Privacy Notice (GDPR)
Last updated: 31 July 2026
1. Introduction
ICI Tech Teknoloji A.Ş. processes personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
This notice is for users and customer organizations in the EEA and United Kingdom. It supplements our Privacy Policy at https://panic.app/privacy.
- Data controller: ICI Tech Teknoloji A.Ş.
- Website: https://panic.app
- Email: app@icitech.com.tr
- Country of establishment: Republic of Türkiye
2. EU representative and DPO
EU Representative (Article 27 GDPR): We are in the process of designating an EU representative. Updated contact details will be published at https://panic.app/privacy once appointed.
Data Protection Officer: We do not currently meet the mandatory DPO threshold under Article 37 GDPR. Contact: app@icitech.com.tr.
3. Our role under GDPR
As data controller (Article 4(7)): We control marketing-site enquiry data, our operational security data, and typically customer admin account data under our service relationship.
As data processor (Articles 4(8) and 28): We process workplace safety, incident, and employee status data on behalf of customer organizations. The customer organization is the data controller for that data.
Data Processing Agreement (Article 28): Customer organizations in the EEA may request a standalone DPA at app@icitech.com.tr (subject: DPA Request — panic.app).
4. Workplace and employee data
panic.app may process employee safety status, incident responses, location data during incidents (where configured), and related operational records. Under employment and data protection law, the customer organization remains responsible for informing employees, establishing lawful bases, and using data proportionately.
Employees should contact their employer first to exercise rights over workplace data. We cooperate with customer organizations on documented instructions.
5. Data we process
- Marketing and sales enquiries: name, contact details, message content.
- Admin account data (as controller): credentials and organization details for platform administrators.
- Workplace safety data (as processor): incident/drill records, employee status responses, related operational data under the customer account.
- Technical and security data: IP addresses, session logs, access timestamps, error logs.
6. Legal bases (GDPR)
- Responding to enquiries / steps prior to contract — Art. 6(1)(b) and/or Art. 6(1)(f).
- Account management and service delivery — Art. 6(1)(b).
- Processing workplace data as processor — Art. 6(1)(b) via the customer organization's basis and instructions.
- Security and fraud prevention — Art. 6(1)(f).
- Optional analytics/marketing cookies — Art. 6(1)(a) consent.
- Legal obligations — Art. 6(1)(c).
7. What we do not do
We do not sell personal data. We do not use marketing-site data for automated decisions with legal or similarly significant effects (Art. 22). panic.app is not a substitute for official emergency services.
8. Your rights under GDPR
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), complaint (Art. 77).
- For marketing-site or admin-account data we control: email app@icitech.com.tr — subject "GDPR Data Subject Request — panic.app".
- For workplace safety data: contact your employer (controller) first; we will cooperate with the customer organization.
9. Supervisory authorities
- France: CNIL — https://www.cnil.fr
- Germany: BfDI + state DPAs — https://www.bfdi.bund.de
- Spain: AEPD — https://www.aepd.es
- United Kingdom: ICO — https://ico.org.uk
- Other EEA: your national DPA — https://edpb.europa.eu/about-edpb/about-edpb/members_en
10. International transfers
ICI Tech is established in Türkiye. No adequacy decision currently exists for Türkiye under GDPR Article 45. For EEA/UK transfers, we rely on Standard Contractual Clauses and UK IDTAs where applicable, and other lawful transfer mechanisms offered by vendors.
11. Retention
Enquiries: up to 3 years after last contact. Admin accounts: duration of relationship plus contractual wind-down. Workplace content: per customer configuration and contract. Technical logs: typically 12 months. Financial/billing records: up to 10 years where required.
12. Security and breach notification
We use HTTPS/TLS in transit, access controls, and organizational measures appropriate to the risk. Breach notification: supervisory authority within 72 hours where Art. 33 applies; affected individuals notified without undue delay for high-risk breaches (Art. 34).
13. Changes and contact
Material changes may be notified in advance where appropriate. Current version: https://panic.app/privacy/gdpr.
Email: app@icitech.com.tr | DPA requests: subject DPA Request — panic.app | Data deletion: https://panic.app/data-deletion