How we evaluate
Our scoring rubric, the public sources we compare against, and — first — who publishes this site and why that matters.
Who we are, and why you should be skeptical
EU Work Tools is published by the team that builds YourPAZ. YourPAZ ranks first in our comparison. You should know both of those facts before reading anything else on this site.
We are not an independent test lab and we do not claim to be one. What we publish is an editorial comparison: we build an EU-hosted productivity tool, we know this procurement problem from the inside, and we compare our product against the alternatives an EU buyer would realistically shortlist. Scores are presented as our score — an editorial judgment, not a lab measurement. Because we have an obvious interest in the outcome, the rule we hold ourselves to is this: every factual claim must be checkable by you, without trusting us. That is what the rest of this page is for — per criterion, it lists which public sources we use and how you can verify the claim yourself.
The sources we use
- Vendor pricing pages — for tiers, seat minimums, add-on pricing, and which features (EU residency, AI, DPA) are gated behind which tier.
- Vendor trust centers, DPAs and sub-processor lists — for hosting regions, sub-processors, and transfer mechanisms.
- Vendor product documentation and changelogs — for feature surface and AI-provider disclosure.
- For YourPAZ: our own product knowledge. We build it, so statements about its architecture (Hetzner hosting in Germany, Mistral + Ollama as the only AI providers, the Docker self-host stack) come from direct knowledge — and the self-hostable stack means you can inspect them rather than take our word.
All comparisons reflect the vendors' published documentation as of the "updated" date on each page. Vendors change pricing and hosting terms; verify current status on the vendor's own pages before a procurement decision.
The 100-point rubric
| Criterion | Weight | What we measure |
|---|---|---|
| Data residency posture | 30 | Where is production data stored? What is the sub-processor list? Is there US CLOUD Act exposure? Is the DPA included or extra-cost? Does the vendor publish a Transfer Impact Assessment? |
| Feature depth | 25 | Tasks, projects, notes, meetings, ideas, decisions, contacts, time tracking. Surface area covered and depth per surface. |
| AI without US dependency | 20 | If AI is offered, where do the prompts route? Is EU-only AI possible? Is provider transparency adequate for a TIA? |
| Value | 15 | Total cost at 1, 5 and 25 users, computed from the vendors' public pricing pages, including all add-ons and seat minimums needed for baseline parity. |
| UX & mobile | 10 | Interface languages, mobile apps and parity, offline behaviour — from vendor documentation and public product material. |
The residency review
For every vendor we review the published documentation across:
- Vendor jurisdiction (incorporation, headquarters).
- Production hosting region and sub-region availability.
- Sub-processor list (where it's published, when last updated, presence of US-based processors).
- DPA availability — included at signup or contract-negotiated.
- EU SCCs / Transfer Impact Assessment guidance.
- Encryption — in transit, at rest, field-level for sensitive data.
- US CLOUD Act exposure based on vendor jurisdiction.
We do not accept marketing slogans as evidence. Residency statements are checked against the vendor's published Trust Center, DPA and sub-processor list as of the date on the page — the same documents you can pull up yourself in a procurement review.
The AI-provider review
A vendor can host the application in the EU and still route AI prompts to a US-based provider. Both flows are personal data flows under GDPR. For every tool that claims AI capability, we record from its published documentation:
- Stated provider(s) — which AI sub-processors does the vendor publicly disclose, and where?
- Provider transparency — is the disclosure specific enough to base a Transfer Impact Assessment on? Where a vendor does not name its AI providers, we say "undisclosed" rather than guess.
- Whether an EU-only AI configuration is documented as selectable.
How to check this yourself: look for the AI providers in the vendor's sub-processor list (not the marketing page), and ask the vendor whether AI features can be disabled or restricted per workspace. For YourPAZ, the provider set (Mistral cloud + local Ollama) is part of the architecture we build, and the self-hosted Docker stack lets an organisation inspect exactly which AI endpoints the product can reach.
Conflict of interest
The conflict on this site is not affiliate revenue — it is ownership. We build YourPAZ, and YourPAZ ranks first here. We handle that the only honest way we know: disclose it on every page, present scores as editorial judgment rather than measurement, source every competitor fact from public documentation you can check, and correct promptly when a vendor tells us a fact is wrong (contact details on the about page).