Last updated: [Insert Date] • Effective date: [Insert Date] • Owner: TwinSpan LLC
This Data Protection Policy sets out how TwinSpan LLC ("TwinSpan," "we," "us," or "our") collects, processes, stores, and protects personal data in the course of operating our digital twin platform and related services. It applies to all TwinSpan employees, contractors, and founding partners who handle personal data, and to all personal data processed through our website, platform, and client engagements, regardless of where that data is stored or processed.
Consistent with UAE Federal Decree-Law No. 45 of 2021 (the PDPL), TwinSpan commits to processing personal data in accordance with the following principles:
| Role | Responsibility |
|---|---|
| Data Controller | TwinSpan LLC — determines the purposes and means of processing personal data collected via our website and platform. |
| Data Processor (for Client Data) | TwinSpan LLC, acting on behalf of Clients under signed service agreements, when processing building/asset data that may incidentally contain personal information. |
| Data Protection Lead | [Insert: name of the individual internally responsible for data protection compliance — e.g., a founding partner, until/unless a formal Data Protection Officer is appointed as required by law] |
| All Staff & Contractors | Must handle personal data in accordance with this Policy and report suspected breaches immediately per Section 9. |
TwinSpan will appoint a formal Data Protection Officer if and when required to do so under the PDPL's executive regulations based on the scale or nature of our data processing.
| Category | Examples | Source |
|---|---|---|
| Contact & business data | Name, company, email, phone, job title | Provided directly via forms, email, calls |
| Website usage data | Pages visited, device/browser type, approximate location | Collected automatically via cookies/analytics |
| Client building/asset data | 3D scans, BIM models, sensor readings, maintenance logs | Captured during service delivery; may incidentally include personal data (e.g., a technician's name in a log) |
| Employee/contractor data | [Insert: HR data categories if applicable] | Provided during onboarding |
| Processing Activity | Lawful Basis |
|---|---|
| Responding to demo/pricing requests | Steps taken at the data subject's request prior to entering an agreement |
| Delivering contracted services to Clients | Performance of a contract |
| Website analytics | Consent (via cookie banner) or legitimate interest, as applicable |
| Marketing communications | Consent, or legitimate interest with opt-out, as applicable under PDPL |
| Compliance with legal/regulatory requests | Legal obligation |
This register should be reviewed and updated as TwinSpan's processing activities evolve.
Any individual may submit a request to exercise their rights under the PDPL (access, correction, deletion, restriction, objection, or data portability) by contacting us using the details in Section 16. Upon receipt, TwinSpan will:
Where TwinSpan engages third-party service providers who process personal data on our behalf (e.g., cloud hosting, email delivery, CRM tools), we will use commercially reasonable efforts to ensure such providers are bound by written data processing terms requiring them to: process data only on our documented instructions; implement appropriate security measures; and assist with data subject requests and breach notifications as needed. [Insert: list of current key vendors/sub-processors once finalized, e.g., cloud hosting provider, email service provider.]
Where personal data is transferred outside the UAE (for example, to a cloud hosting region located abroad), TwinSpan will take steps intended to ensure an adequate level of protection consistent with the PDPL, which may include contractual safeguards with the receiving party, and will document the transfer mechanism relied upon. [Insert specific transfer mechanisms/regions once your infrastructure provider and hosting regions are finalized.]
In the event of a suspected or confirmed personal data breach, TwinSpan will:
All staff and contractors must report a suspected breach immediately to [Insert: internal escalation contact/email] upon discovery — do not wait for confirmation before reporting.
Before launching a new product feature, platform integration, or data processing activity that could pose a significant risk to individuals' privacy (for example, new AI-driven analytics on personal data, or a new category of data collection), TwinSpan will conduct a Data Protection Impact Assessment (DPIA) to identify and mitigate risks before processing begins.
TwinSpan will maintain a Record of Processing Activities (ROPA) documenting, at minimum: the categories of data processed, the purposes of processing, categories of recipients, retention periods, and security measures in place — consistent with accountability obligations under the PDPL. This record should be reviewed and updated at least [Insert: e.g., annually].
All TwinSpan staff and contractors with access to personal data or client building data will be made aware of their data protection obligations under this Policy and are bound by confidentiality obligations under their engagement terms. [Insert: details of any formal training program once established.]
| Data Category | Retention Period |
|---|---|
| Prospect/lead contact data (no engagement) | [Insert: e.g., 24 months from last contact] |
| Active client contact & account data | Duration of the service agreement |
| Client building/asset data | Duration of the service agreement, plus [Insert period] thereafter unless otherwise agreed |
| Financial/invoicing records | [Insert: e.g., 7 years, per UAE accounting/tax record-keeping requirements] |
| Website analytics data | [Insert period, e.g., 14–26 months, consistent with analytics tool defaults] |
This Policy is an internal governance document. To the maximum extent permitted by applicable law, nothing in this Policy creates rights enforceable by third parties beyond those already granted under the PDPL, the Privacy Policy, or a signed client agreement. TwinSpan's liability in connection with data protection matters toward Clients and data subjects is governed by the limitation of liability provisions in the Terms of Service and applicable law, and nothing in this Policy expands that liability.
This Policy will be reviewed at least [Insert: e.g., annually], and whenever there is a material change to TwinSpan's data processing activities, applicable law, or following any significant data protection incident.
Questions about this Policy, or to report a suspected data protection issue, should be directed to: