whats-best.ai
Search Sign in

Data Protection

preeco | datenschutz

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by preeco GmbH & Co. KG · www.preeco.de

Compare with caralegal → Compare with audatis MANAGER → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

preeco | datenschutz is a GDPR management platform from preeco GmbH & Co. KG in Ulm. Its strongest showing is audit readiness at 8: every approval freezes an immutable revision with a SHA-256 checksum, plus an automatic log of changes. Privacy management follows at 8-9 on a connected record model linking activities to systems, measures and contracts; rights and incidents sits at 7-8 on web-form intake, deadline monitoring and nine notification templates for Art. 33/34 and BSI duties. The genuine split is framework coverage, ranging 5-7: lower scores read the non-GDPR additions as content packs around a GDPR-centric record, while the in-house counsel's 7 credits one record serving GDPR and the EU AI Act plus German specifics like the Bavarian questionnaire. The weakness is integrations and automation at 4: the vendor describes a closed system with no public REST API, custom endpoints only on Private Cloud and On-Premises. Sovereignty scores 7-8: hosting pages name Hetzner data centers in Germany, while the privacy notice also names UpCloud in Finland. No prices are published; the licence scales with employees, modules and hosting variant.

Report an error

Speaks for it

  • Every approval freezes an immutable revision with SHA-256 integrity checks and an automatic activity log
  • Request and breach workflows run from embeddable web forms through automatic deadline monitoring to nine notification templates covering Art. 33/34 and BSI duties
  • Multi-mandate operation with cross-client inheritance supports external DPOs and groups, with the licence scaling by employees, modules and hosting variant rather than number of organizations
  • Cloud and Private Cloud hosting runs in ISO-27001-certified Hetzner data centers in Germany, with a published DPA, downloadable TOMs and AI functions off by default

Report an error

Held against it

  • No public REST API — the application is described as a closed system, with customer-specific endpoints only on Private Cloud and On-Premises
  • We found no public information on directory import, ticketing or HR connectors, webhooks or SCIM
  • Single sign-on via SAML2 is available only on the Private Cloud and On-Premises variants
  • Beyond GDPR and the EU AI Act we found no public information on UK GDPR, Swiss or ePrivacy coverage, and framework coverage scores range from 5 to 7
  • Missing DPA-to-record links are closed by hand, and we found no public information on evidence that a deletion was executed

Report an error

Best for

  • You are an external DPO or consultancy managing many client mandates, where cross-client inheritance, one-click tenant switching and licensing that does not scale by number of organizations matter
  • You operate in the German market and need the Bavarian supervisory authority questionnaire and BSIG reporting templates generated from your own records
  • You must show auditors or authorities a defensible, point-in-time state of your documentation
  • You want AI drafting that stays off by default and runs on your own API key

Report an error

Avoid if

  • You need live synchronization with your IT estate — directory import, ticketing or HR connectors — since the vendor describes the application as a closed system without a public REST API
  • You depend on single sign-on on the standard Cloud tier, since SAML2 is offered only on Private Cloud and On-Premises
  • You seek on-premises deployment as a smaller organization, as that variant is typically reserved for the public sector and enterprise segment

Report an error

The scores

Records & DPIA depth

Show reasoning
How this is scored

The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.

3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.

5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.

8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.

10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.

Report an error

The External DPO

The record of processing is a genuinely connected model: activities carry their systems, safeguards and data processing agreements as a graphical relationship view, recipients without a contract surface as marked-missing rows, and every approval freezes a PDF revision with checksum. For my practice the mandate story is real — connected documents inherit content across clients, new tenants are created in minutes with per-tenant module configuration, and the Bavarian authority's questionnaire plus status reports and procedure files are generated at the push of a button. The one step short of full marks: I found no public information on a completeness view that drives technical and organizational measure coverage from the record itself. 16 17 11 2 2

Report an error

The In-House Counsel

The register is a genuinely connected model: every Article 30 mandatory field is guided in the record, activities are intelligently linked to systems, TOMs and contracts, and data processing agreements are matched to data recipients automatically by name with uncovered recipients flagged as missing. The Article 35 necessity and screening assessment is proposed from the activity itself, deletion classes derive deletion rules with deadlines and responsibilities, and external DPOs and groups can run hundreds of mandates with cross-client inheritance plus one-click status reports, procedure files and the Bavarian authority questionnaire. I hold back the top mark because missing processor connections are closed by hand, and I found no public information on TOM coverage being computed and reported off the register. 1 16 17 2 2 7

Report an error

The Drafted Generalist

The record of processing is a guided form through every mandatory field — purpose, data categories, legal bases, recipients, third-country transfers, retention — and the links run on to systems, TOMs and contracts in a graphical relationship view, which is exactly the software-knows-the-law experience I need. DPIA handling sits on the same record with Art. 35 necessity checks and a Schrems II assessment, and multi-client handling with cross-client inheritance is built in rather than copy-paste. Missing contract links are flagged automatically but you wire some of them by hand, which is what keeps this a rung below a fully self-driving register. 16 17 1 2 11

Report an error

The Lead Auditor

Processing activities carry every Art. 30 field and are linked graphically to systems, technical and organizational measures and Art. 28 contracts, with recipient-to-contract coverage created by automatic name matching and gaps surfacing as marked rows. Impact assessments, including transfer assessments for third-country cases, run off the same record with a necessity pre-check, measures are versioned and linked, and mandate capability with cross-client inheritance is built in rather than copy-paste. We found no public information on a coverage view showing measures complete across every record, which is what would close the loop. 1 2 16 17 7

Report an error

The IT Integrator

The data model is genuinely connected: every processing activity carries its systems, TOMs and data processing agreements in a graphical relationship view, the record itself feeds the Art. 35 necessity assessment, and deletion classes derive rules from linked activities — with multi-mandate operation, strict tenant separation and cross-client inheritance documented in depth. It stays below the top for me because missing DPA-to-record connections are established by hand and by name matching rather than flowing from one model. 2 16 17 2

Report an error

The Skeptic

The record model is genuinely connected: every Art. 30 mandatory field, graphical links from processing activities to systems, TOMs and contracts, and a contract view flagging which data recipients are covered by a DPA — with missing links still set by hand rather than derived. Reusable text modules, cross-client inheritance for mandates and one-click BayLDA procedure files match the connected-model anchor; we found no evidence that DPIA necessity or processor coverage is derived rather than AI-proposed and hand-confirmed, which keeps it below system-of-record territory. 16 17 2 7 11

Report an error

Data subject rights & incidents

Show reasoning
How this is scored

The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

0 — Requests arrive by email and live there; breaches are a phone call and a memo.

3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.

5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.

8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.

10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.

Report an error

The External DPO

Requests arrive through embeddable web forms covering every Art. 15–22 type, identity verification and rejection grounds are documented, replies go out from the system via a one-time encrypted link, and the statutory clock is watched automatically with proactive warnings. Breaches get nine ready notification templates including the Art. 33 reports to the supervisory authority and the BSI duties, a clear per-report deadline status and graphical risk mapping, and deletion classes link to processing activities to derive rules with deadlines and responsibilities. What I miss for full marks is evidence of execution: I found no public information on tracking that shows a deletion actually happened. 18 7 19 20 2

Report an error

The In-House Counsel

This is the operational half done to a standard I would defend: web-form intake, documented identity verification with time of request, all Article 15-22 request types under automatic deadline monitoring with proactive warnings, and replies sent only as a one-time link to an encrypted page. The breach workflow produces what I would actually file — nine ready templates covering the initial, follow-up and final reports to the authority under Article 33, the Article 34 notices and the German BSI reports, each with an unambiguous deadline state and a documented justification when a deadline is missed. Deletion classes tie to processing activities and derive rules with deadlines and owners, but I found no public information on execution tracking or evidence that a deletion was carried out. 18 7 2 20 19 23

Report an error

The Drafted Generalist

Requests arrive through embeddable web forms, every Art. 15–22 type is covered, deadlines are monitored automatically with clear status states and documented justifications, identity checks and rejection reasons are recorded, and replies go out as one-time encrypted links — close to end-to-end. Breach handling produces the actual authority notifications from nine ready templates (Art. 33/34 plus BSI reports) with the 72-hour clock tracked. I found no public information on escalation chains or on tracked evidence that a deletion actually executed, which is what held me back from the top of this band. 18 19 2 7

Report an error

The Lead Auditor

Requests come in through embeddable web forms, identity verification and rejection grounds are documented fields, replies go out as one-time encrypted links, and every request type under Art. 15–22 runs under automatic deadline monitoring with proactive warnings; breaches carry severity classification, a risk matrix, 72-hour monitoring and nine ready notification templates for Art. 33, Art. 34 and the German BSI with an unambiguous deadline status per report. Requests and incidents link to the affected processing activities, and deletion rules with deadlines, procedures and responsibilities derive from deletion classes tied to the register. We found no public information on escalation chains for missed deadlines or on evidence that a deletion was actually executed. 18 19 20 7

