Legal
Privacy Policy
Hygio — AI-Powered Facility Hygiene Management Platform
Effective date: June 02, 2025 Last updated: June 02, 2025
1. Who We Are
Hygio is developed and operated by ICI Tech Teknoloji A.Ş. ("Company", "we", "us", or "our"), a technology company registered in Turkey.
| Company | ICI Tech Teknoloji A.Ş. |
| Website | https://hygio.app/ |
| app@icitech.com.tr |
What Hygio is: Hygio is a B2B SaaS platform that helps facility operators, FM companies, and cleaning service providers monitor cleaning operations using photo evidence and AI image analysis. It is not a medical device, FDA-approved product, sanitary certification system, or regulatory compliance instrument. "Approved (Clean)" / "Rejected (Dirty)" labels are internal operational quality signals, not third-party inspection certificates or legally binding compliance records.
2. Our Role — Controller and Processor
Hygio operates in two distinct legal roles:
As Data Controller: We are the data controller for platform user account data, our own operational security data, and direct communications with customer organizations.
As Data Processor: We act as a data processor on behalf of our customer organizations (facility operators, FM firms, cleaning companies) for data processed within the platform — including cleaning photos, task records, and staff performance data. The customer organization is the data controller for this data.
Customer organization responsibilities: Organizations using Hygio are responsible for informing their employees and end-users about data processing activities under applicable law, obtaining necessary consents, and complying with employment data protection obligations regarding staff monitoring.
3. Data We Collect
Account and User Data: Email addresses, passwords (one-way hashed), names, job titles, and organization details for admin and field staff accounts.
Staff Task and Performance Data (as Processor): Which staff member completed which cleaning task, at which location, at what time; NFC/QR scan records for location verification; AI hygiene scores associated with individual staff members' task completions.
Facility Photography (as Processor): Before and after photos of facility areas (bathrooms, toilets, washrooms, common areas) uploaded by field staff. These are analyzed by Hygio's own image processing engine and stored under the customer organization's account.
AI Analysis Results (as Processor): "Approved (Clean)" / "Rejected (Dirty)" labels, cleanliness scores, and deficiency flags generated from uploaded photos.
Management Dashboard Data (as Processor): Hygiene scores, trend reports, performance summaries, and alert histories accessible to authorized managers.
End-User Feedback Data (as Processor): Complaints or "dirty report" submissions made by facility visitors via QR/NFC-linked feedback mechanisms. The customer organization is the data controller for this data.
Technical and Security Data: IP addresses, session logs, access timestamps, app version, device type, error and crash reports.
Communications Data: Email correspondence from demo requests, support inquiries, and contract communications.
Staff performance data: Task completion records and AI scores are linked to individual staff members. This constitutes employee monitoring data. Customer organizations must fulfill their own transparency obligations toward their employees under applicable employment and data protection law.
4. Photographs of Facility Areas
Hygio requires camera access to capture before and after photos of cleaning activities. The following applies:
Photos are uploaded to Hygio's cloud infrastructure and analyzed by Hygio's own AI image processing engine. Photos are stored under the customer organization's account for evidence and reporting purposes. Retention periods are governed by the customer organization's configuration and applicable contractual terms. Staff should ensure that photos show only the facility area and do not inadvertently capture individuals. If a photo captures a person, that person's image data is the responsibility of the customer organization as data controller.
5. AI Image Analysis — Hygio's Own Technology
Hygio uses its own proprietary deep learning image processing engine to analyze cleaning photos. Unlike some of our other products, Hygio does not send photos or analysis content to a third-party AI API. All image analysis is performed within Hygio's own infrastructure. The AI model has been trained on labeled visual datasets of facility cleaning contexts.
AI analysis accuracy varies depending on lighting conditions, camera angle, photo quality, and area type. Hygio does not publish a fixed accuracy percentage. The AI classification is an operational tool and does not constitute a certified hygiene inspection.
6. Employee Data — Special Considerations
Hygio tracks task completion and hygiene scores at the individual staff level. This functionality constitutes employee performance monitoring under GDPR Article 88 and applicable national employment laws. Customer organizations using Hygio's staff tracking features must:
Inform their employees that task data and performance scores are recorded and accessible to management. Ensure a lawful basis for employee performance monitoring under applicable employment and data protection law. Establish appropriate internal policies regarding the use of performance data in employment decisions. We assist customer organizations with their data protection obligations through data processing agreement terms — contact app@icitech.com.tr for DPA documentation.
7. Legal Bases for Processing
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Platform service delivery (as Processor) | Performance of contract with customer organization |
| Staff task and performance tracking | Performance of contract / Customer organization's lawful basis |
| AI photo analysis | Performance of contract |
| Security monitoring and access control | Legitimate interest |
| Demo requests and commercial communications | Legitimate interest / Consent |
| Legal obligations | Legal obligation |
8. What We Do Not Do
We do not sell personal data. We do not use cleaning photos or staff data for purposes other than providing the Service to the customer organization. We do not use photos or analysis results to train our AI model without appropriate contractual basis. We do not share staff performance data with third parties outside the customer organization's account. We do not represent that Hygio analysis constitutes medical, sanitary, or regulatory certification. We do not use advertising identifiers.
9. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Cloud infrastructure provider | Hosting, storage, processing | Available on request |
Hygio does not use third-party AI APIs for photo analysis. All AI processing is performed within Hygio's own infrastructure.
10. Data Sharing and Disclosure
We share data only as necessary: with cloud infrastructure providers (platform operations, under strict data processing agreements); with financial and legal advisors (compliance); with courts and regulators (lawful requests); with customer organization's authorized managers (their own staff and facility data via the dashboard); with potential acquirers under strict confidentiality. We do not share data with advertising networks.
11. International Data Transfers
ICI Tech Teknoloji A.Ş. is based in Turkey. Infrastructure providers may operate internationally. All transfers are subject to appropriate safeguards per KVKK Article 9, including standard contractual clauses.
12. Data Retention
Account data is retained for the duration of the account plus 3 years after termination. Cleaning photos and task records are retained according to the customer organization's configuration and applicable contractual terms. AI analysis results are retained in line with cleaning photo retention. Staff performance data is retained per the customer organization's configuration. Communications and demo inquiry data are retained for 3 years. Technical and security logs are retained for 12 months. Financial and contractual records are retained for 10 years per Turkish commercial law.
13. Security
All data in transit uses TLS 1.2+ encryption. Stored data is encrypted at rest. Role-based access controls separate manager and field staff visibility. Photo evidence is stored with audit-trail integrity. Regular security assessments are conducted. Data breach response plan is in place per KVKK requirements.
14. Your Privacy Rights
To exercise your rights, contact app@icitech.com.tr with subject "Privacy Request — Hygio". If you are a staff member of a Hygio customer organization, your primary point of contact for data rights is your employer (the data controller for your task and performance data). We will redirect requests appropriately and assist customer organizations in fulfilling data subject requests.
We respond within 30 days, free of charge.
15. EEA and UK Users
If you or the customer organization is in the EEA or UK, GDPR applies. Read our GDPR Privacy Notice at https://hygio.app/privacy/gdpr for full GDPR details including Article 28 data processing agreements, Article 88 employee data, supervisory authority contacts, and breach notification rights.
16. Changes
Material changes notified at least 14 days in advance. Current version at https://hygio.app/privacy.
17. Contact Us
Email: app@icitech.com.tr Website: https://hygio.app/ Subject: "Privacy Request — Hygio"
We acknowledge enquiries within 5 business days.
18. Governing Law
This Policy is governed by the laws of the Republic of Turkey, including KVKK No. 6698. Disputes are subject to Turkish court jurisdiction.
Cookie Policy·Privacy Notice (GDPR)·Terms of Service·Data Deletion