---
title: "Privacy Notice (GDPR & UK GDPR)"
description: "GDPR privacy notice for EEA and UK users."
canonical: "https://clocktice.com/en/yasal/gdpr/"
locale: "en"
type: "WebPage"
keywords: ["legal", "gdpr", "Clocktice"]
dateModified: "2026-08-30"
lastModified: "2026-08-30"
languageAlternates: ["https://clocktice.com/tr/yasal/gdpr/", "https://clocktice.com/en/yasal/gdpr/", "https://clocktice.com/de/yasal/gdpr/", "https://clocktice.com/fr/yasal/gdpr/", "https://clocktice.com/es/yasal/gdpr/"]
---

# Privacy Notice (GDPR & UK GDPR)

GDPR privacy notice for EEA and UK users.

# Privacy Notice (GDPR & UK GDPR)

**Clocktice — Workforce Management & Time Tracking Platform**
**For Users and Customer Organizations in the EEA and United Kingdom**

**Effective date: June 02, 2025**
**Last updated: June 02, 2025**

---

## 1. Introduction

**ICI Tech Teknoloji A.Ş.** processes personal data in compliance with the **EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)** and the **UK GDPR** (as retained in UK law by the European Union (Withdrawal) Act 2018).

| | |
|---|---|
| **Data Controller** | ICI Tech Teknoloji A.Ş. |
| **Email** | app@icitech.com.tr |
| **Website** | https://clocktice.com/ |

For privacy requests: app@icitech.com.tr.

**EU Representative (GDPR Article 27):** For EEA users, we are in the process of designating an EU representative. Details will be published at https://clocktice.com/privacy once appointed.

**Data Protection Officer:** We are assessing whether a DPO appointment is mandatory given the nature of employee biometric data processing. Contact: app@icitech.com.tr.

---

## 2. Our Role Under GDPR

**As Data Controller (Articles 4(7) and 6):** We control admin user account data, our operational security data, and direct communications.

**As Data Processor (Articles 4(8) and 28):** We process employee attendance, location, biometric, and performance data on behalf of customer organizations. The customer is the data controller.

**Data Processing Agreement (Article 28):** Our Terms of Service include data processing clauses satisfying Article 28 GDPR. Customers in the EEA or UK may request a standalone DPA at app@icitech.com.tr.

---

## 3. Biometric Data — Article 9 GDPR

The optional facial recognition feature processes **biometric data** within the meaning of **GDPR Article 9(1)** (data concerning a natural person's physical characteristics that allows unique identification).

Processing biometric data requires a lawful basis under both Articles 6 and 9. The customer organization, as data controller, must rely on **Article 9(2)(b)** (employment law obligations — where permitted under national law) or **Article 9(2)(a)** (explicit consent) to process employee biometric data.

**Our obligations as data processor:** We process biometric data only as instructed by the customer. We implement appropriate technical and organizational security measures for biometric data. We do not use biometric data for any purpose other than identity verification at check-in/check-out.

**Customer obligations:** Ensure national employment law permits biometric data processing for attendance; obtain employees' explicit consent where required; provide employees with clear information under Article 13 GDPR; conduct a DPIA (Data Protection Impact Assessment) as required under Article 35 where large-scale biometric processing is involved.

If in doubt, use QR code or camera-free alternatives, which do not involve biometric data.

---

## 4. Employee Data — Article 88 GDPR

Clocktice processes employee attendance, location, leave, and performance data on behalf of customers. Under **GDPR Article 88** and applicable national employment laws, customers must:

Have a lawful basis for employee monitoring under Article 6 (typically Art. 6(1)(b) — performance of employment contract, or Art. 6(1)(c) — legal obligation). Inform employees under Articles 13/14 that their attendance, location (if enabled), and performance data is processed via Clocktice. Establish internal policies for using attendance and performance data in employment decisions. Apply proportionality — only collect data necessary for the legitimate business purpose.

---

## 5. Location Verification — GDPR Considerations

Location data captured at check-in/check-out is not continuous tracking — it is a point-in-time verification. Nonetheless, customers must ensure:

Employees are informed that location is collected at check-in and check-out. A lawful basis exists (typically employment contract or legitimate interest balanced against employee rights). Location data is retained only as long as necessary for attendance management purposes.

---

## 6. Data We Process

**Admin account data (Controller):** Email, password (hashed), name, job title, company details.

**Employee attendance data (Processor):** Check-in/check-out timestamps, type (QR, camera, camera-free), location coordinates (if enabled).

**Biometric data (Processor — optional):** Facial recognition data for identity verification.

**Leave and break data (Processor):** Leave type, dates, approval status; break start/end times.

**Shift and scheduling data (Processor):** Planned shifts, changes, working hours.

**Performance and reporting data (Processor):** Monthly summaries, weekly reports, break statistics.

**Technical and security data (Controller):** IP addresses, session logs, crash reports.

---

## 7. Legal Bases (GDPR)

| Purpose | GDPR Legal Basis |
|---|---|
| Admin account management | Art. 6(1)(b) — Performance of contract |
| Platform services | Art. 6(1)(b) — Performance of contract |
| Employee data processing (as Processor) | Art. 6(1)(b) — Performance of contract with customer |
| Location verification (as Processor) | Customer's Art. 6(1)(b) or (c) |
| Biometric data — facial recognition (as Processor) | Art. 9(2)(a) — **Explicit consent** (obtained by customer) / Art. 9(2)(b) where national law permits |
| Security monitoring | Art. 6(1)(f) — Legitimate interests |
| Billing and subscription | Art. 6(1)(b) — Performance of contract |
| Legal obligations | Art. 6(1)(c) — Legal obligation |

---

## 8. What We Do Not Do

We do not sell employee data. We do not share attendance, location, or biometric data with advertising networks. We do not use employee data for AI training or profiling. We do not make fully automated employment decisions about individuals (Art. 22). We do not use advertising identifiers.

---

## 9. Your Rights Under GDPR / UK GDPR

**For admin users:** Contact app@icitech.com.tr — subject "GDPR Data Subject Request — Clocktice".

**For employees:** Contact your employer first. The employer is the data controller for your attendance, location, biometric, and performance data. If your employer cannot assist, contact us at app@icitech.com.tr and we will route your request.

Rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), object (Art. 21), not to be subject to automated decisions with significant effects (Art. 22), lodge a complaint (Art. 77).

Response within one month, free of charge.

---

## 10. Right to Lodge a Complaint

| Country / Region | Authority | Website |
|---|---|---|
| 🇬🇧 United Kingdom | **ICO** (primary for UK processing) | https://ico.org.uk |
| 🇫🇷 France | CNIL | https://www.cnil.fr |
| 🇩🇪 Germany | BfDI + state DPAs | https://www.bfdi.bund.de |
| 🇪🇸 Spain | AEPD | https://www.aepd.es |
| Other EEA | Your national DPA | https://edpb.europa.eu/about-edpb/about-edpb/members_en |

---

## 11. International Data Transfers

For EEA transfers, we rely on Standard Contractual Clauses approved by the European Commission. Where data is processed by infrastructure providers, we rely on appropriate transfer mechanisms.

---

## 12. Data Retention

Admin accounts: duration plus 3 years after termination. Employee data: per customer configuration and contractual terms. Biometric data: per customer configuration; deleted on termination. Subscription records: 10 years. Technical logs: 12 months. Support communications: 3 years.

---

## 13. Security

TLS 1.2+ in transit; encryption at rest. Biometric data processed with heightened security measures. **Breach notification:** ICO (UK) within 72 hours (UK GDPR Art. 33); relevant EEA supervisory authority within 72 hours (GDPR Art. 33); individuals notified without undue delay for high-risk breaches (Art. 34).

---

## 14. Children's Privacy

Clocktice is a business platform for adult users. We do not knowingly process data from individuals under 18.

---

## 15. Changes

Material changes notified 14 days in advance. Current version: https://clocktice.com/privacy/gdpr.

---

## 16. Contact Us

**Email:** app@icitech.com.tr
**DPA requests:** app@icitech.com.tr — subject "DPA Request — Clocktice"
**Website:** https://clocktice.com/

Acknowledge within 5 business days, resolve within one month.

## Other Legal Pages

- [Privacy Policy](https://clocktice.com/en/yasal/gizlilik/)
- [Terms of Service](https://clocktice.com/en/yasal/kullanim-sartlari/)
- [Subscription Terms](https://clocktice.com/en/yasal/abonelik-kosullari/)
- [Data Deletion](https://clocktice.com/en/yasal/veri-silme/)
- [KVKK Notice](https://clocktice.com/en/yasal/kvkk/)
- [Cookie Policy](https://clocktice.com/en/yasal/cerez/)

## Platforms

- iOS App Store: https://apps.apple.com/tr/app/clocktice/id6468580733?l=tr
- Google Play: https://play.google.com/store/apps/details?id=com.b1.clocktice&hl=en
- Web: https://clocktice.com
- KVKK and GDPR aligned
- SSL-secured data transfer
- Available on iOS and Android
- 24/7 support team
- Industry-specific demos

## Identity

- Product: **Clocktice** — Manage Time, Boost Productivity
- Clocktice is a mobile-ready platform that unifies workforce management and time tracking in one place.
- Email: app@icitech.com.tr
- Phone: +90 212 366 57 26
- Hours: Monday – Friday, 09:00 – 18:00
- Locales: [TR](https://clocktice.com/tr/) · [EN](https://clocktice.com/en/) · [DE](https://clocktice.com/de/) · [FR](https://clocktice.com/fr/) · [ES](https://clocktice.com/es/)

## Get Started

[Request a Demo](https://clocktice.com/en/iletisim/)
