A retention policy is a rule stating how long a category of data is kept before it is deleted, applied automatically rather than left to somebody remembering.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
What Retention policy means
Retention is where two legal pressures meet head-on. Data protection law says personal data must not be kept longer than the purpose requires, which argues for deleting early. Commercial, tax and sector law require certain records to be kept for years — in Germany, the periods in § 257 HGB and § 147 AO — which argues for keeping. A retention policy is the written resolution of that conflict, per category of data.
The operational difficulty is that deletion at scale is not a single statement. Deleting a message means deleting its attachments, its search index entries, its notifications, its audit references and its backups, and doing so without breaking the referential integrity of everything that pointed at it. Systems that treat deletion as an afterthought end up with data that has disappeared from the interface and not from the database.
Retention also interacts with encryption in a way worth stating plainly. A policy can only inspect what the server can read. In an end-to-end encrypted room the server holds ciphertext, so retention can delete on a schedule but cannot make a decision that depends on the content.
How Enclessa uses it
Enclessa supports per-organisation retention, and the default keeps data rather than deleting it, so nothing disappears because a setting was never visited. Finer-grained retention per team and per channel is planned work in phase 5 and is not available today. The People module carries its own retention metadata on custom fields, and organisation deletion runs as a resumable purge that derives its scope from the schema rather than from a hand-written list.
Where Retention policy is specified
Related terms
Read further
The security page explains how Enclessa protects data and which certifications it does not hold. The trust centre covers the processing agreement, the subprocessors and the residency position. The FAQ answers the questions buyers ask most often.
Encrypted collaboration, hosted in Europe.
Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.
Open beta. Free plan, no payment card to start.