Clex Privacy Policy (archived 2026-08-04 version)

The privacy policy for Clex products: Clex Keyboard for Android and iOS, Clex Web, and the Clex website.

Archived version. This is the privacy policy that applied from 4 August 2026 until 11 August 2026. It is kept for reference and is no longer in force. The current policy is at clex.ai/en/legal/privacy-policy/.

Effective date: 4 August 2026

This policy covers the Clex products and services listed in section 2, including this website. Details specific to website visits (access logs, the contact form) are also described in the website privacy policy.

1. Who We Are

This Privacy Policy is issued by Clex A/S, a Danish corporation (CVR 37750840) with registered address at Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark.

Clex develops language-technology writing support for the care sector. This policy describes how we handle information when you use our products and services.

FieldDetails
Legal nameClex A/S
CountryDenmark (EU)
CVR37750840
Websiteclex.ai
ContactContact Clex support

2. Scope

This policy covers all Clex products and the Clex website:

ProductPlatformDistribution
Clex KeyboardAndroidGoogle Play
Clex KeyboardiOSApp Store
Clex WebChrome / EdgeChrome Web Store
Clex WebsiteBrowserclex.ai

The products are designed for professional care workers who document care activities within their organization’s electronic health record (EHR/EOJ) systems.

Clex Keyboard for Android has its own, more detailed privacy policy, which describes the Android app field by field: Privacy Policy, Clex Keyboard for Android. Where this policy and that one describe Android behaviour differently, the Android policy is the accurate one.

3. Our Approach to Privacy

Clex products are built on a local-first, privacy-by-design architecture:

  • Free text you type stays on your device or in your browser and is never sent to Clex servers for sentence suggestions.
  • Core features such as word prediction, translation, and read-aloud run locally on the device or in the browser.
  • When sentence suggestions are requested, only pictogram identifiers and language codes are transmitted.
  • No keystrokes are logged, monitored, or transmitted at any point.

About the keyboard access warning. When you enable Clex Keyboard on Android or iOS, your operating system displays a standard warning that the keyboard may be able to collect everything you type, including passwords and credit card numbers. This warning is shown for all third-party keyboards and is not specific to Clex. We want to be clear: Clex Keyboard does not collect, store, or transmit any text you type. All text processing happens locally on your device. No keystrokes, passwords, or typed content ever leave your device through Clex.

4. What Data Is Processed

4.1 Sentence Suggestions

When you select pictograms to generate a documentation sentence, the following structured data is sent to the Clex API:

  • Pictogram identifiers
  • The selected output language

No free text, no keystrokes, and no personal data about residents or care workers is included in the request. The API returns a generated sentence that is inserted into your active text field.

4.2 Licensing and Activation

A license token is sent to the Clex licensing service when the product is activated or periodically validated. The token is used only for authorization and does not contain personal data about end users.

4.3 Operational Monitoring

To maintain service reliability, we collect aggregated operational metrics:

  • Daily counts of errors, timeouts, and sessions
  • App version and general device category

This data is aggregated and does not include individual events, stack traces, free text, or device identifiers that could be used to identify a person.

4.4 Local Features (No User Text Transmitted)

The following features run locally on your device or in your browser. No user text is sent to Clex or any third party for these features:

  • Word prediction – runs locally on all platforms.
  • Translation – runs locally on all platforms. Language resources are downloaded once on first use and cached on the device.
  • Read-aloud – runs locally on all platforms using offline speech engines.

No user text is included in any download or network request related to these features.

4.5 Clex Website (clex.ai)

The Clex website is designed with the same privacy-first approach as our products:

  • No cookies. The website does not set, read, or require any cookies. No cookie consent banner is needed because no cookies are used.
  • No tracking or analytics. The website does not use Google Analytics, Facebook Pixel, or any other tracking or analytics service. No visitor behavior is recorded or profiled.
  • No external scripts. All JavaScript is self-hosted. No third-party scripts are loaded in your browser.
  • No external fonts. All fonts are self-hosted. No requests are made to Google Fonts or other external font services.
  • No local storage. The website does not use browser localStorage or sessionStorage.

Contact form. The website includes a voluntary contact form. When you submit the form, the information you provide (name, email, company, and message) is delivered by email to the relevant Clex market contact and used only to respond to your inquiry. This data is not used for marketing, profiling, or any other purpose. The bot check (proof-of-work) runs in your browser and sets no cookies. Contact form data is subject to the legal basis described in section 6.

5. What We Do Not Collect

We do not collect or store:

  • Text you type into EHR/EOJ systems or any other application
  • Keystrokes, keystroke timing, or input patterns
  • Personal data such as names, addresses, phone numbers, or health records of any individual
  • Voice recordings, photographs, or other user-generated media
  • Information from the EHR/EOJ systems where text is entered
  • Device contacts, call logs, or browsing history
  • Individual-level usage events or crash stack traces

6. Legal Basis (GDPR Article 6)

Clex A/S is the data controller for the limited data described in section 4 (aggregated operational metrics, license validation, sentence suggestion requests, and contact form submissions). The deploying organization (municipality, care provider, or employer) remains the data controller for any personal data that care workers enter into EHR/EOJ systems. Since free text stays on the device or in the browser and sentence suggestions use pictogram identifiers and language codes, a data processing agreement (DPA) between the organization and Clex is generally not required. If the organization determines that supplementary documentation is needed, Clex can support that assessment.

Because Clex products are designed to avoid processing personal data on the server side, the scope of data processing that requires a legal basis is limited:

Processing activityLegal basisReference
Sentence suggestion requests (pictogram data)Performance of a contractArt. 6(1)(b) GDPR
License validationPerformance of a contractArt. 6(1)(b) GDPR
Aggregated operational monitoringLegitimate interest (service reliability)Art. 6(1)(f) GDPR
Contact form submissions (name, email, message)Pre-contractual steps and legitimate interest (responding to your inquiry)Art. 6(1)(b), (f) GDPR

You may object to the processing of your contact-form data and ask us to delete it at any time by contacting us.

Clex does not carry out any automated decision-making or profiling as defined in Article 22 of the GDPR. Our products generate draft sentence suggestions from pictogram selections and language codes, but the care worker reads and decides whether to use each suggestion. No automated decisions are made about individuals, and no personal profiles are created.

7. Data Sharing and Sub-processors

We do not sell, rent, or trade personal data. The following providers are involved in delivering the service:

ProviderRoleLocationTransfer safeguard
Hetzner Online GmbHServer hostingGermany (EU)Not required (EU)
BunnyWay d.o.o. (Bunny.net)CDN, DDoS protection, authoritative DNSSlovenia (EU); EU-only edge routingNot required (EU)
Key-Systems GmbHDomain registrar (clex.ai)Germany (EU)Not required (EU); no traffic, no personal data

No other third-party services receive data from Clex products or the Clex website in normal operation. On-device components process data locally and do not transmit data to any external party.

8. Infrastructure and Data Residency

All Clex-managed server-side processing takes place on dedicated servers hosted by Hetzner Online GmbH in Germany.

Key points:

  • All production data processing occurs within the EU.
  • No data is transferred to servers outside the EU for processing.
  • Edge traffic is routed only through European edge locations, and visitor IP addresses are anonymised at the edge before any access logs are written.
  • The architecture is designed to minimize external service dependencies and to maintain EU-only data residency for all server-side operations.

9. Data Security

All communications between Clex products and Clex-managed servers are encrypted in transit. Server infrastructure is protected using industry-standard security controls.

While we apply commercially reasonable security measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we design our systems to minimize the data that is exposed in the first place.

10. Data Retention

  • Aggregated operational metrics are retained only for the period needed to support service monitoring and issue resolution, after which they are deleted.
  • License validation records are retained for the duration of the customer contract.
  • Contact form submissions are retained for as long as needed to respond to and follow up on the inquiry, after which they are deleted.
  • Product usage is retained only as aggregate operational totals that carry no identifier for any person. For Clex Keyboard on Android, these totals are deleted automatically 24 months after the day they describe, and sooner if the organisation asks or its contract ends. No free text from product usage is ever retained, because none is sent.

11. Your Rights Under the GDPR

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access personal data we hold about you
  • Rectify inaccurate personal data
  • Erase personal data (“right to be forgotten”)
  • Restrict processing of your personal data
  • Port your personal data to another controller
  • Object to processing based on legitimate interest

What we hold on the server side is aggregate usage totals that carry no identifier for any person, so there is no record we can search for you and no share of it we can separate out as yours. That is a consequence of how the systems are built, not a refusal. If you have questions about any data we handle, please contact us.

You also have the right to lodge a complaint with the Danish Data Protection Agency:

AuthorityDatatilsynet
AddressCarl Jacobsens Vej 35, 2500 Valby, Denmark
Websitedatatilsynet.dk

12. Children’s Privacy

Clex products are designed for use by professional care workers in an organizational context. They are not intended for use by children. We do not knowingly collect information from children under the age of 16.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this document and post the revised version on our website. We encourage you to review this policy periodically.

14. Contact

If you have any questions about this Privacy Policy or how we handle data, please contact us:

EmailContact Clex support
Websiteclex.ai
AddressClex A/S, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark