Data Processing Agreement
Effective Date: April 2, 2026
This Data Processing Agreement (“DPA”) is Exhibit A to the Terms of Service (“Agreement”) between Customer and Berkman LLC (“Berkman”). It applies when Berkman processes personal data on Customer’s behalf under the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or the Swiss Federal Act on Data Protection (“Swiss FADP”).
Capitalized terms not defined here have the meanings given in the Agreement.
If this DPA and the Agreement conflict on personal data processing, this DPA controls.
1. Definitions
“Data Protection Law” means the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Swiss FADP, and any implementing or successor legislation, as applicable.
“Personal Data” means any information relating to an identified or identifiable natural person that Berkman processes on Customer’s behalf through the Platform.
“Processing” means any operation performed on Personal Data — including collection, storage, retrieval, use, disclosure, combination, erasure, or destruction.
“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
“Sub-Processor” means a third party Berkman engages to process Personal Data on Customer’s behalf.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to processors established in third countries, approved by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
2. Roles and Scope
2.1 Roles
Customer is the controller. Berkman is the processor. Each party will comply with its obligations under Data Protection Law.
2.2 Scope of Processing
Berkman processes Personal Data only to provide, maintain, and improve the Platform as described in the Agreement. The details of processing — including the categories of data, data subjects, and processing activities — are described in Annex 1 of this DPA.
2.3 Duration
Berkman processes Personal Data for the duration of the Agreement. After the Agreement ends, Berkman handles Personal Data as described in Sections 4.5 and 4.6 of the Agreement (data export and deletion).
3. Customer’s Instructions
3.1 Documented Instructions
Berkman will process Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s configuration of the Platform constitute Customer’s instructions. Customer may provide additional written instructions consistent with the Agreement.
3.2 Instruction Limits
If Berkman believes an instruction violates Data Protection Law, Berkman will promptly notify Customer and may pause the relevant processing until Customer provides clarified instructions.
3.3 No Other Purpose
Berkman will not process Personal Data for any purpose other than fulfilling Customer’s instructions — except where required by EU or member state law. If law requires Berkman to process Personal Data for another purpose, Berkman will inform Customer before processing (unless the law prohibits this notification).
4. Confidentiality
Berkman ensures that all persons authorized to process Personal Data are bound by confidentiality obligations — whether by contract or by law. This is in addition to the confidentiality obligations in Section 12 of the Agreement.
5. Security
Berkman maintains the technical and organizational security measures described in Section 5.1 of the Agreement. These measures are appropriate to the risk and include encryption in transit and at rest, role-based access controls, and audit logging.
Berkman may update its security measures over time, but will not materially reduce the overall level of protection.
6. Sub-Processors
6.1 Authorization
Customer gives Berkman general written authorization to engage Sub-Processors to process Personal Data. Berkman maintains the authoritative list of current Sub-Processors — including each Sub-Processor’s purpose, the categories of Personal Data it processes, and its location — at lextree.ai/legal/sub-processors. That page also records changes to the list.
6.2 Notice of Changes
Berkman will update the Sub-Processor list and give Customer at least thirty (30) days’ notice before a new Sub-Processor begins processing Personal Data. Customer may subscribe to change notices by emailing team@lextree.ai.
6.3 Objection
If Customer objects to a new Sub-Processor on reasonable data protection grounds, the parties will negotiate in good faith. If they cannot resolve the objection, Customer may terminate the affected services without penalty. This is the same process as Section 5.3 of the Agreement.
6.4 Sub-Processor Obligations
Berkman imposes data protection obligations on each Sub-Processor that are no less protective than this DPA. Berkman remains responsible to Customer for each Sub-Processor’s performance.
7. Data Subject Rights
7.1 Assistance
Berkman will assist Customer in responding to requests from Data Subjects exercising their rights under Data Protection Law — including rights of access, rectification, erasure, restriction, portability, and objection.
7.2 How Berkman Helps
Berkman will promptly notify Customer if Berkman receives a request from a Data Subject directly. Berkman will not respond to the Data Subject unless Customer instructs Berkman to do so or law requires it.
The Platform’s export and deletion tools (described in Sections 4.5 and 4.6 of the Agreement) are the primary means for Customer to fulfill Data Subject requests.
8. Data Breach Notification
Berkman will notify Customer of a confirmed security breach affecting Personal Data within seventy-two (72) hours, as described in Section 5.2 of the Agreement. That notification satisfies Berkman’s obligation under Article 33(2) of the GDPR to notify the controller without undue delay.
9. Data Protection Impact Assessments
If Customer must carry out a data protection impact assessment or prior consultation with a supervisory authority under Articles 35 or 36 of the GDPR, Berkman will provide reasonable assistance — including information about Berkman’s processing activities and security measures.
10. Audits
10.1 Information
Berkman will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR.
10.2 Audit Right
Customer (or a qualified third-party auditor bound by confidentiality) may audit Berkman’s compliance with this DPA once per year, with at least thirty (30) days’ advance written notice. Audits take place during normal business hours and must not unreasonably disrupt Berkman’s operations.
10.3 Cooperation
Berkman will cooperate with audits and provide reasonable access to relevant records, systems, and personnel. Customer bears the cost of any audit it initiates.
