Assistive technology at universities and GDPR: TorTalk, ClaroRead, Stava Rex, SpellRight and similar tools
Text-to-speech and spelling support tools are among the most widely licensed software at European universities. They look harmless, and usually are, but the way they are offered can reveal that a student has a disability, and some features send the text a student is reading or writing to a vendor's servers. This guide explains when assistive technology touches health data under the GDPR, why local and cloud processing differ, what four common vendors document, and how student support services can keep the risk low.
The short answer
- The tool is rarely the problem; the context is. A spell checker under a campus licence that every student can use reveals nothing about health. The same tool handed out only to students with a documented disability can turn a licence list into data concerning health under Article 9 GDPR.
- Local and cloud features differ. Vendor documentation shows that on-device voices can work without sending anything, while online voices, OCR, word prediction and browser extensions may send the student's text to a server.
- Vendors document very different amounts. ClaroRead publishes a detailed list of servers and providers. For TorTalk, Stava Rex and SpellRight we found much less public detail on how text is processed (checked 7 October 2026), so ask.
- What to do: prefer campus licences open to all students, prefer local processing and network versions, keep the disability support register separate from software provisioning, and screen each tool for a DPIA.
When assistive technology becomes health data
The GDPR defines data concerning health as personal data related to the physical or mental health of a person which reveal information about their health status (Article 4(15)) [1]. Recital 35 adds that this covers data revealing past, current or future physical or mental health status [1]. Processing health data is prohibited under Article 9(1) unless one of the exceptions in Article 9(2) applies, such as explicit consent (point (a)) or substantial public interest on the basis of Union or Member State law (point (g)) [1].
A diagnosis of dyslexia, ADHD or a visual impairment is plainly health data. The harder question is whether the fact that a student uses a reading or spelling tool is. The Court of Justice gave the test in OT v Vyriausioji tarnybinės etikos komisija (C-184/20, 1 August 2022). It asked whether data capable of revealing a sensitive characteristic "by means of an intellectual operation involving comparison or deduction" falls under Article 9(1), and held that data liable to disclose sensitive information indirectly is special category data [2]. The case concerned sexual orientation, but the reasoning applies to every category in Article 9(1), including health.
Validemic's analysis Applied to assistive technology, the deduction test gives three practical cases:
| How the tool is offered | Does a licence or usage record reveal health? | Likely GDPR position |
|---|---|---|
| Campus licence, any student or staff member can download it | No. Many users have no disability. | Ordinary personal data |
| Tool offered to all, but a support service keeps a list of students it recommended it to | The recommendation list does, the general licence does not. | Article 9 for the list only |
| Licence issued only after a disability is documented | Yes. Being a licence holder implies a documented disability. | Article 9 for licence records and possibly usage logs |
Several Swedish universities illustrate the first model. Karlstad University says all students can download StavaRex and SpellRight to their private computer [10], and SLU says all staff and students can use TorTalk on campus and on private computers for study and research [15]. Under that model, a vendor's user list is not a list of disabled students.
The content a student processes can also be sensitive in its own right, such as a scanned letter from a doctor. That is why where the processing happens matters as much as the licence.
Local versus cloud processing
Assistive tools combine features with very different data flows. The most useful split is between features that run on the student's device and features that call a server.
| Feature | Typical local option | Cloud variant and what may leave the device |
|---|---|---|
| Text-to-speech | Voices installed on the device | Online voices: the text to be spoken is sent to a speech provider |
| Spelling and grammar | Desktop program or office add-in with local dictionaries | Browser extensions and online editors: snippets of text sent for checking |
| Word prediction | Local language model in the program | Online prediction: text sent as the student types |
| OCR and document conversion | Desktop OCR engine | Online conversion: whole documents or images uploaded |
| Usage analytics, licensing and updates | Network or site versions with these switched off | Analytics services, licence servers and update checks |
ClaroRead's documentation shows both sides in one product. It says that "if ClaroRead uses on-board local speech, then there is no data transferred anywhere", while the Chrome version uses online servers for OCR and document conversion, sending entire documents and images, and an online server for prediction and spellcheck, sending snippets of text [4]. The same vendor says site licences receive network versions with no Google Analytics, licensing calls or automatic updates [4].
