Legal
Data processing agreement
Where an organisation uses Enclessa, that organisation is the controller of the personal data it puts into the platform and Enclessa is the processor. This agreement sets out that relationship as required by Article 28 (3) GDPR. It forms part of the terms of service; a separate signature is required only if the organisation asks for one. This is a translation for convenience. The German version at /de/rechtliches governs, because the seller is German and the contract language is German.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
Version: 7 September 2026
1. Subject matter, duration, nature and purpose
(1) The subject matter is the provision of the hosted Enclessa collaboration platform.
(2) The nature and purpose of the processing are the storage, transmission, display, backup and deletion of the content the controller and its users create, together with the metadata operation requires.
(3) The duration corresponds to the term of the service contract plus the periods set out in section 10.
(4) Processing takes place exclusively in the European Union; exceptions are named in the sub-processor annex.
2. Categories of data subject and of personal data
Data subjects are the controller’s employees, contractors, applicants, customers and business partners, and any other person whose data the controller enters.
- Identification and contact data: name, username, email address, telephone number, language, time zone
- Communication content: messages, attachments, comments, call metadata
- File content including any personal data it contains
- Task, project and time data: entries, absences, bookings
- Personnel master data in the People module together with contract and remuneration data, to the extent the controller enters it
- Health data within the meaning of Article 9 (1) GDPR to the extent the controller enters it, in particular sickness reports, periods of incapacity for work and certificates of incapacity for work; the service provides no field of its own for a diagnosis
- Usage and security data: sessions, devices, IP addresses, audit records
3. Instructions
(1) Enclessa processes personal data only on the documented instructions of the controller. The service contract, this agreement and the controller’s use of the platform’s features constitute such instructions.
(2) Further instructions are given in text form to the address named in section 11.
(3) If Enclessa considers an instruction to infringe data protection law it says so without delay and may suspend execution until the instruction is confirmed.
(4) Where processing is exceptionally required by law, Enclessa informs the controller before processing unless the law prohibits it.
4. Confidentiality
(1) Enclessa binds every person authorised to process personal data to confidentiality and instructs them in the relevant duties of data protection law.
(2) The control plane used to operate the platform is a separate identity with its own sign-in and its own log. It can list organisations, suspend one, schedule a deletion and run a purge; it cannot read content. That separation is enforced by a build check: the control-plane package may not import anything that can read content, and the build fails if that changes. No feature exists by which staff could assume a user’s identity.
5. Technical and organisational measures (Article 32 GDPR)
Enclessa implements the measures below and maintains them for the term. They may be developed further as long as the level of protection is not reduced.
- Confidentiality: end-to-end encryption of direct messages per RFC 9420 (MLS), encryption in transit over TLS, encryption at rest, tenant isolation asserted at a single choke point and proven by a suite generated from the API description that drives every operation across the organisation boundary
- Access control: permissions as a bitmask in the data layer rather than in the interface, roles per organisation, exactly one owner per organisation, two-factor authentication mandatory for the provider’s operations tier and available to every member, which an organisation can make mandatory for administration, finance and people roles, sign-out after 30 days without use, access tokens scoped to named operations
- Integrity: an audit log of administrative action, malware scanning of uploads, link previews fetched server-side only and protected against requests into internal networks
- Availability and resilience: regular backups with tested restores, rate limits per organisation and member, separation of environments
- Review procedures: dependency and static security analysis in the build, four-eyes review of changes, a documented process for security incidents
- Data protection by default: separation of control plane and content, no use of customer content for model training, the deletion regime in section 10
6. Sub-processors
(1) The controller gives general authorisation for the sub-processors listed below.
(2) Enclessa notifies the controller in text form at least 30 days before engaging a further sub-processor or replacing an existing one. The controller may object within that period on a substantial data protection ground. If the objection cannot be resolved, the controller may terminate the service contract for cause with effect from the intended change.
