Skip to content
Dixit
Solutions
Solutions overview Imaging Core LabCore lab infrastructure for multicentre trials Central ReviewControlled, independent review workflows Site QualificationStandardised imaging quality across sites Regulatory ArchivingInspection-ready imaging archives Workflow CoordinationControlled clinical imaging operations Custom Imaging SolutionsFlexible solutions for complex programmes
WIDEN
WIDEN overview What is WIDEN Workflow & TraceabilityInvestigator-initiated trials Data Transfer & QCCentralised reads & QC Reviewer Environment Regulatory Compliance Security & Audit Trail
Therapeutic Areas
Therapeutic Areas overview Oncology Haematology Molecular Imaging & Theranostics
Resources
Resources overview PublicationsPeer-reviewed methodology & trial results TestimonialsNamed investigators on central review
Global Studies About Contact Log in
Legal

Privacy notice

Version 2026-08-01 · in effect from 1 August 2026

In short. This site sets no cookies and uses no third-party tracking. Our visitor statistics are self-hosted, contain no identifier of any kind, and never leave our server. If you write to us through the contact form, we store what you send — encrypted — so we can answer you, and we delete it after 24 months. We do not sell or share personal data, and nothing here is used for profiling or advertising.

1. Who is responsible for your data

The data controller is Dixit s.r.l., an imaging Clinical Research Organisation registered in Italy.

  • Via Agostino da Montefeltro 2, 10134 Torino, Italy
  • VAT / P.IVA 10493140015 · REA TO 1137723
  • Email: [email protected]
  • Telephone: +39 389 945 4479

We have not appointed a Data Protection Officer, as we are not required to. Use the address above for any question or request about your personal data.

2. Website statistics

We measure how the site is used so we can tell which pages are worth maintaining and whether the site is working. We do this with our own software running on our own server. There is no Google Analytics, no advertising pixel, no tag manager and no session recording, and no third party receives anything.

2.1 What is recorded

One record is written per page view, containing only:

Data recorded for each page view
Recorded Detail
Page address The path of the page on this site, for example /about. Never a query string.
Date and time When the page was opened.
Country and region Derived from your IP address as described in 2.2.
Referring website The domain name only, and only when you arrived from another site — for example google.com. Never the full address of the page you came from.
Device type One of desktop, mobile or tablet.
Automated-traffic flag Whether the visit looked like a person or a crawler, so bots can be excluded from the figures.

2.2 What is not recorded

  • No cookies and no browser storage. The statistics script reads and writes nothing on your device — no cookies, no local storage, no session storage. This is why you are not asked to accept cookies.
  • No IP address. Your IP address is used in memory, for the fraction of a second it takes to look up the country and region it belongs to, and is then discarded. It is never written to our statistics.
  • No device fingerprint and no identifier. Nothing links two page views to each other, on this site or on any other. We cannot tell whether two records came from the same person.
  • No browser identification string beyond reducing it to the three-way device type above, after which it is discarded.

The country lookup uses a database file stored on our own server (MaxMind GeoLite2). Nothing about your visit is sent to MaxMind or to anyone else in order to perform it.

For a few minutes after a visit, a one-way cryptographic hash of the IP address is held in a temporary counter, purely to stop automated flooding of the statistics. These counters erase themselves within minutes and are never connected to the statistics records or to anything else.

2.3 Why we may do this, and for how long

Our lawful basis is legitimate interests (Article 6(1)(f) GDPR): we need a basic understanding of how our site is used in order to run it. We have weighed this against your interests, and consider the impact minimal — no identifier is created, no profile is built, nothing is stored on your device, nothing is shared, and you are not tracked across websites.

Because these records contain no identifier, they cannot be traced back to a person and are held as an aggregate statistical record. We do not currently apply an automatic expiry to them.

2.4 Your rights over the statistics, and how to object

We are being direct about a consequence of the design. The statistics contain nothing that identifies you and nothing that connects one record to another, so we genuinely cannot find "your" records — not on request, and not for our own purposes. Under Article 11 GDPR, where a controller cannot identify a data subject, the rights of access, correction, erasure and portability do not apply, and we are not obliged to collect extra information about you purely to make them possible. We are not going to start identifying visitors in order to be able to delete their data.

You retain the right to object under Article 21 GDPR. Because the records cannot be located after the fact, objecting has to work by preventing collection rather than by deleting anything. You can achieve that immediately by blocking /assets/static/js/app.js in your browser or with any content blocker, and the site will work exactly as before. If you would like us to arrange this differently, write to us at the address in section 1.

2.5 Server logs

Separately from the statistics above, the web server that delivers this site keeps standard access logs, which do record the IP address of every request. These are created and retained by our hosting provider as part of operating and securing the server, on the basis of our legitimate interest in keeping it available and secure. They are not used for analytics and are not combined with anything described above.

