Hacker News new | ask | show | jobs
by brendoelfrendo 1659 days ago
Companies with data retention requirements might be legally obligated to keep those DMs, and I don’t see how Quill would be unaware of that. Either they’re confident that none of their clients have such a need or they decided that it would be too hard to export DMs with 4 days notice and said “meh.”
1 comments

If they are legally required for data retention why did they use this product in the first place?
Here are a few possible explanations based on my experience at various employers.

1. Departments/divisions have their own budgets; Quill was purchased before security or compliance was involved.

2. Quill was deployed or piloted for a group without retention requirements then escaped into the wild. Security or compliance wasn't involved until it was in use company wide.

3. A client required using Quill so the usual compliance requirements were waived.