whats-best.ai
Search Sign in

Data Protection · head-to-head

caralegal vs preeco | datenschutz

caralegal

EU-Made

Panel rating

Sovereignty: not determined

Full evaluation →

preeco | datenschutz

EU-Made

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The IT Integrator

Has to feed the compliance platform from the estate that already exists: Entra ID, Jira, the CMDB. Optimizes for directory import, a real API, webhooks and SSO — compliance data that stays current because it syncs, not because someone retypes it. Rejects data islands with a CSV drawbridge.

caralegal

preeco | datenschutz

This judge's pick

Criterion by criterion

Records & DPIA depth

caralegal

The legal artifacts are genuinely connected: processing activities synchronize automatically with DPIAs, TOMs and service providers, the DPIA threshold analysis derives from risky activities, and outputs from processor agreements to the RoPA go to the authority at a click. With more than 200 activity templates, records for both controller and processor roles, and legally reviewed templates, this is a real data model rather than linked folders. I found no public information on multi-client or mandate capability for consultancies, which keeps it a step below the strongest showing.

preeco | datenschutz

The data model is genuinely connected: every processing activity carries its systems, TOMs and data processing agreements in a graphical relationship view, the record itself feeds the Art. 35 necessity assessment, and deletion classes derive rules from linked activities — with multi-mandate operation, strict tenant separation and cross-client inheritance documented in depth. It stays below the top for me because missing DPA-to-record connections are established by hand and by name matching rather than flowing from one model.

Data subject rights & incidents

caralegal

Requests land in the system with automatic deadline tracking, automatic data-location lookup and a secure data room for responses, the breach register runs a guided decision process, and the deletion concept is generated straight from the record of processing. The harder automation is not visible: no public information on intake portals or forms, identity verification, a 72-hour authority notification output for breaches, or evidence that deletion actually executes rather than being documented.

preeco | datenschutz

Requests and incidents run as operations: embeddable web forms for intake, documented identity verification with rejection reasons, automatic deadline monitoring with proactive warnings, and nine ready report templates covering Art. 33 initial, follow-up and final notifications plus BSI reports with an unambiguous deadline status each. Deletion classes link to processing activities with deadlines, procedures and responsibilities; I found no public information on tracked evidence that a deletion actually executed.

Privacy regime coverage

caralegal

The German core is deep: the Standard-Datenschutzmodell 3.1 with all seven guarantee goals and continuously updated modules is built in, and AI Act and ISO duties arrive as audit templates plus an AI Flow that sits on the same documentation as the Privacy Flow. Beyond that market I found no public information on Swiss nDSG, UK GDPR or ePrivacy, and no per-country variants or a documented update cadence when regimes move.

preeco | datenschutz

GDPR is the backbone with real German depth — the BayLDA questionnaire at a button push and BSIG reporting templates — and EU AI Act risk checks run in the same system as the GDPR record. Beyond that the picture thins: I found no public information on Swiss or UK regime mapping, so additions read as content packs rather than one record across regimes.

Audit readiness & evidence

caralegal

Output is the strong half: one-click authority submissions from processor agreements to the RoPA, audit templates for ISO, DSGVO and the AI Act, and questionnaire templates for gap analyses, with PDF and Excel export of the register. The defensible trail is unevidenced — no public information on revision-safe change history, auditor access roles or evidence packs, so the state of a record at a past date stays unproven from the captured pages.

preeco | datenschutz

Every approval freezes an immutable revision with a SHA-256 checksum and colour-coded comparison — a defensible fixed state for any past date — and status reports, procedure files and the BayLDA questionnaire generate at a button push, backed by a dedicated audit module whose permissions separate answering from managing. Schedulable recurring reports and a permission-aware dashboard with compliance metrics round it out; I found no public information on auditor-scoped evidence packs bundled into a single export.

