Citra LabsBeta

Privacy Policy

Version 2.2 · Last updated: 8 September 2026

In plain language

This Privacy Policy explains how Gogopass Asia Sdn Bhd ("GGPA", "CitraLabs", "we", "us" or "our"), the operator of the CitraLabs platform (the "Service" or "Platform"), collects, uses, discloses, stores, and protects personal data in connection with the Service. This Privacy Policy is issued in compliance with the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), and its subsidiary legislation and guidelines issued by the Personal Data Protection Commissioner (collectively, the "PDPA").

1. Application and Scope

2. Definitions

TermMeaning
Personal DataAny information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information, as defined in section 4 of the PDPA.
Sensitive Personal DataPersonal data consisting of information on physical or mental health, political opinions, religious or similar beliefs, the commission or alleged commission of an offence, and biometric data, as defined in section 4 of the PDPA (as amended).
Biometric DataPersonal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of an individual (e.g. facial images used for recognition, voice data), which is treated as Sensitive Personal Data under the PDPA.
ContentAny text, image, photo, logo, audio, video footage, script, or other material a Customer uploads to, or generates using, the Platform.
Data SubjectAn individual who is the subject of personal data.
Processor / Service ProviderA third party that processes personal data on our behalf and under our instructions, including cloud/GPU hosting providers, AI model providers, and payment processors.
JPDPJabatan Perlindungan Data Peribadi – the Department of Personal Data Protection, and its Commissioner, the primary PDPA regulator.
Data User ("Data Controller")The person who either alone, or jointly or in common with other persons, processes any personal data or has control over or authorises the processing of any personal data, as defined in section 4 of the PDPA. GGPA is the Data User for personal data processed to operate the Service; a Customer is a separate Data User for personal data of third parties depicted in Content the Customer uploads (see Clause 4.3).

3. Personal Data We Collect

3.1 Account and Business Data. Information you provide when you register and use an account, such as your name, username, email address, and password, and any business information you choose to add to the Platform, such as a business or brand name, logo, and brand colours. Registration information is mandatory to use the Service; business information is optional.

3.2 Payment Data. Billing name, billing address, and purchase details. Card or payment account details are collected and processed directly by our payment processor(s) (see Clause 10 and Appendix A of the AI Privacy Policy); GGPA does not store full card numbers on its own systems.

3.3 Content Data. Logos, product photos, video footage, audio, scripts, and brand materials you upload to generate advertising content. Where uploaded Content depicts identifiable individuals (e.g. staff, models, customers, or members of the public captured in footage), this may include images, likenesses, and — where used for AI-driven facial animation, lip-sync, or similar processing — biometric data of those individuals. We also store the AI-generated outputs (videos, images, voiceovers) produced from your Content and prompts.

3.4 Usage and Technical Data. Device information, IP address, browser type, operating system, log data, timestamps (see Clause 17 on cookies); records of prompts submitted and features used, for service delivery, billing, and abuse-prevention purposes.

3.5 Communications Data. Correspondence with our support team and any feedback or preferences you choose to share with us.

4. Sensitive Personal Data and Biometric Data – Unbundled Consent

See also our Biometric Data Notice, the document the in-product consent step links to.

5. How We Collect Personal Data

6. Purposes of Processing

PurposeExamples
Account and service deliveryCreating and managing your account; authenticating login; providing AI video-generation features; processing and storing Content and outputs.
Payments and billingProcessing Credit purchases, invoicing, refunds, and fraud prevention, via our payment processor(s).
Customer supportResponding to enquiries, troubleshooting, and handling complaints.
Service improvementAnalysing aggregated usage patterns and diagnosing errors to improve platform performance and reliability (not model training — see Clause 9).
Legal and complianceComplying with applicable law, tax and accounting obligations, responding to lawful requests from authorities, and enforcing our Terms of Service.
Marketing (optional)Sending product updates or promotional communications, where you have opted in; you may opt out at any time.
Security and abuse preventionDetecting and preventing fraud, misuse of AI features, and content policy violations (e.g. generation of illegal or misleading advertising).

7. Legal Basis and Consent

8. Notice and Choice Principle Compliance Map

PDPA s.7(1) RequirementWhere addressed
That personal data is being processed and description of the dataClause 3
Purposes of collectionClause 6
Third parties to whom data may be disclosedClause 10; AI Privacy Policy Appendix A
Choices/means to limit processingClauses 4, 7, 14
Data access and correction procedureClause 14
Contact details for queries/complaintsClause 21
Whether provision of data is obligatory or voluntary, and consequences of not providing itClause 3.1
Right to request data not be processed for direct marketingClauses 6 (marketing), 14

9. Use of Personal Data for AI Purposes; Model Training

10. Disclosure of Personal Data

We disclose personal data only as necessary and to the following categories of recipients:

We do not sell personal data, and we do not share personal data with advertisers for behavioural advertising. All processors are bound by written contracts requiring PDPA-equivalent data protection standards, confidentiality, and use of data solely for the purposes we specify.

11. Cross-Border Data Transfer

12. Data Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls and role-based permissions, per-user scoping of stored content, staff confidentiality obligations, and vendor security due diligence, to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction, as required under the Security Principle (section 9 of the PDPA). AI-specific safeguards are set out in Section 11 of the AI Privacy Policy.

13. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, including to satisfy legal, accounting, or reporting obligations. Indicative retention periods:

Data categoryRetention
Account dataLife of the account, plus up to 30 days after closure
Uploaded Content and generated outputsUntil you delete them or your account is closed, plus up to 30 days for purge from active systems
Payment and Credit ledger records7 years, for tax and accounting compliance
Server and application logsUp to 90 days
Support correspondenceUp to 6 months after the request is closed

Copies residing in routine backups, where they exist, are not used for active processing and expire in the ordinary rotation cycle, subject to any legal retention requirements.

14. Your Rights as a Data Subject

Subject to the PDPA and any applicable exceptions, you have the right to:

To exercise these rights, contact us via https://citralabs.com/contact (Clause 21). We may charge a prescribed fee for access requests and will respond within the timeframes required under the PDPA. You can delete individual uploaded assets in-product at any time; account closure and full deletion are actioned on verified request.

15. Automated Decision-Making and Profiling

16. Data Breach Notification

17. Cookies and Similar Technologies

CitraLabs sets only essential cookies: a session authentication cookie required to keep you logged in and to secure your account. We do not use third-party analytics, advertising, or cross-site tracking cookies, and we do not share browsing data with advertising platforms. Because only strictly necessary cookies are used, no cookie consent banner is required; if we ever introduce non-essential cookies, we will introduce a consent mechanism and update this Policy first. You can manage or clear cookies through your browser settings; blocking the essential cookie will prevent login.

18. Children

CitraLabs is a business-to-business platform intended for use by SME owners, marketers, and authorised business users, and is not directed at, or knowingly used to collect personal data from, children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete it.

19. Governing Language

This Privacy Policy is issued in English.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes through the Platform or by email, and will indicate the "Effective date" at the top of this document. Continued use of the Service after such changes constitutes acknowledgement of the updated Privacy Policy.

21. Contact Us

FieldDetails
Data User (Data Controller)Gogopass Asia Sdn Bhd (Company No. 201601040201)
Registered addressNo. 39-1, Jalan Teknologi 3/6B, The Core Kota Damansara, 47810 Petaling Jaya, Selangor Darul Ehsan, Malaysia
Privacy requests and general supporthttps://citralabs.com/contact

You may also lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi) at www.pdp.gov.my.