Loading…
Clocktice — Workforce Management & Time Tracking Platform For Users and Customer Organizations in the EEA and United Kingdom
Effective date: June 02, 2025 Last updated: June 02, 2025
ICI Tech Teknoloji A.Ş. processes personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018).
| Data Controller | ICI Tech Teknoloji A.Ş. |
| app@icitech.com.tr | |
| Website | https://clocktice.com/ |
For privacy requests: app@icitech.com.tr.
EU Representative (GDPR Article 27): For EEA users, we are in the process of designating an EU representative. Details will be published at https://clocktice.com/privacy once appointed.
Data Protection Officer: We are assessing whether a DPO appointment is mandatory given the nature of employee biometric data processing. Contact: app@icitech.com.tr.
As Data Controller (Articles 4(7) and 6): We control admin user account data, our operational security data, and direct communications.
As Data Processor (Articles 4(8) and 28): We process employee attendance, location, biometric, and performance data on behalf of customer organizations. The customer is the data controller.
Data Processing Agreement (Article 28): Our Terms of Service include data processing clauses satisfying Article 28 GDPR. Customers in the EEA or UK may request a standalone DPA at app@icitech.com.tr.
The optional facial recognition feature processes biometric data within the meaning of GDPR Article 9(1) (data concerning a natural person's physical characteristics that allows unique identification).
Processing biometric data requires a lawful basis under both Articles 6 and 9. The customer organization, as data controller, must rely on Article 9(2)(b) (employment law obligations — where permitted under national law) or Article 9(2)(a) (explicit consent) to process employee biometric data.
Our obligations as data processor: We process biometric data only as instructed by the customer. We implement appropriate technical and organizational security measures for biometric data. We do not use biometric data for any purpose other than identity verification at check-in/check-out.
Customer obligations: Ensure national employment law permits biometric data processing for attendance; obtain employees' explicit consent where required; provide employees with clear information under Article 13 GDPR; conduct a DPIA (Data Protection Impact Assessment) as required under Article 35 where large-scale biometric processing is involved.
If in doubt, use QR code or camera-free alternatives, which do not involve biometric data.
Clocktice processes employee attendance, location, leave, and performance data on behalf of customers. Under GDPR Article 88 and applicable national employment laws, customers must:
Have a lawful basis for employee monitoring under Article 6 (typically Art. 6(1)(b) — performance of employment contract, or Art. 6(1)(c) — legal obligation). Inform employees under Articles 13/14 that their attendance, location (if enabled), and performance data is processed via Clocktice. Establish internal policies for using attendance and performance data in employment decisions. Apply proportionality — only collect data necessary for the legitimate business purpose.
Location data captured at check-in/check-out is not continuous tracking — it is a point-in-time verification. Nonetheless, customers must ensure:
Employees are informed that location is collected at check-in and check-out. A lawful basis exists (typically employment contract or legitimate interest balanced against employee rights). Location data is retained only as long as necessary for attendance management purposes.
Admin account data (Controller): Email, password (hashed), name, job title, company details.
Employee attendance data (Processor): Check-in/check-out timestamps, type (QR, camera, camera-free), location coordinates (if enabled).
Biometric data (Processor — optional): Facial recognition data for identity verification.
Leave and break data (Processor): Leave type, dates, approval status; break start/end times.
Shift and scheduling data (Processor): Planned shifts, changes, working hours.
Performance and reporting data (Processor): Monthly summaries, weekly reports, break statistics.
Technical and security data (Controller): IP addresses, session logs, crash reports.
| Purpose | GDPR Legal Basis |
|---|---|
| Admin account management | Art. 6(1)(b) — Performance of contract |
| Platform services | Art. 6(1)(b) — Performance of contract |
| Employee data processing (as Processor) | Art. 6(1)(b) — Performance of contract with customer |
| Location verification (as Processor) | Customer's Art. 6(1)(b) or (c) |
| Biometric data — facial recognition (as Processor) | Art. 9(2)(a) — Explicit consent (obtained by customer) / Art. 9(2)(b) where national law permits |
| Security monitoring | Art. 6(1)(f) — Legitimate interests |
| Billing and subscription | Art. 6(1)(b) — Performance of contract |
| Legal obligations | Art. 6(1)(c) — Legal obligation |
We do not sell employee data. We do not share attendance, location, or biometric data with advertising networks. We do not use employee data for AI training or profiling. We do not make fully automated employment decisions about individuals (Art. 22). We do not use advertising identifiers.
For admin users: Contact app@icitech.com.tr — subject "GDPR Data Subject Request — Clocktice".
For employees: Contact your employer first. The employer is the data controller for your attendance, location, biometric, and performance data. If your employer cannot assist, contact us at app@icitech.com.tr and we will route your request.
Rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), object (Art. 21), not to be subject to automated decisions with significant effects (Art. 22), lodge a complaint (Art. 77).
Response within one month, free of charge.
| Country / Region | Authority | Website |
|---|---|---|
| 🇬🇧 United Kingdom | ICO (primary for UK processing) | https://ico.org.uk |
| 🇫🇷 France | CNIL | https://www.cnil.fr |
| 🇩🇪 Germany | BfDI + state DPAs | https://www.bfdi.bund.de |
| 🇪🇸 Spain | AEPD | https://www.aepd.es |
| Other EEA | Your national DPA | https://edpb.europa.eu/about-edpb/about-edpb/members_en |
For EEA transfers, we rely on Standard Contractual Clauses approved by the European Commission. Where data is processed by infrastructure providers, we rely on appropriate transfer mechanisms.
Admin accounts: duration plus 3 years after termination. Employee data: per customer configuration and contractual terms. Biometric data: per customer configuration; deleted on termination. Subscription records: 10 years. Technical logs: 12 months. Support communications: 3 years.
TLS 1.2+ in transit; encryption at rest. Biometric data processed with heightened security measures. Breach notification: ICO (UK) within 72 hours (UK GDPR Art. 33); relevant EEA supervisory authority within 72 hours (GDPR Art. 33); individuals notified without undue delay for high-risk breaches (Art. 34).
Clocktice is a business platform for adult users. We do not knowingly process data from individuals under 18.
Material changes notified 14 days in advance. Current version: https://clocktice.com/privacy/gdpr.
Email: app@icitech.com.tr DPA requests: app@icitech.com.tr — subject "DPA Request — Clocktice" Website: https://clocktice.com/
Acknowledge within 5 business days, resolve within one month.