Legal Agreement

Clixerfy MasterServices Agreement.

The terms governing access to and use of Clixerfy's Adfraud and Bot Blocker platform and related services.

Governing Law: Province of Ontario, CanadaOperating Entity: Toon Group Inc.

Provider

Toon Group Inc. (Clixerfy)

Governing Law

Ontario & Applicable Canadian Law

Billing Contact

billing@clixerfy.com

Agreement Between

Provider

Toon Group Inc.

Operating as Clixerfy, a corporation organized under the laws of the Province of Ontario, Canada.

Client

The Legal Entity

The legal entity registering for, accessing, or utilizing the services described in this Master Services Agreement.

Agreement Overview

Clear rules fora complex protection system.

Client-controlled settings

Operational thresholds, caching lifecycles, and restriction periods are configured directly by the Client.

Integrated data processing

The agreement includes data processing, anonymization, retention, and cross-border transfer provisions.

Third-party dependencies

Service performance may depend on external advertising platforms, APIs, technical limitations, and platform policies.

Section I

Commercial & Service Terms

01Commercial Terms

Scope of Service, User-Dictated Thresholds, and Configuration Auditing

Provider operates an automated cybersecurity, infrastructure optimization, and ad-fraud mitigation platform known as Clixerfy's Adfraud and Bot Blocker (the "Service").

The Service monitors network metrics and behavioral telemetry on Client's digital properties via an asynchronous tracking script to identify invalid interactions and programmatically sync exclusion lists with Client's connected digital advertising platforms, including Google Ads.

The Service categorizes traffic based on automated scoring models entirely governed by custom operational thresholds, caching lifecycles, and restriction lifespans configured directly by the Client within the user management panel (the "User-Dictated Configurations").

Client acknowledges and explicitly agrees that they assume sole operational, legal, and commercial liability for the selection, sensitivity limits, modifications, and enforcement parameters of these User-Dictated Configurations.

To maintain transparency and an immutable audit trail, the Service automatically transmits a formal electronic mail confirmation to the Client's registered administrative email account immediately upon any change, modification, or adjustment made to these User-Dictated Configurations, logging the exact technical modifications deployed.

02Commercial Terms

Free Trial, Pricing Tiers, and Subscription Activation

30-Day Free Trial

Client is entitled to a one-time, thirty (30) day free trial of the Service starting from the date of initial account registration. No fees shall be levied during this trial period.

Proactive Trial Auditing & Quote Issuance

Seven (7) days prior to the expiration of the 30-day free trial, Provider will audit Client's ongoing web traffic parameters and transmit a formal, custom subscription quote to the Client via email.

Subscription Activation

If Client accepts the custom quote, automated corporate billing will execute immediately upon the conclusion of the 30-day trial period, activating the paid subscription. Client may also independently select a standard public subscription tier at any time via the pricing panel.

Right to Freeze Services

If the Client fails to accept a custom quote or select a standard tier before the trial window expires, Provider retains the absolute right to freeze or suspend the Service at midnight on the 30th day of the trial. Provider explicitly disclaims all liability for any ad spend waste or malicious traffic occurred while the account is frozen.

Traffic Allocation & Overages

Fees are structured in tiers mapped to estimated website visitor volume. If Client's actual monthly traffic volume exceeds their selected tier threshold by more than fifteen percent (15%) for two consecutive billing cycles, Provider reserves the right to automatically adjust Client to the appropriate corresponding pricing tier for subsequent cycles.

Non-Refundability

Monthly subscription fees are billed in advance and are completely non-refundable.
03Commercial Terms

Price Adjustments

Right to Modify Fees

Provider reserves the right to increase subscription fees at any time by providing at least sixty (60) days' written notice to the Client.

Objection and Dispute Window

If Client does not agree to the proposed price increase, Client must explicitly notify Clixerfy's billing department via email at billing@clixerfy.com prior to the upcoming renewal date.

Effect of Cancellation Notice

Upon receipt of a valid cancellation email disputing a price increase, billing obligations and the Service will be paused and systematically terminated within thirty (30) days of the notification date.
04Commercial Terms

Invoicing, Non-Payment, and Service Suspension

Payment Terms

Invoices are generated monthly. Client must clear all outstanding invoices within the specific net-payment timeframe designated on the invoice.

Suspension for Non-Payment

If Client fails to pay any due invoice, Provider reserves the absolute right to immediately and without notice stop, disable, or suspend the Service. Provider explicitly disclaims any liability for ad spend waste or fraudulent traffic incurred by Client during a suspension period caused by non-payment.

Emergency Protective Suspension

Provider reserves the right to temporarily or permanently stop, limit, or suspend the Service at any time, with or without prior notice, if Provider detects network anomalies, security vulnerabilities, API system errors, or external threats, or otherwise deems it necessary to protect the Client's digital infrastructure, ad budget, or credentials.

