The limits on what a Guest can obtain are stated in this document where each arises. They are listed together here so that a right and its constraints are read at the same time: (a) Who answers. The Studio is the controller and owes these rights. Carnelian supports the Studio; Carnelian does not decide a Studio's answer (clauses 16.1, 16.2, 7.3). (b) Identity first. Nothing is disclosed, corrected or erased until we are satisfied who is asking — the obvious risk on a service reached by a telephone number (clause 16.3). (c) Erasure is done by redaction, is not instantaneous, and is not always complete. A record is erased by redacting the personal data in it and leaving a marker in its place, so that past bookings and payments stay attributable (clause 9.6.3); there is no automated erasure tooling and a request is actioned by hand; a route for conversation content specifically is still being built; and encrypted backups until they age out, sub-processor retention under their own terms, and records required by law all survive a request (clause 9.6.4). (c bis) A copy is provided on request, by hand. There is no self-service export in the Console today; a request under clause 16.1(b) is fulfilled manually (clause 16.2). (d) Human review means the Studio's human. There is no Carnelian review or override, and no dedicated review queue exists today; the request travels the ordinary escalation route to the Studio's team, which decides it (clauses 16.5.1, 16.5.2, 13.1(c)). (e) Explanation has limits. We will explain what drove an outcome; we will not disclose another Guest's data, source code or provider-confidential material, and we do not undertake to hand over assessments (clause 13.1(g) and (h)). (f) A Studio's own terms can remove the objection right in respect of the automated handling they describe — but never the right to human review (clause 16.5.3, clause 22A.3).
17. Changes to this document
17.1 This document is versioned and dated. The current version, its date and its effective date are shown in the change log at the end of this page, which is the version record published with it.
17.2 We do not silently edit a published page. Every version is archived with its effective date, and the change log at the end of this document records what changed and when. The runtime scripts in Part B are versioned in the same way, because they are evidence of what a Guest was actually told on a given date.
17.3 Changes that matter are notified. Where a change materially affects what a Guest is told or what a Studio must do, Carnelian gives prior notice to Studios by email to their registered contacts and in the Console, on the notice period and with the termination and refund consequences stated in the Master Subscription Agreement, which governs. Changes required by law, by a Platform Provider, or to address a security risk may take effect on shorter notice, with notice given as soon as reasonably practicable.
17.4 Continued use is not treated as acceptance of a material change. Where acceptance is required, it is captured afresh.
18. Governing law, forum and language
18.1 Two limbs, deliberately. 18.1.1 Part A (this public notice), as it concerns Guests and the public, and any non-contractual matter arising from it, is governed by the federal law of the United Arab Emirates as applicable in the Emirate of Dubai. The courts of Dubai have non-exclusive jurisdiction. This is without prejudice to any mandatory right, protection or forum available to a Guest under applicable consumer-protection or data-protection law, which is not affected by this clause. 18.1.2 Parts C, D and E, as incorporated into a Studio's Master Subscription Agreement, are governed by the law and subject to the forum stated in that Agreement, and this clause does not vary them.
18.2 Data protection regime, stated separately — and not fixed by the choice of court. The data-protection law applicable to any given processing is whichever law applies to it from time to time — including by reason of the Studio's place of establishment, the location of the processing, the residence of the Guest, or the category of the data. In the United Arab Emirates that is ordinarily the federal personal data protection legislation, except where other legislation governs a particular category of data: health information, in particular, is carved out of the general regime and governed by the UAE's own health-information legislation, which restricts where such data may be stored and processed (clauses 8.4.1 and 12.3.2). Choosing a court does not choose a data-protection law, and this document does not purport to do so.
18.2A Free zones, and the Deployer/Operator allocation. Where a Studio is established in a financial free zone with its own data-protection legislation — the DIFC and the ADGM each have one — or where processing takes place there, that legislation may apply to the Studio, to Carnelian, or to both. Where the DIFC's autonomous-systems regulation applies, the Studio is the Deployer and Carnelian is the Operator, and the parties' respective obligations, including notice content, register-keeping and any assessment or certification requirement, are allocated between them in the Master Subscription Agreement and the Data Processing Agreement. Clause 20.6 carries the same allocation into Part C so that it binds. Carnelian is not established in the DIFC and holds no certification, quality mark or conformity assessment under any such regime.
18.3 Talk to us first. Before commencing proceedings, we ask that a written notice describing the issue be sent to Carnelian's notice address published in the Legal Notice, and that both sides attempt in good faith to resolve it within 30 days. This does not prevent either party from seeking urgent relief.
18.4 Language — two limbs, matching clause 18.1. 18.4.1 The public limb. This document is published in English and Arabic. For Part A, and for the Guest-facing text in Part B and Part D (the runtime scripts and the reception notice in clause 22), the Arabic version prevails in the event of any conflict, to the fullest extent permitted by applicable law — because that text is a public, consumer-facing notice, the applicable forum under clause 18.1.1 is an onshore one, and the Arabic is what a UAE court will work from. 18.4.2 The contractual limb. Parts C and E, and the Studio-facing obligations in Part D (clause 21 and the instructions accompanying clauses 22 and 22A), are contractual terms binding Studios and are incorporated into the Master Subscription Agreement. The language and precedence clause in that Agreement governs them, and this clause does not vary it. Clause 18.1 splits governing law between the same two limbs for the same reason; a single language rule across both would put two precedence rules over one text and hand a Studio a threshold argument on which language governs its own obligation. 18.4.3 Where the two meet. The Guest-facing text a Studio is obliged to display is governed as to its wording by 18.4.1 — it is what a Guest reads — while the obligation to display it is governed by 18.4.2. Nothing in 18.4.2 permits a Studio to display the Guest-facing text in English only; clause 21.2 is unaffected.
