Legal · v3.1
Privacy Policy · Effective 11 July 2026 · Last updated 12 July 2026
Manifesto Agency — Privacy Policy & Personal Data Protection Notice
Data Controller: Manifesto Agency (Registration No. 202603059119) Address: Adiva Residence, 158 Persiaran Residen 8, Desa ParkCity, 52200 Kuala Lumpur, Wilayah Persekutuan, Malaysia Contact: hello@manifesto.studio Effective Date: 11 July 2026
*(Bahasa Malaysia version available: Dasar Privasi (BM) · Versi Bahasa Malaysia tersedia di pautan tersebut, selaras dengan Akta Perlindungan Data Peribadi 2010.)*
1. Introduction and Identity of the Data Controller
1.1 This Privacy Policy and Personal Data Protection Notice ("Privacy Policy" or "Notice") explains how Manifesto Agency ("we", "us", "our") collects, uses, discloses, transfers, stores, secures, retains and deletes your personal data when you:
(a) visit https://www.manifestoheadshot.com/ or related domains we operate (the "Website"), including Studio and account pages;
(b) download, install or use the Manifesto Headshot mobile application for iOS or any other mobile version we publish (the "App");
(c) create or use an account (on the Website or in the App), including sign-in with email, Google or Apple;
(d) purchase Digital Products on the Website or make in-app purchases / subscriptions via an App Store;
(e) use the Done-for-You Service ("DFY Service"); or
(f) otherwise interact with us (support, marketing, refunds).
This Notice applies to both the Website and the App, and to the APIs and cloud services that support them (including authentication and optional sync of preferences and favourites).
1.2 We are committed to processing personal data in full compliance with the Personal Data Protection Act 2010 of Malaysia, as amended (including by the Personal Data Protection (Amendment) Act 2024) ("PDPA"), all subsidiary legislation, standards and guidelines issued under it (including the Personal Data Protection Standard 2015 and any guidelines issued by the Personal Data Protection Commissioner on biometric data, data breach notification, data protection officers and cross-border transfers), and all other Applicable Law.
1.3 For the purposes of the PDPA, Manifesto Agency is the data controller (referred to in the PDPA as the "data user") that determines the purposes and means of processing your personal data. This Notice is provided pursuant to the Notice and Choice Principle under section 7 of the PDPA.
1.4 This Notice should be read together with our Terms of Service and Cookie Policy. In the event of any inconsistency concerning personal data, this Notice prevails.
2. Scope of this Policy
2.1 This Notice applies to personal data processed in connection with: (a) visits to the Website; (b) use of the App; (c) accounts, authentication and optional cloud sync of profile preferences, favourites/likes and related app data; (d) profile or avatar photos you choose to set in the App (which, in the current App version, are stored on your device unless we later offer cloud upload with clear notice); (e) purchases of Digital Products on the Website and in-app purchases or subscriptions via an App Store (including entitlement status we receive from Apple or a subscription provider such as RevenueCat); (f) the DFY Service, including the upload and biometric processing of Reference Photos; (g) customer support, enquiries and correspondence; (h) marketing communications, including the free sample pack; and (i) our business administration, record-keeping and legal compliance.
2.2 This Notice does not apply to: (a) data you provide directly to third parties, including Third-Party AI Platforms to which you upload images yourself — their own privacy policies govern that processing; (b) data processed by Stripe as an independent controller of payment data; or (c) anonymous or aggregated data that does not identify you and cannot reasonably be re-identified, which we may use without restriction.
2.3 If you provide us with personal data of another individual (for example, Reference Photos of a colleague under Section 8 of the Terms), you warrant that you have informed that individual of this Notice and obtained the consents it requires, and you are responsible for the accuracy and lawfulness of that disclosure.
