Pre-launch draft — Lexboard is not yet operating as a legal entity. These documents are drafts under legal review and are not yet in effect or binding.
Legal
Effective Date: May 11, 2026. This DPA is incorporated by reference into the Lexboard Master Services Agreement (or Terms of Service) executed between the Lexboard operating entity (in formation) and the customer law firm.
1
This Data Processing Addendum (“DPA”) is entered into between the Lexboard operating entity (in formation) (“Processor”) and the customer identified at signup (“Controller” or “Customer”). It governs the processing of Personal Data by Processor on behalf of Controller in connection with the provision of the Lexboard platform (the “Services”).
This DPA takes effect only upon formation of the Lexboard operating entity and removal of the pre-launch notice displayed above. Upon formation, the entity will ratify and assume this DPA, and it will apply as if executed by that entity from the date of acceptance.
In the event of any conflict between this DPA and the Master Services Agreement, this DPA controls with respect to the processing of Personal Data.
2
3
Processor processes Personal Data on Controller's behalf for the duration of the MSA and until all such Personal Data is deleted or returned per Section 11 below.
4
Processor processes Personal Data to: provide the Services (case management, document storage, communications, AI-assistive drafting, e-signature, and subscription billing for the firm’s own Lexboard fees — Lexboard does not hold, process, or transmit client, settlement, or trust funds; trust-accounting features are recordkeeping only), maintain platform security, meet legal obligations, and (in aggregated/de-identified form) improve the Services. Processor does not use Personal Data for its own marketing or to train its own machine-learning models.
5
The Services may process the following categories:
Sensitive categories (medical records, financial data, government IDs) are processed only because the legal-services use case requires it. Processor applies heightened controls per Section 7.
6
7
Processor implements technical and organizational measures appropriate to the risk, including:
A summary of current controls is available at /legal/security.
8
Processor uses the sub-processors listed at /legal/subprocessors to deliver the Services. Each sub-processor is bound by written data-protection commitments substantively equivalent to those in this DPA.
Processor will provide Controller with at least thirty (30) days' prior notice before adding or replacing a sub-processor. Controller may object in writing during the notice period; if the parties cannot reach a mutually acceptable resolution, Controller may terminate the affected Services without penalty.
9
Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after confirming a Personal Data Breach affecting Controller's Personal Data. Where investigation is ongoing, Processor may provide notification in phases as information becomes available. Notification is not an acknowledgment of fault or liability. The notification will include, where known:
Processor will cooperate with Controller's reasonable instructions to support Controller's regulatory notifications and Data-Subject notifications.
10
Processor provides Controller with tools to fulfill Data-Subject requests for access, correction, deletion, restriction, and portability. Where a Data Subject contacts Processor directly, Processor will (a) not respond to the substance of the request itself, (b) acknowledge receipt, and (c) refer the Data Subject to Controller as the responsible party.
10A
Controller represents and warrants that it has all rights, consents, and legal bases required to submit Personal Data to the Services, including (a) client authorizations for medical records (e.g., HIPAA authorizations under 45 CFR §164.508), (b) all consents required by applicable call-recording and wiretap laws for any recorded calls or voicemails, and (c) authority to act on behalf of its clients with respect to their Personal Data. Controller's instructions to Processor shall comply with applicable law. Controller will indemnify Processor for third-party claims arising from Controller's breach of this Section.
11
On cancellation, firm administrators retain export access for 30 days (via the admin-only firm-data export endpoint). Customer Data is deleted from primary systems within 90 days of cancellation, except as required by law. Encrypted daily backups containing the data age out automatically within 7 days of primary deletion. The following are excepted from deletion:
12
Controller may, at its own expense and no more than once per twelve (12) months (or more frequently following a Personal Data Breach), audit Processor's compliance with this DPA. Audits may be conducted by Controller's personnel or a mutually acceptable third-party auditor under appropriate confidentiality obligations. Processor will provide reasonable cooperation, including SOC-2 reports or similar third-party assurance when available, in lieu of on-site audits where reasonable.
13
The Services are offered to United States law firms and Personal Data is processed in the United States. Lexboard does not target or offer the Services in the EU/UK. If Controller determines that case records incidentally include EU/UK data subjects, the parties will, upon Controller's written request, execute the EU Standard Contractual Clauses (2021/914, Module 2) and/or the UK International Data Transfer Addendum as needed.
14
With respect to Personal Information of California residents, Processor is a “Service Provider” (as defined by CCPA / CPRA). Processor shall not (a) sell or share Personal Information, (b) retain, use, or disclose Personal Information for any purpose other than performing the Services, or (c) combine Personal Information received from Controller with Personal Information received from other sources for cross-context behavioral advertising.
15
Lexboard is not a covered entity. In the typical personal-injury engagement, the customer firm obtains medical records under a HIPAA authorization (45 CFR §164.508) signed by its own client; records so obtained are not subject to HIPAA in the firm’s hands, and no Business Associate Agreement is required for Lexboard to process them. Lexboard nonetheless applies safeguards consistent with the HIPAA Security Rule (encryption in transit and at rest, role-based access, audit logging).
If the customer firm itself acts as a business associate of a covered entity (e.g., represents a healthcare provider), the firm must not upload PHI received in that capacity to Lexboard — Lexboard does not currently offer a Business Associate Agreement. Firms with BAA requirements should contact legal@lexboard.net to discuss enterprise options.
16
The MSA's limitation-of-liability and indemnification provisions apply to claims under this DPA, except that Processor's aggregate liability for breach of Sections 7 (Security) and 9 (Breach Notification) is capped at the greater of (a) two times (2×) the fees paid or payable by Controller in the twelve (12) months preceding the event, or (b) $100,000. Nothing in this DPA limits liability for a party's fraud or willful misconduct, limits Customer's payment obligations or the parties' indemnification obligations, or excludes liability that cannot be limited under applicable law.
17
This DPA, the Standard Contractual Clauses (where executed), the MSA, and the order form are interpreted as a single agreement. In the event of conflict, the order of precedence is: (1) this DPA, (2) the Standard Contractual Clauses where executed (which control only as to the transfers they govern), (3) the MSA, (4) the order form.
18
To exercise rights under this DPA, request a signed copy, or negotiate amendments, contact legal@lexboard.net.
Note for customers: this DPA is provided as a standard reference document. Customers are welcome to send their own DPA template for review — most reasonable variations are acceptable. Contact legal@lexboard.net to begin a redline.