Privacy notice
Data processing and site analytics
Last updated: 2 August 2026
Controller and contact
The data controller is Aletheia Technologies. For requests concerning personal data, email [email protected].
Contact form data
We process the data you choose to submit: name, email, organisation, telephone number if you give one, area of interest and message. The telephone number is optional: the form works without it. Security systems may also process technical data such as IP address, timestamps and request identifiers to prevent abuse. Please do not include health data or other special categories of personal data in the message; if they are necessary, contact us first to arrange a suitable channel.
Analytics and preferences
Cloudflare Web Analytics collects aggregate usage and performance statistics without cookies or browser local storage.
On publication pages, the browser queries Zenodo’s public API to display current view and download counts. The request includes no credentials, referrer or form data and sets no cookies on our behalf; Zenodo still receives ordinary connection data such as the IP address under its privacy policy.
On the reading pages we count how often a publication is opened, read through, or downloaded. What the database holds is sums per publication, version, event type and day: no row is about a single visit, and we set no cookie for it.
So that one person is not counted twice, since 2 August 2026 we apply the same rule as the Zenodo archive: opening the same page several times within the same hour counts once. To recognise that without knowing who you are, the server computes an irreversible fingerprint of your IP address combined with the current hour and with a secret we never let out, and keeps that fingerprint at most until the end of the hour, after which it expires by itself. The address is not stored, not written to any log and does not leave the server: it is read for that computation and to limit abuse, and that is where it ends. The fingerprint cannot be turned back into the address without the secret, which is in neither the database nor the public code.
Your browser also avoids sending the same event twice in the same tab, and that memory is gone when you close it. If the counting fails, the page works anyway.
Only with your consent do we load Microsoft Clarity to analyse interactions such as clicks, scrolling and navigation, create heatmaps and replay masked sessions. The contact form is explicitly masked and field contents are not captured. We signal analytics consent to Clarity while keeping advertising storage denied. Microsoft processes data under its privacy statement.
According to Microsoft’s documentation, Clarity retains playback
recordings for 30 days, and for 9 months the aggregated click data per
page, heatmaps, and sessions that have been labelled or favourited. Your choice
is stored locally for six months solely to remember the preference. A
separate technical cookie stores the it or en
language for up to one year.
Purpose and legal basis
We use form data to assess and respond to the request and take requested pre-contractual steps (Article 6(1)(b) GDPR) or, for general enquiries, on the basis of our legitimate interest in replying to those who contact us (Article 6(1)(f) GDPR). Protection against spam and attacks serves our legitimate interest in keeping the service secure (Article 6(1)(f) GDPR). The Zenodo API request serves our legitimate interest in presenting current public engagement data for publications (Article 6(1)(f) GDPR). Microsoft Clarity is used only on the basis of consent (Article 6(1)(a) GDPR), which is optional and can be withdrawn at any time. The form does not automatically subscribe users to marketing messages.
Retention and recipients
We retain correspondence for the time needed to manage the contact and, if a professional relationship begins, for any further applicable obligations. The service uses Cloudflare for security, technical delivery and aggregate statistics, Zenodo/CERN for public publication statistics, Microsoft for Clarity only after consent, and an email provider for the mailbox. Some providers may process data outside the European Economic Area, applying the European Commission Standard Contractual Clauses where required. Data is not sold or used by us for advertising profiling.
Your rights
You may request access, rectification, erasure, restriction, objection and, where applicable, data portability as provided by law. You can withdraw analytics consent using the control above and lodge a complaint with the Italian data protection authority (Garante).