Skip to content

Glossary · Compliance

GDPR

The GDPR is Regulation (EU) 2016/679, the European Union law that governs the processing of personal data and applies to any organisation processing the data of people in the EU, wherever that organisation is established.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

Also called

General Data Protection Regulation

What GDPR means

The regulation is built on a small number of ideas that recur throughout it. Processing needs a lawful basis. It must be limited to a stated purpose and to the data that purpose actually requires. It must be transparent to the people whose data it is, who hold enforceable rights over it. And it must be secured, with the measures proportionate to the risk.

The distinction that matters most in a software purchase is between the controller, who decides why and how personal data is processed, and the processor, who processes it on the controller’s documented instructions. When a company buys a collaboration platform, the company is the controller for everything its people put into it and the vendor is the processor. That relationship must be written down in a contract meeting Article 28, and the vendor cannot take it on for the customer.

Because of this split, "GDPR compliant" is not a property a product can have on its own. A product can provide the controls and the paperwork compliance requires — a processing agreement, a subprocessor list, export and deletion, security measures — while the lawful basis, the retention decisions and the transparency to staff remain the customer’s.

How Enclessa uses it

Enclessa is built for GDPR rather than certified against it: hosted in the European Union, sold by a German company, with a data processing agreement, per-organisation retention, full organisation export and a data-subject export in the People module. Enclessa is the processor for customer content and the controller for its own account, billing and website data. Enclessa holds no compliance certification of any kind.

Where GDPR is specified

Related terms

Read further

The security page explains how Enclessa protects data and which certifications it does not hold. The trust centre covers the processing agreement, the subprocessors and the residency position. The FAQ answers the questions buyers ask most often.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.