Legal

Data Protection Policy

Last updated: [Insert Date]  •  Effective date: [Insert Date]  •  Owner: TwinSpan LLC

⚠ Template Notice — Read Before Publishing or Adopting Internally This is a professionally structured starting template, not a finished, legally reviewed governance document. Claude is not a lawyer, and this is not legal advice. Before adopting this policy internally or publishing it, have it reviewed by a lawyer qualified in UAE data protection law to confirm it accurately reflects TwinSpan LLC's actual data processing activities, appoints a real Data Protection Officer or responsible individual if one is required, and satisfies UAE Federal Decree-Law No. 45 of 2021 (the Personal Data Protection Law, "PDPL") and its executive regulations, plus any DIFC Data Protection Law (if TwinSpan processes data through a DIFC entity) or other applicable regime. Bracketed placeholders must be completed with real, accurate information — do not publish this with placeholders still in place.
How this document relates to the Privacy Policy: The Privacy Policy is the public-facing notice explaining to website visitors and clients what data we collect and why. This Data Protection Policy is the more detailed internal governance framework describing how TwinSpan LLC implements those commitments day to day — our data protection principles, roles and responsibilities, breach response procedure, and processing records. Where the two documents differ, the Privacy Policy governs your rights as a data subject; this Policy governs our internal practices.

Contents

  1. 1. Purpose & Scope
  2. 2. Data Protection Principles
  3. 3. Roles & Responsibilities
  4. 4. Categories of Data Processed
  5. 5. Lawful Basis Register
  6. 6. Data Subject Rights Procedure
  7. 7. Third-Party Processors & Vendors
  8. 8. Cross-Border Transfers
  9. 9. Data Breach Response
  10. 10. Data Protection Impact Assessments
  11. 11. Records of Processing Activities
  12. 12. Staff Training & Confidentiality
  13. 13. Retention Schedule
  14. 14. Liability & Enforcement
  15. 15. Policy Review
  16. 16. Contact & Escalation

1. Purpose & Scope

This Data Protection Policy sets out how TwinSpan LLC ("TwinSpan," "we," "us," or "our") collects, processes, stores, and protects personal data in the course of operating our digital twin platform and related services. It applies to all TwinSpan employees, contractors, and founding partners who handle personal data, and to all personal data processed through our website, platform, and client engagements, regardless of where that data is stored or processed.

2. Data Protection Principles

Consistent with UAE Federal Decree-Law No. 45 of 2021 (the PDPL), TwinSpan commits to processing personal data in accordance with the following principles:

3. Roles & Responsibilities

RoleResponsibility
Data ControllerTwinSpan LLC — determines the purposes and means of processing personal data collected via our website and platform.
Data Processor (for Client Data)TwinSpan LLC, acting on behalf of Clients under signed service agreements, when processing building/asset data that may incidentally contain personal information.
Data Protection Lead[Insert: name of the individual internally responsible for data protection compliance — e.g., a founding partner, until/unless a formal Data Protection Officer is appointed as required by law]
All Staff & ContractorsMust handle personal data in accordance with this Policy and report suspected breaches immediately per Section 9.

TwinSpan will appoint a formal Data Protection Officer if and when required to do so under the PDPL's executive regulations based on the scale or nature of our data processing.

4. Categories of Data Processed

CategoryExamplesSource
Contact & business dataName, company, email, phone, job titleProvided directly via forms, email, calls
Website usage dataPages visited, device/browser type, approximate locationCollected automatically via cookies/analytics
Client building/asset data3D scans, BIM models, sensor readings, maintenance logsCaptured during service delivery; may incidentally include personal data (e.g., a technician's name in a log)
Employee/contractor data[Insert: HR data categories if applicable]Provided during onboarding

5. Lawful Basis Register

Processing ActivityLawful Basis
Responding to demo/pricing requestsSteps taken at the data subject's request prior to entering an agreement
Delivering contracted services to ClientsPerformance of a contract
Website analyticsConsent (via cookie banner) or legitimate interest, as applicable
Marketing communicationsConsent, or legitimate interest with opt-out, as applicable under PDPL
Compliance with legal/regulatory requestsLegal obligation

This register should be reviewed and updated as TwinSpan's processing activities evolve.

