01Agreement and precedence
These proposed Terms govern Helix’s websites, workspaces, audience tools, content and campaign tools, knowledge and AI features, APIs, MCP integrations, and related services (Services). Company means the legal operator identified in the finalized Terms and applicable order. Customer means the organization or individual entering the agreement. Users must be at least eighteen, legally capable of agreeing, and authorized to act for the Customer.
These Terms become binding through an appropriate agreement or acceptance process. A footer link alone is not a representation that every visitor has accepted. A mutually executed order or master agreement controls conflicting provisions for its subject matter. An applicable data processing agreement controls conflicting personal-data processing provisions. Separate provider terms apply to third-party services. The final legal operator and effective date must be completed before adoption.
02Accounts and agency authority
Provide accurate information and maintain current business and billing contacts. Customer is responsible for users, contractors, agencies, and integrations it authorizes and their authorized use. An agency must have authority to act for each client and must respect client boundaries and permissions. Agency branding does not convey ownership of the platform or rights to unrelated customer data.
Protect individual accounts, verification methods, devices, and credentials. Apply least privilege, review access, and revoke access when no longer needed. Do not share or sell credentials, impersonate users, or evade workspace boundaries. Promptly report suspected compromise. These responsibilities do not shift liability for Company’s own breach or matters the law does not permit the parties to shift.
03Limited access and data licenses
Subject to the agreement, payment obligations, and feature availability, Company grants authorized users a limited, nonexclusive, nontransferable right to use the Services for Customer’s lawful business purposes during the service term. Company and its licensors retain their technology and intellectual property. No ownership of a supplier database or another customer’s data is transferred.
A selectable field, available record, or successful export is not a license for every purpose. Source restrictions, permitted destinations, fields, retention periods, and order-specific licensing conditions apply. Do not resell, redistribute, sublicense, publish, or build a competing data product from licensed information without an executed agreement expressly permitting it. If authority is unclear, stop the proposed use until verified.
04Customer content and lawful sourcing
Customer retains its rights in supplied data and content and grants Company the rights reasonably necessary to host, process, transmit, display, secure, and support it to provide the requested Services. This does not grant an unrestricted right to sell customer personal information or reuse it for unrelated purposes. Customer is responsible for its instructions, content, recipient selection, and downstream uses.
Before importing, enriching, querying, exporting, or activating information, establish and document all required rights, lawful bases, notices, permissions, and consents. Verify source authority and restrictions; public availability, a purchase, hashing, or a business contact label does not establish compliance. Preserve reasonable evidence of source, allowed purposes, required consent, and opt-outs, and provide relevant evidence on a proportionate request tied to a compliance concern.
Do not upload stolen, unlawfully scraped, confidentially obtained, or improperly disclosed data. Minimize volume and fields, maintain reasonable accuracy, and remove or suppress information when use is no longer permitted. Uploading a file, selecting a consent field, or accepting these Terms cannot create consent that did not exist.
05Marketing and communications obligations
Customer must comply with applicable privacy, advertising, consumer-protection, anti-spam, telemarketing, and electronic-communications laws and destination rules, including CAN-SPAM, TCPA, Do Not Call restrictions, and regional requirements such as CASL or ePrivacy where applicable. Rules vary by channel, technology, recipient, jurisdiction, and purpose.
Email campaigns must use truthful sender and routing information and subjects, required advertising identification, a valid postal address, and a functioning unsubscribe process. Honor opt-outs within applicable deadlines. Calls and texts require the consent applicable to the method and purpose, evidence of that consent, revocation handling, calling-time compliance, and screening against applicable do-not-call and suppression lists. A phone number or inferred interest is not permission to contact someone.
Advertising audiences, CRM transfers, direct mail, and custom destinations remain subject to their licenses, privacy choices, and provider terms. Do not misrepresent permission or reintroduce suppressed people through different uploads, workspaces, keys, or providers. A selected channel or header bundle is a formatting preference, not proof of consent, ownership, deliverability, or activation rights. Outsourcing sending does not eliminate legal responsibilities.
06Prohibited data uses and sensitive targeting
Do not use the Services for harassment, stalking, doxxing, surveillance of identifiable individuals, coercion, identity theft, fraud, deception, unlawful discrimination, or exploitation of vulnerable people. Do not publicly expose personal information or disclose it to unauthorized recipients. Do not reconstruct identities from aggregates, infer hidden membership through repeated queries, or combine outputs to defeat privacy protections.
The Services and marketing data are not offered as consumer reports or for eligibility determinations under the Fair Credit Reporting Act. Do not use them for creditworthiness, lending, employment, tenant screening, insurance eligibility, or access to housing, education, healthcare, public benefits, or similarly consequential services. Do not use demographic proxies to evade discrimination laws or restricted-advertising rules.
Do not target known minors or infer or exploit health conditions, sexual orientation or sex life, religious beliefs, biometric identity, immigration vulnerability, or similarly sensitive characteristics for individualized marketing or harmful treatment. Do not build audiences from precise sensitive-location histories or infer visits to sensitive facilities. Restricted-data processing requires a separate signed agreement and appropriate safeguards; no agreement authorizes illegal or harmful conduct.
