Privacy policy
How clex.ai handles visitor data. Minimal collection, EU hosting, no cross-site tracking.
This privacy policy covers this website (clex.ai). How Clex products handle personal data - the keyboards and the browser extension - is documented in the Clex Privacy Policy and the platform policies for Android, iOS and Clex Web; the security and GDPR documents are listed on the compliance page.
Controller
Clex A/S, CVR 37750840, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark, is the controller for this website. For the Swedish market, Clex Sweden AB (org.nr 559544-8001) is the contracting party; Clex A/S remains the controller.
What this website collects
- Edge access logs - the EU edge network in front of the website keeps access logs for 72 hours, with the last part of the IP address removed at the edge; Clex’s own servers keep no per-request access log.
- Contact-form submissions (name, email, message) - used only to respond to your enquiry. Lawful basis: GDPR Article 6(1)(b) and (f) - pre-contractual steps and our legitimate interest in replying. Delivered by email to the relevant market contact. The submission travels as an e-mail to Clex’s mailbox at its e-mail service provider, which processes it for Clex as a processor under a data processing agreement and stores it within the EU. Submissions are kept while the enquiry is open and for 12 months after our last reply, so that a follow-up can be answered; if the enquiry leads to a customer contract, the correspondence becomes part of that customer file. After that they are deleted. The bot check (proof-of-work) runs on your device and sets no cookies.
No client-side analytics. No cross-site trackers. No advertising cookies. No third-party embeds.
Third parties
- Hetzner Online GmbH (Falkenstein, Germany) - hosting.
- BunnyWay d.o.o. (Bunny.net) (Slovenia, EU) - CDN, edge caching and DNS, configured to route traffic within the EU only.
- E-mail service provider - carries and stores contact-form submissions for Clex as a processor under a data processing agreement, within the EU.
TLS certificates come from a public certificate authority, which receives only the domain name.
No US CDN, no US analytics, no US tag manager.
Your rights under the GDPR
Access, rectification, erasure, objection, data portability, and complaint to the supervisory authority. Requests: Email us. Response within one month, as required by GDPR Article 12.
Supervisory authority: Datatilsynet (Denmark), Integritetsskyddsmyndigheten (Sweden), or, in Germany, the competent federal or state data-protection authority.
Last updated
2026-09-02. The policy is reviewed at least annually and whenever a processor changes.
