whats-best.ai

Contract Management (CLM)

ContractHero

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by ContractHero GmbH · www.contracthero.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Reads the subprocessor list before the feature page. Asks which model provider receives contract text, whether it is retained or used for training, where OCR runs, and whether the counterparties' personal data in every contract is covered by the DPA.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Drafting, templates & clause library

How this is scored

Creating a contract without starting from an old one: templates with variables and conditional clauses, an approved clause library, self-service generation for business teams, and support for German-language and German-law templates.

0 — No drafting at all; contracts are uploaded as finished files.

3 — Templates with simple placeholders, but no conditional logic, no clause library, and every draft still edited by hand by legal.

5 — Templates with variables and conditional clauses, a clause library with approved fallbacks, a questionnaire or form that lets business users generate standard contracts, and German-language templates supported.

8 — Template and clause versioning with an owner per clause, multilingual templates from one source, generation from CRM or procurement records, playbook rules that flag deviations from approved wording, and template use reported.

10 — Drafting is governed end to end: every clause traceable to its approved version and owner, deviations from the playbook visible on every draft, bilingual German–English contracts generated side by side, and templates exportable in an open format.

Report an error

The Data Protection Officer

Templates appear as downloadable model documents (an NDA and a shareholder resolution, both German) and contract creation via Word Add-in or templates in the Professional tier, with the vendor itself noting a model contract is a tool, not a finished result. We found no public information on template variables, conditional clauses, an approved clause library with fallbacks, or playbook rules that flag deviations. 2 6 7

Report an error

Negotiation, redlining & approval

How this is scored

Getting from draft to agreed text with a counterparty and through internal sign-off: redlining in Word and in the browser, external collaboration, version comparison, approval workflows, and a record of who approved which version.

0 — No negotiation support; versions are emailed back and forth outside the system.

3 — Comments and a version list inside the system, but no redline comparison, no Word round-trip, and approvals handled by email.

5 — Redlining with tracked changes, a Word add-in or round-trip that keeps changes, counterparty access without a licence, version comparison, and configurable approval steps by contract type or value.

8 — Conditional approval routing (value, deviation from playbook, risk), parallel and sequential approvers with delegation, an audit trail of every change and approval per version, and internal comments kept separate from what the counterparty sees.

10 — Negotiation is an auditable record: every concession traceable to who proposed and who approved it, approval rules an auditor or the board can read, negotiation duration reported per contract type, and the full history exportable with the signed version.

Report an error

The Data Protection Officer

Internal sign-off is genuinely strong: rule conditions include contract value with comparison operators, multi-stage ordered approval groups where any member can complete a step, immediate stop on rejection, and every approval and rejection recorded with timestamp, person and, for deletions, a mandatory reason visible in the change log. Approvers must be internal members, and we found no public information on redlining, version comparison or counterparty access to negotiate a draft. 8 9 2

Report an error

Repository, deadlines & obligations

How this is scored

Knowing what has been signed and what it requires: a searchable repository with metadata, notice periods and renewal dates captured and reminded, obligations tracked to an owner, access rights by department, and reporting on the portfolio.

0 — A file store with folders; no metadata, no dates and no reminders.

3 — Metadata fields and an end date with an email reminder, but notice periods and auto-renewal are not modelled and reminders go to one person.

5 — Notice periods, renewal terms and end dates modelled as fields, reminders with escalation to named owners, full-text search including scanned contracts (OCR), and access rights per department or contract type.

8 — Obligations and milestones tracked with owners and status, contract hierarchies (framework, amendments, orders) linked, reminders logged so a missed deadline can be traced, and portfolio reports on renewals, value and counterparties.

10 — The repository is a system of record a company can be audited on: every deadline derived from a cited clause, reminders and their acknowledgements logged, retention and deletion rules per contract type, and a portfolio view a CFO can use for commitments and cancellations.

Report an error

The Data Protection Officer

Notice periods, end dates and deadline/renewal management are modelled and consolidated in a calendar with month, week, day and agenda views, and full-text search covers scanned contracts via OCR while respecting role and team permissions. We found no public information on reminders escalating to named owners, obligations and milestones tracked with owner and status, or logged reminder acknowledgements, and the reporting module is named without portfolio detail. 11 10 2 1

Report an error

AI extraction & review transparency

How this is scored

Whether the AI that extracts dates and clauses or reviews a draft is disclosed, verifiable and controllable: named model provider and processing location, no training on customer contracts, extracted values shown with their source passage, and features the customer can switch off. A product without AI features is judged on stating so.

0 — AI extraction or review is marketed with no statement of the model, where it runs, or what happens to the contract text.

3 — AI features described as a benefit with a general privacy assurance, but no model provider named, no statement on training, and extracted values shown without their source.

5 — The model provider or subprocessor named, a stated commitment not to train on customer contracts, extracted values linked to the source passage for confirmation, and AI features that can be disabled per account.

8 — AI processing available within the EU, each AI feature documented with its purpose and inputs, accuracy or confidence shown per extracted field, review results traceable to the playbook rule that triggered them, and an EU AI Act position published.

10 — AI is an accountable assistant: customer choice of model or EU-only processing, no retention of contract text by the model provider stated contractually, every AI-suggested value logged with who confirmed or corrected it, and AI off by default until the customer enables it.

