1. Overview

This document defines the licensing terms and data governance framework for Wembassy Intel — Wembassy's AI-powered operations platform — as deployed for Clients("Client"). It establishes binding commitments regarding data ownership, data privacy, AI model training, third-party access, and operational boundaries.


2. AI Models & Infrastructure

2.1 Model Platform

Wembassy Intel is powered by AI models running on Wembassy's own infrastructure via a local, self-hosted inference engine. No Client data is transmitted to external AI providers for processing unless explicitly approved by Client in writing.

2.2 No Training on Client Data

  • Wembassy does not use Client data — in whole or in part — to train, fine-tune, evaluate, benchmark, or improve any AI model, machine learning system, or statistical model.
  • The AI models utilized by Wembassy Intel are pre-trained, open-weight models. They are used as-is for inference only. No model weights are modified, updated, or adapted using Client data.
  • This commitment applies to all models accessed through the platform, whether hosted locally by Wembassy or accessed via approved external APIs.

2.3 Model Selection & Transparency

  • Wembassy will maintain a current list of all AI models used in connection with Client data (provided in Exhibit C).
  • Client may request information about any model's architecture, training data provenance, and licensing terms at any time.
  • Wembassy will not introduce a new model into Client's environment without notifying Client and providing relevant details about the model's origin and licensing.

2.4 AI Services & Limitations

Client acknowledges and agrees that:

  • AI-generated outputs may be inaccurate, incomplete, or inappropriate.
  • Client is solely responsible for reviewing and verifying AI-generated outputs before use or publication.
  • Wembassy does not guarantee the accuracy, reliability, or suitability of AI outputs for any specific purpose.
  • Client should not rely on AI outputs for critical decisions without independent human verification.
  • AI agents operating on the platform act as assistants to designated human operators, not as autonomous decision-makers.

2.5 Responsible Use

  • Wembassy commits to using AI services only for lawful purposes in connection with Client operations.
  • Wembassy will not use AI models to: violate applicable laws or regulations, infringe on the intellectual property or rights of any third party, transmit harmful or illegal content, or interfere with or disrupt any third-party service.
  • Wembassy does not use Client inputs or outputs to train AI models or develop competing products.

2.6 Model Infrastructure & Data Processing

  • AI inference (text generation, analysis, summarization) is performed on Wembassy-managed infrastructure.
  • Where any third-party model API is accessed (if explicitly approved by Client), Wembassy will configure such services to disable any data retention, logging, or training features. Where such features cannot be disabled, those services will not be used for Client data processing.
  • No Client data is retained in model training datasets, evaluation sets, prompt logs, or any other form used for model improvement.

2.7 Intellectual Property — AI Models

  • The AI model runtime and platform infrastructure remain the intellectual property of Wembassy and its licensors.
  • Pre-trained models utilized by Wembassy Intel are used under their respective open-source or commercial licenses. Wembassy maintains compliance with all applicable model license terms.
  • Client retains ownership of all content generated by AI models in connection with Client operations (see Section 12.3).

3. Data Ownership & Sovereignty

3.1 Client Data Ownership

  • All data processed, stored, or generated through Wembassy Intel in connection with Client operations — including but not limited to member information, event data, registration records, communications, content, and analytics — remains the sole and exclusive property of Client.
  • Wembassy retains no ownership interest in Client data.
  • Wembassy acts as a data processor on behalf of Client. Client is the data controller.

3.2 Data Residency

  • Client data is stored on infrastructure designated and approved by Client.
  • Wembassy will not migrate, replicate, or mirror Client data to any infrastructure not explicitly approved by Client in writing.
  • All primary processing occurs on Wembassy-managed infrastructure under Client's direction.

4. No Model Training on Client Data

4.1 Prohibition on Training

Wembassy expressly commits that:

  • No Client data — in whole or in part — will be used to train, fine-tune, evaluate, benchmark, or improve any AI model, machine learning system, or statistical model.
  • This includes but is not limited to: language models, embedding models, recommendation systems, classification models, and any derivative or successor systems.
  • This prohibition applies to Wembassy's own models, third-party models accessed through the platform, and any models operated by subcontractors or infrastructure providers.

4.2 No Data Retention for Model Improvement

  • No Client data will be retained in model training datasets, evaluation sets, or prompt logs used for model improvement.
  • Where third-party AI models are accessed via API (e.g., for text generation or analysis), Wembassy will configure such services to disable any data retention, logging, or training features offered by those providers. Where such features cannot be disabled, those services will not be used for Client data processing.

4.3 Audit Confirmation

  • Upon Client's written request, Wembassy will provide a written confirmation affirming compliance with this section, including a list of all AI models and providers accessed in connection with Client data during the requested period.

5. No Third-Party Data Sharing

5.1 Prohibition on Sharing

  • Wembassy will not share, sell, license, transfer, disclose, or make available any Client data to any third party.
  • This includes but is not limited to: data brokers, advertisers, marketing partners, analytics providers, research institutions, government agencies (except where required by law), and any other commercial or non-commercial entities.

5.2 Approved Agents & Authorized Users

Client data may only be accessed, processed, or transmitted to the following:

  • Wembassy personnel directly assigned to Client account (listed in Exhibit A)
  • AI agents explicitly approved by Client (listed in Exhibit B)
  • Client's own designated personnel and administrators
  • Access to Client data is restricted to these approved agents and users only. No other individuals, systems, or automated processes may access Client data.
  • Wembassy will maintain a current list of all approved agents and users. Any additions or removals require written approval from Client's designated point of contact.

5.3 Subcontractor Disclosure

  • Wembassy does not currently engage subcontractors for processing Client data.
  • If Wembassy intends to engage a subcontractor who would have access to Client data, Wembassy will:
    1. Notify Client in writing at least 30 days in advance
    2. Provide Client the opportunity to object or require additional safeguards
    3. Ensure the subcontractor is bound by written terms no less protective than this agreement
    4. Obtain Client's written approval before granting access

6. Data Processing Boundaries

6.1 Purpose Limitation

Client data will be processed only for the explicit purposes authorized by Client, including:

  • Event management and registration processing
  • Content management and publishing
  • Member communications and engagement
  • Platform operations, maintenance, and support
  • Analytics and reporting as directed by Client
  • Client data will not be used for any purpose not explicitly authorized by Client.

6.2 Automated Decision-Making

  • No fully automated decisions will be made about Client members or operations without Client's explicit configuration and approval.
  • AI agents operating on Wembassy Intel act as assistants to designated human operators, not as autonomous decision-makers.

6.3 Cross-Client Isolation

  • Wembassy serves multiple clients on Wembassy Intel. Client data is strictly isolated from data belonging to any other Wembassy client.
  • No data cross-contamination, data pooling, shared training sets, or cross-client analytics will occur.
  • Each client environment operates in logically separated workspaces with independent data stores, access controls, and agent configurations.

7. Security & Access Controls

7.1 Access Management

  • Access to Client data is governed by role-based access controls (RBAC).
  • All access is authenticated and logged.
  • Access logs are retained for a minimum of 90 days and are available to Client upon request.

7.2 Encryption

  • Data in transit: TLS 1.2+ encryption for all network communications.
  • Data at rest: AES-256 encryption for stored data on primary infrastructure.
  • Credentials and secrets: Managed via secure vault; never stored in plaintext or in version control.

7.3 Infrastructure Security

  • Platform infrastructure is maintained with current security patches and updates.
  • Regular security assessments are conducted by Wembassy's technical team.
  • Infrastructure access is restricted to authorized Wembassy personnel via SSH key authentication only.

8. Data Retention & Deletion

8.1 Retention

  • Client data is retained for the duration of the licensing agreement and any renewal periods.
  • Upon Client's request, Wembassy will delete specific data categories or records within 30 days.

8.2 Termination

  • Upon termination of this agreement:
    • Wembassy will return or destroy all Client data within 60 days, at Client's election.
    • Wembassy will provide written confirmation of completion.
    • Any data retained solely for legal compliance will be held in encrypted cold storage and inaccessible for any other purpose.

8.3 Backup Data

  • Backup copies of Client data will be purged within 90 days of termination in accordance with standard backup rotation schedules.

9. Compliance & Audit Rights

9.1 Client Audit Rights

  • Client retains the right to audit Wembassy's compliance with this document, including:
    • Reviewing access logs and agent configurations
    • Verifying no model training has occurred
    • Confirming data isolation between clients
  • Audits may be conducted annually or upon reasonable suspicion of non-compliance.
  • Wembassy will provide reasonable cooperation and access to relevant documentation.

9.2 Breach Notification

  • Wembassy will notify Client within 24 hours of discovering any unauthorized access, data breach, or violation of this agreement.
  • Notification will include: nature of the incident, data affected, containment measures taken, and remediation plan.

9.3 Regulatory Compliance

  • Wembassy will comply with all applicable data protection laws and regulations relevant to Client's operations, including but not limited to applicable state privacy laws and international regulations where Client members are located.

10. Agent Interaction & Communication

10.1 Communication Channels

Client interactions with Wembassy Intel AI agents are conducted through the following authorized channels:

  • Discord: Wembassy maintains a dedicated Discord server environment where Client's designated personnel can communicate directly with approved AI agents via direct messages and assigned channels. Discord is the primary real-time interface for agent interaction, task assignment, and operational coordination.
  • Email: Client may communicate with AI agents by emailing wren@wembassy.com. Messages sent to this address are processed by the Wembassy Intel platform and routed to the appropriate agent for response.

