Privacy Policy
- ✓100% EU Data Residency: All store, catalog, and transaction data is hosted in Frankfurt and Falkenstein (Germany).
- ✓Zero AI Model Training: Your proprietary business records and customer PII are strictly never used to train public or commercial AI models.
- ✓Statutory Fiscal Retention: Cryptographically sealed audit trails are archived for statutory 7–10 year holding periods compliant with European tax authorities.
1. Introduction and Data Controller
Mars AI Technology Solutions Limited ("Grosa", "we", "us", or "our") is dedicated to protecting the privacy, confidentiality, and data sovereignty of our enterprise subscribers, their staff, and retail consumers. This Privacy Policy governs all personal data collected, stored, and processed through the Grosa.io cloud platform, edge point-of-sale (POS) terminals, mobile applications, APIs, and official web portals.
1.1 Data Controller Identity
Under the European Union General Data Protection Regulation (GDPR — Regulation EU 2016/679) and the UK Data Protection Act 2018 / UK GDPR, the legal entity acting as Data Controller for direct subscriber accounts, administrative registrations, and platform telemetry is:
- Entity Name: Mars AI Technology Solutions Limited (trading as Grosa / Grosa.io)
- Company Registration Number: 14863498 (Registered in England and Wales, Companies House, Cardiff)
- Incorporation Date: 11 May 2023
- Registered Corporate Office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- VAT Identification Number: GB 442 8168 22
- Data Protection Officer (DPO):
[email protected] - Legal and Regulatory Desk:
[email protected] - General Inquiries:
[email protected]
1.2 Data Controller vs. Data Processor Role
For data entered into the Grosa platform by merchant tenants regarding their end-customers, retail patrons, employee shift rosters, and store transactional ledger items, the merchant is the Data Controller and Grosa acts solely as a Data Processor pursuant to Article 28 of the GDPR. Our obligations as a Data Processor are governed by our Data Processing Agreement (DPA).
2. Legal Bases for Data Processing
Grosa processes personal data strictly in accordance with Article 6(1) of the GDPR under the following lawful bases:
- Performance of a Contract (Article 6(1)(b) GDPR): Provisioning merchant tenant instances, synchronizing edge POS terminals with the cloud core, processing subscription billings, facilitating multi-store inventory routing, and delivering technical customer assistance.
- Compliance with Legal and Fiscal Obligations (Article 6(1)(c) GDPR): Retaining transactional receipts, tax breakdown journals, and cryptographic fiscal tamper-evident archives mandated by European tax administrations (such as the German GoBD and KassenSichV, French Code Général des Impôts / NF525, and Dutch Algemene wet inzake rijksbelastingen).
- Legitimate Commercial Interests (Article 6(1)(f) GDPR): Hardening infrastructure against cyber threats, monitoring edge synchronization queues, detecting fraudulent payment attempts, diagnosing network anomalies, and optimizing system uptime and latency.
- Consent (Article 6(1)(a) GDPR): Disseminating elective product updates, partner program briefs, or developer ecosystem newsletters. Consent may be retracted at any moment.
3. Categories of Data Collected
We categorize the personal and operational data processed across our ecosystem into the following clear scopes:
3.1 Subscriber and Administrative Account Data
- Merchant Identity: Full name, executive contact credentials, corporate email address, and direct telephone numbers.
- Business Details: Registered corporate entity name, trading name, commercial register number (e.g., Dutch KvK, German Handelsregister, French SIREN/SIRET), VAT number, and registered physical retail premises.
- Billing Records: Subscription invoices, payment method tokens, and SEPA/credit card transaction references managed through certified payment gateways.
3.2 In-Store POS Operator and Staff Telemetry
- Operator Identifiers: Employee profile name, internal staff ID, assigned retail branch, and granular role-based permissions (Cashier, Floor Supervisor, Store Manager).
- Security Credentials: Cryptographically salted one-way hashes of staff PIN codes. Raw, unhashed terminal PINs are never transmitted or persisted on disk.
- Audit Logs: Clock-in/clock-out timestamps, register drawer opening events, cash drop logs, voided transaction entries, and supervisor override approvals.
