Skip to main content
For DPOs & Privacy Teams

AI-enabled GDPR compliance that never leaves the EU

Manage records of processing, data subject requests, breaches, DPIAs and TIAs in one auditable platform – AI-assisted, multi-tenant and hosted in ISO 27001-certified data centers in Germany. No third-country transfers. Built with DPOs, for DPOs.

Hosted in Germany
ISO 27001 Data Center
No Third-Country Transfers
GDPR-compliant
app.preeco.de

Trusted by these companies – and many more

fischerwerke GmbH & Co. KG Scheer GmbH TÜV NORD Mobilität Dussmann Group Komm.ONE A.d.ö.R Eckes-Granini Deutschland GmbH dfv Mediengruppe

Why preeco

Why privacy teams choose preeco

GDPR documentation costs time, nerves and money. preeco automates the most tedious tasks – without your data ever leaving the EU.

Book a Demo

Data stays in the EU

ISO 27001-certified data centers in Germany, 100% green energy – no third-country transfers.

Audit-proof by design

Export revisions as PDF – with SHA-256 integrity checks and colour-coded revision comparison, for permanent, historic auditability and a fixed record of your documentation at any point in time.

AI on your terms

Optional, OpenAI-compatible and self-hostable. Your data, your choice – off by default.

Automatic deadline tracking

Data subject requests, breach notifications and deletion deadlines – no deadline is ever missed.

Multi-tenant for external DPOs

Manage all clients centrally – switch between them with a single click.

All GDPR-relevant functions included

Every GDPR obligation covered in one platform – no add-on modules, no hidden extras. Provisioned within 48 hours on business days, with no setup fees and no cancellation periods.

Built for cross-border teams

Interface and documents in 25 languages, English included – with optional DeepL translation. Keep your EU and UK entities side by side in one system.

Platform

One platform for the entire GDPR lifecycle

From the first record to the supervisory authority – every GDPR obligation in one system, instead of scattered across spreadsheets and shared drives.

Records of Processing (Art. 30)

Complete documentation of processing activities, systems and information obligations – structured, AI-assisted, and including import of existing records and legally reviewed templates.

Data Subject Requests (Art. 15–22)

Access, erasure and other data subject rights with automatic deadline monitoring and web form integration.

Data Breaches (Art. 33/34)

Structured documentation, 72-hour deadline monitoring and graphical risk mapping for reporting to the supervisory authority. Nine ready-to-use notification templates (Art. 33/34 GDPR, German BSI under Sections 25 and 32 BSIG) with an unambiguous deadline status per notification.

DPIA & TIA (Art. 35 / Schrems II)

Guided data protection impact assessments and transfer impact assessments for third-country transfers – including a Schrems II evaluation.

Contracts & Consent (Art. 28/7)

DPAs, joint controller agreements and consent declarations with an online signature workflow.

TOMs & Policies

Document, version and link technical and organizational measures directly with processing activities and contracts.

Audits & Catalogs

Pre-built questionnaires (preeco catalog included; BSI IT-Grundschutz, CISIS12 and VdA ISA optional add-ons) for structured, traceable reviews.

Training & Certificates

Run online training, track participation automatically and generate certificates as PDF.

Book your 30-minute demo

Pick a time that works for you

We will get back to you within a few hours.

Privacy
Please see our privacy policy.

What to expect from your demo

30 focused minutes, no slide deck. We tailor the session to your team's day-to-day and answer your questions live.

  • A live walkthrough of preeco, tailored to your use cases – not a generic pitch
  • See records of processing, data subject requests, breaches and DPIA/TIA in one place
  • Straight answers from a privacy expert on hosting, AI, migration and pricing
  • Bring your toughest GDPR questions – we'll address them on the call
  • No obligation and no sales pressure – just a clear picture of whether preeco fits

Customer Testimonial

fischerwerke relies on preeco | data protection

Referenz

By using preeco | data protection, we were able to quickly achieve significantly better data quality while also considerably increasing the efficiency with which the companies and departments of the fischer Group collaborate on data protection.
fischerwerke GmbH & Co. KG

Jonathan Haist

IT Security Manager

fischerwerke GmbH & Co. KG

Made and hosted in Germany

Development, operations and support in Germany – backed by independent certifications and professional memberships.

ISO 27001 Zertifizierte Rechenzentren Software Made in Germany Cloud Services - Made in Germany Berufsverband der Datenschutzbeauftragten Deutschlands e.V. Bundesverband IT-Mittelstand e.V. 100% Ökostrom im Rechenzentrum

FAQ

Frequently Asked Questions

In ISO 27001-certified data centers operated by Hetzner Online GmbH in Germany (Nuremberg, Falkenstein), running on 100% green energy. Daily backups with off-site storage and a guaranteed availability of 99.0% per calendar month.

No. Your data never leaves the EU. For any transfer you assess yourself, a built-in Transfer Impact Assessment (TIA) including a Schrems II evaluation is available.

The AI features are optional and off by default. preeco uses an OpenAI-compatible interface – you freely choose your provider or self-host the model. The platform works fully without AI.

Yes. preeco | data protection is available as Cloud, as a Private Cloud with your own domain and Single Sign-On (SAML2), and as an on-premises installation in your own data center – for maximum control and data sovereignty.

Yes. preeco is fully multi-tenant. External data protection officers manage all clients centrally in one system; each client has its own settings and documents, and you switch between them with a single click.

If you offer goods or services to people in the EU, or monitor their behaviour, the GDPR applies to you no matter where your company sits (Art. 3(2)) – including records of processing, data subject requests, 72-hour breach notification and DPIAs. Those obligations are exactly what preeco documents. Controllers outside the EU usually also have to appoint an EU representative under Art. 27. preeco is not that representative – it is the system your documentation lives in, and it produces the structured exports your representative or a supervisory authority will ask you for.

For the documentation, yes. The UK GDPR keeps the same core instruments as the EU GDPR – records of processing, data subject rights, 72-hour breach notification and DPIAs – so the structures you build in preeco carry across unchanged. If you fall under both regimes, preeco is multi-tenant: your EU and UK entities sit side by side in one system, each with its own records and settings, and you switch between them with a single click.

Yes. The interface and your documents are available in 25 languages, English included, and the same record can be maintained in more than one language. An optional DeepL integration translates existing content at professional quality – useful when a German subsidiary documents in German while group compliance reports in English.

Yes. preeco | data protection brings every GDPR obligation together in one system – with no add-on modules or hidden surcharges. Legally reviewed text modules and templates, optional AI assistance for filling in fields, and a built-in training module relieve staff who handle data protection alongside their main role. Cloud instances are set up within 48 hours (on working days), with no setup fees and no cancellation periods.

A complete solution covers the entire GDPR lifecycle: the record of processing activities under Art. 30, data subject requests under Art. 15–22, data protection impact assessments under Art. 35, data breaches under Art. 33/34, data processing agreements under Art. 28, TOMs, a deletion concept, and employee training. preeco | data protection brings exactly these modules together in one system – complete, traceable, and with automatic deadline monitoring for data subject requests and data breaches.

For the mid-market, GDPR software should meet three requirements: cover the entire GDPR lifecycle without add-on modules, be usable without a dedicated data protection team, and support several group companies in a multi-tenant setup. preeco | data protection meets all three: record of processing activities (Art. 30), data subject requests (Art. 15–22), DPIAs (Art. 35), data breaches (Art. 33/34), DPAs (Art. 28), TOMs and a deletion concept in one system – with legally reviewed templates, optional AI assistance for filling in fields, and multi-tenant management for group structures. Cloud instances are set up within 48 hours (on working days), with no setup fees and no cancellation periods.

Instead of spreadsheets and shared drives, preeco | data protection keeps all GDPR evidence in one place: processing activities, systems, TOMs, contracts, incidents and training stay centrally linked and versioned. Every approval creates an immutable revision, and all changes are logged automatically. Existing records can be imported as DOCX or XLSX, and status reports, case files and the BayLDA questionnaire can be generated at the push of a button – keeping your GDPR documentation audit-ready at all times.

For SMEs, what matters is completeness without add-on modules, a low-threshold entry, and traceability for audits: every GDPR obligation in one system, legally reviewed templates instead of blank forms, automatic deadline monitoring (such as the 72-hour deadline under Art. 33 GDPR), immutable revisions and an activity log. preeco | data protection meets these criteria, is multi-tenant capable for several group companies, available in 25 languages, and is hosted in ISO 27001-certified data centers in Germany – with no third-country transfers.

A meaningful comparison asks five questions: Does the software cover the entire GDPR lifecycle – record of processing activities (Art. 30), data subject requests (Art. 15–22), data breaches (Art. 33/34), DPIAs (Art. 35), DPAs (Art. 28), TOMs and a deletion concept – or do modules have to be booked separately? Can it be operated without a specialized data protection team, for example through legally reviewed templates? Is the data hosted in ISO 27001-certified data centers in Germany with no third-country transfers? Are revisions immutable and changes traceable? And how quickly is the software ready to use? preeco | data protection meets all five criteria: every GDPR obligation without add-on modules, legally reviewed text modules and templates, hosting in Germany, immutable revisions with SHA-256 integrity checks, and provisioning within 48 hours on working days – with no setup fees and no cancellation periods.

See preeco on your own use case

In 30 minutes we show you how preeco | data protection simplifies your day-to-day compliance work.