18.5 Severability. If any provision of this document is held invalid or unenforceable, it is to be read down to the minimum extent necessary to make it valid and enforceable, and the remainder is unaffected. Where a limitation is read down, it is replaced by the highest limitation that is lawful.
PART B — THE RUNTIME NOTICE SCRIPTS
B1. Voice
S1 — Call opening, audio retained
EN:
"Hello, and thank you for calling {Studio}. This is {Assistant} — {Studio}'s AI assistant, not a member of staff. This call is being recorded, written down and summarised, so that we can arrange your appointment and keep an accurate record of it. If anyone else is with you, or you are on speakerphone, please let them know as well. If you would rather the call wasn't recorded or written down, tell me now and I'll stop it. Say 'human' at any time and I'll take an urgent message for the team. How {Studio} handles your information is at abstwin dot com slash privacy — I can send you the link on WhatsApp if you'd like."
AR:
«أهلاً وسهلاً، وشكراً لاتصالك بـ{Studio}. معك {Assistant}، المساعد الذكي لدى {Studio}، ولستُ موظفاً بشرياً. يتم تسجيل هذه المكالمة وتدوينها كتابةً وتلخيصها لترتيب موعدك والاحتفاظ بسجلّ دقيق له. وإذا كان معك شخص آخر أو كانت المكالمة على مكبّر الصوت، فيرجى إبلاغه بذلك أيضاً. وإذا كنت تفضّل عدم تسجيل المكالمة أو تدوينها، فأخبرني الآن وسأوقف ذلك. وقل «موظف» في أي وقت وسأدوّن رسالة عاجلة للفريق. وطريقة تعامل {Studio} مع بياناتك موضّحة على abstwin.com/legal/privacy، ويمكنني إرسال الرابط لك عبر واتساب إذا رغبت.»
S1-ALT — Call opening, audio retained, where a decline cannot be honoured mid-call
EN:
"…If you would rather the call wasn't recorded, tell me now — I can't switch it off during a call, but I'll end the call and you can message {Studio} on WhatsApp instead, where nothing is recorded as audio…"
AR:
«...إذا كنت تفضّل عدم تسجيل المكالمة، فأخبرني الآن — لا أستطيع إيقافه أثناء المكالمة، لكنني سأنهي المكالمة ويمكنك مراسلة {Studio} عبر واتساب حيث لا يوجد تسجيل صوتي...»
S2 — Call opening, audio not retained (transcript and summary kept)
EN:
"Hello, and thank you for calling {Studio}. This is {Assistant} — {Studio}'s AI assistant, not a member of staff. The audio of this call isn't kept, but what we say is written down as a full written record and a short summary, and kept with your record at {Studio}. If you would rather it wasn't written down, tell me now and I'll stop it. Say 'human' at any time and I'll take an urgent message for the team. How {Studio} handles your information is at abstwin dot com slash privacy — I can send you the link on WhatsApp if you'd like."
AR:
«أهلاً وسهلاً، وشكراً لاتصالك بـ{Studio}. معك {Assistant}، المساعد الذكي لدى {Studio}، ولستُ موظفاً بشرياً. لا يُحفَظ صوت هذه المكالمة، لكن يُدوَّن ما نقوله كسجلّ كتابي كامل وملخّص قصير، ويُحفَظ ضمن سجلّك لدى {Studio}. وإذا كنت تفضّل عدم تدوين المكالمة، فأخبرني الآن وسأوقف ذلك. وقل «موظف» في أي وقت وسأدوّن رسالة عاجلة للفريق. وطريقة تعامل {Studio} مع بياناتك موضّحة على abstwin.com/legal/privacy، ويمكنني إرسال الرابط لك عبر واتساب إذا رغبت.»
S3 — Caller declines, audio-retained configuration (capture can be stopped mid-call)
EN:
"Of course — I've stopped the recording. I'll still keep a short written note of your appointment so the team has a record of what you asked for. How can I help?"
AR:
«بالتأكيد — أوقفتُ التسجيل. وسأحتفظ بملاحظة كتابية قصيرة عن موعدك ليكون لدى الفريق سجلّ بما طلبته. كيف يمكنني مساعدتك؟»
S3-T — Caller declines, audio-not-retained configuration (transcript and summary can be stopped)
EN:
"Of course — I've stopped writing the call down. I'll keep only what we need to deal with your request: your number, the time of the call, and the booking itself. How can I help?"
AR:
«بالتأكيد — أوقفتُ تدوين المكالمة. وسأحتفظ فقط بما نحتاجه لتنفيذ طلبك: رقمك، ووقت المكالمة، والحجز نفسه. كيف يمكنني مساعدتك؟»
S3-ALT — Caller declines and the decline cannot be honoured mid-call
EN:
"I understand. I'm not able to stop that during a call, so let's do this instead: I'll end the call now, and you can message {Studio} on WhatsApp, where nothing is recorded as audio — or I can take a message for the team to call you back. Which would you prefer?"
AR:
«أتفهّم ذلك. لا أستطيع إيقاف ذلك أثناء المكالمة، لذا دعنا نفعل الآتي: سأنهي المكالمة الآن، ويمكنك مراسلة {Studio} عبر واتساب حيث لا يوجد تسجيل صوتي — أو يمكنني تدوين رسالة ليعاود الفريق الاتصال بك. أيّهما تفضّل؟»
S18 — Another person joins the call
EN (audio retained):
"Hello — just so you know, I'm {Assistant}, {Studio}'s AI assistant, not a member of staff. This call is being recorded, written down and summarised, and kept with the customer record at {Studio}. If anyone here would rather it wasn't, say so now and I'll stop it. Say 'human' at any time and I'll take an urgent message for the team. How {Studio} handles your information is at abstwin dot com slash privacy."
EN (audio not retained):
"Hello — just so you know, I'm {Assistant}, {Studio}'s AI assistant, not a member of staff. The audio isn't kept, but what we say is written down as a full written record and a short summary, and kept with the customer record at {Studio}. If anyone here would rather it wasn't, say so now and I'll stop it. Say 'human' at any time and I'll take an urgent message for the team. How {Studio} handles your information is at abstwin dot com slash privacy."
AR (audio retained):
«مرحباً — للعلم، أنا {Assistant}، المساعد الذكي لدى {Studio}، ولستُ موظفاً بشرياً. يتم تسجيل هذه المكالمة وتدوينها كتابةً وتلخيصها، وتُحفَظ ضمن سجلّ العميل لدى {Studio}. وإذا كان أي شخص هنا يفضّل عدم ذلك، فليخبرني الآن وسأوقفه. وقل «موظف» في أي وقت وسأدوّن رسالة عاجلة للفريق. وطريقة تعامل {Studio} مع بياناتك موضّحة على abstwin.com/legal/privacy.»
AR (audio not retained):
«مرحباً — للعلم، أنا {Assistant}، المساعد الذكي لدى {Studio}، ولستُ موظفاً بشرياً. لا يُحفَظ الصوت، لكن يُدوَّن ما نقوله كسجلّ كتابي كامل وملخّص قصير، ويُحفَظ ضمن سجلّ العميل لدى {Studio}. وإذا كان أي شخص هنا يفضّل عدم ذلك، فليخبرني الآن وسأوقفه. وقل «موظف» في أي وقت وسأدوّن رسالة عاجلة للفريق. وطريقة تعامل {Studio} مع بياناتك موضّحة على abstwin.com/legal/privacy.»
B2. WhatsApp
S4 — First message of a new WhatsApp thread
EN:
"Hello! You're chatting with {Assistant}, {Studio}'s AI assistant — not a person. I can book, move or cancel appointments and answer questions about {Studio}'s services. Your messages are saved to your customer record at {Studio}. Ask for a person at any time and I'll pass your message and this conversation to the {Studio} team, who will reply to you. How your information is handled: abstwin.com/legal/privacy"
AR:
«مرحباً! أنت تتحدث مع {Assistant}، المساعد الذكي لدى {Studio}، ولستُ شخصاً. يمكنني حجز المواعيد أو تغييرها أو إلغاؤها والإجابة عن أسئلتك حول خدمات {Studio}. تُحفَظ رسائلك ضمن سجلّ عميلك لدى {Studio}. واطلب التحدث مع شخص في أي وقت وسأحيل رسالتك وهذه المحادثة إلى فريق {Studio} ليردّوا عليك. طريقة التعامل مع بياناتك: abstwin.com/legal/privacy»
B3. Instagram Direct
S5 — First message of a new Instagram thread
EN:
"Hello! You're messaging {Assistant}, {Studio}'s AI assistant on Instagram — not a person. I can answer questions about {Studio}'s services and arrange appointments. Instagram doesn't share your phone number with us, so if you'd like to book I'll ask you for it. This conversation is saved to your record at {Studio}. Ask for a person at any time and I'll pass your message and this conversation to the {Studio} team, who will reply to you. More: abstwin.com/legal/privacy"
AR:
«مرحباً! أنت تراسل {Assistant}، المساعد الذكي لدى {Studio} على إنستغرام، ولستُ شخصاً. يمكنني الإجابة عن أسئلتك حول خدمات {Studio} وترتيب المواعيد. لا يزوّدنا إنستغرام برقم هاتفك، لذا سأطلبه منك إذا رغبت في الحجز. تُحفَظ هذه المحادثة ضمن سجلّك لدى {Studio}. واطلب التحدث مع شخص في أي وقت وسأحيل رسالتك وهذه المحادثة إلى فريق {Studio} ليردّوا عليك. للمزيد: abstwin.com/legal/privacy»
B4. Shared scripts — every messaging channel and voice
S6 — Re-disclosure after a significant gap, or on handover back to automation
EN:
"Just so you know, you're speaking with {Assistant}, {Studio}'s AI assistant again. Ask for a person any time and I'll pass this to the {Studio} team."
AR:
«للتوضيح، أنت تتحدث مجدداً مع {Assistant}، المساعد الذكي لدى {Studio}. واطلب التحدث مع شخص في أي وقت وسأحيل المحادثة إلى فريق {Studio}.»
S7 — Handover to a human
EN:
"I've passed this to the {Studio} team — someone will come back to you."
AR:
«لقد أحلتُ هذه المحادثة إلى فريق {Studio} — وسيعاود أحد أفراده التواصل معك.»
S8 — Medical or suitability deferral
EN:
"I'm not able to advise whether a treatment is right for you — one of {Studio}'s specialists will do that properly. Would you like me to book a consultation?"
AR:
«لا أستطيع إبداء رأي في مدى ملاءمة العلاج لك — سيقوم أحد المختصين لدى {Studio} بذلك على النحو الصحيح. هل تودّ أن أحجز لك موعد استشارة؟»
S9 — Emergency limitation
EN:
"I'm not able to help with an emergency and I can't contact the emergency services. Please call 999 for police, 998 for an ambulance, or 997 for civil defence, straight away."