Report an error

The IT Integrator

Requests and incidents run as operations: embeddable web forms for intake, documented identity verification with rejection reasons, automatic deadline monitoring with proactive warnings, and nine ready report templates covering Art. 33 initial, follow-up and final notifications plus BSI reports with an unambiguous deadline status each. Deletion classes link to processing activities with deadlines, procedures and responsibilities; I found no public information on tracked evidence that a deletion actually executed. 18 7 2

Report an error

The Skeptic

Requests and breaches are run as real operations: embeddable intake forms, documented identity verification with timestamp, recorded rejection reasons, automatic deadline monitoring with per-report states, replies by one-time encrypted link, a 72-hour breach clock with severity classification, and nine ready report templates covering Art. 33/34 and BSI. Deletion classes are linked to processing activities and derive rules with deadlines and responsibilities, but we found no public information on deadline escalation or on evidence that a deletion was actually executed. 18 19 7 2 20

Report an error

Privacy regime coverage

Show reasoning
How this is scored

Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

0 — One regime, hard-coded; anything else is "on the roadmap".

3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.

5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.

8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.

10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.

Report an error

The External DPO

GDPR plus the German specifics my clients actually face — BSIG reporting duties and the Bavarian authority's questionnaire — and the EU AI Act conformity checks run in the same system with risk classification of AI systems, refreshed by roughly monthly updates. That is real one-record-many-regimes work for GDPR plus AI Act. I found no public information on UK GDPR, Swiss nDSG or ePrivacy coverage, so cross-regime mapping beyond that pair is not evidenced. 2 7 2 15

Report an error

The In-House Counsel

Coverage is Germany-anchored but genuinely one-record-many-regimes: the GDPR record carries the EU AI Act conformity checks and risk classification in the same system, breach incidents emit both Article 33/34 notifications and the German NIS2 reports under a single deadline status, and Schrems II transfer impact assessments and the Bavarian supervisory questionnaire are generated from the same data. Roughly monthly, automatically distributed updates are visible maintenance of a living product. I found no public information on Swiss, UK or other national privacy regimes, so beyond the German-speaking EU this is partial coverage. 2 7 20 23 3

Report an error

The Drafted Generalist

For a German buyer this goes deep: GDPR plus the BayLDA questionnaire at the push of a button, BSIG notification duties in the breach templates, an HinSchG whistleblower module, and EU AI Act conformity checks in the same system as the GDPR record, with roughly monthly updates as visible maintenance. Beyond that home market, I found no public information on Swiss nDSG, UK GDPR or ePrivacy operationalization, and the one-record-many-regimes mapping is really GDPR-plus-AI-Act rather than broad coverage. 2 2 1 23

Report an error

The Lead Auditor

The GDPR stack is deep and German in flavor — the register, breaches under Art. 33/34 alongside German BSI reporting duties, Art. 35 assessments including Schrems II transfer analysis, and the Bavarian supervisory authority's questionnaire at the push of a button — with EU AI Act risk classification running in the same system and roughly monthly updates as the visible maintenance cadence. One record therefore serves two regimes for the home market. We found no public information on Swiss, UK or ePrivacy regime support. 15 2 18 23 7

Report an error

The IT Integrator

GDPR is the backbone with real German depth — the BayLDA questionnaire at a button push and BSIG reporting templates — and EU AI Act risk checks run in the same system as the GDPR record. Beyond that the picture thins: I found no public information on Swiss or UK regime mapping, so additions read as content packs rather than one record across regimes. 15 2 23 7

Report an error

The Skeptic

GDPR is deep and the German specifics are real — the BayLDA questionnaire generates at a button press, BSI reporting templates ship with the breach module, and EU AI Act risk classification runs in the same system as the GDPR record. We found no public information on UK GDPR, Swiss FADP or ePrivacy, and no evidence that one processing activity maps across regimes rather than living in a GDPR-centric world with content packs of varying depth. 2 23 2 20

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The External DPO

Every approval produces an immutable revision with SHA-256 integrity checks and colour-coded comparison — a fixed state of the documentation at any point in time — and an automatic activity log records each change with timestamp and user. The audits module spans planning through follow-up with the preeco catalog included and BSI IT-Grundschutz, CISIS12 and VdA ISA as paid add-ons, reports export as PDF, DOCX and XLSX, and specialized data protection officer reports evaluate across tenants. I found no public information on evidence attachments collected per activity, so a full audit file still means assembly work. 22 23 16 7

