VinStream Terms of Service
Version 2026-09-18-1
These Terms of Service govern the business subscription to VinStream provided by IronHill AI, LLC, a Pennsylvania limited liability company, with a mailing address at 1526 Aspen Drive, Pottstown, PA 19464, United States (Provider, we, us). The customer is the dealership business identified in an accepted order (Customer, you). Notices and support requests may be sent to info@ironhill.ai; the business telephone number is 484-318-9520. These Terms become effective between the parties when Customer affirmatively accepts the identified version through an authorized representative and Provider accepts the accompanying order.
1. Agreement and authority
An Order is the written or electronic order schedule accepted by both parties identifying Customer, locations, authorized signer, purchased services, quantities, price, billing frequency, discounts, and any expressly negotiated terms. Provider accepts by delivering an express final order confirmation or countersigned Order after Customer's authorized acceptance; a draft, receipt of an inquiry, or payment redirect alone is not that confirmation. Payment must not be collected before Provider accepts the Order. An administrator's preparation of a draft, nomination of a contact, or creation of a dealership record does not by itself constitute Customer acceptance or authorize a charge. A representative accepting an Order represents that they have authority to bind its named Customer. No person becomes a personal guarantor merely by signing for Customer, administering the account, or using the application.
These Terms, the accepted Order, the VinStream Payment Agreement, and expressly accepted amendments constitute the subscription agreement. The data processing schedule in Section 18 is part of these Terms. The VinStream End User License Agreement governs individual application licenses. The VinStream Privacy Policy explains personal information practices; acknowledging its receipt is not a waiver of privacy rights or consent to optional marketing. The VinStream Dispute Resolution Agreement applies only if separately and affirmatively accepted by the party against whom it is invoked.
Mandatory law controls. An express signed amendment controls the provision it specifically changes. The data processing schedule controls conflicts concerning processing of Customer personal information, and a separately accepted Dispute Resolution Agreement controls its subject. The Order then controls identified services, quantities, prices, and term; the Payment Agreement controls billing mechanics; these Terms control other subscription matters. A purchase order, invoice notation, linked webpage, or unilateral policy update does not amend an accepted agreement. General Order language does not silently override data protection obligations or mandatory individual rights.
2. Services and intended use
VinStream provides the dealership video capture, upload, hosting, sharing, customer interaction, administration, and related functionality included in the Order. Only expressly ordered functionality is purchased. References to development plans, previews, integrations, or demonstrations are not commitments to future functionality. The service is intended for U.S. dealership business and authorized adults, not for children or personal consumer subscriptions.
Customer remains responsible for vehicle availability, descriptions, condition, pricing, financing statements, service estimates, diagnosis, repair authorizations, and communications with its customers. A video, view event, appointment request, service acknowledgment, or generated summary is not by itself a purchase contract, credit decision, repair authorization, or proof of legally sufficient consent. Customer must separately satisfy applicable requirements for those transactions. VinStream does not provide legal, tax, lending, insurance, or professional mechanical advice or guarantee sales, engagement, repair outcomes, or regulatory compliance.
3. Accounts and administration
Customer must provide accurate business and contact information, use individual credentials, designate authorized administrators, and promptly remove access for personnel who leave or change responsibilities. Customer authorizes its administrators to manage the users, settings, and Customer content within their assigned scope. Customer must distinguish a person permitted to use or administer the service from a person authorized to purchase, amend an Order, or accept legal terms.
Customer must protect credentials and devices, use required security controls, and notify Provider promptly of suspected unauthorized access. Provider may verify a user's email, business authority, or payment authority before allowing an action. Customer is responsible for use by its authorized personnel within their authority, except to the extent a loss results from Provider's breach. Customer is not responsible merely because an attacker bypasses safeguards maintained solely by Provider. Provider personnel may access account information only for authorized support, operation, security, compliance, or another purpose allowed by this agreement and applicable law.