AR:
«لا أستطيع المساعدة في حالات الطوارئ ولا يمكنني الاتصال بخدمات الطوارئ. يرجى الاتصال فوراً بالرقم ٩٩٩ للشرطة، أو ٩٩٨ للإسعاف، أو ٩٩٧ للدفاع المدني.»
S10 — Marketing opt-in ask
EN:
"One quick thing — would you like {Studio} to send you occasional offers and news on WhatsApp? Reply YES to receive them, or NO and I won't ask again."
AR:
«سؤال سريع — هل ترغب أن يرسل لك {Studio} عروضاً وأخباراً من حين لآخر عبر واتساب؟ أرسل «نعم» للاشتراك، أو «لا» ولن أسألك مرة أخرى.»
S11 — Opt-out confirmation
EN:
"Done — {Studio} won't send you marketing messages. You'll still get confirmations and reminders for appointments you make."
AR:
«تم — لن يرسل لك {Studio} رسائل تسويقية. وستستمر في تلقّي تأكيدات وتذكيرات المواعيد التي تحجزها.»
S12 — Data-rights pointer
EN (messaging):
"Your information is held by {Studio}, who decides how it's used. To see it, correct it, or ask for it to be erased, contact {Studio} directly — or write to privacy@contact.abstwin.com. If you'd like a person at {Studio} to look at something I decided, just say so and I'll pass it to their team, who will decide it. How the assistant works: abstwin.com/legal/ai-disclosure · How your information is handled: abstwin.com/legal/privacy"
AR (messaging):
«بياناتك محفوظة لدى {Studio}، وهو الجهة التي تحدّد كيفية استخدامها. للاطّلاع عليها أو تصحيحها أو طلب محوها، تواصل مع {Studio} مباشرةً، أو راسلنا على privacy@contact.abstwin.com. وإذا رغبت في أن يطّلع أحد موظفي {Studio} على أمر قرّرته، فأخبرني وسأحيله إلى فريقهم ليبتّوا فيه. لمعرفة كيفية عمل المساعد: abstwin.com/legal/ai-disclosure · وطريقة التعامل مع بياناتك: abstwin.com/legal/privacy»
S12-V — Data-rights pointer, voice
EN:
"Of course. Your information is held by {Studio}, who decides how it's used, and I write what we discuss to your record there. Some of what you say is handled by our technology providers outside the UAE so that I can understand and answer you. To see your information, correct it or ask for it to be erased, speak to {Studio}, and it's all set out at abstwin dot com slash privacy — I can send you that link on WhatsApp if you'd like. And if you'd like a person at {Studio} to look at something I decided, just say so and I'll pass it to their team."
AR (voice):
«بالتأكيد. بياناتك محفوظة لدى {Studio}، وهو الجهة التي تحدّد كيفية استخدامها، وأنا أدوّن ما نتحدث عنه ضمن سجلّك لديه. ويُعالَج جزء ممّا تقوله لدى مزوّدي التقنية لدينا خارج الإمارات لكي أتمكّن من فهمك والرد عليك. وللاطّلاع على بياناتك أو تصحيحها أو طلب محوها، تحدّث مع {Studio}، وكل ذلك موضّح على abstwin.com/legal/privacy، ويمكنني إرسال الرابط لك عبر واتساب إذا رغبت. وإذا رغبت في أن يطّلع أحد موظفي {Studio} على أمر قرّرته، فأخبرني وسأحيله إلى فريقهم.»
S13 — Sensitive details refused
EN:
"Please don't send card numbers, bank details or ID document numbers here — I'm not able to take them, and this isn't the right channel for them. {Studio} will handle payment with you directly."
EN (health variant — used where medical or clinical details are being sent):
"Please don't send medical or health details here — I'm not able to use them, and anything sent in this conversation is saved with it. Please share anything clinical with {Studio} directly, at reception or with the specialist, and I'll gladly book you a consultation."
AR:
«الرجاء عدم إرسال أرقام البطاقات المصرفية أو التفاصيل البنكية أو أرقام وثائق الهوية هنا — لا يمكنني استلامها، وهذه ليست القناة المناسبة لها. سيتولّى {Studio} أمر الدفع معك مباشرةً.»
AR (health variant):
«الرجاء عدم إرسال تفاصيل طبية أو صحية هنا — لا يمكنني استخدامها، وكل ما يُرسَل في هذه المحادثة يُحفَظ معها. يرجى مشاركة أي معلومات طبية مع {Studio} مباشرةً، في الاستقبال أو مع المختص، ويسعدني أن أحجز لك موعد استشارة.»
S14 — De-escalation, then close
EN:
"I'd like to help, but I can't continue if the conversation stays like this. I'm going to end the call here — you're very welcome to call back, or to message {Studio} on WhatsApp."
AR:
«أودّ مساعدتك، لكن لا أستطيع المتابعة إذا استمرت المحادثة على هذا النحو. سأنهي المحادثة هنا — ويسعدنا معاودة اتصالك أو مراسلة {Studio} عبر واتساب.»
S15 — Complaint acknowledgement and escalation
EN (messaging):
"I'm sorry — that shouldn't have happened. I've passed this to the {Studio} team as a complaint and someone will come back to you. I'm not able to resolve it myself."
EN (voice):
"I'm sorry — that shouldn't have happened, and it isn't something I can settle on the phone. Please send the details to {Studio} on WhatsApp so they reach the right person, and I'll also leave an urgent message for the team now."
AR (messaging):
«أعتذر — ما كان ينبغي أن يحدث ذلك. لقد أحلتُ الأمر إلى فريق {Studio} كشكوى وسيتواصل معك أحد أفراده. لا أستطيع معالجة الأمر بنفسي.»