Report an error

The In-House Counsel

Defensibility is engineered in: every approval freezes an immutable revision, SHA-256 checksums expose any later manipulation, and the vendor advertises a fixed state of the documentation for any point in time — the answer to 'show me the state on date X'. Status reports, procedure files per processing activity and the Bavarian authority questionnaire generate at the push of a button, a complete automatic activity log records every change and administrative action with user and timestamp, and a full audit module with prebuilt catalogs and permissions separating answering from managing sits on top. I found no public information on external auditor access roles or scope-assembled evidence packs, which is what separates this from the standing-state ideal. 3 7 23 22 16 18

Report an error

The Drafted Generalist

Status reports, procedure files and the BayLDA questionnaire are push-button, reports can run on a schedule with email notification, and a full audits module with an included data protection catalog even separates who answers from who manages. I found no public information on a point-in-time view across the whole register or continuous status broken down per legal regime. 2 23 2 22

Report an error

The Lead Auditor

Every approval freezes an immutable revision with SHA-256 checksums and color-coded comparison, described as a fixed documentation state at any point in time, and an automatic log records document changes and account administration with timestamp, user and action. Authority and management output is push-button — status reports, procedure files per activity, the Bavarian questionnaire, scheduled cross-tenant DPO reports — and the audits module separates answering from managing. We found no public information on evidence attachments collected per activity or exportable proof bundles, so assembling a full file still looks partly manual. 2 7 18 22 23

Report an error

The IT Integrator

Every approval freezes an immutable revision with a SHA-256 checksum and colour-coded comparison — a defensible fixed state for any past date — and status reports, procedure files and the BayLDA questionnaire generate at a button push, backed by a dedicated audit module whose permissions separate answering from managing. Schedulable recurring reports and a permission-aware dashboard with compliance metrics round it out; I found no public information on auditor-scoped evidence packs bundled into a single export. 7 22 23

Report an error

The Skeptic

Every approval freezes an immutable revision sealed with a SHA-256 checksum and exported as PDF — the captured pages explicitly promise a fixed documentation state at any point in time — backed by an automatic log of every change and admin action with user and timestamp. Status reports, procedure files and the BayLDA questionnaire generate at a push of a button and a full audit module with gap-derived tasks exists; we found no public information on dedicated auditor access roles or pre-assembled evidence packs, which is what separates this from a standing audit state. 3 16 7 22 23

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.

8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.

Report an error

The External DPO

The captured pages state plainly that there is currently no public REST API — the application is conceived as a closed system, with customer-specific endpoints developed only for Private Cloud and On-Premises. What does connect: a Model Context Protocol server that lets AI assistants query processing activities and export revisions, an optional DeepL integration, DOCX/XLSX import and export, and SAML2 single sign-on on the premium hosting variants. I found no public information on directory import, ticketing or HR connectors, or webhooks, which for feeding a real client estate is the daily toil I bill against. 15 24 2 2

Report an error

The In-House Counsel

The vendor describes the application as a closed system with no public REST API, developing customer-specific endpoints only for Private Cloud and On-Premises; I found no public information on directory import, ticketing or HR connectors, webhooks or SCIM. What the pages do show: structured DOCX and XLSX import of existing registers, embeddable web forms via HTML snippet, a Model Context Protocol server that lets an AI assistant query activities and export revisions under application access rights, optional SAML2 single sign-on on the higher hosting tiers, and AI drafting that must pass review and approval before entering documentation. Automation is reminders, recurrence and scheduled reports rather than a live feed from the IT estate. 2 15 24 3 2 12

Report an error

The Drafted Generalist

The honest headline for my IT colleagues: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints only on Private Cloud or On-Premises — and single sign-on via SAML2 likewise only on those variants. What it automates, it automates well: deadline clocks, recurring reports, automatic revisioning, name-matching that links contracts to data recipients, and an MCP server that lets an AI assistant query records under the application's own permissions. I found no public information on directory import from AD or Entra, ticketing connectors or webhooks. 2 15 24 17

Report an error

The Lead Auditor

The vendor's own pages describe a closed system with no public REST API — custom endpoints are developed only for Private Cloud and On-Premises — and standard-tier data exchange is DOCX/XLSX import against PDF/DOCX/XLSX export, with legacy migrations run as individual projects. Above a pure file island sit an MCP server letting external AI assistants query processing activities and export revisions under application access rights, embeddable intake forms, DeepL translation, and SAML2 single sign-on restricted to the upper hosting variants. We found no public information on directory import, ticketing or HR connectors, webhooks, or user provisioning sync. 3 15 24 2

