Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

weclapp

VéRIFIé
CRM · Germany
Founded 2008 · weclapp.com ↗

German cloud ERP + CRM (weclapp SE), Frankfurt and Karlsruhe data centres, ISO 27001/27018/27701, banking-grade encryption.

Pourquoi ce score ?

German Societas Europaea (weclapp SE) running customer ERP/CRM data exclusively on a Frankfurt data centre with Karlsruhe backup, both certified ISO 9001/27001/27018/27701/22301/20000-1/PCI-DSS/CSA STAR/SSAE16 — no public hyperscaler used for customer business data — and US sub-processors limited to marketing-site analytics, chat, and HR (Google, Microsoft, Intercom, Meta, LinkedIn) under SCC; score sits at 4/5 because a public DPA URL was not resolvable at audit and the chat sub-processor (Intercom, US) sees some product-UI data.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About weclapp

weclapp is a German cloud ERP + CRM platform operated by weclapp SE — a Societas Europaea legal form adopted to support international expansion — with offices in Frankfurt am Main, Marburg, Kitzingen, and Karlsruhe. Founded in 2008, the platform combines CRM, sales pipelines, quotations, invoicing, accounting, project management, and full inventory/warehouse management for SMBs and mid-market companies, with strong integrations into German marketplaces, payment providers, and shipping platforms (Amazon, eBay, Shopify, etc.). The product has won "ERP-System des Jahres" multiple times and is positioned as the first German cloud ERP with TÜV-certified data protection. For procurement-grade EU buyers the hosting story is among the strongest in this directory. Customer ERP/CRM data is stored exclusively on a Frankfurt am Main data centre with a Karlsruhe backup; both facilities carry an exceptional certification stack (ISO 9001, ISO 27001, ISO 27018, ISO 27701, ISO 22301, ISO 20000-1, PCI-DSS, CSA STAR CCM v4.0, SSAE16 / ISAE3402). No US-owned hyperscaler sits in the customer-data path. The privacy policy (last updated September 2024) names sub-processors transparently; the US-resident ones — Google, Microsoft, Intercom, Productboard, Meta, LinkedIn — are scoped to marketing-site analytics, advertising pixels, customer chat, and product roadmapping rather than customer business records, with SCCs cited under Art. 46 GDPR for any onward transfers. Brevo (FR) handles newsletters and Personio (DE) handles application data. Pricing in EUR: ERP Starter €39/user/month, ERP Services €86/user/month, ERP Trade €163/user/month, Enterprise custom for 10+ licences. A 30-day free trial requires no credit card and auto-cancels. Best fit: German and DACH SMBs and mid-market companies that need an integrated ERP + CRM with explicit German data residency, multi-ISO certifications, and broad e-commerce-marketplace integrations. The lack of an obvious public DPA URL is the primary friction for a fully procurement-grade buyer — request the AVV directly and confirm the Frankfurt / Karlsruhe DC contractual commitments before signing.
SUB-PROCESSORS

Carte des sous-traitants · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Référentiels & certifications

ISO/IEC 27001
ACTIVE
ISO/IEC 27018
ACTIVE
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Tarifs & paliers

PAYANT
à partir de €39/mois
Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

  • Data Processing Addendum (DPA)
    www.weclapp.com/en…
    Open ↗
  • Sub-processors list
    www.weclapp.com/en…
    Open ↗
ALTERNATIVES

Alternatives dans cette catégorie