Legal
Privacy policy
This notice explains, as required by Articles 13 and 14 GDPR, what personal data is processed when you use this website and the hosted Enclessa service. Where Enclessa processes data on behalf of a customer organisation, the data processing agreement governs instead of this notice. This is a translation for convenience. The German version at /de/rechtliches governs, because the seller is German and the contract language is German.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
Version: 7 September 2026
1. Controller and data protection officer
The controller within the meaning of Article 4 (7) GDPR is:
Quavon UG (haftungsbeschränkt)
Langbehnstraße 39
83022 Rosenheim, Deutschland
Email: privacy@enclessa.app
Data protection officer: not appointed. Fewer than twenty persons at the provider are permanently engaged in the automated processing of personal data (§ 38 (1) BDSG), and none of the conditions of Article 37 (1) GDPR is met. The provider answers data protection enquiries directly.
2. The two roles Enclessa plays
For its own relationship with you, Enclessa is the controller: your account, billing, support correspondence and this website.
For everything your organisation puts into the platform — messages, files, time records, personnel data — Enclessa is a processor acting on your organisation’s instructions. Your organisation is the controller and its own privacy notice governs.
3. Visiting this website
When you open this website the server processes access data your browser transmits: IP address, date and time of the request, the resource requested, the volume transferred, the response status, the referrer and the user agent.
The legal basis is Article 6 (1) (f) GDPR. The legitimate interest is operating the site, diagnosing faults and defending against attacks. Access logs are neither shipped to an external logging service nor archived: they are files on the server, continuously overwritten by rotation. What is kept beyond that is only what defending against attacks derives from them — the temporary blocking of a conspicuous IP address, say — and that for at most 14 days; where logs are needed to investigate a specific security incident, the lines concerned are preserved separately and deleted when the investigation closes.
Typefaces are bundled at build time and served locally, so no connection to a font service occurs. Beyond that, this website loads a single resource from another server: the usage measurement running on Rybbit at tracker.quavon.de, which Quavon operates itself.
Rybbit sets no cookies and stores nothing on your terminal equipment: nothing is written to or read from your browser’s local storage or session storage. As no access to your terminal equipment within the meaning of § 25 (1) TDDDG takes place, no consent is required for it, which is why no consent banner is shown. What is processed is the page opened, the referring page and coarse technical details of browser, operating system and screen size.
The legal basis is Article 6 (1) (f) GDPR. The legitimate interest is the statistical evaluation of usage in order to improve what is offered. Under Article 21 GDPR you have the right to object to this processing at any time on grounds relating to your particular situation; the contact details are in the imprint.
4. Contacting us
If you write to us by email, we process your address and the content of your message in order to answer it. The legal basis is Article 6 (1) (b) GDPR for contract-related enquiries and otherwise Article 6 (1) (f) GDPR.
Support correspondence is deleted 24 months after the last contact, unless a commercial or tax retention duty applies.
5. Registration and use of the service
To provide Enclessa we process account data: email address, display name, username, language and time zone, together with authentication material in the form of a password hash and any two-factor configuration.
The legal basis is Article 6 (1) (b) GDPR, as the processing is necessary to perform the contract.
Signing in sets a strictly necessary cookie named enclessa_session. It is bound to your organisation’s host, unreadable to scripts (HttpOnly), transmitted only over TLS (Secure) and not sent on requests originating from other sites (SameSite=Strict). It serves session management alone and is exempt from consent under § 25 (2) no. 2 TDDDG.
The service also keeps the following on your terminal equipment. None of it serves advertising or measurement, and each is exempt from consent under § 25 (2) no. 2 TDDDG, because without it the function you asked for cannot be provided:
- enclessa_portal — the customer portal’s session cookie, set when you redeem a portal link you were sent. HttpOnly, Secure and SameSite=Lax; Lax because opening it from a mail client is a cross-site navigation, which a Strict cookie would not accompany.
- enclessa_locale — the display language last used, so the first page arrives in your language. One year, readable to scripts, carrying no identifier and no sign-in effect.
