Contracting company: DSLS PARTNERS LTD, a private limited company incorporated in Cyprus under company number HE 488020, with registered office at Chrysanthou Mylona 1, Panayides Building, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus (“OnStat”, “we”, “us”).
1. Agreement and business use
These Terms govern access to OnStat’s hosted software, browser extension, APIs, dashboards, analytics, automation, support, and related services (the “Service”). The entity or person accepting these Terms for business or professional purposes is the “Customer”.
The agreement consists of these Terms, an applicable order form or online checkout (“Order Form”), the Data Processing Addendum, and any Security Measures made available to Customer with the DPA or Order Form (collectively, the “Agreement”).
DSLS PARTNERS LTD is the sole OnStat contracting party under the standard Agreement. A reference to an affiliate does not make that affiliate a contracting party or transfer an OnStat obligation to it. Another entity becomes a contracting party only if a separately signed Order Form or amendment expressly identifies that entity and its role.
The Service is offered only for business or professional use. An individual creator may contract only in the course of that individual’s trade or profession and represents that consumer-protection rights applicable to personal or household purchases do not apply. If OnStat elects to serve consumers, it must issue separate consumer terms before doing so.
The person accepting the Agreement represents that they are at least 18 years old, have legal capacity, and have authority to bind the Customer. If they lack that authority, they must not accept or use the Service.
2. Order of precedence
If documents conflict, the following order applies:
- the DPA controls for processing of personal data;
- a signed Order Form controls for its commercial terms;
- the Security Measures control for expressly committed technical and organizational safeguards;
- these Terms.
An Order Form will not reduce a mandatory data-protection obligation unless the DPA expressly permits it and applicable law allows it.
3. Accounts, tenants, and authorized users
Customer must provide accurate registration information, keep it current, protect all credentials and connected-platform sessions, and immediately report suspected compromise. Customer is responsible for configuring roles according to least privilege and for the acts and omissions of its employees, contractors, agency personnel, chatters, and other users (“Authorized Users”).
Customer must not share a named user account. OnStat may require multi-factor authentication, account re-verification, beneficial-owner or authority information, or additional security steps where risk warrants. Customer must promptly remove users whose authority ends.
The Service is multi-tenant. Customer may access only its own tenant and accounts it is lawfully authorized to manage.
If Customer creates a partner, chatter, or other Shared Portal link, Customer must disclose whether the portal is read-only or action-capable, select the minimum fields and actions, identify the intended recipient, deliver the link securely, monitor use, and revoke it promptly when the relationship or authority ends or compromise is suspected. A read-only partner link may remain active while the underlying partner relationship remains active; action-capable access may require a shorter validity period and additional authentication. Customer may deactivate a partner link through the applicable workspace control. OnStat may record the authorized actor, time, affected link/partner, and stated reason as minimized security and contract-administration evidence. OnStat may remind the Customer every 90 days to review active read-only partner links; failure to respond to a reminder does not itself deactivate an otherwise active link. Portal Users are subject to the Shared Portal Access Terms and Privacy Notice. Customer remains responsible for its contracts, commissions, payouts, employment/contractor status, notices, and disputes with Portal Users.
4. Service license and documentation
During the subscription term and subject to the Agreement, OnStat grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service for Customer’s internal business operations. Customer may permit Authorized Users and contracted agencies to use the Service only under Customer’s control and subject to terms no less protective than the Agreement.
OnStat may update the Service and documentation. We will not materially reduce the core functionality of a paid Order Form during its then-current committed term without reasonable notice, except where necessary for security, law, or third-party platform changes.
Beta, preview, and experimental functionality may be changed or withdrawn at any time, may be less secure or reliable, and is provided without a service-level commitment unless an Order Form says otherwise.
API keys, OAuth, MCP connections, connectors, tools, webhooks, exports, and other machine-to-machine interfaces (“Developer Interfaces”) may expose Customer Data to a Customer-selected external recipient. Where a Developer Interface offers technical scopes, they are access and downstream-disclosure controls; they do not replace Customer’s authority, lawful basis, notices, contracts, platform permission, or assessment of that recipient. An API key without narrower displayed scopes must be treated as a privileged tenant credential and disclosed only to a recipient authorized for that level of access.
Customer must permit only an authorized owner or administrator to create credentials; use unique credentials for each integration and environment; store secrets securely; grant the minimum accounts, data categories, permissions, and duration necessary; review active connections; and promptly rotate or revoke credentials after personnel, vendor, purpose, or security changes. Customer must not use prompt injection, tool chaining, fabricated identifiers, repeated queries, or another technique to evade scopes, query bounds, approval steps, rate limits, or safety controls.
When Customer selects ChatGPT, Claude, another AI workspace, agent, or external client, Customer is responsible for that recipient’s terms, privacy practices, transfers, retention, security, model-training settings, personnel access, and deletion controls. Unless OnStat separately appoints the recipient as its subprocessor, it is Customer’s recipient and not an OnStat subprocessor. Revoking an OnStat connection stops future authorized access but does not delete copies, logs, conversation history, memory, embeddings, or outputs already held by Customer or the recipient.
OnStat may enforce live role and account checks, available scope and field allowlists, expiry, pagination, query limits, rate limits, and logging. The standard confirmation model does not add a separate confirmation to read-only analytics or ordinary low-impact product actions. It requires an action-specific confirmation before an immediate financial, destructive, externally visible publication, mass-message, or similarly high-impact action.