4. Customer content and license
Customer retains its rights in videos, audio, photographs, captions, comments, messages, descriptions, listings, links, branding, vehicle records, customer information, and other material it or its authorized users submit, import, post, share, or direct the service to process (Customer Content). Customer grants Provider and its authorized service providers a nonexclusive right to receive, host, copy, format, transcode, transmit, display, and otherwise process Customer Content solely to provide, secure, support, and administer the contracted service and comply with lawful obligations. This license lasts only as needed for those purposes, including permitted retention after termination.
Customer represents that it has the rights and notices, permissions, and other legal bases necessary for its instructions and intended sharing. An available manufacturer branding preset does not convey trademark or franchise rights. Customer should avoid capturing bystanders, private conversations, license documents, financial records, or unrelated personal information. Provider receives no right under this agreement to sell Customer Content or use identifiable Customer Content to train a general purpose AI model. A materially different use requires a separate lawful arrangement and any required individual consent.
Customer-directed public or recipient links may be forwarded, photographed, recorded, or downloaded by recipients. Link expiry and revocation do not erase copies already made outside the service. Customer must use available restrictions appropriate to the content and avoid placing sensitive information in public links. Provider must honor the access controls it undertakes to provide; this warning does not excuse a defect in those controls.
Responsibility for posted material. As between Customer and Provider, Customer is solely responsible for Customer Content submitted by Customer or by persons acting on its behalf, and for the decision to record, upload, import, publish, distribute, or share it. This responsibility includes the material's legality, accuracy, completeness, context, and claims; copyright, trademark, publicity, privacy, and other rights; required recording and communications permissions, notices, and releases; and the selection of recipients and access settings. Customer must review material, including any draft captions, descriptions, or information produced with an automated tool, before adopting or publishing it. The individual submitting material also remains responsible for that person's own conduct under their applicable agreement and law. Use of VinStream does not transfer these responsibilities to Provider.
No endorsement or content warranty. Provider supplies the technology for Customer's content and communications. Customer Content is not a statement, representation, offer, warranty, or professional opinion of Provider. Hosting, processing, formatting, transmitting, displaying, or moderating submitted material does not by itself mean that Provider authored, approved, verified, or endorsed it. Provider does not warrant the truth, legality, quality, or suitability of Customer Content or information supplied by an independent third party. Customer remains responsible for its own vehicle claims, repair recommendations, advertisements, promises, and resulting customer transactions.
Claims arising from posted material. To the maximum extent permitted by law, Provider has no liability to Customer for Customer Content or material supplied by an independent third party, including inaccurate, misleading, offensive, defamatory, unlawful, or infringing material, or for decisions and transactions based on that material. Customer bears responsibility for its material and the covered third-party claims described in Section 14. This allocation does not excuse Provider's own breach, negligent or unlawful conduct, unauthorized use of content, or material that Provider itself creates or unlawfully develops; it does not diminish agreed security or confidentiality duties or any liability or remedy that cannot lawfully be excluded. The mandatory exceptions in Section 15 continue to apply.
Content complaints and removal. Report suspected unlawful, infringing, or otherwise prohibited content to info@ironhill.ai with the specific page or content identifier and the reason for the report. Provider may review, restrict, remove, or disable access to material reasonably believed to violate this agreement, another person's rights, or law, or when needed to address a credible safety or security concern or valid legal process. Customer must reasonably cooperate with lawful investigations, preservation duties, and correction or removal requests and must not knowingly restore prohibited material to evade a restriction. Except as required by law or an express commitment, Provider does not undertake to review every submission before publication. The availability or exercise of moderation does not transfer the submitting party's responsibility to Provider. Nothing in this provision limits mandatory reporting, preservation, or removal duties or waives an available statutory defense.
5. Acceptable use and communications
Customer and its users must not use the service to violate law; infringe intellectual property or privacy rights; upload malicious software; threaten, harass, defraud, or impersonate others; publish knowingly misleading vehicle or repair information; bypass tenant boundaries or security protections; gain unauthorized access; or materially disrupt the service. Customer must not resell access, scrape restricted data, or conduct intrusive security testing without written authorization, except where applicable law protects the activity notwithstanding this restriction.