- In the browser’s local storage: the appearance you chose (light, dark, high contrast), the areas and emoji you last opened, notices you dismissed, a mute switch for the ringtone, on the shared front door the identifiers of the organisations this browser was last sent to (the identifier only, no name), and an installation identifier minted once per browser profile that lets end-to-end encryption recognise this device again.
- For end-to-end encryption: this device’s key material — in the browser in local storage and the Origin Private File System, in the apps in the operating system’s protected key store. It does not leave the device.
- In the browser’s session storage: the sign-in session token and the page to return to after signing in. Both end when the tab is closed.
6. Processing during operation
Running the service produces further data required for security and accountability. The legal basis is Article 6 (1) (b) GDPR where it forms part of the service and Article 6 (1) (f) GDPR for security and abuse prevention.
- Sessions and signed-in devices, each with the time and IP address of sign-in
- Rate-limit counters per organisation and per member
- An audit log of administrative action within an organisation
- Malware scanning of uploaded files before they can be opened
- Link previews are fetched by the server rather than by your browser, so your IP address never reaches the target site
7. Push notifications
If you enable push notifications, we transmit the device token and the title and sender line of the notification to the device manufacturer’s push service so that it can be delivered. For end-to-end encrypted conversations the notification carries no message text.
The legal basis is Article 6 (1) (a) GDPR together with the permission granted on your device, which you can withdraw there at any time.
8. Video and voice calls
Calls run over a media server we operate ourselves. Connection data is processed: participants, start and end, device type and the network addresses used to establish the connection. Media content is not stored unless recording is explicitly started.
The legal basis is Article 6 (1) (b) GDPR.
9. End-to-end encrypted content
Direct messages and encrypted group conversations are encrypted using Messaging Layer Security (RFC 9420). The server stores ciphertext only and holds no key that opens it.
Enclessa therefore cannot read the content of those conversations or disclose it to anybody, including in response to an official order. What is processed is the metadata delivery requires: sender, recipient group, time and size.
10. Billing and payment
For paid subscriptions we process company name, billing address, VAT identification number, the seats booked, invoices and payment status. The legal basis is Article 6 (1) (b) GDPR and Article 6 (1) (c) GDPR in conjunction with commercial and tax retention duties.
Payments are handled by Mollie B.V., Amsterdam, Netherlands. Mollie is a payment service provider rather than a merchant of record; payment instrument data such as card numbers is processed there and is neither collected nor stored by Enclessa.
11. Recipients and processors
Personal data is disclosed to the processors below, in each case under an Article 28 GDPR contract. The same list forms the annex to the data processing agreement and the two are maintained together.
| Recipient | Purpose | Seat | Transfer |
|---|---|---|---|
| netcup GmbH | Operation of the servers, databases and object storage the service runs on | Karlsruhe, Germany | Processing exclusively in datacentres located in Germany |
| Mollie B.V. | Payment processing for paid subscriptions (payment service provider, not merchant of record) | Amsterdam, Netherlands | Processing within the European Union |
| Apple Distribution International Ltd. | Delivery of push notifications to iOS and macOS devices through the Apple Push Notification service; the device token and the title and sender line are transmitted | Cork, Ireland | Transfer to the USA possible; adequacy decision for the EU-US Data Privacy Framework or standard contractual clauses |
| Google Ireland Limited | Delivery of push notifications to Android devices through Firebase Cloud Messaging; the device token and the title and sender line are transmitted | Dublin, Ireland | Transfer to the USA possible; adequacy decision for the EU-US Data Privacy Framework or standard contractual clauses |
| OpenAI Ireland Ltd. | Operation of the language model behind the model-assisted features (the “companion” module): the assistant itself, the draft notes and letters in the customer area, and — where the organisation has switched it on — the summaries of incoming email. What those features put to it is transmitted: the question and the conversation, the records read, the customer’s contact list, the text of incoming messages. Only in organisations that have installed the module; end-to-end encrypted rooms stay out of reach. | Dublin, Ireland | Processing also takes place in the USA; standard contractual clauses under Article 46 (2) (c) GDPR, supplemented by the EU-US Data Privacy Framework adequacy decision where the receiving company is certified |
| Infomaniak Network SA | Operation of the mail servers and sending of invitations, notifications, invoices and security-related email | Geneva, Switzerland | Transfer to Switzerland on the basis of the European Commission’s adequacy decision for Switzerland (Article 45 GDPR) |
12. Model-assisted features (the companion)
The companion is the module through which this installation reaches a language model. An organisation installs it for itself; without that installation nothing anywhere in the service is transmitted to a model provider. Which provider and which model are in use is stated in the interface, and the provider is named in the list in section 11.