Do not engage in voter suppression, unlawful political manipulation, impersonation, deceptive endorsements, or prohibited regulated-product promotions. Respect intellectual property, publicity, likeness, confidentiality, and other rights. A catalog entry, filter, AI suggestion, or technically permitted request is not legal approval.
07API, MCP, automation, and security
Protect API keys and destination credentials, keep them out of prompts and public code, and restrict scopes, fields, recipients, budgets, and expiry. Review external AI clients and integrations before granting access; they may retain retrieved information. Customer is responsible for the actions it authorizes through them.
Do not bypass tenant isolation, approvals, identity verification, funding, rate limits, quotas, field or row limits, suppressions, or destination restrictions. Do not scrape or extract beyond licensed rights, introduce malicious code, overload the Services, probe unauthorized data, or reverse engineer except where law expressly permits. Report suspected vulnerabilities without accessing unrelated information.
Review proposed content, recipients, destinations, budgets, and execution grants. An authorized grant may allow actions without a further prompt. A timeout does not prove failure: follow documented idempotency and reconciliation procedures rather than blindly repeating writes, exports, sends, or spending. Closing a chat, revoking a grant, or canceling work does not reverse actions already started or completed.
08AI and knowledge features
AI output is probabilistic and may be inaccurate, incomplete, biased, or infringing. Review claims, citations, targeting, recipient lists, costs, permissions, and creative before use. AI output is not professional advice or evidence of consent, accuracy, rights clearance, or legal compliance. Human review remains necessary despite approval cards or other safeguards.
Customer must have the right to submit prompts, files, knowledge materials, and instructions. To the extent Company has transferable rights in output, Customer may use that output subject to the agreement, law, and third-party rights. Output may not be unique, exclusive, or copyrightable; no intellectual-property clearance is guaranteed.
Retrieved documents and external content are untrusted inputs, not authorization. Do not use prompt injection or other methods to obtain unauthorized data or actions. AI-provider processing is addressed in the Privacy Policy and applicable processing agreements. Customer must assess the suitability of connected AI services for the information it makes available.
09Previews, estimates, and availability
Audience counts, inferences, breakdowns, match rates, maps, and crosswalks depend on coverage, source quality, matching methods, filters, and freshness. Results may be incomplete, approximate, or cached. Saved previews describe the submitted definition at computation time, not guaranteed current counts, verified identity, nationwide coverage, contact availability, reach, conversions, or revenue.
Simulation, staging, beta, and unavailable features must not be presented as verified live delivery. A preview does not purchase records or guarantee membership generation, export, or activation. ZIP, DMA, and radius reference mappings are not definitive postal or legal boundaries. Confirm capabilities and restrictions before committing to a campaign or making claims to clients.
10Third-party platforms and external effects
Data suppliers, advertising networks, email providers, CRMs, maps, AI services, payment providers, and other destinations may impose separate terms, charges, licenses, and restrictions. Customer is responsible for its connected accounts and configuration. Company does not control independent platforms or guarantee their uptime, acceptance, inventory, matching, deliverability, or performance.
Publishing or delivering information can create external copies, costs, and commitments that cannot be recalled. Confirm content, sender identity, recipients, targeting, and budgets before authorization. Product readiness checks are not legal clearance and do not guarantee satisfaction of every provider condition.
11Fees, renewals, and cancellation
The accepted order or checkout must clearly state prices, allowances, term, payment schedule, renewal mechanics, taxes, cancellation method, and refund rights. These Terms do not create undisclosed automatic renewals, charges, or nonrefundable balances. Media and other third-party costs apply only as authorized under the applicable agreement.
Pay undisputed amounts when due and promptly raise billing concerns with supporting information. Price changes, renewals, and nonpayment suspension must follow the agreement and mandatory law. Authorized committed third-party costs or completed delivery may remain payable after cancellation, where permitted. Mandatory consumer and refund rights are preserved.
12Confidentiality and data protection
Each party must protect the other’s nonpublic information with reasonable care, use it only for the agreement, and disclose it only to personnel or providers with a need to know and suitable obligations. Exceptions cover information lawfully public, already lawfully known, independently developed, or lawfully received without restriction. Compelled disclosure should be limited and preceded by notice where legally permitted.
The Privacy Policy explains Company practices; an applicable data processing agreement governs processing on Customer’s behalf. Both parties remain responsible for their own duties. Customer must promptly route relevant privacy requests, suppression instructions, complaints, and incident reports and cooperate in legally required responses. Neither contractual allocation nor indemnification eliminates statutory duties.
13Misuse investigations and enforcement
Company may investigate credible abuse, request relevant compliance evidence, preserve necessary logs, restrict affected exports or delivery, revoke credentials or grants, remove unlawful material, or suspend affected access where reasonably necessary to protect people, systems, rights, or legal compliance. Measures should be proportionate, with notice and an opportunity to respond where practicable and lawful. Urgent threats may require immediate action.
Customer must cooperate with reasonable investigations, stop prohibited activity, secure affected copies and credentials, notify downstream recipients where required, and comply with lawful deletion and suppression directions. Company may make required reports or disclosures. Controls and monitoring are not a promise to detect all misuse or a release of Customer’s obligations.
