Customer Service & Helpdesk
OTRS
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by OTRS AG · otrs.com
Compare with Zammad → Compare with Znuny → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
The bench judged OTRS almost entirely from legal pages: three homepage captures plus the imprint and privacy policy, with no product capability evidenced anywhere. Its strength is the vendor's legal posture — sovereignty scores span 3-4, built on a German contracting entity (OTRS GmbH, Oberursel, Amtsgericht Frankfurt am Main HRB 143059, VAT DE453344897), a named external DPO and stated retention periods — though hosting for customer instances is stated nowhere — while customer data protection spreads 2-4 on how much credit to give practices that govern OTRS's own website rather than a customer's ticket archive. The weaknesses are broad: integrations sits at 0 with no API, webhooks, SSO or named connector in any capture; ticketing, queues & SLA ranges 0-2 with no queue, routing, SLA or search shown; omnichannel and knowledge base & deflection top out at 1, resting on the 'Customer Service & Helpdesk' label and the vendor's own FAQ page. flagged splits flagged none above threshold; the protection spread is a credit question, not a factual dispute. Pricing is unpublished and not counted.
Speaks for it
- Contracting entity is German and register-listed: OTRS GmbH, Oberursel, Amtsgericht Frankfurt am Main, HRB 143059, VAT DE453344897.
- Named external DPO (Robert Aumiller, IITR GmbH) with a published privacy statement, GDPR page and Trust Center.
- Retention periods stated per category: application data 6 months, business cards 5 years, email archive 10 years.
- Third-country transfers disclosed with SCCs for the US video-conference processor, and video recording only with documented consent.
Held against it
- No ticketing feature evidenced in any capture — no queue, routing rule, SLA timer or search (ticketing, queues & SLA 0-2).
- Integrations at 0: no API, webhooks, SSO or named CRM/shop connector anywhere on captured pages.
- No product channel or help-centre facts — the only FAQ mention is on OTRS's own website (omnichannel max 1, knowledge base & deflection max 1).
- Every captured GDPR fact governs the vendor's own website, not a customer's ticket archive — no agent roles, audit log, redaction or executable deletion evidenced.
- Hosting and data residency for customer instances stated nowhere, and the published subprocessor list is the marketing site's trackers (Google, LinkedIn, Vimeo, 6sense).
Best for
- You need a German-registered contracting entity (OTRS GmbH, Amtsgericht Frankfurt am Main HRB 143059) to pass a jurisdiction filter and can verify product capability in a sales conversation.
- Your procurement requires published GDPR documentation — named DPO, privacy statement, Trust Center — before any technical evaluation.
- You are doing an early longlist pass where vendor legal posture is the screening criterion.
Avoid if
- You need API, webhooks or CRM/shop integrations wired in — the captures evidence none, and context would be copied in by hand.
- You need channels beyond the helpdesk label or a searchable customer-facing help centre with deflection reporting.
- You must document product-side controls — agent roles, ticket audit, requester deletion — before signing.
- You need to know where your ticket archive is hosted before contracting; the evidence states no residency.
The scores
Ticketing, queues & SLA
Show reasoningHide reasoning
How this is scored
The engine: how work is routed, prioritised, escalated and measured — and whether an agent can find the ticket they need among ten thousand.
0 — A shared mailbox with labels; no ownership, no status model, no history beyond the thread.
3 — Tickets with assignment and open/closed status, but routing is manual, there are no SLA timers and search covers subject lines only.
5 — Queues with rules-based routing, priorities, a working status model, SLA timers with breach warnings, and full-text search across ticket bodies.
8 — Business-hours-aware SLA policies per queue or customer, escalation chains, macros and triggers, merge and split, and reporting on first-response and resolution time by agent and queue.
10 — The workload is managed rather than merely tracked: capacity-aware assignment, SLA per contract with reporting an account manager could show a customer, audit of every status change, and search that finds the ticket from a half-remembered phrase.