AR (voice):
«أعتذر — ما كان ينبغي أن يحدث ذلك، وليس أمراً أستطيع تسويته عبر الهاتف. يرجى إرسال التفاصيل إلى {Studio} عبر واتساب لتصل إلى الجهة المختصة، وسأترك أيضاً رسالة عاجلة للفريق الآن.»
S16 — Delayed or dropped reply
EN:
"Sorry for the delay — something went wrong on our side. The {Studio} team has been alerted and someone will reply to you here."
AR:
«نعتذر عن التأخير — حدث خطأ لدينا. تم تنبيه فريق {Studio} وسيرد عليك أحد أفراده هنا.»
B5. Messages the Assistant sends first
S17 — Outbound-initiated first contact
EN (template opening line — precedes the substantive content):
"{Studio} here — this is {Assistant}, {Studio}'s AI assistant, not a person. Ask for a person at any time and I'll pass your message to the {Studio} team."
EN (worked example — appointment reminder):
"{Studio} here — this is {Assistant}, {Studio}'s AI assistant, not a person. A reminder of your {service} with {Studio} tomorrow at {time}. Reply to change or cancel it, or ask for a person and I'll pass your message to the {Studio} team."
EN (worked example — marketing, opted-in Guests only):
"{Studio} here — this is {Assistant}, {Studio}'s AI assistant, not a person. {Studio offer text}. Reply STOP and you won't receive offers again; ask for a person and I'll pass your message to the {Studio} team."
AR (template opening line):
«{Studio} هنا — معك {Assistant}، المساعد الذكي لدى {Studio}، ولستُ شخصاً. واطلب التحدث مع شخص في أي وقت وسأحيل رسالتك إلى فريق {Studio}.»
AR (worked example — appointment reminder):
«{Studio} هنا — معك {Assistant}، المساعد الذكي لدى {Studio}، ولستُ شخصاً. تذكير بموعدك لخدمة {service} لدى {Studio} غداً الساعة {time}. يمكنك الرد لتغييره أو إلغائه، أو اطلب التحدث مع شخص وسأحيل رسالتك إلى فريق {Studio}.»
AR (worked example — marketing):
«{Studio} هنا — معك {Assistant}، المساعد الذكي لدى {Studio}، ولستُ شخصاً. {Studio offer text}. اكتب «إيقاف» ولن تصلك العروض مرة أخرى؛ أو اطلب التحدث مع شخص وسأحيل رسالتك إلى فريق {Studio}.»
PART D — FOR STUDIOS: WHAT YOU MUST DISPLAY
21. Your display obligations
21.1 The runtime scripts cover the moment a Guest reaches the Assistant. They do not cover the moment a Guest decides to call you, or walks through your door. Each Studio must therefore make the following visible to its own Guests, in English and Arabic:
| # | Where | What must be shown | Severity |
|---|---|---|---|
| 1 | Your website — on the contact page, the booking page, and anywhere you publish your telephone or WhatsApp number | A short notice that your telephone line and WhatsApp are answered by an AI assistant; that calls are recorded and transcribed (where they are); and a link to abstwin.com/legal/ai-disclosure | Required |
| 2 | Your WhatsApp Business profile | Accurate business contact information, and a description that does not present the account as staffed by a person at all times | Required (platform rule) |
| 3 | Your Instagram profile — if the Instagram channel is enabled | The same disclosure in the bio or in the pinned business information | Required where enabled |
| 4 | Reception desk / point of sale | A printed card or small sign carrying the notice in clause 22, so a walk-in Guest sees the same information a caller hears | Required |
| 4a | Your service catalogue | Prices recorded inclusive of VAT, so that a price the Assistant quotes to a Guest is the price payable. A price displayed or quoted to a consumer is a price display, and quoting a tax-exclusive figure is your exposure, not the software's. Our billing and invoicing terms are operative on tax and invoicing | Required |
| 4b | Your recorded telephone greeting or IVR, and any call-back message — where you operate one | The same pointer to abstwin.com/legal/privacy that the Assistant gives, so that a Guest who reaches a recorded message rather than the Assistant is not left without it. This is not permission to place an IVR ahead of the Assistant's own scripts, which clause 20.1(c) prohibits | Required where you operate one |
| 5 | Your booking confirmation and appointment reminder | The identification line stating that the assistant is an AI and how to reach a person — inside the approved message template itself, because the template text cannot be changed at send time (script S17) | Required — it is the same fixed behaviour as clause 19.1(a), not a recommendation |
| 5a | Outbound marketing campaigns — offers, broadcasts, birthday and win-back messages | Running these is your own regulated activity, not Carnelian's: you need any approval the rules require, numbers registered to your own licence, Do Not Contact Register screening before you send, evidenced opt-in per number, sending only within the permitted hours, and retention of the records the rules require. Clause 20.4.1 sets out the warranty you give; the AI & Communications Addendum and the Acceptable Use Policy are operative | Required where you use any outbound marketing feature |
| 5b | Discounts and promotional offers | Obtaining any permit or approval the rules require for running a discount or promotion is your own regulated activity. Carnelian applies the discount arithmetic within the limits you set; it does not obtain, hold or check any permit for you | Required where you run any discount or promotion through the Assistant |
| 6 | Your own privacy notice | Your identity as the controller of your Guests' data; that you use a third-party platform to run reception; the link to abstwin.com/legal/privacy and abstwin.com/legal/sub-processors | Required |
| 7 | Treatment intake forms and consultation records | Nothing that invites a Guest to submit Restricted Data through the Assistant. Clinical information belongs in your own clinical records, under the Restricted / Health Data Addendum | Required |
| 8 | Staff briefing | Your team must know that the Assistant answers first, that a Guest saying "human" reaches them, and that they must not tell a Guest that an automated message was written by a person | Required |
21.2 Language. Items 1 to 5b must exist in Arabic as well as English. Consumer-facing information and advertising in the UAE must be provided in Arabic, and this is a criminal-band obligation, not an administrative one.
