XingImaging Opens State-of-the-Art Research Facility in New Haven, Connecticut

XingImaging, LLC
XingImaging, LLC
  • Home
  • Commitment to Quality
  • Leadership Team
  • History
  • Contact Us
  • Careers
  • More
    • Home
    • Commitment to Quality
    • Leadership Team
    • History
    • Contact Us
    • Careers

  • Home
  • Commitment to Quality
  • Leadership Team
  • History
  • Contact Us
  • Careers

XingImaging's Privacy Policy

Effective date May 28, 2026 


XingImaging, LLC (hereafter, “XingImaging”) (“we,” “us,” or “our,” or “our Company”) is committed to safeguarding your privacy and personal data. Our Company is part of the Mitro Company Group, which includes Mitro Imaging UK LLC, and Mitro Imaging France LLC.


This Privacy Notice explains how we may collect, use, secure, and disclose ("process") your personal information when you interact with XingImaging. This applies when you participate in our research trials, visit our clinical research site, access our website (www.xingimaging.com) (the "Site"), utilize our sales or consulting services, engage with our marketing activities and events, interact with us on social media platforms, or use any other Services that link to this Privacy Notice (collectively, our "Services"). Specifically, this Privacy Notice covers all information received by XingImaging through any electronic or written communication you share with us, information you provide while at our clinical research site, and information shared with us by third parties. This Privacy Notice does not apply to your use of any third-party sites linked to this website.


For further questions, XingImaging’s Regulatory and Compliance Team can be contacted:


By email: dpo@xingimaging.com

By mail: XingImaging, LLC, 55 Church Street, New Haven CT 06510


Understanding your Health Record

A record is made each time you agree to participate in a clinical research trial being conducted at our site. Information about your examination and test results is recorded. These records provide information about your research visit pertaining to the applicable clinical study in which you have consented to participate.

Understanding what information is collected and retained in your record and how that information may be used or shared is defined in the associated clinical study informed consent document. 


XingImaging is not considered a covered entity, i.e., waived under the Health Insurance Portability and Accountability Act (HIPPA). XingImaging is a research organization. XingImaging is not a health care provider.


You can jump to particular topics by going to the headings below:


• What is Personal Information?

• What Data Do We Collect?

• Legal Basis for Processing Your Information

• How Do We Collect Your Data?

• How Will We Use Your Data?

• Cookie Policy

• How Do We Disclose Your Data?

• How Do We Store and Secure Your Data?

• International Data Transfers

• Data Privacy Framework Compliance

• How Long Do We Retain Your Data?

• Use of Subprocessors

• How Do We Market Your Data?

• What are Your Data Protection Rights?

• How Do We Process Children’s Data?

• Privacy Policies of Other Websites

• Changes to Our Privacy Notice

• How to Contact Us

• How to Contact the Appropriate Authority

• Supplemental European Privacy Rights Statement


What is Personal Information? 

Personal Information refers to any information that identifies, relates to, or is reasonably capable of being associated with an identifiable individual or household. 


This includes, but is not limited to names, addresses, geolocation data, online identifiers, and other unique characteristics. Personal Information can also include indirect identifiers such as device identifiers and aggregated data if it can reasonably be linked to an individual.


An identifiable natural person, or "Data Subject," is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location information, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

What Data Do We Collect?

Legal Basis for Processing Your Information


If you are located in the EU or UK, this section applies to you.


The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:


▪ Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time.


▪ Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.


▪ Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms.


      For example, we may process your personal information for some of the purposes described in order to: 


      ▪ Send users information about special offers and discounts on our products and Services.

      ▪ Analyze how our Services are used so we can improve them to engage and retain users.

      ▪ Diagnose problems and/or prevent fraudulent activities.

      ▪ Understand how our users use our products and services so we can improve user experience.


▪ Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.


▪ Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.


How Do We Collect Your Data?


For our research participants, you directly provide Our Company with most of the data we collect. We collect data and process data when you directly submit to us as part of the study enrollment.


Once you have signed an informed consent form to participate in a study you give permission for your health information and any data gathered from study procedures to be used as part of the specific study to which you consented, your health record will then be processed as part of that study. We also collect data via our medical equipment, such as PET-CT, SPECT-CT and MRI scanners. Specifically, data is collected through direct participant interaction before, during and after clinic visits, electronic data capture (EDC) systems provided by study sponsors/CROs or internal system (Dacima Evident IQ), source documentation completed by qualified personnel, integrated lab, imaging and device uploads (e.g. central lab portals, imaging vendor platforms), paper or electronic forms, when applicable, for questionnaires or assessments, following study protocols, Good Clinical Practice (GCP) guidelines and applicable regulatory requirements.


Study participants are under no legal or contractual obligation to provide us with personal information. However, failure to do so will mean that you are unable to be enrolled or take part in potential research studies conducted at our site.


As a Company, we also perform image analysis and collect data provided to us from other research sponsors, who have contracted with us to analyze their data. That data is collected via electronic routes, such as Microsoft Azure, and other software servers. This data is stripped of its personal identifiers via an anonymization or pseudonymization process. Here, we serve as the data processors on behalf of the data owners (e.g. research sponsors). We will obtain data either directly from sponsor sites, or through other electronic routes (e.g. Microsoft Azure, sftp servers, etc.).


How Will We Use Your Data?


We process your personal information for a variety of reasons, depending on how you interact with our Services, including:


▪ To deliver and facilitate delivery of our Services. Data is provided back to the associated study sponsors and/or representatives for the purposes of:


     - Evaluation of study endpoints defined by the protocol

     - Safety monitoring and adverse event reporting

     - Eligibility conformation and protocol compliance

     - Submission to regulatory authorities for potential approval of investigational products

     - Scientific analysis and publication, if applicable and approved.


▪  To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.


▪ To send administrative information to you. We may process your information to send you details about our products and Services, changes to our terms and policies, and other similar information.


▪ To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.


▪ To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.


▪ To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.


▪ To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.


Cookie Policy


a) What are cookies?


Cookies are text files placed on your computer to collect standard internet log information and visitor behavior information. When you visit our websites, we may collect information from you automatically through cookies or similar technology.

For more information, visit allaboutcookies.org.


b) How do we use cookies?


Our Company only uses cookies to track the total number of individuals who visit our website in a given year. We do not track your usage of our website, and we do not share any of your information for marketing purposes.


c) How to manage cookies:


You can set your browser not to accept cookies, and the above website tells you how to remove cookies from your browser. However, in a few cases, some of our website features may not function as a result.


How Do We Disclose Your Data?


We may share Personal Information with:


1. Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. These third parties are bound by contracts requiring them to protect your data, act only on our instructions, and not share your information with others.


2. As Required by Law: To comply with legal obligations, protect against fraud, and ensure compliance with law enforcement and regulatory mandates.


3. Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.


4. In Business Transactions: In connection with mergers, acquisitions, or sales of business assets, where Personal Information may be considered a transferable asset.


5. With Consent: Where you explicitly permit the sharing of your information, ensuring transparency and choice.


How Do We Store and Secure Your Data?


We implement appropriate and reasonable technical, physical, and organizational safeguards to protect your personal information from accidental loss, unauthorized access, disclosure, alteration, or destruction.


Data is stored through Institution-managed secure servers or cloud platforms, compliant with 21 CFR Part 11, HIPAA, and institutional IT security standards, validated electronic systems (e.g. EDC, CTMS, eRegulatory platforms), Microsoft Azure, and SliceVault – a SaaS provided clinical trial medical imaging management application hosted within Microsoft Azure, sponsor-approved portals (e.g., lab, imaging, eConsent platforms) and secured in a locked physical medical records room for source documents, accessible only to authorized personnel.


To protect your personal information, XingImaging has put in place physical, electronic and managerial procedures to secure the information we process. This includes but is not necessarily limited to:


• Restricting access to the computing environment by a minimum necessary standard so that only those employees who are deemed to require access to sensitive data for their job function will have access to that data.


• Robust access logs and monitoring of network activity, when applicable.


• Implementation of multi-factor authentication (MFA)


• Implementing a comprehensive information security policy


• Pseudonymization or de-identification of your personal health information


• Storing information in a locked, secure environment with restricted access only to authorized personnel.


• Maintaining computer systems in accordance with all applicable industry rules and standards.


However, despite our efforts, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee that cybercriminals, hackers, or other unauthorized third parties will never be able to defeat our security measures or improperly access, steal, or modify your data.


Transmission of personal information to and from our Services is at your own risk. You should only access our Services through secure networks and environments. If we are legally required to inform you of a data breach, we may notify you electronically, in writing, or by telephone, in accordance with applicable laws.