Customer approval when an automation is first enabled, and again after a material change to its action, trigger, account scope, recipients, limits, or duration, authorizes executions within that recorded configuration without a confirmation before every execution. It does not authorize an action outside the configuration or a category that OnStat has not approved for automation. OnStat may require additional review, step-up authentication, approval, or human confirmation where risk warrants and may reject, reduce, revoke, or suspend an interface immediately for security, law, platform requirements, capacity, suspected misuse, or loss of authority. “Read-only” means the interface is not intended to trigger an external write; it does not mean returned data is non-sensitive.
5. Connected creator-platform accounts
5.1 Customer authority
Before connecting an account, Customer must:
- be the account owner or possess current, documented authority from the account owner;
- ensure that the owner is an adult and that all persons whose content or communications are managed are adults and have provided all legally required consents and releases;
- if Customer is not the account owner, maintain a valid written agreement or other reasonable evidence authorizing Customer to manage the account, appoint OnStat and its subprocessors, and instruct the enabled processing;
- ensure its agreement with the account owner covers the relevant access, personnel, subprocessors, data uses, actions, compensation, termination, and return of control; and
- ensure that each Authorized User is permitted to perform the enabled actions.
At connection, Customer must make the following per-account attestation, or an equivalent attestation displayed in the Service:
I confirm that I am the creator/account owner or have a current written agreement authorizing me to manage this account, appoint OnStat and its subprocessors, and provide instructions for the features I enable. I will maintain reasonable evidence of this authority and provide sufficient redacted evidence on OnStat’s reasonable request.
OnStat does not require Customer to upload a creator agreement or separate authorization form in the ordinary course of onboarding. Customer may use its own agreement or other reasonable evidence, provided it adequately documents Customer’s authority to manage the account, appoint OnStat and its subprocessors, and authorize relevant personnel.
OnStat may request sufficient, appropriately redacted evidence where an account owner disputes Customer’s authority, account ownership or Customer’s authority materially changes, OnStat receives a platform, regulatory, or legal notice, or other reasonable grounds indicate that the authorization may be invalid, expired, or insufficient. OnStat may refuse, restrict, suspend, or disconnect the affected account until the issue is resolved.
5.2 Separate platform permission
OnStat is an independent third-party management and analytics service used with creator-authorized accounts. OnStat is not affiliated with or endorsed by OnlyFans. Customers must comply with applicable platform terms. OnStat may restrict or disable functionality in response to platform requirements, security controls, or legal risk.
Customer authority over a creator account does not establish that the creator platform permits the Service, automated access, session sharing, private endpoints, browser extensions, proxies, data extraction, messaging, or other enabled conduct.
Customer must independently comply with every connected platform’s current terms, policies, technical limits, and applicable law. Customer must not use the Service where doing so is prohibited. Customer must stop using an integration if permission or authority ends, the platform objects, or the account is suspended, and must not use proxies, altered tokens, signatures, rotated identities, or automation to evade a platform restriction, CAPTCHA, rate limit, or security control.
OnStat does not warrant that a connected platform has approved the Service or that a connection will remain available. OnStat may impose rate limits, disable functionality, or terminate a connection immediately where needed to respect a platform restriction, protect users, or reduce legal or security risk.
5.3 Customer-controlled actions
The Service can send messages, change lists, configure campaigns, create or update posts and promotions, and perform other actions through connected accounts. Customer determines whether, when, and for whom these functions are enabled and remains responsible for the business purpose, recipients, content, timing, legal basis, platform permission, and human oversight.
As between the parties, when Customer or an Authorized User composes, approves, schedules, or configures a message, publication, or connected-account action for execution through the Service, Customer is the initiating sender, publisher, or account operator for that action. Customer must identify the relevant creator, agency, personnel, or automation where law or platform rules require it. This allocation does not override the factual legal characterization of an activity or exclude responsibility OnStat has for its own conduct, processing, or product design.
Performance of a Customer-configured action through the Service does not eliminate any responsibility OnStat has under applicable law or the Agreement.
5.4 Feature configuration as Customer instruction
By enabling, configuring, or using a Service feature—including analytics, messaging, account actions, campaigns, attribution, automation, or AI functionality—Customer instructs OnStat to process Customer Data and, where applicable, perform the actions selected by Customer through that feature.
For an approved automation, Customer's affirmative enablement and each affirmative approval of a material configuration change are Customer's documented instructions for later executions within the recorded action, trigger, account scope, recipients, limits, and duration. Customer must review those elements before approval, keep the configuration current, and disable the automation promptly when the instruction or authority ends.
An immediate financial, destructive, externally visible publication, mass-message, or similarly high-impact action requires an Authorized User to review the material action details and confirm execution, unless the action occurs within a previously approved automation that OnStat has expressly made eligible for that execution model. This confirmation is an operational instruction and safety control, not consent on behalf of a fan, visitor, or other data subject.
Customer is responsible for ensuring that it has the authority, lawful basis, notices, consents, contracts, and platform permissions required for the feature, its data, its recipients, and the selected actions. A feature instruction does not expand Customer’s underlying authority or replace a notice or consent that Customer must obtain from a creator, fan, message participant, website visitor, or other person.
OnStat may provide a feature-specific notice or require an additional confirmation where a feature introduces a materially different purpose, recipient, data category, or risk. This includes Dialogs AI transfer of private message text to an external model provider. A Customer user deliberately starts each Dialogs AI summary or question; enabling general analytics alone does not submit private messages to a model provider. Non-essential analytics or attribution cookies remain subject to any consent or opt-out required from the relevant website visitor.
5.5 Customer-selected advertising and postback integrations
Customer may configure the Service to transmit click, conversion, attribution, or related events server-to-server to Meta, Google, TikTok, X, Keitaro, or another advertising, analytics, or postback recipient selected and credentialed by Customer. Enabling, configuring, or using such an integration is Customer's documented instruction to make the selected transmissions. As between the parties, Customer determines the recipient, campaign, event mapping, business purpose, and use of the recipient account and is responsible for the recipient's terms, privacy role, lawful basis, notices, consents or opt-outs, international transfers, and restrictions on advertising or sensitive data.
For Customer Personal Data processed and transmitted solely under that Customer configuration, Customer is the Controller and OnStat acts as Customer's Processor in accordance with the DPA. If Customer acts for another Controller, Customer is the Processor and OnStat is its Subprocessor. These contractual labels do not override a different role that mandatory law assigns based on the parties' actual conduct. Customer's obligations in this Section are material obligations under the Agreement, and Section 16.1 applies to covered claims arising from Customer's integration, event selection, recipient, instruction, missing notice or consent, unlawful basis, platform breach, or prohibited data.
Under OnStat's standard campaign-redirect design, the redirect must not create _fbp,
_fbc, or another advertising identifier in the visitor's browser. The Service may process
platform click identifiers already carried in the requested URL, an OnStat-generated event
identifier, timestamp, IP address, user agent, and other allowlisted event fields to perform
Customer's configured server-to-server transmission. The absence of an OnStat-created
browser cookie does not establish that consent, notice, an opt-out, or another legal basis is
unnecessary for Customer's tracking link or onward transmission.
Customer must not instruct or configure an advertising or postback recipient to receive raw
creator-platform account, creator, or fan identifiers; message or media content; detailed
adult-platform activity labels; complete URLs or unfiltered query parameters; or other data
that Customer knows or reasonably should know the recipient prohibits or treats as
sensitive. Generic event names such as PageView, Lead, Subscribe, or Purchase do not
remove Customer's obligation to assess whether the event is sensitive in context. OnStat
may omit, generalize, block, or stop a field, event, recipient, or integration where needed
for minimization, security, law, platform requirements, or legal risk.
OnStat may immediately restrict, pause, or disable an advertising or postback integration in response to a complaint or objection from an individual, a platform or recipient request, a regulatory or legal notice, a security incident, suspected prohibited data, or another reasonable legal or platform risk. Where practicable and lawful, OnStat will notify Customer and scope the action to the affected field, event, campaign, recipient, or integration.
6. Customer Data
“Customer Data” means information, content, credentials, communications, personal data, configuration, and other material submitted to or collected through the Service on Customer’s behalf. As between the parties, Customer retains its rights in Customer Data. Neither party obtains ownership of data belonging to a connected platform or another person merely because the Service accesses, processes, or calculates results from that data.
Customer grants OnStat and its subprocessors a limited right to host, copy, transmit, transform, analyze, and otherwise process Customer Data only to provide, secure, support, and terminate the Service in accordance with the Agreement and documented Customer instructions.
The standard Service does not accept or persist original adult photo or video files from a connected creator platform. It may process media identifiers and metadata, store minimized thumbnails or technical previews needed for an authorized product view, and temporarily proxy media bytes without persistent storage. Thumbnails and previews remain private Customer Data and may be retrieved only after an Authorized User's tenant and account permissions are verified. If OnStat uses an expiring signed delivery URL, it is issued only after that authorization check and does not make the media public.
Customer must not use the Service, a Shared Portal, an export, a media URL, or another feature as a public adult-content gallery, public file host, or general content-distribution service. OnStat will not introduce persistent storage of original adult media or public adult-media delivery without a separate product, security, privacy, content-safety, and legal review and an updated Agreement where required.
“Customer-Specific Outputs” means dashboards, reports, calculated metrics, scores, predictions, and similar results generated for Customer solely from Customer Data. Subject to law and third-party rights, Customer may use Customer-Specific Outputs for its business. Customer retains whatever rights it lawfully holds in Customer Data and Customer-contributed configurations, labels, templates, and content. OnStat retains all rights in the Service, software, models, algorithms, formulas, methods, schemas, visualizations, generic templates, and other Service components used to generate or present those outputs. Customer-Specific Outputs do not include cross-customer benchmarks or Service Data.
“Service Data” means operational telemetry, security records, billing measurements, and statistics about the performance and use of the Service, excluding Customer Data. OnStat may use Service Data to operate, secure, bill, support, and improve the Service in accordance with the Privacy Notice.
OnStat will not use identifiable or pseudonymous Customer Data for cross-customer benchmarking, generalized product improvement, or cross-customer model training unless Customer enters a separate written opt-in agreement that identifies the data, purpose, rights, retention, and withdrawal terms. OnStat may use statistics derived from Customer Data for those purposes without a separate opt-in only where OnStat has demonstrated that the statistics are anonymized so that neither Customer nor an individual is reasonably identifiable; pseudonymized data is not treated as anonymous. OnStat will not train or fine-tune a cross-customer generative model on Customer Data without that separate written opt-in.
Customer represents and warrants that:
- it has all rights, notices, lawful bases, consents, contracts, and platform permissions necessary for Customer Data and the instructed processing;
- its instructions comply with law and do not infringe another person’s rights;
- it has assessed heightened requirements for data revealing sex life, sexual orientation, adult-industry participation, financial activity, or private communications;
- it will provide data subjects with required notices and mechanisms to exercise rights; and
- it will not instruct OnStat to retain or process data beyond what is necessary.
The standard Service may calculate operational analytics and create Customer-configured groups using subscription status, purchases, spend, message or account activity, engagement, and similar service-use information. It is not designed or licensed to infer, label, score, rank, segment, target, or predict an individual's sex life, sexual orientation, health, biometric identity, ethnicity, beliefs, or another special-category or comparably sensitive characteristic. Customer must not configure, prompt, query, label, or combine Service features to create such a sensitive profile, even where source messages, notes, profiles, or purchases contain or imply the characteristic.
Incidental presence of sensitive information in Customer Data does not by itself make that information a permitted targeting or profiling field. OnStat will process incidentally included sensitive information only to provide the Customer-configured feature under the DPA and will not use it for OnStat advertising, cross-customer analytics, generalized model training, or another independent commercial purpose. Customer remains responsible for its Article 6 legal basis and, where applicable, Article 9 condition. Sensitive profiling may be introduced only after a separate legal and product review, documented lawful basis and safeguards, required DPIA and notices, a signed written agreement, and any product controls OnStat requires.
OnStat may reject an instruction that it reasonably believes violates law, the Agreement, a person’s safety, or a third party’s rights. If the issue cannot be resolved, OnStat may suspend the affected processing.
7. Data protection and security
For personal data that OnStat processes on Customer’s documented instructions, the DPA applies. OnStat acts as an independent controller for its own account administration, billing, tax, security, fraud prevention, support, legal compliance, and marketing purposes, as described in the Privacy Notice. Legal roles depend on actual processing and are not changed by labels alone.
Customer must use the Service in a manner consistent with its own privacy notices, records of processing, data-protection impact assessments, retention rules, and data-subject request procedures.
For creators, fans, subscribers, purchasers, message participants, campaign visitors, and other individuals represented in Customer Data, Customer is responsible for providing every privacy notice required from Customer as Controller, including any notice required where Customer obtains personal data from a connected platform or another source rather than directly from the individual. Customer may provide that information through its own creator- or agency-level privacy notice or another lawful and reasonably accessible channel, provided the notice is timely, accurate, sufficiently specific to the enabled processing, and kept current. Customer must identify itself as the responsible Controller, provide a working rights-contact route, and describe the relevant data sources, purposes, legal bases, recipient categories, transfers, retention, profiling or automation, sensitive-data processing, and individual rights to the extent applicable law requires.
OnStat does not ordinarily deliver Customer's Controller notice to, or collect a separate authorization form from, each individual represented in Customer Data. Customer must not assume that lack of direct contact, operational inconvenience, a platform's own privacy notice, or another market participant's practice removes Customer's transparency duties. If Customer relies on a statutory exception to an individual-notice requirement, Customer must document why the exception applies and any protective steps the law requires. OnStat will make its own Privacy Notice available and assist Customer with rights requests as required by the DPA. Nothing in this allocation excludes responsibility imposed directly on OnStat for its own acts or omissions.
OnStat will maintain the safeguards stated in the Security Measures. No online system is completely secure, and Customer remains responsible for endpoint security, role configuration, connected-platform credentials, exports, and copies outside the Service.
8. AI and automation
AI Analytics may send a user question, schema and tenant/account context, generated query material, aggregate results, and limited sample rows to a disclosed model provider. Dialogs AI may send private creator/fan message text to that provider and store answers and citations. Customer must use the narrowest necessary accounts, date range, fields, samples, and message scope.
Dialogs AI is not triggered merely because general analytics is enabled. A Customer user must deliberately request a Dialogs AI summary or answer, and the interface identifies that private-message text may be sent to an external model provider. OnStat may introduce a separate versioned activation record or require renewed confirmation for a materially different provider, purpose, data category, or retention position.
Customer must keep a qualified human in control, review prompts, sources, generated SQL, outputs, recipients, and proposed actions, and maintain a way to pause or correct automation. Customer must not use the Service to make solely automated decisions that produce legal or similarly significant effects on an individual; determine employment, credit, housing, insurance, healthcare, immigration, age, identity, or consent; expose credentials, government IDs, biometric data, suspected illegal content, or unnecessary sensitive data to a model; or impersonate a creator in a materially deceptive manner.
AI outputs may be inaccurate, incomplete, biased, or unsuitable. They are not legal, medical, financial, tax, employment, or identity/age-verification advice. Customer must provide legally required AI interaction, generated-content, profiling, and automation notices to affected people. OnStat will not train or fine-tune a cross-customer generative model on Customer Data without a separate express written opt-in identifying the data, purpose, model, rights, security, retention, withdrawal, and benefit.
9. Acceptable use
Customer must not:
- reverse engineer, copy, resell, lease, or provide the Service as a service bureau, except for an authorized agency’s management of its contracted creators;
- access an account, tenant, endpoint, message, database, or data without current authority;
- bypass authentication, CAPTCHAs, device binding, geographical restrictions, rate limits, platform suspensions, access controls, or other security measures;
- share, buy, sell, or traffic in credentials, sessions, tokens, signing material, or compromised accounts;
- probe or disrupt the Service, introduce malicious code or abusive load, exploit a vulnerability, or interfere with logs, attribution, notices, or safety controls;
- connect, manage, message for, market, monetize, identify, sexualize, contact, profile, or target a person under 18, or upload, store, request, generate, analyze, promote, link to, or distribute child sexual abuse material, grooming, trafficking, or exploitative material;
- process or distribute non-consensual intimate imagery, hidden-camera, coerced, stolen, deceptive deepfake, revenge, extortion, or other material outside documented consent and required performer releases;
- use the Service for unlawful spam, harassment, threats, stalking, hate, blackmail, sextortion, deceptive impersonation, fraudulent upselling, fake scarcity, unauthorized charges, or communications to an opted-out or unlawful audience;
- process personal or sensitive data without required notice, purpose, lawful basis and, where applicable, special-category condition, or re-identify de-identified data or combine tenants’ data;
- infer, label, score, rank, segment, target, or predict a person's sex life, sexual orientation, health, biometric identity, ethnicity, beliefs, or another special-category or comparably sensitive characteristic, except under a separately reviewed and signed agreement that expressly permits the processing;
- use fan or message data for employment, credit, housing, insurance, immigration, healthcare, eligibility, identity verification, or another high-impact decision;
- use the Service for fraud, money laundering, sanctions evasion, trafficking, bribery, fraudulent payment disputes, compromised wallets or payment credentials, illegal trade, false attribution, or manipulation of clicks, conversions, revenue, referrals, reports, or billing tiers;
- use Service data to build a competing dataset, model, or product;
- infringe copyright, trademark, privacy, publicity, database, confidentiality, or trade-secret rights, remove proprietary notices, or falsely imply affiliation with OnStat or any platform; or
- use the Service in violation of export controls, sanctions, anti-bribery, trafficking, privacy, communications, intellectual-property, or computer-access laws.
Customer must not download, copy, or send suspected CSAM through ordinary email. It should preserve only safe, non-content identifiers and report the concern to the safety contact in section 22. OnStat may investigate credible reports, preserve evidence, restrict or remove data, disconnect an account, suspend or terminate access, notify an account owner or platform, or report to competent authorities. Imminent harm, suspected exploitation of a minor, credential compromise, sanctions risk, or unauthorized access may result in immediate action without prior notice.
10. Fees, subscriptions, balance, and taxes
Amounts payable for the Service (“Fees”), plan limits, trial terms, usage metrics, and subscription periods are shown in the Order Form or checkout. Unless expressly stated otherwise:
- all prices, Fees, prepaid balances, charges, credits, invoices, and refunds are denominated and calculated in United States dollars (“USD”);
- the displayed Fee is the final gross price for the OnStat service and includes any VAT or sales tax that OnStat is required to charge; those taxes are not added to the displayed Fee at checkout;
- Customer remains responsible for any reverse-charge, withholding or similar tax that it must self-account for;
- OnStat bears the Inqud processing fee charged to OnStat as merchant for the checkout and does not add that fee to the displayed Fee; Customer remains responsible for any fee or conversion charge imposed independently by Customer's own wallet, exchange, bank, or the selected blockchain network;
- a checkout is labelled either as purchase of a fixed service period or as funding of a prepaid workspace balance; neither creates automatic renewal or an automatic future wallet charge;
- a workspace may separately opt in to applying its prepaid balance to cover the next period;
- creator-account revenue may determine the applicable plan tier;
- Customer must pay undisputed amounts when due.
An invoice may state commercial amounts in USD and also state VAT payable in EUR or another legally required national currency using the conversion method required by applicable tax law. That tax display does not change USD as the contractual currency.
Customer must provide accurate and complete billing and tax information, including its legal or professional name, billing address and any applicable VAT or tax identifier. The hosted payment provider supplies payment confirmation and OnStat records the transaction. Where OnStat is legally required to issue a tax invoice, receipt, credit note, or correction note, it will provide the required document through the supported billing or support process. These Terms do not promise automated in-product tax-document generation in every jurisdiction.
If Customer’s wallet, exchange, bank, or selected blockchain network converts USD or charges Customer directly, Customer bears that conversion rate or external charge. The Inqud processing fee payable by OnStat does not reduce the gross Fee shown on the invoice; it is an OnStat expense. An approved refund is calculated in USD by reference to the original USD charge or credit. OnStat is not responsible for an exchange-rate difference or Customer-side wallet, exchange, bank, or network fee, except where mandatory law requires otherwise.
OnStat may correct an obvious pricing error before accepting payment, cancel and refund rather than charge a corrected price without consent, and suspend paid features after a failed payment or grace period.
A prepaid workspace balance is a contractual credit for eligible OnStat services, not a bank account, deposit, stored-value product, investment, or interest-bearing fund. It is not transferable between customers and has no cash value except where mandatory law requires a cash refund. Balance auto-cover is off by default, enabled separately for each account, and is an automatic use of prepaid credit rather than an automatic external payment charge. Customer may disable it before the displayed due time; disabling it does not reverse a completed debit.
Crypto payments may be irreversible, delayed, volatile, and subject to network fees. Customer must verify the chain, asset, amount, and payment address. Credit is applied only after the provider’s required confirmations and compliance checks.
Except where a signed Order Form or mandatory law says otherwise, Fees for an activated
service period and used prepaid credit are non-refundable. OnStat will provide a pro-rata
refund of prepaid unused fees if OnStat terminates without Customer breach, an uncured
OnStat warranty breach makes the paid Service materially unusable, Customer validly rejects
a material adverse Terms change, or mandatory law requires it. OnStat may also correct a
duplicate charge or demonstrable billing error or approve another refund in exceptional
circumstances. Customer must submit a request for such a discretionary refund to
[email protected] within 14 calendar days after the applicable charge and identify the
Customer, tenant, invoice or transaction, amount, and reason. This deadline applies only to
those discretionary requests; it does not limit the required pro-rata refunds listed above
or shorten a mandatory statutory right. An approved refund or confirmed provider reversal
may revoke the corresponding paid access.
Unless mandatory law or OnStat expressly agrees otherwise, OnStat first credits an approved refund in USD to Customer's prepaid workspace balance. Because a crypto transfer generally cannot be automatically reversed, OnStat does not promise an automatic return to the originating wallet, asset, network, or payment method. Any separately agreed manual payout requires a supported destination plus authority, ownership, fraud, sanctions, security, and provider verification; it is not a generally available withdrawal feature for ordinary balance funding or promotional credit.
11. Third-party services
The Service interoperates with third-party platforms and providers. Those services are governed by their own terms and may change, restrict, suspend, or discontinue access without notice. OnStat is not responsible for a third party’s service, content, decision, or security except to the extent applicable law or the DPA assigns responsibility to OnStat for its selection and use of a subprocessor.
Customer authorizes the subprocessors listed in the Subprocessor List subject to the DPA.
12. Intellectual property
As between Customer and OnStat, OnStat owns the Service, OnStat software, documentation, designs, trademarks, Service Data, and all related intellectual-property rights, excluding Customer Data and Customer-contributed elements of Customer-Specific Outputs. Third-party components and materials remain owned by their applicable licensors. No right is granted except as expressly stated in the Agreement.
If Customer provides feedback, it grants OnStat a worldwide, perpetual, irrevocable, royalty-free right to use it without identifying Customer or disclosing Customer Confidential Information.
Customer is responsible for the lawfulness of Customer Data. Copyright, trademark, privacy, consent, illegal-content, and safety reports may be sent to the contacts in section 22 without attaching illegal content or credentials. Customer may use OnStat names and marks only as necessary to identify its authorized use of the Service and may not imply sponsorship, certification, partnership, or endorsement.
13. Confidentiality
“Confidential Information” means non-public information disclosed by one party (“Discloser”) to the other (“Recipient”) that is marked confidential or reasonably should be understood as confidential. Customer Data, creator credentials, security materials, pricing, and product roadmaps are Confidential Information.
Recipient will use Confidential Information only to perform the Agreement, protect it with at least reasonable care, and disclose it only to personnel and contractors who need to know and are bound by confidentiality obligations. These duties do not apply to information that Recipient can document is public without breach, already lawfully known, independently developed, or lawfully received without restriction.
If law compels disclosure, Recipient will provide advance notice where legally permitted, disclose only what is required, and reasonably assist protective measures. Trade secrets remain protected while they qualify as trade secrets; other confidentiality obligations continue for five years after disclosure.
14. Monitoring, suspension, and emergency action
OnStat may use proportionate automated and manual controls to secure the Service, enforce the Agreement, investigate abuse, comply with law, and protect people. OnStat does not undertake a general duty to monitor all Customer Data.
OnStat may limit, suspend, or terminate affected access immediately if reasonably necessary to address:
- a security incident, credential compromise, unlawful or dangerous conduct;
- suspected exploitation of a minor or non-consensual intimate material;
- breach of platform terms or a platform demand;
- non-payment after applicable notice or grace period;
- material breach of the Agreement; or
- legal, sanctions, court, or regulatory requirements.
Where practicable and safe, OnStat will give notice and an opportunity to cure. OnStat will scope action to the affected account or function where reasonable.
15. Warranties
Each party warrants that it has authority to enter the Agreement and will comply with laws applicable to its own performance.
OnStat warrants that the paid Service will materially conform to its documentation under normal authorized use. Customer’s exclusive remedy for a verified breach is re-performance or, if OnStat cannot cure within a reasonable period, termination of the affected Order Form and a pro-rata refund of prepaid unused fees for that Order Form.
Except for the express warranty above, and to the maximum extent permitted by law, the Service, beta features, AI outputs, third-party integrations, and results are provided “as is” and “as available”. OnStat disclaims implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, and uninterrupted or error-free operation. OnStat does not warrant creator-platform availability, account safety, increased revenue, deliverability, attribution accuracy, or regulatory compliance for Customer’s business.
16. Indemnification
16.1 By Customer
Customer will defend, indemnify, and hold harmless OnStat and its affiliates, directors, officers, employees, contractors, consultants, agents, and licensors, and its Subprocessors solely to the extent a claim concerns their authorized provision of the Service for Customer (collectively, the “OnStat Indemnified Parties”), from and against any third-party claim, demand, action, investigation, or proceeding, including one brought by a creator, performer, fan, platform, data subject, regulator, or other public authority, arising from or relating to:
- Customer’s or an Authorized User’s use or alleged use of the Service;
- a connected account, synchronization or import, analytics or export, message, campaign, list, account action, automation, attribution function, AI Analytics, Dialogs AI, or other feature enabled, configured, requested, or used by Customer or an Authorized User;
- a Customer-selected advertising, analytics, or postback integration, including its event mapping, recipient, credentials, notice, consent or opt-out, lawful basis, platform terms, transfer, or Customer-instructed disclosure;
- Customer Data, Customer content, prompts, instructions, configured actions, AI outputs, products, communications, or Customer’s use or disclosure of any of them;
- lack of creator/account authority, performer consent, age verification, or platform permission;
- Customer’s or an Authorized User’s breach of the Agreement, applicable platform terms, or law, including applicable intellectual-property, privacy, data-protection, marketing, sanctions, export-control, or anti-money-laundering requirements;
- Customer’s infringement, misappropriation, privacy or confidentiality violation, fraud, exploitation, or unauthorized access; or
- a dispute connected with Customer Data or use of the Service between Customer and a creator, performer, fan, subscriber, Authorized User, employee, contractor, chatter, platform, advertising partner, or other third party, including a dispute about account authority, content rights, employment or contractor status, attribution, commission, or payout.
This indemnity covers resulting liabilities, damages, losses, approved settlements, reasonable external legal fees, costs, and expenses, and fines or penalties to the extent they may lawfully be indemnified. It does not apply to the extent a claim is finally determined to have been caused by OnStat’s material breach of the Agreement, fraud, wilful misconduct, or independently supplied OnStat material, except to the extent the claim also arises from Customer Data, a Customer instruction, a combination or modification not supplied by OnStat, or unauthorized use.
Each OnStat Indemnified Party is an intended beneficiary of this Section 16.1. OnStat may enforce this Section and recover covered amounts on its own behalf and on behalf of another OnStat Indemnified Party.
16.2 Defence procedure
OnStat will give Customer reasonably prompt written notice of a claim covered by Section 16.1 where practicable. Delay reduces Customer’s obligations only to the extent it materially prejudices the defence. Customer must promptly provide reasonable cooperation, information, records, personnel access, and payment of covered defence costs.
OnStat may elect to control the defence, negotiations, choice of counsel, and settlement strategy using counsel reasonably selected by OnStat, at Customer’s expense. If OnStat does not make that election, Customer may control the defence using counsel reasonably acceptable to OnStat, while OnStat may participate through separate counsel at its own expense. Control of the defence does not reduce Customer’s indemnity obligations.
Customer must not admit fault by, impose liability on, impose a non-monetary obligation on, or settle without an unconditional release of an OnStat Indemnified Party without OnStat’s prior written consent. If OnStat controls the defence, it will not settle a claim by requiring Customer to admit wrongdoing, accept a direct non-monetary obligation, or pay an amount not covered by this Section without Customer’s prior written consent. A consent required by this paragraph must not be unreasonably withheld, conditioned, or delayed.
16.3 No standard OnStat indemnity
OnStat does not provide Customer with an intellectual-property or other defence or indemnity unless a separately signed Order Form or master services agreement expressly states one. Any negotiated OnStat indemnity applies only to the claims, exclusions, remedies, procedure, and separate liability cap stated in that signed agreement. The limited Service warranty in Section 15, Customer’s payment of Fees, and OnStat’s ownership statements do not create an implied defence or indemnity.
17. Limitation of liability
17.1 Excluded losses
To the maximum extent permitted by law, OnStat and its affiliates, officers, directors, employees, contractors, licensors, and suppliers will not be liable under or in connection with the Agreement, the Service, or a third-party platform, under contract, tort (including negligence), statute, strict liability, restitution, or any other legal theory, for:
- indirect, incidental, special, exemplary, punitive, or consequential loss or damage;
- loss of profits, revenue, anticipated savings, business opportunities, customers, goodwill, reputation, data, or creator earnings, whether characterized as direct or indirect; or
- loss or damage arising from a third-party platform’s change, unavailability, suspension, restriction, termination, enforcement action, or decision concerning an account.
These exclusions apply even if OnStat was advised that the loss was possible and even if a limited remedy fails of its essential purpose. The exclusion of lost data does not eliminate OnStat’s obligation to perform an express security, incident-response, deletion, export, or restoration commitment stated in the Agreement.
17.2 Aggregate cap
To the maximum extent permitted by law, OnStat’s total aggregate liability under or in connection with the Agreement, the Service, and all related acts and omissions will not exceed the lower of:
- the total Fees actually paid to and retained by OnStat under the Agreement before the first event giving rise to liability; and
- US$2,000, or its equivalent in the currency of payment using the prevailing exchange rate on the date of that first event.
This is one combined cap for all claims by Customer and its Authorized Users, accounts, subscriptions, Order Forms, incidents, related events, and legal theories. It is not a separate cap per claim, incident, account, user, or Order Form. Fees that are payable but have not actually been paid and retained do not increase the cap.
The same general cap applies to OnStat’s contractual liability concerning confidentiality, the DPA, and Security Measures; there is no separate enhanced cap unless a signed Order Form expressly states otherwise. No contractual limitation changes a data subject’s statutory rights or a Supervisory Authority’s powers.
17.3 Matters outside the limitations
Nothing in the Agreement limits liability that cannot lawfully be limited, including for fraud, fraudulent misrepresentation, wilful misconduct, or death or personal injury caused by negligence where applicable.
Customer’s payment obligations, its indemnity obligations under Section 16.1, and its liability for unauthorized access to or infringement or misappropriation of OnStat intellectual property are not subject to the exclusions or cap in this Section 17.
Customer acknowledges that the Fees reflect this allocation of risk and that the exclusions and cap are an essential basis of the Agreement.
18. Term, subscription expiry, and termination
The Agreement begins when Customer accepts it and continues until all subscriptions end. Either party may terminate for an uncured material breach after 30 days’ written notice, or immediately if breach cannot be cured, the other party becomes insolvent, or law requires. OnStat may terminate a free account on reasonable notice.
When a paid subscription expires or terminates:
- access to paid features ends at the end of the paid period after an explicit cancellation; a natural lapse or failed renewal may receive the displayed grace period before suspension;
- accrued payment obligations remain due;
- for 30 days after the subscription ends, Customer may request a standard export or reactivate the subscription, unless law, security, platform restrictions, Customer breach, or account state prevents it; and
- after that 30-day period, OnStat may permanently delete Customer Data from active systems without further notice, and Customer will have no right to access or recover that data.
Reactivation is subject to then-current eligibility, pricing, payment, security, law, and platform requirements. It does not guarantee that connected-platform credentials, third-party access, or functionality can be restored. OnStat may begin deletion earlier on Customer’s verified instruction where the DPA and applicable law allow it.
Each generated export download link expires 24 hours after issuance. Expiry of a link does not shorten the 30-day offboarding window: while that window remains open, Customer may request a new export link, subject to the restrictions above.
Protected backup copies may remain after active-system deletion for legal, security, and disaster-recovery purposes until overwritten under OnStat’s normal backup cycle. Backup data is not available for ordinary use and, if restored for disaster recovery, remains subject to the applicable deletion instruction.
OnStat will otherwise delete or return Customer Data as described in the DPA and Privacy Notice. Provisions intended by their nature to survive will survive, including payment, confidentiality, IP, indemnity, liability, and dispute provisions.
Termination does not require OnStat to retain connected-platform credentials or reactivate a platform account.
19. Changes
OnStat may update the Agreement for legal, security, product, or operational reasons. For a material adverse change, OnStat will provide at least 30 days’ advance notice by email or in the Service unless urgent law or security needs require a shorter period. Changes do not retroactively alter a dispute that arose before their effective date.
If Customer objects to a material adverse change, it may terminate the affected paid subscription before the change takes effect and receive a pro-rata refund of prepaid unused fees. Continued use after the effective date constitutes acceptance.
20. Governing law and disputes
The Agreement is governed by the laws of the Republic of Cyprus, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods.
Before filing a claim, a party will give written notice and allow senior representatives 30 days to attempt good-faith resolution. Subject to mandatory law and either party’s right to seek urgent injunctive relief, the courts of the Republic of Cyprus have exclusive jurisdiction.
No arbitration, class-action waiver, shortened limitation period, or prevailing-party clause applies unless it is stated in a signed Order Form and enforceable under applicable law.
21. General
Neither party may assign the Agreement without the other’s consent, except to an affiliate or in connection with a merger, reorganization, or sale of substantially all relevant assets, provided the assignee assumes the Agreement. An assignment to an entity that offers services materially substitutable for those of the non-assigning party requires that party’s prior written consent. OnStat remains responsible for permitted subcontractors as required by the Agreement.
Neither party is liable for delay caused by events beyond reasonable control, excluding payment obligations and failures that reasonable business continuity or security measures should have prevented.
The Agreement is the complete agreement on its subject. Waiver must be explicit; invalid provisions will be modified to the minimum extent necessary; headings are for convenience; “including” means “including without limitation”; electronic acceptance and signatures are valid; and no third party has enforcement rights unless mandatory law says otherwise or Section 16.1 expressly provides it.
The parties are independent contractors. The Agreement creates no partnership, employment, fiduciary, franchise, or agency relationship. Customer cannot bind OnStat, and OnStat does not become Customer’s agent for the creator platform merely by technically performing a Customer instruction.
The English-language version of the Agreement controls. Any translation is provided for convenience only unless a signed Order Form expressly states otherwise. This paragraph does not limit a mandatory right or language requirement that applicable law does not permit the parties to exclude.
22. Notices and contact
Legal notices to OnStat must be sent to [email protected] and to DSLS PARTNERS LTD, Chrysanthou Mylona 1, Panayides Building, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus. Notices to Customer may be sent to the account owner’s email or through the Service. Notice is effective on confirmed delivery, subject to mandatory law.
Support questions: [email protected]
Privacy questions: [email protected]
Abuse and safety reports: [email protected]