Skip to content

business task

Our approach to protecting sensitive customer data and ensuring the ability of institutions to act in the event of a possible shutdown.

As of July 21, 2026

A business closure must not result in an institution losing access to its data or having to suddenly interrupt central processes. That's why Lua considers data protection, data portability and technical continuity together.

Our approach doesn't start with the source code, but with the customer data and an orderly transition. If desired, an institution can also arrange a verified SaaS escrow.

1st principle

The respective institution remains responsible for the personal data recorded in Lua. Datascale GmbH processes this data as a processor within the framework of the institution's contractual agreements and instructions.

In the event of a contract termination or business cessation, protection is based on four steps:

  1. Issue customer data in full in common machine-readable formats;

  2. enable an orderly transition to a successor solution;

  3. if necessary, prepare a temporary continuation of operations;

  4. Upon customer request, we can arrange escrow as additional technical and legal security.

2. Transition

If Lua is planned to be discontinued, the institution concerned should be informed as early as contractually agreed and actually possible. The transition is organized with clear responsibilities, dates and contact persons.

Depending on the agreement, this includes in particular:

  • a defined continued operation or read-only phase;

  • the immediate provision of a customer-specific overall export;

  • documented support for the handover to a successor provider;

  • transparently regulated handover services and costs;

  • the deletion of remaining customer data after confirmed handover and expiry of legal retention obligations;

  • a written confirmation of deletion.

The duration, scope, cooperation obligations and prices of such a transition phase are bindingly determined in the respective SaaS contract or in a supplementary exit appendix.

3. Data export

Data export is primarily intended for further machine processing and migration. The content remains directly visible in the formats provided; an additionally designed PDF dossier is not part of the standard export. Depending on the agreed scope of services, these include:

  • structured data in common formats such as CSV, JSON or Excel;

  • documents in their original formats;

  • clear assignments between data sets and documents;

  • Master data, user accounts, roles and authorizations;

  • relevant historical and audit data;

  • a data description or a field catalog;

4. Escrow

A stored archive with source code does not ensure functional operation. Restoring a SaaS application also requires, among other things, database schema and migrations, files, infrastructure definitions, build artifacts, configurations, dependencies, licenses, and operational and recovery instructions.

The practical test is just as important: an expert, authorized third party must actually be able to build the application from the stored components and operate it safely.

Lua operates the application for each institution in its own, isolated single-tenant environment. The protection and any continuation of operations therefore relate exclusively to the customer-specific environment. Environments and data of other customers remain completely separate.

A verified SaaS continuity escrow is only agreed individually at the request of a customer. This option is available regardless of the type or size of the institution.

Update, technical review, recovery goals and release reasons are objectively determined. Possible triggers include, in particular, a legally binding declaration of bankruptcy, the definitive cessation of business operations, a contractually defined long-term critical failure or the refusal to export data that is owed.

The rights of use after release are expressly regulated. You can allow continued internal operation and the commissioning of a successor operator without permitting publication, remarketing or use for other institutions.

5. Data protection

The principles of purpose limitation, confidentiality, data security and the separation of customer environments also apply in exit or escrow cases. Data will only be released to contractually and legally authorized recipients. External continuation or escrow partners are obliged to maintain confidentiality and take appropriate protective measures.

The handover is documented. Copies that are no longer required will be deleted after confirmed migration, expiry of agreed deadlines and subject to legal obligations. Data from other institutions is excluded from publication.

6. Commitment

This page describes the basic approach of Lua. The contracts concluded with the respective institution are binding, in particular the SaaS contract, the order processing contract and any exit, continuation or escrow appendices.

The scope and costs of additional continuation or escrow services depend on the requirements of the institution. The specific design will be checked and agreed in writing before the contract is concluded.

Consent

This site uses third party services that need your consent.