GDPR Compliance & Data Processing Agreement
- ✓Controller vs. Processor Roles: The merchant acts as Data Controller; Grosa operates as Data Processor under Article 28 GDPR with a binding DPA.
- ✓Technical & Organizational Measures: AES-256-GCM encryption at rest, TLS 1.3 in transit, role-based access controls, and automated 72-hour breach notification procedures.
- ✓Data Portability & Deletion: Merchants retain sovereign control with open standard exports (CSV/JSON) and automated deletion upon contract end.
1. Commitment to GDPR and European Data Sovereignty
Mars AI Technology Solutions Limited ("Grosa", "we", "us", or "our") is uncompromisingly committed to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — GDPR), the UK Data Protection Act 2018 (UK GDPR), and Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
The Grosa.io cloud platform and edge POS terminal ecosystem have been architected from the foundation upward adhering strictly to the statutory principles of Privacy by Design and Privacy by Default (Article 25 GDPR). We empower retail merchants across Europe to modernize their store operations while maintaining unassailable data sovereignty.
2. Article 28 Data Processing Agreement (DPA) Framework
Under European data protection jurisprudence, when an enterprise retail subscriber ("Merchant") utilizes the Grosa platform to process retail transactions, customer loyalty accounts, or employee shift rosters:
- The Merchant is the Data Controller under Article 4(7) of the GDPR.
- Grosa acts solely as the Data Processor under Article 4(8) of the GDPR.
Our standardized, enterprise-ready Data Processing Agreement (DPA) is incorporated directly into our commercial subscription contract and satisfies all statutory mandates of Article 28(3) of the GDPR.
2.1 Scope and Subject Matter of Processing
Grosa processes personal data exclusively on behalf of the Merchant for the following operational purposes:
- Provisioning merchant database clusters and edge POS synchronization queues;
- Managing inventory levels, product barcodes, and retail pricing rules;
- Generating cryptographic receipt audit trails, tax summaries, and daily Z-reports;
- Storing customer loyalty balances and contact records (solely where configured by the Merchant);
- Administering employee roles, terminal PIN hashes, and shift logs.
2.2 Processing Strictly on Documented Instructions
Pursuant to Article 28(3)(a) GDPR, Grosa shall process personal data solely upon documented instructions from the Merchant, including with regard to transfers of personal data to a third country, unless required to do so by European Union or national Member State law to which Grosa is subject.
2.3 Personnel Confidentiality Obligations
In accordance with Article 28(3)(b) GDPR, Grosa ensures that all employees, contractors, and software engineers authorized to process merchant personal data have committed themselves to strict statutory and contractual confidentiality obligations.
3. Data Residency: 100% EU Infrastructure with Zero Non-EU Spillage
To eliminate exposure to foreign surveillance legislation and ensure compliance with the Schrems II ruling of the European Court of Justice:
- Core Production Servers: Hosted within Amazon Web Services (AWS) EMEA SARL in Frankfurt am Main (
eu-central-1), Germany. - Cold Backup Vaults: Replicated to independent facilities operated by Hetzner Online GmbH in Falkenstein (Vogtland), Germany.
- No Non-EU Spillage: Merchant tenant databases, transactional records, and customer PII are never routed, stored, or processed on physical servers outside the European Economic Area.
- UK Corporate Governance: For operational oversight conducted from our London headquarters, data flows are safeguarded under the European Commission Adequacy Decision for the United Kingdom (Article 45 GDPR) and supplemented by standard contractual clauses (SCCs).
4. Sub-processors and Third-Party Vendor Governance
Pursuant to Article 28(2) and Article 28(4) of the GDPR, Grosa maintains an authorized register of specialized sub-processors:
| Sub-processor | Operational Role | Data Processing Center | Safeguards & Certifications | | :--- | :--- | :--- | :--- | | Amazon Web Services EMEA SARL | Cloud infrastructure, managed PostgreSQL clusters, object storage | Frankfurt am Main, Germany | ISO 27001, SOC 2 Type II, C5, PCI-DSS Level 1 | | Hetzner Online GmbH | Cold encrypted backup arks and disaster recovery replication | Falkenstein, Germany | ISO 27001, 100% German Data Center | | Vercel Inc. | Edge web application firewall, static assets, and CDN delivery | Frankfurt & European Edge Nodes | Standard Contractual Clauses (SCCs), DPA | | Mollie B.V. | Subscription payment processing and merchant acquiring | Amsterdam, Netherlands | Licensed by De Nederlandsche Bank (DNB), PCI-DSS Level 1 | | Stripe Payments Europe Ltd. | Card payments, fraud mitigation, and subscription billing | Dublin, Ireland | Central Bank of Ireland Licensed, PCI-DSS Level 1 |
4.1 Prior Notification of Sub-processor Changes
Grosa will notify the Merchant of any intended appointment or replacement of a sub-processor at least 30 calendar days in advance via email or administrative portal announcement. The Merchant retains the right to object to such changes on reasonable, documented data protection grounds.
