whats-best.ai
Search Sign in

Data Protection

heyData

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by heyData GmbH · heydata.eu

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

heyData, a Berlin GmbH in the commercial register (HRB 242016 B, Amtsgericht Charlottenburg), scores highest on records & DPIA depth and privacy regime coverage: an Art. 30 RoPA with templates and export, an Art. 35 DSFA, Art. 28 vendor management on a 4,000+ vendor database and TOM documentation are named linked modules, and DSGVO, UK GDPR, revDSG, EU AI Act, NIS2 and ISO 27001 fill the catalogue. Weakest is pricing transparency: 'Professional ab 99 €/Monat*' with an asterisk footnote the capture never shows, a final price 'nach Unternehmensgröße' by custom quote, and an Art. 37 DSB appointment plus annual DSFA bundled in. The clearest split sits on data subject rights & incidents: the Skeptic's 3 rests on data subject request handling having no product evidence, while the 4s credit the Art. 33 breach module's 72-hour deadline tracking. flagged splits show none above threshold; audit readiness & evidence and sovereignty hold single-point spreads over whether the vendor-assembled 'prüffähiges Paket' is a standing audit state and whether 'Hosted in Germany' outweighs the vendor's own disclosed US processor chain; persona-weighted totals span 3.9-4.6.

Report an error

Speaks for it

  • Art. 30 RoPA with templates and export, an Art. 35 DSFA, Art. 28 vendor management on a 4,000+ vendor database and TOM documentation are named linked modules (records & DPIA depth 5-6)
  • Framework catalogue spans DSGVO, UK GDPR, revDSG, EU AI Act, NIS2 and ISO 27001 with guided ISO/IEC 27001:2022 Annex A mapping
  • Breach module documents incidents against the 72-hour Meldefrist with workflows, reminders and prepared reporting steps under Art. 33
  • Privacy trainings are assigned automatically, followed by reminders, with completions evidenced in centrally documented Nachweisen
  • German GmbH in the Handelsregister (HRB 242016 B, Amtsgericht Charlottenburg) claiming 'Hosted in Germany' on an ISO 27001-certified hoster

Report an error

Held against it

  • Real invoice is incomputable from public pages: 'Professional ab 99 €/Monat*' with the asterisk footnote never shown and the final price 'nach Unternehmensgröße' via custom quote (pricing transparency 3)
  • The Professional plan bundles an Art. 37 DSB appointment and an annual DSFA, fusing software and consulting into one price
  • Data subject request intake, the Art. 12 clock, identity checks and deletion execution appear nowhere in the product evidence (data subject rights & incidents 3-4)
  • No documented API, directory import, SSO/SCIM or webhooks; integration evidence is a single line naming Microsoft 365, Jira and Slack (integrations & automation 4)

Report an error

Best for

  • You are a DACH or UK SMB that wants DSGVO, UK GDPR and revDSG documentation packs in one platform, with EU AI Act and NIS2 modules alongside
  • You need an Art. 30 RoPA, Art. 35 DSFA, Art. 28 vendor checks and TOM documentation as linked modules with templates, exports and a 4,000+ vendor database
  • You want breach incidents tracked against the 72-hour deadline with prepared reporting steps and automatically evidenced employee training
  • You would rather have an Art. 37 external DSB appointment and annual DSFA bundled with the platform than procured separately

Report an error

Avoid if

  • You need the real invoice computable from public pages — pricing is a custom quote scaled by 'Unternehmensgröße' with consulting fused into the plan
  • You need data subject request workflows — intake, the Art. 12 clock, identity checks, deletion execution — as product functionality
  • You depend on an API, SSO/SCIM, directory import or webhooks to connect the platform to your existing IT estate
  • You must verify sovereignty claims before procurement — ask the vendor: the public pages we read do not show it

Report an error

The scores

Records & DPIA depth

Show reasoning
How this is scored

The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.

3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.

5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.

8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.

10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.

