Account & data deletion
Who this page is for
You have an ABS Twin staff account. You sign in to the Staff App, or you did. Your account was created by your studio, not by you. If you still have the app, the fastest route is inside it: open the Me screen, scroll to the bottom, and tap "Delete my account" — it deletes the account there and then, after showing you what goes and what stays. This page is for making the same request without the app, or for any other request about your data.
You use the ABS Twin Console for a studio — owner, manager or reception. Your login, sessions and devices are held by us, and you can ask us about them here.
You are a guest of a studio — you messaged, called or booked with a salon, spa or clinic that uses ABS Twin. Your booking, your conversation and your customer record belong to that studio, not to us. See "If you are a guest of a studio" below.
Anyone may also use this page for a request that is not a deletion: a copy of your data, a correction, erasure of one item without closing your account, restriction, objection, a portable copy of what you gave us, or a person to review something decided automatically. Exercising any of these rights is free, and it is never conditional on a studio's invoice being paid.
How to make a request
Email privacy@contact.abstwin.com — or write to us at the address in the Legal Notice, marked for the attention of the Data Protection Officer.
Why that address. It is our data-protection mailbox and it reaches our Data Protection Officer. We tested it before printing it here, because an address that quietly swallows your request would be worse than no address at all. If an abstwin address is not available to you, support@carnelian.tech reaches us too.
Who reads it. Our Data Protection Officer is Syed Sharique Ali, a Manager of Carnelian Technologies L.L.C-FZ, appointed with effect from 21 August 2026. You may write to the officer directly at dpo@contact.abstwin.com, and you do not need to go through your studio, or anyone else, to do it. Both addresses are company mailboxes rather than personal ones; a message for the officer is passed to the officer on the day it is recognised, and it is not left sitting in an inbox. One thing we would rather tell you plainly: we have not yet notified the officer's contact details to the UAE Data Office, which the law requires and which we are doing.
The in-app route exists and is the fastest: in the Staff App, open the Me screen, scroll to the bottom, and tap Delete my account. It performs the deletion immediately, after one confirmation step — no email needed, no waiting. An earlier version of this page said that control was being built; it is built, and this page now says so.
This page itself carries no form. The route from here is the email above — we say that plainly rather than describe a button that is not there. And a third route also works: ask your studio owner or manager, who can remove your access in the Console immediately and can also delete the login identity.
Tell us, in your own words:
- what you want — deletion of your account, a copy, a correction, or something else;
- the work email address on the account, if this is about a staff or Console login;
- if it is about a studio's records, which studio, and the phone number, Instagram account or email the studio holds for you;
- how to reach you if that is different.
You do not need to use legal language, cite a law, fill in a form, or write in English or Arabic. "Delete my number" is a request.
How we check it is you
A deletion request from the wrong person is itself a security incident, so we verify before we act — and we verify proportionately. We ask for the least that will do the job, we do not use it for anything else, and over-asking is its own failure.
- Account requests: we send a confirmation link to the work email address on the account. If you have lost access to that mailbox, tell us, and we will ask your studio to confirm instead. A request made from inside the app while you are signed in needs nothing further.
- WhatsApp: control of the phone number on the record, shown in the thread.
- Instagram: verification inside the same Instagram thread, plus one detail already on the record that a stranger would not know. We will never ask an Instagram user for a phone number — the platform does not give us one, and a record made that way has none.
- By phone: caller ID alone is never enough. We will ask for a non-guessable detail, or move the request to writing.
- By email: control of the address on the record, plus one non-guessable detail.
A non-guessable detail means something like the approximate date of a past visit or the service last booked. It never means a full card number, a government ID number or a password. We ask for a government-issued identity document only where nothing less will verify you, we never attach it to your record, and we destroy it as soon as the check is done.
If we cannot verify you, we do not refuse you: we close the request as unverified, tell you exactly what was missing, and reopen it the moment you supply it.
What happens next, and how long it takes
- We acknowledge within 5 business days and give you a reference you can quote.
- We may take up to 10 business days to verify who you are.
- We give a substantive response within 30 calendar days of verifying you.
- Where a request is genuinely complex we may take one further 30 calendar days, and we tell you why before the first period runs out, not after.
- A deletion requested by email is completed within 30 days of verification, and we email you when it is done. A deletion made inside the app does not use this timetable at all: it is performed immediately, and the app confirms on screen while you watch.
- An objection to marketing is acted on when it arrives, before verification finishes.
About those numbers. They are our own service commitment, not a statutory deadline. The UAE Personal Data Protection Law is in force, but the Executive Regulations that will set response periods have not been issued, and we will not quote you a deadline that does not exist. Where another country's data-protection law applies to your request and sets a period, that period governs and we apply it. When the Regulations are issued, we apply whatever they require — including to a request that is still open.
Some data is carved out of that law and governed by another regime — health data under the UAE health-information legislation, and banking and credit data. If your request touches it, we will tell you which regime we consider applies and why.
What deleting a staff account removes — and what it does not
We delete: your login identity and credentials at our authentication provider — your sessions and signed-in devices cannot survive it — and the record that linked that login to your staff profile: your access status, your app role, and your invitation and activation dates. Notifications stop in two ways at once: your device clears its own notification subscriptions as you are signed out — a best-effort tidy-up — and, the actual guarantee, our servers refuse to send anything addressed to you from the moment your access ends. The push provider's own device registration is not something we delete; it simply never receives anything again, and it ages out on that provider's schedule.
We do not delete your studio's records. Its bookings, its client records, its roster and leave history, and its employment record about you belong to the studio. Deleting your login does not touch them, and it never did. If you want those changed or erased, ask your studio — we will help the studio act on it.
Some of our own records survive a deletion request. There are five grounds and no others: a law requires it, including tax and commercial record-keeping; it is needed to establish, exercise or defend a legal claim, or a dispute is live; a court, a regulator or a lawful hold requires it; it is still being used for security and fraud prevention, and for nothing else; or an incident investigation is open, during which deletion is suspended so evidence is not destroyed. Anything kept on one of those grounds is used only for that ground and is deleted when the ground ends. The record of what an account did — who changed what, and when — is one of these, and it survives the login.
Suspending access is not deletion, and we do not present it as such.
While a deletion is running. A deletion made inside the app has no waiting period — it completes immediately, and only the provider tails below follow it. A deletion requested by email takes days, so five rules govern the window, and they are the same five rules, in the same terms, as clause 12.5A of the Staff App Privacy Notice:
- Your access ends when the request is verified, not when the deletion finishes. A request made from inside the app is verified by the fact that you are signed in — there is nothing further to check, and nothing further to wait for. Rules 2 and 4, which are about the confirmation email, apply to the email route only.
- Signing in does not cancel your request. If you change your mind, cancel it — reply to our acknowledgement, or tell us at the addresses above.
- If your studio re-invites you during the window, the request still stands. We complete the deletion of the old account and the invitation creates a new one, with a new login identity. You and your studio are both told — the one exception to rule 5's no-notice position, and it says only what this rule says.
- If the confirmation email bounces, or is never confirmed, we do not act. We try the address once more, we can ask your studio to confirm instead if you have lost the mailbox, and if nothing is confirmed within 30 days we close the request without deleting anything and tell you at the address we have.
- Your studio cannot veto the deletion of your login. It does not need to — every record it controls stays either way. And we do not send your studio a notice about your deletion: from the moment your access ends, its Console simply shows your account's app access as "No access". No reason, no content, no copy of anything you said.
Our authentication provider runs its own deletion tail after ours: it deletes its copy within 90 days of account termination, per its published terms. Copies inside encrypted backups disappear as those backups age out.
If you are a guest of a studio
The studio decides, and we are the software it runs. When a guest's request reaches us we acknowledge it, pass it to the studio without undue delay, and help the studio answer it — but we do not act on it on your instruction alone, because the record is not ours to decide about. We will tell you that this is what we have done. If you cannot reach the studio, write to us anyway and we will route it.
There is no self-service export or deletion screen for a guest record today. A copy or an erasure is produced by hand, by a named person here, on the studio's instruction. We say so rather than describe a control we have not built.
Withdrawing consent is not the same as deletion
If you gave permission for something and take it back, that is a withdrawal of consent. It must be as easy to take back as it was to give, you do not have to give a reason, it works from now on rather than backwards, and it stops what rested on that permission — while processing that rests on a different ground may lawfully continue. We will tell you which is which if you ask.
If you are not satisfied
Tell us first — we would rather fix it. You may also complain to the competent UAE data-protection authority, the UAE Data Office, at any time. We will publish its complaint route here once we have confirmed it is operational, and we give what we have on request in the meantime — we would rather do that than print a route we have not checked answers.
Nothing on this page reduces a right you have under the law. Where this page and a right conflict, the right prevails.
More detail: Privacy Policy · Staff App Privacy Notice · AI & Recording Disclosure · Sub-processor List · Legal Notice
Publisher: Carnelian Technologies L.L.C-FZ, a Limited Liability Company licensed by the Meydan Free Zone, Dubai, United Arab Emirates. Trade licence 2415615.01, valid to 25 January 2027. Registered and correspondence address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Contact: privacy@contact.abstwin.com for privacy, data requests and complaints · legal@contact.abstwin.com for legal notices · info@contact.abstwin.com for anything else · support@carnelian.tech reaches us too · +971 56 498 4007.
Languages: English, and Arabic from the date its legally reviewed Arabic text is published.