The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Lead Auditor
Audits management systems for a living and has seen every folder of screenshots. Optimizes for revision-safe history, evidence packs on demand, and a defensible answer to "show me the state on date X". Rejects systems where the audit trail is assembled the week before the audit.
caralegal
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
caralegal
The captured pages show a connected model: processing records synchronize automatically with impact assessments, technical measures and vendors, the DPIA threshold analysis is derived from the record, and legal bases under Art. 6 and 9 sit in legally reviewed templates alongside SDM-linked technical measures. A one-click package to the authority spanning processor agreements through records suggests authority-usable outputs. We found no public information on reusable group templates or multi-client mandate handling; entity counts per plan are the only group signal.
preeco | datenschutz
Processing activities carry every Art. 30 field and are linked graphically to systems, technical and organizational measures and Art. 28 contracts, with recipient-to-contract coverage created by automatic name matching and gaps surfacing as marked rows. Impact assessments, including transfer assessments for third-country cases, run off the same record with a necessity pre-check, measures are versioned and linked, and mandate capability with cross-client inheritance is built in rather than copy-paste. We found no public information on a coverage view showing measures complete across every record, which is what would close the loop.
Data subject rights & incidents
caralegal
Requests arrive as cases with owner, status and ID, deadlines and data locations are determined automatically, responses go out through a protected data room, and the deletion concept is generated from the record itself; incidents are documented centrally with a guided decision process. We found no public information on intake portals or forms, identity checks, deadline escalation, a 72-hour clock, or evidence that a deletion actually executed.
preeco | datenschutz
Requests come in through embeddable web forms, identity verification and rejection grounds are documented fields, replies go out as one-time encrypted links, and every request type under Art. 15–22 runs under automatic deadline monitoring with proactive warnings; breaches carry severity classification, a risk matrix, 72-hour monitoring and nine ready notification templates for Art. 33, Art. 34 and the German BSI with an unambiguous deadline status per report. Requests and incidents link to the affected processing activities, and deletion rules with deadlines, procedures and responsibilities derive from deletion classes tied to the register. We found no public information on escalation chains for missed deadlines or on evidence that a deletion was actually executed.
Privacy regime coverage
caralegal
GDPR depth is real, the German Standard Data Protection Model 3.1 is built in with always-updated building blocks and seven guarantee goals, and AI Act duties run as an AI Flow that builds on the same documentation as the privacy module — one record serving two regimes. We found no public information on Swiss, UK or other national privacy regimes.
preeco | datenschutz
The GDPR stack is deep and German in flavor — the register, breaches under Art. 33/34 alongside German BSI reporting duties, Art. 35 assessments including Schrems II transfer analysis, and the Bavarian supervisory authority's questionnaire at the push of a button — with EU AI Act risk classification running in the same system and roughly monthly updates as the visible maintenance cadence. One record therefore serves two regimes for the home market. We found no public information on Swiss, UK or ePrivacy regime support.
Audit readiness & evidence
caralegal
Evidenced: register exports in PDF and Excel, a one-click package to the authority spanning processor agreements through records, audit templates for ISO, GDPR and the AI Act, gap-analysis questionnaires and PDCA planning. We found no public information on revision-safe change history, evidence attachments per activity, or auditor access roles; how a record looked on a given date is the question nothing captured answers.
preeco | datenschutz
Every approval freezes an immutable revision with SHA-256 checksums and color-coded comparison, described as a fixed documentation state at any point in time, and an automatic log records document changes and account administration with timestamp, user and action. Authority and management output is push-button — status reports, procedure files per activity, the Bavarian questionnaire, scheduled cross-tenant DPO reports — and the audits module separates answering from managing. We found no public information on evidence attachments collected per activity or exportable proof bundles, so assembling a full file still looks partly manual.
Integrations & automation
caralegal
Shown: automatic migration of existing documentation into the platform, a live website cookie check by URL, approval workflows with follow-up reminders, and an AI assistant with agents taking over recurring steps. We found no public information on a documented API, directory import, ticketing connectors, SSO or webhooks, so the automation on show is guided workflow and reminders rather than the platform feeding from the live estate.
preeco | datenschutz
The vendor's own pages describe a closed system with no public REST API — custom endpoints are developed only for Private Cloud and On-Premises — and standard-tier data exchange is DOCX/XLSX import against PDF/DOCX/XLSX export, with legacy migrations run as individual projects. Above a pure file island sit an MCP server letting external AI assistants query processing activities and export revisions under application access rights, embeddable intake forms, DeepL translation, and SAML2 single sign-on restricted to the upper hosting variants. We found no public information on directory import, ticketing or HR connectors, webhooks, or user provisioning sync.
European sovereignty
caralegal
The imprint establishes a GmbH seated in Berlin with a German VAT ID and named managing directors, which settles the entity question cleanly. Beyond that we found no public information on where the platform itself is hosted, on a customer data processing agreement, or on a platform subprocessor list; the captured privacy policy documents the website chain only, which includes a US provider in Delaware with AWS hosting and Google LLC and Microsoft Corporation transfers under the Data Privacy Framework. For the system that would hold a customer's register of processing, that silence is not a small thing.
preeco | datenschutz
A German company in Ulm hosts Cloud and Private Cloud exclusively in named Hetzner data centers in Nürnberg and Falkenstein, offers on-premises, publishes its Art. 28 contract with two-week subprocessor change notice and downloadable technical and organizational measures, and states no third-country transfer of product data; AI features are off by default and run on customer-held keys. The privacy notice additionally names UpCloud Oy of Finland as a hosting subprocessor, so the captured pages give different pictures of where hosting occurs, though both named providers sit inside the EU. Ownership structure is not publicly documented, which is what keeps this short of the cleanest band.
Pricing transparency
caralegal
The Essential tier carries a public starting price quoted as ab 79€ pro Monat, with one legal entity, unlimited users and unlimited documents stated. The captured pricing page gives entity counts for Professional, Corporate and Enterprise but shows a figure only for Essential, with Enterprise priced auf Anfrage, so the real invoice for a multi-entity group is not computable from public pages; we found no public information on setup fees or how software and services are separated.
preeco | datenschutz
Not one price figure appears on the captured pages: the license is described as scaling with employees, modules and hosting variant, with no setup fees and no cancellation periods, but the real invoice is not computable without a sales conversation. One page promises all GDPR obligations without add-on modules or hidden surcharges, while other captures list optional paid items such as audit catalogs, DeepL translation, premium support and migration projects. We found no public information on entry pricing, per-module figures or scale steps.
Sovereignty, side by side
Dimension
caralegal
preeco | datenschutz
Legal entity
Not determined
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.
Data · Retention contact form
contact form data · deleted automatically after request fully processed1