The data is spread across products that do not agree
An HR system, a chat product, a file store and a project tool each hold part of the answer in a different shape, and reconciling them into one response is manual work under time pressure.
Use case · data protection
Enclessa answers a data-subject request from two places: the People module produces a data-subject export of one person’s employment record, generated asynchronously with a checksum and an expiring link, and the organisation-wide export produces everything the platform holds in open formats with a manifest naming every table and its row count. End-to-end encrypted direct messages are the exception and the honest part of the answer — the server holds ciphertext and cannot produce their contents for anybody, including us.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
Somebody has asked what personal data you hold about them, and there is a deadline. The answer has to be complete enough to be honest and precise enough to be useful, and it has to account for a collaboration platform that holds an employment record, a few years of messages, some uploaded files and an audit log.
An HR system, a chat product, a file store and a project tool each hold part of the answer in a different shape, and reconciling them into one response is manual work under time pressure.
A download that arrives as an undocumented archive with no statement of what is in it cannot be checked for completeness, which is precisely what the requester and the regulator want.
If some rooms are end-to-end encrypted, somebody has to be able to say clearly what that does and does not mean for the response, before the request arrives rather than during it.
Some records must be kept and some must go, and a platform that only knows how to keep everything forever fails the first duty as reliably as one that deletes everything fails the second.
For an employee asking about their personnel data, the People module produces a data-subject export covering their record — identity, employment, and the rest of what the module holds about them. For anything wider, the organisation export covers what the platform holds across the whole tenant.
Exports are produced asynchronously and delivered over a signed link that expires, with a checksum. The organisation export carries a manifest naming every table and its row count, and naming what was deliberately withheld and why — so completeness is something you can check rather than assume.
Direct messages and group direct messages are end-to-end encrypted, so the server holds ciphertext and cannot produce their contents. That is a property of the product rather than a refusal, and the requester can produce their own copy from their own device, where the plaintext actually is.
If the request is for deletion rather than access, retention categories and legal holds may require the record to be kept. An erasure that is blocked is refused as a whole and names the rule that blocked it, rather than partially succeeding and leaving nobody able to say what remains.
Administrative action is recorded with the organisation it belongs to, and document downloads in the People module are audited individually — so the file showing how the request was handled is a by-product rather than something to assemble afterwards.
The per-person data-subject export is part of the People module, on the Business plan. The organisation-wide export, the audit log and per-organisation retention are on the Team plan and above. There is no plan on which your data is held hostage: an export is a feature, not a negotiation.
Compare the plansCreate a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.
Open beta. Free plan, no payment card to start.