Privacy Policy
Last updated 27 August 2026.
Summary
We collect very little. This website sets no cookies of its own, runs no advertising or analytics trackers that profile you across sites, and does not sell personal data to anyone, ever.
The only personal information we routinely collect is what you type into the contact form, and we use it to answer you.
Our free tools process everything inside your browser. Text you paste into them is never transmitted to us or to anyone else.
Who we are and how to reach us
Twinsoft Innovations FZE is a company licensed by the Sharjah Publishing City Free Zone Authority in the United Arab Emirates, with its registered office at Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Our trade licence number is provided on request and appears in every client contract.
We are the data controller for personal information collected through this website. For any privacy question, request or complaint, write to hello@twinsoftinnovations.com and mark it for the attention of the privacy contact. We answer within 30 days.
What we collect
Contact enquiries: your name, company, email address, the service and budget range you select, and the message you write. Providing a company name is optional.
Server logs: our hosting provider records IP addresses, timestamps, requested URLs and user-agent strings as a normal part of serving a website. These are used for security and troubleshooting and are retained for a short period by the provider.
Anti-spam: the contact form uses Cloudflare Turnstile to distinguish people from bots. Turnstile is designed to work without profiling visitors or tracking them across sites. It receives technical signals from your browser to make that assessment.
Free tools: nothing. Text entered into the array converter or JSON formatter is processed by JavaScript in your browser and never leaves your device. You can confirm this by disconnecting from the network — the tools continue to work.
We do not knowingly collect data from children, and this site is not directed at them.
Why we process it, and on what legal basis
To answer your enquiry and, where relevant, prepare a proposal. Under the GDPR this is your consent, given when you tick the consent box and submit the form, and our legitimate interest in responding to business enquiries. Where we go on to work together, processing is necessary to perform our contract with you.
To keep the website secure and available. This is our legitimate interest in preventing abuse, spam and attacks.
To meet legal obligations, including UAE commercial, tax and anti-money-laundering record-keeping requirements where an engagement proceeds.
How long we keep it
Enquiries that do not lead to a project are deleted within 24 months.
Where we enter into a contract, records are kept for the period required by UAE commercial and tax law, which is currently five years from the end of the relevant financial period, and then deleted.
Server logs are retained by our hosting provider for a short period, typically no more than 30 days.
Backups are rotated on a defined schedule, so data deleted from live systems is removed from backups within that cycle rather than persisting indefinitely.
Who else sees it
We do not sell, rent or trade personal data. We share it only with the service providers necessary to run the business, each acting on our instructions under a data processing agreement: our form-handling provider, our email provider, our hosting and content delivery provider, and Cloudflare for bot protection.
We may disclose information where we are legally required to, or to establish, exercise or defend legal claims.
Client project data is separately covered by the confidentiality terms of the relevant engagement and by any non-disclosure agreement in place.
International transfers
We are based in the United Arab Emirates and our providers may process data in other countries, including within the European Economic Area and the United States.
Where personal data of individuals in the EEA or the United Kingdom is transferred outside those areas, we rely on the appropriate safeguards permitted under Article 46 of the GDPR, principally the European Commission's Standard Contractual Clauses, incorporated into our agreements with those providers.
Where personal data is transferred outside the United Arab Emirates, we do so in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing provisions.
Your rights
Wherever you are, you may ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to delete it, ask us to restrict how we use it, object to our processing, or ask for it in a portable machine-readable format. Where we rely on consent, you may withdraw it at any time; that does not affect processing carried out beforehand.
If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR and UK GDPR, and you have the right to complain to your national supervisory authority.
If you are in the United Arab Emirates, these rights arise under Federal Decree-Law No. 45 of 2021, and you may complain to the UAE Data Office.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request deletion or correction, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights. Residents of other US states with comparable privacy laws have equivalent rights and may exercise them the same way.
To exercise any right, email hello@twinsoftinnovations.com. We may ask you to confirm your identity so that we do not disclose your data to someone else. There is no charge, and we respond within 30 days.
Cookies and similar technologies
This website sets no cookies of its own. There is no analytics tracker, no advertising pixel, and no cross-site profiling.
Cloudflare Turnstile may set a short-lived token in connection with the anti-bot check on the contact form. It is strictly necessary for that security function and is not used to track you.
If we ever introduce analytics or advertising, we will update this policy and, where the law requires it, ask for your consent before anything non-essential is set.
Security
The site is served over HTTPS with HTTP Strict Transport Security, a strict Content-Security-Policy and a set of hardening headers. It is a static site with no database and no server-side application code, which removes most classes of attack.
Access to enquiry data is limited to those who need it. Client credentials are held in encrypted storage and never in source control.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, notify the UAE Data Office as required under UAE law, and inform you directly without undue delay where the risk to you is high.
Changes to this policy
We will update this page if our practices change and revise the date shown above. Material changes affecting existing clients will be communicated directly rather than left to be discovered.