21.2.1 Where a Studio operates outside the United Arab Emirates. Clause 21.1 is drafted for the UAE. Where a Studio operates in another jurisdiction, the display obligations are those of that jurisdiction, and they may be more onerous than these — several states in the region require a privacy notice in Arabic in prescribed terms, a permit or prior authorisation for processing sensitive data, or explicit consent before any direct marketing. Clause 21.1 is a floor, not a ceiling: a Studio must satisfy whatever its own jurisdiction requires, and must tell Carnelian before going live in one this document does not address, so that the scripts, the notice and the applicable-law position in clause 18.2 can be reviewed for it. The Master Subscription Agreement governs where a variation is agreed.
21.3 Keep it current. If you change your recording configuration, your channels, your persona name or your opening hours, update your displayed notice. An out-of-date public notice is worse than none.
21.4 Carnelian supplies the text, you supply the display. The notice in clause 22 is provided as a product deliverable. Using it does not transfer your obligations to Carnelian (clause 15.8), and Carnelian does not review or approve a Studio's own website, signage or privacy notice.
22. The Guest notice a Studio may display
*Reproduce as-is, inserting your studio name and choosing the remaining italicised alternative correctly — what happens when a Guest declines. The recording line is no longer an alternative: calls are not audio-recorded on any configuration in use (clause 9.0), and the notice states that as a fact. Clause 22.1 explains the decline alternative, which is a question of fact about your configuration, not of wording. Available as a printable card and as web copy.*
EN:
Our reception is answered by an AI assistant
When you call or message {Studio}, you are answered first by {Assistant}, our AI assistant. It is software, not a member of our team, and it will always tell you so.
It can: book, change and cancel appointments · tell you our prices and treatment times · answer questions about our services, hours and location · take a message.
It cannot: advise whether a treatment is suitable for you, or give any medical, dental, nutritional, legal or financial advice · handle an emergency or call the emergency services · take card, bank or ID numbers.
It can make mistakes. Prices, times and availability are confirmed by us.
Calls are not recorded as audio, but are written down in full and summarised, and kept with your customer record.
You can ask us not to. *(Choose the line that matches your configuration — see clause 22.1 below. Where it can be stopped mid-call: just say so at the start of the call, or at any point, and the assistant will stop and carry on with only what is needed to deal with your request. Where it cannot: just say so and the assistant will end the call and invite you to message us on WhatsApp instead, where nothing is recorded as audio — or take a message for us to call you back.)*
The assistant does not identify you by your voice. It listens in order to write down what you say. It does not create a voiceprint and does not do voice recognition of who you are. The voice you hear is generated by software and is nobody's voice. It also does not telephone you — it answers our line.
To reach a person, say so at any point — on a call the assistant takes an urgent message for our reception, and on WhatsApp or Instagram your message and the conversation are passed to our team — or ask any member of our team here.
If you cannot use the telephone — because you are deaf or hard of hearing, or for any other reason — message us on WhatsApp instead. The same assistant answers in writing, does everything it does on a call, and gives you the same information in text at the start of the conversation. You can also speak to us at reception.
Your information is held by {Studio}. To see it, correct it or have it erased, speak to us at reception or write to {Studio contact}. Erasure is done by removing the personal details from a record and leaving a marker in their place, so that past bookings and payments still add up. If you would like a person here to look at something the assistant decided, tell us and we will — that decision is ours, not the software provider's.
More about the assistant: abstwin.com/legal/ai-disclosure · How data is handled: abstwin.com/legal/privacy
AR:
يتم الرد على استقبالنا بواسطة مساعد ذكي
عند اتصالك بـ{Studio} أو مراسلته، يرد عليك أولاً {Assistant}، المساعد الذكي لدينا. وهو برنامج وليس أحد أفراد فريقنا، وسيخبرك بذلك دائماً.
يستطيع: حجز المواعيد وتغييرها وإلغاءها · إخبارك بأسعارنا ومدد العلاجات · الإجابة عن أسئلتك حول خدماتنا وساعات العمل والموقع · تدوين رسالة لك.
لا يستطيع: إبداء رأي في مدى ملاءمة أي علاج لك، ولا تقديم أي مشورة طبية أو سنّية أو غذائية أو قانونية أو مالية · التعامل مع حالات الطوارئ أو الاتصال بخدمات الطوارئ · استلام أرقام البطاقات أو الحسابات البنكية أو وثائق الهوية.
وقد يقع في الخطأ. الأسعار والمواعيد والتوافر تُؤكَّد من جانبنا.
تُسجَّل المكالمات وتُدوَّن كتابةً وتُلخَّص *(البديل: لا تُسجَّل المكالمات صوتياً، لكنها تُدوَّن كتابةً بالكامل وتُلخَّص)*، وتُحفَظ ضمن سجلّ عميلك.