3. Definitions
In this Notice: "personal data" means any information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information or from that and other information in our possession, as defined in the PDPA; "sensitive personal data" means personal data classified as sensitive under the PDPA, which following the 2024 amendments includes biometric data, as well as data as to physical or mental health, political opinions, religious beliefs, the commission or alleged commission of any offence, and such other data as may be prescribed; "biometric data" means personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person, including facial images processed for the purpose of uniquely characterising a person; "processing" has the meaning given in the PDPA and includes collecting, recording, holding, storing, organising, adapting, altering, retrieving, using, disclosing, transferring, erasing and destroying personal data; "data processor" means a person who processes personal data solely on our behalf and does not process it for their own purposes.
4. Categories of Personal Data We Collect
4.1 Contact and identity data. Name, email address, display name (if you set one), and, where you provide them, phone number, company name, job title, and social or professional profile links. Where you sign in with Google or Apple, we receive limited account identifiers and may receive name and email as authorised by that provider.
4.2 Account and app preference data. Account identifiers; authentication session tokens; style and look preferences (for example gender look preference, goal, vibe); favourites/likes; saved prompts; progress metrics you generate in the App (for example streaks or lesson completion); and similar data when you use cloud sync.
4.3 Profile / avatar photos (App). If you set a profile picture in the App from your device library, that image is User Content you choose. In the current App version it is stored on your device for display in the App and is not used to train AI models. If we later offer cloud backup of avatars, we will notify you and update this Notice.
4.4 Reference Photos and biometric data. If you use the DFY Service (or otherwise upload photos to us for generation), we collect the face photographs you voluntarily upload — recommended eight (8) to twenty (20) well-lit images — together with the biometric information derivable from them, which may include facial geometry and structure, skin tone, facial proportions, eye spacing, jawline shape, hairline, and other physical characteristics. Under the PDPA as amended in 2024, this constitutes biometric data and sensitive personal data, and is processed only as described in Section 5. Phase 1 of the App does not require DFY photo upload; browsing prompts and education does not by itself process biometric data.
4.5 Transaction and payment data. Order details, products purchased, amounts, currency, timestamps, billing name and email, and payment status. For Website checkout, full card numbers are collected and processed by Stripe, not by us; we receive only limited payment metadata. For App Store purchases, Apple processes payment; we may receive entitlement, product and transaction identifiers via Apple or a provider such as RevenueCat (not your full card number).
4.6 Technical and usage data. IP address, device type and identifiers, browser or app version, operating system, referral source, pages or screens viewed, time spent, clicks and interactions, approximate location derived from IP address, crash or diagnostic data if enabled, and data collected through cookies and similar technologies on the Website (see the Cookie Policy). The App primarily uses local storage and secure device storage for sessions rather than browser cookies.
4.7 Communications data. The content of emails, forms, support requests, refund requests, testimonials and other communications you send us, together with associated metadata.
4.8 Marketing preference data. Your subscription status, consent records, and interaction with our emails (such as opens and clicks, where measured).
4.9 Data we do not collect. We do not intentionally collect: personal data of minors (see Section 15); data as to health, political opinions or religious beliefs; or national identity card or passport numbers (do not upload images of identity documents). We do not sell personal data.
5. Biometric and Sensitive Personal Data — Explicit Consent and PDPA Compliance
5.1 Legal classification. Facial reference images and the characteristics derived from them are biometric data and are treated as sensitive personal data under the PDPA (as amended 2024). Section 40 of the PDPA prohibits the processing of sensitive personal data except with the explicit consent of the data subject or in other narrowly defined circumstances.
5.2 Explicit consent. We process your biometric data only with your explicit consent, which we obtain through a clear, affirmative, separate consent action (an unticked checkbox and confirmation statement) at the point of upload, as set out in Part 5, Document A of this document. We do not infer biometric consent from your general acceptance of the Terms, from browsing the Website, or from any pre-ticked box.
5.3 Specified purposes. We process biometric data only for the following specific, explicitly notified purposes:
(a) generating, curating and delivering AI headshots and optimised prompts to you under the DFY Service;
(b) performing quality control on the deliverables of your specific order;
(c) communicating with you about your order, including requesting replacement Reference Photos where needed;
(d) preventing fraud and misuse, including verifying that uploaded photos comply with Section 8 of the Terms (own-likeness and consent requirements); and
(e) establishing, exercising or defending legal claims, where necessary.
