Privacy Policy
Version 2.2 · Last updated: 8 September 2026
In plain language
- CitraLabs is an AI video-generation tool. We collect account, payment, and content data (including any photos, logos, or footage you upload) to provide the service.
- If you upload images or footage containing recognisable faces or voices, this may constitute biometric data or other sensitive personal data under applicable Malaysian law. CitraLabs may, at its sole discretion, refuse to process, restrict or suspend the processing of such images or footage for AI purposes where the required consent has not been obtained, or where CitraLabs considers such processing to be inappropriate, unlawful, or otherwise inconsistent with its policies or legal obligations. We ask for separate, specific consent before processing it for AI purposes (see the AI Privacy Policy, which sets out the single consent framework for the Platform).
- We do not use your uploaded content or generated outputs to train our AI models, and every AI vendor in our pipeline is engaged under terms that commit the vendor not to train on customer data. Any future model-improvement programme would be a separate, optional opt-in.
- We do not sell your personal data, and we use no third-party advertising or analytics trackers — the only cookie the Platform sets is the essential login cookie.
- We share data only with categories of service providers who help us run CitraLabs (cloud/GPU hosting, AI model providers, payment processing), under contract.
- Some of our service providers are located outside Malaysia. Where that happens, we rely on the safeguards required under section 129 of the PDPA (as amended).
- You can access, correct, export, delete, or withdraw consent for your data, and you can lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, "JPDP").
This Privacy Policy explains how Gogopass Asia Sdn Bhd ("GGPA", "CitraLabs", "we", "us" or "our"), the operator of the CitraLabs platform (the "Service" or "Platform"), collects, uses, discloses, stores, and protects personal data in connection with the Service. This Privacy Policy is issued in compliance with the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), and its subsidiary legislation and guidelines issued by the Personal Data Protection Commissioner (collectively, the "PDPA").
1. Application and Scope
- This Privacy Policy applies to all personal data processed by GGPA in connection with the CitraLabs website, application, and related services, including data of: (a) registered SME customers and their authorised users ("Customers", "you"); (b) individuals whose images, likenesses, or other personal data appear in content uploaded to, or generated by, the Platform ("Data Subjects in Content"); and (c) visitors to our website.
- This Privacy Policy forms part of, and should be read together with, the CitraLabs Terms of Service and the AI Privacy Policy, which supplements this Policy for AI-specific and biometric processing. Where there is a direct conflict solely on data protection matters: this Privacy Policy prevails over the Terms of Service, and the AI Privacy Policy prevails over this Policy on AI-specific and biometric matters.
- This is a Notice and Choice statement for the purposes of section 7 of the PDPA. It is directed at commercial transactions and applies to personal data we process in Malaysia and, where relevant, personal data processed outside Malaysia but relating to Malaysian data subjects or processed for GGPA's Malaysian operations.
2. Definitions
| Term | Meaning |
|---|
| Personal Data | Any information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information, as defined in section 4 of the PDPA. |
| Sensitive Personal Data | Personal data consisting of information on physical or mental health, political opinions, religious or similar beliefs, the commission or alleged commission of an offence, and biometric data, as defined in section 4 of the PDPA (as amended). |
| Biometric Data | Personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of an individual (e.g. facial images used for recognition, voice data), which is treated as Sensitive Personal Data under the PDPA. |
| Content | Any text, image, photo, logo, audio, video footage, script, or other material a Customer uploads to, or generates using, the Platform. |
| Data Subject | An individual who is the subject of personal data. |
| Processor / Service Provider | A third party that processes personal data on our behalf and under our instructions, including cloud/GPU hosting providers, AI model providers, and payment processors. |
| JPDP | Jabatan Perlindungan Data Peribadi – the Department of Personal Data Protection, and its Commissioner, the primary PDPA regulator. |
| Data User ("Data Controller") | The person who either alone, or jointly or in common with other persons, processes any personal data or has control over or authorises the processing of any personal data, as defined in section 4 of the PDPA. GGPA is the Data User for personal data processed to operate the Service; a Customer is a separate Data User for personal data of third parties depicted in Content the Customer uploads (see Clause 4.3). |
3. Personal Data We Collect
3.1 Account and Business Data. Information you provide when you register and use an account, such as your name, username, email address, and password, and any business information you choose to add to the Platform, such as a business or brand name, logo, and brand colours. Registration information is mandatory to use the Service; business information is optional.
3.2 Payment Data. Billing name, billing address, and purchase details. Card or payment account details are collected and processed directly by our payment processor(s) (see Clause 10 and Appendix A of the AI Privacy Policy); GGPA does not store full card numbers on its own systems.
3.3 Content Data. Logos, product photos, video footage, audio, scripts, and brand materials you upload to generate advertising content. Where uploaded Content depicts identifiable individuals (e.g. staff, models, customers, or members of the public captured in footage), this may include images, likenesses, and — where used for AI-driven facial animation, lip-sync, or similar processing — biometric data of those individuals. We also store the AI-generated outputs (videos, images, voiceovers) produced from your Content and prompts.
3.4 Usage and Technical Data. Device information, IP address, browser type, operating system, log data, timestamps (see Clause 17 on cookies); records of prompts submitted and features used, for service delivery, billing, and abuse-prevention purposes.
3.5 Communications Data. Correspondence with our support team and any feedback or preferences you choose to share with us.
4. Sensitive Personal Data and Biometric Data – Unbundled Consent
- Because biometric data is Sensitive Personal Data under the amended PDPA, we do not bundle your consent to process biometric data (e.g. facial data in uploaded footage used for AI face-related features) together with your general consent to our Terms of Service or this Privacy Policy.
- Before any biometric or other Sensitive Personal Data is processed, we obtain your separate, explicit, and informed consent through the consent framework set out in Section 6 of the AI Privacy Policy (a distinct in-product consent step at the point of upload for features that process a face or voice), which: (a) identifies the feature involved; (b) explains the processing purpose in plain language; and (c) allows you to decline without losing access to unrelated features of the Service. That framework is the single consent mechanism for the Platform.
- Where Content you upload depicts third parties (e.g. your employees, models, or customers), you confirm that you have obtained their consent, or have another valid legal basis, for their personal data — including any biometric data — to be processed by CitraLabs for the purposes described in this Privacy Policy. GGPA relies on this representation from Customers, who act as a separate Data User (see Definitions) in respect of personal data of third parties depicted in Content they upload.
- You may withdraw consent to biometric processing at any time by contacting us via https://citralabs.com/contact (Clause 21); this will not affect the lawfulness of processing carried out before withdrawal, but may limit or disable AI features that depend on that data.
See also our Biometric Data Notice, the document the in-product consent step links to.
5. How We Collect Personal Data
- Directly from you, when you register, purchase Credits, upload Content, submit prompts, contact support, or complete forms.
- Automatically, through the essential cookie and server logs when you use the Platform.
- From third parties, such as payment processors (confirming successful payment) or publicly available sources, where relevant to verify a business account.
6. Purposes of Processing
| Purpose | Examples |
|---|
| Account and service delivery | Creating and managing your account; authenticating login; providing AI video-generation features; processing and storing Content and outputs. |
| Payments and billing | Processing Credit purchases, invoicing, refunds, and fraud prevention, via our payment processor(s). |
| Customer support | Responding to enquiries, troubleshooting, and handling complaints. |
| Service improvement | Analysing aggregated usage patterns and diagnosing errors to improve platform performance and reliability (not model training — see Clause 9). |
| Legal and compliance | Complying with applicable law, tax and accounting obligations, responding to lawful requests from authorities, and enforcing our Terms of Service. |
| Marketing (optional) | Sending product updates or promotional communications, where you have opted in; you may opt out at any time. |
| Security and abuse prevention | Detecting and preventing fraud, misuse of AI features, and content policy violations (e.g. generation of illegal or misleading advertising). |
7. Legal Basis and Consent
- As a commercial transaction under the PDPA, our processing of your personal data is generally based on your consent, given when you register for and use the Service and agree to this Privacy Policy.
- For Sensitive Personal Data (including biometric data), we rely on your separate, explicit consent as described in Clause 4 and Section 6 of the AI Privacy Policy, or another applicable ground under section 40 of the PDPA (e.g. necessity for legal proceedings), where consent is not practicable.
- Where processing is necessary to perform our contract with you (e.g. processing payment to deliver the Credits you purchased) or to comply with a legal obligation, we may process personal data on that basis without separate consent, as permitted under the PDPA.
- You may withdraw consent at any time by contacting us via https://citralabs.com/contact. Withdrawal does not affect processing carried out before withdrawal and may result in us being unable to continue providing all or part of the Service to you.
8. Notice and Choice Principle Compliance Map
| PDPA s.7(1) Requirement | Where addressed |
|---|
| That personal data is being processed and description of the data | Clause 3 |
| Purposes of collection | Clause 6 |
| Third parties to whom data may be disclosed | Clause 10; AI Privacy Policy Appendix A |
| Choices/means to limit processing | Clauses 4, 7, 14 |
| Data access and correction procedure | Clause 14 |
| Contact details for queries/complaints | Clause 21 |
| Whether provision of data is obligatory or voluntary, and consequences of not providing it | Clause 3.1 |
| Right to request data not be processed for direct marketing | Clauses 6 (marketing), 14 |
9. Use of Personal Data for AI Purposes; Model Training
- We use your Content and prompts to generate the outputs you request, using AI models self-hosted by GGPA on contracted GPU cloud infrastructure and/or third-party AI model providers acting as our processors under contract (see Clause 10 and Appendix A of the AI Privacy Policy).
- GGPA does not use Customer Content, prompts, or generated outputs to train or fine-tune GGPA's own AI models, and engages each third-party AI model processor under terms that commit the processor not to use such data to train the processor's own models. The per-vendor position is recorded in our internal vendor register and re-verified whenever a vendor is onboarded or its published terms change. If GGPA introduces an optional model-improvement programme in future, participation will require a separate, express, unticked opt-in consent, and declining will not affect your use of the Service.
- Where a third-party AI model provider's own terms differ from the position above, we will disclose this in Appendix A of the AI Privacy Policy and obtain any necessary additional consent before onboarding that provider.
- Because CitraLabs performs automated content-policy screening and may personalise in-product recommendations, Clause 15 (Automated Decision-Making) applies, together with Section 8 of the AI Privacy Policy.
10. Disclosure of Personal Data
We disclose personal data only as necessary and to the following categories of recipients:
- Processors and sub-processors engaged to operate the Service, by category: cloud/GPU hosting and storage providers, AI model providers, email delivery, and support tooling. A detailed vendor register is maintained and available on written request via https://citralabs.com/contact (this satisfies the s.7(1)(e) disclosure of classes of third parties).
- Payment processor(s), to process Credit purchases.
- Professional advisers (legal, accounting, auditors), where necessary.
- Government authorities or regulators, including JPDP, where required or permitted by law, or to respond to a lawful request.
- A successor entity, in connection with a merger, acquisition, financing, or sale of assets, subject to equivalent data protection commitments.
We do not sell personal data, and we do not share personal data with advertisers for behavioural advertising. All processors are bound by written contracts requiring PDPA-equivalent data protection standards, confidentiality, and use of data solely for the purposes we specify.
11. Cross-Border Data Transfer
- Some of our processors (including GPU cloud and AI model providers) are located, or process data, outside Malaysia. Any such transfer is carried out in accordance with section 129 of the PDPA (as amended by Act A1727, in force from 1 April 2025), which removed the previous "whitelist" regime.
- We transfer personal data outside Malaysia only where at least one of the following applies: (a) the recipient jurisdiction has in force a law substantially similar to, or that provides protection at least equivalent to, the PDPA (section 129(2)); or (b) we have your explicit consent to the transfer; the transfer is necessary for performance of our contract with you; the transfer is necessary to protect your vital interests; or we have taken all reasonable precautions and exercised all due diligence to ensure the recipient will not process the data in a manner that would breach the PDPA (section 129(3)).
- We also have regard to the Cross-Border Personal Data Transfer Guideline issued by JPDP (29 April 2025) in assessing and documenting our transfer mechanisms, and maintain a transfer register, summarised by category and destination in Appendix A of the AI Privacy Policy and available in detail on written request via https://citralabs.com/contact.
12. Data Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls and role-based permissions, per-user scoping of stored content, staff confidentiality obligations, and vendor security due diligence, to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction, as required under the Security Principle (section 9 of the PDPA). AI-specific safeguards are set out in Section 11 of the AI Privacy Policy.
13. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, including to satisfy legal, accounting, or reporting obligations. Indicative retention periods:
| Data category | Retention |
|---|
| Account data | Life of the account, plus up to 30 days after closure |
| Uploaded Content and generated outputs | Until you delete them or your account is closed, plus up to 30 days for purge from active systems |
| Payment and Credit ledger records | 7 years, for tax and accounting compliance |
| Server and application logs | Up to 90 days |
| Support correspondence | Up to 6 months after the request is closed |
Copies residing in routine backups, where they exist, are not used for active processing and expire in the ordinary rotation cycle, subject to any legal retention requirements.
14. Your Rights as a Data Subject
Subject to the PDPA and any applicable exceptions, you have the right to:
- Access the personal data we hold about you (section 30);
- Request correction of inaccurate, incomplete, or outdated personal data (section 34);
- Withdraw consent to processing, including for direct marketing (sections 38 and 43);
- Request that we cease or not begin processing your data for a purpose likely to cause you damage or distress (section 42);
- Request that certain personal data be provided to you in a portable, machine-readable format (see also Section 12.2 of the AI Privacy Policy);
- Lodge a complaint with JPDP if you believe we have breached the PDPA.
To exercise these rights, contact us via https://citralabs.com/contact (Clause 21). We may charge a prescribed fee for access requests and will respond within the timeframes required under the PDPA. You can delete individual uploaded assets in-product at any time; account closure and full deletion are actioned on verified request.
15. Automated Decision-Making and Profiling
- CitraLabs uses automated tools to screen prompts and scripts before generation for policy violations (e.g. illegal, misleading, or infringing advertising content); certain upstream AI providers additionally apply their own automated content filters.
- Where such automated decision-making or profiling produces legal or similarly significant effects on you (e.g. suspension of your account), we provide a means to request human review, consistent with JPDP's guidance on profiling and automated decision-making. See Section 8 of the AI Privacy Policy for the full ADMP notice.
- Where our automated decision-making qualifies as high-risk under JPDP's Data Protection Impact Assessment ("DPIA") Guideline, we conduct and maintain a DPIA for that processing activity.
16. Data Breach Notification
- If we become aware of a personal data breach that causes or is likely to cause significant harm, or that affects 1,000 or more data subjects, we will notify JPDP as soon as practicable and, in any event, within 72 hours of becoming aware of the breach, in accordance with the PDPA's mandatory breach notification requirements (in force from 1 June 2025) and JPDP's Data Breach Notification Guideline.
- Where the breach is likely to cause significant harm to affected individuals, we will notify those individuals without unnecessary delay and, in any event, within 7 days of notifying JPDP, through direct means (e.g. email) or, where direct contact is not practicable, by public notice (e.g. on our website).
- Breach notifications to affected individuals will include a description of the breach, its likely consequences, and the measures taken or proposed to address it.
17. Cookies and Similar Technologies
CitraLabs sets only essential cookies: a session authentication cookie required to keep you logged in and to secure your account. We do not use third-party analytics, advertising, or cross-site tracking cookies, and we do not share browsing data with advertising platforms. Because only strictly necessary cookies are used, no cookie consent banner is required; if we ever introduce non-essential cookies, we will introduce a consent mechanism and update this Policy first. You can manage or clear cookies through your browser settings; blocking the essential cookie will prevent login.
18. Children
CitraLabs is a business-to-business platform intended for use by SME owners, marketers, and authorised business users, and is not directed at, or knowingly used to collect personal data from, children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete it.
19. Governing Language
This Privacy Policy is issued in English.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes through the Platform or by email, and will indicate the "Effective date" at the top of this document. Continued use of the Service after such changes constitutes acknowledgement of the updated Privacy Policy.
21. Contact Us
| Field | Details |
|---|
| Data User (Data Controller) | Gogopass Asia Sdn Bhd (Company No. 201601040201) |
| Registered address | No. 39-1, Jalan Teknologi 3/6B, The Core Kota Damansara, 47810 Petaling Jaya, Selangor Darul Ehsan, Malaysia |
| Privacy requests and general support | https://citralabs.com/contact |
You may also lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi) at www.pdp.gov.my.