Hokma IQ

Privacy Policy

1. Our Obligation

This policy explains how Hokma IQ collects, uses, and protects personal data. It applies to clients, prospective clients, company representatives, shareholders, service providers, and other parties who interact with us or our services.

Hokma IQ is committed to handling personal data responsibly and in accordance with the ADGM Data Protection Regulations 2021.

2. Who We Are

Hokma IQ is an Abu Dhabi Global Market (ADGM) entity authorised and regulated by the Financial Services Regulatory Authority (FSRA) as a Category 3C financial services firm.

We act as the Data Controller for personal data processed in connection with our business and regulated activities.

For any privacy-related queries, please contact us at:

3. Information We Collect

We may collect the following types of personal data:

  • Identity information: name, passport or ID number, date of birth
  • Contact details: address, email address, telephone number
  • Financial information: account details, assets, income, and investment history
  • Investor profile, investment objectives, and relevant suitability information
  • Communications: emails, call recordings, meeting records, and written correspondence
  • Compliance and regulatory documents: KYC, AML, sanctions screening, and source of funds or source of wealth documentation
  • Information required to meet our regulatory and contractual obligations

We collect data directly from you, from your authorised representatives, and where necessary from third parties such as banks, regulators, financial institutions, professional advisers, and service providers.

4. Why We Collect Your Data

We collect and use personal data to:

  • Establish and manage client and investor relationships
  • Provide investment management and related financial services within the scope of our FSRA permissions
  • Manage investment, operational, and regulatory activities
  • Meet legal and regulatory obligations including AML, KYC, sanctions screening, and FSRA requirements
  • Conduct client and investor due diligence
  • Assess risk and, where applicable, investment suitability
  • Prevent fraud, money laundering, terrorist financing, and other financial crime
  • Communicate with clients, investors, counterparties, and other stakeholders
  • Operate and improve our business, systems, and services

We only collect information that is reasonably necessary for these purposes.

5. Legal Basis for Processing

We process personal data under the following legal bases as set out in the ADGM Data Protection Regulations 2021:

  • Legal obligation: where processing is required to comply with applicable laws, regulations, or FSRA requirements.
  • Contractual necessity: where processing is needed to enter into or perform an agreement with you.
  • Legitimate interests: where processing supports our legitimate business, operational, security, compliance, or risk-management interests without overriding your rights.
  • Consent: where you have specifically agreed to the use of your data for a particular purpose. You may withdraw consent at any time, where consent is the applicable legal basis.

6. Profiling and Decision Making

We may assess client or investor risk, financial circumstances, investment objectives, and other relevant information as part of delivering regulated financial services and meeting our regulatory obligations.

We may also use technology, analytical tools, and proprietary systems to support investment research, risk analysis, compliance, and operational decision-making.

Material decisions affecting clients or investors are subject to appropriate human oversight and are not made solely by automated systems where applicable law or regulation requires human involvement.

7. Who We Share Data With

We may share personal data with trusted third parties where necessary and lawful, including:

  • The FSRA, ADGM authorities, and other regulatory or government authorities
  • Banks, custodians, brokers, counterparties, and financial institutions
  • Fund administrators and other investment-related service providers, where applicable
  • IT, cloud, cybersecurity, and infrastructure providers
  • External auditors, accountants, legal advisers, and professional advisers
  • Compliance, risk, AML, and regulatory consultants
  • Other service providers supporting our regulated and operational activities

Data is only shared where there is an appropriate legal basis, including compliance with legal or regulatory obligations, performance of contractual services, legitimate business interests, or the prevention of financial crime.

We do not sell personal data to third parties.

8. International Transfers

In certain circumstances, personal data may be transferred outside the ADGM, including to service providers, financial institutions, counterparties, advisers, or technology providers located in other jurisdictions.

Where such transfers occur, we take appropriate measures to ensure that personal data is protected in accordance with the ADGM Data Protection Regulations 2021, including the use of appropriate contractual, organisational, and technical safeguards.

9. How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to meet applicable legal, regulatory, contractual, and business requirements.

Certain records may be retained for prescribed periods in accordance with FSRA requirements, AML obligations, and other applicable laws and regulations.

Once data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in accordance with our data retention policies.

10. How We Protect Your Data

We take the security of personal data seriously. Our measures include:

  • Restricted and role-based access to systems holding personal data
  • Secure data storage within our Microsoft 365 environment and other approved systems
  • Appropriate authentication and access controls
  • Confidentiality obligations for employees, directors, contractors, and relevant service providers
  • Regular review of access permissions and data-handling practices
  • Technical and organisational measures designed to protect information against unauthorised access, loss, alteration, or disclosure

11. Third-Party Websites

Our website may contain links to external sites. Hokma IQ is not responsible for the privacy practices, security, or content of those sites.

We recommend reviewing the privacy policy of any third-party website you visit.

12. Your Rights

Under the ADGM Data Protection Regulations 2021, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate or incomplete personal data
  • Request deletion of personal data in certain circumstances
  • Object to or restrict certain processing of your personal data
  • Request information concerning how your personal data is processed
  • Withdraw consent where processing is based on consent

To exercise any of these rights, please contact us at contactus@hokma.ae.

You also have the right to raise a concern with the ADGM Commissioner of Data Protection:

  • Phone: +971 2 333 8888
  • Email: Data.Protection@adgm.com
  • Address: ADGM Building, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, UAE

13. Policy Updates

We may update this policy from time to time to reflect changes in our business, regulatory obligations, technology, or applicable law.