3. The contact form

3.1 What we collect and why

If you send us an enquiry, we collect your name, your institution, your email address, the subject, and the message you write. We use this to read your enquiry, route it to the right person, and reply to you.

Our lawful basis is Article 6(1)(b) GDPR — taking steps at your request before entering into a possible contract — and, where your enquiry is not about a potential engagement, our legitimate interest under Article 6(1)(f) in responding to people who contact us. The tick box on the form records your agreement to be contacted about your request and your acknowledgement of this notice; we store which version of this notice was in effect when you sent it, together with the date and time.

3.2 Please do not send us clinical information

This is a general business enquiry form and is not an appropriate channel for patient data. Please do not include patient-identifying or clinical information in it. Tell us about the study in general terms and we will arrange a secure channel for anything sensitive. If an enquiry does arrive containing clinical detail, we delete it as soon as it has been dealt with, rather than keeping it for the period in section 3.4.

3.3 Who sees it

Your enquiry is delivered by email to our [email protected] mailbox and is stored in our own database. Within Dixit, it can be read by the colleagues who handle enquiries and by the administrator of our website dashboard. Every occasion on which stored enquiries are opened in that dashboard is logged.

The only third party involved is our email provider, Aruba S.p.A. (Italy), which transmits and hosts the message as our processor. We do not sell your data, we do not share it for anyone else’s marketing, and we will not use your address to send you marketing you did not ask for.

3.4 How long we keep it

  • Your enquiry: 24 months from the date you sent it, after which it is deleted automatically. Enquiries containing clinical detail are deleted as soon as they have been answered (section 3.2).
  • A one-way hash of your IP address: 30 days. We store the address only in hashed form, never in the clear. It exists so that abuse of the public form — spam floods, automated submissions — can be investigated while that is still meaningful. After 30 days it is erased from the record automatically, while the enquiry itself remains.

3.5 How it is protected

Your name, email address, subject and message are encrypted (AES-256-GCM) before they are written to the database, so a stolen backup or database copy yields nothing readable without the separate key. The form is served over HTTPS, and the dashboard from which stored enquiries can be read requires a password, is limited to one administrator, and records every access.

3.6 Your rights over your enquiry

Unlike the statistics, an enquiry is clearly yours, and every right in section 5 applies to it in full. Ask us and we will retrieve it, correct it, send it to you, or delete it — including the copy in our mailbox.

4. Cookies

This website sets no cookies on visitors' devices, and stores nothing in local or session storage. That is a deliberate design decision, and it is why you see no cookie banner here. The only exception is entirely separate from the public site: our own staff dashboard at /analytics uses one strictly necessary session cookie to keep an administrator signed in. It is never set for visitors.

5. Your rights

Under the GDPR you have the right to:

  • ask whether we hold personal data about you, and get a copy (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data deleted (Article 17);
  • have our use of it restricted while a question is resolved (Article 18);
  • receive it in a portable, machine-readable form (Article 20);
  • object to processing based on legitimate interests (Article 21);
  • withdraw any consent you have given, at any time, without affecting what was done before.

Write to [email protected]. We answer within one month, and there is no charge. Please note the limits explained in section 2.4 for the website statistics: those records contain nothing that would let us find yours.

If you are not satisfied with how we have handled your request, you may complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma — garanteprivacy.it (opens in a new tab)), or to the authority in your own country of residence.

6. Storage and transfers

This website, its statistics and its enquiry database run on a single server within the European Economic Area, and our email provider is established in Italy. We do not transfer personal data outside the EEA. Should that ever change, we will update this notice and put an appropriate transfer mechanism in place first.

7. Automated decision-making

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Our website statistics classify each visit as human or automated in order to keep crawler traffic out of the figures; this is a judgement about traffic, not about a person, and it has no consequence for anyone visiting the site.

8. Children

This site is a business service aimed at clinical research professionals and organisations. It is not directed at children, and we do not knowingly collect data from them.

9. Changes to this notice

If we change how we handle personal data, we will update this page and raise the version number shown at the top. The version in effect when you sent an enquiry is recorded with it, so we can always tell you what you were told at the time.

Imaging CRO for multicentre clinical trials. Built in Turin, Italy.

Product

  • WIDEN
  • Global studies
  • Publications
  • Testimonials
  • Request a demo
  • Log in (opens in a new tab)

Company

  • About
  • Team
  • Contact
  • Privacy

Get in touch

  • +39 389 945 4479
  • [email protected]
  • Via Agostino da Montefeltro 2, 10134 Torino, Italy
© 2011–2026 Dixit s.r.l. · P.IVA 10493140015 · REA TO 1137723 · All rights reserved.
ISO 9001 CERTIFIED