10.4 Certifications and Reports
If Berkman holds relevant certifications or third-party audit reports (such as SOC 2), Berkman may provide those to Customer in place of an on-site audit, provided the report addresses the matters Customer’s audit would cover.
11. International Data Transfers
11.1 Transfer Mechanism
When the Platform transfers Personal Data from the European Economic Area (“EEA”), the United Kingdom, or Switzerland to the United States (where the Platform’s infrastructure is located, per Section 5.5 of the Agreement), the Standard Contractual Clauses apply as the transfer mechanism.
11.2 Application of the SCCs
The parties agree to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as follows:
(a) Module Two (Controller to Processor) applies;
(b) Clause 7 — the optional docking clause is included, allowing additional parties to accede;
(c) Clause 9(a) — Option 2 (general written authorization) applies, with a notice period of thirty (30) days for new Sub-Processors;
(d) Clause 11 — the optional language on independent dispute resolution is not included;
(e) Clause 17 — Option 1 applies; the SCCs are governed by the law of the EU member state where Customer is established (or, if Customer is not established in the EU, the law of Ireland);
(f) Clause 18(b) — disputes are resolved before the courts of the same member state identified in Clause 17 (or Ireland, as applicable); and
(g) Annexes I and II of the SCCs are completed using the information in Annex 1 and Annex 2 of this DPA.
11.3 UK and Swiss Transfers
For transfers from the United Kingdom, the SCCs apply as supplemented by the UK International Data Transfer Addendum (issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018). For transfers from Switzerland, the SCCs apply with the modifications required by the Swiss FADP.
11.4 Conflict
If the SCCs conflict with this DPA, the SCCs prevail to the extent of the conflict — but only for the Personal Data transfer they cover.
12. Data Return and Deletion
When the Agreement ends, Berkman will make Personal Data available for export for thirty (30) days, then delete it from production systems within a commercially reasonable time. Encrypted backup copies are purged within ninety (90) days through normal rotation. This is consistent with Sections 4.5 and 4.6 of the Agreement.
13. General
13.1 Precedence
If this DPA conflicts with the Agreement on personal data processing, this DPA controls. In all other matters, the Agreement governs.
13.2 Amendments
This DPA may be amended in writing signed by both parties. If Data Protection Law changes in a way that requires updates to this DPA, Berkman will propose amendments and the parties will negotiate in good faith.
13.3 Liability
Each party’s liability under this DPA is subject to the limitations in Section 14 of the Agreement.
Annex 1: Processing Details
This Annex describes the processing Berkman performs on Customer’s behalf and serves as Annex I to the Standard Contractual Clauses.
A. Parties
| Data Exporter (Controller) | Customer, as identified in the Agreement |
| Data Importer (Processor) | Berkman LLC, 109 East 17th Street, Suite 4137, Cheyenne WY 82001, USA |
| Contact | team@lextree.ai |
B. Description of Processing
| Subject matter | Processing Personal Data to provide the Lextree compliance management platform |
| Duration | The Subscription Term, plus the data export and deletion periods described in Sections 4.5 and 4.6 of the Agreement |
| Nature and purpose | Storage, retrieval, display, organization, and transmission of Personal Data as needed to operate the Platform, provide support, and maintain the service |
| Categories of Data Subjects | Customer’s employees, contractors, agents, and other Authorized Users; business contacts and individuals whose information Customer enters into the Platform (e.g., officers, directors, registered agents, compliance contacts) |
| Categories of Personal Data | Names, titles, business email addresses, phone numbers, professional roles and responsibilities, organizational affiliations, and other business contact information Customer enters into the Platform. The Platform is not designed to process special categories of data (Article 9 GDPR) or Prohibited Data as defined in Section 4.4 of the Agreement. |
C. Competent Supervisory Authority
The supervisory authority of the EU member state where the Data Exporter is established. If the Data Exporter is not established in the EU, the Irish Data Protection Commission.
Annex 2: Security Measures
This Annex describes the technical and organizational security measures Berkman maintains and serves as Annex II to the Standard Contractual Clauses.
| Measure | Description |
|---|---|
| Encryption in transit | All data transmitted between Customer and the Platform is encrypted using TLS 1.2 or higher |
| Encryption at rest | Customer Data is encrypted at rest using AES-256 or equivalent |
| Access controls | Role-based access controls limit access to Personal Data to authorized personnel based on job function and need-to-know |
| Authentication | Multi-factor authentication for Berkman personnel accessing production systems |
| Audit logging | All access to Customer Data and administrative actions are logged and retained for review |
| Network security | Firewalls, intrusion detection, and network segmentation isolate production systems |
| Incident response | Documented incident response procedures with defined roles, escalation paths, and communication protocols |
| Personnel | Confidentiality obligations for all personnel with access to Personal Data; security awareness training |
| Sub-Processor oversight | Due diligence and contractual data protection obligations for all Sub-Processors |
| Business continuity | Regular backups with tested restoration procedures; encrypted backup copies purged within 90 days of deletion from production |
Berkman reviews and updates these measures periodically. Updates will not materially reduce the overall level of protection.
This Data Processing Agreement is Exhibit A to the Terms of Service.