None of these features can reach an end-to-end encrypted conversation. Beyond that, your organisation can decide separately whether message, mail, file and page content may be sent at all.
The legal basis is Article 6 (1) (b) GDPR towards your organisation as the controller; Enclessa acts as processor here and the model provider as a further processor under Article 28 (4) GDPR. The transfer to a third country is described in section 13. The content is not used to train models.
Three features reach the model, and they differ in who sets them off:
- The assistant itself: when you put a question to it, the question, the conversation so far and the content of the records it read for you are transmitted. Under each answer it says what actually left this installation.
- Drafts in the customer area: when you ask for a draft note or letter, the text you entered and that customer’s contact list — names, roles, email addresses — are transmitted.
- Summaries of incoming email: where your organisation has switched this on explicitly, the text of incoming messages is transmitted to produce a draft note on the customer record. It happens as the message is fetched and without further action; the permission is checked afresh for every message.
13. Transfers to third countries
The service is operated in Germany. The platform’s content, files and databases are held exclusively in datacentres located in Germany and do not leave the European Union.
A transfer to a third country occurs in three cases. First, in the delivery of push notifications, and there only to the extent set out in section 7; this rests on the adequacy decision for the EU-US Data Privacy Framework and, in the alternative, on standard contractual clauses under Article 46 (2) (c) GDPR. Second, in the sending of email, which runs through mail servers in Switzerland; that rests on the European Commission’s adequacy decision for Switzerland under Article 45 GDPR.
Third, in the AI companion of section 12, where your organisation has installed it: the content named there is transmitted to OpenAI Ireland Ltd., Dublin, and processed in the United States as well. This rests on standard contractual clauses under Article 46 (2) (c) GDPR, supplemented by the EU-US Data Privacy Framework adequacy decision where the receiving company is certified.
14. Retention
Personal data is deleted once its purpose has ceased and no statutory retention duty stands in the way.
| Category | Period |
|---|---|
| Server logs of this website | Until rotation overwrites them; blocking decisions derived from them, 14 days |
| Sessions and device records | Until sign-out, at most twelve months from last use; device records until the device is removed |
| Account and content data | For the term of the contract; thereafter per § 15 of the terms and clause 10 of the data processing agreement |
| Audit log | As configured by the organisation; absent such a setting, until the organisation is deleted |
| Support correspondence | 24 months after the last contact |
| Invoices and accounting records | 8 years under § 257 (4) HGB and § 147 (3) AO as applicable from 2025 |
15. Your rights
You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). Consent once given can be withdrawn at any time with effect for the future.
A message to privacy@enclessa.app is enough to exercise them. Requests are answered without undue delay and within one month of receipt at the latest (Article 12 (3) GDPR).
Where your request concerns data your organisation has put into the platform, we pass it to your organisation as the controller and support it in answering.
Right to object under Article 21 GDPR: where processing rests on Article 6 (1) (f) GDPR, you may object on grounds relating to your particular situation. We will then stop processing unless we demonstrate compelling legitimate grounds.
16. Right to lodge a complaint
Without prejudice to any other remedy, Article 77 GDPR gives you the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement.
The authority competent for the provider is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland, https://www.lda.bayern.de
17. Whether provision is required
Account and billing data must be provided in order to conclude the contract; without it the service cannot be supplied. There is no further statutory or contractual obligation to provide data.
18. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR. The companion of section 12 decides nothing: it proposes changes, and a person’s approval is what carries them out.
Content is not used to train machine-learning models.
19. Changes to this notice
This notice is amended when the processing or the law changes. The version published on this page governs, and its date is shown above. Material changes affecting existing customers are additionally announced by email.