HR Management
Lucca
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Lucca SAS · www.lucca.fr
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Lucca, an HR Management suite sold by Lucca SAS and presented on a French-language site, is strongest at leave and absence administration: time and absence scores cluster at 5-6, crediting seniority, fractionnement and CET rules, entitlement regularization, per-location public-holiday calendars, automatic justification follow-up, and reporting on leave provisions and absenteeism rates. Core HR records scored 4-5 on an effective-dated job-position model that keeps career history, though the personnel file surfaces only as a beta upload-and-retrieve interface. Payroll readiness sits at 3-4: the absence export is month-end aware but no payroll system is named, and the documented downstream is the French DSN sick-leave declaration. Recruiting and onboarding scored 2, on evidence that reduces to a public, unauthenticated XML job-offers feed plus an upcoming-employee status. Employee data governance scored 1-2, with no public information on retention, deletion, roles or a data-processing agreement, and sovereignty scored 2-3, with no sovereignty attributes on record. No prices are public; the only path shown is a demo request. The flagged split checks came back empty.
Speaks for it
- Absence administration runs deep — seniority, fractionnement, CET, entitlement regularization, day or hour counting, per-location public-holiday calendars and automatic justification follow-up, for time and absence scores of 5-6.
- The payroll export is month-end aware, grouping cancellations, late and pending-validation absences and splitting stoppages that straddle two periods.
- Job positions are effective-dated career stages constrained to the employment, with a calculated active, upcoming or deactivated status, so history is kept.
- Sick leave feeds the French DSN social declaration with transmission-deadline alerts.
- Employees submit leave requests with balances from web or mobile apps and managers approve in one click.
Held against it
- Recruiting and onboarding scored 2, with the join path evidenced only as a public, unauthenticated job-offers XML feed and an upcoming-employee status.
- We found no public information on retention periods, executable deletion, role separation or a signable data-processing agreement for employee data.
- No payroll system is named for the absence export and no public information covers formats for a German payroll handoff.
- Working-time arrangements are an opt-in feature, and we found no public information on working-time recording, break and rest rules or tamper-evident records.
- The sovereignty record is empty: we found no public information on hosting region, data-centre provider or subprocessors.
Best for
- You run a French private-sector payroll and need sick-leave absences tied into the DSN declaration cycle with deadline alerts.
- Your heaviest admin burden is leave under collective agreements — seniority, splitting, carry-over, justification chasing — across sites with different local holidays.
- You already have payroll software and want a software-agnostic absence export rather than a named integration.
- You need dated career history per employee, not an overwritten flat record.
Avoid if
- You need applicant tracking, structured hiring stages, rejection handling and onboarding checklists from the same suite.
- You must review retention periods, deletion, an audit trail and a signable data-processing agreement before contracting.
- Your procurement or works council requires documented hosting region, data-centre provider and subprocessors.
- You must record working time to a legal recording duty, including break and rest rules.
The scores
Digital personnel file & data model
Show reasoningHide reasoning
How this is scored
The system of record: employee master data, the digital personnel file, org structure, custom fields, and whether history is kept rather than overwritten.
0 — A contact list with job titles; no document storage, no org structure, no history — changes overwrite what was there.
3 — Employee records with document upload, but a flat structure: no org chart, few or no custom fields, and no dated history of contract or salary changes.
5 — Digital personnel file with structured document types, an org chart, custom fields, and change history on the core employment fields.
8 — Complete record: versioned contract and compensation history with effective dates, document templates with e-signature, org structure supporting multiple entities and cost centres, and granular field-level permissions.
10 — The file is the single source of truth an auditor could work from: full effective-dated history on every field, retention rules per document type, delegated administration per entity, and export that reproduces the record intact.