Report an error

The IT Integrator

This is the make-or-break lens for me: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints developed only for Private Cloud and On-Premises, and data exchange via DOCX/XLSX import — a file drawbridge, not a sync. The token-authenticated MCP server genuinely lets external assistants query processing activities and export revisions under application access rights, and SAML2 single sign-on exists but is gated to the private hosting variants; I found no public information on directory import, webhooks or ticketing connectors. 2 15 24 2

Report an error

The Skeptic

The vendor states plainly that the application is designed as a closed system without a public REST API, with custom endpoints developed per customer only on Private Cloud and On-Premises. The live touches that do exist — an MCP server for AI assistants under token control, SAML2 single sign-on on two hosting variants, embeddable web forms and optional DeepL — sit above pure import-and-export, but we found no public information on directory import, ticketing or HR connectors, webhooks or SCIM. 2 24 15 2

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The External DPO

A German entity in Ulm, hosting exclusively in ISO-27001 datacenters of Hetzner in Nuremberg and Falkenstein, no transfers to third countries, a published data processing agreement with downloadable TOMs and two weeks' written notice on subprocessor changes, and named processors Hetzner in Germany and UpCloud in Finland. Development, operations and support sit in Germany, with an on-premises variant for public sector and enterprise. I found no public information on the ownership structure, which keeps me just short of a fully clean bill. 5 15 6 10

Report an error

The In-House Counsel

The compliance record lives under German law end to end: a German entity in Ulm, hosting exclusively in the named Hetzner data centers in Nuremberg and Falkenstein, the vendor stating no transfer of personal data to third countries, and a published data processing agreement with downloadable TOMs and two weeks' written notice of subprocessor changes. The hosting subprocessors named on the vendor's privacy policy are Hetzner in Germany and UpCloud in Finland, on-premises is available where data may never leave the customer's datacenter, and the AI functions are off by default and can run against the customer's own endpoint. I deduct for the undocumented ownership structure and because the same privacy policy concedes that transfers to the US parent companies of LinkedIn, Google and X are not excluded for the vendor's own website. 5 15 9 10 6 9

Report an error

The Drafted Generalist

A German entity, hosting exclusively in named ISO-27001 data centers at Hetzner in Nuremberg and Falkenstein, a published DPA with downloadable TOMs, deletion certified on contract end, and AI off unless I bring my own key — that is a chain I can explain to our managing director in one breath. I found no public information on the vendor's ownership, and the privacy policy names UpCloud in Finland as a host of the software alongside Hetzner, so the captured pages give different pictures of the hosting chain; a standalone public subprocessor list was also not evident to me. 5 3 15 10 6

Report an error

The Lead Auditor

A German company in Ulm hosts Cloud and Private Cloud exclusively in named Hetzner data centers in Nürnberg and Falkenstein, offers on-premises, publishes its Art. 28 contract with two-week subprocessor change notice and downloadable technical and organizational measures, and states no third-country transfer of product data; AI features are off by default and run on customer-held keys. The privacy notice additionally names UpCloud Oy of Finland as a hosting subprocessor, so the captured pages give different pictures of where hosting occurs, though both named providers sit inside the EU. Ownership structure is not publicly documented, which is what keeps this short of the cleanest band. 5 6 10 15 3

Report an error

The IT Integrator

A German entity in Ulm hosts exclusively in named Hetzner datacenters in Nürnberg and Falkenstein with no third-country transfers stated, publishes its order-processing contract with downloadable TOMs and two weeks' notice on subprocessor changes, and the named hosting subprocessors (Hetzner, and UpCloud in Finland) all sit inside the EU. On-premises exists but is positioned for public sector and enterprise, and I found no public information on the ownership structure, so the cleanest end of the scale stays out of reach. 6 9 10 15

Report an error

The Skeptic

A German company hosts exclusively in named Hetzner data centers in Nürnberg and Falkenstein, publishes its DPA and downloadable TOMs, and names its subprocessors — Hetzner in Germany, UpCloud in Finland, both EU — with AI switched off by default and no third-country transfer claimed for platform data. We found no public information on ownership, and the on-premises route is described as typically reserved for the public sector and enterprise, which leaves the top anchor out of reach. 5 6 10 9 21

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.

