Privacy Policy, Clex Web

The privacy policy for the Clex Web browser extension: what stays in your browser, what leaves it, and what happens to it afterwards.

Effective date: 21 August 2026

This policy covers Clex Web, the browser extension for Chrome and Edge. The other Clex products, and the Clex website, are covered by the general Clex privacy policy. Where the two describe the extension’s behaviour differently, this one is the accurate document.

At a Glance

QuestionAnswer
Does Clex see what I type?No. Your text is processed in the browser. Clex does not store it and it is not sent to Clex; the licence and statistics requests have no field for free text, and each release is reviewed for this.
Does Clex hear what I dictate?No. Speech is turned into text in the browser; the audio is not stored and not sent.
What does leave the browser?A licence check, requests for model files, and a daily set of usage counts. Section 4 lists every field.
Can a usage report be traced to me?No identifier for you, your device or your installation is in a report; it carries a random one-time report number and your organisation’s access token, and its counts are added to your organisation’s totals on arrival. In a very small deployment the organisation’s totals can in practice describe few people, and our anonymity assessment states this openly.
Can I switch the counting off?Yes, on the extension’s settings page, at any time.
Which websites does Clex run on?On the websites your organisation allows. Clex Web switches itself off on a built-in list of 46 websites, and your organisation can restrict it to approved websites through its browser policy.
Where is the data processed?On servers in Germany, behind an EU-only edge network; everything Clex manages is processed within the EU.

1. Who We Are

This Privacy Policy is issued by Clex A/S, a Danish corporation (CVR 37750840) with registered address at Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark. For the Swedish market, Clex Sweden AB (org.nr 559544-8001) is the contracting party.

Clex develops language-technology writing support for the care sector. This policy describes how we handle information when you use Clex Web.

FieldDetails
Legal nameClex A/S
CountryDenmark (EU)
CVR37750840
Websiteclex.ai
Data-protection contactUffe Gorm Pal Hansen - Email us
General contactEmail us

Clex A/S is an independent controller for the data it receives, described in section 4. The organisation that deployed Clex to you (municipality, care provider, or employer) is the controller for the records its staff write in its own systems, and Clex never receives those records. Section 7 sets out the roles activity by activity.

2. Scope

This policy covers Clex Web, distributed through the Chrome Web Store and installed either centrally by your organisation’s IT department or by you with an activation code. It runs in Chrome and Edge.

The extension is designed for professional care workers who document care activities within their organization’s electronic health record (EHR/EOJ) systems.

3. Our Approach to Privacy

Clex Web is built on a local-first, privacy-by-design architecture:

  • The free text you write stays in your browser. Clex does not store it and it is not sent to Clex.
  • Word prediction, sentence suggestions, sentence correction, translation, speech to text, and read-aloud all run in the browser, using language models stored there.
  • What does leave the browser is a licence check, a set of usage measurements, and requests for model files. Section 4 lists every field.
  • No keystrokes are logged, monitored, or transmitted at any point.

Clex Web does not use the web application’s own interfaces or databases. It reads, in the browser, the content of the text field the user is typing in (input fields, text areas and rich-text editors, including fields inside frames on the page) so that it can show suggestions and insert accepted changes: word suggestions use the text before the cursor, and sentence correction and rewrite read the whole field when the user asks for it. All of this is processed in the browser. Clex stores none of this text, and none of it is sent to Clex. The browser permission behind this means the extension can technically read and change pages it is allowed to run on; an organisation can restrict which websites that is through its browser policy (see the deployment guides).

The usage measurements are daily counts of feature use. They are counted per organisation and calendar day, they carry no identifier for a person, device or installation, and you can switch them off on the extension’s settings page. Sections 4.2 and 4.3 describe the whole report and what becomes of it.

About the extension permissions warning. When Clex Web is installed, your browser explains that the extension can read and change data on the websites you visit. That warning is shown for any extension that works inside text fields, and it describes what the browser allows, not what Clex does. Clex Web does not collect, store or transmit the text you type, and it does not track which websites you visit. What keeps typed text in the browser is Clex’s design, verified by code review of each release, and the fixed format of the licence and statistics requests, which have no field for free text. Section 4 lists everything the extension sends, and section 5 lists what it never sends.

Where Clex Web does not run. Clex Web switches itself off on a built-in list of 46 websites: no suggestions appear, nothing is read, and nothing runs. The list covers banks, national identity and login services such as MitID and BankID, and payment services. It also covers Google Docs and Google Keep, where Clex Web is switched off, and the Chrome Web Store, which browsers do not allow extensions to run on; the full list is in the Clex Web technical documentation. To know when to switch off, Clex Web checks the address of the page you are on against that list, inside your browser. The address is not sent anywhere and is not stored. Your organisation can additionally restrict Clex Web to approved websites through its browser policy.