The Support Lead
Three homepage captures and the legal pages don't evidence a single ticketing capability — no routing, no SLA timers, no escalation chains, no search, not even a status model. All I have is the 'Customer Service & Helpdesk' category label and a 'service management suite' descriptor, which gets it off the absolute floor but tells me nothing I could put in front of my team on a Monday. 1
The Agent Advocate
The evidence proves the category label — 'Customer Service & Helpdesk' on the homepage — and nothing else: no queue, no routing rule, no SLA timer, no macro, not a word on whether search reaches ticket bodies. I judge by the hundredth reply, and I can't put a routing model in front of a team that this sheet doesn't show. One point for the label, and that's charity. 1 1
The Data Protection Officer
Not one fact about routing, queues, SLA timers, escalation or search appears in any capture; a 'Customer Service & Helpdesk' category label and a homepage are all I have, and a label is not an engine. Absence this total sits at the bottom of the scale, with a single point only for the category claim. 1 1
The Shop Operator
Nothing in the captured pages evidences a queue, a status model, an SLA timer, routing rules or ticket search — I cannot even confirm a ticket exists in this product from this sheet. For a shop at ten-thousand-ticket volume, an engine the evidence is silent on is an engine I must treat as absent. 1 3 2
The Integrator
The category label says Customer Service & Helpdesk, so a ticket engine presumably exists, but three homepage captures never mention a queue, a routing rule, an SLA timer or search — not one engine feature is evidenced, so I can't go past 'the engine exists'. 1 1 1
The Skeptic
Three captures of the homepage produced no queues, no SLA timers, no routing, no search — the entire registry is legal notices and the vendor's own privacy policy, so the engine is unevidenced end to end. rubric level 0 is where absence of any ownership/status/history model sits, and I can't even confirm a shared mailbox. 1 1
Channels in one queue
Show reasoningHide reasoning
How this is scored
Email, chat, phone, portal, messengers and social — judged on what actually lands in the same queue with the same history, not on how many channel logos the marketing page carries.
0 — Email only.
3 — Email plus one more channel, but the second lives in its own inbox: no shared history, and a customer who switches channel starts again.
5 — Email, a web form or portal and live chat all landing as tickets in one queue, with the customer's history visible whichever channel they used.
8 — The above plus telephony integration with call logging, at least one messenger (WhatsApp, Signal or similar) with its consent handling stated, and a customer portal where a requester can see their own tickets.
10 — Channel is an implementation detail: every channel including voice and messengers writes to one conversation with one history, agents answer from one screen, and the customer can move between channels mid-issue without repeating themselves.
The Support Lead
Nothing in the evidence evidences any channel at all — not email handling, not a portal, not a single messenger — let alone channels landing in one queue with one history. rubric level 0 says email only; the evidence gives me less than that to work with, so this is the floor. 1
The Agent Advocate
The word 'helpdesk' is the only reason to believe email lands anywhere; no chat, phone, portal, messenger or social channel appears in any of the six captured pages. I can't even confirm one shared queue, let alone a customer switching channels mid-issue without starting over. 1 1
The Data Protection Officer
No chat, portal, phone, or messenger integration is evidenced anywhere in the evidence, so there is nothing to credit beyond the helpdesk category's implied email handling — which is the anchor-zero position. The marketing site's own channels (forums, video, X buttons) are about OTRS, not the product's queue. 1
The Shop Operator
No email, chat, phone, portal, WhatsApp or social channel lands anywhere in this evidence; the only channel-adjacent fact is a video-conference tool OTRS itself uses, hosted with a US processor. One queue with one history, an order surface inside the ticket, a customer moving mid-issue — none of it is evidenced. 1 2
The Integrator
Not one channel fact in the evidence — even email-to-ticket is unconfirmed, and the only channel-adjacent quotes (web forms, video conferencing via a US provider) describe OTRS's own website, not the product's queue. 1 2
Knowledge base & deflection
Show reasoningHide reasoning
How this is scored
Whether the product reduces the number of tickets as well as organising them: public help centre, article workflow, suggestions to agents and to customers.
0 — No knowledge base; answers live in agents' heads and old tickets.
3 — A basic article list, public or internal, with no editorial workflow, no versioning and no link between articles and tickets.
5 — A searchable public help centre with categories, draft and publish states, and agents able to insert an article into a reply.
8 — Article suggestions to the customer before they submit and to the agent while they answer, multilingual articles, review dates that flag stale content, and reporting on which articles deflect.
10 — Knowledge is a managed asset: gaps identified from unanswered tickets, article performance measured against ticket volume by topic, versioned content with approval, and deflection reported as a number the team can act on.
The Support Lead
The only knowledge-base-adjacent fact anywhere is that OTRS's own website has FAQs — that's their marketing site, not a product help centre, article workflow, or deflection reporting. There is no evidence the product reduces ticket volume at all. 2 1
The Agent Advocate
The only knowledge content anywhere is 'viewing FAQs' on OTRS's own website — that's their marketing, not a help centre my customers could search. No article workflow, no agent suggestions, no deflection reporting: as this sheet shows it, answers live in agents' heads and old tickets, which is the definition of the floor. 1 2
The Data Protection Officer
The only knowledge-adjacent fact is that OTRS's own website shows FAQs to registered visitors — a vendor article list, not a product help centre, editorial workflow, or deflection reporting. Nothing here evidences the product organising or reducing ticket volume. 2
The Shop Operator
The lone FAQ mention is about viewing FAQs on OTRS's own website during free-trial registration, not a public help centre with workflow or deflection reporting in the product. No article states, no suggestions, no deflection number my December ticket count would respond to — silence is the information here. 2
The Integrator
The single KB-shaped fact is that OTRS's own website has FAQs you can view after registering; nothing on article workflow, agent suggestions, review dates or deflection reporting for the product, so knowledge as a managed asset is entirely unevidenced. 2
Customer data protection
Show reasoningHide reasoning
How this is scored
A ticket archive is personal data written by the data subject. Retention, deletion, access control, subject rights, and what the vendor does with attachments — judged on what executes rather than what is promised.
0 — No retention policy stated, no deletion path, agents all see everything, and no DPA is published.
3 — A DPA on request and coarse roles; deletion is described as something the customer arranges, and there is no stated retention period.
5 — A signable DPA published, configurable agent roles and queue-level visibility, a stated retention period, and deletion of a requester's data that can actually be executed.
8 — Automatic retention rules per queue or data category, attachment handling stated, an audit log of who opened which ticket, documented support for access and erasure requests, and pseudonymisation or redaction of ticket content.
10 — Built for a data-protection audit: retention executed and evidenced per category, field-level redaction, full audit trail, subprocessor list published, and the vendor's own support access to customer instances documented and consent-gated.
The Support Lead
Credit where due: a published privacy statement, GDPR page and Trust Center exist, a named external DPO is on record, and retention periods are actually stated (10 years general, 6 months application data) — but every one of those governs OTRS's own website and CRM, not the helpdesk product. Nothing evidences agent roles, queue-level visibility, per-queue retention rules, a ticket audit log, redaction, or an executable deletion of a requester's data inside the product, which caps this at the DPA-on-request-and-coarse-practices level. 3 2
The Agent Advocate
The GDPR practice on display is real but entirely about OTRS GmbH's own website: stated retention periods (trial data 3 years, emails 10 years for tax), a named external DPO, and a long subprocessor list with SCCs for the US ones. Nothing executes on the product side — no agent roles, no queue visibility, no ticket redaction, no audit of who opened which ticket, and no signable DPA confirmed in the Trust Center. The vendor polices its own cookies well; the ticket archive is silent. 3 2
The Data Protection Officer
The vendor polices its own house well — named external DPO (IITR), published privacy statement, Trust Center, and concrete retention per data category (6-month application data, 3-year trial, 10-year email archive) — but says not one word about the product: no queue-level retention rules that execute, no redaction, no audit of who opened which ticket, no DPA, no answer on vendor support access, and a blanket 'usually 10 years' is a hoard, not a policy. That is a compliance posture, not capability, and it sits between rubric level 0 and 3. 3 2
The Shop Operator
Retention is stated per category (6 months application data, 5 years business cards, 10 years email archive), a DPO is named and a Trust Center exists, which already beats the anchor-3 state of 'no stated retention period'. But this is the vendor's handling of its own website visitors, not the product's ticket archive: no agent roles, no queue visibility, no audit of who opened which ticket, no executable requester deletion is evidenced — so it cannot reach 5. 3 2
The Integrator
There is a published privacy statement, a named external DPO and stated retention periods — but every one of them governs OTRS's own marketing and website data, not the ticket archive; the product gets no evidenced retention rules, agent roles, audit log or executable deletion path for a requester. 3 2
The Skeptic
The vendor's own GDPR hygiene is real: a named external DPO (IITR GmbH), a published privacy statement with stated retention periods, SCCs documented for the US video-conference processor, and recording gated on documented consent. But every one of those facts governs OTRS GmbH's website — nothing evidences a signable DPA, agent roles, retention configuration or an executable deletion path for a customer's ticket archive, which pins this just above zero. 2 3
Integrations & API
Show reasoningHide reasoning
How this is scored
The systems a helpdesk has to reach — CRM, shop, order management, identity — and whether the API is documented for building or gated behind a partner conversation.
0 — No API and no named integrations; context is copied in by hand.
3 — A handful of native integrations and a read-mostly API, with no webhooks and no documented rate limits.
5 — Named integrations for common CRM and shop systems, a documented REST API with keys, webhooks for the core ticket events, and SSO.
8 — Maintained bidirectional integrations, customer context from other systems shown inside the ticket, SCIM provisioning, documented rate limits and a sandbox.
10 — A component rather than a destination: versioned API with a deprecation policy, event streaming both directions, an app framework for in-ticket extensions, and integrations the vendor maintains rather than lists.
The Support Lead
No API, no webhooks, no SSO, no named CRM or shop integration — nothing. The named Google, HubSpot and 6sense entries in are the vendor's own website marketing stack, not product integrations, and I won't count them as such. 2 1
The Agent Advocate
The only integrations named anywhere are the vendor's own marketing stack — Google Tag Manager, HubSpot, 6sense, LinkedIn pixels — which serve their ads, not my tickets. No CRM connector, no API docs, no webhooks, no SSO: as far as this sheet goes, context gets copied in by hand. 2
The Data Protection Officer
No API, webhook, SSO, rate limit, or named integration appears in any captured page; context would have to be copied in by hand, which is precisely the zero anchor. Across three homepage captures not a single system-to-system fact surfaced. 1
The Shop Operator
No API, no webhooks, no rate limits, no named CRM, shop or identity integration appears anywhere in the three homepage captures or the legal pages. The order in front of the agent without a second login has zero support in this registry — hand-copied context is the anchor-0 state. 1 1
The Integrator
No API, no webhooks, no SCIM, no sandbox, no rate limits, and not one named CRM, shop or identity connector on any captured page — there isn't even an integrations page to read a partner form off. In the world this sheet gives me, context is copied in by hand and I can wire nothing. 1 1 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the ticket archive lives, who the contracting entity is, which subprocessors touch it, and whether vendor support can read customer data. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — support tooling, analytics, AI features — are non-EU without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, EU contracting entity, full subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor in the EU, certification published, and a self-hosted or private-cloud option for buyers who need the archive on their own infrastructure.
The Support Lead
The contracting entity is genuinely German — OTRS GmbH, Amtsgericht Frankfurt HRB 143059, Oberursel address, German VAT — which rules out the bottom anchors. But hosting and data residency for a customer's ticket archive are stated nowhere, the product's own subprocessor list is absent, and the vendor's own chain runs US processors (Google Tag Manager, LinkedIn, Vimeo) with third-country transfers declared possible — where my archive lives is the first question I ask, and this sheet can't answer it. 3 2
The Agent Advocate
The imprint puts the contracting entity squarely in Germany — OTRS GmbH, Oberursel, registered at Amtsgericht Frankfurt, VAT DE-numbered — and third-country processing is at least named with SCCs. But hosting for customer instances is stated nowhere (the pipeline marks residency unknown), and the published subprocessor list is website trackers, not the product chain, so I can't tell a buyer where the ticket archive would sleep. German entity gets it above the 3 anchor; unproven hosting keeps it well short of 5. 3 2
The Data Protection Officer
The contracting entity is firmly German — OTRS GmbH, Oberursel, HRB 143059 at Amtsgericht Frankfurt, DE VAT — and the privacy policy does name subprocessors and discloses third-country transfers with SCCs for the US video-conferencing processor. But that subprocessor list is the marketing website's trackers (Google, LinkedIn, Vimeo, 6sense), the hosting location of a customer's ticket archive is nowhere stated, and whether OTRS support can open a customer instance goes unanswered — better than the pipeline's zero, short of anchor five. 3 2
The Shop Operator
But where the ticket archive is hosted is unstated, the product's subprocessor list is absent, and the vendor's own web chain runs Google, LinkedIn, Vimeo and 6sense with US transfers papered over by SCCs — that is the anchor-3 'subprocessor list absent' arm, not 5. 3 2
The Integrator
The contracting entity is solidly German — OTRS GmbH, Oberursel, HRB 143059 at Amtsgericht Frankfurt — which is real, but product hosting is unstated and the archive's own subprocessor chain is absent; the privacy policy itself concedes processors outside the EU and forum hosting partly outside the EU, and the named web-stack subprocessors include Google Inc., LinkedIn Corp and Vimeo in the US. 3 2
The Skeptic
The contracting entity is firmly German and register-listed (OTRS GmbH, HRB 143059, Amtsgericht Frankfurt, DE VAT number), which is a genuine plus the pipeline's 0 doesn't credit. But where the ticket archive is hosted and which subprocessors touch it is entirely unstated, and the policy concedes processors 'could also be used outside the European Union' — so rubric level 3's absent-subprocessor-list scenario is where this lands. 3 2
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a support lead can compute the real annual invoice for their agent count — including the channels and features they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-agent headline exists, but the tier where the needed channel or SLA feature begins is unstated, or light-agent and contact limits are not mentioned.
5 — Per-agent prices public for the main tiers with billing period stated, but at least one commonly needed capability (telephony, messengers, SLA policies) sits in an unpriced bundle.
8 — Every tier and add-on priced publicly with per-agent maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.
10 — Complete price computability: a calculator or table producing the annual invoice for a given agent count and channel selection, including usage-metered channels and overage.
The Support Lead
Three separate captures of the homepage produced not one price, tier, add-on or billing term. A support lead can't compute any invoice from this, so it's the floor. 1
The Agent Advocate
Three separate homepage captures and a full legal sweep, and not one euro figure, tier name or per-agent price appears anywhere. I can't compute an annual invoice for eight agents from what I was shown, which means every tier is a sales conversation as far as this sheet goes. 1 1 1
The Data Protection Officer
No price, tier, add-on, billing period or agent-count fact appears in any capture; a support lead could not compute even a rough invoice from this evidence, which is the bottom anchor. 1 1
The Shop Operator
Three homepage captures plus the legal and privacy pages and there is no per-agent price, no tier, no billing period, no VAT treatment — every tier is a sales conversation, which is rubric level 0 verbatim. A support lead could not compute one line of the annual invoice from these pages. 1 3 1
The Integrator
Three homepage captures plus the legal and privacy pages contain no price, no tier, no per-agent number, no billing period — the annual invoice is uncomputable from public pages alone. 1 3 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 3 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 31 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any pricing information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 71 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 32 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (8)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage otrs.com Checked 15 Sep 2026 +2 earlier captures: 11 Sep 2026, 31 Aug 2026 Details →
- 2 Privacy policy otrs.com Checked 15 Sep 2026 +1 earlier capture: 31 Aug 2026 Details →
- 3 Imprint otrs.com Checked 30 Sep 2026 Details →
- 4 Ticketing, queues & SLA — found from sitemap otrs.com Checked 1 Oct 2026 Details →
- 5 Ticketing, queues & SLA — found from sitemap otrs.com Checked 1 Oct 2026 Details →
- 6 Customer data protection — found from sitemap otrs.com Checked 1 Oct 2026 Details →
- 7 Integrations & API — found from sitemap otrs.com Checked 1 Oct 2026 Details →
- 8 Integrations & API — found from sitemap otrs.com Checked 1 Oct 2026 Details →