Privacy Policy
Privilege-Native Architecture • Data Minimization • Transparency
Version 3.0 · Effective Date: September 30, 2026 · Last Updated: September 30, 2026 · Supersedes: Privacy Policy dated February 19, 2026
1. Introduction and Scope
LexAxiom, Inc. ("LexAxiom," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy ("Policy") describes how we collect, use, disclose, and protect information when you visit our websites or use our software-as-a-service platform and related services (collectively, the "Services").
HOW OUR ARCHITECTURE SHAPES THIS POLICY
LexAxiom is built on a Privilege-Native Architecture with Bring Your Own Key (BYOK) encryption. Customer Data is encrypted with keys that each Customer generates and controls, and LexAxiom does not hold those keys in any system of record or backup. To do the work you ask of it (searching, drafting, and running agent workflows), the platform must process Customer Data in decrypted form, in memory, while your key is active. Sections 3.4, 9, and 10 explain what that means in plain terms.
What we do not do: we do not train artificial intelligence (AI) models on Customer Data, we do not sell or share it, and our personnel do not access it except as described in Section 4.2.
This Policy applies to: (a) visitors to our websites; (b) organizations that subscribe to the Services ("Customers"); (c) individuals a Customer authorizes to use the Services ("Authorized Users"); and (d) individuals whose personal information a Customer processes through the Services.
2. Our Two Roles: Business and Service Provider
Privacy law asks who decides why and how information is used. For some information we decide; for the rest, our Customers do.
(a) Business or Controller. For Account Information, Operational Metadata, and website data (Sections 3.1 through 3.3), LexAxiom determines the purposes and means of processing. We act as a "business" under the California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.140(d), and as a "controller" under comparable state laws and the European Union (EU) General Data Protection Regulation (GDPR). This Policy governs that information.
(b) Service Provider or Processor. For Customer Data (Section 3.4), the Customer determines the purposes and means. LexAxiom processes Customer Data only on the Customer's documented instructions, as a "service provider" under Cal. Civ. Code § 1798.140(ag) and a "processor" under comparable laws. The Customer's agreement with LexAxiom, including the End User License Agreement (EULA) and any Data Processing Addendum (DPA), governs Customer Data. If that agreement and this Policy conflict as to Customer Data, the agreement controls.
(c) If you are a client of a law firm or business that uses LexAxiom. Your relationship is with that organization, which is responsible for its own privacy notices to you. Please direct requests about your information to that organization. If we receive a request from you about Customer Data, we will refer it to the responsible Customer and assist that Customer as our agreement requires.
3. Information We Collect
3.1 Account Information
When a Customer creates an account or provisions an Authorized User, we collect: name and business email address; organization name, role, and billing address; payment information (processed by third-party payment processors; we do not store full payment card numbers); account credentials and authentication data, including multi-factor authentication (MFA) settings; and communication preferences and support correspondence.
3.2 Operational Metadata
Running a secure and reliable platform requires logs. Like every cloud provider, we automatically collect certain technical information when the Services are used ("Operational Metadata"), including: Internet Protocol (IP) address; device, browser, and operating system type; login and session events (timestamps, success or failure, and MFA status); feature usage events (which functions were used, and when); error reports and crash diagnostics; security event logs (for example, failed login attempts, permission changes, and administrative actions); and Application Programming Interface (API) request logs.
Operational Metadata describes how the Services are being used. It is not the content of your matters. We design Operational Metadata to exclude Customer Data content: error reports and usage events are scrubbed of document text, prompts, and outputs. File names, matter names, prompts, and search queries entered into the Services are Customer Data (Section 3.4), not Operational Metadata, and are protected accordingly.
WHY WE LOG
An earlier version of this Policy stated that we did not log IP addresses or user activity. We have replaced that statement with this one. The security controls our Customers rely on (MFA, brute-force protection, anomaly detection, incident investigation, and the independent audits that verify them) cannot operate without access logs. The honest position, and the one taken by the leading legal technology and cloud providers, is to log, to scope the logs narrowly, to keep them for a defined period (Section 11), and never to use them to profile you.
3.3 Website Visitors and Cookies
On our public websites we use strictly necessary cookies and privacy-respecting analytics to measure site performance. We do not use third-party advertising cookies, pixels, or cross-context behavioral advertising on the Services. If we introduce such technologies on our public marketing website in the future, we will update this Policy and honor the opt-out signals described in Section 8 before doing so.
3.4 Customer Data
"Customer Data" means all data, documents, content, prompts, and outputs that a Customer or its Authorized Users submit to or generate through the Services, including inputs to and outputs from AI Features (as defined in the EULA). Customer Data is encrypted at rest with Customer-Managed Keys (Section 10). We process Customer Data only to provide the Services to the Customer and as the Customer instructs.
4. How We Use Information
4.1 Purposes
We use Account Information and Operational Metadata to: (a) provide, operate, maintain, and secure the Services; (b) authenticate users and manage accounts; (c) process payments and send invoices; (d) detect, investigate, and prevent fraud, abuse, and security incidents; (e) provide customer support; (f) comply with legal obligations and enforce our agreements; (g) communicate with you about the Services, including service announcements and security notices and, where you have consented or the law otherwise permits, marketing communications from which you may opt out at any time; and (h) analyze aggregate, de-identified usage patterns to improve the performance, reliability, and design of the Services.
We use Customer Data only to provide the Services to the Customer, including operating AI Features on the Customer's behalf, and as the Customer otherwise instructs. We do not use Customer Data to improve or develop our products, to build profiles, or for marketing.
4.2 Access to Customer Data by LexAxiom Personnel
LexAxiom personnel do not access Customer Data except: (a) to provide or support the Services at the Customer's request under our Support Access Policy, which requires authorization by the Customer's designated attorney-owner, enforces that authorization as a technical control in the key management layer rather than as a procedural policy alone, and prohibits snapshots, exports, or recordings during any support session; (b) to investigate a security incident affecting the Customer, with notice to the Customer; or (c) to comply with applicable law or a binding order of a governmental body, subject to Section 9.
4.3 AI Features and Model Providers
When you use AI Features, the relevant portions of Customer Data are transmitted, encrypted in transit, to the large language model (LLM) providers identified on our Subprocessor page. We require our AI provider Subprocessors, by contract, to: (a) process Customer Data only to generate the requested output; (b) not use Customer Data or outputs to train, fine-tune, or improve their models or services; (c) not retain Customer Data or outputs after the request is completed, and not log them for human review; and (d) not disclose Customer Data to any other party. Outputs generated for a Customer are that Customer's Customer Data. AI Features are configured so that no Customer's data is used to generate outputs for any other Customer.
5. No AI Training
COMMITMENT: LexAxiom does not use Customer Data or Content to train, fine-tune, or improve artificial intelligence or machine learning (ML) models, whether our own or a third party's. This commitment binds LexAxiom and all Subprocessors. We will not apply any change to this commitment retroactively to data already collected. Any future training use would require separate, affirmative, opt-in consent from the Customer, obtained independently of the EULA and this Policy, following clear and conspicuous notice of exactly what would change.
6. Information Sharing
6.1 No Sale or Sharing
LexAxiom does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah), and has not done so in the preceding twelve months. We do not monetize Customer Data in any way.
6.2 Limited Disclosure
We disclose information only: (a) to Subprocessors that need it to provide the Services, under written contracts that limit their use of the information to providing services to us and impose confidentiality and security obligations no less protective than this Policy; (b) in response to valid legal process, subject to Section 9; (c) to a successor in connection with a merger, acquisition, financing, or sale of assets, with notice to Customers before their information becomes subject to a different privacy policy, and with the commitments in Sections 5 and 6.1 continuing to bind the successor as to previously collected data; (d) to prevent an imminent threat of death or serious physical injury; (e) to our professional advisors, including auditors, counsel, and insurers, under confidentiality obligations; and (f) at your direction or with your consent.
6.3 Subprocessor Transparency
A current list of Subprocessors is maintained at https://www.lexaxiom.com/legal/subprocessors, including: name and headquarters location; processing activities; categories of data accessed; data residency regions; and applicable data transfer mechanisms. We update the list within ten (10) business days of any material change. Customers may subscribe to notice of changes and may object to a new Subprocessor as provided in the EULA.
7. Your Privacy Rights
Depending on your jurisdiction, you may have the right to: (a) Access: request a copy of the Personal Information we hold about you; (b) Correction: request correction of inaccurate Personal Information; (c) Deletion: request deletion of your Personal Information; (d) Portability: receive your Personal Information in a portable and, to the extent technically feasible, readily usable format; (e) Opt Out: opt out of the sale or sharing of Personal Information, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects (we do not engage in these activities); (f) Limit Use: limit the use and disclosure of Sensitive Personal Information; (g) Appeal: appeal our decision on a request; and (h) Non-Discrimination: exercise these rights without discriminatory treatment.
To exercise rights: privacy@lexaxiom.com or https://www.lexaxiom.com/privacy-rights. We verify requests using information associated with your account. Where the law permits, you may use an authorized agent.
Response time: 45 days, extendable once by an additional 45 days with notice where reasonably necessary. Appeals: we will respond in writing within the period required by applicable law (not more than 60 days), with our reasons. If we deny an appeal, we will provide a method for you to contact your state attorney general. See, e.g., Tex. Bus. & Com. Code § 541.053.
Requests concerning Customer Data: because we process Customer Data on behalf of Customers, we refer such requests to the responsible Customer and assist the Customer as our agreement requires.
8. Global Privacy Control (GPC)
LexAxiom honors Global Privacy Control (GPC) signals and other recognized opt-out preference signals. When we detect such a signal from your browser or device, we treat it as a valid request to opt out of the sale or sharing of Personal Information and of targeted advertising under California, Colorado, Connecticut, Texas, and other applicable state laws. See Cal. Civ. Code § 1798.135(b)(1); Cal. Code Regs. tit. 11, § 7025; Colo. Rev. Stat. § 6-1-1306(1)(a)(IV); Conn. Gen. Stat. § 42-520(e); Tex. Bus. & Com. Code § 541.055(e). No additional verification is required. Because we do not sell or share Personal Information, honoring the signal does not change how we treat your information.
9. Government Access
9.1 Response to Legal Process
We require valid legal process before disclosing information to a government body: a subpoena for basic subscriber and billing records; a court order for non-content records such as Operational Metadata; and a search warrant issued on a showing of probable cause for the contents of Customer Data. See 18 U.S.C. § 2703. We interpret every request narrowly, produce only what the process lawfully compels, and challenge requests that are overbroad, vague, or improperly issued. Where legally possible, we direct requesters to obtain Customer Data from the Customer, which is the party best positioned to assert privilege and other objections.
What we can produce depends on the state of your keys. While a Customer's key is active, the platform can decrypt Customer Data to provide the Services, and LexAxiom could be compelled by valid process to produce Customer Data in decrypted form. If a Customer has revoked or destroyed its key, LexAxiom cannot decrypt stored Customer Data and can produce only ciphertext, Account Information, and Operational Metadata. See Section 10 and the Key Custody Limitation below.
9.2 Customer Notification
We will notify affected Customers within 48 hours of receiving a government request for their information, unless prohibited by law or court order. If we are prohibited from giving notice, we will: (a) ask the requesting authority or the issuing court for permission to notify the Customer, and document that request; (b) seek judicial review of any indefinite nondisclosure order, including review under 18 U.S.C. § 3511 for national security letters; and (c) notify the Customer at the earliest legally permitted time.
KEY CUSTODY LIMITATION
LexAxiom does not hold Customer-Managed Keys in any system of record or backup. Key material is retrieved from the Customer's key service on demand and used only for immediate encrypt and decrypt operations. A Customer can revoke or destroy its key at any time, after which LexAxiom cannot decrypt stored Customer Data and cannot produce it in decrypted form to anyone, including a court.
This is a real protection, and it is a bounded one: while your key is active, the platform decrypts Customer Data to serve you, and valid legal process can reach what the platform can read. We state the boundary plainly because a promise a provider cannot keep protects no one.
COUNTERPOINT: THE DIGITAL RIGHTS VIEW
The Electronic Frontier Foundation (EFF) has long argued that vendor security claims without independent verification are marketing rather than assurance, and that a provider capable of accessing data can be compelled to do so. The courts have agreed with the second point. See In re Under Seal, 749 F.3d 276 (4th Cir. 2014) (affirming contempt sanctions against Lavabit, LLC, an encrypted email provider ordered to produce its private encryption keys). We accept both premises. That is why this Policy no longer describes access as architecturally impossible, why key custody stays with you, and why our encryption implementation is independently audited as described in Section 10.
10. Data Security
We maintain security measures including: (a) Encryption: Customer Data is encrypted at rest using the Advanced Encryption Standard (AES)-256 and in transit using Transport Layer Security (TLS) 1.2 or higher; (b) Key Custody (BYOK): Customers generate and hold their own encryption keys in a key management service (KMS) they control; LexAxiom retrieves key material on demand for immediate encrypt and decrypt operations and does not persist it in any system of record or backup; Customers may rotate, revoke, or destroy their keys at any time; (c) Access Controls: role-based access, least-privilege administration, MFA, and attorney-owner authorization for support access (Section 4.2); (d) Audits: annual System and Organization Controls (SOC) 2 Type II examination; (e) Penetration Testing: annual independent testing; (f) Cryptographic Audit: at least every two years, an independent audit of our key custody and encryption implementation verifying that no master keys, key escrow mechanisms, or backdoors exist, that key material is not persisted, and that the implementation matches our published architecture documentation; (g) Employee Training: regular security awareness training; and (h) Security Incident Notification: notice to affected Customers within 48 hours after we become aware of a Security Incident (as defined in the EULA), with information sufficient to support the Customer's own notification obligations.
11. Data Retention
We retain information as follows: (a) Account Information: for the duration of the account plus 30 days, then deleted except as retained under (b); (b) Billing Records: seven years, to satisfy legal, tax, and audit requirements; (c) Customer Data: for the subscription term and as the Customer configures; following a deletion request or account termination, Customer Data is retained for a 90-day export window and then deleted from active systems within 30 days, with encrypted backups overwritten within 90 days thereafter; a Customer's destruction of its key renders any residual ciphertext permanently unreadable; (d) Operational Metadata: security and access logs for 12 months and other logs for up to 180 days, unless a longer period is required for an active security investigation, a legal hold, or a legal obligation; (e) AI Feature inputs and outputs: retained as Customer Data under (c) and not retained by AI provider Subprocessors after a request is completed; and (f) Aggregate Analytics: indefinitely, in de-identified form that cannot reasonably be linked to any individual.
12. International Transfers
The Services are hosted in the United States and in any Data Residency Region a Customer selects under the EULA. For transfers of Personal Information outside your jurisdiction, we rely on: the EU Standard Contractual Clauses (SCCs) for transfers from the EU and the European Economic Area (EEA); the United Kingdom (UK) International Data Transfer Agreement (IDTA) or Addendum; encryption and access controls as supplementary measures; and compliance with the United States Department of Justice (DOJ) rule restricting access to bulk sensitive personal data by countries of concern, 28 C.F.R. pt. 202, under which we do not transfer covered data to countries of concern.
13. Children's Privacy
The Services are not directed to children under 16. We do not knowingly collect Personal Information from children. If we learn that we have collected such information, we will delete it promptly.
14. Changes to This Policy
We may update this Policy. For material changes, we will provide at least 30 days' notice by email to Customer administrators and through the Alert Subscription Service before the changes take effect. We will not apply a material change to Section 5 (No AI Training) or Section 6.1 (No Sale or Sharing) to information collected before the change without your affirmative consent. The current version is always available at https://www.lexaxiom.com/privacy, and prior versions are archived at https://www.lexaxiom.com/privacy/archive. Continued use of the Services after a change takes effect constitutes acceptance of the updated Policy.
15. Contact Us
Privacy questions: privacy@lexaxiom.com
Data Protection Officer: dpo@lexaxiom.com
Mailing address: LexAxiom, Inc., 445 E FM 1382 Ste 3 #392, Cedar Hill, Texas 75104
Privacy rights portal: https://www.lexaxiom.com/privacy-rights
Questions: legal@lexaxiom.com · privacy@lexaxiom.com