Clex is developed as reading and writing support, and it is rolled out to whole teams and used by people with and without reading or writing difficulties. Clex does not ask for, record or infer a diagnosis, and the usage statistics are never linked to a person, device or installation, so Clex cannot derive anything about an individual from them. If your organisation itself links the use of Clex to a named employee, for example as an agreed workplace accommodation, that is your organisation’s own processing and your organisation assesses its legal basis under Article 6 and, where relevant, Article 9. Counting per organisation, reading only organisation totals and the short life of the report number are safeguards, not a legal basis. Nothing in the extension switches on or off on the basis of a diagnosis; every feature is available to every user.

4. What Data Is Processed

4.1 What Leaves Your Browser

What is sentWhenPurpose and legal basis
Your organisation’s licence key, exchanged for a short-lived access tokenExtension start and token refreshConfirms the extension is licensed. Legitimate interest, Article 6(1)(f), see section 7
Your organisation’s activation code (Bring Your Own Device only)When you activate the extensionSame
Usage measurements, listed in 4.2One report per day of use, uploaded when the browser is onlineService reliability, and knowing which features are used. Legitimate interest, Article 6(1)(f), see section 7
Requests for language and model filesFirst use of a language or feature, and when models are updatedInstalls and updates the models stored in the browser. Legitimate interest, Article 6(1)(f), see section 7

Nothing else is transmitted. There is no request that carries the text you write.

4.2 The Usage Measurements: What Is in a Report

One report describes one calendar day. This is the whole report, and nothing else:

  • the date it describes, as a day only, with no clock times
  • the extension version, shortened to its first two numbers
  • the writing language, if it is Danish, Swedish, English or German. Every other language is reported as “none”
  • three fixed labels, identical in every report from every device: the name of the report format, the product (“Clex Web”) and the platform (“Chrome”, which is what an Edge browser reports too)
  • a random report number, created for that one report, used only so a repeated upload of the same report is not counted twice, and deleted at most 15 days after the report arrives
  • the counters: for each measured thing, the number of times it happened that day

If the writing language or the extension version changes during a day, the day’s counts are split into one report per combination, each still describing only that calendar day.

The counters record how many times a feature was used or failed that day: a suggested word taken, a sentence correction started or accepted, a translation produced, text read aloud, the language or a setting changed, and whether the extension was used at all that day. Response times are reported as counts within fixed ranges, never as individual measurements.

The remaining counters are operational rather than about you. They record how quickly the extension responded, whether model downloads and licence checks succeeded or failed and for what technical reason, whether report uploads went through, and whether the extension was switched on or off. They describe the software’s health, not your use of it.

A report never contains what you typed, which website or record system you were writing in, any time of day, any character count, or an identifier for a person, user, device, installation or session. It is sent with your organisation’s access token, section 4.4, so that Clex can tell which organisation the counts belong to, and no more.

You can switch the measurements off, on the extension’s settings page, with the switch currently labelled “Share anonymous usage statistics”. It is on until you turn it off. Turning it off stops the counting at source and deletes every report not yet sent. To object to this processing in other ways, see section 8.

4.3 What Happens to a Report After It Arrives

A report is checked, then added. Our service accepts only the field names listed in 4.2 and only counter names from a fixed list. Anything else is refused. The accepted numbers are validated and added to your organisation’s running daily totals on arrival, and the individual report is not kept.

What is stored is a total, not an event. One stored row is: the date, the organisation, the product, the platform, the version bucket, the language, the counter name, and the number. There is no row for a device, an installation, a session, or a person, because no such value reaches the service.

The counts are not held against a person or a device. A usage report contains no identifier for a person, user, device, installation or session. It contains a random report number created for that one report and used only to discard duplicates, and it is sent with your organisation’s access token so that Clex can tell which organisation the counts belong to. The report number cannot link reports from different days or devices; it is deleted at most 15 days after the report arrives. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged.

We do not store where the report came from. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The usage-statistics endpoint has edge logging switched off. Section 10 describes network logging in full.