International Data Transfers 


We transfer and store international employee data on our secure SharePoint platform. We store image files and associated visit metadata within our image management platform, SliceVault, as well as within our Microsoft Azure cloud environment. Data on both platforms are hosted on servers located within the United States. Where required, we implement appropriate safeguards for international data transfers, such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), industry best practices, and compliance with applicable regulations. These measures ensure that personal data remains protected even when transferred outside these jurisdictions.


Data Privacy Framework Compliance


XingImaging complies with the European Union (EU) and United States (US) EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the United Kingdom (UK) Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.


XingImaging has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. XingImaging has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.


If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/. 


In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, XingImaging commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF. 


The Federal Trade Commission (FTC) has investigatory and enforcement power over XingImaging’ compliance with the EU-U.S. DPF, the UK Extension to the EU- U.S. DPF and the Swiss-U.S. Data Privacy Framework.


Under certain conditions, individuals may invoke binding arbitration to resolve disputes regarding XingImaging’s compliance with the Data Privacy Framework (DPF) Principles. XingImaging is committed to arbitrating claims in accordance with Annex I of the DPF Principles, provided that the individual has delivered notice to XingImaging and followed the conditions set forth in Annex I of Principles.


XingImaging is committed to protecting Personal Information in accordance with the Data Privacy Framework (DPF) Principles. In cases where XingImaging transfers Personal Information to a third party, XingImaging remains responsible under the DPF Principles if the third party processes such information in a manner inconsistent with the DPF Principles, unless XingImaging can demonstrate that it is not responsible for the event giving rise to the damage.


How Long Do We Retain Your Data?


Our Company will keep your personal data for 15 years. Once this time period has expired, we will delete your data in accordance with regulatory obligations and company protocols by utilizing specialized software to securely wipe the data from devices and servers in the case of electronic data, and by utilizing secure cross-shredding for paper documents. In the event of an erasure request, we will also document the erasure process for compliance.


Use of Sub-processors


XingImaging engages certain third-party service providers (“subprocessors”) to support the delivery of our Services. We maintain an up-to-date list of these subprocessors which is available upon request. We may add or replace subprocessors as our business needs evolve and will update our subprocessor list accordingly.


In situations where we are required to provide notice under applicable law or a specific contractual obligation, we will notify users of such changes directly.

By continuing to use our Services, you acknowledge and accept any changes made to our subprocessor list. If you have questions or concerns about our subprocessors, please contact us at dpo@xingimaging.com .


How Do We Market Your Data?


XingImaging does not use your data in any marketing activities.


What are Your Data Protection Rights?


Our Company would like to make sure you are fully aware of all your data protection rights. Every Participant is entitled to the following:


The right to access: 


You have the right to request Our Company for copies of your personal data. We may charge you a fee for this service.


The right to rectification:


You have the right to request that Our Company correct any information you believe is inaccurate. You also have the right to request Our Company to complete information you believe is incomplete.


The right to erasure:


You have the right to request that Our Company erase your personal data, under certain conditions.


The right to restrict processing:


You have the right to request that Our Company restrict processing of your personal data, under certain conditions.


The right to object to processing:


You have the right to object to Our Company’s processing of your personal data, under certain conditions.


The right to data portability:


You have the right to request that Our Company transfer the data that we have collected to another organization, or directly to you, under certain circumstances.


If you make a request, we are required to respond without undue delay. If you would like to exercise any of these rights, please contact us at our email: dpo@xingimaging.com, call us at: 475-318-8200, or write to us at Xing Imaging LLC, 55 Church Street, New Haven 06510.


Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.


If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.


How Do We Process Children’s Data?


XingImaging does not currently conduct clinical research studies that involve the collection and processing of personal data relating to children under the age of 18.


Privacy Policies of Other Websites


Our Company website contains links to other websites. Our privacy notice applies only to our website, so if you click on a link to another website, you should read their privacy notice.


Changes to Our Privacy Notice


We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.


This notice was last updated on [2026-May-28]


How to Contact Us


If you have any questions about Our Company’s privacy policy, the data we hold on you, or if you would like to exercise one of your data protection rights, please do not hesitate to contact us.


