Privacy & Data Protection

Clixerfy PrivacyPolicy.

Transparency is part of how we build Clixerfy. This policy explains how Toon Group Inc. collects, processes, protects, and safeguards information through the Clixerfy platform.

Operating Entity: Toon Group Inc.Registered Office: Ontario, Canada

Operating Entity

Toon Group Inc. (o/a Clixerfy)

Registered Office

Ontario, Canada

Privacy Contact

legal@clixerfy.com
Privacy at a glance

Built to detect threats,not monetize personal data.

Strict purpose limitation

Security metadata and Click Data are processed to protect advertising infrastructure and detect invalid activity.

Data minimization

Identifying information is subject to defined operational retention periods and edge anonymization processes.

No data resale

Click Data and technical network indicators are never commercialized for marketing, profiling, or data brokering.

01Introduction & Scope

Introduction and Scope

This Privacy Policy describes how Toon Group Inc.("Clixerfy", "we", "us", or "our") collects, uses, discloses, and safeguards data when you visit our website (clixerfy.com), register for an account, or use Clixerfy's Adfraud and Bot Blocker (the "Service").

This policy satisfies transparency obligations under the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), Quebec's Law 25, the EU/UK GDPR, the California Consumer Privacy Act ("CCPA/CPRA"), the Australian Privacy Act 1988, and Brazil's LGPD.

02Our Role

Processor vs. Controller

DP

Clixerfy as a Data Processor

When our business clients install our script on their properties, we process website visitor telemetry ("Click Data") strictly as a Data Processoroperating under the client's explicit instructions. Our clients act as the Data Controllersfor their visitors' information.

DC

Clixerfy as a Data Controller

When you buy our software, create an account, or interact with our sales team, we act as a Data Controller regarding your business contact, corporate registration, and billing information.

03Information

Information We Collect and Process

3.1 Account Information (Processed as a Data Controller)

When you create a corporate account or request a custom tier quote, we collect business contact details including name, company name, corporate email address, and phone number.

We also process secure financial billing information through PCI-DSS compliant payment processing sub-processors, along with authenticated developer API keys and user access authorization tokens necessary to link your account to external advertising networks.

3.2 Transient Telemetry and Click Data (Processed as a Data Processor)

Through the script layer deployed on Client properties, our infrastructure processes raw network telemetry regarding visitors interacting with paid ad placements. This data is handled transiently within our secure volatile caching layer and includes:

  • Inbound internet protocol (IP) addresses and unique system Visitor IDs (visitor_id).
  • Network and click event timestamps.
  • User-Agent parameters, including operating system builds, browser types, and software versions.
  • HTTP Referrer URLs and digital ad placement tokens, such as GCLID parameters.
  • High-frequency velocity signals and behavioral interaction anomalies.
04Purpose Limitation

How We Use Information & Purpose Limitation

4.1 Strict No-Marketing & Data Resale Prohibition

We maintain a permanent, structural prohibition on commercializing security metadata.

Click Data and technical network indicators processed via the Service will never be used by us or our sub-processors for marketing, behavioral audience profiling, cross-context remarketing, data brokering, or commercial gain.

4.2 Primary Operational Uses

We process collected data exclusively to:

  • Validate infrastructure integrity and secure ad network campaign spend against invalid, automated, or fraudulent interactions.
  • Deliver real-time activity metrics to the Client dashboard.
  • Generate aggregated, fully anonymized behavioral threat parameters to improve algorithmic detection accuracy.
05Data Retention

Multi-Layered Data Retention and Edge Anonymization Lifecycles

We enforce rigorous data minimization scripts across our global server infrastructure mapped to individual Client dashboard configurations.

01

Transient Caching Tiers (Redis)

Inbound parameters containing full personal data, such as raw IP addresses, are processed within a volatile local memory layer for a customized operational lifespan selected directly by the Client during system configuration. Upon expiration of this user-configured cache threshold, all identifying keys automatically expire and are completely dissolved from system memory, entirely independent of long-term metrics parameters.
02

Evaluation Log Ledger (click_logs)

Complete traffic metadata is committed to a central master ledger table (click_logs) for multi-tenant trend analytics. Prior to database persistence, all inbound records are programmatically and permanently stripped of raw IP addresses and unique visitor identifiers at the software edge.

The resulting anonymous, non-identifiable feature matrices are retained for a maximum of ninety-one (91) days before absolute database purging.
03

Enforcement & History Tiers (ip_bans & ip_ban_history)

Confirmed threat signatures are written to an active block ledger (ip_bans) containing unmasked details for an operational duration selected directly by the Client within their control panel settings.

Immediately upon expiration of that custom active ban window, the raw IP identity and visitor_id are completely and permanently dropped. The record then moves to an inactive ledger (ip_ban_history) storing exclusively non-identifiable behavioral vectors for ninety (90) days before complete erasure.
04

Machine Learning Training & Persistent Analytics

To optimize our detection algorithms, our system extracts anonymized behavioral and environmental features during software edge ingestion. This structural data contains zero personal information or tracking hashes and may be retained by us indefinitely.

Network Context

Autonomous System Numbers (ASN), high-level connection classifications, country, and province-level geographic metadata.

Temporal Metrics

Relative click deltas representing millisecond spacing between interaction events and diurnal traffic distributions scaled to a uniform timezone.

Environmental Footprints

Aggregated interaction scores, including mouse tracking, touch coordinates, scroll vectors, and User-Agent entropy metrics.

06International Transfers

International Data Transfers & Safeguards

Toon Group Inc. is a Canadian corporation. Data processed through our network is securely transferred, stored, and evaluated on secure cloud infrastructure deployed in global data center hubs, including secure deployments through certified sub-processors in Virginia, United States.

We ensure international transfers comply with prevailing data protection statutes by incorporating the EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum into our master agreements.

We also apply mandatory transport-layer encryption of TLS 1.2 or higher and execute provincial Privacy Impact Assessments (PIAs) where required.

07Security

Data Security and Breach Disclosures

We maintain administrative, technical, and physical safeguards designed to defend against unauthorized system access, data destruction, or disclosure.

72

Hours

Affected Clients will be notified within seventy-two (72) hours of confirmation of an infrastructure incident affecting Client data safeguards.

24

Months

In accordance with PIPEDA's Breach of Security Safeguards Regulations, records of security safeguard breaches are maintained for a minimum of twenty-four (24) months from discovery.

08Policy Changes

Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect architectural backend adjustments, changes to our automated edge-anonymization scripts, or updates to global data protection laws.

Any modifications will become effective immediately upon being posted to this URL. We will indicate the date of the latest revisions by updating the "Last Updated" timestamp at the top of this page.

We encourage visitors and account holders to review this page periodically to remain informed about how we process and safeguard technical routing metadata.

09Contact

Contact and Corporate Complaints

For privacy questions or to file a formal inquiry under PIPEDA or Law 25 parameters, contact our designated privacy group:

Privacy Officer

Toon Group Inc. (o/a Clixerfy)
Ontario, Canada

legal@clixerfy.com

Clixerfy

Protecting campaigns without compromising privacy.

Back to Clixerfy