Skip to main content

Data Processing Agreement

18 min read

Effective Date: September 26, 2026

This Data Processing Agreement (“DPA”) is Exhibit A to the Terms of Service (“Agreement”) between Customer and Berkman LLC (“Berkman”). It applies when Berkman processes personal data on Customer’s behalf under the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or the Swiss Federal Act on Data Protection (“Swiss FADP”).

Capitalized terms not defined here have the meanings given in the Agreement.

If this DPA and the Agreement conflict on personal data processing, this DPA controls.


1. Definitions

“Data Protection Law” means the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Swiss FADP, and any implementing or successor legislation, as applicable.

“Personal Data” means any information relating to an identified or identifiable natural person that Berkman processes on Customer’s behalf in providing the Platform and related support services.

“Processing” means any operation performed on Personal Data — including collection, storage, retrieval, use, disclosure, combination, erasure, or destruction.

“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

“Sub-Processor” means a third party Berkman engages to process Personal Data on Customer’s behalf.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, with the modules and selections in Section 11.2. Replacement instruments are adopted as provided in Section 13.2.


2. Roles and Scope

2.1 Roles

Customer acts as a controller or as a processor acting for another controller. Berkman acts as Customer’s processor or sub-processor, respectively. Where Customer is a processor, Customer is authorized to engage Berkman and communicate the controller’s instructions and will fulfill its obligations to that controller. Each party will comply with its obligations under Data Protection Law.

2.2 Scope of Processing

Berkman processes Personal Data to provide, maintain, secure, and support the Platform on Customer’s documented instructions. The details of processing are described in Annex 1. Product improvement using aggregated or anonymized information is subject to Section 4.7 of the Agreement. Section 19.3 of the Agreement describes semantic-search model processing and the search index in the Subscription’s hosting region and prohibits model training on Customer Data.

2.3 Duration

Berkman processes Personal Data for the duration of the Agreement and any applicable return or deletion period under Section 12 of this DPA. This DPA continues to protect Personal Data for as long as Berkman or its Sub-Processors retain it.


3. Customer’s Instructions

3.1 Documented Instructions

Berkman will process Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s configuration of the Platform constitute Customer’s instructions. Customer may provide additional written instructions consistent with the Agreement.

3.2 Instruction Limits

If Berkman believes an instruction violates Data Protection Law, Berkman will immediately notify Customer and may pause the relevant processing until Customer provides clarified instructions.

3.3 No Other Purpose

Berkman will not process Personal Data for another purpose except where required by EU or member state law or, for processing governed by UK or Swiss Data Protection Law, the corresponding applicable law. Berkman will inform Customer of that legal requirement before processing unless the law prohibits notification on important grounds of public interest. Requests under other countries’ laws remain subject to the applicable SCCs and other transfer safeguards, including their requirements concerning review, challenge, and notice of government access requests.


4. Confidentiality

Berkman ensures that all persons authorized to process Personal Data are bound by confidentiality obligations — whether by contract or by law. This is in addition to the confidentiality obligations in Section 12 of the Agreement.


5. Security

Berkman maintains the technical and organizational security measures described in Section 5.1 of the Agreement. These measures are appropriate to the risk and include encryption in transit and at rest, role-based access controls, and audit logging.

Berkman may update its security measures over time, but will not materially reduce the overall level of protection.


6. Sub-Processors

6.1 Authorization

Customer gives Berkman general written authorization to engage Sub-Processors to process Personal Data. Berkman maintains the authoritative list of current Sub-Processors — including each Sub-Processor’s purpose, the categories of Personal Data it processes, and its location — at lextree.ai/legal/sub-processors. That page also records changes to the list.

6.2 Notice of Changes

Berkman will update the Sub-Processor list and notify affected Customers by email to their notice contacts under Section 20.7 of the Agreement at least thirty (30) days before a new Sub-Processor begins processing Personal Data on their behalf. Customer may designate an additional notice contact by emailing team@lextree.ai.

6.3 Objection

If Customer objects to a new Sub-Processor on reasonable data protection grounds, the parties will negotiate in good faith. If they cannot resolve the objection, Customer may terminate the affected services without penalty and receive a pro-rata refund of prepaid fees for the unused period of those services. Fees for services already provided remain payable. This is the same process as Section 5.3 of the Agreement.

6.4 Sub-Processor Obligations

Berkman will enter into a written contract with each Sub-Processor imposing equivalent data protection obligations appropriate to the processing, as required by Article 28(4) of the GDPR and the applicable transfer safeguards. This does not require identical commercial terms. Berkman remains responsible to Customer for each Sub-Processor’s performance of those obligations.


7. Data Subject Rights

7.1 Assistance

Taking into account the nature of the processing, Berkman will assist Customer through appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under Data Protection Law — including access, rectification, erasure, restriction, portability, and objection.

7.2 How Berkman Helps

Berkman will promptly notify Customer if Berkman receives a request from a Data Subject directly. Berkman will not respond to the Data Subject unless Customer instructs Berkman to do so or law requires it.

The Platform’s available export and deletion tools and Berkman’s standard support process are the starting point for assistance. Customer may send requests requiring further assistance to privacy@lextree.ai. The parties may agree reasonable fees for exceptional assistance where permitted by law, but fees or fee discussions will not prevent timely performance of mandatory assistance obligations or the effective exercise of required rights.


8. Data Breach Notification

Berkman will notify Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed on Customer’s behalf, in accordance with Article 33(2) of the GDPR and Section 5.2 of the Agreement. The notice will include available information, with further details provided as the investigation progresses, without undue further delay.

Berkman will provide the information and reasonable assistance described in Section 5.2 of the Agreement to support Customer’s compliance with applicable breach-notification obligations. Customer remains responsible for determining and making any notifications required of Customer to supervisory authorities or Data Subjects. This does not limit any notification obligation applicable to Berkman under Data Protection Law.


9. Data Protection Impact Assessments

Taking into account the nature of processing and information available to Berkman, Berkman will assist Customer with its obligations under Articles 32–36 of the GDPR, including security, data protection impact assessments, and prior consultation with a supervisory authority. Standard descriptions of processing and security measures are the starting point; Customer remains responsible for its own assessment and consultation. The assistance and fee safeguards in Section 7.2 also apply here.


10. Audits

10.1 Information and Reports

Berkman will, upon request, make available to Customer all information necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. Customer will ordinarily first review Berkman’s documentation and any relevant certifications or independent audit reports that Berkman makes available.

10.2 Further Verification

Berkman will allow for and contribute to audits, including inspections, conducted by Customer or a qualified independent auditor designated by Customer and bound by confidentiality, to the extent required by Data Protection Law or the applicable SCCs. The parties will assess in good faith the appropriate scope and method of verification, taking account of the information already provided, the nature of the processing, and relevant risks. This DPA does not establish a fixed annual audit entitlement.

10.3 Procedures and Costs

Customer will provide written notice describing the proposed audit’s purpose and scope, ordinarily at least thirty (30) days in advance. Shorter notice will apply where reasonably necessary because of a security incident, indications of non-compliance, or a regulatory requirement. Audits will take place during normal business hours, avoid unreasonable disruption, and follow reasonable confidentiality and security safeguards that protect other customers’ data. Berkman will provide access to relevant records, systems, premises, and personnel as necessary for the audit.

Customer bears all reasonable costs and expenses of an audit it requests, including its auditor’s fees and Berkman’s reasonable, documented costs of assisting with the audit. Charges must be proportionate and must not prevent the effective exercise of required audit rights.

10.4 Required Rights

These procedures do not limit rights under Data Protection Law or the applicable SCCs, including Customer’s right to determine the appropriate form of audit where required, or a competent supervisory authority’s powers. Documentation, certifications, or reports do not replace an inspection where one is required under those provisions.


11. International Data Transfers

11.1 Transfer Mechanism

Berkman is established in the United States. The selected hosting region determines primary application storage and retained backup locations as described in Section 5.5 of the Agreement. US personnel provide operations and support, and the Sub-Processor list identifies processing outside the selected region, including authentication, support communications, error monitoring, and temporary backup processing.

Where a transfer is restricted under Data Protection Law, the parties apply the safeguards below to the extent legally applicable to that transfer. A transfer to a recipient or country covered by an applicable adequacy decision may rely on that decision within its scope. If the SCCs below are not an available legal mechanism for particular processing, including because of the importer’s territorial scope under the GDPR, Berkman must establish another applicable lawful transfer mechanism before making that restricted transfer. EU hosting alone does not eliminate the need for applicable transfer safeguards.

11.2 Application of the SCCs

The parties agree to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as follows:

(a) Module Two (Controller to Processor) applies where Customer is a controller, and Module Three (Processor to Processor) applies where Customer is a processor; each applies to the processing for which that role is relevant;

(b) Clause 7 — the optional docking clause is included, allowing additional parties to accede;

(c) Clause 9(a) — Option 2 (general written authorization) applies, with a notice period of thirty (30) days for new Sub-Processors;

(d) Clause 11 — the optional language on independent dispute resolution is not included;

(e) Clause 17 — Option 1 applies; the SCCs are governed by Irish law;

(f) Clause 18(b) — disputes are resolved before the courts of Ireland, without limiting Data Subjects’ rights under Clause 18(c); and

(g) Annexes I and II of the SCCs are completed using the information in Annex 1 and Annex 2 of this DPA. Customer’s acceptance of the Agreement also constitutes acceptance of these incorporated SCCs; Berkman agrees to them by entering into the Agreement. The Agreement’s acceptance record supplies the date and evidence of execution. No separate negotiated form is required.

11.3 UK and Swiss Transfers

United Kingdom. For restricted transfers governed by UK Data Protection Law, the parties incorporate the UK International Data Transfer Addendum issued by the Information Commissioner, version B1.0 in force from March 21, 2022, including its mandatory Part 2 clauses as revised under its Section 18 (“UK Addendum”). Its tables are completed as follows:

UK Addendum tableAgreed information
Table 1: Parties and start dateThe parties, contacts, roles, and acceptance details are those in Annex 1(A). The start date is the effective date of the Agreement incorporating this DPA. Customer’s main or registered address and official identifier, where applicable, are those supplied in the Order Form or contracting records. Berkman’s full name is Berkman LLC, trading as Berkman Solutions, a Wyoming LLC; its US employer identification number (EIN) is 45-1996380. Its registered address is 109 East 17th Street, Suite 4137, Cheyenne, WY 82001, USA, for entity identification only. All correspondence must use the PO Box in Annex 1(A).
Table 2: Selected SCCsThe SCCs identified in Section 11.2, with Module Two or Module Three and the clause selections stated there; the UK Addendum makes the required UK adaptations.
Table 3: Appendix informationAnnex 1(A) supplies SCC Annex I(A); Annex 1(B) supplies Annex I(B); Annex 2 supplies Annex II. The Sub-Processor list referenced in Section 6.1 supplies the relevant Sub-Processor information; general authorization applies.
Table 4: Ending on an approved changeBoth the importer and exporter may end the UK Addendum under, and only in accordance with, its Section 19.

The UK Addendum prevails over conflicting provisions of the SCCs for covered UK transfers.

Switzerland. For restricted transfers governed by the Swiss FADP, references in the SCCs to the GDPR are read to include the Swiss FADP as applicable to those transfers; references to EU or member state law are read to include Swiss law where necessary. The Swiss Federal Data Protection and Information Commissioner is the competent authority for the Swiss transfers. Clause 18(c) also permits Data Subjects habitually resident in Switzerland to bring proceedings in Switzerland. These adaptations do not displace the EU GDPR or its competent supervisory authority where both regimes apply. The governing-law selection in Section 11.2 remains subject to the SCCs’ requirement that third-party beneficiary rights be available.