Report an error

The External DPO

Art. 30 register, DSFA, Art. 28 AVV/vendor management and TOMs are all real linked modules with templates and a 4,000+ vendor database, which clears the linked-modules bar. But nothing evidences one connected data model where the RoPA drives DSFA triggers or legal bases, and no multi-mandate/client-separation capability appears anywhere — for thirty clients that still means copy-paste. 1 3 4

Report an error

The In-House Counsel

All four core artifacts are in the platform — an Art. 30 Verarbeitungsverzeichnis with templates and export, an Art. 35 DSFA that derives measures, Art. 28 AVV/vendor management with deadlines and Nachweise, and central TOM documentation. But nothing evidences a connected data model: no legal-basis modeling, no DPIA triggers derived from the register, no group templates or multi-client capability — each is sold as its own module. Linked modules with shallow connection, not a system of record. 1 3

Report an error

The Drafted Generalist

The GDPR pages show a structured Art. 30 RoPA with templates and export, a guided DSFA that derives measures directly, TOM documentation with gap visibility, and Art. 28 AVV/vendor management with status, deadlines and a 4,000+ vendor database — that's genuinely more than shallow checklists. But nothing evidences legal bases linked in the record, reusable group templates or authority-accepted outputs, so it stops short of the connected data model an 8 would require. 1 3 4

Report an error

The Lead Auditor

VVT with templates and exportable documentation, structured DSFA, central TOM documentation, and Art. 28 vendor management with tracked status, deadlines and Nachweise are all named modules, plus a 4,000+ vendor database. But nothing evidences a connected data model — legal bases, DPIA triggers derived from records, and multi-client/mandate reuse are all absent from the evidence — so this is marketing-level module breadth at rubric level 5, not the linked system of record of rubric level 8. 1 3 4

Report an error

The IT Integrator

RoPA with templates and export, structured DSFA, AVV/vendor management with deadlines and a 4,000+ vendor database, plus TOM documentation all live in the platform — but nothing evidences one connected data model, DPIA triggers derived from the record, legal bases, or multi-client reuse; it reads as capable linked modules, which is exactly rubric level 5. 3 4 1

Report an error

The Skeptic

The evidence gives me one marketing sentence each for a RoPA with templates and export, an Art. 35 DSFA, Art. 28 AVV/vendor management and TOM documentation — that is feature breadth at anchor-5 level, but nothing evidences a connected data model, legal-basis linkage, DPIA triggers derived from the record, group templates, or multi-client reuse. Processor and TOM modules are claimed to exist inside the platform, which lifts it above rubric level 3, but depth beyond the tagline is entirely unproven. 1 3

Report an error

Data subject rights & incidents

Show reasoning
How this is scored

The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

0 — Requests arrive by email and live there; breaches are a phone call and a memo.

3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.

5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.

8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.

10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.

Report an error

The External DPO

Breach handling is genuinely structured — Art. 33 workflows, the 72-hour clock, reminders and prepared notification steps. But data subject requests, identity checks and deletion execution have zero product evidence in the evidence, so I can only credit half the operational picture. 3

Report an error

The In-House Counsel

The breach side is real — structured incident documentation, the 72-hour Meldefrist tracked, workflows, reminders and 'vorbereitete Meldeschritte' — though prepared steps is short of actually producing the Art. 33 notification, which is what I would need to see. The evidence is silent on data subject request intake, the Art. 12 clock, identity checks and any deletion-concept workflow, and silence is information: one solid pillar out of three. 3

Report an error

The Drafted Generalist

Breach handling is described reasonably well — structured documentation, the 72-hour Meldefrist kept in view, workflows, reminders and prepared notification steps — which sits at the anchor-5 level on its own. But data subject request handling appears nowhere in the evidence: no intake channel, no Art. 12 clock, no identity checks, no deletion workflow, and half the operational DSMS missing is half a pass. 3

Report an error

The Lead Auditor

Breach handling is credibly described — Art. 33, 72-hour deadlines, workflows, reminders, prepared reporting steps — which carries the incident half toward rubric level 5. Data subject request handling appears nowhere in the product evidence; the "rights" facts are heyData's own website privacy policy, not DSMS functionality, so the rights half of the criterion is unevidenced and caps this at 4. 1 3 6

Report an error

The IT Integrator

The breach module is real — Art. 33 workflows, Meldefristen kept in view, reminders and prepared reporting steps — but the evidence is silent on DSR intake, Art. 12 clock automation, identity checks and deletion concepts as workflow; the rights list at E8 is heyData's own website privacy policy, not product capability, so I interpolate between rubric level 3 and 5. 3 6

Report an error

The Skeptic

The breach module gets a real sentence — 72-hour deadline tracking, workflows, reminders, prepared reporting steps — but I find zero evidence of any data subject request intake, Art. 12 clock, identity checks, or deletion execution tied to the RoPA; the 'rights' facts in this sheet are heyData's own privacy policy, not product features. One operational half exists at reminder level, the other doesn't appear at all, which lands on rubric level 3. 3

Report an error

Privacy regime coverage

Show reasoning
How this is scored

Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

0 — One regime, hard-coded; anything else is "on the roadmap".

3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.

5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.

8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.

10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.

Report an error

The External DPO

GDPR, UK GDPR and Swiss revDSG plus an EU AI Act module are listed, decent breadth for a DACH/UK practice. But nothing shows one record mapping across regimes or an update cadence when the law moves, so I read this as island documentation per regime until proven otherwise. 1 3

Report an error

The In-House Counsel

The catalogue names DSGVO, UK GDPR, revDSG and an EU AI Act module — usefully, exactly the regimes my companies operate under — plus NIS2 and ISO 27001. But the regimes appear as parallel modules with no evidence that one processing record maps across them, no per-country variants, and no documented update cadence for the legal content, which for me is the disqualifier for anything higher. 1 4

Report an error

The Drafted Generalist

GDSR/DSGVO, UK GDPR, Swiss revDSG and an EU AI Act module cover the regimes an 80-person firm would realistically face, with ISO 27001 and NIS2 beyond privacy. What's absent is any evidence that one processing record maps across regimes or that the content is maintained as the law moves — so content packs of varying depth, not a living regime product. 1 4

Report an error

The Lead Auditor

The module list covers DSGVO, UK GDPR, revDSG, DSFA, TOMs, EU AI Act, NIS2 and ISO 27001 with guided mapping to ISO/IEC 27001:2022 Annex A — the major regimes plus newer duties for its market. No evidence of one-record-many-regimes mapping or a documented update cadence when regimes move, so this sits at rubric level 5, not 8. 1 4

Report an error

The IT Integrator

DSGVO, UK GDPR and Swiss revDSG sit alongside NIS2 and EU AI Act as named modules, with ISO 27001:2022 Annex A mapping on the security side — solid market coverage, but no evidence that one record maps across regimes, so each regime presents as its own content pack: rubric level 5. 1 4

Report an error

The Skeptic

The module menu lists DSGVO, UK GDPR, revDSG and an EU AI Act pack, which clears rubric level 3's 'GDPR plus one national law' bar. But every regime is presented as a separate content pack and the evidence is silent on one-record-many-regimes mapping, per-country variants, and any update cadence when the law moves — so rubric level 5's 'content packs of varying depth' is exactly what's evidenced, no further. 1 3

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The External DPO

Exportable Art. 30 documentation, training completions documented centrally with Nachweise and guided ISO 27001:2022 mapping exist. But the 'prüffähiges Paket' is assembled by heyData rather than pulled on demand, and there is no evidence of revision-safe history or auditor access roles — I cannot hand a client a defensible 'state on date X'. 3 4

Report an error

The In-House Counsel

There is an audit-prep offering ('prüffähiges Paket' of Nachweise, Risikoberichte, Policies, ISMS-Dokumentation), exportable Art. 30 documentation, training certificates and vendor evidence tracking. But I see no revision-safe change history, no auditor access roles, no on-demand evidence packs — and the package reads as something heyData assembles for you, a service step, not a standing state I can defend to an authority. 3 4

Report an error

The Drafted Generalist

There is an explicit promise that evidence, risk reports, policies and ISMS documentation get assembled into a 'prüffähiges Paket', plus centrally documented training certificates and an exportable RoPA. But that sentence reads like the expert services team assembling files for me, and the evidence shows no revision-safe change history, no auditor access roles and no answer to 'show me the state on date X' — assembling an audit file would still be a project. 3 4

Report an error

The Lead Auditor

Exportable Art. 30 documentation, centrally documented training certificates, and a claim that heyData assembles Nachweise, risk reports and policies into a "prüffähiges Paket" give report generators and per-activity evidence. But there is not one word on versioned records or revision-safe change history — and a pack assembled by the vendor is exactly the week-before-the-audit pattern I reject when no point-in-time trail underlies it; 4, not 5. 3 4

Report an error

The IT Integrator

heyData assembles evidence, risk reports, policies and ISMS documentation into a prüffähiges package, and training completions are documented with certificates while the RoPA exports — but there is no evidence of revision-safe change history, auditor access roles, or a point-in-time view, so the full audit file still needs assembly: rubric level 5. 4 3

Report an error

The Skeptic

I can credit training completion Nachweise, exportable RoPA documentation and guided ISO/IEC 27001:2022 mapping, but the 'prüffähiges Paket' is heyData assembling documents for you — a service, not a standing system state — and there is no evidence of revision-safe history, auditor roles, or a 'show me date X' answer. And I note the homepage ISO 27001 badge sits next to a product page saying only an 'ISO 27001-ready Management System' with a certified *Hoster* — ready is not certified, and the certificate belongs to somebody else. 1 3 4

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.

