Skip to main content

Data Processing Agreement

9 min read

Effective Date: April 2, 2026

This Data Processing Agreement (“DPA”) is Exhibit A to the Terms of Service (“Agreement”) between Customer and Berkman LLC (“Berkman”). It applies when Berkman processes personal data on Customer’s behalf under the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or the Swiss Federal Act on Data Protection (“Swiss FADP”).

Capitalized terms not defined here have the meanings given in the Agreement.

If this DPA and the Agreement conflict on personal data processing, this DPA controls.


1. Definitions

“Data Protection Law” means the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Swiss FADP, and any implementing or successor legislation, as applicable.

“Personal Data” means any information relating to an identified or identifiable natural person that Berkman processes on Customer’s behalf through the Platform.

“Processing” means any operation performed on Personal Data — including collection, storage, retrieval, use, disclosure, combination, erasure, or destruction.

“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

“Sub-Processor” means a third party Berkman engages to process Personal Data on Customer’s behalf.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to processors established in third countries, approved by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.


2. Roles and Scope

2.1 Roles

Customer is the controller. Berkman is the processor. Each party will comply with its obligations under Data Protection Law.

2.2 Scope of Processing

Berkman processes Personal Data only to provide, maintain, and improve the Platform as described in the Agreement. The details of processing — including the categories of data, data subjects, and processing activities — are described in Annex 1 of this DPA.

2.3 Duration

Berkman processes Personal Data for the duration of the Agreement. After the Agreement ends, Berkman handles Personal Data as described in Sections 4.5 and 4.6 of the Agreement (data export and deletion).


3. Customer’s Instructions

3.1 Documented Instructions

Berkman will process Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s configuration of the Platform constitute Customer’s instructions. Customer may provide additional written instructions consistent with the Agreement.

3.2 Instruction Limits

If Berkman believes an instruction violates Data Protection Law, Berkman will promptly notify Customer and may pause the relevant processing until Customer provides clarified instructions.

3.3 No Other Purpose

Berkman will not process Personal Data for any purpose other than fulfilling Customer’s instructions — except where required by EU or member state law. If law requires Berkman to process Personal Data for another purpose, Berkman will inform Customer before processing (unless the law prohibits this notification).


4. Confidentiality

Berkman ensures that all persons authorized to process Personal Data are bound by confidentiality obligations — whether by contract or by law. This is in addition to the confidentiality obligations in Section 12 of the Agreement.


5. Security

Berkman maintains the technical and organizational security measures described in Section 5.1 of the Agreement. These measures are appropriate to the risk and include encryption in transit and at rest, role-based access controls, and audit logging.

Berkman may update its security measures over time, but will not materially reduce the overall level of protection.


6. Sub-Processors

6.1 Authorization

Customer gives Berkman general written authorization to engage Sub-Processors to process Personal Data. Berkman maintains the authoritative list of current Sub-Processors — including each Sub-Processor’s purpose, the categories of Personal Data it processes, and its location — at lextree.ai/legal/sub-processors. That page also records changes to the list.

6.2 Notice of Changes

Berkman will update the Sub-Processor list and give Customer at least thirty (30) days’ notice before a new Sub-Processor begins processing Personal Data. Customer may subscribe to change notices by emailing team@lextree.ai.

6.3 Objection

If Customer objects to a new Sub-Processor on reasonable data protection grounds, the parties will negotiate in good faith. If they cannot resolve the objection, Customer may terminate the affected services without penalty. This is the same process as Section 5.3 of the Agreement.

6.4 Sub-Processor Obligations

Berkman imposes data protection obligations on each Sub-Processor that are no less protective than this DPA. Berkman remains responsible to Customer for each Sub-Processor’s performance.


7. Data Subject Rights

7.1 Assistance

Berkman will assist Customer in responding to requests from Data Subjects exercising their rights under Data Protection Law — including rights of access, rectification, erasure, restriction, portability, and objection.

7.2 How Berkman Helps

Berkman will promptly notify Customer if Berkman receives a request from a Data Subject directly. Berkman will not respond to the Data Subject unless Customer instructs Berkman to do so or law requires it.

The Platform’s export and deletion tools (described in Sections 4.5 and 4.6 of the Agreement) are the primary means for Customer to fulfill Data Subject requests.


8. Data Breach Notification

Berkman will notify Customer of a confirmed security breach affecting Personal Data within seventy-two (72) hours, as described in Section 5.2 of the Agreement. That notification satisfies Berkman’s obligation under Article 33(2) of the GDPR to notify the controller without undue delay.


9. Data Protection Impact Assessments

If Customer must carry out a data protection impact assessment or prior consultation with a supervisory authority under Articles 35 or 36 of the GDPR, Berkman will provide reasonable assistance — including information about Berkman’s processing activities and security measures.


10. Audits

10.1 Information

Berkman will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR.

10.2 Audit Right

Customer (or a qualified third-party auditor bound by confidentiality) may audit Berkman’s compliance with this DPA once per year, with at least thirty (30) days’ advance written notice. Audits take place during normal business hours and must not unreasonably disrupt Berkman’s operations.

10.3 Cooperation

Berkman will cooperate with audits and provide reasonable access to relevant records, systems, and personnel. Customer bears the cost of any audit it initiates.

10.4 Certifications and Reports

If Berkman holds relevant certifications or third-party audit reports (such as SOC 2), Berkman may provide those to Customer in place of an on-site audit, provided the report addresses the matters Customer’s audit would cover.


11. International Data Transfers

11.1 Transfer Mechanism

When the Platform transfers Personal Data from the European Economic Area (“EEA”), the United Kingdom, or Switzerland to the United States (where the Platform’s infrastructure is located, per Section 5.5 of the Agreement), the Standard Contractual Clauses apply as the transfer mechanism.

11.2 Application of the SCCs

The parties agree to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as follows:

(a) Module Two (Controller to Processor) applies;

(b) Clause 7 — the optional docking clause is included, allowing additional parties to accede;

(c) Clause 9(a) — Option 2 (general written authorization) applies, with a notice period of thirty (30) days for new Sub-Processors;

(d) Clause 11 — the optional language on independent dispute resolution is not included;

(e) Clause 17 — Option 1 applies; the SCCs are governed by the law of the EU member state where Customer is established (or, if Customer is not established in the EU, the law of Ireland);

(f) Clause 18(b) — disputes are resolved before the courts of the same member state identified in Clause 17 (or Ireland, as applicable); and

(g) Annexes I and II of the SCCs are completed using the information in Annex 1 and Annex 2 of this DPA.

11.3 UK and Swiss Transfers

For transfers from the United Kingdom, the SCCs apply as supplemented by the UK International Data Transfer Addendum (issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018). For transfers from Switzerland, the SCCs apply with the modifications required by the Swiss FADP.

11.4 Conflict

If the SCCs conflict with this DPA, the SCCs prevail to the extent of the conflict — but only for the Personal Data transfer they cover.


12. Data Return and Deletion

When the Agreement ends, Berkman will make Personal Data available for export for thirty (30) days, then delete it from production systems within a commercially reasonable time. Encrypted backup copies are purged within ninety (90) days through normal rotation. This is consistent with Sections 4.5 and 4.6 of the Agreement.


13. General

13.1 Precedence

If this DPA conflicts with the Agreement on personal data processing, this DPA controls. In all other matters, the Agreement governs.

13.2 Amendments

This DPA may be amended in writing signed by both parties. If Data Protection Law changes in a way that requires updates to this DPA, Berkman will propose amendments and the parties will negotiate in good faith.

13.3 Liability

Each party’s liability under this DPA is subject to the limitations in Section 14 of the Agreement.


Annex 1: Processing Details

This Annex describes the processing Berkman performs on Customer’s behalf and serves as Annex I to the Standard Contractual Clauses.

A. Parties

Data Exporter (Controller)Customer, as identified in the Agreement
Data Importer (Processor)Berkman LLC, 109 East 17th Street, Suite 4137, Cheyenne WY 82001, USA
Contactteam@lextree.ai

B. Description of Processing

Subject matterProcessing Personal Data to provide the Lextree compliance management platform
DurationThe Subscription Term, plus the data export and deletion periods described in Sections 4.5 and 4.6 of the Agreement
Nature and purposeStorage, retrieval, display, organization, and transmission of Personal Data as needed to operate the Platform, provide support, and maintain the service
Categories of Data SubjectsCustomer’s employees, contractors, agents, and other Authorized Users; business contacts and individuals whose information Customer enters into the Platform (e.g., officers, directors, registered agents, compliance contacts)
Categories of Personal DataNames, titles, business email addresses, phone numbers, professional roles and responsibilities, organizational affiliations, and other business contact information Customer enters into the Platform. The Platform is not designed to process special categories of data (Article 9 GDPR) or Prohibited Data as defined in Section 4.4 of the Agreement.

C. Competent Supervisory Authority

The supervisory authority of the EU member state where the Data Exporter is established. If the Data Exporter is not established in the EU, the Irish Data Protection Commission.


Annex 2: Security Measures

This Annex describes the technical and organizational security measures Berkman maintains and serves as Annex II to the Standard Contractual Clauses.

MeasureDescription
Encryption in transitAll data transmitted between Customer and the Platform is encrypted using TLS 1.2 or higher
Encryption at restCustomer Data is encrypted at rest using AES-256 or equivalent
Access controlsRole-based access controls limit access to Personal Data to authorized personnel based on job function and need-to-know
AuthenticationMulti-factor authentication for Berkman personnel accessing production systems
Audit loggingAll access to Customer Data and administrative actions are logged and retained for review
Network securityFirewalls, intrusion detection, and network segmentation isolate production systems
Incident responseDocumented incident response procedures with defined roles, escalation paths, and communication protocols
PersonnelConfidentiality obligations for all personnel with access to Personal Data; security awareness training
Sub-Processor oversightDue diligence and contractual data protection obligations for all Sub-Processors
Business continuityRegular backups with tested restoration procedures; encrypted backup copies purged within 90 days of deletion from production

Berkman reviews and updates these measures periodically. Updates will not materially reduce the overall level of protection.


This Data Processing Agreement is Exhibit A to the Terms of Service.

Search