Privacy Policy

Effective date: 8 October 2026

This Privacy Policy explains how we (“we”, “us”, “our”) collect, use, disclose and protect your personal data when you use the Citadel First mobile application (the “App”). We process personal data in accordance with the Personal Data Protection Act 2010 of Malaysia, as amended (the “PDPA”). This notice is provided in English and Bahasa Malaysia; if they differ, the English version prevails.

1. Who This Policy Covers

This policy applies to:

  • Clients (settlors) who register, complete identity verification and invest in trust products through the App;
  • Agents who register to service clients through the App;
  • Beneficiaries, guardians and third-party payers whose details a client provides to us; and
  • anyone else who downloads or uses the App.

2. Personal Data We Collect

We collect different types of personal data depending on which features you use.

2.1 Identity

  • Full name (for identity verification and your trust documents)
  • NRIC, passport or other ID number and document type (for identity verification)
  • Date of birth (to confirm you are 18 or over)
  • Gender, nationality, title and marital status (for your trust documents and regulatory records)

2.2 Identity Documents & Biometrics

  • Images of your ID card or passport, front and back (for eKYC)
  • Selfie (to confirm you are the document holder)
  • Facial template derived from your selfie and ID photo (for face matching only)

2.3 Contact Details

  • Residential and mailing address, including postcode, city, state and country
  • Mobile and home telephone numbers
  • Email address (for login, account recovery and notices)

2.4 Employment & Financial Profile

  • Employment type, occupation and employer details
  • Annual income range and estimated net worth
  • Source of trust fund and source of income (for anti-money laundering checks)

2.5 Regulatory Declarations

  • Politically exposed person (PEP) status
  • Tax residency and tax identification numbers (for CRS reporting)
  • Bankruptcy declaration and country of birth

2.6 Bank & Payment Details

  • Bank name, account holder name, account number, SWIFT code and bank address (to pay you distributions)
  • Bank statements (to verify your account)
  • Payment receipts and transfer slips (to confirm your payments)

2.7 Beneficiaries, Guardians & Third-Party Payers

Data you give us about other people:

  • Beneficiaries: names, ID numbers, dates of birth, relationship to you, contact and bank details, ID copies and bank statements
  • Guardians of beneficiaries under 18: names, ID numbers, relationship, contact details
  • Third-party payers (immediate family who pay on your behalf): names, ID numbers, relationship and declaration form

2.8 Trust & Transaction Records

  • Trust orders, amounts and tenure
  • Dividends, rollovers, reallocations, redemptions and withdrawals
  • Signed agreements, statements of account and your digital signature

2.9 Agent Data (agents only)

  • Agency details, ranking and servicing relationships
  • Commission records and bank details (for commission payouts)

2.10 Device & Technical Data

  • Push notification token (to send you notifications)
  • IP address recorded with your disclaimer acceptance and bankruptcy declaration, and for agents at each registration step (as evidence of your submission)

Identity verification (eKYC). To meet our obligations under anti-money laundering and know-your-customer rules, the App scans your ID document and captures a selfie. ID scanning and face detection run on your device using Microblink BlinkID and Google ML Kit. The resulting images are sent to our servers, where we compare your selfie with your ID photo to confirm you are the document holder.

Device biometrics. If you enable fingerprint or Face ID login, the check is performed by your device's operating system. We never receive or store your fingerprint or Face ID data.

Data about other people. When you give us details of beneficiaries, guardians or third-party payers, you confirm that you are authorised to do so and that you have told them about this policy. For a beneficiary under 18, you confirm you are acting with the consent of their parent or legal guardian.

Screenshots. For your protection, the App blocks screenshots and screen recording while you view your signed trust agreement. We do not collect the contents of your screen.

3. How We Use Your Data

We use your personal data only for these purposes:

  1. To create and manage your account and verify your identity.
  2. To carry out customer due diligence, sanctions and PEP screening, and to meet our obligations under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001, tax reporting (including CRS) and other laws.
  3. To process trust purchases, payments, dividends, rollovers, reallocations, redemptions and withdrawals.
  4. To prepare, sign and keep trust agreements, statements of account and receipts.
  5. To pay distributions to you and your beneficiaries.
  6. To let your servicing agent assist you, and to calculate and pay agent commissions.
  7. To send you service notifications by push notification, email and in-app message about your account and orders.
  8. To protect the App and our clients against fraud, unauthorised access and misuse.
  9. To meet audit, legal, regulatory and court requirements, and to establish or defend legal claims.

We rely on your consent, on the need to perform our contract with you, and on our legal obligations. Supplying the data marked as required in the App is obligatory: without it we cannot open your account or administer your trust. We do not sell your personal data, and we do not use it for third-party advertising.

4. Who We Share It With

RecipientWhat and why
Your servicing agentYour profile, orders and documents, so they can service your account
VanguardFor Vanguard trust products: your identity, KYC, beneficiary, payment and order details, which Vanguard needs as trustee to accept and administer your trust
Cloud and service providersAmazon Web Services (data storage and hosting, Singapore), Google Firebase (push notifications), our email delivery provider, Microblink and Google ML Kit (on-device ID scanning and face detection)
Banks and payment processorsTo receive your payments and pay distributions
Auditors, legal and professional advisersUnder duties of confidentiality
Regulators, law enforcement and courtsWhere the law requires or permits, including Bank Negara Malaysia, the Securities Commission, LHDN and enforcement agencies
A successor businessIf we restructure, merge or sell our business, under equivalent protection

Our service providers may use your data only on our instructions and must keep it secure and confidential.

5. Transfers Outside Malaysia

Our servers are hosted by Amazon Web Services in Singapore. Some service providers may process data in other countries. We transfer personal data out of Malaysia only where the PDPA allows it, including where the receiving country has comparable protection or the recipient is bound by contract to protect it. By using the App, you consent to these transfers.

6. How We Protect It

We encrypt data in transit and at rest, restrict staff access by role and permission, keep audit logs, and use presigned, time-limited links for documents. No system is completely secure, so please keep your login details and device secure and tell us at once if you suspect unauthorised access.

7. How Long We Keep It

We keep your personal data for as long as your account or any trust is active, and for [Retention period] afterwards, to meet record-keeping, tax and anti-money-laundering obligations and to handle disputes. After that we delete it or make it anonymous.

8. Your Rights

Under the PDPA you may:

  • ask for access to the personal data we hold about you, and a copy of it;
  • ask us to correct data that is inaccurate, incomplete or out of date; you can also update most details in the App;
  • withdraw consent, or ask us to limit how we process your data;
  • ask us to transfer your data to another organisation, where the PDPA allows; and
  • ask us not to use your data for direct marketing.

Withdrawing consent or limiting processing may mean we can no longer administer your trust. We may charge a fee for a copy of your data as the PDPA permits, and will respond within 21 days.

9. Deleting Your Account

You can ask to delete your account in the App under Profile > Delete My Account, or by contacting us. We will close your account and delete your data, except data we must keep by law or for an active trust, which we keep only for the period in section 7.

10. Children

The App is for persons aged 18 and above. We process data about beneficiaries under 18 only as provided by a client, together with their guardian's details.

11. Data Breaches

If a personal data breach is likely to cause you significant harm, we will notify you and the Personal Data Protection Commissioner as the PDPA requires.

12. Changes to This Policy

We may update this policy. We will tell you about material changes in the App or by email before they take effect. The effective date at the top shows the current version.

13. Contact Us

Data Protection Officer
cgt.admin@citadelgroup.com.my