Legal and Security
Enterall legal, privacy, and security overview
Effective date: June 26, 2026. This page summarizes the baseline privacy, security, retention, incident response, and commercial due diligence materials available for enterprise customers. It is a product and compliance summary, not a substitute for a signed DPA, MSA, order form, or legal advice.
Privacy Notice
Enterall collects the personal data needed to provide, secure, support, and improve the product. This may include account information, email addresses, user identifiers, authentication metadata, board and document content, uploaded and generated images, collaboration metadata, usage events, device information, IP addresses, support communications, and operational logs.
We use this data to provide core functionality, run collaboration and AI workflows, maintain security, prevent abuse, troubleshoot issues, improve reliability, communicate with users, and comply with legal obligations. We do not sell personal data. Data subjects may request access, correction, deletion, restriction, objection, or portability where applicable by contacting hello@enterall.co.
International Transfer Setup
Some personal data may be processed outside the EU or EEA by infrastructure, analytics, email, AI, or support providers. Where GDPR transfer rules apply, Enterall relies on lawful transfer mechanisms such as the European Commission Standard Contractual Clauses, vendor data processing agreements, and supplementary transfer risk assessments where required.
Enterprise customers may request the relevant DPA, subprocessor list, and a basic transfer summary showing which service categories may process data outside the EEA, the transfer mechanism used, and the safeguards applied.
Technical and Organisational Measures
Enterall maintains baseline security controls appropriate for an early-stage SaaS product handling customer workspace, board, document, and AI workflow data.
- HTTPS is required for production application traffic.
- Encryption at rest is used where supported by our hosting, database, storage, and infrastructure providers.
- Production access is limited to named team members with a business need.
- MFA is required for cloud infrastructure, source control, database, payment, email, and administrative tools where available.
- Secrets are stored in managed environment-variable systems and are not intentionally committed to source control.
- Backups are maintained through database and infrastructure provider backup capabilities.
- Application, infrastructure, and security-relevant events are logged for operational troubleshooting and abuse investigation.
- Dependencies and platform components are reviewed and patched as part of normal engineering maintenance.
- Customer data deletion and export requests are handled through documented operational processes.
- Customer workspaces, boards, documents, and related records are separated by customer/user access controls in the application and database layer.
Incident Response
Security reports can be sent to hello@enterall.co. Enterall follows a lightweight incident response process:
- Receive and triage reports through the security contact or internal monitoring.
- Assess scope, affected systems, affected data categories, and whether personal data may be involved.
- Contain the incident, preserve relevant logs, and assign an internal owner.
- Maintain an internal breach log with facts, timestamps, decisions, and remediation actions.
- Notify affected customers without undue delay when a confirmed incident materially affects their data or service.
- Support controller obligations under GDPR, including information needed for supervisory authority notifications that may be required within 72 hours.
- Complete remediation and a post-incident review.
Data Map and ROPA-Lite
Enterall keeps an internal data map covering the practical substance enterprise buyers normally ask for: data categories, processing purposes, systems used, subprocessors, storage locations, access groups, retention periods, deletion workflows, and international transfer locations. A full formal record of processing activities may not be mandatory for every small company, but this operational record is maintained so customer due diligence can be answered consistently.
Retention and Deletion Policy
Account data
Retained while the account is active and for a reasonable period afterward where needed for security, legal, billing, or dispute purposes.
Workspace, board, and document content
Retained until deleted by the customer, removed through account/workspace deletion, or deleted following contract termination.
Uploaded and generated files
Retained while associated product content remains active, then deleted or made inaccessible through the relevant deletion workflow.
Application logs
Retained for a limited operational period for security, debugging, abuse prevention, and reliability.
Backups
Retained according to provider backup cycles and expire automatically through backup rotation.
Support and commercial records
Retained as needed to manage requests, contracts, legal obligations, and business records.
At contract termination, customer data is returned, exported, deleted, or made inaccessible according to the signed agreement and operational feasibility. Backup copies expire through normal backup rotation unless earlier deletion is technically feasible.
Security Questionnaire Pack
For procurement and vendor review, Enterall can provide or prepare the following materials:
- Security overview and technical and organisational measures
- Privacy policy and subprocessor list
- Architecture and data-flow summary
- Incident response summary
- Retention and deletion policy
- Insurance certificate, if maintained and requested
Commercial Contract Basics
Enterprise purchases are expected to be governed by an order form, SaaS terms, MSA, DPA, or equivalent written agreement. The commercial terms should cover confidentiality, customer data ownership, permitted processing, support, availability expectations, warranties and disclaimers, liability limits, termination, data return or deletion, governing law, and any customer-specific security or procurement terms.
Contract and procurement questions can be sent to hello@enterall.co.