Processing instructions
Customer prompts and outputs should be processed only to provide, secure and support the service, subject to the final agreement and configured upstream provider terms.
Security
Access controls, credential protection, audit records and incident response should be documented in the security page and operational controls.
Subprocessors
Providers that may process customer data must be identified with their purpose and relevant location information before production commitments are made.
Deletion and return
Retention and deletion rules must distinguish active service data, security records, financial records and legally required preservation.