Section II

Integrated Data Processing Addendum (DPA)

06Data Processing Addendum

Privacy Warranties & Purpose Limitation

Strict Purpose Limitation

Provider warrants that any network data harvested via Client's properties, including technical user metadata and Internet Protocol (IP) addresses, shall be processed exclusively for security verification, infrastructure defense, and fraud blocking via the Service.

No Commercial Exploitation

Provider is strictly prohibited from selling, renting, sharing, retaining, or repurposing Client's traffic data for cross-context behavioral advertising, retargeting, or the creation of cross-client commercial profiling networks.

Algorithmic Profiling Nature

The parties explicitly agree that any designation of a traffic signature as malicious or fraudulent is a technical, statistical, and probabilistic assessment only. It does not constitute a legal, criminal, or regulatory finding of fraud. False positives and false negatives will inherently occur.
07Data Processing Addendum

Volatile Processing and Edge-Anonymization Protocols

To maintain campaign protective integrity while ensuring compliance with global data minimization, anonymization, and storage limitation principles, Provider routes and maintains telemetry data through an automated, state-governed database pipeline dictated dynamically by the Client.

A

Transient Volatile Caching Layer (Redis)

Inbound network signatures containing full, unmasked personal data, specifically raw IP addresses and initial execution counters, are processed and stored strictly within a localized, volatile memory layer (Redis cache clusters) for an operational window customized directly by the Client during platform initialization.

All personal identification parameters written to this volatile tier are subject to a strict Time-To-Live (TTL) deletion script mapped exactly to the Client's user-selected configuration, ensuring raw identifiers are permanently and completely dissolved from system RAM automatically upon expiration of that specific window.
B

Evaluation Logging Layer (click_logs)

Complete traffic metadata is committed to a central master ledger table (click_logs) for multi-tenant trend analytics. Prior to database persistence, all inbound records are programmatically and permanently stripped of raw IP addresses and unique visitor identifiers at the software edge.

The resulting anonymous, non-identifiable feature matrices are retained for a maximum of ninety (91) days before absolute database purging. Because this persistent layer is entirely anonymous on arrival, it falls outside the scope of personal data processing under applicable global privacy laws and outside statutory data protection constraints.
C

Active Threat Enforcement Tier (ip_bans)

Network signatures that breach the frequency or temporal thresholds configured by the Client are classified as verified threats and written to an active restriction table (ip_bans) to execute automated ad network API exclusions.

The raw network signature is retained within this active partition exclusively for the duration of the active restriction window configured dynamically by the Client within the dashboard setup panel. This restricted operational lifespan is enforced solely to maintain live synchronization loops with third-party advertising platform APIs and defend Client infrastructure, after which the raw identifier is systematically deleted.
D

Inactive Threat Intelligence Tier (ip_ban_history)

Immediately upon expiration of the Client's custom active ban window within the ip_bans tier, the corresponding record transitions to a historic archive table (ip_ban_history).

The raw IP address and personal identifiers are permanently dropped upon entry into this table. The historical record stores exclusively non-identifiable threat attributes for a maximum duration of ninety (90) days following the conclusion of the active ban window, after which it is completely deleted from system disks.

Fully anonymized behavioral and environmental features extracted during any minimization phase contain zero personal information or tracking hashes and may be retained by Provider indefinitely to train machine learning models.
E

Mandatory Remediation (The Whitelist Override)

Client must maintain active review of their dashboard logs. If a legitimate user or trusted partner IP address is incorrectly flagged due to operational Threshold configurations, Client's sole remedy and immediate obligation is to execute a manual whitelist override via the Clixerfy dashboard to restore ad visibility to that network signature.
08Data Processing Addendum

Cross-Border Data Transfers & Frameworks

Client authorizes Provider to utilize secure global cloud infrastructure, including secure deployments through certified sub-processors, to transfer, store, and process technical metadata and network signatures.

Where European Union, EEA, or United Kingdom traffic is involved, the parties contractually incorporate the EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum into this agreement by reference to govern the transfer, unless Provider maintains active self-certification under the EU-U.S. Data Privacy Framework (DPF).

Where Canadian traffic is processed, Provider implements contractual safeguards ensuring a comparable level of data protection.

09Data Processing Addendum

Mandatory Breach Record Keeping & Reporting

72

Hours

Notification

Provider will notify Client within seventy-two (72) hours of discovery of a security breach involving Client data safeguards.

RROSH

Statutory Evaluation

Client assumes sole statutory responsibility for evaluating whether an incident meets the applicable Real Risk of Significant Harm threshold.

24

Months

Breach Records

Provider maintains records of platform security safeguard breaches for a minimum of twenty-four (24) months from discovery.

Real Risk of Significant Harm (RROSH)

Client assumes sole statutory responsibility for evaluating whether an incident meets the Real Risk of Significant Harm threshold under PIPEDA section 10.1 or provincial equivalents. Client is responsible for filing mandatory reports with the Office of the Privacy Commissioner of Canada (the "OPC") or relevant provincial regulators and notifying affected individuals.

24-Month Statutory Log

In compliance with PIPEDA's Breach of Security Safeguards Regulations, Provider will log and maintain records of all platform security safeguard breaches for a minimum of twenty-four (24) months from discovery, regardless of whether a risk threshold is met.

Section III

Indemnity, Liability, and Third-Party Dependencies

10Liability & Dependencies

Programmatic Access and Agency Authorization

Client hereby grants Provider a limited, non-exclusive, revocable license and express authorization to act as Client's technical agent for the sole, restricted purpose of accessing Client's connected digital advertising environments, such as Google Ads, via programmatic Application Programming Interfaces (APIs).

This authorization is granted exclusively to allow the Service to automatically and dynamically modify "IP Exclusion Lists," "Placement Exclusion Lists," and closely related targeting parameters to shield Client's advertising spend from flagged fraudulent traffic sources.

Client affirms that any automated modifications executed by the Service within Client's connected accounts are fully authorized, are executed on Client's behalf as their technical agent, and shall be legally treated as if executed directly by the Client.

11Liability & Dependencies

Third-Party Infrastructure and API Dependencies

Client explicitly acknowledges that the execution and performance of the Service relies fundamentally on third-party digital advertising platforms, including but not limited to Google Ads, their proprietary API ecosystems, network-enforced rate limits, system thresholds, and platform terms of service.

Disclaimer of Third-Party Fault

Provider shall not be held responsible, liable, or contractually deficient for any service interruptions, systemic outages, synchronization failures, enforcement delays, account suspensions, or API changes or deprecations initiated by these external third-party ad networks.

Operational Limits

Client accepts that programmatic blocks are subject to the technical limits imposed by the respective ad network, such as maximum allowable IP exclusions per account. Provider holds no obligation or liability should an ad network block fail due to reaching such third-party platform limitations.
12Liability & Dependencies

Limitation of Liability and False Positives Warranty

Client acknowledges that bot-detection and fraud auditing utilize complex probabilistic algorithms.

No Absolute Guarantee

Provider does not warrant that the Service will catch 100% of invalid traffic, nor that it will achieve zero "False Positives", including misclassifying a real human as a bot.

Limitation of Loss

Because the exclusion mechanism is invisible to the end-user and merely prevents an ad from appearing, Provider shall not be held liable for any alleged lost revenue, dropped conversion rates, or business interruption arising from accidental exclusions. Client's sole remedy is to manually override and whitelist any flagged network signature via the Clixerfy dashboard.

Cap on Damages

In no event shall Provider's cumulative aggregate financial liability exceed the total fees paid by Client to Provider during the three (3) months immediately preceding the event giving rise to liability.

13Liability & Dependencies

Indemnification Against Publisher Claims

Client agrees to defend, indemnify, and hold harmless Provider from any civil actions, losses, regulatory audits, or claims of Tortious Interference brought against Provider by third-party web publishers, website networks, or traffic channels resulting from placement or domain exclusions initiated by the Service on behalf of Client's ad accounts.

14Liability & Dependencies

Term, Termination, and Offboarding Obligations

Term

Subject to the trial, adjustment, and suspension terms above, this agreement operates on a month-to-month basis. Either party may terminate the agreement at any time by providing thirty (30) days' written notice or canceling through the account dashboard.

Mandatory Client Offboarding Duties

Upon termination or expiration of this agreement for any reason, the Client assumes sole and immediate responsibility for offboarding. Client must:

  • Manually revoke Provider's programmatic and user access permissions within their internal Google Ads user management system, console, or connected ad center.
  • Completely remove and delete the Clixerfy tracking and installation script from the source code of all digital properties.

Release of Liability

Provider ceases all API management upon the effective date of termination and holds zero liability for any configuration remnants, orphan scripts, or ad account security vulnerabilities if Client fails to execute these offboarding steps. Client data will be securely deleted within ninety (90) days following termination.
15Liability & Dependencies

Amendments and Modifications to Terms

Provider reserves the right to modify the technical, operational, and processing descriptions contained within this Agreement and its integrated Data Processing Addendum (DPA) to reflect system upgrades, infrastructure changes, or shifting regulatory requirements.

Provider shall notify Client of any material changes to data handling, table architectures, or data preservation limits via email or through an in-dashboard notification at least thirty (30) days prior to implementation of such updates.

Client's continued utilization of Clixerfy's Adfraud and Bot Blocker following the conclusion of the 30-day notice period shall constitute binding acceptance of the updated terms.

Clixerfy

Clear terms for smarter campaign protection.

Back to Clixerfy