11.4 Conflict

If the SCCs or UK Addendum conflict with this DPA or the Agreement, the applicable transfer terms prevail to the extent of the conflict for the transfer they cover. Nothing in the Agreement limits mandatory rights of Data Subjects or supervisory authorities.


12. Data Return and Deletion

At Customer’s choice, Berkman will return or delete Personal Data after the services end and delete existing copies unless retention is required by applicable law consistent with this DPA and the applicable SCCs. Unless Customer instructs otherwise, Berkman will make Personal Data available for export for thirty (30) calendar days and then delete it from production systems without undue delay. Berkman will fulfill valid return or deletion instructions without undue delay; conflicting waiting periods in Section 4.8 of the Agreement do not apply to those instructions or mandatory legal deadlines. Requests may be sent to team@lextree.ai.

Subject to those instructions and mandatory deadlines, copies may persist in operational backups for up to ninety (90) days and archival backups for up to twelve (12) months. They remain protected by this DPA, are kept beyond ordinary use, and are purged through normal rotation. Backups are used only to restore service; Berkman retains an opaque record identifier and deletion timestamp and re-applies deletions before restored data is used. Any legally required retained data is restricted to that purpose. The applicable switching and erasure rights under Section 4.9 of the Agreement take precedence over ordinary retention periods.


13. General

13.1 Precedence

If this DPA conflicts with the Agreement on personal data processing, this DPA controls. In all other matters, the Agreement governs.

13.2 Amendments

Updates to this DPA follow the notice and acceptance process in Section 9 of the Agreement, unless the parties have agreed another process in writing. Updates will not materially reduce the overall protection of Personal Data or amend the mandatory SCC or UK Addendum text except as those instruments permit. If a change in law requires another transfer mechanism or agreed documentation, the parties will cooperate to put it in place before the affected processing continues without a lawful basis. This Section does not override amendment requirements in a version already binding on Customer.

13.3 Liability

Each party’s liability under this DPA is subject to Section 14 of the Agreement to the extent permitted by Data Protection Law and the applicable SCCs or UK Addendum. Those limitations do not override the liability provisions of the applicable transfer terms, including liability between the parties, or restrict mandatory rights of Data Subjects or supervisory authorities.


Annex 1: Processing Details

This Annex describes the processing Berkman performs on Customer’s behalf and serves as Annex I to the Standard Contractual Clauses.

A. Parties

Data ExporterCustomer, with its legal name, address, and notice contact identified in the Order Form or contracting records; controller or processor according to Section 2.1. Customer’s activities relevant to the transfer are using the Platform to manage business records and compliance information for itself or authorized clients.
Data ImporterBerkman LLC, doing business as Berkman Solutions, a Wyoming limited liability company; US EIN 45-1996380; processor or sub-processor according to Section 2.1. Its relevant activities are providing, maintaining, securing, and supporting the Platform.
Correspondence addressBerkman LLC, PO Box 1701, Beaverton, OR 97075, USA. All postal correspondence under this DPA must use this address.
Importer contactPrivacy contact: privacy@lextree.ai; service and notice contact: team@lextree.ai. These are designated contact functions, not a representation that Berkman has appointed a statutory data protection officer.
Acceptance and dateThe parties’ acceptance of the Agreement incorporating this DPA and its recorded effective date constitute their execution and date for the incorporated transfer terms. Customer keeps its contracting details and designated contacts current.