Report an error

The Data Protection Officer

Extracted values carry a jump-to-source reference that can be verified field by field, the pipeline (OCR, layout recognition, chunking, prompt, instruction) is publicly documented, and a test-before-activate button plus re-runs that never overwrite existing values give the customer real control over accuracy. We found no public information on which model provider receives the contract text, whether that text is retained or used for training, where AI and OCR processing run, any per-account way to switch AI off, or an AI Act position beyond the term appearing — and the published privacy policy covers only the website, so the counterparties' data in every contract is not visibly covered by a product DPA. 12 13 3

Report an error

Integrations, signature & exit

How this is scored

How contracts connect to the rest of the company and leave it again: CRM, procurement and ERP integration, e-signature (and which eIDAS level), SSO, an API, and a documented export of documents together with their metadata, versions and audit trail.

0 — No integrations, no API and no stated export; contracts can only be downloaded one by one.

3 — One CRM or storage integration and a bulk download of files, but metadata, versions and audit trail stay behind.

5 — A documented API, integrations with named CRM and storage systems, e-signature integrated with the level stated (simple, advanced or qualified), SSO, and a bulk export of documents with their metadata.

8 — Maintained integrations with systems common in DACH (SAP, Microsoft 365, Salesforce, DATEV-connected or procurement tools), qualified electronic signature available, webhooks, SCIM, and an export that includes versions, approvals and audit trail in an open format.

10 — Exit is designed in: a versioned API with a deprecation policy, a documented migration path in and out with the format stated, deletion after contract end confirmed, and the full repository — files, metadata, obligations and history — handed back without a professional-services fee.

Report an error

The Data Protection Officer

A REST API with webhooks, named integrations including SAP, MS Dynamics, Salesforce, HubSpot, SharePoint, PowerBI and DocuSign, SSO with MFA at Enterprise, digital signatures labelled FES, and a contractual promise to provide all customer data for download in a readable, editable format on termination give a credible connect-and-leave story. Exports deliver contract metadata as an xlsx table with the original PDFs only via a separate bulk download, and we found no public information on a qualified signature option, SCIM, or an export that includes versions, approvals and audit trail in an open format. 14 2 15 5

Report an error

European sovereignty

How this is scored

Who the contracting entity is, where contracts and their extracted data are hosted, and who the subprocessors are — including the AI and OCR providers the text is passed to. Independently sourced by the sovereignty pipeline; weighted with care here because a contract repository holds a company's most confidential commitments and those of its counterparties.

0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and AI processing of unclear location.

3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent, or AI and OCR processing run outside the EU without saying so.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — AI models, OCR, email delivery, support — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, subprocessor list published including AI and OCR providers with locations, and a DPA covering contract data as the customer's processing.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, AI processing within the EU on providers the customer can see, certifications (ISO 27001, BSI C5 or equivalent) published.

Report an error

The Data Protection Officer

The contracting entity is ContractHero GmbH in Halle (Saale) with a register entry, and German hosting is claimed as standard on marketing and pricing pages; the terms, however, place the software on servers of ContractHero or a commissioned service provider without naming it. The only subprocessor list we found covers website services (several US providers such as Webflow, AWS CloudFront, Google Analytics), and we found no public information naming the hosting, AI model or OCR providers for the product, or on a DPA covering contract data — a material gap for a repository holding a company's and its counterparties' most confidential commitments. 4 1 7 3 5

Report an error

Pricing transparency

How this is scored

Whether a buyer can compute the real annual cost from public pages alone: the pricing basis (per user, per contract, per module), which features sit in which tier, add-ons for AI, e-signature volume or integrations, onboarding and migration fees, and the minimum term.

0 — No public prices at all; every tier is a sales conversation.

3 — A starting price exists, but the pricing basis (users, contracts, modules) or which features sit in which tier is unstated — the invoice is unknowable.

5 — Tier prices public with the pricing basis and main limits given, but at least one commonly needed piece (AI features, signature volume, integrations, extra users or onboarding) is unpriced.

8 — Every tier priced publicly with its basis and limits, add-on prices listed, onboarding and migration costs stated, minimum term and VAT treatment given.

10 — Complete price computability: annual invoice derivable for a given number of users, contracts and signatures, with every add-on, overage and implementation fee published.

Report an error

The Data Protection Officer

All prices are given only "auf Anfrage": the tiers, their user and contract limits (500/5, unlimited/15, unlimited/50) and which features sit in each are published, and the terms disclose the basis (base fee plus one-time onboarding, add-ons for users, companies and modules) along with auto-renewal and price-change rules. No figures for the base fee, onboarding, add-ons or overages appear anywhere, so a buyer cannot compute the annual invoice from public pages. 2 5

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency EU only ⚠ unverified 3/3 pts 2 Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (15)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.contracthero.com Checked 1 Oct 2026 Details →
  2. 2 Pricing page www.contracthero.com Checked 1 Oct 2026 Details →
  3. 3 Privacy policy www.contracthero.com Checked 1 Oct 2026 Details →
  4. 4 Legal notice www.contracthero.com Checked 1 Oct 2026 Details →
  5. 5 Terms of service www.contracthero.com Checked 1 Oct 2026 Details →
  6. 6 Drafting, templates & clause library — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
  7. 7 Drafting, templates & clause library — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
  8. 8 Negotiation, redlining & approval — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  9. 9 Negotiation, redlining & approval — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  10. 10 Repository, deadlines & obligations — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  11. 11 Repository, deadlines & obligations — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  12. 12 AI extraction & review transparency — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  13. 13 AI extraction & review transparency — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
  14. 14 Integrations, signature & exit — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
  15. 15 Integrations, signature & exit — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →