Legal

Software and Services Agreement

This agreement governs your use of WDYE Studio. You accept it when you buy a plan. Please read it: it sets out what you are buying, what we owe you, and what happens to your data.

Version 1.0 · Effective September 18, 2026 · We Do Your Events LLC

1. The Agreement

This Software and Services Agreement (the "Agreement") is between We Do Your Events LLC ("we", "us") and the individual or organization that purchases a plan ("you"). You accept it by ticking the acceptance box at checkout. The version you accepted is recorded against your purchase and is the version that governs it; later versions do not change a plan you already bought until you renew.

If you are accepting on behalf of an organization, you confirm that you are authorized to bind it.

2. What You Are Buying

WDYE Studio is software we host and operate. You are buying the right to use it for the plan you purchased, not a copy of the software.

Per Event is one credit, spent when one event site goes live. It includes the website, the attendee app and registration for that event, and a stated number of included registrants.

Annual covers unlimited events for twelve months, with a stated number of included registrants across all of them and the Pro Service hours stated on the plan.

The registrant allowance and the price of your plan are shown at checkout and on the pricing page at the time you buy.

3. Registrants, Allowances and Overage

A "registrant" is a person registered through your event, not an order: a group registration of ten people counts as ten. Test-mode registrations and cancelled registrations are not counted.

Exceeding your allowance never stops your registration form. We do not block sign-ups, and we do not take an event offline for going over. Registrants beyond your allowance are billed at the overage rate stated on your plan and invoiced separately.

Your annual allowance counts from the start of your current annual period. Registrations taken before your plan began are never counted against it.

4. Fees, Payment and ACH Authorization

Fees are payable in advance in US dollars. Per Event credits do not expire. Annual plans renew automatically at the then-current price for that plan unless cancelled before the renewal date; we will tell you before a price change affects a renewal.

If you pay by bank debit (ACH), you authorize us, through our payment processor Stripe, to debit the account you provide for the amounts due under this Agreement, including automatic renewals until you cancel. ACH payments are not instant: your plan activates when the funds settle, which is typically one to three business days. You may revoke this authorization by cancelling your plan, which stops future debits.

Overage invoices are due 30 days from issue. We may suspend an account that is more than 30 days past due, after telling you first.

Attendee payments are yours, not ours. Money your registrants pay goes directly to your own Stripe account. We never hold it and we take no percentage of it.

5. Refunds

An unspent Per Event credit may be refunded within 30 days of purchase. A credit that has been spent to publish an event is not refundable, because the service it bought has been delivered.

An annual plan may be refunded in full within 10 days of purchase if no event has been published under it. After 10 days an annual plan is not refundable, though you may cancel at any time to stop it renewing.

A registrant allowance is capacity, not credit. An allowance you do not use is not refunded, is not exchangeable, and does not carry over to a renewal or to another plan, whichever plan it came with. This applies whether the allowance went unused because your event was smaller than expected, because it was cancelled, or for any other reason.

6. Pro Service Support

Annual plans include the number of Pro Service hours stated on the plan. Pro Service is hands-on help from us: setup, configuration, data import, or walking your team through the software. It is scheduled by agreement and available through your plan period; unused hours do not carry over to a renewal. Ordinary support is not deducted from these hours.

7. Your Content and Your Data

Everything you put into the software stays yours: your event content, your branding, your speakers and sponsors, and your registrant data. We claim no ownership of it.

You grant us only the permission we need to run the service for you: to host, process, back up and display your content in order to operate your event site, your attendee app and your registration.

We do not sell your data and we do not sell your registrants' data. We do not use your registrant lists to market to them.

Registrant data is personal data and you are responsible for the notices and consents your own event requires. We act on your instructions in handling it.

You can export your data at any time while your plan is active. If your plan ends we will keep your data available for at least 30 days so you can retrieve it, then we may delete it.

8. Service Providers and AI Processing

We run the service on infrastructure and services operated by others. Those providers process your content only to deliver the service to you, and are bound to confidentiality and security obligations no weaker than ours. They are: Cloudflare (hosting, database, file storage and bot protection), Stripe (payments), Resend (transactional email) and Anthropic (the AI setup review described below). We will give you notice of a change to this list, and you may object on reasonable data protection grounds.

The AI setup review sends your event's configuration to Anthropic. It runs only when a user of your account asks for it. What is sent is a snapshot of the event's SETUP: its settings, sections, schedule structure, plan state and the findings our own rule engine has already computed. Registrant records are not sent: no attendee names, emails, phone numbers, payment details or answers to your registration questions.