The People Lead
The core product claims centralisation and historisation of all HR data, and the job-position model is properly dated — each position is a career stage within an employment, with effective start and end dates and a lifecycle status the system calculates, so a promotion does not overwrite what was there. Beyond a beta file upload and retrieve API we found no public information on document templates with e-signature, custom fields, or field-level permissions. 1 7
The Payroll Officer
The core HR module is described as centralising, historising and updating all HR data, and the developer model shows effective-dated job positions as career stages inside dated employments, with employee status calculated rather than retyped. We found no public information on org charts, custom fields, structured document types or field-level permissions, and the file upload/retrieve interface is generic and in beta. History is clearly kept rather than overwritten, but the personnel file itself is thin on evidence. 1 7
The Works Council Advocate
The developer documentation models a career as dated job positions with effective dates, department and manager attached, alongside a file upload-and-retrieve endpoint marked beta, and the vendor speaks of centralising and historising all HR data. We found no public information on structured document types, e-signature, custom fields, retention rules for the file, or permissions on who may read which part of it — the questions a co-determination review starts with. 1 7
The Data Protection Officer
The HR core advertises centralization and historization of all HR data, and the job-position model is genuinely effective-dated: career stages tied to an employment with start dates constrained to its range, calculated end dates, departments, business establishments and manager links, so change is kept rather than overwritten. I found no public information on structured document types, e-signature, custom fields or field-level permissions; file handling surfaces only as a beta upload-and-retrieve endpoint. 1 7
The IT Integrator
The developer documentation shows a genuine data model: employments carrying effective-dated job positions tied to business establishments, departments and qualifications, with a calculated active, upcoming or deactivated status, and the vendor claims centralization and historization of all HR data. We found no public information on an org chart view, custom fields or structured document types, and the file endpoints are in beta with only upload and retrieve. That structure sits above a flat employee list but falls short of an evidenced digital personnel file. 1 7
The Skeptic
The developer documentation shows a genuine data model — career stages dated and constrained to the employment, departments and business establishments, calculated active/upcoming/deactivated statuses — and the HR core page claims centralization and historization of all HR data. The personnel file itself is barely evidenced: documents appear only as beta upload-and-retrieve endpoints, and we found no public information on org charts, custom fields or field-level permissions. 7 1
Payroll handoff
Show reasoningHide reasoning
How this is scored
Whether the month closes cleanly into payroll — DATEV, Lohn und Gehalt, an in-house system or an external tax adviser — and how much of that is automated rather than re-typed.
0 — No payroll path stated at all; whatever leaves the system leaves as a spreadsheet somebody retypes.
3 — Generic CSV export said to be usable for payroll, with no named payroll system, no defined format and no handling of mid-month changes.
5 — A named payroll integration or a documented export format for at least one major system (e.g. DATEV LODAS/Lohn und Gehalt), covering the recurring monthly fields.
8 — Certified or vendor-maintained integration with a named payroll provider, covering variable pay, absences and mid-month joiners and leavers, with a documented pre-payroll check.
10 — Payroll is a first-class part of the product: maintained bidirectional integrations with several named systems, an auditable approval and lock step before transmission, retro-accounting for backdated changes, and the tax adviser given their own access.
