Cookie & Tracking Notice
Plain-language summary
The marketing site does not set cookies. abstwin.com itself writes nothing to your browser — no cookies, no local storage. There is no consent banner because there is nothing to consent to. (Two qualifications, and clause 3.1 states them exactly: if you are also signed in to our Console, a session cookie set there may be scoped to the wider abstwin.com domain and so be technically present while you visit the marketing site; and the hosting platform that serves both surfaces may set an operational cookie of its own. Clause 5.1 records what is and is not there, and both points are open verifications until the verification recorded under the clause 5 heading is completed.) We measure how the site is used with an analytics tool that runs in memory only and builds no profile of you.
The Console and the Staff App set only what they need — the session cookies that keep you signed in, the preferences you set yourself (branch, theme, language), a service worker so that notifications and the offline app shell work, and a bot check on the two public forms (the studio application form and the support form) so that automated submissions can be filtered out. They set no analytics, advertising or cross-site tracking technologies. Clause 5 lists all of it. We run no advertising networks, no advertising pixels and no cross-site tracking on any of our surfaces, and nothing about a Studio's Guests goes into our analytics.
If we ever add a technology that is not strictly necessary, we will ask for your consent first, with a genuine choice to refuse, and we will update this notice before that technology goes live.
This summary is written for readability. Clauses 1 to 13 are the operative text, and clause 5 — not this summary — is the definitive statement of what is actually in use.
1. About this notice
1.1 Who we are. This notice is published by Carnelian Technologies L.L.C-FZ ("Carnelian", "we", "us", "our"), a Limited Liability Company licensed by Meydan Free Zone, Dubai, United Arab Emirates, licence no. 2415615.01 (issued 26 January 2024, expiring 25 January 2027), registered address Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E., which is also the correspondence address. Full identity particulars are set out in the Legal Notice / Imprint.
1.2 What this notice is. It explains, in one place, every cookie and similar technology used on the surfaces listed in clause 1.3: what each one does, who provides it, how long it lasts, the legal basis on which we use it, and how you can object to or control it. It supplements, and does not replace, the Privacy Policy, which describes all of our processing of Personal Data.
1.3 What this notice covers. This notice covers:
1.3.1 the marketing website at abstwin.com (the apex domain is canonical; www.abstwin.com redirects to it), including the Demo Surfaces as defined in the Website Terms of Use — the demonstration telephone line, the demonstration WhatsApp conversation and any interactive demonstration published on the site. As at the verification date recorded under the clause 5 heading, no Demo Surface stores anything on your device: the demonstration routes you to a telephone call or to WhatsApp, and the technologies of those channels are outside this notice (clause 1.4.2). If an on-page interactive demonstration is introduced, it is recorded in table 5.1 before it goes live;
1.3.2 the Console at app.abstwin.com — the owner, reception, manager and administrator surfaces used by Studios and by Carnelian staff;
1.3.3 staging.abstwin.com, our pre-production copy of the Console, which behaves the same way; and
1.3.4 the browser-delivered parts of the Staff App at staff.abstwin.com (and staff-staging.abstwin.com), including where that web application is displayed inside a native iOS or Android shell.
1.4 What this notice does NOT cover. This notice does not cover, and Carnelian does not control:
1.4.1 a Studio's own website, booking page, landing page or social profile. A Studio that embeds a link to ABS Twin in its own website remains solely responsible for the cookies and tracking technologies on that website and for its own cookie notice and consent mechanism. Nothing in this notice is a representation that any Studio's own website or booking page is compliant with any law;
1.4.2 Platform Providers' own surfaces — including WhatsApp and Meta Platforms, Instagram, telephony carriers, the Apple App Store and Google Play. When a Guest messages a Studio on WhatsApp or Instagram, that conversation happens inside the Platform Provider's application, under the Platform Provider's own terms and privacy notices, and that provider sets whatever technologies it chooses on the Guest's device;
1.4.3 third-party websites we link to, which have their own notices; and
1.4.4 the internal handling of Personal Data generally, which is described in the Privacy Policy and, for Guest Data, in the Data Processing Agreement.
1.5 Defined terms. Capitalised terms not defined in this notice have the meaning given in the Master Subscription Agreement and in the Privacy Policy — in particular ABS Twin, Studio (also referred to as Customer), Guest, Authorised User, Assistant, Customer Data, Guest Data, Digital Twin, Personal Data, Controller, Processor, Sub-processor, Platform Providers, Console, Staff App and Order Form — and Business Day, which has the meaning given in clause 1.1.7 of the Master Subscription Agreement and is read throughout our legal documents as *a day other than a Saturday, a Sunday or a public holiday in the United Arab Emirates*. Demo Surfaces is defined in clause 3.2 of the Website Terms of Use. Applicable Data Protection Law has the meaning given in the Privacy Policy and is used in that sense wherever it appears in this notice — at clauses 6.1, 7.6 and 10.4 and in the supervisory-authority row of clause 12; clause 6.1A applies the same idea in longhand, without using the defined term. Terms defined locally in this notice appear in clause 2.
1.6 In what capacity we act. For the technologies and the server-side records described in this notice — the cookies, storage keys, service workers and push registrations in clause 5, the analytics in clause 8 and the logs, rate-limiting records, audit records and waitlist record in clause 9 — as they relate to visitors to abstwin.com, applicants and prospective customers, Carnelian acts as Controller and determines the purposes and means of that processing. For an Authorised User's account and security data, Carnelian acts as Controller of the identity record. Guest Data is different: for a Guest's Personal Data processed through ABS Twin, the Studio is the Controller and Carnelian acts as its Processor under the Data Processing Agreement. Guest Data is not the subject of this notice, and none of it is placed in any cookie or storage key (clause 5.4). The full allocation of roles and responsibilities is set out in the Privacy Policy and the Data Processing Agreement; where a technology described here is provided by a third party, that provider acts as our Sub-processor and is listed in the Sub-processor List.
1.7 Status of this notice. This notice is an information document. It is not a contract and it does not vary the Master Subscription Agreement, the Data Processing Agreement or any Order Form. Where this notice and a signed agreement address the same subject matter, the signed agreement prevails as between Carnelian and the Studio. Your use of the surfaces described in clause 1.3 — including this page — is subject to the Website Terms of Use. Nothing in this notice excludes or limits any liability which cannot lawfully be excluded or limited (clause 10.3).
1.8 Children. The surfaces listed in clause 1.3 are business tools intended for Studio owners, their staff and prospective business customers. They are not directed at children. We do not knowingly set any cookie or similar technology for, or measure the use of those surfaces by, a person under 18 years of age. 18 is the figure stated across our legal documents — clause 31.4 of the Privacy Policy, the Website Terms of Use and the Staff App Privacy Notice. Honest limitation: no age gate exists in the product, the Service does not verify age, and this is a statement of what we do not knowingly do rather than of a control that enforces it. Where you tell us that a child's Personal Data has reached us through these surfaces, we will investigate, and where we confirm it we will delete or irreversibly anonymise it within 30 days from confirming it, except to the extent we must retain it by law, need it to establish, exercise or defend a legal claim, or a competent authority or court has directed us to preserve it; a copy may persist in backups until the backup cycle completes, subject to the security measures in the Privacy Policy. Where the record belongs to a Studio as Controller, we refer the request to that Studio and assist it under the Data Processing Agreement. A Guest's interaction with a Studio through WhatsApp, Instagram or the telephone is governed by the Studio's own notice and by the Privacy Policy, not by this clause.
2. What we mean by "cookies and similar technologies"
2.1 Cookie. A small text file that a website asks your browser to store, and that your browser sends back on later requests to the same site. A first-party cookie is set by the site you are visiting; a third-party cookie is set by a different domain whose content the site loads. A session cookie is deleted when you close your browser; a persistent cookie survives until it expires or you delete it.
