The messenger your data protection officer can sign offThemessengeryourdataprotectionofficercansignoff
Enclessa is a team messenger hosted in Germany by netcup GmbH and sold by Quavon UG (haftungsbeschränkt), a German company, so the platform’s content, files and databases stay in the European Union. The Article 28 data processing agreement is part of the terms and applies from first use; subprocessors are named with 30 days’ notice of any change; direct messages are end-to-end encrypted with MLS (RFC 9420); and data-subject exports, retention rules and legal holds are built in. Compliance itself is a property of how your organisation processes data, not of a product: Enclessa supplies the contract and the controls, holds no ISO 27001 or comparable certification, and the lawful basis remains yours.
Your team talks in a consumer messenger or in a US suite, and the data protection officer has asked what that means for the personal data in it. The replacement has to work well enough that people actually move, and it has to come with answers a DPO can check: who processes the data, where, under which contract, with which subcontractors, and how it can be found, kept or deleted.
What goes wrong when this is spread across four products
The consumer messenger has no contract for you
A messenger built for private use has no data processing agreement with your company, reads the address books it is given, and leaves a DPO nothing to sign. Its encryption is real and does not answer the question being asked.
The suite is hosted in the EU and owned elsewhere
An EU data centre answers where the data is stored. It does not answer which law the provider is subject to, and a DPO has to document that transfer risk rather than wave it through.
“GDPR-compliant” is a badge, not an answer
A product page that says compliant without naming the processor, the subprocessors, the data flows that leave the EU and the certifications it does not hold has told the reviewer nothing they can put in a record of processing.
Nobody planned the exit
A data-subject request, a retention duty or the end of the contract all need the data to be found and moved, and a messenger chosen for its chat alone often turns out to have no export worth the name.
How Enclessa handles it
1
Settle the roles and the processing agreement
Your organisation is the controller for what it puts into Enclessa, and Enclessa is the processor acting on your instructions. The Article 28 data processing agreement is part of the terms and applies from the moment you use the service; where your organisation needs a signed counterpart, one is issued on request.
2
Check where the data lives and what leaves the EU
The platform’s content, files and databases run with netcup GmbH in Karlsruhe, Germany. Two flows leave the EU and are named in the privacy notice: push notifications through Apple and Google, which never carry the body of an encrypted message, and email dispatched through servers in Switzerland, which has an adequacy decision.
3
Review the subprocessors and the change notice
The subprocessor list sits in the annex of the processing agreement and is mirrored in the privacy notice. A new or replaced subprocessor is announced at least 30 days ahead, and you may object on a substantive data protection ground.
4
Decide which conversations are end-to-end encrypted
Direct and group direct messages are end-to-end encrypted with MLS, so the server holds no key that opens them. Channels are server-managed instead, which is what makes them searchable and exportable. Knowing which is which is the difference between a data map that is right and one that is hopeful.
5
Plan retention, requests and the exit before you need them
Retention rules and legal holds keep what must be kept; the People module produces a data-subject export for one person; and the organisation export produces everything in open formats with a manifest. After the contract ends the data stays exportable for 30 days and is deleted, backups included, within a further 30.
Which plan this needs
Encrypted direct messages, EU hosting and the processing agreement come with every plan, including Free for up to ten members. Retention rules, legal holds and the per-person data-subject export are on the Business plan. The pricing page lists what each plan includes.
Stated here rather than discovered after signing up.
Enclessa holds no ISO 27001, SOC 2, BSI C5 or comparable certification, and its own implementation has had no external security audit. If a certification is a procurement gate, the answer is no.
There is one European Union region on the standard plans and no choice of country within it. A dedicated deployment in a region you name is the Enterprise arrangement.
Channels are not end-to-end encrypted; they are server-managed, which is what makes search, retention and export work for them.
Retention can be set per organisation. Retention per team or per channel is planned and not available today.
None of this is legal advice, and using Enclessa does not make an organisation compliant. It supplies the contract and the controls; the processing, and its lawful basis, remain yours.
Choosing a GDPR-compliant messenger: common questionsChoosingaGDPR-compliantmessenger:commonquestions
Enclessa is built for the GDPR: hosted in the European Union, sold by a German company, with an Article 28 processing agreement, data-subject export, retention rules and legal holds. Compliance is a property of how your organisation processes data rather than of a product, so Enclessa provides the controls and the agreement, and the lawful basis remains yours.
With netcup GmbH in Karlsruhe, Germany. The platform’s content, files and databases stay there. Push notifications reach Apple and Google without the body of an encrypted message, and email is sent through servers in Switzerland; both are named in the privacy notice.
No separate signature is needed: the Article 28 agreement is part of the terms and applies from first use. If your organisation requires a signed counterpart, one is issued on request.
Not direct messages: they are end-to-end encrypted with MLS, and the server holds no key that opens them. Channels are server-managed, so the platform can search, retain and export them for your organisation, which is the trade-off the product shows rather than hides.
No. Enclessa holds no ISO 27001, SOC 2 or comparable certification and has had no external audit of its own implementation. What exists instead is published architecture, a documented data model and an encryption standard implemented through an independently audited library.
Your team. Your keys. Your continent.Yourteam.Yourkeys.Yourcontinent.
Create a workspace in a minute. Free for up to ten people, forever.