8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.

Report an error

The External DPO

Named integrations with Microsoft 365, Jira and Slack beat CSV purgatory, and automated training assignment with reminders exists. But no REST API, directory import, SSO/SCIM or webhook appears anywhere in the evidence — onboarding thirty tenants still means typing by hand. 3 4

Report an error

The In-House Counsel

Named integrations with Microsoft 365, Jira and Slack plus genuine recurrence automation — automatic training assignment, reminders, documented completions — put this above CSV in/out. But the evidence evidences no API, no directory import, no SSO/SCIM, no webhooks; 'Integrationen mit bestehenden Tools' is breadth without demonstrated depth, and I cannot assume infrastructure the vendor does not document. 3 4

Report an error

The Drafted Generalist

Integrations with Microsoft 365, Jira and Slack get one marketing line, and training assignment with reminders is automated — that's the extent of it. No documented API, no directory import, no SSO/SCIM, no webhooks anywhere in the evidence, so the platform can't feed from my real IT estate and I'd be re-typing it. 3 4

Report an error

The Lead Auditor

Three native connectors (Microsoft 365, Jira, Slack) and reminder/assignment automation for trainings and breach deadlines are real but thin. No documented API, no directory import, no SSO/SCIM, no webhooks anywhere in the evidence — the connectivity half of rubric level 5 is missing, so 4. 1 3 4

Report an error

The IT Integrator

The only integration evidence is a single marketing line naming Microsoft 365, Jira and Slack — it names my ticketing estate but proves nothing about depth, and the evidence is entirely silent on REST API, webhooks, SSO/SCIM or directory import; the automation on record is reminders and automated training assignment. Better than a CSV drawbridge, but barely. 4 3

Report an error

The Skeptic

One line claims integrations 'mit bestehenden Tools wie Microsoft 365, Jira oder Slack' and training assignment plus deadline reminders are automated — that is a handful of connectors and reminder-level automation, mid-way between rubric level 3 and 5. No documented API, no directory import, no SSO/SCIM, no webhooks anywhere in the evidence; 'wie' (such as) is doing a lot of unverified work. 3 4

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The External DPO

A Berlin GmbH in the Handelsregister with 'Hosted in Germany' and an ISO 27001-certified hoster is a solid start. But no named data centers, no public platform subprocessor list or TOMs, and the vendor's own disclosed chain runs content through Webflow (USA), Google LLC and Reddit under DPF-reliance transfers — the 'kein Zugriff durch Nicht-EU-Behörden' badge is doing heavy lifting. 3 5 6 6

Report an error

The In-House Counsel

A German GmbH at a Berlin address claiming Germany hosting on an ISO 27001-certified hoster with 'kein Zugriff durch Nicht-EU-Behörden' is the right posture for the record itself. EU entity and German hosting, but the publication duty is unmet and US exposure in the chain is documented by the vendor itself. 3 5 6 6

Report an error

The Drafted Generalist

The entity is a confirmed Berlin GmbH with a commercial register entry, hosting is claimed 'in Germany' with an ISO 27001-certified hoster, and a customer DPA is referenced — that clears the anchor-5 bar. But the data centers aren't named, the platform's own subprocessor chain isn't published, and the privacy policy shows a marketing stack firmly in US jurisdictional reach (Webflow, Google LLC, AWS CloudFront, Taboola, Reddit) while the product page claims 'kein Zugriff durch Nicht-EU-Behörden' — those two facts don't sit together. 3 5 6

Report an error

The Lead Auditor

A German GmbH with commercial register entry and "Hosted in Germany" with an ISO 27001-certified hoster beat rubric level 3, but the platform's DPA and subprocessor list are not published and the vendor's own policy shows the website chain on Webflow, AWS Cloudfront, Google, Meta, Taboola and Reddit with US transfer mechanisms. The marketing claim "kein Zugriff durch Nicht-EU-Behörden" sits unevidenced against that exposure — 4. 3 4 5 6 6

Report an error

The IT Integrator

Between rubric level 3 and 5. 5 6 3 6

Report an error

The Skeptic

The German entity is solid — Handelsregister HRB 242016 B, Amtsgericht Charlottenburg — and 'Hosted in Germany' is claimed, but the hoster is unnamed and the platform's own subprocessor chain and DPA are nowhere published. 3 5 6 6

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.