2.2 Similar technologies. This notice treats the following as equivalent to cookies, because they have the same effect — reading from or writing to your device, or allowing you to be recognised: 2.2.1 local storage and session storage — browser storage areas a site can write key/value data into; 2.2.2 pixels, web beacons and tracking images — tiny requests embedded in a page or an email that record that it was opened; 2.2.3 software development kits (SDKs) embedded in a mobile application; 2.2.4 device or browser fingerprinting — deriving a quasi-identifier from device and browser characteristics rather than from stored data; and 2.2.5 service workers and browser caches, where used to store data on your device rather than merely to speed up delivery.
2.3 Not covered by the word "cookie". Server-side records — such as web-server request logs, security and rate-limiting records, our own audit log and the early-access waitlist record — are not cookies and are not controlled by browser cookie settings. They are disclosed separately in clause 9.
3. Our position in short
3.1 The marketing site itself sets nothing on your device. The abstwin.com marketing site sets no cookies of its own and writes no browser storage of its own. Two qualifications make the claim exact: a session cookie our sign-in provider sets for the Console may be scoped to the parent domain abstwin.com, in which case it is present here for a signed-in Authorised User; and the hosting platform, which serves both surfaces, may set its own operational cookie. The "Set on (domain)" column in tables 5.1 and 5.2 records the position for each, and both are subject to the verification under the clause 5 heading. Because nothing non-essential is stored by the marketing site, there is nothing for you to consent to, and we therefore do not show a consent banner. See clause 6.4 for what happens if that changes.
3.2 The Console and the Staff App set only what they need. Signing in to a private, tenant-isolated control panel is not possible without a session mechanism. They therefore set strictly necessary authentication and session cookies, store functional preferences you set yourself, and — so that notifications and the offline app shell work — register a service worker. They set no analytics cookies, no advertising cookies and no cross-site tracking technologies.
3.3 We run no advertising technology. As at the verification date recorded under the clause 5 heading, across every surface listed in clause 1.3: no advertising networks and no advertising pixels — including no Meta pixel, no Google Ads tag and no Google Analytics; no cross-site or cross-app tracking and no identity graph; no sharing of Personal Data with data brokers, and we do not sell, rent or trade Personal Data and do not share it for advertising purposes; no use of cookies or similar technologies to build advertising or marketing profiles of Guests; and no device or browser fingerprinting. Introducing any of them would require the steps in clause 6.4, including an update to clause 5 and the change log before deployment.
3.4 Read clause 5, not clause 3. Clauses 3.1 to 3.3 describe the position as at the verification date recorded under the clause 5 heading. The authoritative statement of what is in use at any time is the versioned table in clause 5, with the change log at the end. We will not leave a headline claim standing while the table underneath it changes.
4. The categories we use
4.1 Categories. We classify every cookie and similar technology into one of five categories:
| # | Category | What it means | In use today? |
|---|---|---|---|
| 4.1.1 | Strictly necessary | Required to deliver a service you have asked for — signing you in, keeping you signed in, keeping the session secure, delivering the application itself (including its offline shell), and protecting our public forms from automated abuse. Without these, the Console cannot function. | Yes — Console and Staff App only (clauses 5.2 and 5.3A) |
| 4.1.2 | Functional / preference | Remembers a choice you actively made — which branch you are viewing, light or dark theme, English or Arabic, whether you dismissed a prompt, and whether you allowed or refused notifications. | Yes — Console and Staff App only (clauses 5.2, 5.3 and 5.3A) |
| 4.1.3 | Performance / analytics (not a cookie or a similar technology — listed for completeness, because it is measurement and a reader looking for it should find it here) | Measures how a site is used. We do this without cookies or device storage (clause 8). | Yes, cookieless — marketing site only |
| 4.1.4 | Targeting / advertising | Builds a profile to select or measure advertising. | No — none, anywhere |
| 4.1.5 | Social media | Embedded social widgets and share buttons that set their own cookies. | No — none, anywhere |
4.2 Categories 4.1.4 and 4.1.5 are not merely unused — they are excluded by design. We would have to change this notice, obtain consent, and add the relevant provider to the Sub-processor List before either category could be introduced. See clause 6.4.
5. What is actually in use — the technology tables
These tables are the operative disclosure. Each is stated as at the verification date below.
Technologies last verified against the production deployments on the date shown in the version line above. A version date is a drafting date; the verification date is the date on which the cookies, storage keys, service workers and push registrations below were last actually inspected in a running production browser session. Where a revision ever moves the version date without a fresh inspection, the two dates are stated separately and the earlier of them is the date on which this disclosure was last known to be complete.
Where the providers named below are established, and on what basis data reaches them, is stated at clause 5.6.
5.1 Marketing site — abstwin.com
| Technology | Provider | Category | First/third party | Set on (domain) | Purpose | Stored on your device? | Duration |
|---|---|---|---|---|---|---|---|
| None set by the marketing site | — | — | — | — | The marketing site sets no cookies of its own and writes no browser storage of its own. | No | — |
| Analytics script (PostHog) | PostHog, Inc. — storage region European Union (PostHog EU Cloud); our client sends to the European Union ingestion host eu.i.posthog.com | Performance / analytics | Third-party script, no third-party cookie | — (nothing is set) | Counts page views, section views, clicks on calls-to-action, opened FAQ items and web-performance measurements. Configured to hold its state in memory only. | No — no cookie, no local storage | Nothing persists; state is discarded when the tab is closed |
| Authentication session cookie set by the Console, where scoped to the parent domain | Clerk, Inc. (our authentication provider) | Strictly necessary | First-party | Set by the Console and the Staff App on their own hostnames; whether our authentication provider also scopes a session cookie to the parent domain .abstwin.com is stated at the next technical verification | Not set by, or used by, the marketing site. Listed here only so that a signed-in Authorised User who inspects this page's cookies finds every cookie accounted for. Its purpose and lifetime are in table 5.2. | Only if parent-domain scoped — see the "Set on (domain)" column | As stated in table 5.2 |
| Platform / infrastructure cookie | Vercel Inc. (hosting) | Strictly necessary | First-party | First-party on our own domains; none observed with a cross-site scope | Operational only, if set at all. The marketing site runs on the same hosting platform as the Console, so the open question recorded at 5.2 e applies here too and is resolved for both surfaces together. Clause 6.3.1A states the basis if such a cookie exists. | Only if the platform sets one; none observed on the marketing site | None observed; where one is set, its duration is stated at the next technical verification |
Notes to table 5.1:
5.1.1 Configuration, and the Do Not Track signal. The analytics tool is configured with memory-only persistence, person profiles disabled entirely, session recording disabled, and surveys, heatmaps and dead-click capture disabled. Our configuration also instructs the provider's library to respect a browser "Do Not Track" signal; as verified on the verification date, where the browser sends that signal no analytics events are sent. Two qualifications, because this control is neither ours nor universal. First, not every browser offers a Do Not Track setting — Safari removed its control in 2019 and does not send the signal, so the route is unavailable on Apple platforms; because nothing is stored on your device, blocking the analytics request in your browser or with an extension has the same practical effect, and clause 7.1 adds a written route. Second, Do Not Track is the signal our provider supports and therefore the one we act on; we do not claim to honour Global Privacy Control, because we could not evidence it.
5.1.2 Because nothing is stored, each visit is counted as a new visit. We cannot recognise a returning visitor and we do not attempt to.
5.1.4 Where analytics events go, and on what basis they leave the UAE. Analytics events are transmitted from your browser to our analytics provider, PostHog, Inc., and are ingested through its European Union ingestion host (eu.i.posthog.com).
(a) The position we take first is that the transfer regime is not engaged, because the events are not Personal Data: no account is identified, no person profile is created or stored, no persistent identifier is assigned, and the source IP address is truncated at ingestion. The control which makes that true is the event-property discipline at clause 8.5, and it is stated as a control rather than as a belief.
(b) If that footing is lost — if any event property ever carries an identifier, or IP truncation is found not to be enabled — the transfer must be re-based or the measurement must stop.
(c) The contractual safeguard, on the footing that the regime is engaged. We assert no adequacy — no adequacy list has been published. Any transfer is made under the instrument described at clause 5.6.
(d) Support access. The provider's supporting operations — technical support, incident investigation and maintenance — may involve access to the ingested events from outside the European Union, which would be a further transfer to be recorded and assessed.
The full assessment is held in our internal cross-border transfer assessment; the position for our whole stack is stated publicly in the Privacy Policy.
5.1.5 How long analytics events are kept. Analytics event data is retained for 12 months, after which it is deleted or retained only in irreversibly aggregated form from which no individual visit can be reconstructed. The qualifications at clause 9.7.5 apply to this period as they apply to every other period stated in this notice — it is a maximum, deletion runs on a periodic cycle, and a copy may persist in backups until the backup cycle completes. The retention position for every other record described in this notice is stated at clause 9.7; the internal evidence base is our internal retention and deletion schedule.
5.2 Console (app.abstwin.com, staging.abstwin.com) and Staff App (staff.abstwin.com)
| # | Cookie / technology | Provider | Category | Party | Set on (domain) | Purpose | Duration |
|---|---|---|---|---|---|---|---|
| a | The session cookie our authentication provider sets, named per its published documentation — enumerated here at the next technical verification | Clerk, Inc. (our authentication provider) | Strictly necessary | First-party on app.abstwin.com / staff.abstwin.com | app.abstwin.com / staff.abstwin.com; whether the provider also scopes it to the parent domain .abstwin.com is stated at the next technical verification | Holds the signed session that proves you are logged in, so that every page and API request can be authorised. Without it you cannot sign in or stay signed in. | The lifetime of the signed-in session, as set by our authentication provider; stated exactly at the next technical verification |
| b | The client-state cookie our authentication provider sets, named per its published documentation — enumerated here at the next technical verification | Clerk, Inc. | Strictly necessary | First-party | The same hostnames as row a; stated exactly at the next technical verification | Tracks whether a session exists so the application can decide, without a server round-trip, whether to render a signed-in or signed-out view. | The lifetime set by our authentication provider; stated exactly at the next technical verification |
| c | The sign-in-protection cookies our authentication provider sets, named per its published documentation — enumerated here at the next technical verification | Clerk, Inc. | Strictly necessary | First-party (may be set on the provider's own domain during the sign-in redirect) | First-party, and on the provider's own domain during the sign-in redirect; stated exactly at the next technical verification | Protects the sign-in exchange against cross-site request forgery and replay. | Session / short-lived, for the duration of the sign-in exchange; stated exactly at the next technical verification |
| d | abs_branch | Carnelian | Functional / preference | First-party | app.abstwin.com (and staging.abstwin.com); Path=/ | Remembers which branch of a multi-branch Studio you selected, so the Console shows that branch's data on your next visit. The value is a branch identifier, or the value all where you have selected All Branches. As verified on the verification date recorded under the clause 5 heading, the Console validates that identifier server-side against your own Studio's branches and refuses a value that does not belong to it. | 365 days; Path=/; SameSite=Lax |
| e | Platform / infrastructure cookies | Vercel Inc. (hosting) | Strictly necessary | First-party | First-party on our own domains; none observed with a cross-site scope | Operational only, if any is set — for example deployment protection or edge routing. Clause 6.3.1A states the basis if one exists. Whether the hosting platform sets any cookie in production is confirmed at the next technical verification; none has been observed. | None observed; where one is set, its duration is stated at the next technical verification |
| f | Bot-protection challenge (Cloudflare Turnstile) — loaded only on the public application form (/apply) and the public support form (/support) | Cloudflare, Inc. | Strictly necessary | Third-party script from challenges.cloudflare.com | Any entry it sets belongs to challenges.cloudflare.com, the domain the challenge is loaded from; the exact scope is stated at the next technical verification | Distinguishes a human from an automated submission before we accept a form. Processes your IP address and a challenge token. | Whether it sets a cookie or a browser-storage entry in our configuration, and for how long, is confirmed at the next technical verification |
5.3 Browser storage keys (not cookies) — Console and Staff App
| # | Key | Surface | Category | Purpose | Duration |
|---|---|---|---|---|---|
| a | abs-cockpit-theme | Console (owner) | Functional | Remembers whether you chose the light or dark theme. | Until cleared |
| b | rc-theme, rc-lang | Console (reception) | Functional | Remembers the reception console's theme, and whether you chose Arabic or English. | Until cleared |
| c | abs-mgr-floor-action-mode | Console (manager) | Functional | Remembers whether the manager floor view is in action mode. | Until cleared |
| d | ck-push-optout | Console | Functional | Records that you declined or dismissed the browser notification prompt, so you are not asked again. This key exists to respect a refusal. | Until cleared |
| e | abs_lang | Staff App | Functional | Remembers whether the staff member chose Arabic or English (the app is bilingual with right-to-left support). | Until cleared |
| f | abs_push_optout | Staff App | Functional | Records that the staff member declined or dismissed push notifications. | Until cleared |
| g | abs_a2hs_seen | Staff App | Functional | Records that the "add to home screen" prompt was dismissed, so it is not shown again. | Until cleared |
| h | abs_dev_access | Staff App | Development only | A development-only key that is not present in production builds. | Until cleared |
5.3A Service workers, caches and push registration — Console and Staff App
Clause 2.2.5 treats service workers and browser caches as equivalent to cookies where they store data on your device. They do here, and so this sub-table discloses them. Nothing in this sub-table is set on the marketing site.
| # | Technology | Surface | Provider | Category | What is stored on your device | Duration |
|---|---|---|---|---|---|---|
| a | Service worker registered at /service-worker.js | Console — the reception and manager surfaces, where the push listener is mounted (app.abstwin.com, staging.abstwin.com). An owner who uses only the cockpit does not register it | Carnelian (the script), Bird / Pusher Beams (the push code it loads — row e) | Strictly necessary / functional | The service-worker script itself, kept by the browser for the Console's origin. Its only job is to receive push notifications and relay them to an open Console tab. It caches nothing. | Until you unregister it in your browser or clear site data for the Console |
| b | Service worker registered at /sw.js | Staff App (staff.abstwin.com, and inside the native shells) | Carnelian (the script), Bird / Pusher Beams (the push code it loads — row e) | Strictly necessary / functional | The service-worker script itself, plus the Cache Storage entry described in row c. It handles push notifications, the notification tap, and offline delivery of the application shell. | Until you unregister it or clear site data; the cached content is treated as described in row c |
| c | Cache Storage (cache name abs-staff-v2) | Staff App | Carnelian | Strictly necessary / functional | The application's own shell and static assets only — the start page, application code and stylesheets, fonts, icons and the web-app manifest, so the app opens when the connection is poor. As verified on the verification date recorded under the clause 5 heading, the cache is configured as a default-deny allow-list limited to the application shell and static assets of our own origin, with every request to a data endpoint fetched from the network and never cached, and is cleared on sign-out and on lock. No schedule, booking, Guest record or other response from our data endpoints is written to it. The cache name and the clearing behaviour are re-checked at each technical verification. | Cleared on sign-out and on lock, and replaced when the application is updated |
| d | Push registration with the notification service (Bird (formerly Pusher) — Pusher Beams) | Console and Staff App | Bird / Pusher (see row e) | Strictly necessary / functional — only after you allow notifications | A device registration held by the browser's push service, and, stored on the device by the notification SDK, the list of alert topics ("interests") your session is subscribed to. In the Console these are branch-level topics of the form reception-{branch id} and managers-{branch id}. In the Staff App they are staff-{staff id} — an identifier for the signed-in staff member — and, for a housekeeping role once that role exists, refreshments-{branch id} (no such role exists today, so that interest is not subscribed). They are internal identifiers, not names, and they contain no Guest data. Nothing is registered unless you grant the browser's notification permission; if you decline, the refusal is recorded in the opt-out keys at 5.3 d and 5.3 f. | Until you revoke notification permission, sign out, unregister the service worker or clear site data |
| e | Third-party script loaded into our service workers from https://js.pusher.com/beams/service-worker.js | Console and Staff App | Bird (formerly Pusher) — Pusher Beams — the contracting entity is Pusher Ltd (United Kingdom), part of Bird, per its published terms, which describe United Kingdom, European Union and United States infrastructure; the specific region in which device registrations are held is not stated in those terms and is confirmed with the provider | Strictly necessary / functional | Our service workers import the notification provider's own code, which therefore executes on our origin and handles the incoming push payload. It stores the device registration and interests described in row d. We disclose it as a third-party technology because that is what it is. | As row d |
Notes to table 5.3A:
5.3A.1 Why these exist. Push notification is the mechanism by which a therapist learns that a Guest has arrived and a manager learns that a booking has changed. It is not a measurement, marketing or profiling technology, and it is not used as one.
5.3A.2 The provider's open items. The provider is listed in the Sub-processor List (row 12, as "Bird (formerly Pusher) — Pusher Beams"). Of the two items recorded there, the contracting entity is stated from the provider's own published terms — Pusher Ltd (United Kingdom), part of Bird — and is restated against the executed terms when that check is complete; the region in which device registrations are held is not stated in those terms, and it stays open until the provider confirms it.
5.3A.3 Notification content, and health-related data. What a push notification itself contains — and the deliberate minimisation applied to it — is described in the Staff App Privacy Notice and the Privacy Policy. This clause describes only what is stored on the device. Where a Studio's services are health-related, restrictions on the handling and location of health data, and the categories of Studio to which the service may be provided, are addressed in our Restricted / Health Data Addendum; nothing in this notice states a position which that addendum does not support.
5.4 What none of these carry. No cookie, storage key, cache or push registration listed in clauses 5.2, 5.3 and 5.3A contains, transmits or is used to derive: a Guest's name, phone number, email address, booking, payment, treatment record, conversation content, voice transcript or Digital Twin profile. The abs_branch cookie carries a branch identifier belonging to your own Studio, or the value all, and nothing else. The push interests at 5.3A d carry an internal staff or branch identifier and nothing else. The Staff App's cache carries the application's own shell and static assets and nothing else.
This clause is about what is STORED ON YOUR DEVICE by the technologies listed above. The content of a notification we send is a different matter. A notification delivered to the Console or the Staff App may contain a Guest's first name and the service booked, and your device's operating system will display it — including on a locked screen — and retain it in its own notification area, which is outside our control. What a notification contains, and the minimisation applied to it, are described in the Staff App Privacy Notice; where the service booked is health-related, our Restricted / Health Data Addendum applies.
5.5 Native application shells. Where the Staff App is delivered inside a native iOS or Android shell, the browser storage keys in clause 5.3 and the service worker, cache and push registration in clause 5.3A apply within the shell's web view in the same way, and are disclosed here because they are device storage on our origin. As at the verification date recorded under the clause 5 heading, the native shells are built to contain no advertising software development kits, no attribution software development kits and no analytics software development kit. Delivery of notifications to the native shells uses the operating-system push services of Apple and Google and the notification provider's own software; the native operating-system push token, the delivery of notifications through those services, and the content of the notifications themselves are described in the Staff App Privacy Notice and the Privacy Policy.
5.6 Where these providers are established, and on what basis data reaches them. Each provider named in clause 5 is a Sub-processor listed in the Sub-processor List. We do not assert that any recipient country has been the subject of a published adequacy decision. Where a transfer of Personal Data outside the United Arab Emirates occurs, it is made under a written contract obliging the recipient to apply the protections, measures, controls and requirements imposed by UAE data-protection law to the transferred data, and specifying how appropriate measures may be imposed on the recipient through a competent supervisory or judicial authority in its own country — in the United States, the Federal Trade Commission, the relevant State Attorney General and the State and federal courts; in the European Union, the lead supervisory authority and the national courts. Where a provider's own standard terms do not contain that specification, a supplementary instrument is required, and the absence of one is recorded below.
| Provider | What it provides | Where it processes | Transfer instrument in force |
|---|---|---|---|
| PostHog, Inc. | Analytics (5.1, clause 8) | European Union (PostHog EU Cloud) | The provider's published data-processing terms — see the note below |
| Clerk, Inc. | Authentication cookies (5.2 a–c) | United States, per the provider's published documentation | The provider's published data-processing terms — see the note below |
| Vercel Inc. | Hosting (5.1, 5.2 e); server logs (9.1) | United States primary, per the provider's published documentation, which reserves a general right to process globally | The provider's published data-processing terms — see the note below |
| Cloudflare, Inc. | Bot protection on public forms (5.2 f) | United States, with a global edge network — a challenge is served from the edge location nearest the visitor | The provider's published data-processing terms — see the note below |
| Bird (formerly Pusher) — Pusher Beams | Push registration and delivery (5.3A d–e) | United Kingdom, European Union and United States infrastructure, per its published terms; the region in which device registrations are held is not stated in them (5.3A.2) | The provider's published data-processing terms — see the note below |
Note to the table. Each entry in the last column is the provider's own published data-processing terms. The check described in the paragraph above this table — whether those terms carry the specification of how appropriate measures may be imposed on the recipient in its own country — is not complete for these providers. We say that rather than record an instrument we have not read to the end. Where a provider's terms are found not to carry it, the supplementary instrument required is obtained and recorded here, and its absence in the meantime is recorded here too.
6. Legal basis, and how consent works here
6.1 The framework we apply. We apply the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, and any successor or amending instrument) as the applicable data-protection regime for this notice, together with the applicable federal legislation on trading by modern technological means and on consumer protection. Where a Studio, an Authorised User or a Guest is subject to another data-protection regime, Applicable Data Protection Law as defined in the Privacy Policy applies in addition, and clause 6.1A states what we do about it.
6.1A Where another regime is stricter. Where a Studio, an Authorised User or a Guest is subject to another data-protection regime — including the DIFC Data Protection Law and its Regulations (in particular the DIFC standards on electronic marketing and on cookie consent), the ADGM Data Protection Regulations, or the data-protection law of another GCC state — and that regime imposes a stricter standard for a technology described in clause 5 or for a marketing preference described in clause 7.4, we apply the stricter standard to that processing, and the relevant supervisory authority is added to the table in clause 12.
6.2 The bases we rely on. For the technologies described in this notice we rely on the bases identified in clause 6.3, and we do not rely on a legitimate-interests or balancing-test basis under the UAE Personal Data Protection Law. Where another data-protection regime applies to a reader (clause 6.1A), the basis relied on under that regime is stated in the Privacy Policy.
6.3 Basis for what is in use today.
6.3.1 Strictly necessary session and security cookies (5.2 a–c). These are used because they are necessary to perform the service the Authorised User has asked for by signing in, and to keep that session secure. We layer the basis rather than relying on a single limb: the act of signing in is itself a clear, affirmative and logged action by the Authorised User; access to the Console is provided under terms the Authorised User accepts on invitation; and securing an authenticated session is required in order to meet our own security obligations.
6.3.1A Platform / infrastructure cookies (5.1, 5.2 e). If the hosting platform sets an operational cookie in production, it is set in order to route and protect requests to the surfaces you asked for, and is necessary to deliver them. Whether any such cookie is set at all is an open question recorded in tables 5.1 and 5.2, and this clause applies only if the answer is yes.