ويمكنك أن تطلب منّا عدم ذلك. *(اختر العبارة المطابقة لإعداداتك — انظر البند ٢٢.١ أدناه. إذا كان بالإمكان الإيقاف أثناء المكالمة: يكفي أن تخبرنا في بداية المكالمة أو في أي وقت، وسيوقف المساعد ذلك ويتابع معك بما يلزم لتنفيذ طلبك فقط. وإذا لم يكن ذلك ممكناً: يكفي أن تخبرنا، وسينهي المساعد المكالمة ويدعوك لمراسلتنا عبر واتساب حيث لا يوجد تسجيل صوتي، أو يدوّن رسالة لنعاود الاتصال بك.)*
ولا يتعرّف المساعد عليك من صوتك. فهو يستمع إليك لتدوين ما تقوله فقط، ولا يُنشئ بصمة صوتية ولا يُجري تعرّفاً على هوية المتحدث. والصوت الذي تسمعه مُولَّد بواسطة البرنامج وليس صوت أي شخص. كما أنه لا يتصل بك هاتفياً — بل يرد على خطنا.
للتحدث مع شخص، أخبرنا في أي وقت — ففي المكالمة يدوّن المساعد رسالة عاجلة لاستقبالنا، وفي واتساب أو إنستغرام تُحال رسالتك والمحادثة إلى فريقنا — أو اطلب ذلك من أي فرد من فريقنا هنا.
وإذا تعذّر عليك استخدام الهاتف — بسبب ضعف السمع أو الصمم أو لأي سبب آخر — فراسلنا عبر واتساب. يجيبك المساعد نفسه كتابةً، ويقوم بكل ما يقوم به عبر المكالمة، ويمنحك المعلومات ذاتها نصّاً في بداية المحادثة. ويمكنك أيضاً التحدث إلينا في الاستقبال.
بياناتك محفوظة لدى {Studio}. للاطّلاع عليها أو تصحيحها أو محوها، تحدّث إلينا في الاستقبال أو راسل {Studio contact}. ويتم المحو بإزالة البيانات الشخصية من السجلّ وترك علامة مكانها، بحيث تظل الحجوزات والمدفوعات السابقة متّسقة. وإذا رغبت في أن يطّلع أحد موظفينا على أمر قرّره المساعد آلياً، فأخبرنا وسنفعل — فالقرار قرارنا، لا قرار مزوّد البرنامج.
لمعرفة المزيد عن المساعد: abstwin.com/legal/ai-disclosure · وطريقة التعامل مع البيانات: abstwin.com/legal/privacy
22.1 Choosing the recording lines — and why one of them is now settled. The notice above carried two alternatives in two places, and both are choices of fact, not of tone. The first is settled by clause 9.0 and is stated as a fact; the second remains a choice. (a) Whether calls are recorded at all — settled, and no longer a choice. No Studio's Assistant records call audio (clause 9.0), so the notice states as a fact that calls are not audio-recorded but are written down in full and summarised. The recording line returns as an alternative only if a Studio is ever put on the audio-retained configuration, and Carnelian states it under limb (c) before that happens. (b) What happens when a Guest declines. Use the "stop and carry on" line only where the voice platform can in fact stop the capture in progress, and the "end the call and move to WhatsApp" line where it cannot (clause 9.3, scripts S3, S3-T and S3-ALT). A Studio must not display the first line on a configuration that behaves in the second way. (c) Carnelian states which lines apply; the Studio displays them. The Studio does not have to work out which branch its configuration is on: Carnelian states it, and will notify the Studio of a change. The Studio is responsible for displaying the line Carnelian states and for keeping its display current (clause 21.3). Clauses 15.8, 15.9 and 21.4 apply to this clause as they do to every other part of the tooling.
22A. A paragraph for a Studio's own booking terms (not a notice — a term)
*Clause 22 is a notice: it informs, and it is what a Guest reads at reception. This clause is different. It is a contractual paragraph for a Studio to fold into its own terms of engagement with its Guests — its booking terms, its intake form, its online booking checkbox — and it does work that a notice cannot do.*
22A.1 What it does. UAE data protection law gives an individual a right to object to decisions taken by automated processing, and provides that the right does not arise where the automated processing is included in the terms of the contract between the individual and the controller. The paragraph below is supplied so that a Studio's own booking terms describe the Assistant's automated handling accurately. Whether it has that effect in any given case is a matter for the Studio and its own advisers; clause 22A.4 applies.
22A.2 The paragraph. Insert into your own booking terms. Adapt the studio name and the persona name; do not dilute the description of what is automated, because the exception is only as wide as the description.
EN:
Automated handling of bookings and messages. You agree that {Studio} uses an AI assistant, {Assistant}, to answer its telephone line and its business messaging channels, and that the following are handled automatically, without a member of our staff reviewing them at the time: understanding your request; checking our calendar; creating, changing and cancelling your appointment; quoting prices and treatment times from our published price list; applying any discount within limits we have set in advance; sending you confirmations, reminders, aftercare notes and — if you have opted in — offers; transcribing and summarising calls and voice notes; and maintaining a written profile generated from your conversations — your preferences, how you like to be spoken to, your sensitivity to price, how receptive you appear to be to a suggested add-on, and services you may be interested in — to save you repeating yourself. This automated handling forms part of these terms. You may at any time ask that a member of our staff review anything decided automatically, and we will; and you may withdraw marketing consent at any time. Calls are recorded and/or written down as described in our reception notice and at the start of each call.
