ILLUSTRATIVE INPUT. FICTIONAL MATTER. NOT A LEGAL FORM. D1. Processing. Provider will process personal information only to provide the service and follow Customer’s documented instructions. Provider will not sell personal information. These Data Terms do not expressly address training of shared models or identify a replacement for services-agreement section 2. D2. Security and incidents. Provider will maintain appropriate technical and organizational safeguards. Provider will notify Customer of a confirmed security incident affecting personal information without undue delay. No outside notification deadline is stated. D3. Service providers. Provider may engage subprocessors subject to written confidentiality and security obligations. The current subprocessor list and notice procedure have not been supplied with this fixture. D4. Return and deletion. On termination and Customer’s request, Provider will return or delete personal information, except where retention is legally required. No deletion timetable or backup schedule is stated. These Data Terms do not expressly replace services-agreement section 5. D5. Responsibility. Provider remains responsible for its obligations under these Data Terms. This provision does not expressly amend the services agreement’s limitation of liability. Supplied vendor statement: “We use encryption and restrict access to authorized personnel.” No audit report, testing evidence, insurance certificate or detailed retention schedule is included. Do not treat the absence of those materials as proof that the vendor lacks the corresponding controls.