Loading…
Clocktice — Workforce Management & Time Tracking Platform
Effective date: June 02, 2025 Last updated: June 02, 2025
Clocktice is developed and operated by ICI Tech Teknoloji A.Ş. ("Company", "we", "us", or "our"). Contact: app@icitech.com.tr.
| Company | ICI Tech Teknoloji A.Ş. |
| Website | https://clocktice.com/ |
| app@icitech.com.tr |
What Clocktice is: Clocktice is a B2B SaaS workforce management platform enabling businesses to track employee attendance, manage shifts, record leave and breaks, verify location, and generate workforce reports. It is not an HR consultancy, legal advisor, or payroll processor.
As Data Controller: We control personal data for organization admin user accounts, our own operational security, and direct communications.
As Data Processor: We process employee data on behalf of our business customers. The business customer (employer) is the data controller for its employees' attendance, location, biometric, and performance data. We process this data only as instructed by the customer.
Customer responsibilities as data controller: Customers using Clocktice are responsible for informing employees about the platform and data processing activities; ensuring a lawful basis for employee monitoring including location verification and, where used, biometric data; complying with applicable employment and data protection law; facilitating employee data subject requests.
Admin Account Data: Email address, password (one-way hash), name, job title, company name and address, tax identification number.
Employee Data (as Processor): Employee name, surname, and employee ID (entered by the customer); check-in and check-out timestamps and type (QR, camera, camera-free); geographical location at check-in/check-out (if enabled by customer); biometric data (facial recognition) — only if customer enables this optional feature; break start and end times; leave type, dates, request and approval status, remaining entitlement; shift schedule and any changes; monthly and weekly working hour summaries.
Subscription and Billing Data: Plan tier, billing dates, transaction records. Payment card details are processed by our payment provider — we never store card numbers.
API Integration Data: Data exchanged with ERP, CRM, or accounting systems connected by the customer via API — processed as instructed by the customer.
Technical and Security Data: IP addresses, session logs, access timestamps, app version, device type, crash reports.
Communications Data: Email and message content from support, sales, and demo inquiries.
Biometric data (facial recognition) and location data are sensitive categories that require special care. We process them only when the customer enables these optional features and only as instructed by the customer.
The facial recognition feature is optional and must be actively enabled by the customer organization.
When enabled: facial recognition data is captured from employees at check-in/check-out and processed to verify identity. Facial recognition data constitutes biometric data under GDPR Article 9 and equivalent national laws. The customer organization, as data controller, must obtain employees' explicit consent before enabling this feature. Where consent cannot be obtained, customers must not use the facial recognition feature. We process facial recognition data only as instructed by the customer and only for identity verification at check-in/check-out.
Customers can disable facial recognition at any time. Alternative check-in methods (QR code, camera-free) are always available.
When the customer enables location verification, the employee's geographical coordinates are captured at the moment of check-in or check-out to confirm they are at the designated work location. Location is captured only at the time of the check-in event — it is not continuously tracked. Customers must inform employees that location is collected at check-in/check-out. Location data is stored under the customer's account and visible to authorized managers.
| Purpose | Legal Basis |
|---|---|
| Admin account management | Performance of contract |
| Platform service delivery | Performance of contract |
| Employee data processing (as Processor) | Performance of contract with customer |
| Location verification (as Processor) | Customer's lawful basis / employee consent |
| Biometric data — facial recognition (as Processor) | Explicit consent (employee consent obtained by customer) |
| API integrations | Performance of contract |
| Security monitoring | Legitimate interest |
| SMS notifications (leave approvals) | Performance of contract |
| Billing and subscription management | Performance of contract |
| Support and demo communications | Legitimate interest / Contract |
| Legal obligations | Legal obligation |
We do not sell employee data or admin account data. We do not share employee attendance or location data with advertising networks. We do not use biometric data for any purpose other than identity verification at check-in/check-out. We do not use advertising identifiers. We do not provide payroll processing, legal advice, or HR consulting. We do not access employee data for any purpose other than providing the Service to the customer.
When a customer uses the leave management module, SMS notifications may be sent to employees (e.g. to confirm leave approval or rejection). SMS delivery is handled by a third-party SMS provider. Only the minimum data needed for delivery (phone number and message content) is shared with the SMS provider.
Clocktice supports integration with ERP, CRM, and accounting systems via API. When customers connect third-party systems, data exchanged through these integrations is governed by the third-party system's own terms. We process integrated data only as instructed by the customer.
| Service | Purpose | Policy |
|---|---|---|
| Cloud infrastructure provider | Hosting and data storage | Available on request |
| Payment provider | Subscription billing | Available on request |
| SMS provider | Leave approval notifications | Available on request |
| ERP/CRM systems | Customer-configured API integrations | Customer-managed |
We share data only as necessary: with cloud infrastructure providers (platform operations); with payment provider (billing); with SMS provider (notifications); with customer-configured ERP/CRM systems (API integration as instructed by customer); with financial and legal advisors (compliance); with courts and regulators (lawful requests); with potential acquirers under strict confidentiality. We do not share employee data with advertising networks.
ICI Tech Teknoloji A.Ş. operates in Turkey and the UK. Cloud infrastructure providers may process data internationally. All transfers are subject to appropriate safeguards per KVKK Article 9 and, for EEA/UK users, Standard Contractual Clauses and UK IDTAs.
Admin account data: duration of subscription plus 3 years after termination. Employee attendance, location, leave, and break data: per customer configuration and contractual terms. Biometric data: per customer configuration; deleted upon termination. Subscription records: 10 years per Turkish and UK commercial law. Support and demo communications: 3 years. Technical logs: 12 months.
TLS 1.2+ in transit; encryption at rest. Role-based access controls. Location and biometric data restricted to authorized managers and HR personnel. Regular security assessments. Data breach response plan per KVKK and UK GDPR requirements.
Admin users: contact app@icitech.com.tr. Employees: contact your employer first — the employer is the data controller for your attendance and biometric data. If your employer cannot assist, contact us and we will route your request. We respond within 30 days, free of charge.
If you are in the EEA or UK, GDPR and/or UK GDPR applies. Read our GDPR Privacy Notice at https://clocktice.com/privacy/gdpr for full details including biometric data Article 9 protections, Article 88 employee data, supervisory authority contacts, and breach notification rights.
Material changes notified at least 14 days in advance. Current version at https://clocktice.com/privacy.
Email: app@icitech.com.tr Website: https://clocktice.com/ Subject: "Privacy Request — Clocktice"
We acknowledge enquiries within 5 business days.
This Policy is governed by the laws of the Republic of Turkey, including KVKK No. 6698. Disputes are subject to the applicable courts based on the governing law.