6. Data Subject Rights Procedure

Any individual may submit a request to exercise their rights under the PDPL (access, correction, deletion, restriction, objection, or data portability) by contacting us using the details in Section 16. Upon receipt, TwinSpan will:

  1. Acknowledge the request within [Insert: e.g., 5 business days].
  2. Verify the requester's identity before taking action.
  3. Respond substantively within [Insert: e.g., 30 days, or the timeframe required under applicable law], or explain any extension needed.
  4. Document the request and TwinSpan's response for internal accountability records.

7. Third-Party Processors & Vendors

Where TwinSpan engages third-party service providers who process personal data on our behalf (e.g., cloud hosting, email delivery, CRM tools), we will use commercially reasonable efforts to ensure such providers are bound by written data processing terms requiring them to: process data only on our documented instructions; implement appropriate security measures; and assist with data subject requests and breach notifications as needed. [Insert: list of current key vendors/sub-processors once finalized, e.g., cloud hosting provider, email service provider.]

8. Cross-Border Transfers

Where personal data is transferred outside the UAE (for example, to a cloud hosting region located abroad), TwinSpan will take steps intended to ensure an adequate level of protection consistent with the PDPL, which may include contractual safeguards with the receiving party, and will document the transfer mechanism relied upon. [Insert specific transfer mechanisms/regions once your infrastructure provider and hosting regions are finalized.]

9. Data Breach Response

In the event of a suspected or confirmed personal data breach, TwinSpan will:

  1. Contain and assess the breach as soon as reasonably possible upon discovery.
  2. Determine whether the breach poses a risk to the rights and freedoms of affected individuals.
  3. Where required under the PDPL, notify the UAE Data Office (or applicable regulator) without undue delay.
  4. Where the breach is likely to result in a high risk to affected individuals, notify those individuals directly, describing the nature of the breach and recommended protective steps.
  5. Document the breach, its impact, and remedial actions taken, regardless of whether notification was required.

All staff and contractors must report a suspected breach immediately to [Insert: internal escalation contact/email] upon discovery — do not wait for confirmation before reporting.

10. Data Protection Impact Assessments

Before launching a new product feature, platform integration, or data processing activity that could pose a significant risk to individuals' privacy (for example, new AI-driven analytics on personal data, or a new category of data collection), TwinSpan will conduct a Data Protection Impact Assessment (DPIA) to identify and mitigate risks before processing begins.

11. Records of Processing Activities

TwinSpan will maintain a Record of Processing Activities (ROPA) documenting, at minimum: the categories of data processed, the purposes of processing, categories of recipients, retention periods, and security measures in place — consistent with accountability obligations under the PDPL. This record should be reviewed and updated at least [Insert: e.g., annually].

12. Staff Training & Confidentiality

All TwinSpan staff and contractors with access to personal data or client building data will be made aware of their data protection obligations under this Policy and are bound by confidentiality obligations under their engagement terms. [Insert: details of any formal training program once established.]

13. Retention Schedule

Data CategoryRetention Period
Prospect/lead contact data (no engagement)[Insert: e.g., 24 months from last contact]
Active client contact & account dataDuration of the service agreement
Client building/asset dataDuration of the service agreement, plus [Insert period] thereafter unless otherwise agreed
Financial/invoicing records[Insert: e.g., 7 years, per UAE accounting/tax record-keeping requirements]
Website analytics data[Insert period, e.g., 14–26 months, consistent with analytics tool defaults]

14. Liability & Enforcement

This Policy is an internal governance document. To the maximum extent permitted by applicable law, nothing in this Policy creates rights enforceable by third parties beyond those already granted under the PDPL, the Privacy Policy, or a signed client agreement. TwinSpan's liability in connection with data protection matters toward Clients and data subjects is governed by the limitation of liability provisions in the Terms of Service and applicable law, and nothing in this Policy expands that liability.

15. Policy Review

This Policy will be reviewed at least [Insert: e.g., annually], and whenever there is a material change to TwinSpan's data processing activities, applicable law, or following any significant data protection incident.

16. Contact & Escalation

Questions about this Policy, or to report a suspected data protection issue, should be directed to: