Momentous

Privacy and Data Protection Policy

Privacy information for the Momentous mobile application and clinician dashboard, developed for research use by the eHealth Lab at Cyprus University of Technology.

Research Purpose Momentous supports assigned questionnaire completion within scientific research projects.
Secure Processing Data is transmitted using standard encrypted communication protocols.
User Rights Users may contact the Data Controller to exercise applicable GDPR rights.

Last updated: August 2026

Download PDF Policy

Important: Momentous is provided for research purposes. It is not intended for medical diagnosis, treatment, emergency support, or medical advice.

Terms and Conditions

1. Purpose of the App

The MOMENTOUS app is developed exclusively for the collection of data within the framework of a scientific research project. Its sole function is to support the research process by collecting and processing anonymous data voluntarily provided by study participants.

2. Processing Transparency

The app performs no concealed or undisclosed data processing activities. All processing operations are fully transparent and strictly limited to the objectives of the research project.

3. Free Use

The app is provided entirely free of charge. Users are not required to pay any fees at any stage of use.

4. License Agreement

This app is licensed, not sold, to users. By downloading or using the app, users agree to the terms of this license. Ownership, copyright, and all related intellectual property rights remain with the licensor.

The license is granted exclusively to users actively enrolled in the research project. If a user withdraws from the study or upon completion of the project, the license may be revoked. The developer also reserves the right to terminate the license at their discretion if the user fails to comply with these terms or if termination is deemed necessary to protect the integrity and objectives of the research.

5. Use Restrictions

Users must agree to utilize this application solely for the intended research purposes. Any use of the app for purposes outside of the specified research project is strictly prohibited.

6. Safe and Secure Use

Users are required to operate the app only under safe and secure conditions. They must refrain from utilizing the app in any environment or situation where its use could potentially lead to problems or unsafe conditions. The user assumes all responsibility for ensuring that the app is not used in any manner that may cause risk to themselves or to others.

7. User Responsibility for Accuracy

Users are expected to provide accurate and truthful information when interacting with the application to the best of their ability. This is crucial for the integrity of the research project, as the quality and reliability of the research outcomes are directly dependent on the authenticity of the data provided by users.

8. Commitment to Reliability

The developers are committed to ensuring that the application provides reliable responses and data as part of the overarching scientific research project. However, users acknowledge that the application is provided as is for research purposes and not for diagnostic or treatment purposes.

9. App Developer Contact

The App Developer can be reached at: michalis.gemenaris@cut.ac.cy

Data Protection Policy and User Rights

This Data Protection Policy outlines our commitment to safeguarding the privacy and personal data of users. The application has been prepared to operate safely, transparently, and with working contact information for support and review.

1. Data Collection and Use

The application collects data that originates from user input and questionnaire interaction. The purpose of data collection is to support the functionality of the application and advance the objectives of the research project.

  • The application does not collect data from the operating system of the device.
  • The application does not access or collect GPS or geolocation data.
  • The application does not interface with or collect data from third-party health applications.

2. Data Transmission Security

All data transmitted back to the data controller is protected using standard commercial-grade encrypted communication protocols. These protocols safeguard data during transfer and help prevent interception or unauthorized access.

3. Commitment to Data Security

We are committed to the security of users' data both at rest and in transit. Security measures are designed to protect data against unauthorized access, alteration, disclosure, or destruction and are reviewed to remain aligned with industry standards.

4. External Processing

The data controller does not control processing activities conducted by the smartphone or operating system manufacturer. The data controller's responsibility is limited to the application and does not extend to device-level functionality or third-party operating system processing.

5. Registration Data

Registration data may include information such as email address and account details required to authenticate users and provide access to assigned research tasks.

6. Role of the Data Controller

As the developer of the application, we assume the role of Data Controller and are responsible for managing personal data in compliance with applicable data protection laws, including the GDPR.

7. Scope of Data Processing

Data processing activities are confined to what is necessary to fulfil research goals, provide app functionality, and meet applicable legal requirements.

8. Data Processing Localization

Data processing activities, including hosting and communications, are performed within the European Union, supporting compliance with EU data protection regulations.

9. Data Processors

In accordance with Article 28 of the GDPR, Data Centres and Internet Providers may be engaged as Data Processors. These processors are selected to meet the data protection standards required by the GDPR.

10. Disclosure of Personal Data

We do not disclose personal data to third parties, except where required by law to public authorities with the necessary legal mandate.

11. Data Retention

Data is kept for the period deemed necessary for research purposes and for an additional five years thereafter for potential use in legal proceedings or for validating research findings. After this period, data will be permanently deleted.

12. User Rights

Users have the right to object to processing and hold rights under the GDPR, including the right to fair processing, integrity, availability, reliability of their data, and deletion where applicable.

13. Exercising User Rights

Users can exercise their rights by contacting the Data Controller. Verification of identity may be required to process such requests, and a response will be issued within thirty days.

14. Data Controller Contact