preeco | data protection
GDPR-compliant data protection management for professional documentation and process control. Manage processing activities, data subject requests, data breaches and TOMs centrally – with AI-assisted text support, threshold analysis and TIA for third-country transfers. Multi-tenant, available in 25 languages, auditable and hosted in ISO 27001-certified data centers in Germany (Cloud and Private Cloud), optionally as On-Premises in your own data center – with no third-country transfers.
Trusted by these companies – and many more
Processing
Processing Activities and Systems
Run your record of processing activities under Art. 30 GDPR as an ongoing process – not a document you write once, but one that is continuously maintained and always audit-ready. Systems, information obligations and processing activities stay centrally linked and permanently up to date.
Processing Activities
Complete documentation in accordance with Art. 30 GDPR with AI-assisted content completion for individual sections and legally reviewed templates. Existing records can be imported as DOCX or XLSX; the AI can also draft new processing activities from a free-text description of the task – shown in a preview for your review before you adopt them. Structured form with legal bases, data categories, recipient details and deletion periods.
Processing Activities on Behalf
Recording and documentation of processing activities carried out on behalf of third parties – with a structured form covering responsibilities, description of processing, data transfers and TOMs. Record of processing activities as report (PDF, DOCX), protection needs assessment via the damage scenario matrix, AI-assisted completion of individual sections and the "Contract relationships" section with data recipients and covering agreements – in combination with the Contract Management module.
Data Processing Systems
Central management of all deployed systems with provider details, data categories and TOM links. Display of assigned processing activities. Optional determination of protection needs for confidentiality, integrity and availability via a damage scenario matrix based on the maximum principle – manual or AI-supported.
Information Obligations
Documentation of information obligations under Art. 13 and 14 GDPR. Automatic revisioning and display of relationships to other documents.
Security Measures and Policies
Keep policies and technical and organizational measures continuously current and effective. TOMs stay directly linked with processing activities and contracts – reviewable, versioned and demonstrable at any time.
Policies
Central storage and management of all relevant policies. Linking with other documents and complete activity log for full traceability.
Technical and Organizational Measures
Documentation and versioning of TOMs with AI-assisted content completion and automatic revisioning. Linking with processing activities and contracts – always audit-ready.
Contracts
Contract Management
Manage data processing agreements, consent declarations and joint controller agreements – with an online signature workflow and status tracking, structured and legally compliant.
Data Processing Agreements
Central management of all DPAs in accordance with Art. 28 GDPR. Easy generation of contract drafts using text modules. Online signature workflow with any number of signatories per contract party and reminders for pending signatures, status tracking and automatic revisioning. Sub-processor lists are maintained centrally and rolled out across any number of contracts – including a prepared notice to your contract partners. preeco's reviewed template DPA is available at www.preeco.de/avv.
Consent Declarations
Creation and documentation of consent declarations. Automatic revision tracking of all versions with complete activity log.
Joint Controllership
Documentation of joint controller agreements under Art. 26 GDPR. Online signature workflow and automatic linking with data recipients in processing activities. The "contract relationships" section shows linked processing activities, processing activities carried out on behalf of a controller and data processing systems – links are retained during automatic assignment. Automatic revisioning of approved documents.
Training
Training and Qualification
Plan, conduct and document data protection training for your employees. Templates for GDPR (including a public-administration variant), AI competency, IT security and home office are included. Participation is automatically tracked and certified as PDF.
Training
Creation and management of data protection training courses. Revision-proof documentation of training content, results and participation.
Training Participation
Recording and documentation of all training participation. Overview of the training status of all employees at a glance. Certificates of participation as PDF.
Training Templates
Pre-built training templates for GDPR, AI competency, IT security, and home office – including certificates of participation and part of the package. Customizable to your organization-specific requirements and ready to use immediately.
Data Protection Deletion Concept
Create and manage deletion concepts for all processing activities. Define deletion periods and document compliance traceably.
Deletion Concepts
Structured creation and management of deletion concepts: define deletion classes, link them to processing activities and derive deletion rules with deadlines, deletion procedures, and responsibilities. The task log documents the actual execution – traceable documentation and export as complete evidence for audits and supervisory authorities.
Subject Requests and Incidents
Process all request types under Art. 15–22 GDPR on time and document data breaches in a structured manner. Receive requests via embeddable web forms; deadlines are automatically monitored.
Data Subject Requests
Efficient processing of all request types under Art. 15–22 GDPR – access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and other. Respond via email directly from the system.
Data Breaches
Structured documentation of data breaches including notification obligations under Art. 33/34 GDPR, measures and graphical risk mapping.
Audits
Audits and Audit Catalogs
Plan, conduct and document data protection audits in a structured manner. Use ready-made catalogs – the preeco Audit Catalog Data Protection, BSI IT-Grundschutz, CISIS12 and VdA ISA – or create your own questionnaires.
Audit Catalogs
Pre-built and individually customizable questionnaires as a basis for your audits. The preeco Audit Catalog Data Protection is included; BSI IT-Grundschutz, CISIS12 and VdA ISA additionally provide ready-to-use catalogs for German specialist standards (optional, paid add-ons). Structured, reusable and deployable across tenants.
Audits
Structured execution and traceable documentation of data protection audits. Results are traceable at all times and exportable.
Risk Analysis and Impact Assessments
Assess risks systematically and conduct data protection impact assessments in accordance with Art. 35 GDPR in a guided and structured manner.
Data Protection Impact Assessments
Structured execution of DPIAs under Art. 35 GDPR. The AI additionally suggests the assessment of necessity according to Art. 35 para. 1 GDPR, a structured risk catalogue and appropriate countermeasures. Guided process covering all legal requirements. Automatic revisioning of all approved documents.
Risk Analyses
Structured documentation of risks with graphical risk mapping. Recording of risk mitigation measures with responsible persons and deadlines.
Websites
Privacy Policies
Create and maintain privacy policies and notices for your websites. The integrated editor and numerous text modules significantly accelerate the creation process.
Privacy Policies
Integrated editor with automatically numbered sections. Publication via direct link to the current revision or embedding in the website.
AI Regulation
Review the use of AI systems for compliance with the EU AI Act – GDPR and AI Act compliance in one system. Classify AI systems by the risk classes of the regulation, keep a dedicated register of your AI systems and document technical and organizational measures for AI applications.
AI Compliance Reviews
Systematic review of deployed AI systems against the requirements of the EU AI Act. Structured form with all relevant checkpoints.
AI Technical and Organizational Measures
Documentation of TOMs specifically for AI applications. Linking with affected systems and processing activities. Automatic revisioning.
Reporting and Activities
Create comprehensive status reports and keep track of all activities. Complete documentation of all changes for maximum transparency.
Activities
Automatic log of all document changes. Full traceability with timestamp, user and action performed – for audits and compliance evidence.
Reports
Status reports with details on all documents and automatically generated table of contents. Process files for individual processing activities can be created.
Features
Collaboration and Task Management
Manage tasks, checklists, files and messages centrally in one place. All participants keep an overview – thanks to the dashboard and follow-ups.
Tasks
Create and assign tasks directly within documents. The dashboard shows all open tasks at a glance. Email notifications ensure timely action.
Checklists
Multiple-choice checklists for quality assurance. Use template checklists or create your own. Results exportable as PDF or DOCX.
File Storage
Central upload and structured storage of documents. Tags and nestable folders simplify organization. Files optionally shareable via public URL.
Data collection forms
Reusable data collection workflows: multi-page questionnaires with conditional pages and questions. Actions stored for each answer create documents or tasks on release. Assign forms to users or send them by email to external persons.
Contacts
Central creation and maintenance of all relevant contacts via a structured form. Filterable, tabular overview with links to processing activities, contracts and other documents. Including activity log, tasks and follow-ups.
Messages
Internal communication directly in the system. Attach files, email notifications for new messages. Complete tracking of all communication.
Surveys
Create your own surveys with various question types. Evaluation and download as PDF or DOCX. Usable independently or linked to documents.
Follow-ups
Scheduled reminders for all due tasks. Observers are automatically notified. No deadline is missed.
AI Functions
AI-assisted enrichment and revision of content in processing activities, processing activities on behalf, policies, TOMs, incidents, privacy statements as well as data protection impact assessments (DPIA) and data transfer impact assessments (TIA) – including threshold analysis for processing activities. Multi-edit in overviews for efficient work. OpenAI-compatible LLM provider integration with flexible provider selection – via a selection list of the models available at the provider or free entry of a model name. Selectable generation mode – automatic, deterministic, or reasoning in three levels; higher reasoning levels deliver more considered content but take longer. A connection test on saving checks the selection against the configured model. In addition, all AI activities are logged in a traceable protocol with function, executing person, model, status, duration and token usage.
DeepL Integration
Automatic translation of document content into all 25 languages via the DeepL API – optional add-on, used with your own DeepL API key. Professional translation quality for international reporting.
One platform for data protection and information security
Data protection and information security on one shared platform: with both products licensed, switch your working environment between the data protection and information security views with a single toggle.
Highlights
More Highlights
In addition to the core features, preeco | data protection offers a range of additional features that noticeably simplify your daily data protection work – from automated text support and embeddable forms to direct publication of legally relevant content.
Text Modules
Numerous relevant, legally reviewed text modules included. Create, maintain and share your own modules for all organizations or selectively.
True Multi-Tenancy & Whitelabel
Strict tenant separation for external data protection officers, compliance consultants and group structures. Per-tenant settings, documents, users and roles. Switch between organizations with a single click via the organization selector; on Private Cloud and On-Premises, multiple teams can be operated on one platform with physical separation. Whitelabel with your own logo, your own domain and individual document branding.
Form Widgets
Configurable web forms for website or intranet – for data subject requests, data breach reports, custom message forms, consent declarations and DPA signing. Easy to embed via HTML snippet, entries are captured directly in the system.
Publication Features
Publish information obligations and privacy policies directly from the system – via direct link to the current revision or embedded on the website. Always up to date, always traceable.
Global Search & Customizable Overviews
System-wide search, accessible from any view via the ⌘/Ctrl + K keyboard shortcut. Overview tables can be customized individually – column order and width are saved per view.
Custom API Endpoints
The application is designed as a closed system without a public REST API. On the Private Cloud and On-Premises hosting variants, custom API endpoints are developed and provided for your integration scenarios.
Designed for Accessibility
Keyboard operability, semantically structured HTML, sufficient contrast – checked in both light and dark display –, scalable font sizes, usability on narrow screens including the public training and response pages, and alternative texts for graphics. Accessibility is continuously reviewed and improved. Read our accessibility statement
Confidentiality Classes
Optional confidentiality classes for documents – controllable per user group and fully disableable for individual user groups. Decide precisely which user group may access sensitive content. The display of the implementation status on documents is also enabled per user group (disabled by default).
Web-Based, No Installation
Access via any modern web browser – no local installation required. All data transmissions are SSL/TLS encrypted, daily backups with off-site storage provide additional protection.
Multi-Level Permission Concept
Granular rights at module, document and function level via freely definable user groups. Single Sign-On (SAML2) additionally available in Private Cloud and On-Premises.
Privacy by Design and by Default
Data minimisation through structured capture of only the necessary data, default settings at the highest level of data protection, an integrated rights and roles concept, and traceable AI use via a dedicated log of all AI activities.
Customer Testimonial
What Our Customers Say
Three Hosting Options – up to On-Premises in Your Own Data Center
Cloud and Private Cloud are operated exclusively in ISO 27001-certified data centers in Germany – with no transfer of personal data to third countries. On-Premises gives you full data sovereignty.
Cloud Hosting
RECOMMENDEDStandard multi-tenant solution with fast setup. Ideal for getting started right away.
Private Cloud
Dedicated instance with custom domain, optional own mail server and optional Single Sign-On (SAML2) – multiple teams can be operated on one platform with physical separation. For companies with advanced requirements.
On-Premises
Installation in the customer's own data center. Maximum control and data sovereignty. Optional Single Sign-On (SAML2).