Report an error

The External DPO

I found no price figures at all — the license is said to scale by employees, modules and hosting variant, expressly not by the number of organizations, with no setup fees and no cancellation periods, but the actual invoice remains a sales conversation. For budgeting thirty mandates, knowing the licensing dimensions and that extra organizations cost nothing is genuinely useful; the absence of any published number is what the score reflects. 2 3

Report an error

The In-House Counsel

I found no public price figures at all; the license is described only as scaling with employees, modules and hosting variant — usefully never with the number of organizations managed, which matters to a group or a consultancy. The vendor does state there are no setup fees and no cancellation periods and that every GDPR obligation ships without add-on modules, but premium support, the DeepL integration, the optional audit catalogs and data migration are all optional and chargeable with no numbers anywhere, and even the FAQ treats premium support costs as an open question. The real invoice is therefore a sales conversation. 2 3 7 15 8

Report an error

The Drafted Generalist

The model is at least published in words — license by employees, modules and hosting variant, not per organization, with no setup fees and no cancellation periods, and every GDPR obligation claimed included without add-on modules. But I found no public prices at all, not even an entry figure, so I cannot budget even a rough annual number for an 80-person company without booking the 30-minute demo and having the sales conversation. 2 7 20

Report an error

The Lead Auditor

Not one price figure appears on the captured pages: the license is described as scaling with employees, modules and hosting variant, with no setup fees and no cancellation periods, but the real invoice is not computable without a sales conversation. One page promises all GDPR obligations without add-on modules or hidden surcharges, while other captures list optional paid items such as audit catalogs, DeepL translation, premium support and migration projects. We found no public information on entry pricing, per-module figures or scale steps. 3 15 2 7

Report an error

The IT Integrator

No price figures appear anywhere on the captured pages — the licence basis is described as employees, modules and hosting variant (explicitly not the number of organisations) and the no-setup-fees, no-cancellation-terms posture is stated, but the actual invoice is only a sales conversation. Optional paid items such as the ISMS audit catalogs, DeepL translation, premium support and migration are named without figures. 2 7 22

Report an error

The Skeptic

We found no public price figures of any kind; the license is described only as scaling with employees, modules and hosting variant, so the invoice remains a sales conversation. The no-setup-fee and no-cancellation terms are published, and audit catalogs (BSI IT-Grundschutz, CISIS12, VdA ISA) as well as DeepL, premium support and migration are listed as optional paid additions; without a single number published, no configuration is computable. 2 7 2 3

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (25)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 15 Sep 2026, 31 Aug 2026, 24 Aug 2026 Details →
  2. 2 Data protection product page www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 16 Sep 2026, 15 Sep 2026, 31 Aug 2026 Details →
  3. 3 Information security product page www.preeco.de Checked 5 Oct 2026 +4 earlier captures: 16 Sep 2026, 31 Aug 2026, 24 Aug 2026, 23 Aug 2026 Details →
  4. 4 About page www.preeco.de Checked 5 Oct 2026 Details →
  5. 5 Imprint www.preeco.de Checked 5 Oct 2026 Details →
  6. 6 Privacy policy www.preeco.de Checked 5 Oct 2026 Details →
  7. 7 GDPR software page www.preeco.de Checked 5 Oct 2026 +4 earlier captures: 16 Sep 2026, 11 Sep 2026, 31 Aug 2026, 24 Aug 2026 Details →
  8. 8 Product documentation library www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 15 Sep 2026, 31 Aug 2026, 24 Aug 2026 Details →
  9. 9 Hosting variants page www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 16 Sep 2026 Details →
  10. 10 Published DPA (AVV) for cloud customers www.preeco.de Checked 5 Oct 2026 Details →
  11. 11 Multi-entity use case page www.preeco.de Checked 5 Oct 2026 Details →
  12. 12 AI-assisted GDPR use case page www.preeco.de Checked 5 Oct 2026 Details →
  13. 13 MFA documentation www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 15 Sep 2026 Details →
  14. 14 Access rights system documentation www.preeco.de Checked 5 Oct 2026 Details →
  15. 15 Full product specification (Leistungsbeschreibung) www.preeco.de Checked 5 Oct 2026 Details →
  16. 16 Records & DPIA depth — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  17. 17 Records & DPIA depth — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  18. 18 Data subject rights & incidents — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  19. 19 Data subject rights & incidents — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  20. 20 Privacy regime coverage — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  21. 21 Privacy regime coverage — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  22. 22 Audit readiness & evidence — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  23. 23 Audit readiness & evidence — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  24. 24 Integrations & automation — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
  25. 25 Integrations & automation — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →