Security and data protection

Your data. Under your control.

Where your data goes, what we commit to in the contract, what you can verify in the product yourself today and which documents you receive before signing – on one page, point by point.

Request the documents Go to the checklist

Commitment
to be agreed in the contract, in writing before you sign
In the product
verifiable in the demo today

For the executive board The essentials in three lines

Location
Application servers and database in data centres in Frankfurt am Main (EU) – encrypted transfer, a separate data set per group.
Commitment
Access
No access by L+C Technology without your instruction – tied to a named person and logged.
Commitment
Your data
Export yourself, without asking us – Excel, GIR XML, project file; after the contract ends, deletion including backups, confirmed in writing (commitment).
In the product

The full checklist for procurement and IT follows below.

Data flow

The path of your data. There, back, and who can access it in between.

A diagram instead of an architecture slide: where the data comes from, where it is processed, how it returns to you – and which paths are open only on your instruction or as an option.

Checklist for procurement

Ready to tick off. With a status on every line.

What procurement, IT and data protection check before deploying software – with the status of every statement. No seals, no logos: commitments are shown as commitments, evidence as evidence.

Commitment
to be agreed in the contract, in writing before you sign
In the product
verifiable in the demo today
Document today
publicly available, linked here
Document before signing
part of the contract documents

11 commitments · 3 in the product · 3 documents today · 6 before signing

Operations and location

  • Application servers and database in data centres in Frankfurt am Main Commitment
  • Only data centres certified to ISO 27001, evidence with the contract documents Commitment
  • Encrypted transfer (TLS) Commitment
  • Regular backups Commitment

Access and separation

  • No access by L+C Technology without your instruction – tied to a named person, logged Commitment
  • Separate data set per group Commitment
  • Roles model for your team before go-live Commitment
  • Information without undue delay in the event of a security incident Commitment

Data, export and exit

  • Demo and first conversation without your data – using the fictional group Aurora Energie SE In the product
  • Export yourself, without asking us: Excel, GIR XML, project file In the product
  • “Lock the year”; “Minimum Tax Verification Report” as PDF In the product
  • Deletion after the contract ends, including backups, confirmed in writing Commitment

AI assistant LuCy

  • LuCy is a separate, optional module Commitment
  • Which data LuCy processes, where and on what basis – disclosed before the contract is concluded Commitment

Documents

Have your own questionnaire? We answer it point by point, in writing.

Request the documents

Commitments in full

What we commit to. In writing, before you sign.

These points are part of the contract. You receive them in writing before you decide – not as a marketing promise, but as commitments you can hold us to.

Commitment to be agreed in the contract, in writing before you sign

  1. 01Operations and data location

    Application and data storage in Frankfurt am Main

    Our commitment: application servers and database in data centres in Frankfurt am Main (EU). The user interface is delivered via our hosting provider’s global network; your data is processed and stored exclusively in Frankfurt and passes through that network in encrypted form only. You receive evidence of the regions before signing. We use only data centres certified to ISO 27001 – we commit to this in the contract. You receive the evidence with the contract documents.

  2. 02Access

    No access without your instruction

    Our commitment: nobody at L+C Technology accesses your data without your explicit instruction, not even for support. Any access you request is tied to a named person, limited to the case, logged and ends whenever you want.

  3. 03Separation

    Your group, your own data

    Our commitment: every group works on its own separate data set. There is no exchange between the data sets of different groups – not in analyses or comparisons.

  4. 04Encryption and backups

    Encrypted in transit, backed up regularly

    We commit to encrypted transfer (TLS) and regular backups. Methods, key management, frequency and restore are described in the technical and organisational measures you receive before signing.

  5. 05Roles

    Roles model before go-live

    We define together which roles your team receives; you receive the roles model before go-live.

  6. 06AI assistant

    LuCy stays your decision

    LuCy is a separate, optional module. If you use it, we set out in writing before go-live which data it processes, where that happens and on what contractual basis.

  7. 07Incidents

    Information without undue delay

    In the event of a security incident we inform you without undue delay, as the data processing agreement provides, name the scope and the data affected and agree the next steps with you. We receive vulnerability reports via the address in our security.txt.

Your exit

You leave when you want. Your data leaves with you.

You do not need to ask us for an export – it is a feature of Pillarworks. We show it to you in the demo using the fictional group Aurora Energie SE.

TraceabilityIn the product

The locked computation stays on record.

“Lock the year” protects the computation of the provision against changes until you explicitly unlock it; the reporting phase works on a working copy. The Minimum Tax Verification Report documents the locked computation as a traceable record, printable as PDF.

  • Lock the year
  • Minimum Tax Verification Report
  • PDF

The export supports you in meeting your own retention obligations independently of us; completeness, readability and deadlines remain subject to your own procedures.

Contracting party

Who you contract with. Unambiguous.

Contracting party
L+C Technology GmbH
Registered office
Kennedydamm 24, 40476 Düsseldorf, Germany
Register
Düsseldorf Local Court, HRB 113671
Managing directors
Alexander Lohr, Edgar Dokholian, Finn‑Lucas Johannsen, Eike Roß
Scope
Software: Pillarworks, with the AI assistant LuCy as an optional module

We develop software. Tax advice is provided on request by the expert team of LOHR+COMPANY GmbH Wirtschaftsprüfungsgesellschaft – always under a separate engagement that you enter into directly with them. Neither requires the other.

Questions from legal

What legal, IT and data protection ask. Answered briefly.

The usual questions before deploying software. Anything missing here we answer in writing – including in your own questionnaire.

Where is our data held?

Application servers and database are located in data centres in Frankfurt am Main (EU) – part of the written commitments you receive before signing. The user interface is delivered via our hosting provider’s global network; your data is not stored there and passes through in encrypted form only. If you also use the AI assistant LuCy, we set out in writing before go-live where its processing takes place and on what contractual basis.

Is a US provider involved?

For application servers and database we commit to data centres in Frankfurt am Main. Before the contract is concluded, we disclose which providers are involved there and for the optional AI assistant, where they process data and on what contractual basis; you receive the list of sub-processors before signing. Our privacy policy applies to email traffic.

Who at L+C Technology has access to our data?

That is our commitment: nobody without your instruction. For support or troubleshooting we access data only when you request it – tied to a named person, limited to the case and logged. You can end the access at any time.

What data does Pillarworks process?

Group structures, ownership interests, country-by-country reports, financial figures and tax positions – company data. Pillarworks is designed for company data. Personal data is mainly your team’s user accounts (name, email address, role), contact details that individual authorities require in the return, and notes on who prepared a figure. Payroll costs and headcount enter as totals per entity or per jurisdiction, not per person. The data processing agreement sets out the categories in detail.

Is our data separated from other groups’ data?

That is what we commit to: every group works on its own separate data set with its own access. There is no exchange between the data sets of different groups – not in analyses or comparisons.

How is the data encrypted?

We commit to encrypted transfer and encrypted storage. Methods and key management are set out in the technical and organisational measures you receive before signing.

Are you certified?

L+C Technology itself is not certified. We commit to using only data centres certified to recognised standards such as ISO 27001; you receive the evidence with the contract documents. We disclose our technical and organisational measures and answer your IT department’s due diligence questions directly.

What about backups and outages?

We commit to regular backups. Frequency, retention and recovery are part of the contract. Independently of that, you can save your data set yourself at any time as a project file.

What happens when the contract ends?

You export your data – group structure, computations, reports – as Excel, GIR XML and project file. We then delete your data including backups within the agreed period and confirm the deletion in writing. Where statutory retention obligations prevent deletion, we block the records concerned from further processing and delete them once the period has expired.

Which contracts and documents do we receive?

A data processing agreement under Art. 28 GDPR, the technical and organisational measures, the list of sub-processors with a right to object to changes, the backup and deletion policy and, on request, a non-disclosure agreement before detailed discussions – all before signing. The roles model follows before go-live.

Who do we contract with – and who advises?

The contracting party for the software is L+C Technology GmbH. We develop software and do not provide tax advice. Tax advice is provided on request by LOHR+COMPANY GmbH Wirtschaftsprüfungsgesellschaft – always under a separate engagement that you enter into directly with them.

Do you need data from us for a demo?

No. The demo and the first conversation run using the fictional group Aurora Energie SE. Your own data only comes into play when you decide – after consultation with your IT and data protection departments and on a contractual basis.

Does this website use cookies or tracking?

No. This website sets no cookies, stores nothing in your browser’s local storage and embeds no third-party scripts. Your enquiry via the contact form is transmitted to our server over an encrypted connection, forwarded by email to our mailbox and used only to handle your request.

Questions from your IT department? We welcome them.

We talk directly to your legal, data protection or IT department – with the documents on the table before you decide.

Request the documents info@lctechnology.de

+49 211 16451‑100 · L+C Technology GmbH · Kennedydamm 24 · 40476 Düsseldorf, Germany