6.3.2 Functional preference cookie and storage keys (5.2 d, 5.3). These record a choice you made yourself. Selecting a branch, switching to dark mode, switching to Arabic or dismissing a notification prompt is the affirmative action; nothing is written until you act. You can reverse each of them the same way you set them.
6.3.3 Bot protection on public forms (5.2 f). Used on the studio application form and the support form only, and only in order to process the submission you are voluntarily making — that is, as a step taken at your own request in connection with a prospective contract or support request — and to enable us to establish or defend claims arising from abuse of those forms.
6.3.4 Cookieless analytics (5.1, clause 8). The question the UAE Personal Data Protection Law asks is whether Personal Data is processed at all, and if so on which of the express statutory bases. Our position is that the events described in clause 8.2 are not Personal Data: no account is identified — there is no sign-in on the marketing site and no identification call exists in our code; no person profile is created or stored; no persistent identifier of any kind is assigned to a visitor; and the source IP address is truncated at ingestion. On that footing no statutory basis is engaged, because the statute is not engaged. This position is contingent, and we state the consequence rather than assume it holds: if any of those four conditions is lost — an identifier appears in an event property, a profile is created, or IP truncation is found not to be enabled — the events become Personal Data, and we will either obtain consent meeting clause 6.4 before the measurement continues, or stop the measurement. The property discipline which holds the position true is at clause 8.5. Separately, and independently of the basis question, a Do Not Track signal stops the measurement (clause 5.1.1) and clause 7.1 states the other routes.
6.3.5 Service worker, cache and push registration (5.3A). The service worker and the application-shell cache are necessary to deliver the Staff App and the Console as the Authorised User has asked for them — an app that opens on a poor connection and a Console that shows a live board — and they store no Personal Data beyond the application's own files. Push registration is a separate matter and is treated as such: nothing is registered, and no interest is stored, unless the Authorised User grants the browser's notification permission by a clear affirmative action, and a refusal is recorded and respected (clause 5.3 d and 5.3 f). Notification permission can be withdrawn at any time in the browser or operating system, which ends the registration for the future.
6.3.6 The server-side records in clause 9. These are not cookies, but the same discipline applies to them and this notice states their basis rather than deferring it. Server logs and rate-limiting and abuse records (9.1, 9.2) are processed in order to fulfil the security obligations imposed on us as a controller by law, and to enable us to establish, exercise or defend legal claims. The owner-audit log (9.3) is processed in order to fulfil the accountability and security obligations imposed on us by law, and — for entries which support a contract or transaction record — to meet a statutory record-keeping duty; clause 9.7 states what happens to the actor's identity and IP address before the rest of the record. The transactional email record (9.4) is processed in order to perform, or take steps at your request prior to, a contract. The early-access waitlist record (9.5) is processed in order to take a step at your own request prior to entering into a contract — you asked to be told when ABS Twin becomes available — and for no other purpose; the exit route is at clause 7.4 and 9.5. Where a reader is subject to another regime, the basis relied on under that regime is stated in the Privacy Policy.
6.4 The standard we apply if we ever introduce a non-essential technology. This clause states the standard we apply and undertake to apply. It is a statement of our policy under clause 11 and may be amended prospectively in accordance with that clause; consistently with clause 1.7 it is not a contract. On any surface listed in clause 1.3 — the marketing site, the Console, the Staff App or a native shell — we will not deploy any cookie or similar technology in the targeting/advertising or social-media categories, and will not deploy any analytics or product-telemetry technology that stores data on your device, unless all of the following are true first:
6.4.1 prior consent. No non-essential technology is set before you have given consent by a clear affirmative action. Non-essential categories default to off;
6.4.2 a real choice. Refusing is given equal prominence with accepting, in the same place, and requires no greater effort;
6.4.3 no dark patterns. No pre-ticked boxes. No cookie wall — access to any surface listed in clause 1.3 is never conditioned on accepting non-essential technologies, and refusing them never degrades the service you are entitled to. Closing, ignoring or dismissing a banner is treated as a refusal, not as consent;
6.4.4 consent is not inferred from use. Continuing to browse, scrolling, navigating between pages, or simply not responding is not consent, and we will never characterise it as consent;
6.4.5 withdrawal is as easy as granting. A control to reopen and change your choices is reachable from this notice and from the site footer, and withdrawal takes effect immediately for the future. One qualification, because a choice recorded in a browser is a thing stored in that browser: your choice is remembered per browser and per device (clause 7.2.3);
6.4.6 we will log the consent. Before any non-essential technology is deployed we will implement, and this clause will then describe, a consent record capturing which version of this notice and which banner text were shown, when, what choice was made, and through which control — so that we can demonstrate consent if we are asked to. Consent records will be retained for the period for which the consent is relied on, plus 24 months;
6.4.7 the provider is disclosed. The provider is added to the Sub-processor List, with the date it was added, and the cross-border position is assessed internally and stated at clause 5.6; and
6.4.8 this notice is updated first. Clause 5 and the change log are updated, the version is incremented, and the effective date is stated, before the technology is deployed.
6.4A Technologies required by law, mandated by a Platform Provider, or urgently necessary.
6.4A.1 Required by law or by a binding order. Where a cookie or similar technology is required by applicable law, or by a binding order or direction of a court, regulator or competent authority, the basis is fulfilment of an obligation imposed on us by law, not consent. We will not ask for a consent we could not act on. Instead we disclose the technology, the requirement relied on and its scope in clause 5 and in the change log at the time of deployment, and we limit the deployment to what the requirement actually demands and reverse it when the requirement ends.
6.4A.2 Mandated by a Platform Provider, or urgently necessary. Clause 6.4.8 and the 30-day notice period in clause 11.3 do not apply, and the technology may be deployed on publication of the updated notice rather than in advance of it, where a cookie or similar technology is (a) mandated by a Platform Provider — including Meta Platforms, Apple, Google, a telephony carrier or a payment provider — as a condition of our continued access to a service on which ABS Twin depends, on a timetable shorter than 30 days; or (b) urgently necessary for security, fraud prevention or the integrity of the service, including to respond to a live incident or an attack in progress.
6.4A.3 What continues to apply under 6.4A.2. Every other commitment in clause 6.4 continues to apply — where the technology is not strictly necessary, consent under 6.4.1 to 6.4.6 is still obtained before it is set, and the no-dark-patterns and no-cookie-wall commitments are absolute. This notice, the clause 5 tables and the change log are updated at the time of deployment, the change-log entry stating which limb was relied on; the provider is added to the Sub-processor List at the same time; and the deployment is limited to what the mandate or urgency demands and is reversed when it ends. We will not use this route to introduce advertising or cross-site tracking technology.
6.5 Consent-management platforms. No consent-management platform is in use today. If we adopt one, that provider will itself be listed in clause 5 and in the Sub-processor List before it is deployed.
6.6 The Console is not exempt — and what falls outside clause 6.4. Clause 6.4 applies to the Console and the Staff App as it applies to the marketing site: telemetry that stores data on an Authorised User's device engages it, and "it is an internal tool" is not a basis. Two boundaries make the clause workable: (a) cookieless measurement storing nothing on the device is outside clause 6.4 and is governed by clause 6.3.4 and clause 5 disclosure; and (b) where the Studio authorises device-storing telemetry for its own staff, that processing is disclosed to the Authorised User and to the Studio and dealt with under the controllership position at clause 1.6, rather than by asking a staff member for a consent they are not free to refuse. Where neither applies, the technology is not deployed.
7. How to object, refuse and control
7.1 On the marketing site. The marketing site stores nothing of its own on your device to remove (see clause 3.1 for the two qualifications, both of which concern cookies set by the Console or the hosting platform rather than by the site). If you do not wish the site's usage measurement to run, you have three routes:
7.1.1 the browser signal — where your browser offers a "Do Not Track" setting, enable it; our configuration instructs the provider's library to respect it and, as verified on the verification date, no events are then sent. Not every browser offers this: Safari removed its Do Not Track control in 2019 and does not send the signal, so this route is unavailable on Safari;
7.1.2 blocking the request — because nothing is stored on your device, blocking the analytics request with your browser's own controls or an extension has the same practical effect as a signal we honour, on every browser; and
7.1.3 writing to us — you may object in writing using the details in clause 12, and we will confirm what we have done within 5 working days. One real limitation: because we do not identify visitors and store nothing on your device, we cannot apply a persistent server-side suppression to you without identifying you, which we will not do; a written objection is therefore actioned through 7.1.1 and 7.1.2 and, where you tell us of an event we should not have received, by deleting it.
We do not currently claim to honour Global Privacy Control (clause 5.1.1). The site remains fully usable on any of these routes.
7.2 Browser controls generally. Every mainstream browser lets you view, block and delete cookies and clear site storage, usually under Settings → Privacy. Browser vendors publish their own instructions; we do not reproduce them here because they change. Two qualifications:
7.2.1 blocking or deleting the strictly necessary cookies in clause 5.2 will prevent you from signing in to the Console or the Staff App, or will sign you out unexpectedly. That is the direct consequence of what those cookies do, not a fault; and
7.2.2 clearing browser storage will reset the preferences in clause 5.3 — theme, language, dismissed prompts — and you will be asked again.
7.2.3 every choice recorded on this page is per browser and per device. A preference, a dismissed prompt, a refusal of notifications and (if one is ever introduced) a consent choice are stored in the browser you made them in. They do not follow you to another browser, another computer or phone, or into the native application shell, and they are deleted when you clear that browser's site data. If a choice appears "not to have stuck", this is almost always why. That is a consequence of respecting a refusal without identifying you.
7.3 Your session and your preferences are cleared by different actions. Signing out clears your session; the preferences in clause 5.3 are stored separately from it and are not cleared by signing out. Clearing site data for app.abstwin.com or staff.abstwin.com clears both — the session and the preferences together. There is no in-product control that resets the preferences on their own: to remove a single preference without signing out, you would have to delete that individual storage key through your browser's own site-data controls. The simpler route is to set the preference back the way you set it in the first place (clause 6.3.2), which overwrites it.
7.3A Service workers, the offline cache and notifications. The technologies in clause 5.3A are controlled separately from cookies:
7.3A.1 notifications — grant or revoke the notification permission for app.abstwin.com or staff.abstwin.com in your browser's site settings, or for the native application in your device's notification settings. Revoking it ends the push registration and the stored interests for the future. Declining or dismissing the prompt is recorded as a refusal and you are not asked again;
7.3A.2 the offline cache — the Staff App's cache is cleared when you sign out and when the app locks. You can also clear it yourself at any time by clearing site data for staff.abstwin.com; and
7.3A.3 the service worker — every mainstream browser allows a registered service worker to be unregistered, usually under Settings → Privacy → Site data, or through the browser's developer tools. Unregistering it stops push notifications and offline delivery for that browser; the Console and the Staff App otherwise continue to work normally.
7.4 Marketing preferences are separate from cookies. Your choice about receiving advertising and marketing messages by phone, email or social channels is a distinct right and is not controlled by cookie settings:
7.4.1 Guests. A Guest who receives messages from a Studio through ABS Twin may decline marketing at any time by replying to the conversation. The platform records that refusal against the Guest's record and applies it to campaigns sent through ABS Twin. The Studio is the Controller of that relationship and is responsible for honouring a Guest's objection, including in any communication it sends outside ABS Twin; the AI & Recording Disclosure and the Studio's own privacy notice explain it further;
7.4.2 Studios, applicants and prospective customers. You have the right to object at any time to our processing of your data for direct-marketing purposes, by channel — telephone, email or social. A self-service preference centre is not yet available, and there is no self-service unsubscribe route for waitlist and prospect email. Today the right is exercised by replying to any message you receive from us, or by writing to the address in clause 12; we will act on the objection and confirm within 5 working days;
7.4.3 The statutory register. For marketing telephone calls and SMS in the United Arab Emirates you may also register with the TDRA Do Not Contact Register, which applies across all businesses and not only ours.
7.5 Your data-protection rights. Rights of access, correction, erasure, restriction, portability, objection to direct marketing, and objection to decisions based on automated processing — including the right to ask for human review — are described, with the route to exercise them, in the Privacy Policy. Requests about a Guest's data held on behalf of a Studio are normally directed to that Studio as controller; the Privacy Policy explains how we handle a request that reaches us instead.
7.6 Complaints. You may complain to us using the contact details in clause 12. You may also complain to the UAE Data Office; where a Studio is established in, or its processing is subject to, the DIFC or ADGM regimes, the relevant office is the DIFC Commissioner of Data Protection or the ADGM Office of Data Protection respectively, and where another Applicable Data Protection Law applies, to the supervisory authority under that law. Separately from the data-protection route, a Studio or other consumer may complain to the UAE Ministry of Economy and Tourism (formerly the Ministry of Economy) or other competent authority under the consumer-protection and e-commerce legislation, including to any dispute-resolution committee formed under that legislation. Clause 12 lists these routes.
8. Analytics, described narrowly
8.1 Where it runs. Our analytics runs on the marketing site only. It is not loaded in the Console, in the Staff App, or in any native application shell.
8.2 What is measured. Page views and page-leave events; which sections of a page were scrolled into view; clicks on calls to action, recorded as a channel (call, WhatsApp, apply, sign-in, email, in-page anchor) and a placement (which section of the page the click came from); which FAQ items were opened; general click activity through the tool's automatic capture; and browser performance measurements such as page-load and layout stability.
8.3 What is not measured. No account is identified — there is no sign-in on the marketing site and no identification call exists in our code. No person profile is created. No session recording, heat map or survey feature is enabled. We do not send Customer Data or Guest Data to the analytics provider, and event properties are restricted to the structural values listed in clause 8.2 — so no names, phone numbers, bookings, conversation content, treatment records or Digital Twin profiles.
8.4 How that boundary is enforced. The separation described in clause 8.3 is enforced by an automated test in our source repository: the test suite fails, and the change cannot be merged, if the analytics library is referenced outside the marketing site.
8.5 Event property discipline. We restrict analytics event properties to the structural values listed in clause 8.2.
8.6 Provider, location and transfer. The provider is PostHog, Inc., engaged as our processor and listed in the Sub-processor List. The destination of the events, the basis on which they leave the United Arab Emirates and the open verifications on both are stated at clause 5.1.4, and the position for every provider in clause 5 at clause 5.6; they are not repeated here.
9. Things that are not cookies, but which you should know about
9.1 Server logs. Our hosting platform and our application record technical request data — including IP address, timestamp, requested path, response status and user-agent — for the purposes of delivering the service, diagnosing faults, and detecting and investigating abuse.
9.2 Rate limiting and abuse prevention. Public forms are rate-limited per IP address, and submissions pass a bot check before we accept them (clause 5.2 f). Short-lived technical records are held for this purpose.
9.3 Our audit log. Actions taken in the Console by Studio staff and by Carnelian administrators are recorded in an audit log which includes the actor, the action, the result and the actor's IP address. This exists for accountability and security, is described in the Privacy Policy, and is not affected by cookie settings.
9.4 Transactional email. We do not embed tracking pixels in our transactional email templates — application acknowledgements, escalation notices and support replies — and the account-level open-tracking and click-tracking settings at our email provider are inspected and stated here at the next technical verification.
9.5 The marketing site's one write — the early-access / waitlist list. The marketing site stores nothing on your device, but it does collect one thing on our servers if you choose to give it: if you submit the early-access or waitlist form, we record the email address you enter, together with the studio name you give, the source or campaign the visit came from, an approximate country derived from the request, your browser's user-agent string, and the date and time. We use it only to tell you when ABS Twin becomes available to you — the step you asked us to take (clause 6.3.6). It is not sold, not shared with advertisers, and not used to build a profile of you; any measurement of overall demand is done on aggregated figures from which no individual sign-up can be identified. The record is kept for 12 months from sign-up, or until you ask to be removed, whichever is earlier. You may ask us to delete it at any time using the details in clause 12, and we will do so on the terms in clause 1.8 (which apply to this request in the same way).
9.6 Who holds these records. The records described in this clause are held by the following providers, each of which is a Sub-processor listed in the Sub-processor List. The transfer statement at clause 5.6 applies to each of them in the same terms, and no adequacy is asserted for any of them.
| Record | Provider | Where it processes | Transfer instrument in force |
|---|---|---|---|
| Server logs (9.1) | Vercel Inc. (hosting) | United States primary, per the provider's published documentation, which reserves a general right to process globally | As clause 5.6 — the provider's published data-processing terms, subject to the note to that table |
| Rate-limiting and abuse records (9.2) | Upstash, Inc. | A globally replicated database served from the AWS region nearest the caller — the region varies with where the request originates and is not a single fixed country | As clause 5.6 — the provider's published data-processing terms, subject to the note to that table |
| Owner-audit log (9.3) | Formagrid, Inc. (dba Airtable) | United States | As clause 5.6 — the provider's published data-processing terms, subject to the note to that table |
| Transactional email (9.4) | Plus Five Five, Inc. (dba Resend) | Ireland (eu-west-1) — the region in which our sending domain is verified. The provider's own terms state the United States as its primary processing location, so message content may also be processed there | As clause 5.6 — the provider's published data-processing terms, subject to the note to that table |
| Early-access waitlist record (9.5) | Supabase, Inc. | European Union — Ireland (eu-west-1), the region of the project that holds this record, verified from the live database connection | As clause 5.6 — the provider's published data-processing terms, subject to the note to that table |
9.7 Retention of the records in this clause. The legal bases for these records are at clause 6.3.6 and the fuller description is in the Privacy Policy. On retention:
9.7.1 server logs and rate-limiting records are kept for the period recorded in our internal retention and deletion schedule, which is the document that sets it; that period is stated here in the revision that publishes the schedule, and a copy of the applicable period is given on request to the address in clause 12;
9.7.2 the owner-audit log is kept in two stages, following our internal retention schedule: the actor's identity and IP address are severed at 12 months, after which the surviving record of what was done is no longer identifying; and the action record itself is kept for 5 years. Accountability alone is not treated as a retention purpose of unlimited length: the length of the second stage is anchored to the statutory commercial-records duty;
9.7.3 the waitlist record is kept as stated at clause 9.5; and
9.7.4 analytics events are kept as stated at clause 5.1.5.
9.7.5 How every period in this notice is to be read. The periods stated in this notice and at clause 5.1.5 are the maximum periods for which we retain the record for the stated purpose. Deletion is performed on a periodic cycle, so a record may remain for a short period after its retention period ends, and a copy may persist in backups until the backup cycle completes; retained and backed-up records remain subject to the security measures described in the Privacy Policy. Where a law, a limitation period, a competent authority, or the establishment, exercise or defence of a legal claim requires longer retention, we retain the record for that period and for that purpose only.
9.7.6 These periods are commitments, and deletion is not yet automated. The periods above are the periods we commit to. Automated deletion and ageing jobs to enforce them are being built; until those jobs run, a record is deleted on request and on review rather than automatically. The internal schedule we keep as the evidence base for these periods is our internal retention and deletion schedule.
10. Scope limits, responsibilities and liability
10.1 This notice covers our surfaces only. As set out in clause 1.4, this notice covers abstwin.com, the Console and the Staff App. A Studio's own website, booking page, social presence and marketing technologies are the Studio's own responsibility.
10.2 No guarantee of another party's compliance. We do not represent, warrant or guarantee that any Studio's website, booking page or marketing technology, or any Platform Provider's application, complies with the Personal Data Protection Law, consumer-protection legislation, or any other law. Each Studio remains responsible for its own cookie notice, its own consent mechanism, and its own legal compliance, and the Master Subscription Agreement allocates that responsibility.
10.3 Savings clause. Nothing in this notice excludes or limits any liability, or any right or remedy of any person, which cannot lawfully be excluded or limited under applicable law. Any limitation, exclusion or disclaimer in this notice applies only to the fullest extent permitted by applicable law, and if any part of it is found to be unenforceable, it shall apply with the minimum modification necessary to make it enforceable, and the remainder shall be unaffected. This clause leads clauses 10.5 to 10.12 and prevails over each of them.
10.4 No conflict with mandatory rights. Nothing in this notice affects any right that a Guest, a consumer or any other individual has under mandatory provisions of UAE law, or under any Applicable Data Protection Law (as defined in the Privacy Policy — see clause 1.5).
10.5 Browser and device controls. The controls described in clause 7 are provided by browser and device vendors. We do not control them and do not warrant that they operate as their vendors describe.
10.6 Platform Providers. Where you interact with a Studio through WhatsApp, a telephone network or — once it becomes available, the channel being in testing and not yet offered — Instagram, the technologies that provider sets on your device, and its handling of your data, are governed by that provider's own terms and notices, over which Carnelian has no control.
10.7 Technologies provided by third parties. Several technologies disclosed in clause 5 are provided by third parties. Their characteristics — names, domain scope, lifetime, flags and internal behaviour — are determined by that provider and not by us, and may change at any time, including in a routine upgrade, without advance notice to us. We therefore state them as most recently verified by us on the verification date recorded under the clause 5 heading, and treat that as a control rather than an excuse: we re-verify on the cadence in clause 11.4, on every release that touches a surface in clause 1.3, and whenever a provider is upgraded or replaced.
10.7.1 A change, failure, suspension, throttling, deprecation or policy change by a provider named in clause 5 or by a Platform Provider is not a failure by us to meet a commitment in this notice; our obligation in those circumstances is the one stated in clause 11.2.
10.7.2 We do not warrant, and to the fullest extent permitted by applicable law we accept no liability for, a third party's own conduct, its own use of any technology it provides, or its compliance with any law — save that this does not affect our responsibility for choosing that provider, for engaging it under a written contract with data-protection obligations, and for listing it in the Sub-processor List. Nothing in this clause displaces our obligation as Controller under clause 1.6 in respect of the processing we determine.
10.8 The status of the clause 5 tables. The tables in clause 5 state the position as verified on the verification date recorded under the clause 5 heading. They are a disclosure, not a warranty, certification, audit opinion or compliance assessment, and this notice is not legal advice. It must not be adopted, republished or relied on by any other person as that person's own cookie notice, privacy notice or compliance assessment.
10.9 Types of loss for which we are not responsible. To the fullest extent permitted by applicable law, and subject always to clause 10.3, we are not responsible for the following types of loss arising out of or in connection with this notice or with any reliance placed on it, whether direct or indirect and whether or not foreseeable: loss of profit; loss of revenue; loss of anticipated savings; loss of business, contracts or opportunity; loss of goodwill or damage to reputation; loss of or corruption of data; wasted management or staff time; and the cost of obtaining substitute services. As between Carnelian and a Studio, any liability of Carnelian arising out of or in connection with this notice, or with any reliance placed on it, is in addition subject to the limitations and exclusions in clause 20 of the Master Subscription Agreement, which applies to this notice by clause 2.1.2A of that Agreement even though clause 2.1.2 of it does not incorporate this notice into it.
10.10 Who may rely on clauses 10.5 to 10.12. Those clauses are given for the benefit of Carnelian and, to the extent permitted by applicable law, its affiliates, its officers, its employees, its contractors and its Sub-processors, each of whom may rely on them. Save as stated in this clause, this notice does not confer any benefit or right of enforcement on any person, and we do not intend any provision of it to be enforceable by any third party.
10.11 Events outside our reasonable control. Subject always to clause 10.3, where an event outside our reasonable control — including an act, outage, suspension, policy change or unannounced change by a provider named in clause 5 or by a Platform Provider, a regulatory direction, or a security incident — prevents or delays performance of a commitment in clauses 1.8, 5.1.5, 6.4.6, 9.5, 9.7, 10.7 or 11.1 to 11.4, that commitment is suspended for so long as the event continues, we perform it as soon as reasonably practicable afterwards, and the change log records what happened.
10.12 Only the published documents state our position. Only the documents published at abstwin.com/legal state Carnelian's position on the technologies described in this notice. No employee, agent, reseller or introducer is authorised to give a different assurance, and none should be relied on.
11. Changes to this notice
11.1 Versioning and the authoritative text. Each published version of this notice carries a version number and an effective date. The version published at the canonical URL on the front of this document is the authoritative text; previous versions are kept in an accessible archive with their effective dates, and the content hash recorded in the footer identifies the published text. We do not silently edit a published version.
11.2 When we update. We split this by what we control:
11.2.1 where the change is ours — a cookie or similar technology added, removed or materially changed by us, or a provider we choose to change — we update this notice before the change takes effect on any surface listed in clause 1.3; and
11.2.2 where a provider changes the characteristics of its own technology without advance notice to us (clause 10.7), or where clause 6.4A applies, we update this notice as soon as reasonably practicable after we become aware of the change, and in any event at the next verification under clause 11.4, and the change log records the date on which we became aware.
11.3 How we tell you. A material change — in particular the introduction of any non-essential technology — is announced on the notice itself and, for Studios, notified by email to the Studio's registered contacts and, once an in-Console notice channel exists, there as well, in each case at least 30 days before it takes effect, or such shorter period as the change reasonably permits and in any event before the technology is deployed; and consent is collected afresh where clause 6.4 requires it. Non-material changes and corrections take effect on publication. Exception. Where a change falls within clause 6.4A, it takes effect on publication of the updated notice, with the same-day change-log entry required by clause 6.4A.3, and we notify Studios as soon as reasonably practicable and in any event within 7 days of the change taking effect. Where the technology is non-essential, consent is still obtained before it is set on your device.
11.4 Review cadence. This notice is reviewed at least every 12 months, and in any event on the issuance of the Executive Regulations to the Personal Data Protection Law, whichever is earlier.
12. Contact
| Publisher | Carnelian Technologies L.L.C-FZ, a Limited Liability Company licensed by Meydan Free Zone, trade licence 2415615.01, Dubai, United Arab Emirates |
| Correspondence address | Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. |
| General contact | info@contact.abstwin.com — the general and product contact address for ABS Twin. support@carnelian.tech, the company-level mailbox of Carnelian Technologies L.L.C-FZ, is an alternative route for every written route in this table. Inbound delivery on contact.abstwin.com was verified by test on 21 August 2026. The apex domain abstwin.com has no mailbox, so no bare @abstwin.com address is a contact route of ours |
| Privacy / data protection contact | privacy@contact.abstwin.com — it reaches the Data Protection Officer |
| Data Protection Officer | Syed Sharique Ali, Manager of Carnelian Technologies L.L.C-FZ, is the appointed Data Protection Officer, with effect from 21 August 2026. He is reached at dpo@contact.abstwin.com, at privacy@contact.abstwin.com for a request or complaint, or at support@carnelian.tech marked "for the attention of the Data Protection Officer". The PDPL gives a data subject the right to communicate with the officer directly, and that right is not filtered or refused: mail sent to any of those addresses reaches him. The UAE Data Office has not yet published the channel through which a Controller notifies its officer's contact details; the notification will be made as soon as that channel is published. |
| Legal notices | legal@contact.abstwin.com — a monitored mailbox — with a postal fallback to the correspondence address above. Clause 13.3 depends on this address |
| Telephone | +971 56 498 4007 — a staffed number answered by a person. No answering hours are published for it and none are to be inferred |
| Supervisory authority | UAE Data Office. For DIFC- or ADGM-established Studios: the DIFC Commissioner of Data Protection / the ADGM Office of Data Protection, as applicable. Where another Applicable Data Protection Law applies to you (clause 6.1A), the supervisory authority under that law. |
| Consumer complaints | The UAE Ministry of Economy and Tourism (formerly the Ministry of Economy) or other competent authority under the consumer-protection and e-commerce legislation, including any dispute-resolution committee formed under that legislation. Each authority publishes its own consumer-complaint channel from time to time; we give the current route on request, and we do not print one here until we have checked that it answers |
13. Governing law, forum and language
13.1 Governing law. This notice, and any non-contractual matter arising out of or in connection with it, is governed by the federal law of the United Arab Emirates as applicable in the Emirate of Dubai.
13.2 Forum. The courts of Dubai have non-exclusive jurisdiction over any dispute arising out of or in connection with this notice. This is without prejudice to any mandatory right of a consumer or other individual to bring proceedings in another competent forum where that right cannot lawfully be excluded, and without prejudice to any right to complain to the UAE Data Office or another competent supervisory authority. This clause is consistent with clause 19.2 of the Website Terms of Use, which governs your use of this page.
13.3 Pre-action step and notices. Before commencing proceedings, we ask that you notify us in writing at the electronic address for legal notices in clause 12, with a copy to the correspondence address in that clause, and allow 30 days for good-faith resolution. A notice sent to that electronic address is treated as received on transmission where it is sent within business hours on a Business Day, and otherwise at the start of business hours on the next Business Day — the rule in clause 26.3 of the Master Subscription Agreement, which governs and which this notice restates rather than varies. *(Business hours are 09:00–18:00 Gulf Standard Time on a Business Day; Business Day is the defined term imported at clause 1.5.)* Where the sender receives a delivery-failure message the notice is not treated as received, and notice may then be given at the correspondence address; a courier notice is received on the courier's record of delivery. This does not prevent either party from seeking urgent relief and does not affect any limitation period.
13.4 Not an arbitration agreement; no waiver of collective remedies. This notice contains no arbitration agreement and no waiver of any right to participate in collective proceedings.
13.5 Language — and a publication precondition. This notice is published in English and Arabic. To the fullest extent permitted by applicable law, the Arabic version prevails in the event of a conflict between the two texts. The Arabic version is prepared by a qualified legal translator and reviewed by UAE-licensed lawyers, not machine-translated, and is published at the same URL, reachable from the site footer, from the Privacy Policy and from the Console.
Version v0.9 · Effective date: on publication
Supersedes: the cookie notice published at abstwin.com/cookies, 11 August 2026.
Languages: English and Arabic; the Arabic version prevails (clause 13.5).
Publisher: Carnelian Technologies L.L.C-FZ, a Limited Liability Company licensed by Meydan Free Zone — trade licence 2415615.01 — Dubai, United Arab Emirates. Registered and correspondence address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Contact: info@contact.abstwin.com (general). Privacy and data protection: privacy@contact.abstwin.com. Legal notices: legal@contact.abstwin.com. Data Protection Officer: Syed Sharique Ali, Manager of Carnelian Technologies L.L.C-FZ, at dpo@contact.abstwin.com. support@carnelian.tech is the company mailbox and an alternative route to any of these.
Next review: on the cadence in clause 11.4, or on issuance of the Personal Data Protection Law Executive Regulations, whichever is earlier.