Compliance
Security, GDPR, and data-protection documentation for Clex procurement and supplier review. Request the customer document pack.
Clex maintains a complete customer-facing security and data-protection document set. Each document is drawn from verified source material, version-controlled, approved by the CEO before release, and kept current with the product.
At a glance
| Legal entity (DK) | Clex A/S, CVR 37750840 |
| Legal entity (SE) | Clex Sweden AB, org.nr 559544-8001 |
| Headquarters | Copenhagen, Denmark |
| Production hosting | Hetzner, Falkenstein, Germany (EU) |
| Processors | Two: Hetzner Online GmbH (Germany) and BunnyWay d.o.o. (Slovenia). Both EU, both under written agreements. |
| Data processed server-side | Licence checks, daily aggregated usage counts, and requests for model and language files, plus the connection data any internet request carries (the device’s IP address for the duration of the connection; edge access logs are kept 72 hours with the last part of the address removed). No free text. No keystroke logging. No identifier for any person in the usage statistics. |
| Data processed on the device | User-entered free text. All writing features run here; nothing the worker types leaves the device or the browser. |
| SLA availability | See Service Level Agreement document |
| Approver (all documents) | Jonas Henrik Lund, CEO |
Security posture
Clex is designed around local processing. User-entered free text remains on the device or in the browser, and the writing features run there: word prediction, sentence correction and rewrite, speech to text, read-aloud, and translation all use language models stored locally. What Clex receives is a licence check and a daily count of feature use. It carries no identifier for any person, no free text, and no keystrokes. Production hosting is on EU infrastructure in Germany. The FAQ on this site covers the most common questions; the customer document pack below goes into greater depth on each topic.
What is in the customer document pack
Each document answers the questions a procurement team or DPO will ask. Request the pack to receive the current versions as PDFs.
Company and Service Overview
The legal entity, ownership structure, registered addresses, product portfolio, operating footprint, and the contracting structure for each market. Useful for vendor onboarding forms that ask about corporate structure.
Security Management Overview
Governance, risk management, access principles, and how security decisions are made. Covers the organisational side of security: who owns what, how we handle privileged access, and how we maintain security awareness.
Secure Development and Product Security
Software development lifecycle, separation of development and production environments, code review, testing, vulnerability management and the security-testing programme, including how external testing is scheduled. For product-security teams assessing whether Clex Keyboard or Clex Web meets OWASP-class security requirements.
Infrastructure, Operations and Physical Security
Hosting, network security, hardening, logging, monitoring, backup, and patch management. Describes where Clex runs, how it is secured, and how operational changes are managed.
Business Continuity, Incident Response and Disaster Recovery
Continuity planning, incident-management process, recovery objectives, and backup and restore testing. For procurement questions about what happens when something goes wrong - and how we know our recovery plan works.
Data Protection and Sub-processors
Complete processor list, server locations, third-country transfer mechanisms, and the GDPR posture for each data flow. Answers the questions procurement teams and DPOs most often ask: where does data go, and on what legal basis.
Service Level Agreement
Availability commitments, response times for issue categories, and the service commitments Clex makes in a customer contract. Use the SLA document as a starting point for contract negotiation.
GDPR Questions and Answers
Twenty-one plain-language questions and answers covering Clex’s full GDPR scope - from what happens to text on the device, through processor geography, to how data is deleted when a device is retired. Often the document DPOs use to approve a Clex deployment.
Processing Activities, Roles and Legal Bases
The per-activity role and legal-basis matrix for every way Clex processes data, the Article 9 position, data-subject rights by activity, and the legitimate-interest assessment. Answers the question a DPO asks first: who is controller, who is processor, and on what basis.
Usage Statistics Specification and Anonymity Assessment
The daily usage report’s full schema, its lifecycle on device and server, who can read the totals, and the assessment against the EDPB’s anonymisation criteria, including the honest residual for a very small deployment. For the DPO evaluating whether the statistics are truly anonymous.
Technical and Organisational Measures
The per-endpoint network and log matrix, transport security, device and server measures, supply-chain and vulnerability handling, incident response, and a plain statement of what the annex does not claim. The Article 32 evidence a security review asks for.
DPIA Input Pack
The vendor input for your own data protection impact assessment, arranged in the order a DPIA is written and mapped to the Danish supervisory authority’s minimum content, per product.
Models and Quality Documentation
Model cards for each on-device model family, the training-data position, known limitations, the review-step map, and the evaluation programme. For a DPO or product-security reviewer assessing what Clex’s models do and where they come from.
Technical Documentation
One document per product - Clex Keyboard on Android, Clex Keyboard on iOS and Clex Web - covering architecture, features, permissions, network endpoints, data flows, retention and deployment. The systematic description a DPIA author and an IT department need.
AI Act Classification and Transparency Memorandum
Clex A/S’s classification of its products under the AI Act: intended purpose, out-of-scope uses, the Annex III analysis (not a high-risk AI system for its intended purpose), the human-oversight model, AI-literacy support for deployers and the Article 50 transparency analysis for correction, rewrite and translation.
Rollout guides
Step-by-step deployment guides per product and platform: MDM, Intune and Knox for Android, MDM for iOS, and group policy for Chrome and Edge. See the rollout page.
Request the pack
To keep sensitive security and SLA documentation away from automated scrapers, we send the pack by email on request rather than publishing it openly. Your request reaches a named person, not a ticket queue:
- Danish customers: Flakron Sojeva
- Swedish customers: Ron Karlsson
- Technical follow-up: Uffe Gorm Pal Hansen
- German customers: Jonas Henrik Lund
We usually respond within one working day. Procurement officers and DPOs receive the full current pack; we can arrange specific subsets on request (for example, DPIA inputs only).
Quick answers
If you don’t need the full pack, the FAQ covers the sixteen most common procurement, DPO, and IT-department questions with plain short answers.