The People Lead
All absences of the period, including cancellations, late entries and those awaiting validation, are grouped and sent to payroll whatever software you use, and work stoppages straddling two periods are split to avoid double export — that is a month-close with the chasing largely removed. But no payroll system is named for the main handoff and we found no public information on DATEV, Lohn und Gehalt or any German payroll path, so I cannot verify the recurring fields land in a defined format. 2 3 4 5
The Payroll Officer
The absence export is genuinely month-end aware: every absence of the period, including cancellations, delays and those still pending validation, is grouped before being sent to payroll whatever software you use, stoppages straddling two periods are split to avoid double export, and DSN transmission-deadline alerts sit on top. But the destination is deliberately software-agnostic, no payroll system is named, and we found no public information on variable pay, mid-month joiners and leavers, or a documented pre-payroll check; export guides for timesheets and expense accounting appear in the developer documentation. 4 5 2 3
The Works Council Advocate
Absences, including ones still awaiting validation or needing correction, are grouped and sent to payroll whatever software you use — a generic path with no named payroll system — and the payroll-facing material we captured is built around the French DSN declaration cycle. For a German handoff to DATEV, a Lohnbüro or an in-house system we found no public information on export formats, pre-payroll checks or the tax adviser's access. 4 5
The Data Protection Officer
Absences including cancellations, late and pending-approval cases are grouped and sent to payroll without manual intervention whatever the payroll software, and sickness entries feed the French DSN social declaration with transmission-deadline alerts. The captured pages name no payroll system, and I found no public information on variable pay, mid-month joiners and leavers, or a documented pre-payroll check. 4 5
The IT Integrator
Absences — including cancellations, late-arriving requests and periods straddling two months — are grouped and sent to payroll with no manual intervention, which is real handling of mid-month changes, and the French social declaration workflow for sick leave comes with transmission-deadline alerts as the one named downstream. The vendor frames the export as working with whatever payroll software you use, without naming a system or documenting a format, and we found no public information on a certified integration or a pre-payroll check step. 4 5
The Skeptic
Absences — including cancellations, late entries and those awaiting validation — are grouped before export to payroll "whatever the software you use", with sick leave spanning two periods split to avoid double export, yet no payroll system is named anywhere in these pages. The developer pages we found for timesheet and expense exports sit in a legacy section with no confirmed format, and the one deadline-tracked flow is the French DSN sick-leave declaration rather than the payroll file itself. 4 5 2 3
Absence & working-time
Show reasoningHide reasoning
How this is scored
Vacation, sickness and working-time recording — including whether the product meets the German recording duty (BAG 2022, ArbZG) rather than merely offering a timer.
0 — No absence or time handling; both live in a spreadsheet elsewhere.
3 — Vacation requests with an approval step, but entitlement is manual, carry-over is not handled and there is no working-time recording.
5 — Automatic entitlement and carry-over, sickness recording, an absence calendar, and basic working-time capture with a report per employee.
8 — Configurable per country and contract: pro-rata entitlement, public-holiday calendars per location, break and rest-period rules, overtime accounts, and an export the employer can hand to a labour inspection.
10 — Working-time recording built as a legal obligation rather than a feature: tamper-evident records, documented compliance with the ArbZG recording duty, works-council-configurable monitoring limits, and shift or on-call models handled without add-ons.
The People Lead
Absence is the strong leg: self-service requests with balances, one-click manager approval, automatic chasers for missing justifications, configurable public-holiday calendars per location, and entitlement rules covering seniority, splitting, savings accounts, counting in working days, calendar days or hours, and regularisation of acquired rights under any collective agreement. Working time is thin by comparison — arrangements are an opt-in replacement for workcycles and a timesheet export guide exists, but we found no public information on recording built to a legal recording duty, break and rest rules, overtime accounts, or an export fit to hand a labour inspection. 2 4 5 7
The Payroll Officer
Absence handling runs deep and configurably: seniority, splitting, time-savings accounts, worked versus workable days, calendar days or hours, entitlement regularisation, holiday calendars per local practice, rules that apply regardless of collective agreement, justification chasers, DSN deadline alerts for work stoppages, and reporting on leave provisions and absenteeism. Working-time recording as a legal duty is where the pages go quiet — we found no public information on break and rest rules, overtime accounts or tamper-evident records, and working-time arrangements appear only as an opt-in notion in the developer model. 4 5 7
The Works Council Advocate
Vacation and sickness are genuinely handled: seniority-based entitlement, carry-over mechanisms, counting in days or hours, sickness with justification control and automatic reminders to employees, team calendars, configurable public-holiday calendars and absenteeism reporting. Working-time recording is the weak side — a working-time arrangement appears only as an opt-in developer resource, and we found no public information on tamper-evident records, break and rest rules, or any reference to the German recording duty. I also note that absenteeism-rate reporting and the automated chasing of individuals come with no public information on limits or on switching them off, which is precisely a co-determination matter. 4 5 7
The Data Protection Officer
This is the product's centre of gravity: seniority, split-leave rules, time-savings accounts, entitlement regularization, days or hours, public-holiday calendars configurable to local practice, sickness with justification tracking and automatic reminders, absences spanning month-ends split to avoid double export, and reporting on provisions and absenteeism rates. Working-time arrangements are an opt-in feature, and I found no public information on break and rest-period rules, overtime accounts, or handling of the German working-time recording duty. 4 5 7
The IT Integrator
The absence side is the strongest evidence in this product: seniority, fractionnement, CET, entitlement regularization, public-holiday calendars configurable to local practice, sickness with justification tracking and automatic follow-up reminders, and reporting on leave provisions and absenteeism. We found no public information on working-time recording, break and rest rules, or the German recording duty under the ArbZG — the working-time arrangement feature in the API is opt-in and may not be deployed on a given environment. Absence is well covered; working time as a legal obligation is not evidenced. 4 5
The Skeptic
Absence management has real depth: self-service requests with balances, one-click approval, per-location public-holiday calendars, rules that follow any collective agreement, seniority, CET, days-versus-hours accounting, entitlement regularization, automatic justification follow-up and DSN deadline alerts. Working time is the gap — we found no public information on time capture or on break, rest and overtime rules, so the German recording duty cannot be assessed from these pages. 4 5
Recruiting & onboarding
Show reasoningHide reasoning
How this is scored
The join path — vacancy to signed contract to a person who has an account, equipment and a plan on day one.
0 — Neither applicant tracking nor onboarding exists; hiring happens in a shared inbox.
3 — A basic applicant list with statuses, or an onboarding checklist — one of the two, without the handover between them.
5 — Applicant tracking with a careers page, structured stages and rejection handling, plus a checklist-driven onboarding that carries the hired candidate over into an employee record without re-entry.
8 — Multi-posting to named job boards, interview scheduling and scorecards, GDPR-conscious applicant retention and deletion, e-signed contracts, and onboarding that triggers tasks in IT and payroll.
10 — The whole join is one governed flow: approval-gated requisitions with budget, structured and bias-conscious evaluation, automated applicant deletion at the stated deadline, and provisioning driven from the record so day one needs no HR intervention.
The People Lead
A recruitment product exists and can publish customers' active job offers to job boards and aggregators through a public API for those who opt in, and the employee record can exist as upcoming before employment starts. We found no public information on applicant tracking with structured stages and rejection handling, interview scheduling, onboarding checklists, or a handover that turns a hired candidate into an employee record without re-entry. 6 7
The Payroll Officer
A recruitment product exists: a public job-offers feed lets job boards and aggregators pull a customer's active vacancies, and the employment model carries probationary periods. Beyond the posted vacancy the join path is dark — we found no public information on applicant stages, rejection handling, signed contracts or onboarding checklists. 6 7
The Works Council Advocate
The join path shows only a publicly accessible job-offers feed for opted-in customers that third-party boards and aggregators can read — without authentication and without paging — plus an employee status for people whose employment has not yet begun. We found no public information on applicant tracking, evaluation stages, rejection handling, applicant deletion deadlines or onboarding checklists. A public feed keyed by customer subdomain would need its scope examined before I could agree to it. 6 7
The Data Protection Officer
The join path reduces to a public job-offers feed through which opted-in customers' vacancies reach job boards and aggregators, plus an upcoming-employee status in the data model. I found no public information on applicant tracking stages, rejection handling, onboarding checklists, e-signed contracts, or retention with automated deletion of applicant data on a stated date — the point I weigh hardest. 6 7
The IT Integrator
The documented recruitment evidence is a public, unauthenticated job-offers feed in XML that third-party boards and aggregators can pull from opted-in customers, and the employment model supports an upcoming status so a pre-hire record can exist before day one. We found no public information on applicant tracking, structured stages, onboarding tasks, or — the way I judge this — SCIM provisioning or single sign-on that would create the account from the record. 6 7
The Skeptic
The only recruiting surface in evidence is a public, unauthenticated XML feed of opted-in customers' job offers aimed at job boards and aggregators, alongside an "upcoming" employee status that anticipates future hires. We found no public information on applicant tracking, structured evaluation, applicant retention and deletion, or any onboarding flow. 6 7
Employee data protection & co-determination
Show reasoningHide reasoning
How this is scored
How the product handles the most sensitive personal data a company holds — retention, deletion, role separation, subject rights — and whether it can pass a works council (BetrVG §87) rather than merely a procurement checklist.
0 — No stated retention or deletion handling, no role model beyond admin-or-not, and no DPA offered on the site.
3 — A DPA exists on request and roles are coarse; retention and deletion are described as something the customer arranges themselves.
5 — A signable DPA is published, roles are configurable per module, applicant and employee retention periods are stated, and deletion can be executed rather than only promised.
8 — Field-level access control with an audit log of who read what, configurable retention per data category with automatic deletion, documented subject-rights support, and monitoring or analytics features that can be switched off for co-determination.
10 — Built for the works council to say yes: published processing documentation and subprocessor list, per-entity data separation, tamper-evident audit trail, evaluation and behavioural-analysis features off by default with their scope documented, and a data-protection impact assessment the customer can build on.
The People Lead
The only signals are technical: API access tokens with OAuth scopes and access-control events among the webhooks. We found no public information on a signable data processing agreement, stated retention periods, executable deletion, subject-rights support, an audit log of who read what, or monitoring features that can be switched off — nothing here I could bring to a works council for 400 people's most sensitive data. 7
The Payroll Officer
We found no public information on retention periods, deletion that can be executed, a signable DPA, or role separation for the most sensitive data a company holds. The only protection-related evidence is OAuth access tokens with scopes and access-control events in the developer interface, which is authorisation plumbing rather than data governance. 7
The Works Council Advocate
Reading as a works council member — what is logged, who can read it, what can be switched off — the captured pages answer none of it: we found no public information on retention periods, deletion, an audit trail of who read what, field-level permissions or a published data-processing agreement. The only access-control evidence is OAuth scopes and access-control events in the developer API. Meanwhile absenteeism rates and automatic reminders aimed at individual employees are offered as features, with no public information on deactivating or constraining that monitoring. 4 5 7
The Data Protection Officer
On the most sensitive personal data a company holds about people who cannot decline the processing, I found no public information on retention periods per data category, deletion that executes rather than promises, configurable roles, subject-rights support, an access audit log, or a signable data-processing agreement — an unpublished DPA is itself a finding. The only governance-adjacent material is OAuth-scoped tokens and access-control event webhooks, plumbing rather than protection. 1 7
The IT Integrator
For the most sensitive data a company holds, we found no public information on a data processing agreement, retention periods, deletion that can be executed, subject-rights support, or a role model beyond what the developer pages imply. The only signals are API access tokens with OAuth scopes and access-control events among the webhook types — developer-facing access control, not employee-data governance. Nothing captured would help a works council decide. 7
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the data lives, who the contracting entity is, who the subprocessors are, and whether the answer is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as the buyer would weigh it.
0 — US-headquartered vendor, US contracting entity, hosting region unstated or US, subprocessors not named.
3 — EU hosting is offered as an option but the contracting entity is non-EU, or the subprocessor list is incomplete or absent.
5 — EU hosting stated as standard and an EU contracting entity, but the subprocessor chain includes non-EU providers without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, an EU contracting entity, the full subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, contracting entity, hosting and every subprocessor in the EU, certification of the data centres published, and an on-premises or private-cloud option for buyers who need it.