Report an error

The External DPO

A freemium tier, a from-price of 99 €/month with annual -10% and no commitment exist. But the final price follows company size via custom quote, the asterisk footnote is unshown, and the Professional plan bundles external-DSB services and annual DSFAs — the real invoice is a sales conversation, and client budgeting costs me hours. 2 3 6

Report an error

The In-House Counsel

From €99/month with monthly/annual terms and a stated -10% annual discount is a start, but the asterisk's footnote isn't shown, the 'Endpreis nach Unternehmensgröße' scale isn't published, and the default path is a custom Angebot. Worse for computability, the Professional price bundles an official external DSB appointment under Art. 37 and an annual DSFA — software and a regulated legal service fused into one number I cannot decompose. 2 3

Report an error

The Drafted Generalist

There's a 'PROFESSIONAL ab 99 €/Monat*' whose asterisk footnote never appears on the page, a final price 'nach Unternehmensgröße', and an explicit 'Du erhältst ein Angebot' custom-quote model — with the Art. 37 DSB appointment and annual DSFA bundled into the plan, my real invoice is incomputable from public pages. Freemium and the -10% annual discount are the only hard numbers I could find. 2 3 6

Report an error

The Lead Auditor

An entry price exists (Professional from 99€/month, asterisk footnote not shown) plus a freemium tier, but the final price is "nach Unternehmensgröße" with no public scale table, combined offers are custom quotes, and the flagship plan bundles an external DSB and annual DSFA so software and consulting are inseparable. The real invoice is not computable from public pages — rubric level 3. 2 3 6

Report an error

The IT Integrator

An entry price exists — Professional ab 99 €/Monat with an asterisk footnote the page never shows, annual −10% — but 'Endpreis nach Unternehmensgröße' and the custom-quote model, plus software bundled with an Art. 37 DSB appointment as service, make the real invoice incomputable from public pages: rubric level 3. 3 2

Report an error

The Skeptic

There is a real number — 'Professional ab 99 €/Monat*' with an asterisk whose footnote the page capture never shows — but the final price is 'nach Unternehmensgröße' plus 'Du erhältst ein Angebot passend zu deinen Anforderungen', so the actual invoice is a sales conversation. And that Professional plan bundles an official Art. 37 DSB appointment and an annual DSFA: consulting dressed up as a SaaS line item, textbook rubric level 3; the freemium tier is the only fully computable price on the site. 2 3 6

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (17)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage heydata.eu Checked 5 Oct 2026 +1 earlier capture: 16 Sep 2026 Details →
  2. 2 Vendor pricing page heydata.eu Checked 5 Oct 2026 Details →
  3. 3 GDPR product page heydata.eu Checked 5 Oct 2026 Details →
  4. 4 ISO 27001 product page heydata.eu Checked 5 Oct 2026 Details →
  5. 5 Imprint heydata.eu Checked 5 Oct 2026 Details →
  6. 6 Privacy policy heydata.eu Checked 5 Oct 2026 +1 earlier capture: 15 Sep 2026 Details →
  7. 7 Data processing agreement (dpa) heydata.eu Checked 5 Oct 2026 Details →
  8. 8 Security / trust page — found from the homepage heydata.eu Checked 5 Oct 2026 Details →
  9. 9 Records & DPIA depth — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  10. 10 Records & DPIA depth — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  11. 11 Data subject rights & incidents — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  12. 12 Privacy regime coverage — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  13. 13 Privacy regime coverage — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  14. 14 Audit readiness & evidence — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  15. 15 Audit readiness & evidence — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  16. 16 Integrations & automation — found from sitemap heydata.eu Checked 5 Oct 2026 Details →
  17. 17 Integrations & automation — found from sitemap heydata.eu Checked 5 Oct 2026 Details →