B. Description of Processing

Subject matterProcessing Personal Data to provide the Lextree compliance management platform and related support
Duration and retentionThe Subscription Term and applicable return or deletion periods under Section 12. Support requests are retained no longer than necessary to respond and support use of the Platform, subject to valid instructions and law. Operational backups expire within 90 days and archival backups within 12 months, subject to Section 12. Audit and security records follow the periods in Annex 2, subject to applicable law and valid instructions.
Nature and purposeCollection, storage, organization, retrieval, display, transmission, access control, backup, restoration, troubleshooting, support, security monitoring, export, and deletion as needed to deliver the contracted service. Where enabled, an open-source model on DigitalOcean infrastructure produces vector embeddings from record and document text and search queries for semantic search. Model processing and the semantic-search index are in the Subscription’s hosting region: the United States or European Union, respectively. Berkman does not use Customer Data for model training.
Categories of Data SubjectsCustomer’s employees, contractors, agents, and other Authorized Users; business contacts and individuals whose information Customer enters into the Platform (e.g., officers, directors, registered agents, compliance contacts)
Categories of Personal DataNames, business contact details, professional roles, organizational affiliations, user and Subscription identifiers, membership and permissions; personal information in permitted business records, documents, attachments, and support requests; relevant subscription context and technical information such as IP addresses, user agents, sign-in events, activity records, diagnostic details, and search queries processed on Customer’s behalf.
Sensitive data and restrictionsSpecial-category data under Article 9, criminal-conviction and offence data under Article 10, and other Prohibited Data under Section 4.4 of the Agreement are not authorized processing categories. Customer must not submit them. The parties will apply the DPA’s safeguards to any such data inadvertently received while arranging lawful removal or other necessary handling.
Transfer frequencyRecurring throughout service delivery: application and authentication requests as users access the service; monitoring as events occur; scheduled backup operations; support synchronization and requests as relevant records or requests arise; exports, administration, and deletion as needed or instructed.
Recipients and sub-processingBerkman’s authorized US personnel and the Sub-Processors listed under Section 6.1, within their stated purposes, data categories, and locations. Each Sub-Processor’s processing lasts for its service engagement and applicable deletion periods under its obligations and this DPA. Customer-directed recipients receive data only as instructed.

C. Competent Supervisory Authority

The competent supervisory authority is determined under SCC Clause 13: the authority responsible for the Data Exporter’s GDPR compliance where it is established in the EU; if the Data Exporter is outside the EU but within Article 3(2) and must appoint a representative, the authority of the member state where that representative is established; or, where the representative exemption applies, an authority in a member state where affected Data Subjects are located, as identified by Customer. Customer supplies the relevant establishment, representative, or affected-state information in its contracting records or on request. Irish governing law does not by itself select the Irish supervisory authority. For UK and Swiss transfers, Section 11.3 applies.


Annex 2: Security Measures

This Annex describes the technical and organizational security measures Berkman maintains and serves as Annex II to the Standard Contractual Clauses.

MeasureDescription
Encryption in transitAll data transmitted between Customer and the Platform is encrypted using TLS 1.2 or higher
Encryption at restCustomer Data is encrypted at rest using AES-256 or equivalent
Access controlsRole-based access controls limit access to Personal Data to authorized personnel based on job function and need-to-know
AuthenticationMulti-factor authentication for Berkman personnel accessing production systems
Audit loggingDatabase-level audit triggers record changes to business records with the acting user where available. Sign-in attempts and security events include source IP address and user agent. Edge access logs redact credentials and session tokens. Audit records are retained for twelve (12) months, or thirty-six (36) months on plans that include audit history; access-control, sign-in, and security records are archived to separate object storage for three (3) years to support security-incident investigation, subject to applicable law and valid deletion instructions.
Network securityProduction systems use private networking in each hosting region, with database access restricted to authorized application and administrative connections. Cloud firewalls restrict exposed ports to those needed for the service. Administrative access uses an identity-based private network. Brute-force protections and rate limits reduce abusive access.
Incident responseDocumented incident response procedures with defined roles, escalation paths, and communication protocols
PersonnelConfidentiality obligations for personnel with access to Personal Data; practical security and incident-response instruction appropriate to their responsibilities
Sub-Processor oversightDue diligence and contractual data protection obligations for all Sub-Processors
Business continuityRegular backups with tested restoration procedures; operational backup copies expire within 90 days and archival copies within 12 months; deletions are re-applied on any restore

Berkman reviews and updates these measures periodically. Updates will not materially reduce the overall level of protection.


Changes

DateChange
September 26, 2026Initial DPA published.

This Data Processing Agreement is Exhibit A to the Terms of Service.

Search