The statistics are aggregated, and only totals can be read back. Usage statistics are aggregated: they are counted per organisation and calendar day and carry no identifier for a person, device or installation. Clex reads them only as organisation totals, only internally and only with an internal credential; the language and app-version breakdowns are never returned by the read interface. An organisation can ask for its own totals; Clex then delivers organisation totals only. Clex does not use usage statistics to monitor, evaluate or discipline individual employees, to train models, or to market to individuals, and does not combine them with support cases, access logs or any other data. Clex keeps organisation totals for 24 months. The in-app statistics switch is available to every user on Android, iOS and in Clex Web.

Totals are deleted on a fixed schedule. Organisation daily totals are deleted 24 months after the day they describe, and sooner if your organisation asks or its contract ends. Server backups of licence and statistics data are encrypted, held in the EU and under Clex’s control; a deleted record leaves the most recent backups within 48 hours and every backup within 72 days.

4.4 The Access Token

The token identifies the licensed organisation, its expiry, and a wording label set by Clex (the word the extension uses for the person being documented about); it is never a name and your organisation cannot change it. The label is used only in your browser, to adapt suggestions. The token carries no name or contact detail for you. It is held in the browser’s session storage for the extension and cleared when the browser closes, and it is renewed automatically by the licence service. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged. The credential the extension uses to upload cannot read anything back.

4.5 Model and Language Downloads

Requests for model files carry no account, no licence key and no device identifier. As with any network connection, the request carries your browser’s IP address for as long as the connection lasts; the edge network that delivers the file writes its access logs with the last part of the address removed. Section 10 describes network logging in full.

Downloads happen on first use of a language or feature and when models are updated. Downloaded files are verified against the size and, where the manifest publishes one, the checksum in Clex’s file manifest; dictionaries and the sentence-correction models are always checksum-verified. Every file path read from a manifest is checked against Clex’s own domain before it is fetched, so a tampered manifest cannot redirect a download elsewhere. The models are stored in the browser so the writing features keep working without a connection.

4.6 Local Features (No User Text Transmitted)

These features run in your browser. No user text is sent to Clex or to any third party for them:

  • Word prediction.
  • Sentence suggestions and sentence correction, produced by language models stored in the browser.
  • Translation. Language files are downloaded once on first use and then kept in the browser.
  • Read-aloud and text-to-speech, using voices that run offline in the browser.
  • Speech to text, described in section 6.

No user text is included in any download or network request related to these features. The models are static: they never learn from what is typed, dictated or read, and they are updated only as versioned files from Clex. Machine-generated text can contain errors. A suggestion enters the text only when the care worker accepts it, and checking it professionally before the note is saved remains the care worker’s responsibility; the record is the care worker’s, not the model’s.

4.7 What the Extension Keeps in Your Browser

  • Licence status and settings, held in the extension’s own storage in your browser: your licence status, your activation key if you activated the extension yourself, and your language and feature settings. They stay local to that browser profile and are never synchronised to another browser.
  • The access token, held in the browser’s session storage for the extension and cleared when the browser closes, section 4.4.
  • Model and language files, the versioned files described in 4.5, held in the browser’s own database for the extension. They hold no text of yours.
  • Your personal dictionary. The personal dictionary holds the words you add yourself; it can contain names. It stays in your browser, is never synchronised or sent to Clex, and you can delete it in the extension settings.
  • Clex Academy progress, kept as lesson identifiers only in the extension’s own storage in your browser. Nothing of it is sent to Clex.

Removing the extension from your browser removes everything in this list.

5. What We Do Not Collect

We do not collect or store:

  • The text you type or dictate into EHR/EOJ systems or any other website
  • The address or name of the websites you write on
  • Your browsing history
  • The length of what you write. No character counts leave the browser
  • The time of day you type. A usage report names only the calendar day it describes
  • Keystrokes, keystroke timing, or input patterns
  • Personal data such as names, addresses, phone numbers, or health records of any individual
  • The audio you speak into your browser
  • Photographs or other user-generated media
  • Information from the EHR/EOJ systems where text is entered
  • Any identifier for a person, user, device, installation or session

The extension contains no third-party analytics, crash-reporting, advertising or attribution components. Usage measurements go only to Clex’s own servers.

6. Speech to Text and the Microphone

Speech to text writes down what you say. It is optional. The first time you use it, the extension opens a Clex page in a new tab where your browser asks for the microphone permission, and the extension works fully if you decline. You can also switch dictation off in the extension’s settings at any time.