3.3 Transactional and Retail Customer Data
- Sales Transactions: Basket line items, timestamp, terminal identifier, store location, applied promotional discounts, and VAT tax bracket totals.
- Payment Verification Tokens: Masked payment references, card brand, last 4 digits of the payment card, and acquirer authorization codes. Grosa does not store primary account numbers (PAN) or CVV/CVC security codes.
- Loyalty and Customer Accounts (Tenant-Configured): Customer name, contact email, mobile telephone number, and accumulated store reward points, captured strictly at the discretion and direction of the merchant.
3.4 Hardware, Edge, and Network Telemetry
- Hardware Profile: POS terminal motherboard UUID, Android / iOS / Linux operating system version, network MAC address, local subnet IP address, and paired peripheral configurations (certified scale, thermal receipt printer, barcode laser).
- Diagnostic Metrics: Local SQLite sync buffer status, battery health levels, offline queue latency, memory consumption, and thermal warnings.
4. Artificial Intelligence Architecture and Zero-PII Guarantee
Grosa integrates proprietary machine learning algorithms to assist retail merchants with inventory demand forecasting, automated reorder thresholds, dynamic perishable markdown scheduling, and catalog classification.
- Zero PII Exposure: Machine learning models consume strictly aggregated, de-identified numerical time-series (e.g., hourly SKU sell-through quantities, historical weather coefficients, weekday velocity). No customer names, phone numbers, individual credit card records, or employee identities are ever piped into training pipelines.
- No Third-Party Model Training: Your proprietary business data, retail catalog, and store transactions are never used to train public, open, or third-party commercial foundational models.
- Tenant Isolation: Predictive model artifacts operate exclusively within isolated tenant boundaries. Your sales patterns and gross margins are never cross-leveraged to advantage competing retail businesses.
5. Sub-processors and Third-Party Infrastructure
To maintain high availability, low latency, and robust cryptographic security, Grosa partners with select, industry-leading infrastructure providers. All core database records and application workloads are hosted strictly within the European Union:
| Provider | Purpose | Primary Processing Location | Data Transfer Safeguards |
| :--- | :--- | :--- | :--- |
| Amazon Web Services EMEA SARL | Cloud computing, PostgreSQL database clusters, and object storage | Frankfurt am Main (eu-central-1), Germany | EU Data Residency, ISO 27001, SOC 2 Type II |
| Hetzner Online GmbH | Cold backup vaults, secondary replication, and disaster recovery | Falkenstein, Germany | EU Data Residency, ISO 27001 |
| Vercel Inc. | Web frontend distribution and edge content delivery network (CDN) | European Edge Nodes (Frankfurt, Paris, Amsterdam, London) | Standard Contractual Clauses (SCCs), DPA |
| Mollie B.V. | Primary subscription billing and European payment gateway integration | Amsterdam, Netherlands | Licensed Dutch Payment Institution (DNB), PCI-DSS Level 1 |
| Stripe Payments Europe Ltd. | Card acquiring, subscription invoicing, and fraud detection | Dublin, Ireland | Central Bank of Ireland Licensed, PCI-DSS Level 1 |
| Plausible Analytics | Privacy-first website analytics (zero cookies, zero IP logging) | EU-hosted servers | Complete anonymization, no cross-site tracking |
6. Data Retention and Statutory Holding Schedules
We retain data only for as long as necessary to fulfill the operational purposes outlined in this policy or to comply with statutory fiscal obligations:
- Active Merchant Accounts: Maintained continuously throughout the active subscription term.
- Cancelled Merchant Accounts: All active tenant data stores are frozen upon termination and retained in read-only export format for 90 calendar days, after which databases, local device sync tokens, and object stores are cryptographically erased.
- Statutory Fiscal and Accounting Records: European retail laws require transactional ledgers, fiscal daily Z-reports, and tax journals to be preserved for statutory audit periods:
- Germany: 10 years pursuant to § 147 Abgabenordnung (AO) and GoBD.
- France: 10 years pursuant to Article L123-22 of the Code de Commerce.
- Netherlands: 7 years pursuant to Article 52 of the Algemene wet inzake rijksbelastingen (AWR).
- Belgium & Austria: 7 to 10 years in compliance with national commercial bookkeeping statutes.