(3) Enclessa imposes obligations on each sub-processor equivalent to those agreed here and is liable for its conduct as for its own.
| Sub-processor | Service | Seat | Transfer |
|---|---|---|---|
| netcup GmbH | Operation of the servers, databases and object storage the service runs on | Karlsruhe, Germany | Processing exclusively in datacentres located in Germany |
| Mollie B.V. | Payment processing for paid subscriptions (payment service provider, not merchant of record) | Amsterdam, Netherlands | Processing within the European Union |
| Apple Distribution International Ltd. | Delivery of push notifications to iOS and macOS devices through the Apple Push Notification service; the device token and the title and sender line are transmitted | Cork, Ireland | Transfer to the USA possible; adequacy decision for the EU-US Data Privacy Framework or standard contractual clauses |
| Google Ireland Limited | Delivery of push notifications to Android devices through Firebase Cloud Messaging; the device token and the title and sender line are transmitted | Dublin, Ireland | Transfer to the USA possible; adequacy decision for the EU-US Data Privacy Framework or standard contractual clauses |
| OpenAI Ireland Ltd. | Operation of the language model behind the model-assisted features (the “companion” module): the assistant itself, the draft notes and letters in the customer area, and — where the organisation has switched it on — the summaries of incoming email. What those features put to it is transmitted: the question and the conversation, the records read, the customer’s contact list, the text of incoming messages. Only in organisations that have installed the module; end-to-end encrypted rooms stay out of reach. | Dublin, Ireland | Processing also takes place in the USA; standard contractual clauses under Article 46 (2) (c) GDPR, supplemented by the EU-US Data Privacy Framework adequacy decision where the receiving company is certified |
| Infomaniak Network SA | Operation of the mail servers and sending of invitations, notifications, invoices and security-related email | Geneva, Switzerland | Transfer to Switzerland on the basis of the European Commission’s adequacy decision for Switzerland (Article 45 GDPR) |
7. Assistance to the controller
(1) Enclessa assists the controller with appropriate technical and organisational measures in responding to requests from data subjects under Chapter III GDPR. Where a data subject approaches Enclessa directly, they are referred to the controller and the controller is informed without delay.
(2) Enclessa assists the controller in complying with Articles 32 to 36 GDPR, in particular with a data protection impact assessment, and provides the information required for it.
(3) Enquiries are answered within ten working days, and urgent enquiries without undue delay.
8. Personal data breaches
(1) Enclessa informs the controller without undue delay and within 24 hours of becoming aware of any personal data breach affecting the controller’s data.
(2) The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information not immediately available is supplied subsequently.
(3) Notifications and follow-up correspondence run through security@enclessa.app.
9. Evidence and audits
(1) Enclessa makes available all information necessary to demonstrate compliance with Article 28 GDPR and answers one processor questionnaire per calendar year.
(2) Further verification is carried out primarily through documentation and written responses. The controller may require an on-site inspection where there is specific cause; it is announced 30 days in advance, takes place during usual business hours, must not disrupt operations, and requires the inspecting persons to be bound to confidentiality. The inspector may not be a competitor.
(3) Enclessa holds no ISO 27001, SOC 2 or comparable certification and has not undergone an external security audit. That statement is part of the information provided and is not replaced by a general assertion about the state of the art.
10. Deletion and return
(1) After the service contract ends the controller can export its data in full for 30 days.
(2) Enclessa then deletes the data from the live systems within 30 days. Deletion derives its scope from the data model rather than a hand-maintained list of tables, is resumable, and is logged; deletion of stored files is retried until the storage confirms it. Backups expire with their 30-day cycle, so that no later than 31 days after deletion from the live systems no backup contains the data; if a backup is restored before then, Enclessa repeats the deletion.
(3) The only exception is data Enclessa must keep under a statutory duty that binds Enclessa itself, namely its own invoices to the controller and the related payment records (§ 14b UStG, § 147 AO); it is blocked and deleted once the period expires. The controller’s own retention duties do not prevent deletion (Article 28 (3) (g) GDPR); the controller meets them through the export in paragraph 1. On request Enclessa confirms deletion in text form.
11. Contacts and final provisions
(1) Data protection contact at Enclessa: privacy@enclessa.app. Data protection officer: not appointed. Fewer than twenty persons at the provider are permanently engaged in the automated processing of personal data (§ 38 (1) BDSG), and none of the conditions of Article 37 (1) GDPR is met. The provider answers data protection enquiries directly.
(2) Where this agreement and the service contract conflict in respect of the processing of personal data, this agreement prevails.
(3) Liability follows Article 82 GDPR and otherwise the provisions of the service contract.
(4) German law applies. Amendments require text form.