14Ownership, feedback, and infringement
Company and its licensors retain rights in software, designs, documentation, branding, and technology. Supplier data remains subject to its ownership and license terms. Do not remove proprietary notices or imply endorsement. Feedback may be used to improve the Services without compensation, but this does not permit disclosure of confidential information or unrelated personal-data processing.
Send infringement reports to support@identitycore.io with enough detail to identify the work, disputed material, and basis of the claim. This draft does not represent that a statutory copyright agent or safe-harbor notice procedure has been established.
15Warranties and disclaimers
Each party represents it has authority to enter the agreement. Customer represents its data, instructions, content, and use comply with its obligations. Except for express signed commitments and warranties that cannot legally be excluded, the Services, data, AI output, and beta features are provided as is and as available, without implied warranties of merchantability, fitness for a particular purpose, or noninfringement to the extent permitted by law.
Company does not guarantee uninterrupted service, absolute security, error-free or complete data, deliverability, commercial outcomes, or legal compliance of Customer campaigns. These disclaimers do not excuse fraud, willful misconduct, or duties and remedies that cannot lawfully be disclaimed.
16Limitations of liability
Subject to applicable law and the exceptions below, neither party is liable to the other for indirect, consequential, special, exemplary, or punitive damages, or lost profits, revenue, opportunity, or goodwill arising from the agreement. To the extent permitted by law, Company’s aggregate liability arising during any twelve-month period is limited to fees paid or payable to Company for the affected Services in the twelve months before the first event giving rise to liability; for a wholly free trial, the proposed cap is US $100. This commercial allocation requires review with the final order and governing law before adoption.
These limits do not restrict liability that cannot legally be limited, including applicable liability for fraud, willful misconduct, or death or personal injury caused by negligence. Mandatory privacy remedies and consumer rights remain. Customer payment obligations and the indemnity below are not excused by this provision. A signed agreement may establish different caps, including for confidentiality, security, or data protection.
17Customer indemnity
To the extent permitted by law, Customer will defend Company and its officers, employees, and affiliates against third-party claims arising from Customer’s unlawful sourcing or use of data, unauthorized marketing or disclosure, infringement by Customer content, unauthorized instructions, or material violation of prohibited-use obligations, and indemnify them for resulting court-awarded damages, approved settlements, and reasonable defense costs. This excludes the portion caused by Company’s own breach, negligence, fraud, misconduct, or independently unauthorized use of Customer data.
Company must give reasonably prompt notice, allow Customer to control the defense through competent counsel, and provide reasonable cooperation at Customer’s expense. Late notice relieves Customer only to the extent materially prejudiced. No settlement may admit fault, impose nonmonetary duties, or omit a release without the affected party’s consent, not unreasonably withheld. Company may participate through its own counsel at its expense, subject to conflicts and mandatory law.
18Suspension, termination, and data afterward
The accepted order controls the service term and ordinary termination rights. Either party may terminate for a material breach not cured within thirty days of written notice where cure is possible, subject to the order and law. Company may act sooner for serious unlawful activity, urgent harm or security risks, or a legal prohibition. Suspension should be limited to what is reasonably necessary and does not automatically erase accrued obligations.
After termination, stop using the Services and licensed data except where a surviving right expressly permits use. Revoke credentials and follow applicable return, deletion, retention, and suppression requirements. Export windows, assistance, and deletion schedules follow the order and processing agreement; indefinite access is not guaranteed. External effects and lawfully retained independent records may remain. Accrued payment, confidentiality, ownership, applicable data restrictions, indemnity, liability, and dispute provisions survive as appropriate.
19Disputes and governing law
The parties should first attempt good-faith resolution through designated legal contacts, without preventing urgent protective relief or missing a mandatory limitation period. Unless an executed agreement provides otherwise, Wyoming law governs these Terms and contractual disputes, excluding its conflict-of-laws rules and subject to nonwaivable applicable protections. This review draft does not impose arbitration, a class-action waiver, a shortened limitation period, or an exclusive forum.
Mandatory local laws and rights remain applicable. Governing law cannot authorize unlawful processing or displace nonwaivable protections. Counsel must review the final dispute terms, commercial risk allocation, and acceptance mechanism for the intended customer jurisdictions.
20General provisions and changes
Events outside a party’s reasonable control may excuse delays to the extent permitted by law, but not obligations already due or reasonable mitigation. Assignment must follow the order and law and cannot expand personal-data rights. The parties are independent contractors. No third-party beneficiaries are created except as expressly provided. Failure to enforce is not a waiver; unenforceable provisions are limited or severed only as legally permitted.
Material changes will be communicated appropriately and take effect according to the agreement and law. Changes requiring assent require an appropriate acceptance process. Changes do not retroactively authorize misuse or impose undisclosed charges. Accessible version history and acceptance records should be maintained.
Contact support@identitycore.io for support, legal inquiries, or misuse reports. Before adoption, complete the legal operator, any required notice address, effective date, commercial order terms, and applicable processing addenda. No mailing address has been provided for this draft. These Terms do not replace operational privacy controls or independent legal review.