5.4 What we do NOT do with biometric data. We do not: (a) use your Reference Photos or biometric data to train, fine-tune or improve any machine-learning model of our own; (b) sell, rent or trade biometric data to anyone; (c) use biometric data for surveillance, identification of persons in other datasets, or profiling unrelated to your order; (d) use your Reference Photos in marketing without the separate opt-in release in Part 5, Document B; or (e) retain biometric data beyond the retention period in Section 10.
5.5 Third-party generation processors. Where delivery of the DFY Service involves submitting your Reference Photos to a Third-Party AI Platform for generation, we will identify the categories of such processors in our current processor list (available on request), require appropriate contractual protections where the platform acts as our processor, and inform you where the platform acts as an independent controller so that you can review its policy before consenting. If you do not consent to a necessary transfer, we cannot provide the DFY Service and will cancel and refund the order.
5.6 Withdrawal. You may withdraw your consent to biometric processing at any time by emailing hello@manifesto.studio (see Section 14). Withdrawal does not affect the lawfulness of processing carried out before withdrawal. If you withdraw before delivery of a DFY order, the order will be treated as cancelled under Section 15.7 of the Terms. Upon valid withdrawal we will cease processing and securely delete your biometric data except where retention is required or permitted by law (for example, records needed for an ongoing dispute).
5.7 Voluntariness. Provision of biometric data is entirely voluntary. It is required only for the DFY Service; you can purchase and use all Digital Products without ever uploading a photo to us.
6. How We Collect Personal Data
We collect personal data: (a) directly from you, when you place an order, upload Reference Photos, complete forms, request the free sample pack, contact support or submit a testimonial; (b) automatically, through cookies, server logs and similar technologies when you use the Website (see the Cookie Policy); and (c) from third parties, limited to payment confirmation data from Stripe and delivery/engagement data from our email service provider. We do not purchase personal data from data brokers.
7. Purposes of Processing and Lawful Bases
7.1 We process personal data on the following bases recognised by the PDPA: your consent (which is the basis for all biometric processing and all marketing); the necessity of processing for the performance of a contract with you or steps at your request prior to a contract; compliance with legal obligations; and our legitimate interests where processing is necessary for those interests as permitted under the PDPA framework.
7.2 Specific purposes and their bases:
| Purpose | Data categories | Basis |
|---|---|---|
| Providing, operating and securing the Website and Digital Products | Technical, usage | Contract; legitimate interests |
| Processing orders, payments, receipts and refunds | Contact, transaction | Contract; legal obligation |
| Delivering the DFY Service (generation, curation, delivery, revisions) | Contact, Reference Photos/biometric | Contract; explicit consent (biometric) |
| Order and support communications | Contact, communications | Contract |
| Sending the free sample pack and marketing emails | Contact, marketing preference | Consent (with unsubscribe in every message) |
| Marketing Promotion uses of AI Output/testimonials | AI Output, testimonials | Consent (see Terms s.5 and Part 5 Doc B) |
| Internal analytics, product development and service optimisation | Technical, usage (aggregated where possible) | Legitimate interests; consent (analytics cookies) |
| Fraud prevention, security monitoring, misuse investigation | Technical, transaction, communications | Legitimate interests; legal obligation |
| Tax, accounting and statutory record-keeping | Contact, transaction | Legal obligation |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests; legal obligation |
7.3 New purposes. If we wish to process your personal data for a purpose not disclosed in this Notice and not directly related to a disclosed purpose, we will notify you and, where required by the PDPA, obtain your consent before doing so.
8. Disclosure and Sharing of Personal Data; Data Processors
8.1 We disclose personal data only to the following categories of recipients, and only to the extent necessary:
(a) Payment processors (Stripe) — for transaction completion, refunds and fraud screening;
(b) Hosting, storage and infrastructure providers — to operate the Website and store data securely;
(c) Email and delivery service providers — to send transactional and (with consent) marketing emails;
(d) Third-Party AI Platforms / generation processors — solely for the DFY Service, as described in Section 5.5;
(e) Professional advisers — lawyers, accountants, auditors and insurers, under duties of confidentiality;
(f) Authorities — law enforcement, regulators, courts and tribunals, where disclosure is required by law, court order, or is necessary to protect our rights, your vital interests or public safety; and
(g) Business successors — a purchaser or prospective purchaser of our business or assets, subject to confidentiality obligations and to this Notice continuing to apply to the transferred data.
8.2 Processor contracts. Where a recipient processes personal data on our behalf as a data processor, we require, by written contract, that the processor: processes the data only on our documented instructions; implements security measures consistent with the PDPA's Security Principle; keeps the data confidential; does not engage sub-processors without appropriate flow-down obligations; and returns or deletes the data at the end of the engagement.
8.3 No sale of data. We do not sell, rent or trade your personal data to any third party for their marketing purposes, and we do not permit third parties to use data received from us for their own advertising.
9. Cross-Border (International) Transfers of Personal Data
9.1 Some of our service providers (including Stripe, cloud hosting, email providers and Third-Party AI Platforms) may process personal data on servers located outside Malaysia.
9.2 Under section 129 of the PDPA (as amended 2024), we transfer personal data outside Malaysia only where: (a) you have consented to the transfer; (b) the transfer is necessary for the performance of our contract with you; (c) the receiving jurisdiction has laws substantially similar to the PDPA or ensures an adequate level of protection, as assessed in accordance with the Commissioner's guidelines (including, where applicable, a transfer impact assessment); or (d) another condition permitted by the PDPA applies.
9.3 Where we rely on contractual safeguards, we use binding contractual clauses obliging the recipient to protect the data to a standard consistent with the PDPA. Details of the safeguards applicable to a specific transfer are available on request via hello@manifesto.studio.
10. Data Retention and Deletion Schedule
10.1 Principle. In accordance with the Retention Principle under the PDPA, we do not keep personal data longer than is necessary for the fulfilment of the purpose for which it was collected, and we take all reasonable steps to destroy or permanently delete personal data no longer required.
10.2 Standard retention periods (subject to Section 10.3):
| Category | Retention period |
|---|---|
| Reference Photos and biometric data | Securely and permanently deleted within thirty (30) days after final delivery and expiry of the revision window of your DFY order (or promptly after withdrawal of consent or cancellation), unless you expressly request earlier deletion or a longer retention in writing |
| Delivered AI Output (your headshots) | Retained for up to twelve (12) months to support re-delivery requests, then deleted, unless you request earlier deletion |
| Order, transaction and tax records | Seven (7) years, as required for Malaysian tax and accounting compliance |
| Support and general correspondence | Up to twenty-four (24) months after resolution |
| Marketing consent and suppression records | For as long as needed to honour your preferences, plus statutory limitation periods |
| Technical logs | Typically ninety (90) days, unless needed for security investigation |
| Consent records (including biometric consent) | Duration of the relationship plus applicable limitation periods, as evidence of compliance |
10.3 Extended retention. We may retain specific data beyond these periods only where required by law, or where reasonably necessary to establish, exercise or defend legal claims, resolve disputes, or enforce our agreements, in which case the data is isolated and protected until deletion is possible.
10.4 Deletion methods. Deletion is performed using secure erasure appropriate to the storage medium, and includes instructing processors to delete their copies.
11. Security Measures
11.1 In accordance with the PDPA's Security Principle and the Personal Data Protection Standard 2015, we implement technical and organisational measures proportionate to the nature and sensitivity of the data — with heightened protections for biometric data — including: encryption of data in transit (TLS) and at rest where supported; access controls on a strict need-to-know basis; unique credentials and multi-factor authentication on administrative systems; segregation of Reference Photos from general business data; vendor due diligence and contractual security obligations; regular review of security arrangements; secure deletion practices; and staff/contractor confidentiality obligations and awareness of PDPA duties.
