Security and data protection
Your data. In Germany. Under your control.
Group tax data is confidential. So we answer the questions your legal and IT departments will ask right here, before they are asked – and put the documents on the table before you start.
At a glance
Six commitments. No fine print.
- Location
Data centres in Germany
Pillarworks runs in data centres in Germany. Your group data does not leave the European Union.
- Access
No access without your instruction
Nobody at L+C Technology sees your data unless you explicitly ask for it – for support, for instance. Such access is tied to a named person and logged.
- AI
AI assistant optional
LuCy is a separate module and stays your decision. If you use it, we set out in writing before the start which data it processes, where that happens and on what contractual basis. If you do not, we switch the module off for your company.
- Separation
Your group, your data space
Every group works in its own data space. There is no exchange of data between companies – not in analyses either.
- Contracts
DPA, TOMs, sub-processors
You receive a data processing agreement under Art. 28 GDPR, the technical and organisational measures and the list of sub-processors – before signing.
- Exit
Export at any time, deletion on request
You export group structure, calculations and reports at any time as Excel, GIR XML and project file. After the contract ends we delete your data within an agreed period and confirm it in writing – unless a statutory retention obligation applies.
Three pillars
Data, access, operations. Clearly governed.
What Pillarworks processes, who handles it and how the platform is operated.
- Data
Group and financial data, hardly any personal data
Pillarworks processes group structures, country-by-country reports, financial figures and tax positions. Personal data is limited to your team’s user accounts: name, email address, role. Data is encrypted in transit and at rest.
- Access
Roles, rights, audit trail
You decide who in your group sees and edits what. Calculations are documented live, locked years remain unchanged, every GIR carries an evidence snapshot. We agree the connection to your identity system before the start.
- Operations
German data centres, regular backups
Operated in data centres in Germany certified to recognised standards. Regular backups; frequency, retention and restore are part of the contract. We notify you of security incidents without undue delay.
Questions from your legal department
The questions that will come. With answers.
What legal, data protection and IT departments usually check before deploying software – answered here.
Where is our data held?
The application and your data are held in data centres in Germany. If you also use the AI assistant LuCy, we set out in writing before the start where its processing takes place and on what contractual basis – or we switch the module off for your company.
Who at L+C Technology has access to our data?
Nobody without your instruction. For support or troubleshooting we access data only when you request it – tied to a named person, limited to the case and logged. You can end the access at any time.
What data does Pillarworks process at all?
Group structures, ownership, country-by-country reports, financial figures and tax positions – company data. Personal data is limited to your team’s user accounts: name, email address, role. Headcount enters only as a total per jurisdiction, as the substance test requires.
Is our data separated from other groups’ data?
Yes. Every group works in its own data space with its own access. There is no exchange of data between companies – not in analyses or comparisons.
How is the data encrypted?
In transit via TLS, at rest encrypted on the data centre’s systems. Details of methods and key management are set out in the technical and organisational measures you receive with the contract.
What happens to data LuCy sees?
LuCy answers questions about the field you are working in from a curated Pillar 2 knowledge base. It is a separate, optional module: which data it processes, where that happens and what happens to it is agreed with you in writing before the start. If you prefer not to use LuCy, we switch the module off for your company.
Is a US provider involved?
The application and your data are held in data centres in Germany. The only place where the question arises at all is the AI assistant – and that is optional. Which providers are involved there, in which region they process and on what contractual basis, we set out before the start; if you prefer not to use LuCy, you switch the module off.
Which contracts and documents do we receive?
A data processing agreement under Art. 28 GDPR, the description of the technical and organisational measures, the list of sub-processors with a right to object to changes, and on request a non-disclosure agreement before detailed discussions. All before signing.
What about backups and outages?
The platform is backed up regularly. Frequency, retention and restore are part of the contract. Independently of that, you can export your data set yourself at any time as a project file.
What happens when the contract ends?
You export your data completely – group structure, calculations, reports, evidence – as Excel, GIR XML and project file. That lets you meet your own tax retention obligations independently of us and of the software. We then delete your data including backups within the agreed period and confirm the deletion in writing. Where statutory retention obligations prevent deletion, we block the records concerned from further processing and delete them once the period has expired.
Are you certified?
The data centres in which Pillarworks runs are certified to recognised standards such as ISO 27001. L+C Technology itself currently holds no certification of its own; instead we disclose our technical and organisational measures in full and answer your IT department’s audit questions directly.
What happens in the event of a security incident?
We inform you without undue delay, name the scope and the data affected and agree the next steps with you. We receive vulnerability reports via the address in our security.txt and confirm receipt.
Do you need data from us for a demo?
No. The demo and the first conversation run on the fictional group Aurora Energie SE. Your own data only comes into play when you decide – after coordination with your IT and data protection teams and on a contractual basis.
Before the start
The documents are on the table before you sign.
What your legal and IT departments receive from us:
- 01Data processing agreement under Art. 28 GDPR
- 02Technical and organisational measures
- 03List of sub-processors with location and purpose
- 04Proof of data residency for the application and LuCy
- 05Roles and permissions concept for your team
- 06Backup and deletion concept
- 07Reporting channel for security incidents and vulnerabilities
- 08Non-disclosure agreement on request before detailed discussions
You have your own questionnaire? We answer it – completely and in writing.
This website
Here too: no cookies, no tracking.
This website is hosted in Germany, sets no cookies, stores nothing in your browser and embeds no third-party scripts. Your enquiry via the contact form goes to our mailbox over an encrypted connection and is used only to handle your request.
Your IT has questions? Gladly.
We talk directly to your legal, data protection or IT department – with the documents on the table before you decide.
Request the documents info@lctechnology.de
+49 211 16451‑100 · L+C Technology GmbH · Kennedydamm 24 · 40476 Düsseldorf