Validemic's analysis For a university, local processing changes the role of the vendor. If text never leaves the device, the vendor is not processing the student's content at all, and the main GDPR questions become licensing data and analytics. Once text goes to a server, the vendor is processing student content on the university's behalf and needs a data processing agreement under Article 28, a subprocessor list and a transfer assessment for any provider outside the EEA. A student support service that installs the browser extension because it is easier, rather than the desktop version, can move a tool from one category to the other without anyone noticing.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Tool notes: ClaroRead, Stava Rex and SpellRight, TorTalk
The notes below summarise what each vendor publishes. They are not verdicts on the products. Where we found nothing, we say so; that does not mean the vendor lacks the document.
ClaroRead (Claro Software, now part of Everway)
- Vendor: Claro Software's website redirects, via texthelp.com, to Everway's UK pages on the Disabled Students' Allowance, which present ClaroRead as a product for students funded through the UK Disabled Students' Allowance, available on Windows, macOS, Chrome and Edge [5]. Everway is the name Texthelp adopted after joining with n2y [7].
- Online voices: Google voices "call Google servers, potentially located in the USA or EU"; Amazon Polly voices call servers in Stockholm; Nuance voices are hosted in the EU and the vendor says user data "is not cached or stored"; with Cereproc voices the text is not stored but the generated audio is kept for 48 hours [4].
- Chrome version: OCR, document conversion, prediction and spellcheck use online servers; the vendor describes this as anonymous and not stored [4].
- Analytics and licensing: applications use Google Analytics and call Claro's licensing system, which may hold at most an email address; the documentation lists GA4 as processing IP addresses and features used, with data in the USA [4]. Network versions for site licences omit analytics, licensing and automatic updates [4].
- Local storage: the vendor says local data consists of user settings and, at most, an email address for log-in, not other personal data [4].
For a university: deploy the network version where possible, decide centrally which voices are allowed (a local or EU-hosted voice avoids a US transfer question), and treat the Chrome version as a cloud service that needs a DPA. For DSA-funded licences in the UK, the licence is usually supplied to the individual student through the funding scheme rather than by the university, so check who the controller is before assuming the university is responsible.
Stava Rex and SpellRight (Oribi, now Everway)
- Vendor: Stava Rex is a Swedish spelling and grammar tool developed mainly for users with dyslexia, and SpellRight is designed for errors typically made by Swedes, Danes, Norwegians and Finns writing English, according to Karlstad University's description [10]. The Swedish Everway website now describes itself as "Everway: Tidigare Oribi" (formerly Oribi), with an address in Malmö [8].
- Versions: Everway's support page has guides for Windows, Mac, Google Docs, Pages and a Word add-in [9]. Stockholm University tells students to download the program from the supplier's website by logging in to the university's account with the supplier [11].
- Privacy documentation: the Everway website privacy policy (last updated 20 December 2024) states that it does not apply to personal data Everway processes on behalf of customers as a processor, refers to a separate product privacy notice and a processor list, and names a data protection officer reachable at a Texthelp address [6]. Everway's trust page shows ISO/IEC 27001 certification and offers a Global Data Protection Addendum (DPA) for download, described as a statement of its global data protection practices [19].
- Not found: a public, product-specific description of whether Stava Rex or SpellRight checks text locally or on a server, and in which version, was not found in public documentation (checked 7 October 2026). The oribi.se domain now redirects to Everway's Swedish website.
For a university: ask Everway in writing, per version (desktop, Word add-in, Google Docs add-on), whether text is processed locally, which entity is the processor, where any server is located, and which subprocessors apply. The Google Docs version by its nature runs inside a cloud editor, so check it separately from the desktop program.
TorTalk (TorTalk AB)
- Vendor: TorTalk AB offers text-to-speech for Windows, Mac, iOS and Android, with school licences that cover campus and exam computers as well as students' private computers [12][14].
- Privacy documentation: TorTalk's terms describe personal data collected when a customer orders (name and email address, with purchase history visible in the customer's account), the use of a payment provider, and how to request access, correction or deletion under the GDPR [13]. They focus on the vendor's own customer relationship.