  • The microphone is active only while a recording is running. A recording starts when you click the microphone button next to the text field and stops when you click it again. It also stops on its own after a pause in speech, and after 30 seconds at most.
  • Audio is transcribed by a model stored in your browser, inside the extension. It is held in memory while it is transcribed. It is not written to a file, not kept after the transcription, and not uploaded. It is not sent to the browser’s own speech service or to any cloud service either.
  • The transcription is inserted into the text field you started dictating in, the same way as if you had typed it.
  • Like the rest of the extension, speech to text is switched off on the built-in list of websites described in section 3.
  • Speech to text is available for Danish and Swedish.

7. Roles and Legal Basis (GDPR Article 6)

Who is responsible for what. Roles are assigned per processing activity.

  • The notes, messages and other text that care workers write, dictate or have read aloud are processed on the organisation’s own devices and browsers and are never received by Clex. For that processing the organisation is the controller, exactly as for any other text its staff write, and Clex is the supplier of the software, neither a controller nor a processor.
  • For licence validation and activation, the connection data that those requests carry, and the daily usage statistics, Clex A/S decides the purpose and the means and is therefore an independent controller. Hetzner Online GmbH and BunnyWay d.o.o. process that data for Clex A/S as processors. On the Swedish market Clex Sweden AB is the contracting party; Clex A/S remains the controller.
  • Where Clex processes personal data on an organisation’s documented instructions, for example if the organisation grants Clex diagnostic access during a support case, Clex acts as a processor for that activity, and a data processing agreement under Article 28 is in place before that processing begins. Clex provides a per-activity overview on request; when an organisation’s data protection officer requests a data processing agreement for any other activity, Clex concludes one.
ProcessingDataLegal basis
Licence validation and activationOrganisation licence key or activation code, app version, access tokenArticle 6(1)(f), legitimate interest: operating and securing the licensed service for the organisation. The licence key and the organisation identifier in the token describe the organisation, not a person.
Model, dictionary, voice and language downloadsFile request, IP address during the connectionArticle 6(1)(f), legitimate interest: delivering the product’s language resources.
Daily usage statisticsSee section 4 (counts per organisation and day, report number, access token)Article 6(1)(f), legitimate interest: keeping the service reliable and knowing which features are used. You can object at any time by switching statistics off in the app or extension settings.

Clex’s legitimate-interest assessment for these activities is available from Clex. The care workers who use Clex are normally not party to the agreement between their organisation and Clex, which is why Clex does not rely on Article 6(1)(b) for them. The organisation’s own legal basis for the documentation work Clex assists with is the one it already has for that work; Clex adds no new purpose.

Activation codes for Bring Your Own Device installations expire automatically after a limited period.

We carry out no automated decision-making or profiling within the meaning of Article 22. The extension proposes draft sentences and corrections, and the care worker decides whether to use each one. No automated decisions are made about individuals and no profiles are built.

8. Your Rights Under the GDPR

Where the conditions in the GDPR are met you have the right to access, rectify, erase and restrict the processing of personal data about you, and to object to processing based on Article 6(1)(f); the simplest way to object to the usage statistics is to switch them off in the settings. The right to data portability applies only to processing based on consent or contract; of Clex’s own processing, only the website contact form rests on contract, and you can ask us for a copy of what you sent through it. Because usage statistics are counted per organisation and carry no identifier for a person, Clex cannot look up data about an individual in them (Article 11); your organisation can ask Clex to delete all totals belonging to it. Contact: Email us. You can also complain to Datatilsynet (or, in Sweden, Integritetsskyddsmyndigheten).

We answer within one month, as Article 12 requires. That the usage totals cannot be searched for an individual is a consequence of the design in section 4.3, not a refusal. The direct and immediate way to stop the measurements is the switch in section 4.2, which acts at once and needs no request to us.

You can switch usage statistics off at any time in the app’s settings on Android and iOS and on the extension’s settings page in Clex Web; pending reports are deleted when you do.

You can also do these things yourself, at any time, without asking us:

  • Switch off the usage measurements, on the extension’s settings page, section 4.2, which also deletes any reports not yet sent.
  • Delete everything held locally, by removing the extension from your browser.
  • Disable the extension, in your browser’s extensions page, which stops the extension from processing anything further. A report already prepared is kept and sent when you switch the extension on again, or deleted after 14 days.
  • Switch off dictation, in the extension’s settings, section 6.
  • Decline the microphone permission, or withdraw it in your browser’s site settings. Speech to text is optional and the extension works without it.
  • Delete your personal dictionary, in the extension’s settings, section 4.7.

Your organisation can ask us to erase every usage total belonging to it, and we do that on request.

You may lodge a complaint with your supervisory authority:

CountryAuthority
DenmarkDatatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk
SwedenIntegritetsskyddsmyndigheten, imy.se
GermanyThe competent federal or state data-protection authority

9. Data Sharing and Processors

We do not sell, rent, or trade personal data. These providers are involved in delivering the service:

ProcessorRoleLocationTransfer safeguard
Hetzner Online GmbHServer hostingGermany (EU)Not required (EU)
BunnyWay d.o.o. (Bunny.net)Edge network, DDoS protection, authoritative DNSSlovenia (EU); EU-only edge routingNot required (EU)

The extension is distributed through the Chrome Web Store and also runs in Microsoft Edge. Google and Microsoft process account, device and download data for their own store and browser services under their own terms; that processing is not part of Clex’s service and Clex receives none of it.

Read-aloud uses a speech model stored in your browser; text is spoken in the browser and not sent to any service.

Apart from the processors and the distributors named above, no other service receives data from the extension in normal operation. The components that run in the browser process data locally; the only uploads are the licence check and the usage counters described in section 4.

10. Infrastructure and Data Residency

Clex’s services run on servers operated by Hetzner Online GmbH in Germany. In front of them sits an edge network operated by BunnyWay d.o.o. (Slovenia) that delivers model and language files, protects the services against attack and answers DNS queries; it is configured to route traffic within the EU only. Both companies process data for Clex as processors under written agreements. Everything Clex manages is processed within the EU.

IP addresses and network logs. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The edge network that delivers model files and fronts Clex’s services writes its access logs with the last part of the address removed (the last octet of an IPv4 address, the host part of an IPv6 address); those logs are kept for 72 hours on a rolling basis by the edge provider and are not forwarded or archived. The usage-statistics endpoint has edge logging switched off. Clex’s own servers keep no per-request access log.

Key points:

  • No data Clex manages is transferred outside the EU for processing; Google and Microsoft process their own store and browser data under their own terms.
  • Licence validation and usage measurements are received by Clex’s servers in Germany, and model files are delivered from European edge locations only.
  • The architecture is designed to keep external service dependencies few and to keep server-side operations inside the EU.

Section 9 names the processors involved.

11. Data Security

Traffic between the extension and Clex-managed servers is encrypted in transit. The access token travels only as a credential for that connection and is not stored or logged on our side. Data held locally stays in the extension’s own storage in your browser, which the websites you visit cannot read; the access token is held in the browser’s session storage and cleared when the browser closes. Server infrastructure is protected using industry-standard security controls.

We apply commercially reasonable security measures. No method of electronic transmission or storage is completely secure, so we design the systems to keep the amount of exposed data small in the first place.

12. Data Retention

DataWhereRetained
Text typed, dictated audio, suggestions, corrections, translationsBrowser memory onlyDiscarded when the field or session ends; never stored by Clex
Unsent daily usage reportBrowserUntil uploaded, at most 14 days; deleted immediately if you switch the measurements off
Received daily usage reportClex usage-statistics serviceValidated and added to the organisation’s totals on arrival; the individual report is not kept
Report number (duplicate check)Clex usage-statistics serviceAt most 15 days
Organisation daily totalsClex usage-statistics service24 months after the day they describe, or earlier on the organisation’s request or at contract end
Licence validation recordsClex licence serviceFor the duration of the customer contract
Access tokenBrowser session storage for the extensionCleared when the browser closes
Personal dictionary, language and feature settingsBrowser, the extension’s own storageUntil you delete them or remove the extension
Clex Academy progress (lesson identifiers only)Browser, the extension’s own storageUntil you delete it or remove the extension
Edge access logsEdge provider (EU)72 hours, rolling, anonymised IP, not forwarded
Server backups of licence and statistics dataClex-controlled encrypted backups in the EUA deleted record leaves the most recent backups within 48 hours and every backup within 72 days

Removing the extension from your browser removes everything it has stored there. Free text from extension usage is never held on Clex servers, because it is never sent there.

13. Children’s Privacy

Clex Web is made for professional care workers in an organisational context, including students in care-sector vocational programmes. It is not directed at children, and we do not knowingly collect information from anyone under the age of 16.

14. Changes to This Policy

We update this policy as the extension changes. When we do, we change the effective date at the top and post the revised version on our website. Material changes are described rather than made silently. Superseded versions remain available: the version effective 20 August 2026 is archived here, the version effective 18 August 2026 here, and the version effective 11 August 2026 here.

15. Contact

PurposeContact
Data protection and general enquiriesUffe Gorm Pal Hansen - Email us
Danish customersFlakron Sojeva - Email us
Swedish customersRon Karlsson - Email us
SupportEmail us
AddressClex A/S, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark