Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how BEBCO Lexlink LLC (“Lexlink,” “we,” “us”) collects, uses, shares, and protects information in connection with the Lexlink case-management platform (the “Service”). Lexlink is a business-to-business platform used by law firms (“Firms”) to manage their practice. It applies to Firm users (attorneys and staff), the clients and prospective clients whose information Firms store in the Service, and visitors to our websites.
Where a Firm uses the Service to process information about its own clients, the Firm is the controller of that information and Lexlink acts as its processor/service provider, handling that information on the Firm’s behalf and under its instructions.
1. Information we collect
We collect the following categories of information:
- Account information — name, email address, password (stored hashed), phone, role, and professional profile details (e.g., bar admissions) you provide when you create or use an account.
- Firm and matter data — the information Firms enter into the Service, such as clients and contacts, matters/cases, tasks, calendar events, documents, time entries, invoices, trust-accounting records, and communications logged in the Service.
- Connected-account data — if a Firm user connects a Google or Microsoft account, the email messages and calendar events we access to provide the communication and calendar features (described in Sections 3–7). If a Firm connects an accounting system such as QuickBooks Online or Xero, the customer, invoice, payment, and expense records exchanged with that system to keep the Firm’s books in sync.
- Payment information — billing details and payment-method tokens, processed by our payment processor; Lexlink does not store full card numbers.
- Usage and device information — log data, IP address, browser/device type, and actions taken in the Service, used to operate, secure, and improve it.
2. How we use information
We use information to: provide, maintain, and secure the Service; authenticate users and enforce permissions and tenant isolation; deliver the features a Firm enables (matters, documents, calendar, communications, billing, e-signature, reporting, and the optional AI connector described in Section 6); send transactional and service messages; process payments; provide support; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations.
We do not sell personal information, and we do not use connected-account (Google or Microsoft) data for advertising.
3. Connected Google and Microsoft accounts
The communication and calendar features are optional and only operate after a Firm user explicitly connects their own Google or Microsoft 365 account through a standard OAuth consent flow. The connection covers two functions:
- Client email — so the user can read and send client emails from their connected mailbox and have those messages appear on the relevant client’s communication timeline in the Service.
- Calendar sync — so appointments stay in sync between the user’s calendar and the Service, and public booking does not double-book.
The permissions we request are shown to you on the provider’s consent screen before you grant them. From Google we request access to Gmail messages (gmail.modify, which covers reading, sending, and updating read/label state) and to calendar events (calendar.events), plus your basic profile and email address to identify the account. From Microsoft we request the equivalent Microsoft Graph permissions (Mail.ReadWrite, Mail.Send, Calendars.ReadWrite) together with offline_access so the connection can refresh without asking you to sign in again.
A user can disconnect an account at any time from Account → Communications & calendar in the Service, and can also revoke Lexlink’s access directly from their Google or Microsoft account security settings. Disconnecting stops further access and deletes the stored connection.
4. Google API Services — Limited Use
Lexlink’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data Lexlink accesses through Google APIs (Gmail and Google Calendar) is used only to provide and improve the user-facing email and calendar features described in Section 3. In accordance with the Limited Use requirements:
- We do not use Gmail or Google Calendar data for advertising, and we do not sell it.
- We do not transfer this data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
- We do not use Gmail or Google Calendar data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and we do not provide it to any third party for that purpose.
- Gmail and Google Calendar content is not made available to the optional AI connector described in Section 6. The connector cannot retrieve message bodies, subjects, thread listings, attachments, or unread counts from a connected mailbox. It can send a message that you have reviewed and approved, but mailbox content does not flow back out to an AI provider.
- We do not allow humans to read this data, except: with the user’s explicit consent for specific messages; where necessary for security purposes (such as investigating abuse) or to comply with applicable law; or where the data has been aggregated and anonymized.
5. Microsoft 365 data
Data Lexlink accesses through Microsoft Graph (Outlook mail and calendar) is handled on the same basis as Section 4: it is used only to provide the email and calendar features the user enabled, is not used for advertising, is not sold, is not used to develop, improve, or train generalized AI or machine-learning models, and is not transferred to third parties except to provide those features, comply with law, or in a merger/acquisition with notice. As with Google data, Outlook mail content is not made available to the AI connector described in Section 6. Tokens are stored encrypted and access can be revoked by the user at any time.
6. The optional AI connector
Lexlink offers an optional connector that lets a Firm user work with their own Lexlink data from an external AI assistant of their choosing, using the Model Context Protocol. The connector is off until a user turns it on: no data is shared with any AI provider unless and until that user explicitly connects an AI client and authorizes it, and the user chooses which areas of the Service the connection may reach. The Firm’s existing module, role, and permission rules continue to apply on top of that choice, so the connector can never reach data the user could not already open in the Service.
What can be shared. When a user connects an AI client and grants an area, the information in that area — for example matters, clients, documents, tasks, time entries, or invoices — can be sent to that user’s AI provider in order to answer the user’s requests.
What is never shared. The contents of a connected Google or Microsoft mailbox are excluded from the connector entirely, as described in Sections 4 and 5.
Your AI provider is not our subprocessor. The user brings and authenticates their own AI account, so the AI provider is not processing this data on Lexlink’s behalf and Lexlink does not control how it retains that data or whether it is used to improve that provider’s models. Those questions are governed by the agreement between the user (or the Firm) and that provider, and retention and model-training settings differ between consumer and business plans. Firms handling confidential client information should review their AI provider’s terms before enabling the connector. A user can revoke a connection at any time from Account → AI & connectors in the Service.
7. How connected-account data is stored
Access and refresh tokens for connected Google and Microsoft accounts are encrypted at rest. Email and calendar content is processed to populate the relevant client’s timeline and the Firm’s calendar within the Firm’s isolated tenant, accessible only to authorized users of that Firm under the Firm’s permission rules. We retain this data only as long as the account remains connected and the Firm needs it for the Service, subject to Section 9.
8. How we share information
We share information only as needed to run the Service:
- Service providers (subprocessors) — vetted vendors that process data on our behalf under contract, including cloud hosting and database/storage (Amazon Web Services, Supabase), payment processing (Stripe), transactional email delivery (Resend), and text messaging where a Firm enables it (the Firm’s own Twilio account). Our public websites also use an error-monitoring provider (Sentry) to capture diagnostic data about failures.
- At your direction — where you connect a third-party service to your account, we share the information needed to operate that connection. This includes an accounting system you connect (for example QuickBooks Online or Xero), which receives the customer, invoice, payment, and expense records needed to keep your books in sync; a texting number you connect through your own Twilio account; and the optional AI connector described in Section 6. In each case the provider is chosen and authorized by you rather than engaged by Lexlink, and is governed by your agreement with that provider.
- Within a Firm — Firm data is available to that Firm’s authorized users according to the Firm’s roles and permissions, and is isolated from other Firms.
- Legal and safety — where required by law, legal process, or to protect the rights, safety, and security of users, the public, or Lexlink.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with notice as required.
We do not sell personal information.
9. Data retention
We retain information for as long as an account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention period is required by law or a Firm’s compliance configuration (for example, e-signature audit trails). On termination, a Firm may request export of its data within 30 days, after which Lexlink may permanently delete tenant data in accordance with its retention policies.
10. Security
We use industry-standard safeguards including encryption in transit, encryption at rest for sensitive credentials, row-level tenant isolation, role-based access controls, and least-privilege access for service accounts. No method of transmission or storage is completely secure, but we work to protect information and to promptly address vulnerabilities.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. Firm users can update their profile in the Service and disconnect connected accounts at any time. Because Firms control the client data they store, requests about that data are directed to the relevant Firm; Lexlink will assist Firms in responding. To exercise a right or ask a question, contact us at support@lexlink.ai.
12. Cookies
We use strictly necessary cookies and similar technologies to keep you signed in, maintain your session, and operate the Service. We do not use third-party advertising cookies.
13. Children’s privacy
The Service is a professional tool intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
14. International users
The Service is operated from the United States. If you access it from outside the United States, you understand that your information may be processed in the United States, where data-protection laws may differ from those in your country.
15. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice through the platform or by email before the changes take effect. The “Last updated” date above reflects the most recent revision.
16. Contact
Questions about this Privacy Policy or our data practices can be directed to support@lexlink.ai.
BEBCO Lexlink LLC · Privacy Policy · This document supersedes prior versions.