10.2 Channel Access Control

  • Access to the Discord environment is restricted to Client's designated personnel listed in Exhibit A and approved AI agents listed in Exhibit B.
  • Wembassy will provision Discord access for Client's authorized users upon written request.
  • Client is responsible for notifying Wembassy when a user's access should be revoked (e.g., personnel changes, role transitions).
  • The wren@wembassy.com email address is monitored by the Wembassy Intel platform. Emails sent to this address are processed in accordance with the data handling commitments in this agreement — no email content is shared with third parties, used for model training, or retained beyond the purpose of fulfilling Client requests.

10.3 Interaction Logging

  • All agent interactions via Discord and email are logged for operational continuity, audit trails, and quality assurance.
  • Interaction logs are retained for 90 days and are available to Client upon request.
  • Logs are not used for model training, improvement, or evaluation.
  • Logs are not shared with any third party.

10.4 Communication Boundaries

  • AI agents will not initiate outbound communications to Client's members, stakeholders, or external parties without explicit authorization from Client's designated point of contact.
  • AI agents will not communicate through channels other than the authorized Discord environment and wren@wembassy.com email unless explicitly approved by Client.
  • All agent communications are attributable and traceable to the specific agent that generated them.

11. AI Agent Governance

11.1 Agent Transparency

  • All AI agents operating on Client data are documented in Exhibit B, including:
    • Agent name and role
    • Data access scope
    • Permitted operations
    • Human oversight requirements
  • No AI agent not listed in Exhibit B will be granted access to Client data.

11.2 Agent Boundaries

AI agents will not:

  • Transmit Client data to any external API, service, or endpoint not approved by Client
  • Store Client data outside of the designated Client infrastructure
  • Share Client data with agents or systems belonging to other Wembassy clients
  • Make autonomous decisions with material business impact without human review

11.3 Agent Configuration Changes

  • Any changes to AI agent configurations that affect data access, processing scope, or external communications require written approval from Client's designated point of contact.

12. Intellectual Property

12.1 Platform IP

  • Wembassy Intel, including its software, architecture, configurations, and tooling, remains the intellectual property of Wembassy.
  • Client is granted a non-exclusive, non-transferable license to use Wembassy Intel for its operations during the term of this agreement.

12.2 Client Content IP

  • All content created, managed, or published through Wembassy Intel for Client — including event materials, member communications, web content, and data — remains the intellectual property of Client.
  • Wembassy retains no rights to use, reproduce, or distribute Client content for any purpose other than providing services to Client.

12.3 AI-Generated Content

  • Content generated by AI agents in the course of Client operations is the property of Client.
  • Such content is not used for any purpose other than Client's operations and is not retained by Wembassy for any other use.

13. Term & Termination

13.1 Term

  • This agreement is effective upon execution and remains in force for the duration of the service engagement between Wembassy and Client.

13.2 Termination

  • Either party may terminate this agreement with 60 days written notice.
  • Upon termination, Sections 4 (No Model Training), 5 (No Third-Party Sharing), 8 (Data Retention & Deletion), 10 (Agent Interaction & Communication), and 12.2 (Client Content IP) survive indefinitely.

14. Contact & Escalation

14.1 Wembassy Contacts


Exhibits

Exhibit A — Approved Wembassy Personnel

[To be populated with human personnel assigned to Client account]

Name Role Access Level Date Added
Chris McIntosh Owner/Operator Full Sep 15, 2025
Mitzi Hazel Tizon Front end developer Full Sep 15, 2025

Exhibit B — Approved AI Agents

Agent Role Data Access Scope Permitted Operations Human Oversight
Wren (COO) Operations coordination Event data, project management, communications Task coordination, reporting, scheduling Chris McIntosh
Spock (CTO) Technical operations Platform configs, code, infrastructure Development, deployment, maintenance Chris McIntosh
Mason (CMO) Content & marketing Event content, marketing materials Content drafting, publishing, analytics Chris McIntosh
Grayson (CRO) Sales & pipeline Registration data, member contact info Lead management, outreach, reporting Chris McIntosh
Researcher Event research Public event data, Client event spreadsheet Web research, data entry, reporting Wren (COO)

Additional agents may be added with written approval from Client's designated contact.

Exhibit C — AI Models

Model Type Purpose Hosting License Trained on Client Data?
GLM-5.2 Large Language Model Agent reasoning, tool use, operations Wembassy local infrastructure Open-weight No
Qwen 3.5 Large Language Model Lightweight agent tasks, heartbeats Wembassy local infrastructure Open-weight No
No

Wembassy certifies that no model listed above is trained, fine-tuned, or evaluated using Client data. All models are used for inference only. Additional models may be introduced with Client notification and approval per Section 2.3.