AR:
المعالجة الآلية للحجوزات والرسائل. أنت توافق على أن {Studio} يستخدم مساعداً ذكياً باسم {Assistant} للرد على خطه الهاتفي وقنوات المراسلة الخاصة به، وعلى أن ما يلي يُنفَّذ آلياً ودون مراجعة من أحد موظفينا في حينه: فهم طلبك؛ والتحقق من جدول مواعيدنا؛ وإنشاء موعدك وتعديله وإلغاؤه؛ وذكر الأسعار ومدد العلاجات من قائمة أسعارنا المعلنة؛ وتطبيق أي خصم ضمن حدود حدّدناها مسبقاً؛ وإرسال التأكيدات والتذكيرات وملاحظات ما بعد العلاج، والعروض إذا كنت قد اشتركت فيها؛ وتفريغ المكالمات والرسائل الصوتية كتابةً وتلخيصها؛ والاحتفاظ بملف مكتوب يُنشأ من محادثاتك — يشمل تفضيلاتك، وأسلوب التواصل المفضّل لديك، ومدى حساسيتك للسعر، ومدى تقبّلك لخدمة إضافية مقترحة، والخدمات التي قد تهمّك — بما يغنيك عن تكرارها. وتُعدّ هذه المعالجة الآلية جزءاً من هذه الشروط. ويمكنك في أي وقت أن تطلب مراجعة أي أمر تقرّر آلياً من قِبل أحد موظفينا، وسنقوم بذلك؛ كما يمكنك سحب موافقتك التسويقية في أي وقت. وتُسجَّل المكالمات و/أو تُدوَّن كتابةً على النحو الموضّح في إشعار الاستقبال لدينا وفي بداية كل مكالمة.
22A.3 Two limits, stated so that nobody over-reads this. First, the paragraph removes the objection right in respect of the described processing; it does not remove the right to ask that a person review an automated decision, which is unqualified in UAE law, cannot be contracted out of, and is expressly preserved in the paragraph itself. Second, it is only as good as its accuracy: a Studio that pastes it in and then operates differently has a term that describes something else. Keep it current with clause 21.3.
22A.4 This is not legal advice. Clause 22A is a drafting aid supplied as a product deliverable. Carnelian does not review a Studio's terms, does not advise on them, and clause 15.8 applies to this clause as it does to every other part of the tooling. A Studio should have its own terms reviewed.
Parts C and E of this document — the non-defeatable-behaviour policy and the script-control provisions referred to above — are the terms that bind each studio. They are supplied to studios with their subscription documents and a copy is available on request from the contact address above.
Change log
| Version | Date | Effective | Change |
|---|---|---|---|
| v0.1-r1 | 2026-08-18 | Not in force | First version prepared. |
| v0.1-r2 | 2026-08-19 | Not in force | Revision: disclosure scripts, Studio obligations and the Guest notice extended. |
| v0.2 | 2026-08-19 | Not in force | Revision: channel, provider and retention disclosures extended. |
| v0.3 | 2026-08-19 | Not in force | Revision: the call-recording notice and decline route restated for both configurations; the information pointer added to the spoken notices; the health-data position, the applicable-law statement and the Studio obligations updated. |
| v0.4 | 2026-08-19 | Not in force | Revision: the publisher identity block, the definition of the Assistant, the training statement and the regulator names conformed to the rest of the document set. |
| v0.5 | 2026-08-20 | Not in force | Revision: the rendering and version references corrected, and the wording of the recording, demonstration-line and script provisions tidied. |
| v0.6 | 2026-08-20 | Not in force | Revision: the company's licence identity and contact details completed; the Instagram channel stated as in testing and not available; and the call-recording position stated plainly — calls are not audio-recorded, a written transcript and summary are kept as the record of the call, and the assistant announces at the start of the call that it is an AI. |
| v0.7 | 2026-08-21 | Not in force | Revision: the contact routes consolidated on support@carnelian.tech, then reported to be the only mailbox receiving mail, with an attention line for each purpose and a statement that a request is acted on whether or not the line is used; and Carnelian's Data Protection Officer named — Syed Sharique Ali, Manager, appointed with effect from 21 August 2026. The mailbox reading is corrected at v0.8. |
| v0.9 | 2026-08-25 | Not in force | Round-4 evidence: the entities and locations behind the provider table settled. The live voice chain is named — Soniox for speech-to-text (model stt-rt-v5, United States), ElevenLabs for text-to-speech (United States) and OpenAI's gpt-4.1 as the in-call language model (United States), each verified against the live voice configuration on 23 August 2026 — and the "speech providers used within the voice call" placeholder is replaced by named rows. The conversation database is stated as Ireland (eu-west-1), in the European Union, read from the live database endpoint, and clause 12.3.1 is re-cut so that the storage/processing distinction is drawn against a stated region rather than an open one. The alerting platform's geography is stated as its own distributed, global infrastructure. The remaining bracketed placeholders on this page — the code-level guard date, the concierge availability, the lifecycle-message list, the privacy mailbox, the decline-mid-call treatment and the retention target date — are replaced by definite prose or by the actual value. No United States provider is described as European. |
| v0.8 | 2026-08-21 | Not in force | Mailbox correction: delivery on all six addresses was verified by test on 21 August 2026 — an earlier same-day check appeared to fail and was premature — and the branded ABS Twin routes are restored. Privacy and data-subject requests go to privacy@contact.abstwin.com, the Data Protection Officer is reachable directly at dpo@contact.abstwin.com, complaints to info@contact.abstwin.com, legal notices to legal@contact.abstwin.com, and support@carnelian.tech remains the company contact and the alternative route. The rule that a request, report or complaint is acted on whether or not the attention line is used is unchanged. |
Arabic version
An Arabic version of this page will be published alongside the English version at the same URL. The runtime scripts in Part B and the Guest notice in Part D will be deployed in Arabic as well as English; Arabic and English are both launch-blocking for the scripts, and the remaining supported conversation languages follow.
On publication, the precedence rule in clause 18.4.1 applies to Part A and to the Guest-facing text in Parts B and D: the Arabic version prevails, to the fullest extent permitted by applicable law. Parts C and E, and the Studio-facing obligations in Part D, follow the language clause in the Master Subscription Agreement (clause 18.4.2).