Clixerfy MasterServices Agreement.
The terms governing access to and use of Clixerfy's Adfraud and Bot Blocker platform and related services.
Provider
Toon Group Inc. (Clixerfy)
Governing Law
Ontario & Applicable Canadian Law
Billing Contact
billing@clixerfy.comAgreement Between
Provider
Toon Group Inc.
Operating as Clixerfy, a corporation organized under the laws of the Province of Ontario, Canada.
Client
The Legal Entity
The legal entity registering for, accessing, or utilizing the services described in this Master Services Agreement.
Clear rules fora complex protection system.
Client-controlled settings
Operational thresholds, caching lifecycles, and restriction periods are configured directly by the Client.
Integrated data processing
The agreement includes data processing, anonymization, retention, and cross-border transfer provisions.
Third-party dependencies
Service performance may depend on external advertising platforms, APIs, technical limitations, and platform policies.
Section I
Commercial & Service Terms
Scope of Service, User-Dictated Thresholds, and Configuration Auditing
Provider operates an automated cybersecurity, infrastructure optimization, and ad-fraud mitigation platform known as Clixerfy's Adfraud and Bot Blocker (the "Service").
The Service monitors network metrics and behavioral telemetry on Client's digital properties via an asynchronous tracking script to identify invalid interactions and programmatically sync exclusion lists with Client's connected digital advertising platforms, including Google Ads.
The Service categorizes traffic based on automated scoring models entirely governed by custom operational thresholds, caching lifecycles, and restriction lifespans configured directly by the Client within the user management panel (the "User-Dictated Configurations").
Client acknowledges and explicitly agrees that they assume sole operational, legal, and commercial liability for the selection, sensitivity limits, modifications, and enforcement parameters of these User-Dictated Configurations.
To maintain transparency and an immutable audit trail, the Service automatically transmits a formal electronic mail confirmation to the Client's registered administrative email account immediately upon any change, modification, or adjustment made to these User-Dictated Configurations, logging the exact technical modifications deployed.
Free Trial, Pricing Tiers, and Subscription Activation
30-Day Free Trial
Proactive Trial Auditing & Quote Issuance
Subscription Activation
Right to Freeze Services
Traffic Allocation & Overages
Non-Refundability
Price Adjustments
Right to Modify Fees
Objection and Dispute Window
Effect of Cancellation Notice
Invoicing, Non-Payment, and Service Suspension
Payment Terms
Suspension for Non-Payment
Emergency Protective Suspension
Section II
Integrated Data Processing Addendum (DPA)
Legal Roles under Canadian & Global Privacy Laws
For the purposes of applicable global data protection frameworks—including the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), Quebec's Law 25, the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), the Australian Privacy Act 1988, and Brazil's General Data Protection Law ("LGPD")—the parties acknowledge that Client acts as the Data Controller and Provider acts as the Data Processor/Service Provider.
Privacy Warranties & Purpose Limitation
Strict Purpose Limitation
No Commercial Exploitation
Algorithmic Profiling Nature
Volatile Processing and Edge-Anonymization Protocols
To maintain campaign protective integrity while ensuring compliance with global data minimization, anonymization, and storage limitation principles, Provider routes and maintains telemetry data through an automated, state-governed database pipeline dictated dynamically by the Client.
Transient Volatile Caching Layer (Redis)
All personal identification parameters written to this volatile tier are subject to a strict Time-To-Live (TTL) deletion script mapped exactly to the Client's user-selected configuration, ensuring raw identifiers are permanently and completely dissolved from system RAM automatically upon expiration of that specific window.
Evaluation Logging Layer (click_logs)
click_logs) for multi-tenant trend analytics. Prior to database persistence, all inbound records are programmatically and permanently stripped of raw IP addresses and unique visitor identifiers at the software edge.The resulting anonymous, non-identifiable feature matrices are retained for a maximum of ninety (91) days before absolute database purging. Because this persistent layer is entirely anonymous on arrival, it falls outside the scope of personal data processing under applicable global privacy laws and outside statutory data protection constraints.
Active Threat Enforcement Tier (ip_bans)
ip_bans) to execute automated ad network API exclusions.The raw network signature is retained within this active partition exclusively for the duration of the active restriction window configured dynamically by the Client within the dashboard setup panel. This restricted operational lifespan is enforced solely to maintain live synchronization loops with third-party advertising platform APIs and defend Client infrastructure, after which the raw identifier is systematically deleted.
Inactive Threat Intelligence Tier (ip_ban_history)
ip_bans tier, the corresponding record transitions to a historic archive table (ip_ban_history).The raw IP address and personal identifiers are permanently dropped upon entry into this table. The historical record stores exclusively non-identifiable threat attributes for a maximum duration of ninety (90) days following the conclusion of the active ban window, after which it is completely deleted from system disks.
Fully anonymized behavioral and environmental features extracted during any minimization phase contain zero personal information or tracking hashes and may be retained by Provider indefinitely to train machine learning models.
Mandatory Remediation (The Whitelist Override)
Cross-Border Data Transfers & Frameworks
Client authorizes Provider to utilize secure global cloud infrastructure, including secure deployments through certified sub-processors, to transfer, store, and process technical metadata and network signatures.
Where European Union, EEA, or United Kingdom traffic is involved, the parties contractually incorporate the EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum into this agreement by reference to govern the transfer, unless Provider maintains active self-certification under the EU-U.S. Data Privacy Framework (DPF).
Where Canadian traffic is processed, Provider implements contractual safeguards ensuring a comparable level of data protection.
Mandatory Breach Record Keeping & Reporting
72
Hours
Notification
Provider will notify Client within seventy-two (72) hours of discovery of a security breach involving Client data safeguards.
RROSH
Statutory Evaluation
Client assumes sole statutory responsibility for evaluating whether an incident meets the applicable Real Risk of Significant Harm threshold.
24
Months
Breach Records
Provider maintains records of platform security safeguard breaches for a minimum of twenty-four (24) months from discovery.
Real Risk of Significant Harm (RROSH)
24-Month Statutory Log
Section III
Indemnity, Liability, and Third-Party Dependencies
Programmatic Access and Agency Authorization
Client hereby grants Provider a limited, non-exclusive, revocable license and express authorization to act as Client's technical agent for the sole, restricted purpose of accessing Client's connected digital advertising environments, such as Google Ads, via programmatic Application Programming Interfaces (APIs).
This authorization is granted exclusively to allow the Service to automatically and dynamically modify "IP Exclusion Lists," "Placement Exclusion Lists," and closely related targeting parameters to shield Client's advertising spend from flagged fraudulent traffic sources.
Client affirms that any automated modifications executed by the Service within Client's connected accounts are fully authorized, are executed on Client's behalf as their technical agent, and shall be legally treated as if executed directly by the Client.
Third-Party Infrastructure and API Dependencies
Client explicitly acknowledges that the execution and performance of the Service relies fundamentally on third-party digital advertising platforms, including but not limited to Google Ads, their proprietary API ecosystems, network-enforced rate limits, system thresholds, and platform terms of service.
Disclaimer of Third-Party Fault
Operational Limits
Limitation of Liability and False Positives Warranty
Client acknowledges that bot-detection and fraud auditing utilize complex probabilistic algorithms.
No Absolute Guarantee
Limitation of Loss
Cap on Damages
In no event shall Provider's cumulative aggregate financial liability exceed the total fees paid by Client to Provider during the three (3) months immediately preceding the event giving rise to liability.
Indemnification Against Publisher Claims
Client agrees to defend, indemnify, and hold harmless Provider from any civil actions, losses, regulatory audits, or claims of Tortious Interference brought against Provider by third-party web publishers, website networks, or traffic channels resulting from placement or domain exclusions initiated by the Service on behalf of Client's ad accounts.
Term, Termination, and Offboarding Obligations
Term
Mandatory Client Offboarding Duties
Upon termination or expiration of this agreement for any reason, the Client assumes sole and immediate responsibility for offboarding. Client must:
- Manually revoke Provider's programmatic and user access permissions within their internal Google Ads user management system, console, or connected ad center.
- Completely remove and delete the Clixerfy tracking and installation script from the source code of all digital properties.
Release of Liability
Amendments and Modifications to Terms
Provider reserves the right to modify the technical, operational, and processing descriptions contained within this Agreement and its integrated Data Processing Addendum (DPA) to reflect system upgrades, infrastructure changes, or shifting regulatory requirements.
Provider shall notify Client of any material changes to data handling, table architectures, or data preservation limits via email or through an in-dashboard notification at least thirty (30) days prior to implementation of such updates.
Client's continued utilization of Clixerfy's Adfraud and Bot Blocker following the conclusion of the 30-day notice period shall constitute binding acceptance of the updated terms.
Clixerfy