Customer must not submit Social Security numbers, payment card credentials, bank credentials, credit applications, health information, or other sensitive records unnecessary for the ordered video workflow. Customer may not use the service for biometric identification, creditworthiness determinations, unlawful surveillance, or decisions that unlawfully discriminate. Customer must not upload illegal sexual content, exploitative content involving minors, or material that it has no lawful right to possess.
Customer determines whom it contacts, the lawful basis for contact, and required consent and notices. It must honor opt-outs and applicable communications rules, maintain required consent records, and use approved communication channels. A consent to receive a requested service video does not automatically authorize unrelated marketing. Delivery, read, and viewing events are technical indicators and do not conclusively establish identity, receipt, or consent.
6. Provider intellectual property and feedback
Provider and its licensors retain ownership of VinStream software, designs, documentation, and other Provider materials. Subject to the agreement and payment terms, Customer may access and use the purchased service during its authorized term for its internal dealership operations. No source code, exclusivity, or ownership transfers. Restrictions do not override rights granted by applicable open source licenses or nonwaivable law.
If Customer voluntarily provides suggestions without confidential information, Provider may use them to improve its products without payment or attribution. This permission does not grant rights in Customer Content, personal information, trademarks, or inventions separately identified as confidential. Provider may not use Customer's name, logo, testimonial, or case study for promotional purposes without Customer's permission.
7. Third parties and integrations
Hosting, identity, electronic signature, payments, messaging, device platforms, and inventory systems may involve third parties. Provider remains responsible for its contractual obligations when using subcontractors. Third party terms govern a service that Customer independently contracts to use; they do not silently replace Provider's obligations. Customer authorizes only the integrations it enables and must hold rights to provide the relevant data and credentials.
An external platform's unavailability or changes may affect an integration. Provider will use commercially reasonable efforts to explain material changes and offer a reasonable workaround. Provider may change implementation details without materially reducing purchased functionality. If Provider permanently removes a material purchased feature without a substantially equivalent replacement, Customer may terminate the affected service on written notice within 30 days of learning of the removal and receive a proportional refund of unused prepaid fees for that service.
8. Support and service changes
Support is available by email at info@ironhill.ai. Unless an Order expressly states otherwise, no guaranteed response time, uptime percentage, dedicated support hours, disaster recovery time, or service credit applies. Provider will use commercially reasonable efforts to maintain and support the service and communicate planned material interruptions when practicable. Security changes may require prompt updates or reauthentication. Provider will not intentionally reduce purchased functionality materially during a paid term without the rights described in Section 7.
Customer should keep its own copies of business records that it must retain. The service is not an indefinite archive or Customer's sole disaster recovery system. This allocation does not relieve Provider of agreed safeguards, retention duties, restoration efforts, or liability for its breach. Beta features must be identified as such before use and may have additional agreed restrictions; use of a beta does not waive nonwaivable rights.
9. Charges and subscription term
The Payment Agreement and Order state when billing starts, recurring amounts, included and additional seats, taxes, discounts, renewal, cancellation, and payment remedies. The subscription begins when the Order's payment and signing conditions are satisfied and the purchased service is made available. Unless an Order expressly provides a phased start, a consolidated subscription covers all listed locations from its stated start even if Customer delays a particular location's setup. No recurring charge is authorized solely by a support interaction or acceptance of an individual EULA.
10. Confidentiality
Confidential Information includes nonpublic business, technical, security, commercial, and Customer information disclosed in connection with the agreement that is identified as confidential or should reasonably be understood to be confidential. It excludes information the receiving party can demonstrate was lawfully known without restriction, becomes public without breach, is independently developed without use of the information, or is lawfully received from another source without a duty of confidentiality.
Each party will use the other's Confidential Information only to perform or exercise rights under the agreement, protect it with reasonable care, and limit disclosure to personnel, advisers, and service providers who need it and are bound by suitable confidentiality duties. A legally compelled disclosure is permitted, with advance notice where lawful, reasonable cooperation at the requesting party's expense, and disclosure limited to what is required. These duties continue for three years after termination; duties regarding personal information and trade secrets continue for the period required by law and for as long as the information remains protected under the agreement.
11. Suspension and termination
Provider may proportionately suspend affected access to address a credible security threat, unlawful use, a material breach, or unpaid undisputed charges. Except when immediate action is reasonably needed to prevent harm, comply with law, or protect the service, Provider will provide notice explaining the issue and at least 10 days to cure before suspending. Billing-specific grace and notice provisions in the Payment Agreement apply to nonpayment. Provider will use reasonable efforts to narrow the restriction and restore access promptly after the grounds are resolved. Suspension is not automatic permission to delete data or charge an undisclosed reinstatement fee.
Either party may terminate for the other's material breach that remains uncured 30 days after written notice describing it. A shorter period may apply where cure is impossible, continued performance is unlawful, or immediate termination is necessary to prevent serious harm. Provider may terminate affected use for repeated serious misuse after reasonable warnings, unless an immediate response is justified. Customer may cancel renewal under the Payment Agreement without alleging breach.
On termination, ordinary use rights end, unpaid properly incurred obligations remain due, and Provider will refund unused prepaid fees for affected services if termination results from Provider's uncured material breach or Provider's discretionary early termination without Customer breach. Fees are otherwise governed by the Payment Agreement. No provision accelerates all hypothetical future renewals.
12. Exit and retention
Customer may request a reasonable export of available Customer Content during the term and for 30 days after termination by contacting info@ironhill.ai. Provider may verify authority and use a secure delivery process. Existing standard export capabilities, if any, and a reasonable standard assisted export are included; custom transformation or reconstruction requires an agreed scope and price. Export is subject to third party rights, security restrictions, law, and content already deleted under valid instructions. Provider will not withhold an otherwise available standard export solely to coerce payment of a genuinely disputed invoice.
After the export period, Provider will delete or deidentify Customer Content from active service systems within 60 days, unless law, a documented legal hold, dispute preservation, or another agreed legitimate retention requirement applies. Residual backup copies will expire under documented backup cycles, remain protected, and not be restored to active use except for disaster recovery, security, or legal need; if restored, pending deletion instructions must be reapplied. Provider will identify the applicable backup cycle upon reasonable request. Signed contracts, billing records, and limited security or dispute evidence may be retained for applicable tax, limitation, recordkeeping, and defense periods. Such retention does not authorize ordinary use of terminated customer media.
13. Warranties and disclaimers
Each party represents that it has authority to enter the agreement and will comply with laws applicable to its performance. Provider warrants that during a paid term the purchased service will materially conform to the functionality described in the Order and that it will perform support with reasonable skill and care. Customer must report a claimed material nonconformity with reasonable detail promptly after discovery. Provider will use reasonable efforts to correct it; if Provider cannot do so within a reasonable time, Customer may terminate the affected service and obtain a refund of unused prepaid fees. This contractual remedy does not displace nonwaivable remedies or separately applicable security obligations.
EXCEPT FOR EXPRESS WARRANTIES IN THE AGREEMENT AND WARRANTIES THAT CANNOT LAWFULLY BE EXCLUDED, THE SERVICE IS PROVIDED AS AVAILABLE. TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON INFRINGEMENT. PROVIDER DOES NOT WARRANT UNINTERRUPTED OR ERROR FREE OPERATION, ACCURACY OF CUSTOMER OR EXTERNAL DATA, OR A PARTICULAR COMMERCIAL RESULT. NO DISCLAIMER EXCUSES FRAUD, WILLFUL MISCONDUCT, GROSS NEGLIGENCE, OR A LIABILITY THAT LAW PROHIBITS EXCLUDING.
14. Third-party claims
Provider will defend Customer against an unaffiliated third party claim that the unmodified purchased service, as supplied and used as authorized, infringes a U.S. patent, copyright, or trademark, and pay damages and reasonable settlements finally awarded or approved by Provider. This obligation excludes claims caused by Customer Content, unauthorized modification, use outside the agreement, or a combination not supplied or required by Provider where the claim would not otherwise arise. Provider may obtain continued use rights, modify or replace affected functionality without material loss, or terminate the affected service with a refund of unused prepaid fees if those options are not commercially reasonable.
Customer content indemnity. Customer will defend, indemnify, and hold harmless Provider and its officers, employees, and agents against an unaffiliated third party's claim arising from Customer Content, its submission or sharing by Customer or persons acting on Customer's behalf, Customer's unlawful recording or communications instructions, or Customer's intentional misuse of the service. Covered content claims include alleged infringement or misappropriation of intellectual property; infringement of privacy, publicity, confidentiality, or recording rights; defamation; deceptive or misleading statements or advertising; missing required rights or permissions; and other unlawful material or conduct attributable to Customer Content. Customer must pay the reasonable defense costs and attorneys' fees, damages finally awarded, and settlements approved under the procedure below. This obligation does not cover losses to the extent caused by Provider's own breach, negligence, misconduct, unauthorized use of Customer Content, or unlawful creation or development of material. It does not make an individual employee a guarantor or personally liable for Customer's business indemnity.
The protected party must provide prompt notice, permit the defending party to control the defense with competent counsel, and provide reasonable cooperation at the defending party's expense. Late notice relieves an obligation only to the extent materially prejudicial. No settlement may admit the protected party's fault, require its payment, restrict its business, or impose a nonmonetary obligation without its prior written consent, not unreasonably withheld. The protected party may participate through separate counsel at its own expense, except where a material conflict requires separate representation. If Customer fails to assume a covered defense promptly after notice, Provider may arrange a reasonable defense and recover its reasonable costs under this Section; settlement remains subject to the approval protections above. These obligations are subject to Section 15, including its specific treatment of the Customer content indemnity.
15. Limits on liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE UNDER THIS AGREEMENT FOR INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR LOST PROFITS, REVENUE, OR BUSINESS OPPORTUNITIES, WHETHER A CLAIM SOUNDS IN CONTRACT, TORT, OR ANOTHER THEORY, EVEN IF ADVISED OF THE POSSIBILITY. Reasonable direct costs to restore data or respond to a security incident are not automatically excluded merely because they involve data.
Except for the exceptions below, each party's total aggregate liability arising from the agreement is limited to the greater of USD 1,000 or the subscription fees paid or payable by Customer under the affected Order during the 12 months immediately before the first event giving rise to the claim. Related claims share one cap. Amounts properly due for services actually purchased, and refunds expressly owed, are payment obligations and do not use up the damages cap.
The exclusion of damages and cap do not apply to fraud, willful misconduct, gross negligence, death or personal injury caused by conduct for which limitation is prohibited, or other liability or remedies that applicable law does not permit the parties to exclude or limit. They do not restrict regulatory enforcement, protected reporting, or nonwaivable privacy rights.
Customer content claims are not capped by subscription fees. To the extent permitted by law, Customer's defense and indemnity obligations under Section 14 for covered Customer Content claims are excluded from both the liability cap and the exclusion of categories of damages above, solely for covered amounts payable to a third party and reasonable defense costs and attorneys' fees. The procedures and exclusions in Section 14 still apply. The cap otherwise applies to the contractual defense and indemnity obligations in Section 14. The separately accepted Dispute Resolution Agreement changes the forum for covered disputes; it does not expand these limitations or release claims. The parties acknowledge that these limits allocate commercial risk in light of the fees and available alternatives.
16. Law and dispute forum
Pennsylvania law governs the agreement, excluding conflict of laws rules, except that controlling federal and nonwaivable state law continues to apply. A separately accepted VinStream Dispute Resolution Agreement determines arbitration of covered disputes. If no such agreement applies, or a dispute is excluded from arbitration, the parties submit to state courts in Montgomery County, Pennsylvania, or the United States District Court for the Eastern District of Pennsylvania if it has subject matter jurisdiction. This selection does not displace a mandatory forum, a permitted small claims proceeding, or protected public injunctive or regulatory relief. No party waives a jury trial merely by accepting these Terms.
17. Notices and general provisions
Notices to Provider must be sent to info@ironhill.ai or IronHill AI, LLC, 1526 Aspen Drive, Pottstown, PA 19464. Provider will send contractual notices to Customer's designated account or billing contact. Email notice is effective on acknowledged receipt or, absent a delivery failure notice, the next business day after transmission; a sender who learns delivery failed must use another reasonably available method. Cancellation timeliness is governed by the Payment Agreement. Formal service of legal process remains governed by applicable law. Each party must keep contact information current.
Neither party may assign the agreement without the other's consent, except to an affiliate or in a merger, reorganization, or sale of substantially all relevant assets if the successor assumes the obligations and the transfer does not materially diminish the other party's protections. Customer cannot transfer access to unrelated dealerships without an amended Order. Neither party is the other's agent, partner, or employee. Except for expressly identified beneficiaries, the agreement creates no third party beneficiary rights.
A party is excused from delay caused by events reasonably beyond its control, excluding inability to pay, to the extent it promptly notifies the other party and takes reasonable mitigation steps. This does not excuse security obligations that reasonable safeguards should have prevented or payment for service already supplied. If an event prevents material service for 30 consecutive days, Customer may terminate the affected service and receive unused prepaid fees. Failure to enforce a provision is not a continuing waiver. An unenforceable provision is limited only as necessary, and the remainder continues unless doing so would defeat the essential bargain. Changes require a versioned acceptance or signed amendment; merely posting revised terms does not retroactively amend an existing Order. Provisions intended by their nature to continue, including confidentiality, permitted retention, accrued payment, claim handling, and dispute provisions, survive termination.
18. Data processing and security schedule
For personal information in Customer Content, Customer determines the purposes and means of dealership processing and Provider acts as its processor or service provider as those terms apply under law. Provider separately determines purposes for its own business contacts, billing administration, security, and compliance information as described in the Privacy Policy. These roles are functional and may vary with the actual processing; they do not remove either party's legal obligations.
The subject of processing is delivery of the ordered dealership video and related communication service. Processing includes collection, recording, organization, hosting, conversion, retrieval, display, transmission, access management, troubleshooting, and deletion. Data subjects may include dealership personnel, customers, prospects, and persons incidentally recorded. Data may include business and customer contact details, account identifiers, vehicle identifiers, audio and video, service communications, appointments, interaction events, and technical metadata. Processing lasts for the subscription and the permitted exit and retention periods. Sensitive financial and unrelated regulated records are outside the intended service as described in Section 5.
Provider will process Customer personal information only on documented lawful instructions, including the agreement and authorized configuration choices, or as required by law. It will notify Customer if it reasonably believes an instruction violates applicable data protection law and may suspend only the affected instruction pending resolution. Provider will not sell or share that information for cross context behavioral advertising, use it outside the permitted business purposes, or combine it with unrelated personal information except as permitted for a processor or service provider by applicable law. Provider will provide the protection required by applicable law, notify Customer if it can no longer do so, and cooperate in reasonable steps to stop and remediate unauthorized use.
Provider will maintain proportionate administrative, technical, and organizational safeguards addressing access authorization, tenant separation, authentication, protection of data in transit and at rest, activity records, vulnerability management, personnel confidentiality, incident response, and vendor oversight. These are contractual responsibilities, not a representation of a certification or a particular audit result. Where Customer identifies covered nonpublic personal information under the Gramm Leach Bliley Act or FTC Safeguards Rule, the parties will document appropriate service provider safeguards and oversight before processing it. Customer must not assume that ordinary subscription activation approves financial records outside the service scope.
Customer authorizes subprocessors reasonably needed for contracted hosting, identity, media, communications, electronic signature, and billing functions. Provider will maintain an accessible list of relevant subprocessors and functions, bind processors to suitable written confidentiality and data protection duties, and remain responsible for their performance of delegated obligations. Provider will provide at least 15 days' advance notice of a material new subprocessor, unless an urgent replacement requires faster action, in which case notice will follow promptly. Customer may raise a reasonable, documented data protection objection within that period. The parties will seek an alternative; if none is reasonably available, Customer may terminate the affected feature with a proportional refund of unused prepaid fees.
Provider will notify Customer without undue delay, and in any event within 72 hours after confirming unauthorized access to or disclosure, loss, or destruction of Customer personal information in Provider's custody, with information then available. Initial notice may be supplemented and must describe the nature, affected data where known, likely consequences, mitigation, and a contact. An unsuccessful attack without compromise is not by itself a reportable incident under this contractual definition; mandatory earlier or broader notices remain required. Provider will investigate, contain, preserve appropriate evidence, and cooperate with Customer. Each party remains responsible for notices legally assigned to it. Neither party may unnecessarily identify the other publicly without consultation, except as required by law or a protected reporting right.
Provider will assist Customer with lawful access, correction, deletion, portability, and other individual requests, security assessments, and regulatory inquiries reasonably relating to the processing. It will refer direct requests concerning Customer controlled records to Customer when appropriate, without obstructing rights. Customer may request relevant security information and, where necessary under law or following a material incident, a reasonable confidential assessment by a qualified independent reviewer under procedures protecting other customers and system security. Routine requests are included; extraordinary work may require reasonable agreed fees, except where assistance is needed because of Provider's breach or applicable law prohibits charging. Export, deletion, backup restrictions, and legal holds follow Section 12. No schedule provision waives an individual's nonwaivable rights or authorizes an unlawful cross border transfer.
19. Execution and complete records
The parties may execute documents in separate counterparts and by electronic signature. Each accepted counterpart is treated as an original; together they evidence the same agreement. A signature applies to the document and capacity expressly identified beside it. Separate signatures on the Order, these Terms and the Payment Agreement record their respective acceptance; the Privacy Policy and EULA acknowledgment have the limited purposes stated on their signature pages. Only a separate affirmative acceptance establishes the Dispute Resolution Agreement.
Provider will preserve the accepted document texts, versions and exact rendered copies with the related Order, signature evidence and Provider order confirmation. Customer can download the completed record through its secure agreement access and request another copy at info@ironhill.ai. Document fingerprints identify retained versions; a fingerprint or system status alone does not establish the signer's authority. If a material mistake is discovered before completion, the parties must correct and reissue the affected offer for fresh acceptance. Completed records must be retained with any later amendment, not overwritten.
These documents supersede prior proposals and discussions on the same subscription only to the extent stated in the agreed order of precedence. Neither party relies on a sales forecast or future feature promise absent from the accepted Order. This provision does not exclude liability or a remedy for fraud, misrepresentation that cannot lawfully be excluded, or an express warranty in the agreement.
Drafting attribution: The counterpart and electronic-signature structure in Section 19 and the indemnification structure in Section 14 are adapted from Common Paper Cloud Service Agreement Standard Terms, Version 2.1, Sections 12.17 and 9.2, 9.3 and 9.5 (https://commonpaper.com/standards/cloud-service-agreement/2.1/), licensed under Creative Commons Attribution 4.0 International (https://creativecommons.org/licenses/by/4.0/). It has been modified for VinStream. Common Paper does not endorse this agreement; its standard terms are not otherwise incorporated by this attribution.
20. Advertising and separate commercial data uses
The Privacy Policy explains advertising and potential commercial uses of information for which Provider lawfully determines its own purposes. Such uses remain subject to mandatory law, collection notices and the choices of the affected individuals. A business signature does not supply an employee's or shopper's legally required consent. The limited Customer Content license and processor restrictions in Sections 4 and 18 continue to apply. If Customer and Provider later agree to commercialize dealership-controlled data, they must first execute a specific written schedule identifying the permitted data, source, purposes, recipients, safeguards and rights-handling responsibilities, and establish the required notices and permissions. A general reference to the Privacy Policy is not that schedule and cannot retroactively enlarge rights in previously collected data.