What comes back is advice, in the form of a three-step plan. The AI never changes a setting, never decides whether your event may publish, and cannot act on your account. Your data is not used to train any model. One event's snapshot is never included in another event's request.

If you would rather no data reach an AI provider at all, tell us and we will disable the feature for your account.

9. Data Protection

This section applies where you are subject to the EU or UK General Data Protection Regulation, and is in addition to the rest of this Agreement. Words defined in the GDPR have the same meaning here.

You are the controller of registrant personal data and we are your processor. For your own account holders' data (the people who log in to build your events), we are the controller. We process registrant data only on your documented instructions, which this Agreement and your use of the software constitute, unless the law requires otherwise, in which case we will tell you before processing unless the law forbids that notice.

Subject matter and duration: the provision of the service, for as long as your plan is active plus the retention period in section 7. Nature and purpose: hosting, storing, displaying and transmitting registrant data in order to operate your event site, attendee app and registration. Types of data: identification and contact details, registration and order records, and whatever additional questions you choose to ask. Categories of data subject: your registrants, attendees, speakers, sponsors and exhibitors.

We ensure that people authorized to process the data are bound by confidentiality, and we implement appropriate technical and organizational measures under Article 32.

We engage the subprocessors named in section 8 and remain responsible for their performance. We will give you reasonable notice of any addition or replacement and an opportunity to object on reasonable data protection grounds.

We will assist you, so far as we reasonably can and taking account of the nature of the processing, with data subject requests under Chapter III, and with your obligations under Articles 32 to 36. We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data.

At the end of the service we will delete or return the data at your choice, as set out in section 7, except where the law requires us to keep it.

We will make available the information reasonably necessary to demonstrate compliance with this section and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.

Where personal data is transferred outside the EEA or the UK, that transfer is made under the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, which are incorporated into this Agreement by reference.

10. Security

Everything is encrypted in transit and at rest. Every surface is served over TLS only and carries HTTP Strict Transport Security for a year including subdomains, so a browser that has seen us once will not speak to us unencrypted again. Your data and your uploaded files sit in encrypted managed storage.

Access codes are never stored. We store a salted hash, so nobody, including us, can read a code back out of the database. Sign-in is rate limited per address and per network, and an attempt is reserved before it is counted so a burst of parallel guesses cannot slip past the ceiling.

The application sends a Content Security Policy that authorizes its own scripts by hash rather than by a shared token, refuses to be framed except where a surface must be, declines to guess content types, strips path and query from cross-origin referrers so a token in a link cannot leak off-site, and switches off camera, microphone, geolocation and payment access at the browser. Uploads are typed from their bytes rather than the uploader's word, and files that can carry script are refused rather than sanitized.

Every request reaches us through a managed web application firewall. We run Cloudflare's managed ruleset in front of both the software and the event sites it publishes, so protection against common injection, cross-site scripting and known-exploit traffic is maintained against current signatures by a dedicated provider rather than by us alone. It sits alongside, not instead of, the application's own defenses described above.

Access to production is limited to personnel who need it for their role. Every write to a tenant's data is authorized against that tenant, and a login is scoped to the one event it was issued for unless it belongs to an account administrator.

We review the software against the OWASP Top 10 risk categories, treat a confirmed vulnerability as a defect to be fixed rather than a feature to be scheduled, and will tell you, under section 9, about a breach affecting your data. We do not claim a certification we do not hold: if you need a penetration test report, a security questionnaire answered, or a named framework attested, ask and we will tell you honestly what exists and what does not.

You are responsible for the security of your own account: who you invite, what you grant them, and removing people who leave. The software gives you per-section grants and live seat counts so you can.

11. Accessibility

We build to WCAG 2.2 Level AA, which is the standard Section 508 incorporates by reference. The surfaces your attendees and registrants use, the published event site, the registration form, the attendee app and the speaker and sponsor portals, are tested against it and we will correct any conformance failure you report in them as a defect, at no charge.

We will provide a current Accessibility Conformance Report (VPAT) on request, stating what conforms and naming any exception, so you can evaluate it yourself rather than relying on this paragraph.

Content you supply is yours to make accessible: we cannot supply alternative text for your images, caption your videos, or choose readable color combinations on your behalf, though the software derives a readable text color from any brand color you pick so that your choice cannot fail contrast where it is rendered as text.

12. Acceptable Use

You may not use the software to send unlawful or unsolicited bulk email, to publish unlawful content, to infringe anyone's rights, or to attempt to breach the security of the service or another customer's data.

You are responsible for what is published on your event sites and for the conduct of the people you invite into your account.

13. Availability

We aim for 99.5% monthly availability, excluding scheduled maintenance we tell you about in advance and outages outside our reasonable control. This is a target we hold ourselves to; it is not a service credit scheme.

We may change or improve the software over time. We will not remove a capability your plan was sold on without telling you first.

14. Confidentiality

Each of us may learn non-public information about the other. Neither of us will disclose it to anyone else except to people who need it to perform this Agreement and who are bound to keep it confidential, or where the law requires disclosure.

15. Warranties and Disclaimer

We warrant that we will provide the service with reasonable skill and care. Beyond that, and to the fullest extent the law allows, the software is provided "as is" and we disclaim all other warranties, express or implied, including merchantability and fitness for a particular purpose.

16. Indemnification

We will defend you against a third party claim that the software, used as this Agreement permits, infringes that party's patent, copyright, trademark or trade secret, and we will pay the damages finally awarded or the settlement we agree to.

If the software becomes, or we think it may become, the subject of such a claim, we may at our own cost obtain the right for you to keep using it, modify it so it is no longer infringing, or, if neither is reasonably available, terminate the affected plan and refund the unused portion of what you paid for it. That is your exclusive remedy for infringement.

We are not obliged to defend a claim that arises from your content, from your combining the software with something we did not supply, from your use after we told you to stop, or from a modification you made.

You will defend us against a third party claim arising from your content, from your event, or from your use of the software in breach of section 12, and you will pay the damages finally awarded or the settlement you agree to.

Being defended is conditional on the indemnified party telling the other promptly about the claim, giving the other sole control of the defense and settlement, and cooperating reasonably. No settlement that admits fault or imposes an obligation on the indemnified party may be made without its consent.

Where you are a public body that is prohibited by law from giving an indemnity, your obligation under this section applies only to the extent the law permits.

17. Limitation of Liability

To the fullest extent the law allows, neither of us is liable to the other for indirect, incidental, special or consequential damages, or for lost profits or lost data, even if told they were possible.

Each party's total liability arising out of this Agreement is capped at the annual license price: the fee payable for the annual plan in effect when the claim arose, or, if you are not on an annual plan, the total fees you paid us in the twelve months before the claim arose. The parties agree that this cap is a reasonable allocation of risk given the fees charged, and that the fees would be materially higher without it.

The cap does not apply to your obligation to pay fees due, to either party's obligations under section 16, or to a breach of section 14.

Nothing in this Agreement limits liability that cannot be limited by law, including for fraud or for death or personal injury caused by negligence.

18. Term, Cancellation and Termination

This Agreement runs while you hold an active plan or unspent credits. You may cancel an annual plan at any time; it stops renewing and runs to the end of the period you paid for.

Either of us may terminate for a material breach the other has not fixed within 30 days of being told about it. We may suspend an account immediately where continuing would break the law or endanger the service or other customers, and we will tell you why.

Sections 7, 9, 10, 14, 15, 16, 17 and 19 survive termination.

19. Governing Law and Venue

A claim is brought where the party being sued is, under that party's own law. An action against us is brought in the state and federal courts serving Colorado, and is governed by Colorado law. An action against you is brought in the courts having jurisdiction where you are established, and is governed by the law of that jurisdiction. Each of us submits to the jurisdiction of the courts named for it and waives any objection to venue there. Conflict of laws rules are excluded in both directions.

This is deliberate and it cuts both ways: whoever sues travels. It also means a public body that cannot agree to another state's law and venue does not have to, since any claim against it proceeds under its own.

A counterclaim is heard by the court already hearing the claim. Either of us may seek injunctive relief to protect confidential information or intellectual property in any court with jurisdiction.

20. General

We may update this Agreement for future purchases. The version recorded against a purchase governs that purchase.

If any part of this Agreement is unenforceable, the rest stays in force. Neither of us is liable for failures caused by events outside our reasonable control. Neither of us may assign this Agreement without the other's consent, except as part of a sale of substantially all of the business.

This Agreement, together with what your plan states at checkout, is the entire agreement between us on this subject.

21. Contact

Questions about this Agreement: contact us.