top of page

Privacy Policy

PATRIMIUM ASSET MANAGEMENT LIMITED

Privacy Policy

Effective Date: 1 August 2026

Last Reviewed: July 2026

1. Who We Are

Patrimium Asset Management Limited ("Patrimium", "we", "us", "our") is a company incorporated in the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates, and is authorised and regulated by the Dubai Financial Services Authority (DFSA). DFSA Firm Reference Number: F011669. Registered Address: Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE. 

 

Data Protection Contact: patrimium.compliance@patrimiummfo.com, +971 50 633 6186.

As a Controller of personal data under the DIFC Data Protection Law No. 5 of 2020 ("DPL"), Patrimium is responsible for ensuring that personal data we hold about you is processed lawfully, fairly, transparently, and securely. This Privacy Policy explains what personal data we collect, how and why we use it, with whom we share it, how long we retain it, your rights as a data subject, and how to contact us.

This Policy should be read alongside our AI Transparency and Responsible Use Notice, which provides further detail on how personal data may be processed through AI Systems used by Patrimium. Both documents are available at www.patrimiummfo.com/privacy-policy and www.patrimiummfo.com/ai-notice, and on request from patrimium.compliance@patrimiummfo.com.

2. Scope of This Policy

This Privacy Policy applies to current and prospective clients of Patrimium, including authorised representatives, beneficial owners, and associated individuals; visitors to our website at www.patrimiummfo.com; counterparties, service providers, and other individuals whose personal data we process in the course of our business operations; and job applicants.

3. Personal Data We Collect

3.1 Identity and Contact Data

  • Full name, date of birth, nationality, citizenship, and place of birth.

  • Passport, Emirates ID, or other government-issued identification.

  • Residential and business address, telephone number, and email address.

  • Government-issued personal identifier such as tax identification number.

3.2 Financial and Investment Data

  • Source of wealth and source of funds.

  • Investment experience, risk appetite, risk tolerance, and investment objectives.

  • Asset holdings, transaction history, and portfolio information.

  • Bank account details and payment information; financial account information including credit information where applicable and permitted by law.

3.3 Due Diligence and Compliance Data

  • KYC and AML documentation; PEP and sanctions screening results; country risk assessment information.

  • Ultimate beneficial ownership information; adverse media and third-party intelligence relevant to legal and regulatory obligations.

  • Information relating to political affiliations and criminal convictions as required and permitted by law.

3.4 Professional and Organisational Data

  • Role, position, title, and area of responsibility; employer details and business relationships where you are an individual associated with an institutional client.

3.5 Communications and Records Data

  • Records of meetings, calls, correspondence, and communications; instructions received from you; notes from client service interactions.

  • Transcriptions of meetings or calls where AI-assisted transcription tools are used, subject to human review before reliance.

3.6 Technical and Website Data

  • IP address, browser type, and device information when you visit our website; cookie and similar technology data, as described in our Cookie Notice.

3.7 Sensitive Personal Data

 

We do not seek to collect sensitive personal data unless strictly necessary for legal or regulatory compliance. Where we do so, we rely on an appropriate lawful basis as permitted under the DPL.

 

4. How We Collect Personal Data

We collect personal data directly from you during onboarding, account maintenance, and service delivery; from publicly available sources, including company registries, regulatory databases, and publicly accessible media; from third-party due diligence, screening, and identity verification providers; from other entities within any group arrangement of which you form part, where permitted; from our website; and from cookies and similar technologies on our website.

5. How and Why We Use Your Personal Data

We process your personal data only where we have a lawful basis to do so under the DPL. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you may request further information about that assessment. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

  • Delivering investment management services. Examples: Administering services; authorising transactions; billing; operational support. Lawful basis: Performance of contract; Legitimate interests.

  • AML/KYC and legal compliance. Examples: KYC, AML, PEP, and sanctions screening; DFSA regulatory reporting; responding to regulatory requests. Lawful basis: Legal obligation.

  • Risk management and fraud prevention. Examples: Risk management; fraud and financial crime prevention; operational risk assessment; monitoring. Lawful basis: Legitimate interests.

  • Business development and service improvement. Examples: Evaluating and improving services; developing internal tools including AI-assisted processes. Lawful basis: Legitimate interests.

  • Communications. Examples: Portfolio reports, regulatory notices, investment communications, and service updates. Lawful basis: Performance of contract; Legitimate interests.

  • Marketing. Examples: Information about our services where you have consented or where we have a legitimate interest. Lawful basis: Consent; Legitimate interests.

  • Email and digital communications tracking. Examples: Personalising content, improving your experience, and analysing communications performance. Lawful basis: Legitimate interests; Consent.

  • Monitoring. Examples: Monitoring communications and systems for compliance, security, and fraud prevention purposes to the extent permitted by law. Lawful basis: Legal obligation; Legitimate interests.

  • Recruitment. Examples: Confirming references and suitability; carrying out employment obligations. Lawful basis: Performance of contract; Legitimate interests; Legal obligation.

Website operation. Examples: Managing website access, cookies, and analytics. Lawful basis: Legitimate interests; Consent.

6. Use of Artificial Intelligence in Processing Your Personal Data

6.1 Our Approach to AI

Patrimium uses AI technologies, including generative AI large language model tools and, where deployed, automated compliance screening tools, to assist with research and analysis, document summarisation and drafting, compliance and regulatory screening, transcription, and translation.

AI generated outputs are subject to human review appropriate to their purpose, risk and potential impact before they are relied upon externally or used to make a decision affecting an individual. Our use of AI Systems does not result in automated decisions with any material legal or similar effects on any individual without prior human review. Where compliance screening tools generate automated flags or alerts, human intervention is applied before any alert is finalised or any determination or action is taken.

6.2 Regulation 10 Framework

Consistent with Regulation 10 of the DIFC Data Protection Regulations, where AI systems process personal data, we apply governance controls appropriate to the nature, scope, context and risks of the processing. Patrimium, as Deployer of AI Systems that process personal data, implements and maintains the following controls:

  • Data Protection Impact Assessments for AI Systems that process personal data.

  • An AI Register recording each AI System in use, the personal data processed, the purposes, and the applicable lawful basis.

  • Human-defined purposes and limits governing the AI Systems it operates.

  • Human intervention triggers where AI-assisted processing could produce unfair or discriminatory impacts.

  • Contractual and technical safeguards are applied to AI service providers, including restrictions and controls on their handling of personal data, where applicable.

Where required by applicable law in relation to high-risk processing, Patrimium will establish the relevant accountability arrangements.

 

6.3 Further Information

Full details of how we use AI Systems, including human-defined purposes and limits, outputs, design principles, safeguards, and your rights, are set out in our AI Transparency and Responsible Use Notice, available at www.patrimiummfo.com/ai-notice (once published) and on request.

 

6.4 AI in Email and Digital Communications

Some of our email communications, documents, and reports may be prepared with the assistance of AI tools. AI-assisted content intended for external use is subject to appropriate human review before issue. Our emails may also contain tracking technologies to personalise content, improve your experience, and analyse email performance, as disclosed in our standard email footer.

7. Monitoring

To the extent permitted by applicable law, Patrimium may monitor and record verbal and electronic communications and the use of Patrimium's systems in order to establish facts and maintain records; ascertain compliance with regulatory requirements; prevent, detect, and investigate crime and financial crime; comply with applicable law and internal policies; safeguard against unauthorised processing of confidential information; ensure the secure operation of systems; and support quality assurance and risk management. Monitoring may be assisted by AI tools. All significant outputs from monitoring are reviewed by human professionals.

8. Sharing Your Personal Data

We do not sell your personal data. We require third-party processors to be subject to written contractual obligations appropriate to applicable data-protection law. We may share personal data with the following categories of recipients:

  • Regulatory and law enforcement authorities. Purpose: DFSA, DIFC Commissioner of Data Protection, UAE Central Bank, financial intelligence units, courts. Basis: Legal obligation.

  • Third-party service providers and processors. Purpose: Custodians, administrators, IT providers, screening providers, AI service providers, legal advisors, auditors. Basis: Contractual necessity; Legitimate interests.

  • AI service providers. Purpose: Operation of AI Systems on Patrimium's behalf; AI service providers may process personal data only in accordance with applicable contracts, documented instructions and appropriate safeguards. Basis: Contractual necessity.

  • Counterparties. Purpose: Execution of transactions on your behalf. Basis: Contractual necessity.

  • Prospective acquirers. Purpose: In the event of a sale, transfer, or restructuring of the business. Basis: Legitimate interests.

 

9. International Transfers of Personal Data

Where we transfer personal data outside the DIFC, we ensure appropriate safeguards are in place in compliance with Articles 26 and 27 of the DPL, including transfers to jurisdictions recognised as adequate by the DIFC Commissioner, or via standard contractual clauses adopted by the DIFC Commissioner. 

Where personal data is transferred outside the DIFC, we apply an appropriate transfer mechanism and safeguards as required by applicable DIFC data-protection law. You may contact us for further information about the safeguards used for relevant transfers

10. Data Security

We maintain appropriate technical and organisational measures to protect your personal data, including access controls and authentication protocols; encryption of personal data in transit and at rest; secure data storage and backup; staff training on data protection; regular review and testing of security controls; and incident response and breach notification procedures. In the event of a personal data breach posing a risk to your rights, we report to the DIFC Commissioner of Data Protection without undue delay and notify affected data subjects as required under Articles 41 and 42 of the DPL.

11. Data Retention

Client account and investment records: Minimum 6 years from end of client relationship (DFSA and UAE AML requirements)

  • AML/KYC records: Minimum 6 years from end of relationship (UAE Federal Decree-Law No. 10 of 2025)

  • Correspondence and communications: Minimum 6 years from date of communication

  • Marketing data: Until consent is withdrawn or legitimate interest ceases

  • Job applicant records: Up to 2 years from application date if not appointed

  • Prospective client records: Up to 2 years from last contact if no relationship is established

We may retain personal data for longer where necessary to establish, exercise or defend legal claims, respond to regulatory or law-enforcement requests, investigate suspected misconduct, or comply with other legal or regulatory obligations.

 

12. Your Rights as a Data Subject

  • Right to be informed: To receive clear, transparent information about how your data is processed, provided by this Policy and our AI Notice

  • Right of access: To request a copy of the personal data we hold about you

  • Right to rectification: To request correction of inaccurate or incomplete personal data

  • Right to erasure: To request deletion where no lawful basis for continued processing exists

  • Right to restriction: To request that we restrict processing in certain circumstances

  • Right to data portability: To receive your personal data in a structured, commonly used format, where technically feasible

  • Right to object: To object to processing based on legitimate interests, including AI-assisted processing and direct marketing

  • Right to withdraw consent: To withdraw consent at any time where consent is the lawful basis

 

To exercise any of these rights, please submit a written request to the Head of Compliance & MLRO, Patrimium Asset Management Limited, Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE; patrimium.compliance@patrimiummfo.com; +971 50 633 6186. 

We will respond within the period required by applicable data-protection law. Where permitted, that period may be extended where a request is complex or numerous; if so, we will inform you.

13. Right to Complain

If you are not satisfied with our handling of your personal data, you may lodge a complaint with the DIFC Commissioner of Data Protection, Level 14, The Gate, DIFC, P.O. Box 74777, Dubai, UAE; commissioner@dp.difc.ae; www.difc.com/commissioners/data-protection

We welcome the opportunity to address your concerns first.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The current version and its effective date will be available on this page. Where legally required, we will notify you of material changes.

15. Contact Us

Data Protection Contact- Head of Compliance & MLRO 

Patrimium Asset Management Limited,

Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE; 

patrimium.compliance@patrimiummfo.com

+971 50 633 6186; 

www.patrimiummfo.com

 

Patrimium MFO Logo

Patrimium Asset Management Limited is a firm regulated by the Dubai Financial Services Authority (DFSA) and is only authorised to provide financial services to Professional Clients or Market Counterparties (all terms are defined in the DFSA Conduct Of Business (COB) Rules).

© 2026 Patrimium Multi Family Office. All Rights Reserved.

  • LinkedIn
bottom of page