These terms are an agreement between Nikita Cherevko ("Wardentry", "we", "us"), and the organization that signs up for the service ("Customer", "you").
You accept them by creating an organization or by using the service. If you are accepting on behalf of an organization, you confirm you are authorised to bind it. If you are not, do not accept them.
1. What the service is
Wardentry is an access-control system for events and venues that already have a guest list. You bring the people. We issue each of them a credential, enforce the rules you configure at each gate, and give you the record afterwards.
Concretely, the service lets you: create events and gates; define rules such as entry limits and time windows; import or enter a list of members; issue passes and email them; link scanner devices to a gate; admit or deny people at that gate; and read the resulting log.
2. What the service is not
Stated plainly, because assuming otherwise would cost you an event:
- It is not a ticketing platform. There is no checkout, no payment processing, no public event page, and no attendee self-registration. We never handle your attendees' money.
- It does not work offline. Every admission decision is made by our servers. A scanner with no network connection cannot admit anyone, and - this is the part that matters - an entry limit cannot be enforced without connectivity. We do not offer an offline mode that would let two gates each admit the same one-entry pass, because a limit that silently stops applying is worse than a limit you know you do not have. If your venue's connectivity is uncertain, test it before the night.
- It is not a security guarantee. It is a tool your staff use. It cannot stop someone walking past an unattended door, and it cannot tell whether the person holding a pass is the person it was issued to.
- It is not a system of record for anything but access. Keep your own copy of your guest list.
3. The free tier
The service is currently free to use, and the following apply for as long as it is:
- No surprise charges. Pricing, if we introduce it, applies to new signups and to exceeding the quotas in section 7 - not to an organization already on the free tier.
- No service level. There is no uptime commitment, no support response time, and no maintenance window you can rely on. See section 11.
- Things will change. Features may be added, altered or removed. We will not remove something you depend on without telling you first, but we may change how it works.
- We may end it. We can suspend or discontinue the service on 30 days' notice, during which you may export your data. We will not delete your data without that notice period, except as section 18 allows.
4. Your account
You must be at least 18 and able to enter into a contract. Give us accurate registration details and keep them current.
The service is provided from Poland and organizations anywhere may sign up, except where we are not permitted to serve you. You may not create or use an account if you, or the organization you are signing up for, are subject to EU, UK or US sanctions, or are established in or operating from a territory that EU restrictive measures prevent us from supplying. We may refuse or close an account on that basis, and we will tell you when we do so unless we are prohibited from telling you.
You are responsible for everything done through your account, including by your staff. Keep credentials secret, use the roles the service provides rather than sharing one login, and tell us promptly at security@wardentry.com if you believe an account or a device link has been compromised - a device link is a credential that admits people at a gate, so treat the URL like a key.
5. Your data, and your responsibilities for it
"Customer Data" means everything you put into the service or generate through it: your member list, events, rules, passes, and scan history.
You own it. We claim no rights in it beyond what we need to run the service for you.
You are the controller of it. We process it only as your processor, on your instructions, under the Data Processing Agreement, which forms part of these terms and which you accept when you create your organization.
You are responsible for ensuring that:
- you have a lawful basis for collecting your attendees' personal data and for handing it to us to process;
- your attendees have been told that their access to your event is managed by a third-party system on your behalf, and where to find your own privacy notice;
- your data is accurate, and you delete or correct it when you should;
- you do not upload special categories of personal data - health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, or data concerning sex life or sexual orientation - unless we have agreed to it in writing beforehand. The service has no field for any of it and is not built to hold it, and a free-text name or label is not the place to put it either;
- if your attendees include children, you have whatever consent or other basis your law requires.
Our answering a request from one of your attendees is described in section 8 of the DPA: we route it to you, we do not act on it ourselves.
6. Acceptable use
Do not use the service to:
- break the law, or infringe anyone's rights;
- process data you have no right to process;
- attack, probe, overload, or attempt to circumvent the service's limits, its authentication, or its separation between customers - save that good-faith security research reported to security@wardentry.com is welcome and will not be treated as a breach of this section;
- send unsolicited bulk email through our sending infrastructure, or use the pass email as a marketing channel;
- resell, sublicense, or make the service available to a third party as your own, other than by running events for your own clients;
- reverse engineer the service, except where the law says you may.
We may suspend an account immediately if it is causing damage to the service or to other customers, or if we are required to. Otherwise, section 18 applies.
7. Quotas and fair use
Free-tier organizations are limited by default to 5 events, 500 members and 500 passes. Passes are the binding limit for anyone running a series, because each one is an email we pay to send.
We can raise these for you - ask. We may also apply rate limits to protect the
service, currently including limits on scanning, signup and email sending; you
will meet them as a 429 response, not as a silent failure.
8. Staff and devices
You may invite staff and give them roles. An invitation is a credential; so is a device link. Both are yours to manage, and both can be revoked from the console.
Revoking a device link stops it being exchanged for a new scanner session, but a session already issued to a phone remains valid until it expires - currently up to 12 hours. If a phone is lost during an event, revoke the link and treat the gate as compromised for the remainder of that window.
9. Our data protection obligations
The DPA governs our processing of Customer Data. Where these terms and the DPA conflict on a data protection matter, the DPA wins.
Our own privacy notice - for you and your staff, as our customers - is the Privacy Policy.
10. Intellectual property
We own the service, its software, and everything in it other than Customer Data. These terms grant you a non-exclusive, non-transferable, revocable right to use it during the term, and nothing more.
If you send us feedback, ideas, or bug reports, we may use them without obligation to you. That is not a claim over your data; it is a claim over the sentence "the scanner should be brighter in sunlight."
11. Availability and support
We aim to keep the service available and to answer you quickly, and while it remains free neither is a commitment. Support is by email at contact@wardentry.com on business days. There is no on-call rota, and if your event is on a Saturday night you should assume you are running it, not us - plan for the fallback in section 2 rather than for a phone call.
We will give reasonable notice of planned maintenance where we can, and will avoid it where an event is known to be running.
12. Confidentiality
Each of us may learn things about the other that are not public. Neither will disclose the other's confidential information except to people who need it and are under a duty of confidence, or where the law compels it - in which case, as far as we are allowed, we will tell you first.
13. Warranties
Each of us warrants that we have the authority to enter into these terms.
Otherwise, and to the fullest extent the law allows, the service is provided "as is". We disclaim all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the service will be uninterrupted, error-free, or that it will admit or deny any particular person correctly in circumstances outside its control - including a loss of connectivity at your venue, a phone that will not read a QR code, or a credential someone has copied.
Nothing here excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
14. Limitation of liability
Neither of us is liable to the other for indirect, incidental, special or consequential loss, or for loss of profit, revenue, goodwill, or anticipated savings, however arising.
Our total aggregate liability arising out of or in connection with these terms is limited to the greater of the fees you paid us in the twelve months before the claim and €100. While the service is free, that means the second figure is the cap, and you should read this section as a statement that a free service carries a small, fixed limit of liability rather than an open-ended one.
These limits do not apply to your indemnity under section 15, to either party's breach of confidentiality, or to anything section 13's final paragraph preserves. Liability for data protection matters is dealt with in the DPA.
15. Indemnity
You will indemnify us against claims, losses and reasonable costs arising from your use of the service in breach of these terms, and from any claim by one of your attendees or by a supervisory authority relating to your collection or use of their personal data - except to the extent it was caused by us processing outside your instructions or in breach of the DPA.
16. Term and termination
These terms run from your acceptance until the account is closed.
- You may close your organization at any time, for any reason, by writing to us. There is nothing to cancel and no notice period.
- We may terminate for convenience on 30 days' notice, or immediately if you materially breach these terms and - where the breach can be fixed - have not fixed it within 14 days of our telling you about it.
- Either of us may terminate immediately if the other becomes insolvent.
17. Suspension
We may suspend access, in whole or in part, where an account is causing damage to the service or to another customer, where we are legally required to, or where an organization on a paid plan has payment overdue. We will restore access as soon as the cause is resolved and, unless the law prevents it, tell you why.
18. What happens to your data at the end
For 30 days after termination, you may export your Customer Data - the console's exports remain available, and we will help if something has broken.
After that, we delete it. Deletion follows the structure of the database: removing an organization removes its events, members, passes, gates, rules, device links and scan history with it. Copies in backups persist until they fall out of the provider's restore window, and are not restored to live service in the meantime.
We may keep data where the law requires, and may keep aggregate, anonymised statistics that cannot be linked back to you or your attendees.
19. Changes to these terms
We may change these terms. Material changes take effect 30 days after we email organization administrators; continuing to use the service after that is acceptance. If you do not accept, close your account before the change takes effect and section 18 applies.
Changes to the sub-processor list in the DPA follow the notice process in DPA §6, not this section.
20. Governing law and disputes
These terms are governed by the law of Poland, and the courts of Poland have exclusive jurisdiction. If you are a consumer, this does not deprive you of the protection of the mandatory law of the country you live in.
Before starting proceedings, please contact us. Most of what a first-year customer and a one-person company can disagree about is resolvable by email.
21. General
- Assignment. You may not assign these terms without our consent. We may assign them to a successor of the business, on notice to you. That includes the incorporation of a company to operate the service: the company assumes these terms unchanged, your rights are unaffected, and you do not have to accept anything again. The DPA is transferred on the same basis, under its Section 16.
- Subcontracting. We use the sub-processors listed in the DPA, and remain responsible for them.
- Entire agreement. These terms, the DPA, and the Privacy Policy are the whole agreement between us on their subject matter, and replace anything said before.
- Severability. If any provision is unenforceable, the rest survives.
- No waiver. Not enforcing something once does not waive it.
- Force majeure. Neither of us is liable for a failure caused by something genuinely outside our control. Note that this does not extend our disclaimer in section 2: connectivity at your venue is your circumstance, not a force majeure event.
- Notices. To you, by email to your organization's administrators. To us, at contact@wardentry.com - except notices about personal data, which go to privacy@wardentry.com.
- Survival. Sections 5, 10, 12, 13, 14, 15, 18, 20 and 21 survive termination.
22. Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-19 | First published |
| 1.1 | 2026-08-22 | Section 3: clarified that pricing, if introduced, applies to new signups and to exceeding quotas, not to organizations already on the free tier. Section 17: scoped suspension for overdue payment to organizations on a paid plan. |