Skip to content

Use case · data protection

What we can hand over, and what nobody can

Enclessa answers a data-subject request from two places: the People module produces a data-subject export of one person’s employment record, generated asynchronously with a checksum and an expiring link, and the organisation-wide export produces everything the platform holds in open formats with a manifest naming every table and its row count. End-to-end encrypted direct messages are the exception and the honest part of the answer — the server holds ciphertext and cannot produce their contents for anybody, including us.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

At a glance

Per person
A data-subject export from the People module
Whole organisation
A full export in open formats, with a manifest
Delivery
Generated asynchronously, downloaded over an expiring link
Encrypted rooms
Cannot be produced server-side, by anyone
Erasure
Refused by naming its rule when a hold applies
Needs
People for the per-person export — the Business plan

The situation

Somebody has asked what personal data you hold about them, and there is a deadline. The answer has to be complete enough to be honest and precise enough to be useful, and it has to account for a collaboration platform that holds an employment record, a few years of messages, some uploaded files and an audit log.

What goes wrong when this is spread across four products

The data is spread across products that do not agree

An HR system, a chat product, a file store and a project tool each hold part of the answer in a different shape, and reconciling them into one response is manual work under time pressure.

Export means whatever the vendor decided it means

A download that arrives as an undocumented archive with no statement of what is in it cannot be checked for completeness, which is precisely what the requester and the regulator want.

Nobody knows what encryption means for the request

If some rooms are end-to-end encrypted, somebody has to be able to say clearly what that does and does not mean for the response, before the request arrives rather than during it.

Erasure and retention pull in opposite directions

Some records must be kept and some must go, and a platform that only knows how to keep everything forever fails the first duty as reliably as one that deletes everything fails the second.

How Enclessa handles it

  1. Work out which of the two exports you need

    For an employee asking about their personnel data, the People module produces a data-subject export covering their record — identity, employment, and the rest of what the module holds about them. For anything wider, the organisation export covers what the platform holds across the whole tenant.

  2. Run the export and check the manifest

    Exports are produced asynchronously and delivered over a signed link that expires, with a checksum. The organisation export carries a manifest naming every table and its row count, and naming what was deliberately withheld and why — so completeness is something you can check rather than assume.

  3. Say plainly what the encrypted rooms contain and why they are not in it

    Direct messages and group direct messages are end-to-end encrypted, so the server holds ciphertext and cannot produce their contents. That is a property of the product rather than a refusal, and the requester can produce their own copy from their own device, where the plaintext actually is.

  4. Check whether a hold blocks an erasure before you promise one

    If the request is for deletion rather than access, retention categories and legal holds may require the record to be kept. An erasure that is blocked is refused as a whole and names the rule that blocked it, rather than partially succeeding and leaving nobody able to say what remains.

  5. Keep the audit trail of what you did

    Administrative action is recorded with the organisation it belongs to, and document downloads in the People module are audited individually — so the file showing how the request was handled is a by-product rather than something to assemble afterwards.

Which plan this needs

The per-person data-subject export is part of the People module, on the Business plan. The organisation-wide export, the audit log and per-organisation retention are on the Team plan and above. There is no plan on which your data is held hostage: an export is a feature, not a negotiation.

Compare the plans

What this will not do

  • The per-person export covers the People module’s record of that person. It is not a single button that gathers every message they ever wrote across the platform.
  • End-to-end encrypted rooms cannot be produced server-side by anybody, including us. If a response has to include them, it has to come from a participant’s own device.
  • There is no compliance export in a supervision format such as CSV or Actiance XML, and no discovery tooling. What exists is a full data export and an audit log.
  • Enclessa holds no data-protection certification and has commissioned no external audit. What is offered is a published architecture, a documented data model and an export you can inspect.
  • None of this is legal advice, and using Enclessa does not make an organisation compliant with anything. It gives you the operations a response needs; the response is still yours to write.

Where the detail is

Questions

A data-subject access request: common questions

Can Enclessa export the data it holds about one person?

Yes, for their employment record. The People module produces a data-subject export generated asynchronously with a checksum and an expiring download link. Data outside that module is covered by the organisation-wide export.

What happens to end-to-end encrypted messages in a data-subject request?

They cannot be produced by the server, because it holds ciphertext and no keys. The plaintext exists only on the participants’ own devices, so a copy has to come from there — which is the same property that makes the encryption worth having.

Can we get all of our data out of Enclessa?

Yes. A full organisation export produces what the platform holds in open formats, with a manifest naming every table and its row count, and it can include uploaded files. It is available whenever it is asked for.

Can an erasure be blocked?

Yes, where a retention category or a legal hold requires the record to be kept. The erasure is refused as a whole and names the rule that blocked it, rather than partly succeeding and leaving the result ambiguous.

Does using Enclessa make us GDPR compliant?

No. No software does that. Enclessa is hosted in the European Union by a German company, holds no certification, and provides export, audit and retention operations that a compliance process can use. The process is still yours.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.