Integrations & automation

caralegal

This is where it loses me: the only estate-facing evidence is a one-time automatic migration of existing documentation and PDF/Excel export — a drawbridge, not a bridge. I found no public information on a REST API, directory import, SSO, SCIM, webhooks or ticketing connectors; the AI assistant and agents automate internal workflow steps, not synchronization with the systems I already run.

preeco | datenschutz

This is the make-or-break lens for me: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints developed only for Private Cloud and On-Premises, and data exchange via DOCX/XLSX import — a file drawbridge, not a sync. The token-authenticated MCP server genuinely lets external assistants query processing activities and export revisions under application access rights, and SAML2 single sign-on exists but is gated to the private hosting variants; I found no public information on directory import, webhooks or ticketing connectors.

European sovereignty

caralegal

The entity side is solid: a Berlin-based German GmbH with a published imprint, and a privacy policy naming website subprocessors with locations and Article 28 contracts — including a US one (Supademo Inc. in Delaware, hosted on AWS) and US transfers to Google LLC and Microsoft Corporation under the Data Privacy Framework. For the compliance record itself I found no public information on hosting location, named data centers or the platform's own subprocessor chain, which is the part that matters most for a system holding your register.

preeco | datenschutz

A German entity in Ulm hosts exclusively in named Hetzner datacenters in Nürnberg and Falkenstein with no third-country transfers stated, publishes its order-processing contract with downloadable TOMs and two weeks' notice on subprocessor changes, and the named hosting subprocessors (Hetzner, and UpCloud in Finland) all sit inside the EU. On-premises exists but is positioned for public sector and enterprise, and I found no public information on the ownership structure, so the cleanest end of the scale stays out of reach.

Pricing transparency

caralegal

One real number: Essential from 79€ per month with one legal entity, and the legal-entity ladder per plan is published alongside unlimited users and documents, a 50% nonprofit discount and a free trial after a demo. The middle tiers carry no captured prices, Enterprise is on request, and the single figure is a stated starting price — so the real invoice for anything beyond the smallest setup remains a sales conversation.

preeco | datenschutz

No price figures appear anywhere on the captured pages — the licence basis is described as employees, modules and hosting variant (explicitly not the number of organisations) and the no-setup-fees, no-cancellation-terms posture is stated, but the actual invoice is only a sales conversation. Optional paid items such as the ISMS audit catalogs, DeepL translation, premium support and migration are named without figures.

Sovereignty, side by side

Dimension caralegal preeco | datenschutz
Legal entity Not determined Incorporated in DE
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors Not determined Not determined

Facts, side by side

Only facts both products carry under the same definition — anything else would not be a fair row.

Data · Retention contact form contact form data · deleted automatically after request fully processed1

captured 5 Oct 2026 · Report an error

6 · contact form inquiries2

captured 5 Oct 2026 · Report an error

Legal · Company caralegal GmbH3

captured 5 Oct 2026 · Report an error

preeco GmbH · 20264

captured 5 Oct 2026 · Report an error

Legal · Entity caralegal GmbH5

captured 5 Oct 2026 · Report an error

preeco GmbH6

captured 5 Oct 2026 · Report an error

Legal · Entity name caralegal GmbH · 20267

captured 5 Oct 2026 · Report an error

preeco GmbH8

captured 5 Oct 2026 · Report an error

Legal · VAT id DE3312114409

captured 5 Oct 2026 · Report an error

DE31956057610

captured 5 Oct 2026 · Report an error

Product · Data subject requests Data subject request handling with data location lookup, deadlines and secure response data room5

captured 5 Oct 2026 · Report an error

Art. 15-22 · yes11

captured 5 Oct 2026 · Report an error

Product · Dpia DPIA with automated threshold analysis, linked to risky processing activities3

captured 5 Oct 2026 · Report an error

yes11

captured 5 Oct 2026 · Report an error

Product · Records of processing yes5

captured 5 Oct 2026 · Report an error

Art. 30 · yes · yes12

captured 5 Oct 2026 · Report an error

Product · Trainings yes5

captured 5 Oct 2026 · Report an error

yes · yes · yes13

captured 5 Oct 2026 · Report an error

Support · Response time Response within 24 hours (on demo request form)14

captured 15 Sep 2026 · Report an error

within a few hours15

captured 5 Oct 2026 · Report an error