The People Lead
The vendor presents as a French company on a French site under an SAS contracting form, which points to an EU entity, but no sovereignty attributes are on record. We found no public information on hosting location or the data-centre provider, and no public information on the subprocessor chain. 1
The Payroll Officer
The vendor presents as Lucca SAS on a French-language site, which reads as a French contracting entity, but the sovereignty record is empty: we found no public information on hosting region, data-centre provider or subprocessors. A French name on the contract does not tell a buyer where the data sits. 1
The Works Council Advocate
The vendor presents itself as a French company on a French site, but we found no public information on where employee data is hosted, the data-centre provider, or the subcontractor chain, and the recorded sovereignty attributes came back empty. An undocumented chain is not something a works council can sign off on. 1
The Data Protection Officer
Lucca SAS presents itself from France and operates its own lucca.fr and luccasoftware.com properties, so the contracting entity at least is European. I found no public information on where employee data is hosted, the data-centre provider, or a single named subprocessor, and no processing agreement that would document safeguards. 1 6
The IT Integrator
The vendor presents itself as Lucca SAS on a French-language site, but the captured pages give no hosting region, no contracting-entity documentation and no subprocessor list. We found no public information establishing where the data lives or who processes it, so a buyer needing documented European processing has nothing to hold onto. 1
The Skeptic
No sovereignty attributes are on record: we found no public information on hosting region, data-centre provider, contracting entity or subprocessors among the captured pages. A French vendor name, SAS legal form and.fr domain suggest a European company, but the hosting and subcontractor chain a buyer needs documented are not evidenced here. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an HR lead can compute the real annual invoice for their headcount — including the modules they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price per employee exists, but the modules most buyers need are unpriced, or a minimum headcount, setup fee or mandatory onboarding package is not stated publicly.
5 — Per-employee prices are public for the main tiers with the billing period stated, but at least one commonly needed module (payroll, time, recruiting) hides in an unpriced bundle.
8 — Every tier and module priced publicly with per-employee maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.
10 — Complete price computability: a calculator or table that produces the annual invoice for a given headcount and module selection, including setup, minimums and renewal terms.
The People Lead
The pages show fifteen solutions and a demo request, and we found no public information on any price — no per-employee rate, no billing period, no minimum headcount or setup fees. I cannot compute any part of the annual invoice from public pages alone; every tier is a sales conversation. 1 4
The Payroll Officer
We found no public prices for any of the fifteen modules — no per-employee rate and no billing period — and the captured pages route buyers to a demo request. An HR lead cannot compute even a rough annual invoice from what is public. 1 4
The Works Council Advocate
We found no public prices in the captured material — not a per-employee price, not a billing period, not a minimum term or setup fee — only a demo request and talk of fifteen modules. Every tier is a sales conversation. 1 4
The Data Protection Officer
The captured pages present fifteen modules and a demo request, and not one price, per-employee rate, billing period, minimum term or setup fee. An HR lead cannot compute any part of the annual invoice from what is public. 1 4
The IT Integrator
We found no public information on prices — not per-employee rates, tiers, billing period, minimum term or setup fees — on any captured page; the only path shown is "Demander une démo". An HR lead cannot compute any part of the annual invoice from public information. 1 4
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any pricing information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- We could not confirm any compliance information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 18 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 hosting fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (7)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page www.lucca.fr Checked 29 Sep 2026 Details →
- 2 Payroll handoff — found from sitemap developers.luccasoftware.com Checked 1 Oct 2026 Details →
- 3 Payroll handoff — found from sitemap developers.luccasoftware.com Checked 1 Oct 2026 Details →
- 4 Absence & working-time — found from sitemap www.lucca.fr Checked 1 Oct 2026 Details →
- 5 Absence & working-time — found from sitemap www.lucca.fr Checked 1 Oct 2026 Details →
- 6 Recruiting & onboarding — found from sitemap developers.luccasoftware.com Checked 1 Oct 2026 Details →
- 7 Recruiting & onboarding — found from sitemap developers.luccasoftware.com Checked 1 Oct 2026 Details →