Email us at dpo@xingimaging.com

Call us: 475-318-8200

Or write to us at: 

  • XingImaging, LLC
  • C/O Privacy Officer
  • 55 Church Street
  • New Haven, CT 06510


How to Contact the Appropriate Authority


Should you wish to report a complaint or if you feel that Our Company has not addressed your concern in a satisfactory manner, you may contact your Information Security Officer:


For Connecticut Residents:

You may contact the Connecticut Attorney General’s Office of Privacy and Data Security at:

Email: ag.breach@ct.gov

Website: https://portal.ct.gov/


For Connecticut and Non-Connecticut Residents:

You may contact the Department of Health and Human Services at:

Email: OCRMail@hhs.gov

Website: https://ocrportal.hhs.gov/


For UK residents:

You may contact the Information Commissioner’s Office (ICO) at:

Website: https://ico.org.uk/


For French Residents:

You may contact the Commission Nationale de I’Informatique et des Libertés (CNIL) at:

Website: https://www.cnil.fr/en


Supplemental European Privacy Rights Statement


Last Updated [2026-May-28]


If you are a resident of the European Economic Area, we rely on our legitimate interest, contractual relationship, and your consent as described in this Privacy Notice to process your personal information. Additionally, subject to any exemptions as provided by law, you may have certain rights regarding the personal information we maintain about you. We offer you certain choices about what personal information we collect from you, how we use that information, and how we communicate with you. If at any time you wish to exercise your rights, please reach out to us in accordance with the “Contact Us” section below.


According to the GDPR, UK GDPR, and FADP, you have the following rights:


• Right of Access. If you ask us, we will confirm whether we are processing your personal information and, if so, provide you with a copy of that personal information along with certain other details. If you require additional copies, we may charge a reasonable fee.


• Right to Rectification. If your personal information is inaccurate or incomplete, you may be entitled to ask that we correct or complete it.


• Right to Erasure. You may ask us to erase your personal information in some circumstances, such as where we no longer need it, or you withdraw your consent (where applicable) and where there is no other legal basis for processing.


• Right to Restrict Processing. You may ask us to restrict or ‘block’ the processing of your 

personal information in certain circumstances, such as if you contest its accuracy or object to us 

processing it.


• Right to Data Portability. You may have the right to obtain your personal information from us 

that you consented to give us or that was provided to us as necessary in connection with our 

contract with you, and if the processing is carried out by automated means.


• Right to Object. You may ask us at any time to stop processing your personal information, and we 

will do so: (a) if we are relying on a legitimate interest to process your personal information, 

unless we demonstrate compelling legitimate grounds for the processing or your data is needed to 

establish, exercise, or defend legal claims; or (b) we are processing your personal information for 

direct marketing and, in such case, we may keep minimum information about you (for example, in a 

suppression list) as necessary for our and your legitimate interest to ensure your opt out choices 

are respected in the future and to comply with data protection laws.


• Right to Withdraw Consent. If we rely on your consent to process your personal information, you 

may have the right to withdraw that consent at any time, but this will not affect any processing of 

your data that has already taken place.


• Right to lodge a Complaint. If you have a concern about our privacy practices, including the way 

we handled your personal information, you can report it to the data protection authority that is 

authorized to hear those concerns.


Please note that the above rights are not absolute, and we may be entitled to refuse requests, 

wholly or partly, where exceptions under applicable law apply. We will not discriminate against you 

for exercising such rights.


Except as described in this Notice or provided for under applicable privacy laws, there is no charge to exercise your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee taking in account the administrative costs of providing the information or taking the action requested; or refuse to act on the request and notify you of the reason for refusing the request.


Contact Us


If you are a resident in the European Economic Area, we are the "data controller" of your personal information. We have appointed Roger Gunn to be our representative in the EEA. You can contact them directly regarding our processing of your information via RGunn@xingimaging.com.


If you are a resident in the United Kingdom, we are the "data controller" of your personal information. We have appointed Graham Searle to be our representative in the UK. You can contact them directly regarding our processing of your information via GSearle@xingimaging.com.


If you have questions or comments about this Statement, you may:


Email us at dpo@xingimaging.com

Call us: 475-318-8200

Or write to us at: 

  • XingImaging, LLC
  • C/O Privacy Officer
  • 55 Church Street
  • New Haven, CT 06510

  • Home
  • Privacy Policy
  • FCOI
  • Contact Us
  • Directions

XingImaging, LLC

55 Church Street, 7th Floor, New Haven, Connecticut 06510, United States

Copyright © 2026 XingImaging, LLC - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept