Data Protection
caralegal
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by caralegal GmbH · caralegal.eu
Compare with preeco | datenschutz → Compare with Akarion GRC Cloud → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
caralegal is a data protection management platform from caralegal GmbH of Berlin, and the strongest marks land in privacy management at 8: the record of processing synchronizes automatically with impact assessments, technical measures and vendors, the deletion concept is generated from the record, and more than 200 legally reviewed processing-activity templates make the work reusable. Rights and incidents sit at 6 and framework coverage at 5 to 6, reflecting real German depth — Standard-Datenschutzmodell 3.1 with its seven guarantee goals and Art. 30(2) processor records — though we found no public information on Swiss or UK regimes. The soft spots are integrations and automation, scored 3 to 4 with no public information on an API, directory import, SSO or ticketing connectors, and sovereignty, where scores spread from 2 to 4 as judges weighted the confirmed Berlin GmbH against public silence on platform hosting, product subprocessors and a product data processing agreement. Audit readiness spreads 4 to 6 on the same outputs, split over revision-safe change history. Only Essential carries a public price, 'ab 79€ pro Monat'.
Speaks for it
- Privacy management scored 8, with records of processing synchronizing automatically with impact assessments, technical measures and vendors.
- Data subject requests come with automatic data-location lookup, deadlines and a secure data room, plus deletion concepts generated from the record.
- The German core is deep: Standard-Datenschutzmodell 3.1 with its seven guarantee goals, Art. 30(2) processor records and AI Act audit templates on the same documentation.
- More than 200 processing-activity templates and 150 vendor templates, created and reviewed by legal experts, are built in.
- Everything from DPAs to RoPAs goes to the authority with a single click, with PDF and Excel register export.
Held against it
- Sovereignty scores spread 2 to 4, with no public information found on platform hosting location, product subprocessors or a product data processing agreement.
- Integrations scored 3 to 4, with no public information found on an API, directory import, SSO, SCIM, webhooks or ticketing connectors.
- Pricing transparency scored 3 to 4: a figure appears only for Essential at 'ab 79€ pro Monat', Enterprise is 'auf Anfrage', and we found no public prices for Professional and Corporate.
- Audit readiness spread 4 to 6, with no public information found on revision-safe change history, auditor access roles or reconstructing a record's state on a given date.
- Breach handling is described only as central documentation with a guided decision process, and we found no public information on a 72-hour clock, severity assessment or authority notification output.
Best for
- You need one connected GDPR record core where processing activities drive the impact assessment, technical measures, vendors and the deletion concept.
- You work to German requirements, including the Standard-Datenschutzmodell 3.1 guarantee goals and Art. 30(2) processor records.
- You run a single legal entity or a small group, with plans bounded at 1, 3, 8 and unlimited legal entities and unlimited users and documents.
Avoid if
- Your privacy platform must synchronize with the systems you already run — the captured pages show automatic migration of existing documentation and PDF/Excel export, not estate integration.
- You must verify where the platform holding your register is hosted and which subprocessors touch it — the publicly documented subprocessors belong to the marketing website and include US-based providers.
- You need to reconstruct how a record looked on a given date — ask the vendor: the public pages we read do not show it
- You need a computable invoice for a multi-entity group without a sales conversation — only Essential carries a public price and Enterprise is 'auf Anfrage'.
