Skip to content
panic.app logo

Privacy Policy

Last updated: 31 July 2026

1. Introduction

This Privacy Policy describes how ICI Tech Teknoloji A.Ş. ("ICI Tech", "we", "us", "our") processes personal data when you visit the panic.app marketing website, manage cookie preferences, or contact us about panic.app — our enterprise crisis and employee safety communication platform.

This policy applies to the public marketing website at https://panic.app and related enquiries. It does not replace the data processing agreement, privacy terms, or product-specific policies that apply when your organization uses the panic.app software platform under a separate contract. Where contractual terms conflict with this policy regarding licensed software, the contract prevails for that processing.

We process personal data in accordance with the Turkish Personal Data Protection Law (KVKK, Law No. 6698), the EU General Data Protection Regulation (GDPR) where applicable, and other relevant privacy laws.

2. Data controller

  • Legal entity: ICI Tech Teknoloji A.Ş.
  • Address: Maslak, Sun Plaza, Sarıyer / İstanbul, Türkiye
  • Email: app@icitech.com.tr
  • Phone: +90 533 214 6644 | Corporate: +90 212 366 57 26
  • Website: https://panic.app

3. Controller and processor roles

Marketing website and sales/support enquiries: ICI Tech is the data controller.

Customer admin and account data under a customer contract: ICI Tech is typically the controller for its own account, billing, and operational security logs.

Workplace safety, incident, and employee status data inside the panic.app product: your organization (the employer/customer) is normally the data controller; ICI Tech acts as a data processor under the customer agreement and any data processing agreement (DPA).

4. Scope of this policy

This website provides product information, demo requests, and contact channels. We do not create user accounts on this marketing site.

If you are an employee or administrator using panic.app under your employer's subscription, contact your employer's privacy or HR contact for product-related requests. We cooperate with customer organizations on processor instructions.

5. Categories of personal data

  • Identity and contact data: name, email address, phone number, company name, job title (when you provide them).
  • Communication content: messages you send by email or phone when you contact us.
  • Technical and usage data: IP address, browser type and version, device type, operating system, referring URL, pages viewed, date/time of access, and similar server log data.
  • Cookie and consent data: your cookie preference choices stored locally and consent timestamps where applicable.
  • Marketing and analytics identifiers: online identifiers generated by analytics or advertising tools if you consent to those cookies.

6. Sources of data

Directly from you when you contact us or submit information voluntarily.

Automatically through your browser or device when you browse the website.

From analytics and marketing technology providers, only where you have given valid consent for non-essential cookies.

7. Purposes and legal bases

We process personal data only where we have a valid legal basis:

  • Responding to enquiries, demo requests, and sales communications — legitimate interest (Art. 6(1)(f) GDPR) and/or steps prior to entering a contract (Art. 6(1)(b) GDPR); KVKK Art. 5/2-(f) legitimate interest where applicable.
  • Operating, securing, and maintaining the website — legitimate interest in secure operation and fraud prevention.
  • Compliance with legal obligations — e.g. responding to lawful requests from authorities (Art. 6(1)(c) GDPR).
  • Analytics (Google Analytics 4, Google Tag Manager, Microsoft Clarity) — your consent (Art. 6(1)(a) GDPR; KVKK explicit consent where required).
  • Marketing measurement (Meta Pixel, TikTok Pixel) — your consent (Art. 6(1)(a) GDPR; KVKK explicit consent where required).
  • Storing cookie consent preferences — necessary to respect your choices (legitimate interest / technical necessity).

8. Cookies and similar technologies

We use cookies, local storage, and similar technologies as described in our Cookie Policy at https://panic.app/cookie-policy. Non-essential cookies are not placed until you consent through our cookie banner.

You may withdraw consent at any time by changing preferences in the cookie banner (clear site data to reset) or by adjusting browser settings.

9. Recipients and processors

We do not sell personal data. We share data only as necessary with:

  • Hosting and infrastructure providers (e.g. cloud hosting/CDN) to deliver the website.
  • Email and communication tools to respond to your enquiries.
  • Analytics providers (Google, Microsoft) when you consent to analytics cookies.
  • Advertising/measurement partners (Meta, TikTok) when you consent to marketing cookies.
  • Professional advisers (legal, accounting) where required and subject to confidentiality.
  • Public authorities when required by applicable law.

10. International data transfers

Your data may be processed in Türkiye and, when you use optional analytics or marketing tools, in countries where those providers operate (including the United States and the European Economic Area).

Where GDPR applies and data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, provider certifications, or equivalent mechanisms offered by the vendor.

Where KVKK applies, cross-border transfers are made in compliance with KVKK Articles 8 and 9, including explicit consent where required or other permitted transfer mechanisms.

11. Retention periods

  • Contact and sales enquiries: up to 3 years after last interaction, unless a longer period is required for contract performance, dispute resolution, or legal obligations.
  • Server and security logs: typically up to 12 months, unless needed for incident investigation.
  • Billing and contract records (controller records): typically up to 10 years where required by commercial/financial law.
  • Analytics data: according to each provider's configuration and your consent status.
  • Cookie consent records: stored locally on your device until you clear site data or change preferences.

12. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure, including encryption in transit (HTTPS), access controls, and vendor due diligence.

No method of transmission or storage is 100% secure. If you believe your interaction with us is compromised, contact us promptly.

13. Your rights

Depending on applicable law, you may have the following rights regarding your personal data:

  • Right of access — obtain confirmation and a copy of data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure — request deletion where legally applicable.
  • Right to restriction of processing — limit how we use your data in certain cases.
  • Right to object — object to processing based on legitimate interests.
  • Right to data portability — receive data you provided in a structured, machine-readable format where applicable.
  • Right to withdraw consent — at any time, without affecting prior lawful processing.
  • Right to lodge a complaint with a supervisory authority.

14. How to exercise your rights

Submit requests to app@icitech.com.tr with the subject line "Privacy Request — panic.app". We may ask for information to verify your identity.

We respond within 30 days where GDPR applies, and within the statutory period under KVKK (generally 30 days, extendable once by 30 days with notice).

If you are an employee user of the panic.app product, direct workplace data requests to your employer as data controller. See also Data Deletion at https://panic.app/data-deletion.

15. Supervisory authorities

  • Türkiye: Personal Data Protection Authority (KVKK Kurumu) — https://www.kvkk.gov.tr
  • EU/EEA: Your local data protection authority in your country of residence or work.
  • France: CNIL — https://www.cnil.fr
  • Germany: BfDI and competent state DPAs — https://www.bfdi.bund.de
  • Spain: AEPD — https://www.aepd.es
  • UK: Information Commissioner's Office (ICO) — if UK GDPR applies to your situation.

16. Children

This website is directed at business professionals and is not intended for children under 16. We do not knowingly collect personal data from children. Contact us if you believe we have received such data.

17. Automated decision-making

We do not use personal data from this marketing website for automated decision-making or profiling that produces legal or similarly significant effects.

18. Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or business changes. The "Last updated" date at the top indicates the latest revision. Material changes may be highlighted on the website where appropriate.

19. GDPR notice for EEA and UK

If you or your organization are in the EEA or United Kingdom, please also read our Privacy Notice (GDPR) at https://panic.app/privacy/gdpr for additional GDPR-specific information, including Article 28 processor terms and transfer safeguards.

20. Contact

Privacy questions: app@icitech.com.tr

Postal address: ICI Tech Teknoloji A.Ş., Maslak, Sun Plaza, Sarıyer / İstanbul, Türkiye

Back to home