Hilma Privacy Policy
Last updated: August 21, 2026
View Group, Inc., doing business as Hilma ("Hilma", "we", "our", or "us"), respects your privacy and is committed to protecting it. This Privacy Policy describes how we collect, use, store, disclose, and protect personal data about you when you use our software-as-a-service platform, our mobile application, our website at hil.ma, and any related products and services that link to this policy (together, our "Services").
This policy applies to personal data we collect:
- Through the Services, including our platform, mobile application, and the hil.ma website.
- In communications between you and us, including email, in-app messages, and other electronic messages.
- From third parties who provide us with information as described in this policy.
It does not apply to personal data collected by any third party, including through any application, content, or website that may link to or be accessible from the Services but that is not operated by us.
Because we provide our Services to customers in the United Kingdom and the United States, this policy is designed to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and, to the extent they apply to us, US state consumer privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA). Where a particular law applies to us and gives you specific rights, those rights are described in the sections below.
Please read this policy carefully. By using our Services or providing us with your personal data, you acknowledge the practices described in this policy. This policy may change from time to time (see Changes to This Privacy Policy), so please check it periodically.
Who We Are
View Group, Inc., doing business as Hilma, is the sole controller responsible for your personal data. Our platform and website are operated and hosted in the United Kingdom by our affiliate View Global, Ltd (1 Coach House Mews, London SE1 4PP, United Kingdom), which processes personal data on our behalf as our processor. If you have any questions about this policy or how we handle your personal data, or if you wish to exercise your rights, please contact us at [email protected] (see Contact Information). If you are in the United Kingdom, you can also reach us or View Global, Ltd at the London address above.
Children's and Minors' Data
Our Services are intended only for individuals aged 18 or older. The Services are not directed to children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe we have collected personal data from a person under 18, please contact us at [email protected] and we will take steps to delete that information.
The Personal Data We Collect
"Personal data" means information that identifies, relates to, or describes you, directly or indirectly, as an individual. The categories of personal data we collect or process include:
- Account and contact information, such as your name and email address.
- Payment information, such as the payment card or payment method details used to pay for the Services. Payment card details are collected and processed by our payment processor; we do not store full payment card numbers.
- Financial records, such as invoices and other billing records relating to your account.
- Technical and usage data, such as your IP address, device and browser type, operating system, log data, and details of how you interact with and use our platform and mobile application.
- Third-party enrichment data, such as information about artists, prior owners, and collectors that we obtain from data and reference services to enrich the artwork and organisation records in the Services. This category consists of personal data about individuals other than you, and we act as controller of the enrichment data we obtain in this way.
We do not collect special category (sensitive) personal data through the Services.
We also compile aggregated and anonymized data, such as statistical data about how the Services are used. We treat data as anonymized only where it has been altered so that you are no longer identifiable, directly or indirectly, and re-identification is not reasonably likely, taking into account all the means reasonably likely to be used. We recognise that art-collection information can be unusually re-identifying — a small number of distinctive works can point to a particular individual or household — so we do not treat data as anonymized merely because names or other direct identifiers have been removed. Any data from which you remain identifiable, directly or indirectly, is treated as personal data and handled in accordance with this policy and applicable data protection law.
How We Collect Your Personal Data
We collect personal data in the following ways:
- Directly from you. You provide personal data when you join our waitlist or submit your email address on our website at hil.ma, when we create or you manage an account, when you use the platform or mobile application, when you are billed for the Services, or when you contact us.
- Automatically through your use of the Services. As you use our platform and mobile application, we automatically collect technical and usage data using strictly necessary cookies and server logs. Our website at hil.ma does not set cookies and does not collect analytics or other usage data.
- From third parties. We receive information from the service providers we use to operate the Services, including our data and reference services, which we use to enrich artwork and organization records associated with your account.
Personal data we obtain about third parties (not collected from the individual). Where the Services are used to manage artwork and organisation records, we and our data and reference services add information about third parties — such as artists, prior owners, and collectors — that we obtain from public and licensed reference sources rather than from those individuals. We act as controller of the enrichment data we obtain in this way, and we process it on the basis of our legitimate interests (and our customers' legitimate interests) in compiling and maintaining accurate provenance and collection records, weighed against those individuals' interests and rights. Because this personal data is not obtained from the individual, Article 14 of the UK GDPR applies: unless an exemption applies (for example, where providing the information proves impossible or would involve a disproportionate effort, or the individual already has the information), we will make available to affected individuals the information Article 14 requires — including the categories of personal data, the source, the purposes and legal basis for processing, the recipients, the retention period, and their rights — and those individuals may exercise the rights described in this policy by contacting us at [email protected].
How We Use Your Personal Data and Our Legal Bases
We use the personal data we collect to:
- Provide, operate, and maintain the Services and make their features available to you.
- Create and manage your account and authenticate you.
- Process payments and manage invoices, billing, and collections.
- Send you account and service messages, including notices about your account, changes to the Services, and updates to this policy.
- Respond to your requests, questions, and support needs.
- Monitor, analyze, improve, secure, and develop the Services, including troubleshooting, testing, and analytics.
- Detect, prevent, and address fraud, security incidents, and misuse of the Services.
- Comply with our legal, regulatory, tax, and accounting obligations, and establish, exercise, or defend legal claims.
Our legal bases (UK users). Under the UK GDPR, we must have a legal basis for using your personal data. We rely on one or more of the following:
- Performance of a contract — where using your personal data is necessary to provide the Services you have signed up for, including processing payments and managing your account.
- Legitimate interests — where using your personal data is necessary for our legitimate interests in operating, securing, and improving our business and the Services, provided those interests are not overridden by your rights. This includes analytics, service improvement, and fraud prevention.
- Legal obligation — where we must use your personal data to comply with a legal, regulatory, tax, or accounting obligation.
- Consent — where we ask for your consent to a specific use, such as certain optional communications or cookies. You may withdraw your consent at any time, without affecting processing carried out before withdrawal.
Automated Processing and Artificial Intelligence
We use third-party artificial intelligence (AI) processing services to help automate document and data processing tasks within the Services. We do not use these AI services to make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. We do not sell your personal data or use it to train third-party generative AI models for their own purposes.
Who We Share Your Personal Data With
We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
We share personal data with the following categories of service providers, who process it only on our instructions and for the purposes of operating the Services:
- Cloud hosting and storage providers, who host our platform and store Your Content and other data securely.
- Payment processors, who handle payments made through the Services.
- Email and communications providers, who help us send account and service messages.
- AI processing providers, who help us automate document and data processing tasks.
- Data and reference service providers, who help us enrich artwork and organization records.
We require all of our service providers to protect your personal data, to use it only for the purposes for which we provide it, and to treat it in accordance with applicable law.
We may also disclose personal data:
- To comply with any court order, law, or legal process, or to respond to a government or regulatory request.
- To enforce our terms and other agreements, including for billing and collection.
- Where we believe disclosure is necessary to protect the rights, property, or safety of Hilma, our customers, or others, including for fraud prevention.
- To a buyer or successor in the event of a merger, acquisition, reorganization, financing, or sale or transfer of some or all of our assets, in which personal data is among the assets transferred.
- For any other purpose disclosed to you at the time you provide the data, or with your consent.
Cookies and Tracking Technologies
Our website at hil.ma does not set any cookies. When you log in to our platform at hilma.net, we set three first-party cookies that are strictly necessary to authenticate you and keep you signed in. We do not use analytics, advertising, or other non-essential cookies, we do not use third-party cookies, and we do not use cookies to track you across other websites or services.
Because these cookies are strictly necessary to provide the Services you request, they do not require consent under UK and EU rules. You can still block or delete cookies through your browser settings, but if you block our authentication cookies you will not be able to log in to or use the platform.
International Data Transfers
Your personal data is hosted in the United Kingdom by View Global, Ltd. Our controller entity, View Group, Inc., is based in the United States and may access personal data from there, and some of the service providers we use may process personal data outside the United Kingdom. These are international transfers.