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The register drives the rest, which is exactly what I want to see: automatic synchronization of the RoPA with DPIAs, TOMs and vendors, DPIA threshold analysis tied to risky processing activities, a deletion concept generated from the record, and a deep template library — over 200 processing activities, 150 vendors, legal bases under Articles 6 and 9 — that makes the work reusable. That is a genuinely connected data model. I found no public information on multi-client or mandate-level operation, which for a thirty-mandate practice is the difference between a tool and infrastructure. 7 8 9
The In-House Counsel
The record is a connected model: processing activities synchronize automatically with the impact assessment, TOMs and service providers, impact assessments trigger from an automated threshold analysis on risky activities, and the deletion concept is generated from the record itself. With legal-basis, vendor and TOM templates created and reviewed by legal experts, more than 200 processing activity templates, and group structures scaling by legal entities per edition, this is the depth I expect; I found no public information on multi-client mandate handling, which is what would make it a full system of record. 4 7 8 9
The Drafted Generalist
The record of processing sits in a guided workflow with an approval step, and the things that usually live in separate files hang off it: the DPIA decision is derived automatically from risky activities, vendors link to the record with a compliance check, TOMs can be process-specific, and the deletion concept is generated from the record itself. Legal-entity counts per plan point to group use, and the package to the supervisory authority goes out with one click, "von AVV bis VVT". I found no public information on multi-client mandate work, so I stop just short of the top. 2 7 8 9
The Lead Auditor
The captured pages show a connected model: processing records synchronize automatically with impact assessments, technical measures and vendors, the DPIA threshold analysis is derived from the record, and legal bases under Art. 6 and 9 sit in legally reviewed templates alongside SDM-linked technical measures. A one-click package to the authority spanning processor agreements through records suggests authority-usable outputs. We found no public information on reusable group templates or multi-client mandate handling; entity counts per plan are the only group signal. 7 8 9
The IT Integrator
The legal artifacts are genuinely connected: processing activities synchronize automatically with DPIAs, TOMs and service providers, the DPIA threshold analysis derives from risky activities, and outputs from processor agreements to the RoPA go to the authority at a click. With more than 200 activity templates, records for both controller and processor roles, and legally reviewed templates, this is a real data model rather than linked folders. I found no public information on multi-client or mandate capability for consultancies, which keeps it a step below the strongest showing. 7 8 9 2
The Skeptic
The record side is genuinely connected: processing activities run in a workflow with approval steps, the DPIA is triggered by automated threshold analysis linked to risky activities, and vendors and TOMs synchronize automatically with the register, with legally reviewed, editable templates throughout. We found no public information on multi-client or mandate capability, which is what separates the top anchors. Note also that the captured pages give different figures for the total function count (26 and 27). 7 8 9 2
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
Requests arrive in the system with automatic data-location lookup, a visible response deadline and a secure data room for the reply, breaches get centralized documentation through a guided decision process, and the deletion concept is generated from the RoPA — solid mid-weight operations. What keeps me from going higher: I found no public information on an intake portal or form, identity verification, the 72-hour breach clock, an authority notification output, or any tracking that a deletion actually executed. 2 7 8
The In-House Counsel
Requests arrive in the system with the response deadline shown automatically, the relevant data locations looked up, and answers transmitted through a protected data room — the statutory clock is handled as workflow, not a note in a diary. The breach side is documented only as central documentation with a guided decision process: I found no public information on a 72-hour clock, a severity assessment producing the authority notification, or execution tracking for the deletion concepts generated from the register. 7 8 9
The Drafted Generalist
Requests arrive in the tool with an automatic lookup of where the relevant data sits, the reply deadline shown, and answers sent through a protected data room, and incidents get central documentation with a guided decision process — exactly the plain-language hand-holding someone like me needs. I found no public information on escalation when a clock runs out, identity checks, the 72-hour breach clock, or evidence that a deletion was actually executed. 2 8 9
The Lead Auditor
Requests arrive as cases with owner, status and ID, deadlines and data locations are determined automatically, responses go out through a protected data room, and the deletion concept is generated from the record itself; incidents are documented centrally with a guided decision process. We found no public information on intake portals or forms, identity checks, deadline escalation, a 72-hour clock, or evidence that a deletion actually executed. 1 8 9
The IT Integrator
Requests land in the system with automatic deadline tracking, automatic data-location lookup and a secure data room for responses, the breach register runs a guided decision process, and the deletion concept is generated straight from the record of processing. The harder automation is not visible: no public information on intake portals or forms, identity verification, a 72-hour authority notification output for breaches, or evidence that deletion actually executes rather than being documented. 8 9 2 7
The Skeptic
Requests arrive in the system with automatic data-location lookup, automatic deadlines and a secure data room for the response, and the deletion concept is generated from the record itself. The breach module is described only as central documentation with a guided decision process — we found no public information on a 72-hour clock, severity assessment, authority notification output or identity verification, which is why this sits below the stronger anchors. 8 9 7 2
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
GDPR is operationalized deeply and the German layer is unusually strong — software for the Standard-Datenschutzmodell 3.1 with the seven guarantee goals and building blocks linkable to TOMs — while AI Act duties appear as audit templates alongside a separate AI Flow, and a website cookie check covers consent duties. That reads as the major regimes of its home market with newer duties delivered as content packs. I found no public information on Swiss nDSG, UK GDPR, or one record mapping across several regimes. 1 8 9
The In-House Counsel
Coverage is the German core done seriously: GDPR records including the Art. 30(2) processor variant, the Standard-Datenschutzmodell 3.1 with guarantee goals and always-updated SDM modules linked to TOMs, cookie-compliance checks, and AI Act audit templates sitting on the same documentation as the privacy flow. That visible maintenance of the legal content is exactly what I insist on; I found no public information on Swiss or UK regimes or per-country variants, so the one-record-many-regimes story is GDPR-plus rather than broad. 1 8 9
The Drafted Generalist
GDPR is the backbone and the German depth is real — the Standard-Datenschutzmodell 3.1 with its seven guarantee goals and building blocks sits inside the same records, and the AI Flow builds on the same documentation with AI Act audit templates and a cookie check on top. I found no public information on Swiss nDSG, UK GDPR or other per-country variants, so this reads as its home market rather than broad coverage. 2 8 9
The Lead Auditor
GDPR depth is real, the German Standard Data Protection Model 3.1 is built in with always-updated building blocks and seven guarantee goals, and AI Act duties run as an AI Flow that builds on the same documentation as the privacy module — one record serving two regimes. We found no public information on Swiss, UK or other national privacy regimes. 1 8 9
The IT Integrator
The German core is deep: the Standard-Datenschutzmodell 3.1 with all seven guarantee goals and continuously updated modules is built in, and AI Act and ISO duties arrive as audit templates plus an AI Flow that sits on the same documentation as the Privacy Flow. Beyond that market I found no public information on Swiss nDSG, UK GDPR or ePrivacy, and no per-country variants or a documented update cadence when regimes move. 9 8 1 2
The Skeptic
Beyond GDPR the product carries the German Standard-Datenschutzmodell 3.1 with always-updated building blocks, audit templates for the AI Act, and a website cookie check, and the vendor states privacy and AI documentation build on the same basis. We found no public information on Swiss or UK coverage or per-country variants, so the breadth of a top score is not evidenced. 9 8 1
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
Client-ready outputs exist: everything from DPAs to the RoPA goes to the authority with a single click, audit templates for ISO, GDPR and AI Act checks are built in, and the register exports as PDF or Excel. But my audits always end with "show me the state on date X", and I found no public information on revision-safe change history, audit evidence packs, or auditor access roles. 2 7 8
The In-House Counsel
The single-click submission to authorities covering everything from processor agreements to the records register, plus audit templates for ISO, GDPR and the AI Act and questionnaire-based gap analyses, is more than static PDFs. But I found no public information on revision-safe change history, audit-scoped evidence packs or auditor access roles — without those I cannot defensibly answer "show me the state on date X", so assembling the audit file remains unproven from these pages. 2 7 8
The Drafted Generalist
Everything can go to the authority with a single click "from DPAs to RoPAs", the register exports as PDF or Excel, and there are audit templates for ISO, GDPR and AI Act checks. I found no public information on revision-safe change history, auditor access roles, or reconstructing the state on a given date, so I cannot tell how a full audit file would stand up. 2 7 8
The Lead Auditor
Evidenced: register exports in PDF and Excel, a one-click package to the authority spanning processor agreements through records, audit templates for ISO, GDPR and the AI Act, gap-analysis questionnaires and PDCA planning. We found no public information on revision-safe change history, evidence attachments per activity, or auditor access roles; how a record looked on a given date is the question nothing captured answers. 7 8 9
The IT Integrator
Output is the strong half: one-click authority submissions from processor agreements to the RoPA, audit templates for ISO, DSGVO and the AI Act, and questionnaire templates for gap analyses, with PDF and Excel export of the register. The defensible trail is unevidenced — no public information on revision-safe change history, auditor access roles or evidence packs, so the state of a record at a past date stays unproven from the captured pages. 2 8 7
The Skeptic
An Audit & Vendor Flow, audit templates for ISO, GDPR and AI Act, gap-analysis questionnaires, PDF/Excel register export and submission to authorities with a single click are all evidenced. But we found no public information on revision-safe change history, auditor access roles or reconstructing the state on a given date, so the audit file may still take manual assembly even if the outputs are fast. 8 7 2 9
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
In-product automation is real — automatic transfer of existing documentation, automatic synchronization between registers, and an AI assistant and agents taking recurring steps — but the captured pages show little beyond that. I found no public information on a documented API, directory import, ticketing connectors, or SSO, and for thirty mandates that means typing rather than plumbing. 2 1 7
The In-House Counsel
What I can see feeding the platform is a website cookie scan by URL, automatic transfer of existing documentation into the system, and PDF/Excel export of the register, with AI assistants and agents advertised for recurring steps. I found no public information on a documented API, directory import, or ticketing and single-sign-on connectors, so the recurring privacy work appears to depend largely on manual entry rather than the real IT estate. 2 1 7 8
The Drafted Generalist
Existing documentation is transferred automatically rather than re-typed, requests become cases with owner, status and ID, and an AI assistant and agents take over recurring steps. I found no public information on a documented API, directory import, ticketing connectors or single sign-on, so the platform may still be an island in our IT estate. 2 1 7
The Lead Auditor
Shown: automatic migration of existing documentation into the platform, a live website cookie check by URL, approval workflows with follow-up reminders, and an AI assistant with agents taking over recurring steps. We found no public information on a documented API, directory import, ticketing connectors, SSO or webhooks, so the automation on show is guided workflow and reminders rather than the platform feeding from the live estate. 2 1 7
The IT Integrator
This is where it loses me: the only estate-facing evidence is a one-time automatic migration of existing documentation and PDF/Excel export — a drawbridge, not a bridge. I found no public information on a REST API, directory import, SSO, SCIM, webhooks or ticketing connectors; the AI assistant and agents automate internal workflow steps, not synchronization with the systems I already run. 2 7 1
The Skeptic
The only connections to the outside estate evidenced are a one-time automatic transfer of existing documentation and PDF/Excel export; we found no public information on an API, directory import, ticketing or HR connectors, or SSO. The AI assistant and agents appear once in a webinar description with no detail on what they actually do, and I do not credit that as automation. 2 7 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
The imprint confirms a German GmbH seated in Berlin with a German VAT ID, and the privacy policy publishes website subprocessors with Article 28 agreements in place — but those named processors are marketing-stack services, including a Delaware company with AWS behind it, and I found no public information on where the platform itself is hosted or which subprocessors touch customer compliance records. The system that maps my clients' processing is the most concentrated processing I own, and its hosting chain is undocumented on the public pages. 3 5
The In-House Counsel
The vendor is a German GmbH seated in Berlin with a German VAT number, which is the right jurisdiction for the system that will hold my register. But the captured pages give no hosting location, no subprocessor list and no data processing agreement for the product itself — the subprocessors actually documented belong to the marketing website, including a US provider running on AWS — so where my compliance record would live and under whose law is unverifiable from public information. 3 5
The Drafted Generalist
The vendor is a Berlin GmbH with a German VAT number, and the privacy policy openly lists its website processors — including Supademo Inc. in Delaware, Google and Microsoft under the EU-US Data Privacy Framework, and AWS behind the demo tool. I found no public information on where the compliance platform itself is hosted, its product subprocessors, named data centers or a public product DPA, which for the system holding our register is the part I most need. 3 5
The Lead Auditor
The imprint establishes a GmbH seated in Berlin with a German VAT ID and named managing directors, which settles the entity question cleanly. Beyond that we found no public information on where the platform itself is hosted, on a customer data processing agreement, or on a platform subprocessor list; the captured privacy policy documents the website chain only, which includes a US provider in Delaware with AWS hosting and Google LLC and Microsoft Corporation transfers under the Data Privacy Framework. For the system that would hold a customer's register of processing, that silence is not a small thing. 3 4 5
The IT Integrator
The entity side is solid: a Berlin-based German GmbH with a published imprint, and a privacy policy naming website subprocessors with locations and Article 28 contracts — including a US one (Supademo Inc. in Delaware, hosted on AWS) and US transfers to Google LLC and Microsoft Corporation under the Data Privacy Framework. For the compliance record itself I found no public information on hosting location, named data centers or the platform's own subprocessor chain, which is the part that matters most for a system holding your register. 3 5 4
The Skeptic
A German entity with a Berlin seat and VAT number is confirmed in the imprint, and the privacy policy discloses the website's processors — including US-based ones such as Supademo on AWS and Google and Microsoft under the Data Privacy Framework. For the platform holding the customer's register itself, we found no public information on hosting location, product subprocessors or a product data processing agreement, and the captured security page confirmed nothing on certifications either. 3 5 6
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
The captured pricing page shows a figure for one tier only — Essential at "ab 79€ pro Monat" as a starting price with one legal entity — while Enterprise is "auf Anfrage" and I found no public price for the Professional and Corporate tiers, so a multi-entity group's or a consultancy's real invoice stays a sales conversation. Credit for structure: entity boundaries per tier (1, 3, 8, unlimited), unlimited users and documents, the 50% nonprofit discount and the free-trial terms are all public. 4
The In-House Counsel
The boundaries are unusually clear for this market: the entry edition at "ab 79€ pro Monat", legal entities per edition at 1, 3, 8 and unlimited, unlimited users and documents, and a public 50% nonprofit discount. But only the entry edition carries any figure, Enterprise is "auf Anfrage", and I found no public prices for the two middle editions, so the real invoice for a multi-entity group is not computable from the pricing page alone. 4
The Drafted Generalist
The Essential plan is published at "ab 79€ pro Monat" with legal-entity counts per tier and unlimited users and documents, plus a free trial and a 50% nonprofit discount. The middle tiers carry no prices in the captured pages and Enterprise is "auf Anfrage", and nothing says what pushes the starting price upward, so our real invoice still needs a sales call. 4
The Lead Auditor
The Essential tier carries a public starting price quoted as ab 79€ pro Monat, with one legal entity, unlimited users and unlimited documents stated. The captured pricing page gives entity counts for Professional, Corporate and Enterprise but shows a figure only for Essential, with Enterprise priced auf Anfrage, so the real invoice for a multi-entity group is not computable from public pages; we found no public information on setup fees or how software and services are separated. 4
The IT Integrator
One real number: Essential from 79€ per month with one legal entity, and the legal-entity ladder per plan is published alongside unlimited users and documents, a 50% nonprofit discount and a free trial after a demo. The middle tiers carry no captured prices, Enterprise is on request, and the single figure is a stated starting price — so the real invoice for anything beyond the smallest setup remains a sales conversation. 4
The Skeptic
Essential carries a published starting price of "ab 79€ pro Monat" with entity counts per tier, unlimited users and documents, a stated trial condition and a 50% nonprofit discount. Enterprise is "auf Anfrage" and we found no public prices for the Professional and Corporate tiers, so the real invoice for anything above one entity is not computable from the captured pages. 4
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 23 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity, Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 82 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (9)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage caralegal.eu Checked 15 Sep 2026 +2 earlier captures: 24 Aug 2026, 23 Aug 2026 Details →
- 2 Product page (EN) caralegal.eu Checked 5 Oct 2026 Details →
- 3 Imprint caralegal.eu Checked 5 Oct 2026 Details →
- 4 Vendor pricing page caralegal.eu Checked 5 Oct 2026 Details →
- 5 Privacy policy caralegal.eu Checked 5 Oct 2026 Details →
- 6 Security / trust page caralegal.eu Checked 30 Sep 2026 Details →
- 7 Records & DPIA depth — found from sitemap caralegal.eu Checked 5 Oct 2026 Details →
- 8 Records & DPIA depth — found from sitemap caralegal.eu Checked 5 Oct 2026 Details →
- 9 Privacy regime coverage — found from sitemap caralegal.eu Checked 5 Oct 2026 Details →