5. Technical and Organizational Security Measures (TOMs - Article 32)
Grosa implements industry-standard Technical and Organizational Measures (TOMs) designed to guarantee a level of security appropriate to the risk:
5.1 Pseudonymization and Cryptographic Encryption
- Encryption at Rest: All tenant databases, SQLite edge replicas, persistent volumes, and backup archives are encrypted utilizing AES-256-GCM algorithms. Encryption keys are managed via dedicated Hardware Security Modules (HSM) with automatic annual rotation.
- Encryption in Transit: All network traffic between edge POS terminals, barcode scanners, merchant administrative portals, and cloud microservices is strictly encrypted via TLS 1.3 using modern forward-secret cipher suites.
5.2 System Resilience and Disaster Recovery
- Multi-Availability-Zone (Multi-AZ) database replication guarantees a Recovery Point Objective (RPO < 1 hour) and Recovery Time Objective (RTO < 4 hours).
- Cold differential backups are encrypted and mirrored daily to secondary physical infrastructure in Falkenstein. Disaster recovery drills are validated semi-annually.
5.3 Identity and Access Management (IAM)
- Granular Role-Based Access Control (RBAC) separates administrative permissions from cashier operational interfaces.
- Cashier PIN codes are stored strictly as salted, iterative one-way cryptographic hashes. Raw PINs are never persisted in plaintext.
- Production server access for Grosa systems engineering staff requires FIDO2/WebAuthn hardware security keys, multi-factor authentication, and temporary just-in-time access approvals.
5.4 Vulnerability Management and Penetration Testing
Independent CREST-accredited cybersecurity firms perform annual penetration testing of our web APIs, cloud microservices, and POS terminal applications. Continuous automated vulnerability scanning monitors all source repositories.
6. Personal Data Breach Management Protocol (Articles 33 & 34)
Grosa maintains a rigorous Computer Security Incident Response Plan (CSIRP):
- Incident Detection and Triage: Automated security telemetry alerts on-call security engineers 24/7/365 to potential unauthorized access or anomalous data exfiltration attempts.
- Notification within 72 Hours: In the event of a confirmed personal data breach affecting Merchant data, Grosa will notify the affected Merchant without undue delay and, where feasible, no later than 72 hours after becoming aware of the incident (Article 33(2) GDPR).
- Comprehensive Breach Dossier: The breach notification shall provide:
- A description of the nature of the breach, including affected data categories and approximate numbers of data subjects;
- The name and contact details of the Data Protection Officer (
[email protected]); - Likely operational and privacy consequences for affected data subjects;
- Detailed remediation measures already implemented or proposed to mitigate potential adverse effects.
7. Assistance with Data Subject Rights (Articles 15–22)
Because Grosa acts as a Data Processor, any data subject request (access, rectification, erasure, restriction, portability) received directly by Grosa will be forwarded to the relevant Merchant within 48 business hours.
Grosa equips the Merchant with self-service administrative tools directly within the Grosa dashboard:
- Instant Data Export: Download complete customer transaction history in structured, machine-readable JSON or CSV format (Article 20 GDPR).
- Cryptographic Pseudonymization & Anonymization: Sanitize customer loyalty records and personal identifiers with a single administrative action, while preserving statutory aggregate tax numbers required by national fiscal authorities (Article 17 GDPR).
8. Data Deletion, Return, and Post-Termination Clean-Up
Upon termination of the SaaS agreement:
- Grosa will maintain the Merchant's database in a secured, read-only export state for 90 calendar days, enabling the Merchant to retrieve all data without technical hindrance.
- Upon expiration of the 90-day grace period, Grosa will permanently delete and overwrite all active database instances, local synchronization tokens, and temporary files, certifying completion upon written request (Article 28(3)(g) GDPR).
- Statutory fiscal archives required by national tax legislation (e.g., German GoBD/KassenSichV 10-year retention, Dutch AWR 7-year retention) are maintained in immutable, sealed archives until the expiration of statutory holding periods.
9. Audits and Compliance Verification (Article 28(3)(h))
Grosa makes available to the Merchant all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR:
- Grosa provides copies of independent third-party audit reports (including ISO 27001 certificates and SOC 2 Type II summaries) upon request.
- If an on-site inspection is reasonably required by a competent supervisory authority or requested by the Merchant, Grosa will facilitate such audits during standard business hours with reasonable prior notice (minimum 30 calendar days).
10. Contacting the Data Protection Desk & Executing a DPA
To request a countersigned copy of our standard Data Processing Agreement (DPA) or to initiate technical privacy consultations, contact:
- Data Protection Officer (DPO):
[email protected] - Legal & Compliance Desk:
[email protected] - Mailing Address: Mars AI Technology Solutions Limited, Attn: Data Protection Officer, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.