11.2 No method of transmission or storage is completely secure. While we are required to take, and do take, practical steps to protect personal data, we cannot guarantee absolute security, and you accept the residual risk inherent in transmitting information over the internet. This Section 11.2 does not limit any liability we may have under the PDPA that cannot lawfully be excluded.
11.3 You also play a role in security: use a strong unique password, keep your credentials confidential, and notify us immediately of any suspected compromise.
12. Personal Data Breach Notification
12.1 In accordance with the PDPA (as amended 2024) and the Commissioner's data breach notification requirements, if a personal data breach occurs we will: (a) contain and assess the breach without delay; (b) notify the Personal Data Protection Commissioner where the breach meets the notification threshold under the PDPA and applicable guidelines, within the prescribed timeframe (as soon as practicable, and within the period specified by the applicable regulations); and (c) notify affected data subjects without unnecessary delay where the breach is likely to result in significant harm, including in respect of biometric data, providing a description of the breach, the data affected, the measures taken, and steps you can take to protect yourself.
12.2 We maintain an internal breach register and response procedure, and our processor contracts require processors to notify us of breaches without undue delay.
13. Your Rights Under the PDPA
Subject to the conditions and exceptions in the PDPA, you have the following rights:
13.1 Right of access. You may request confirmation of whether we process your personal data and access to a copy of it. We may charge the modest fee prescribed under the PDPA for access requests and will inform you of any fee before processing the request.
13.2 Right of correction. You may require us to correct personal data that is inaccurate, incomplete, misleading or not up to date.
13.3 Right to withdraw consent. You may at any time withdraw consent to processing based on consent (see Section 14).
13.4 Right to prevent processing likely to cause damage or distress. You may, by written notice, require us to cease or not begin processing that is causing or is likely to cause substantial damage or distress to you or another person, where unwarranted.
13.5 Right to prevent processing for direct marketing. You may at any time require us to stop, or not begin, processing your personal data for direct marketing purposes. We will comply without charge.
13.6 Right to data portability. To the extent provided by the PDPA (as amended 2024) and any operative subsidiary legislation, you may request that personal data you provided to us be transmitted to another data controller in a structured, commonly used, machine-readable format, where technically feasible.
13.7 How to exercise your rights. Send your request to hello@manifesto.studio with the subject "PDPA Request", describing the right you wish to exercise and providing sufficient information for us to verify your identity (we will not disclose personal data to a requester whose identity we cannot verify). The procedure is set out in Part 5, Document D. We will respond within the timeframe prescribed by the PDPA (in the case of access and correction requests, twenty-one (21) days, extendable as permitted where notice of extension is given).
13.8 Refusals. Where the PDPA permits or requires us to refuse a request (in whole or part), we will inform you of the refusal and the reason, and of your right to complain to the Commissioner.
13.9 No detriment. You will not be discriminated against for exercising any PDPA right, although withdrawal of consent required for a service (such as biometric consent for the DFY Service) will mean we cannot provide that service.
14. Withdrawal of Consent
14.1 Where processing is based on consent — including all biometric processing and all marketing — you may withdraw consent at any time by emailing hello@manifesto.studio, or, for marketing emails, by clicking the unsubscribe link present in every message.
14.2 On receipt of a valid withdrawal we will cease the relevant processing without unnecessary delay and confirm to you the action taken. Withdrawal does not affect: (a) the lawfulness of processing before withdrawal; (b) processing on other lawful bases (for example, retention of transaction records for tax law); or (c) material already lawfully published before withdrawal, as described in Section 5.3 of the Terms, although we will remove such material from channels within our direct control within a reasonable period not exceeding thirty (30) days.
14.3 Consequences of withdrawal for services are described in Section 5.6 above and Section 15.8 of the Terms.
15. Children and Minors
The Services are intended for adults. We do not knowingly collect personal data from anyone under eighteen (18), and Users must not upload photos of minors in any circumstances. If you believe a minor has provided personal data to us, or that photos of a minor have been uploaded, contact hello@manifesto.studio immediately and we will delete the data as soon as practicable.
16. Marketing Communications and Your Choices
16.1 We send marketing emails (including product updates, new volume releases and offers) only where you have opted in — for example, by requesting the free sample pack with marketing consent, or subscribing to our list. Transactional messages (order confirmations, delivery links, refund communications, legal notices) are not marketing and are sent as needed to perform our contract.
16.2 Every marketing email contains a functioning unsubscribe mechanism. Unsubscribing takes effect promptly and no later than the period prescribed by Applicable Law. We maintain a suppression list to ensure your choice is honoured.
16.3 We do not use your Reference Photos, biometric data or DFY deliverables for advertising targeting, and we do not share your data with third parties for their marketing (Section 8.3).
17. Automated Processing and AI Transparency
17.1 The DFY Service involves automated processing of your Reference Photos by generative AI systems to produce headshots. This processing is performed to fulfil your order, is initiated by you, and its output is reviewed and curated by a human before delivery.
17.2 We do not use your personal data to make automated decisions that produce legal effects concerning you or similarly significantly affect you (such as credit, employment or eligibility decisions).
17.3 As explained in Section 5.4, we do not use your data to train our own or third parties' AI models. Where a Third-Party AI Platform used in the DFY Service offers contractual or technical controls to prevent the use of submitted images for model training, we enable those controls; where a platform does not offer such controls, we will not submit your Reference Photos to it without informing you.
18. Cookies and Tracking Technologies
Our use of cookies and similar technologies is described in the Cookie Policy (Part 4), which forms part of this Notice. Non-essential cookies are used only with your consent, which you may give, refuse or withdraw through the cookie banner and settings link described there.
19. Third-Party Websites and Services
The Website may link to third-party sites (including Stripe's checkout, social media pages and AI Platforms). We are not responsible for the privacy practices of third parties. This Notice applies only to processing by or on behalf of Manifesto Agency. Review the privacy policy of every third-party service you use, especially any AI Platform to which you upload photos directly.
20. Data Protection Contact and How to Reach Us
Questions, concerns, complaints and rights requests concerning personal data should be directed to:
Manifesto Agency — Data Protection Email: hello@manifesto.studio (subject line "PDPA Request" or "Privacy Question") Address: Adiva Residence, 158 Persiaran Residen 8, Desa ParkCity, 52200 Kuala Lumpur, Malaysia
Where the PDPA (as amended 2024) and its subsidiary legislation require the appointment of a Data Protection Officer for our processing activities, we will appoint one and update this Notice with the relevant contact details.
21. Complaints to the Personal Data Protection Commissioner
If you are dissatisfied with our handling of your personal data or of a rights request, you may lodge a complaint with the Personal Data Protection Commissioner / Jabatan Perlindungan Data Peribadi (JPDP), Malaysia. We would, however, appreciate the opportunity to resolve your concern first, and you may contact us at any time at hello@manifesto.studio.
22. Changes to this Privacy Policy
We may update this Notice from time to time to reflect changes in law, technology or our practices. The updated version will be posted on the Website with a new effective date, and for material changes affecting sensitive personal data or marketing we will provide direct notice (by email where we hold your address) and obtain fresh consent where the PDPA requires it. Continued use of the Services after the effective date constitutes acceptance of the revised Notice, except where fresh consent is required, in which case the change will not apply to you until you give it.
23. Language of this Notice
This Notice is issued in English and, as required by the PDPA, is also available in Bahasa Malaysia at /privacy/ms. In the event of inconsistency between versions, the version that complies with the mandatory requirements of the PDPA in respect of the affected provision prevails. The Bahasa Malaysia text is a translation draft for publication; qualified counsel or a certified translator may refine terminology.
Operated by Manifesto Agency (SSM 202603059119 (003829903-D)). Contact hello@manifesto.studio.
Related: Terms · Privacy · Cookies · Plain-language summary