Whenever we transfer personal data out of the United Kingdom to a country that does not provide an adequate level of protection (including to the United States), we take steps to ensure it receives an appropriate level of protection, by relying on one or more of the following safeguards:
- Transfers to countries that the UK or the European Commission has recognized as providing an adequate level of data protection.
- The European Commission's Standard Contractual Clauses, together, where relevant, with the UK International Data Transfer Agreement or the UK Addendum to those clauses.
- Any other transfer mechanism permitted under applicable data protection law.
We maintain a separate International Data Transfers Statement with further detail about these safeguards. It is not published on our website but is available on request. To request a copy of that Statement or more information about these safeguards, please contact us at [email protected].
Your Privacy Rights
Depending on where you live, you have certain rights over your personal data. We will not discriminate or retaliate against you for exercising your rights.
Rights for users in the United Kingdom. Under the UK GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct inaccurate or incomplete personal data.
- Erase your personal data in certain circumstances.
- Restrict our processing of your personal data in certain circumstances.
- Object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
- Data portability — receive certain personal data in a structured, commonly used, machine-readable format, or have it transferred to another controller.
- Withdraw consent at any time where we rely on your consent.
Rights for users in the United States. Some US states have consumer privacy laws (for example, California's CCPA). Where you reside in such a state and that law applies to us, you may have the right to:
- Know and access the categories and specific pieces of personal data we have collected about you, the sources, the purposes for collection, and the categories of recipients.
- Correct inaccurate personal data we maintain about you.
- Delete personal data we have collected from you, subject to certain exceptions.
- Opt out of the sale or sharing of personal data and of certain targeted advertising and profiling. As noted above, we do not sell or share your personal data for these purposes.
The exact scope of these rights and the exceptions that apply vary by law. To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding, and we may ask for additional information for that purpose. You may use an authorized agent to submit a request where permitted by law.
These US state rights apply only where a US state consumer privacy law applies to us. There is normally no fee to exercise your rights. We aim to respond within the time required by applicable law (generally one month under the UK GDPR, and within the period required by any applicable US state consumer privacy law, in each case subject to any permitted extensions). If your request is unfounded, repetitive, or excessive, we may charge a reasonable fee or decline to act, as permitted by law.
How We Protect Your Personal Data
We use appropriate administrative, technical, and physical measures designed to protect your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure. We limit access to your personal data to those who have a business need to know, and they are subject to a duty of confidentiality. No system or transmission is completely secure, however, and we cannot guarantee the security of personal data transmitted to or through the Services. We have procedures to address suspected personal data breaches and will notify you and any applicable regulator where we are legally required to do so.
How Long We Keep Your Personal Data
We keep your personal data for as long as reasonably necessary to fulfil the purposes described in this policy, including to provide the Services, operate our business, comply with our legal, regulatory, tax, and accounting obligations, resolve disputes, and enforce our agreements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and applicable legal requirements. When personal data is no longer needed, we delete, destroy, or de-identify it.
Complaints
If you have a concern about how we handle your personal data, you can make a complaint to us at [email protected]. To make it easy to complain, we provide a complaint form that you can complete and submit to us electronically, and you may also complain by email using the address above. We operate a complaint-handling process and will: acknowledge receipt of your complaint within 30 days; take appropriate steps to investigate and respond to it; and keep you informed of the progress and outcome without undue delay.
Making a complaint to us is free, and you do not have to complain to us before contacting a regulator. However, we would appreciate the chance to resolve your concern first. If you are in the United Kingdom, you also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk.
Changes to This Privacy Policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this policy and post the updated policy through the Services. Where required by law, we will provide additional notice of material changes. Please review this policy periodically to stay informed about how we handle your personal data.
Contact Information
To exercise your rights, or if you have any questions or complaints about this policy or our privacy practices, please contact us at:
View Group, Inc. (dba Hilma)
Email: [email protected]
Website: hil.ma
Postal address: 167 Madison Avenue, Ste 205 #428, New York, NY 10016