Skip to main content

Privacy Policy

17 min read

Effective Date: September 26, 2026

This Privacy Policy describes how Berkman LLC, a Wyoming limited liability company doing business as Berkman Solutions (“Berkman,” “we,” “us,” or “our”), collects, uses, and protects personal information through the Lextree compliance management platform (“Platform”) and the lextree.ai website (“Website”).

This Privacy Policy explains our information practices. Contractual obligations are set out in the Terms of Service (“Agreement”) and the applicable Data Processing Agreement (“DPA”). Capitalized terms not defined here have the meanings given in the Agreement.


1. What This Policy Covers

This Policy applies to:

(a) Visitors — people who browse the Website;

(b) Customers — organizations that subscribe to the Platform; and

(c) Authorized Users — individuals who access the Platform through their individual Accounts under a Customer’s Subscription.

This Policy does not apply to information that third parties collect through their own websites or services, even if linked from the Website or Platform.

Our roles. We act as a controller when we decide how to use information for our own account administration, billing, business communications, Website analytics, marketing, and protection of our business and services. We act as a processor or sub-processor for Customer Data and related support processing performed on Customer’s instructions. A Customer may itself act for another controller. The DPA governs our processing on Customer’s behalf; the responsible controller determines the purposes and lawful basis for that processing.


2. Information We Collect

2.1 Information You Provide

Account and Subscription information. When an individual creates an Account, we collect the name, email address, and profile information provided during registration. When a Customer creates a Subscription, we collect the organization and billing information provided for that Subscription.

Contact form submissions. When you submit a form on the Website, we collect the information you enter — including your name, work email address, company name, and message. We also collect technical context submitted with the form: your timezone, browser language, the page you submitted from, your referring URL, and any UTM campaign parameters.

IP address and approximate location. When you submit a form, our server records your IP address and derives an approximate location from it — city, state or region, and country. This is a coarse estimate produced by a geolocation database (MaxMind GeoLite2) hosted on our own server; it is not precise GPS location, and your IP address is not sent to a third party for this lookup. We use this to understand where inquiries come from and to detect spam and abusive submissions.

Marketing preferences. If you subscribe to marketing communications on the Website, we record that consent along with the date and context. If you hold an Account, we record your product-email preference (see Section 3(c)).

Customer support records. We synchronize Authorized Users’ names, email addresses, and Subscription membership, together with Subscription plan, seat, and billing information, to our customer support system solely to support use of the Platform.

Support requests. When you contact us for support, we collect the information you provide in your request. Support requests sent through the Request Help form inside the Platform also carry your Account email address and display name, the page you sent it from, your browser’s user agent and language, the Platform release, and a snapshot of your Account and current Subscription context (plan and trial status, notification settings, and your permission set; never the content of your records). We store these requests, customer support records, and contact form submissions in a system that we operate on our own infrastructure in the United States. The software provider does not receive this information through our use of the system.

Customer Data. Customers and Authorized Users enter data into the Platform — including entity records, compliance documents, contact information, and file attachments. Section 4 of the Agreement governs Customer Data. We process Customer Data on the Customer’s behalf as a data processor.

2.2 Information We Collect Automatically

Website and sign-up analytics. We operate our own analytics system on our infrastructure in the United States to measure Website traffic and count conversions on the Platform’s sign-up pages. Website analytics include pages viewed, the referring website, browser and device type, screen size, campaign (UTM) parameters, and location at country, region, and city level. The system sets no analytics cookies. The only thing it stores in your browser is your opt-out choice, if you make one. To distinguish visits, it computes a visitor identifier from your IP address, browser user agent, and our website identifier, hashed with a salt that changes monthly. It does not store your IP address.

On the Platform’s sign-up pages, conversion events record that an event such as a completed sign-up occurred, without identifying the individual or Account that converted. We do not link these analytics to names, email addresses, Accounts, or Subscription records, or use this system to track authenticated activity inside the Platform. Our server forwards IP addresses and user agents to the analytics system for the visitor and location processing described above; neither is stored.

The analytics software provider does not receive this information through our use of the system. The system honors your browser’s Do Not Track setting on the Website, and you can opt out of Website analytics with the control below.

Platform operational data. When Authorized Users use the Platform, we collect information about how the Platform is used — including features accessed, actions taken, and performance data. We use this to maintain, improve, and troubleshoot the Platform. These operational records are separate from the Website and sign-up analytics described above.

Session cookies. The Platform uses cookies for session management and authentication, including a session cookie set on the sign-up page before you sign in so the page can keep its state between steps. These cookies are necessary for the Platform to function, are not used for analytics, and cannot be disabled while using the Platform.

Bot protection. We use Cloudflare Turnstile on forms to verify that submissions come from real people, not automated scripts. Turnstile processes technical browser signals and may use cookies for this verification. See Cloudflare’s privacy policy for information about its processing. Our use of this service remains subject to our applicable privacy obligations.

Local storage. The Website stores your dark/light mode preference in your browser’s local storage. This data stays on your device and is never sent to our servers.

2.3 Information Not Requested or Permitted

We do not request Social Security numbers, personal identification or financial account numbers, health information, biometric data, criminal-conviction or offence data, or other Prohibited Data for entry into the Platform. Customers must not submit Prohibited Data as defined in Section 4.4 of the Agreement. Ordinary company registration and business tax or license identifiers are permitted if they do not function as personal identifiers. Free-text fields, uploads, and messages may inadvertently contain restricted information; contact us to arrange its removal. Payment card details entered in the payment provider’s checkout are processed by that provider rather than stored as Customer Data in Lextree.


3. How We Use Your Information

We use personal information for the following purposes:

(a) Providing the Platform. Processing Account and Subscription information and Customer Data to deliver, maintain, and support the Platform.

(b) Communicating with you. Responding to support requests, sending service announcements, and providing information you request through contact forms.

(c) Product updates and marketing. Necessary account, security, billing, and service notices are separate from optional promotional product updates, tips, and newsletters. We send promotional email with consent where required, or under a lawful existing-customer exception only where its conditions are met, including an opportunity to opt out when contact details are collected and in each message. Creating an Account alone is not consent to promotional email. You can change your product-email preference on your account page, unsubscribe through the link in promotional email, or contact us as described in Section 7.

(d) Improving our services. Analyzing usage patterns to improve the Platform and Website using aggregated or anonymized information from which Customers and individuals cannot reasonably be identified, as described in Section 4.7 of the Agreement. Pseudonymized identifiers remain protected as personal information where applicable. We do not use Customer Data to train or fine-tune models.

(e) Security. Protecting the Platform and its users from unauthorized access, fraud, and abuse, including screening Website form submissions for spam.

(f) Legal compliance. Meeting our legal obligations, responding to lawful requests, and enforcing our agreements.


4. How We Share Your Information

We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

We share personal information only in these circumstances:

4.1 Service Providers

We use providers for hosting, authentication, email, support communications, error monitoring, backup processing, payment processing, and Website security. Providers processing information on our behalf do so under applicable data protection terms. Some providers, such as payment processors, also act independently for purposes such as fraud prevention or legal compliance under their own privacy notices. Providers processing Personal Data on Customer’s behalf are identified, with their purposes and locations, in the Sub-Processor list. Software developers are not recipients merely because we run their software on our infrastructure.

4.2 At Your Direction

We share information when you direct us to — for example, when you use an integration or connect a third-party service to your Account.

4.3 AI Features

Where semantic search is enabled for a US-hosted or EU-hosted Subscription, Lextree uses an open-source model on DigitalOcean infrastructure to generate vector embeddings from record and document text and search queries. Berkman does not own or develop the underlying model. This is inference for search, not model training. Berkman does not use Customer Data to train, fine-tune, or improve models or authorize its Sub-Processors to do so.

Embedding generation and the semantic-search index are hosted in the Subscription’s selected region. For EU-hosted Subscriptions, the model processes record and document text and search queries entirely on DigitalOcean infrastructure in the European Union. US-hosted Subscriptions use DigitalOcean infrastructure in the United States. Other service-related processing, including US support, is described in Section 9 and the Sub-Processor list.

Customers may independently send exported data or data retrieved by their chosen API or MCP clients to external AI providers. Where a supported customer-selected AI integration is available, it transmits the data needed for the requested feature to the selected provider. Those providers’ terms and privacy practices govern their independent processing. Customer selection does not remove Berkman’s obligations for its own processing, security, or transmission of data. See Section 19 of the Agreement and the API Terms.

We may disclose personal information if required by law, regulation, legal process, or government request. Where permitted, we will notify you before disclosing.

4.5 Business Transfers

If Berkman is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

We may share information with your consent or at your direction for purposes not described in this Policy.


5. Data Retention

Individual Accounts. We retain Account information to maintain the individual’s login, profile, and preferences for the life of the Account, subject to deletion requests and applicable law. Deleting a Subscription does not itself delete its users’ Accounts. Account deletion or anonymization follows Section 4.8 of the Agreement, subject to the separate retention periods described in this Policy.

Subscription information and Customer Data. Retention and Customer-requested deletion follow Sections 4.5–4.9 of the Agreement and Section 12 of the DPA. Ordinarily, Customer Data is available for export for thirty (30) days after the Agreement ends, followed by production deletion. Valid return or deletion instructions and mandatory deadlines take precedence over ordinary waiting periods. Subject to those instructions and deadlines, copies may persist in operational backups for up to ninety (90) days and archival backups for up to twelve (12) months, protected and kept beyond ordinary use until purged. We retain an opaque record identifier and deletion timestamp so that deletions are re-applied before any restored data is used.

Contact form submissions. We retain contact form submissions for as long as needed to respond to your inquiry and maintain the business relationship. You may request deletion at any time.

Support requests. We retain support requests no longer than necessary to respond to the request and support use of the Platform. You may request deletion at any time, subject to applicable law.

Synchronized support records. We retain synchronized user, Subscription, plan, seat, and billing context only while needed to support use of the Platform. We remove or update these records when they are no longer needed, including following relevant Account or Subscription deletion, subject to valid instructions and the limited recordkeeping purposes below.

Billing and legal records. We retain limited transaction and correspondence records for applicable accounting, tax, dispute, and legal recordkeeping needs. Retention is limited to the information and period necessary for those purposes; it does not authorize continued ordinary use of deleted Customer Data.

Analytics. We retain analytics events for no more than twenty-four (24) months from collection. We do not link these analytics to Accounts or Subscription records. You can opt out as described in Section 2.2 and exercise applicable privacy rights as described in Section 7.

Sign-in and security records. We keep records of sign-in attempts and security events for the Platform, including source IP address and user agent, for twelve (12) months in the Platform and for three (3) years in an archive, to support the investigation of security incidents.

Product updates and marketing communications. We retain preferences and the consent or other permission record while needed to administer communications and demonstrate compliance. We remove you from active promotional mailing lists promptly after you unsubscribe. We may retain a minimal suppression record to honor your opt-out and a limited record of past consent where needed for legal compliance; these records are not used to continue marketing to you.


6. Data Security

We maintain administrative, technical, and physical security measures to protect personal information. These include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, audit logging, and network security controls. For more detail, see Section 5.1 of the Agreement and Annex 2 of the Data Processing Agreement.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information.


7. Your Rights and Choices

7.1 All Users

Marketing opt-out. Account holders can turn off product updates on their account page or through the unsubscribe link in every such email. Website subscribers can unsubscribe through the link in any marketing email or by contacting us at team@lextree.ai. Opting out does not affect service-related communications such as security notices, billing, and deletion confirmations.

Contact form data. You can request that we delete information you submitted through a contact form by emailing team@lextree.ai.

7.2 Platform Users (Authorized Users)

Authorized Users should direct requests about Customer Data to their organization (the Customer), which is responsible for handling the request or coordinating with the relevant controller. We assist Customers as described in the Data Processing Agreement. For information Berkman processes as a controller, such as its own account-administration or marketing records, contact privacy@lextree.ai directly.

7.3 Rights Under the GDPR

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under applicable data protection law:

(a) Access. Request a copy of the personal information we hold about you.

(b) Rectification. Request correction of inaccurate or incomplete information.

(c) Erasure. Request deletion of your personal information, subject to legal retention requirements.

(d) Restriction. Request that we restrict processing of your information in certain circumstances.

(e) Portability. Request your information in a structured, machine-readable format.

(f) Objection. Object to processing based on legitimate interests. You have an absolute right to object to direct marketing at any time: turn off product updates on your account page or use the unsubscribe link, and we will stop.

(g) Withdraw consent. Where processing is based on consent, withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise these rights, contact us at privacy@lextree.ai. Where the EU or UK GDPR applies to our response, we will act on the request and provide information on the action taken without undue delay and within one calendar month of receipt. If necessary because of the complexity or number of requests, we may extend that period by up to two further months and will explain the extension within the first month. If we cannot act on a request, we will explain why and the available complaint or review rights within the required period. We may request information reasonably needed to verify identity. Other applicable laws, including Swiss law, govern their corresponding rights and response requirements.

You also have the right to lodge a complaint with your local data protection supervisory authority (in the United Kingdom, the Information Commissioner’s Office).

7.4 Rights Under US State Privacy Laws

If you are a resident of California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you may have rights to access, delete, or correct your personal information, and to opt out of certain data practices. We do not sell personal information, share it for cross-context behavioral advertising, or use it for automated decision-making or profiling.

To exercise your rights, contact us at privacy@lextree.ai.


Where the GDPR applies to processing for which we act as controller, we use the following legal bases. We assess legitimate interests against individuals’ rights and reasonable expectations. For Customer Data processed on Customer’s instructions, the responsible controller determines the legal basis; our processor obligations are set out in the DPA.

PurposeLegal Basis
Account administration, billing, and responding to business inquiriesPerformance of a contract where the individual is a party (Article 6(1)(b)); otherwise legitimate interests in administering business relationships and communicating with representatives and users (Article 6(1)(f))
Website and sign-up analyticsLegitimate interests in understanding Website use and aggregate conversions (Article 6(1)(f)), subject to consent where applicable privacy or tracking law requires it
Optional promotional product updates and newslettersConsent where required (Article 6(1)(a)); otherwise legitimate interests in communicating about similar services under an applicable customer exception (Article 6(1)(f)), subject to the conditions in Section 3(c) and the right to object
Security and fraud prevention, including sign-in and security recordsLegitimate interest in protecting our services (Article 6(1)(f))
Legal compliance and protection of rightsA legal obligation recognized under Article 6(1)(c); for other applicable requirements or legal claims, legitimate interests under Article 6(1)(f) where appropriate and permitted

9. International Data Transfers

Berkman is located in the United States. The Subscription’s hosting region determines the location of its primary database, file storage, and retained backups: the United States (us.lextree.ai) or European Union (eu.lextree.ai). Service-related processing can occur elsewhere. Website form submissions, support records and requests, analytics, and Berkman’s business email are processed in the United States. US personnel operate and support the Platform, and providers may process information outside the primary hosting region, including temporarily during backup operations. The Sub-Processor list identifies those providers and locations.

Restricted transfers of Personal Data processed on Customer’s behalf are addressed in Section 11 of the DPA. For our own controller activities, we also use applicable transfer safeguards where required, such as a relevant adequacy decision or appropriate contractual safeguards, including the EU Standard Contractual Clauses with UK or Swiss adaptations where applicable. The customer DPA does not by itself cover every transfer of visitor, prospect, or other information processed for our own purposes. You may request information about the safeguards applicable to your information, including a copy of relevant contractual safeguards with necessary confidential information redacted, by emailing privacy@lextree.ai.


10. Children’s Privacy

The Platform and Website are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at privacy@lextree.ai and we will delete it.


11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will ordinarily provide at least thirty (30) days’ advance notice by email or by posting a notice on the Website. Where an earlier change is necessary to meet a legal requirement or address an urgent security issue, we will provide notice as soon as practicable. Non-material changes take effect when posted. This Policy is a notice of our practices; continued use is not consent to processing that legally requires consent. We will obtain that consent where required.

The “Effective Date” at the top of this page reflects the date of the most recent update.


12. Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights:

Email: privacy@lextree.ai

Mail (all correspondence): Berkman LLC PO Box 1701 Beaverton, OR 97075

For general support: team@lextree.ai


Changes

DateChange
September 26, 2026Initial policy published.

See the Terms of Service and Data Processing Agreement for contractual terms.

Search