- Not found: a public statement on whether text read aloud is processed on the device or sent to a server, and a public data processing agreement for institutional licences, were not found in public documentation (checked 7 October 2026). The FAQ says the program searches for updates when the computer is connected to a network [12].
For a university: because TorTalk is installed on exam computers at several institutions, confirm that the speech engine works offline and that no exam text leaves the machine. If the vendor confirms that nothing but licence and update data is transferred, the processing footprint is small.
Other tools
The same questions apply to other reading and writing aids, including the read-aloud functions built into browsers and office suites, and to general writing assistants that students with dyslexia often use. Our fact sheets on Grammarly and DeepL show how much plan tiers matter for cloud writing tools.
Student support services: how tools are handed out
The biggest privacy decisions are made by the disability or accessibility office, not by the vendor. Sweden is a useful example. Students with a permanent disability apply for targeted educational support through Nais, a national system in which each institution owns and is responsible for its own data, including personal data [16]. Applicants attach a medical certificate or other professional statement [16]. At Stockholm University, a coordinator reviews the application and the decision contains recommendations, for example on adjustments for written exams, which the student shares with their department [17].
Validemic's analysis That design keeps the diagnosis with the support office and passes on only the adjustment. Software provisioning should follow the same logic:
- Separate the register from the licence. Do not create vendor accounts or licence lists that can be matched to the support register. A campus licence open to all students achieves this by design.
- Pass on needs, not diagnoses. Exam offices and IT need to know that a student may use text-to-speech on an exam computer, not why.
- Watch exam logs. If assistive software on exam computers is tied to named accounts, the exam system can reveal who received an adjustment. Limit access and retention accordingly.
- Choose the legal basis deliberately. Recital 43 says consent is unlikely to be freely given where the controller is a public authority and there is a clear imbalance [1]. Support for disabled students usually rests on the university's duties under national education and equality law, combined with an Article 9(2) exception that your national law supports. Record which one you rely on.
DPIA considerations
Article 35 GDPR requires a data protection impact assessment where processing is likely to result in a high risk, and names large-scale processing of special category data as one example (Article 35(3)(b)) [1]. The Article 29 Working Party guidelines on DPIAs list nine criteria, including sensitive data, data concerning vulnerable data subjects and large-scale processing, and say that in most cases processing meeting two criteria requires a DPIA [3]. The guidelines describe vulnerable data subjects in terms of a power imbalance with the controller [3].
| Scenario | WP29 criteria likely met | Our suggestion |
|---|---|---|
| Desktop tool, campus licence, local voices, network version | Few or none | Documented screening |
| Browser extension or cloud OCR used by all students | Large scale; sometimes sensitive content | Screening, DPA, transfer check |
| Licences issued only to students with a documented disability, cloud features on | Sensitive data, vulnerable data subjects, possibly large scale | DPIA |
| Assistive tool linked to the support register or the exam system | Sensitive data, matching datasets, vulnerable data subjects | DPIA |
A useful DPIA for assistive technology is short: licensing model, enabled features, where text goes for each, allowed voices, the link to the support register, log retention and student information. Our DPIA template guide includes the structure, and the DPIA screening tool helps decide whether a full assessment is needed.
Does the AI Act apply?
Most text-to-speech and spelling tools are unlikely to fall under the AI Act's high-risk education list. The Commission's draft examples for Annex III point 3(b) place "neurodiverse learning companions" that support neurodivergent students outside its scope where they are not intended to determine grades [18]. Those examples are drafts and not yet adopted. A tool that also produced assessments used for grading or placement would need a fresh look, and an assistive tool that inferred emotions from a student's voice or face in an education setting would raise the Article 5(1)(f) prohibition. See our AI Act guide for universities for the general picture.
Checklist for DPOs and accessibility teams
- List every assistive tool the university licenses or recommends, with version (desktop, add-in, browser extension, mobile app).
- For each version, record which features run locally and which call a server, using the vendor's documentation or a written answer.
- Prefer campus licences open to all, and network versions without analytics or online licensing.
- Restrict online voices to local or EEA-hosted options unless a transfer assessment has been done.
- Sign a data processing agreement with the entity that processes student content, and check its subprocessors.
- Keep the support register separate from software provisioning and exam logs, and record the Article 9(2) exception relied on.
- Tell students which features send text to a server, and screen each tool for a DPIA.
- Review when the vendor changes ownership, name or hosting.
Sources
All sources retrieved 7 October 2026.
- Regulation (EU) 2016/679 (GDPR), Articles 4(15), 9, 35 and recitals 35 and 43, text read from the Publications Office copy of the Official Journal.
- Court of Justice of the EU, Judgment of 1 August 2022, OT v Vyriausioji tarnybinės etikos komisija, C-184/20, paragraph 120 and operative part 2, text read from the Publications Office.
- Article 29 Working Party, Guidelines on Data Protection Impact Assessment (WP248 rev.01).
- Texthelp support, ClaroRead: user data and internet access, last modified 27 June 2025.
- Everway, ClaroRead (DSA) (clarosoftware.com redirects via texthelp.com to Everway's DSA page, which links here).
- Everway, Webbplatsens sekretesspolicy (website privacy policy), last updated 20 December 2024, linked from everway.com/sv-se/integritet.
- Everway, Welcome to Everway (Texthelp rebrand).
- Everway Sweden, Everway: Tidigare Oribi (home page).
- Everway Sweden, Stava Rex support.
- Karlstad University, StavaRex & SpellRight: spell check software.
- Stockholm University, StavaRex & Spellright.
- TorTalk AB, home page and FAQ.
- TorTalk AB, Användarvillkor (terms of use).
- TorTalk AB, Skolor och universitet.
- Swedish University of Agricultural Sciences (SLU), TorTalk licence agreement.
- Swedish Council for Higher Education (UHR), Nais: application for targeted educational support.
- Stockholm University, Studera med funktionsnedsättning.
- AI Act Service Desk, Draft guidelines summary: Education and vocational training (draft, see consultation page).
- Everway, Trust.
About this page
Sources checked on 7 October 2026. We read the GDPR and the Court of Justice judgment in C-184/20 from the EU Publications Office, the WP29 DPIA guidelines, the vendors' own documentation and terms, and the public pages of Swedish universities and UHR. Vendor documentation changes, and two of the vendors have recently been renamed or merged, so check the current version and the contracting entity before relying on any detail. Statements about vendors come from their own pages; our interpretation is labelled as Validemic's analysis. This page is not legal advice, and the right Article 9(2) exception depends on national law. If you see an error or have a newer source, please contact us and we will correct it.
Frequently asked questions
Is the use of assistive technology by a student health data under the GDPR?
Not automatically. A campus licence for a spell checker that every student can install says nothing about anyone's health. It becomes data concerning health when the processing reveals information about a person's health status, for example a list of students who received a tool because of a documented disability. The Court of Justice has held that data which can indirectly reveal sensitive information through deduction falls under Article 9(1) (C-184/20).
Does text-to-speech software send my documents to the vendor?
It depends on the product, version and voice. ClaroRead's documentation, for example, says on-board local speech transfers no data, while online voices send text to Google, Amazon Polly (Stockholm), Nuance or Cereproc servers, and the Chrome version sends whole documents for OCR. Check the vendor's documentation for the exact version you deploy.
Do we need a DPIA for TorTalk or Stava Rex?
Often a documented screening is enough for locally installed tools under a campus licence. If the tool is assigned only to students with a disability, uses cloud processing of student text, or is linked to a support register, two or more of the WP29 criteria (sensitive data, vulnerable data subjects, sometimes large scale) may be met, and a DPIA is the safer course.
Who owns Stava Rex and ClaroRead today?
Stava Rex and SpellRight were developed by Oribi. The Swedish Everway website now presents itself as 'Everway: formerly Oribi', and Claro Software's website redirects, via texthelp.com, to Everway's pages. Everway is the name Texthelp adopted after joining with n2y. Check which legal entity signs your licence and data processing agreement.
Can we rely on student consent for assistive technology?
Consent is fragile when a public authority is the controller, because recital 43 GDPR says consent is unlikely to be freely given where there is a clear imbalance. Support for disabled students usually rests on the university's legal duties under national education and equality law. Where a tool's cloud features are optional, letting students choose a local mode is a better safeguard than a consent form.