Legal
Privacy Notice (GDPR)
Hygio — AI-Powered Facility Hygiene Management Platform For Users and Customer Organizations in the EEA and United Kingdom
Effective date: June 02, 2025 Last updated: June 02, 2025
1. Introduction
ICI Tech Teknoloji A.Ş. processes personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
| Data Controller | ICI Tech Teknoloji A.Ş. |
| Website | https://hygio.app/ |
| app@icitech.com.tr | |
| Country of establishment | Republic of Turkey |
EU Representative (Article 27 GDPR): We are in the process of designating an EU representative. Updated contact details will be published at https://hygio.app/privacy once appointed.
Data Protection Officer: We do not currently meet the mandatory DPO threshold under Article 37 GDPR. Contact: app@icitech.com.tr.
2. Our Role Under GDPR
As Data Controller (Articles 4(7) and 6): We control personal data for platform user account management, our own operational security, and direct communications.
As Data Processor (Article 4(8) and Article 28): We process personal data on behalf of customer organizations — including cleaning photos, task records, and staff performance data. The customer organization is the data controller for this data.
Data Processing Agreement (Article 28): Our Terms of Service include data processing clauses satisfying Article 28 GDPR. Customer organizations in the EEA may request a standalone DPA document at app@icitech.com.tr.
3. Employee Data — Article 88 GDPR
Hygio tracks individual staff task completion and links AI hygiene scores to specific employees. Under GDPR Article 88 and applicable national laws, this constitutes employee performance monitoring.
Customer organizations using Hygio for staff monitoring must: have a lawful basis under Article 88 and applicable national employment law; inform employees under Articles 13/14; establish appropriate policies for using performance data in employment decisions; ensure the monitoring is proportionate to the legitimate business purpose.
We provide technical assistance to customer organizations fulfilling these obligations. However, compliance is the responsibility of the customer organization as data controller.
4. Facility Photography — GDPR Considerations
Photos of facility areas (toilets, bathrooms, washrooms) are taken by field staff and processed by Hygio's AI. The following applies under GDPR:
Photos should capture only the facility area, not individuals. If a photo inadvertently captures a person, that constitutes processing of personal data for which the customer organization is responsible as data controller. Staff should be trained to ensure photos do not capture individuals without lawful basis. Retention of photographic evidence should be proportionate to the purpose and documented in the customer organization's own retention policy.
5. Data We Process
Account and user data: Email, password (hashed), name, job title, organization details for platform users.
Staff task and performance data (as Processor): Task completion records, NFC/QR scan logs, AI scores linked to individual staff members.
Facility photos and analysis results (as Processor): Before/after photos, AI "Approved/Rejected" labels, cleanliness scores.
End-user feedback data (as Processor): Visitor complaints submitted via QR/NFC feedback.
Technical and security data: IP addresses, session logs, access timestamps, crash reports.
6. Legal Bases (GDPR)
| Purpose | GDPR Legal Basis |
|---|---|
| Account management | Art. 6(1)(b) — Performance of contract |
| Platform service delivery (as Processor) | Art. 6(1)(b) — Performance of contract with customer |
| Staff task and performance tracking | Art. 6(1)(b) + Art. 88 (via customer organization's basis) |
| AI photo analysis | Art. 6(1)(b) — Performance of contract |
| Security and access control | Art. 6(1)(f) — Legitimate interests |
| Demo requests | Art. 6(1)(f) / Art. 6(1)(a) — Legitimate interest / Consent |
| Legal obligations | Art. 6(1)(c) — Legal obligation |
7. AI Analysis — No Third-Party AI API
Hygio uses its own proprietary image processing engine. Cleaning photos are not sent to any third-party AI API (such as OpenAI, Google, or Amazon Rekognition). All AI analysis is performed within Hygio's own infrastructure. This means photo data does not leave Hygio's controlled environment for analysis purposes.
8. What We Do Not Do
We do not sell personal data. We do not share staff performance data beyond the customer organization's account. We do not use photos or analysis to train third-party AI models. We do not represent that Hygio analysis constitutes medical, sanitary, or regulatory certification. We do not make automated decisions with legal effects about individuals without appropriate safeguards (Art. 22).
9. Automated Decision-Making (Article 22)
Hygio's AI generates "Approved (Clean)" / "Rejected (Dirty)" labels for cleaning tasks. These labels trigger operational workflow actions within the customer organization's platform (such as assigning a new cleaning task). We do not make fully automated decisions with legal or similarly significant effects about individual employees without human involvement. The customer organization determines how AI outputs are used in employment-related decisions and must comply with Article 22 where applicable.
10. Your Rights Under GDPR
Right of access (Art. 15): Obtain a copy of your personal data.
Right to rectification (Art. 16): Correct inaccurate data.
Right to erasure (Art. 17): Request deletion.
Right to restriction (Art. 18): Limit processing.
Right to data portability (Art. 20): Receive data in machine-readable format.
Right to object (Art. 21): Object to legitimate interest processing.
Right to lodge a complaint (Art. 77): Contact your national supervisory authority.
For staff of customer organizations: Your employer (the data controller) is your primary contact for exercising rights over task and performance data. We will cooperate with customer organizations in fulfilling staff data subject requests.
Email app@icitech.com.tr — subject "GDPR Data Subject Request — Hygio". Response within one month.
11. Right to Lodge a Complaint
| Country | Authority | Website |
|---|---|---|
| 🇫🇷 France | CNIL | https://www.cnil.fr |
| 🇩🇪 Germany | BfDI + state DPAs | https://www.bfdi.bund.de |
| 🇪🇸 Spain | AEPD | https://www.aepd.es |
| 🇬🇧 United Kingdom | ICO | https://ico.org.uk |
| Other EEA | Your national DPA | https://edpb.europa.eu/about-edpb/about-edpb/members_en |
12. International Data Transfers
ICI Tech Teknoloji A.Ş. is established in Turkey. No adequacy decision exists for Turkey under GDPR Article 45. For EEA/UK transfers, we rely on Standard Contractual Clauses and UK IDTAs where applicable. Photo data is not sent to third-party AI providers — Hygio's own infrastructure processes all images.
13. Data Retention
Account data: duration plus 3 years after termination. Photos and task records: per customer organization configuration and contractual terms. Staff performance data: per customer organization configuration. Communications: 3 years. Technical logs: 12 months. Financial records: 10 years.
14. Security
TLS 1.2+ in transit; encryption at rest. Role-based access controls (manager vs field staff). Breach notification: Supervisory authority within 72 hours (Art. 33); affected parties notified without undue delay for high-risk breaches (Art. 34).
15. Changes
Material changes notified 14 days in advance. Current version: https://hygio.app/privacy/gdpr.
16. Contact Us
Email: app@icitech.com.tr DPA requests: app@icitech.com.tr — subject "DPA Request — Hygio" Website: https://hygio.app/
Acknowledge within 5 business days, resolve within one month.