Cloud and Private Cloud options are hosted in ISO 27001-certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein). The data centers run on 100% green electricity. Daily backups with 7-day retention, AES-256 encrypted as password-protected archives, and daily off-site backup at the Hetzner Falkenstein data center. Guaranteed availability: 99.0% per calendar month. Deployment of Cloud and Private Cloud within 48 hours (business days). No setup fees and no cancellation periods. All data transmissions are continuously SSL/TLS-encrypted. Personal data is not transmitted to third countries.
Support
Deployment, Support & Service Level
Deployment within 48 hours (business days), guaranteed availability of 99.0% per calendar month, personal assistance and committed response times by priority – from onboarding to daily operations.
Fixed Service Hours
Our support team is available Monday to Friday from 9:00 a.m. to 5:00 p.m. in German and English (except on public holidays in Germany) – via email, ticket system and, subject to availability, online chat. Phone and video-conference support can be added as optional premium support.
Guaranteed Response Times
Clearly defined response times by priority: in the Private Cloud from 2 business hours for critical incidents to 3 working days for general inquiries, in the Cloud from 4 business hours to 5 working days. For Private Cloud, extended 24/7 on-call availability can be booked as an option. If response times are not met, a multi-level escalation process applies, up to executive management.
Deployment within 48 Hours
Cloud and Private Cloud instances are provisioned within 48 hours (on working days); On-Premises installations by individual agreement. Get started without long lead times.
Updates without Downtime
The software is generally available 24/7. Updates are rolled out automatically about once a month without downtime; security updates are applied at short notice when needed. After each update, a pop-up in the application transparently shows the changes made. Longer maintenance work is announced in advance.
Onboarding and Training
A dedicated contact person accompanies your onboarding: setup of the organizational structure, configuration of user groups and permissions, and individual adjustments such as corporate design and email templates. Data migration and training are optionally available.
Interfaces and API
The application is designed as a self-contained system; a public REST API is currently not available. For Private Cloud and On-Premises variants, customer-specific API endpoints can be developed and provided.
Security Testing and Code Reviews
Regular internal penetration tests, continuous monitoring with prompt security updates, and recurring code reviews keep the application continuously hardened.
Network Security
All systems are protected by a firewall, safeguarded against DDoS attacks at a basic level, and operated in segmented networks. System availability is continuously monitored (Cloud and Private Cloud).
Get Started Now
In 30 minutes, we'll show you how preeco | data protection simplifies your compliance routine.
FAQ
Frequently Asked Questions
You will receive your login credentials by email after registration. Go to the login page and enter your email address and password. If you have any issues, contact our support at support@preeco.de or +49 731 280 651 0.
Navigate to the "Processing Activities" module and click "New Processing Activity". The structured form guides you step by step through all required fields. Text modules and templates significantly simplify documentation. A detailed guide can be found in our user manual.
Yes, preeco | data protection is multi-tenant capable. As an external data protection officer, you can manage multiple tenants centrally in one system. Each tenant has its own settings and documents. Switching between tenants is done with a single click. More information can be found in the user manual in the "Tenant Management" section.
Data subject requests can be recorded and processed via the "Data Subject Requests" module. The system automatically monitors statutory deadlines and reminds you in time. The processing workflow is fully documented. Response templates speed up the handling process.
The "Online Training" module enables the delivery of online training courses directly in preeco | data protection. Training courses consist of learning units (image or video content) and exam questions (multiple-choice, single-choice) with a freely adjustable minimum score for certification. You can use existing templates or create your own training courses.
Included training templates cover GDPR training for companies and public administration, AI competency training, and IT security awareness for employees, among others. Participants can be added manually or imported via XLSX. After passing the exam, they receive a certificate of participation as PDF. You can view the training progress of all participants at any time in the tabular overview.
Because the GDPR requires continuous, provable documentation – a record written once is not enough. preeco | data protection keeps processing activities, TOMs, contracts, incidents, and training centrally linked, versions every approval as an immutable revision, and automatically logs all changes. Status reports, case files for individual processing activities, and even the BayLDA questionnaire can be generated at the push of a button.