- United Kingdom: 6 years under HMRC statutory business record mandates.
- Diagnostic Telemetry and Access Logs: Rotated, encrypted, and automatically purged after 90 days.
7. International Data Transfers
All production application databases, edge synchronization buffers, and customer databases reside on physical server infrastructure within the European Union (Germany).
Because Mars AI Technology Solutions Limited is incorporated in the United Kingdom, operational and corporate communications between our London office and EU server clusters are governed under the European Commission Adequacy Decision for the United Kingdom adopted pursuant to Article 45(1) of Regulation (EU) 2016/679. In the event of secondary technical support requiring escalation outside the European Economic Area, transfers are safeguarded using European Commission Standard Contractual Clauses (SCCs) and supplementary technical encryption measures.
8. Data Subject Rights (GDPR Articles 15–22)
Every individual whose personal data is processed by Grosa enjoys comprehensive rights under European and UK data protection laws:
- Right of Access (Article 15 GDPR): Obtain confirmation as to whether your personal data is being processed and receive a comprehensive electronic copy.
- Right to Rectification (Article 16 GDPR): Demand immediate correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten", Article 17 GDPR): Request the total deletion of your personal data where retention is no longer legally justifiable or required for statutory fiscal audits.
- Right to Restriction of Processing (Article 18 GDPR): Freeze the processing of your data while a dispute regarding accuracy or legal grounds is being investigated.
- Right to Data Portability (Article 20 GDPR): Receive your personal data in a structured, machine-readable format (JSON or CSV) or demand direct transfer to an alternative provider.
- Right to Object (Article 21 GDPR): Object at any time to data processing conducted on the basis of legitimate interests or for direct marketing purposes.
- Rights regarding Automated Decision-Making (Article 22 GDPR): Protection against legal effects arising solely from automated profiling. Grosa does not execute fully automated decisions that produce legal or similarly significant effects on individuals.
To exercise any of these statutory rights, submit a written request to our Data Protection Officer at [email protected]. Responses are provided within 30 calendar days without fee.
9. Security Architecture and Technical Measures (TOMs)
Grosa implements defense-in-depth technical and organizational measures (TOMs) to safeguard data against accidental destruction, loss, alteration, or unauthorized disclosure:
- Cryptographic Encryption: All persistent database storage volumes, file systems, and backups are protected using AES-256-GCM encryption. All communications between POS edge hardware, merchant web portals, and backend APIs utilize TLS 1.3 cryptographic protocols with strict cipher suite enforcement.
- Access Controls and Identity Governance: Access to operational production infrastructure is restricted through hardware security keys (FIDO2 / WebAuthn), multi-factor authentication (MFA), and just-in-time least-privilege role policies.
- Network Isolation and Perimeter Defense: Production systems operate within isolated Virtual Private Clouds (VPC) protected by enterprise Web Application Firewalls (WAF), automated DDoS absorption layers, and continuous ingress rate limiting.
- Resilience and Disaster Recovery: Multi-availability-zone database clustering with automated differential backups stored across geographically separated German facilities (Frankfurt and Falkenstein). Disaster recovery drills are executed semi-annually.
10. Supervisory Authorities and Right to Complain
If you believe that our processing of your personal information infringes European or national data protection laws, you retain the statutory right to lodge an official complaint with the relevant Data Protection Authority in your jurisdiction:
- Netherlands: Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl
- Germany: Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — bfdi.bund.de
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
- Belgium: Autorité de protection des données / Gegevensbeschermingsautoriteit (APD-GBA) — gegevensbeschermingsautoriteit.be
- Austria: Österreichische Datenschutzbehörde (DSB) — dsb.gv.at
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Turkey: Kişisel Verileri Koruma Kurumu (KVKK) — kvkk.gov.tr
11. Amendments and Notification of Changes
Grosa reserves the right to amend this Privacy Policy to reflect advancements in technology, adjustments in statutory retail regulations, or enhancements to our platform architecture. When material changes occur, registered merchant administrators will receive prior notice via email and an administrative dashboard banner at least 30 calendar days before the revisions take legal effect. Continued utilization of Grosa services following the effective date constitutes acceptance of the updated terms.