Skip to content
Menu

Privacy Policy – Mroz Faltas

Last updated: October 2, 2026

About Mroz Faltas

Mroz Faltas is a software system designed to help retail stores and commercial establishments track out-of-stock items and manage customer orders.

The system consists of:

  • A Windows server installed directly on the store’s own on-premise computer;
  • Windows client applications;
  • An Android application.

These components operate and communicate within the store’s local network; the only external communication is the optional AI features described below, when triggered.

Who is responsible for your data (Data Controller)

The store (the business client that uses the software) is the data controller of all personal and operational data entered into Mroz Faltas under the LGPD (Lei Geral de Proteção de Dados, Brazil’s General Data Protection Law). The store determines what information to record, who can access the system, and how long records are retained.

MrozSoft is only the developer and provider of the software. MrozSoft does not receive, does not host, and has no access to the store’s database, audio recordings, or any other data stored by the business. The entire database resides locally on the store’s own physical server.

Data stored on the store’s server

All information entered into the system is saved exclusively on the store’s local on-premise server. This includes:

  • System users: username, staff role, and login password (stored using PBKDF2 cryptographic hashing);
  • Device credentials: an individual credential for each authorized phone or computer, with platform, app version, and first and last access dates;
  • Merchandise and stock shortages: item name, missing quantity, product code, notes, and optional photo;
  • Customer orders: customer name and phone number provided directly by the customer to store personnel;
  • Audio recordings: voice recordings stored in the audio box (each up to 5 minutes long);
  • Operational logs: audit trail logs recording user actions and system backup files.

Android application permissions

The Mroz Faltas Android app requests only the permissions strictly necessary for its day-to-day business operations:

  • Internet and network state (Wi-Fi): required solely to discover and communicate with the store’s local Mroz Faltas server over the local Wi-Fi network;
  • Microphone: used only to allow voluntary voice recordings in the audio box, activated exclusively when the operator taps the record button;
  • Install packages / updates: required to allow the application to receive and install updates distributed by the store’s local server. When installed from Google Play, the app may also check Google Play for updates;
  • Photos: when the user chooses to, the app opens the device’s own camera or gallery to attach a photo to an item record. There is no ongoing access to the device’s photos.

Artificial intelligence (optional)

Mroz Faltas provides optional artificial intelligence assistance features:

  • Voluntary activation: AI features run only when an operator clicks “Executar com IA” (Run with AI) on an audio box recording or when an administrator explicitly authorizes the analysis of an exported WhatsApp chat history;
  • Provider and API keys: requests are sent by the store’s local server directly to Google Gemini, using the store’s own Google Cloud API key (managed within a Google project owned and controlled by the store);
  • Chat transcript handling: when importing WhatsApp chat exports, participant names are replaced with generic labels (such as P1, P2), although the textual content of the messages is not anonymized;
  • Human confirmation: no stock shortage entry or order is created automatically without prior human review and explicit confirmation.

What the application does not do

To ensure complete clarity and privacy in the workplace:

  • No advertisements: the application does not display ads or marketing banners;
  • No analytics or tracking: we do not use analytics packages, user tracking tools, or behavioral telemetry;
  • No data sales: MrozSoft does not sell, rent, license, or share user, customer, or business data with any third party.

Information security

Mroz Faltas incorporates technical safeguards built into the software architecture:

  • Encrypted communication: all communication between apps (Android/Windows) and the local server uses HTTPS, with the store server’s digital certificate pinned inside the app (certificate pinning);
  • Credential security: all operator passwords are protected on the local database using PBKDF2 key derivation functions;
  • Device access control: each authorized device holds a unique credential that administrators can revoke at any time;
  • Session limits: each operator is restricted to a maximum of 2 active devices simultaneously.

Data retention, deletion, and rights

  • Retention periods: retention schedules for stock entries, customer orders, and backups are decided and managed entirely by the store operating the server;
  • Data deletion: store administrators have full authority to delete inventory records, user accounts, authorized devices, and voice recordings. Deleting an audio recording removes it from the server database, keeping only a minimal entry in the audit trail; copies already included in backups remain until discarded under the store’s backup retention settings;
  • Exercising privacy rights: customers wishing to access, correct, or request the deletion of their personal information (such as contact information recorded for customer orders) must contact the store directly. MrozSoft does not possess or host store data and cannot access, modify, or erase these records on its own.

Contact

For technical questions regarding the Mroz Faltas software or this privacy policy:

  • Email: suporte@mrozsoft.com
  • WhatsApp: +55 (66) 99954-3475
  • Developer: MrozSoft (legal entity 48.989.280 MICAEL JOAO MROZINSKI – CNPJ 48.989.280/0001-39), headquartered in Alto Taquari/MT, Brazil.

For the company website, see the Privacy Policy and the Terms of Use.