GDPR and Data Protection
How MobyX handles personal data under the GDPR: controller, legal basis, what is collected, pseudonymisation, retention, participant rights and how to exercise them.
MobyX collects travel behaviour data from residents on behalf of public authorities, operators and research consortia. Location traces are personal data, and the activity metrics used to detect walking are special category data. This page sets out how that processing works in practice — who the controller is, what the legal basis is, what is collected, how long it is kept and what participants can ask for.
It is a summary. The binding documents are the privacy notice, the MobyApp privacy policy and the CitizenApp privacy policy, plus the terms document attached to the specific survey.
This page covers:
Who is responsible
Moby X Software Ltd. (registered as MOBY X SOFTWARE LIMITED, Cyprus company number 386967) is the controller for the data described here, and is established in the EU. The applicable law is the EU General Data Protection Regulation together with the Republic of Cyprus Data Protection Law.
Data protection enquiries, including requests to exercise rights, go to [email protected]. The registered postal address is in the privacy notice.
Legal basis for collection
Location and activity data are collected on the basis of explicit consent, given in the app before any collection begins.
Physical activity metrics such as step count and accelerometer data are used to identify walking segments in a traveller’s diary. These are health data, a special category under Article 9 of the GDPR, and are processed solely on the basis of explicit consent under Article 9(2)(a).
Consent can be withdrawn at any time by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out before it. Other processing — running the service, meeting legal obligations — relies on contract performance, legal obligation or legitimate interests as set out in the privacy policies.
What is collected
- Identity data — username, gender, age.
- Contact data — email address.
- Technical data — IP address, login email, device information and GPS traces.
- Usage data — how the app and services are used.
- Survey data — responses to questionnaires.
- Health data — physical activity metrics, as described above.
Apart from the activity metrics, no other special categories of personal data are collected — no race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, genetic or biometric data — and no information about criminal convictions or offences.
How identity is protected
Four techniques are applied to the data before it reaches analysis:
- Pseudonymisation — identifying fields in the records are replaced, so data cannot be attributed to a participant without separately held information.
- Aggregation — location data is aggregated to a level that shows general trends rather than individual routes.
- Geographic masking — coordinates are slightly altered, which keeps the dataset statistically useful while preventing an exact location being determined.
- Data minimisation — only the location data needed for the study is collected and processed.
Location data is encrypted in storage and in transit. Access is limited to employees, contractors and processors with a business need, who act on MobyX instructions and are bound by a duty of confidentiality.
Consent records and versioning
Each survey has its own terms and conditions document, published at a URL derived from the text of the document itself. Change a word and the URL changes, so a URL identifies exactly one version of the text, permanently.
The consent record stores that URL alongside the participant and the survey. This means a consent can be evidenced against the document the participant was actually shown, rather than against whatever the current wording happens to be.
Retention and deletion
Personal data is retained only as long as necessary for the purposes it was collected for, including satisfying legal, accounting and reporting requirements. The period is set per study rather than by a single default.
On a deletion request, MobyX deletes the personal data within 30 days of receiving it.
Participant rights
Participants can request any of the following, free of charge, by emailing [email protected]:
- Access to their personal data
- Correction of inaccurate data
- Erasure
- Restriction of processing
- Objection to processing
- Transfer of their data to another provider (portability)
- Withdrawal of consent
Third parties and this website
Personal data is not disclosed to third parties except where required by law or ordered by a court, or where a service partner needs it to fulfil the contract — in which case the transfer is limited to the minimum necessary. The full list of exceptions is in section 6 of the privacy notice.
This website itself uses only strictly necessary processing until you consent. Google Analytics 4 / Google Tag Manager and the LinkedIn Insight Tag load only after consent through the cookie banner, on the basis of Article 6(1)(a). Where a provider is outside the EU/EEA, transfers rely on that provider’s standard contractual clauses. Consent can be reviewed or withdrawn at any time through the “Manage Cookies” link in the footer.
Common Questions
Is MobyApp GDPR compliant?
Yes. Moby X Software Ltd. is a Cyprus-registered controller operating under the GDPR and the Republic of Cyprus Data Protection Law. Location and activity data are collected on the basis of explicit consent, and health-related metrics such as step counts are treated as special category data under Article 9 and processed solely on the basis of explicit consent under Article 9(2)(a).
What is the legal basis for collecting location data?
Explicit participant consent, given in the app before any collection begins. Consent can be withdrawn at any time by contacting [email protected]; withdrawal does not affect the lawfulness of processing carried out beforehand.
What rights do survey participants have?
Participants can request access to their personal data, correction, erasure, restriction of processing, transfer of their data to another provider, and can object to processing. They can also withdraw consent. Requests go to [email protected].
How is participant identity protected in the data we receive?
Identifying fields are replaced through pseudonymisation, so records cannot be attributed to a specific participant without separately held information. Location data is additionally aggregated and geographically masked, which preserves analytical value while preventing exact locations being determined.
How long is personal data retained?
Only as long as necessary for the purposes it was collected for, including satisfying legal, accounting and reporting requirements. Retention is set per study. On a deletion request, personal data is deleted within 30 days.
Can we see which version of the terms a participant agreed to?
Yes. Each survey has its own terms document published at a URL derived from the text itself, so changing a word produces a different URL. The consent record stores that URL, which identifies exactly one version of the document.