Skip to main content

Who is responsible for your data

The controller of personal data processed through peeracademics.com is the Publisher of Peer Academics:

ControllerAsociația Societatea Studenților din Uniunea Europeană (EUSS)
Legal formAssociation without patrimonial purpose ("asociație fără scop patrimonial") under Romanian law
RegistrationJudecătoria Sectorului 6 București, 4 December 2023 — Certificat de înscriere a persoanei juridice fără scop patrimonial nr. 188 of 4 December 2023, dosar nr. 20020/303/2023; Registrul special nr. 138 of 4 December 2023
Fiscal codeCIF 49366625, attributed by ANAF on 8 January 2024
Registered seatStr. Arieșul Mare nr. 3, bl. I 10, sc. 5, parter, ap. 63, cam. 1, Sector 6, București, România
Data protection contact[email protected]

This notice covers the journal website and the Open Journal Systems installation that runs it. It does not cover other websites you reach from here, including repositories, ORCID, and authors' own pages, each of which has its own notice.

What personal data the journal processes

  • Account data. Your name, username, email address, a hashed password, and whatever you choose to add to your profile: affiliation, country, ORCID iD, reviewing interests, biography, and notification settings. You cannot submit or review without an account.
  • Submission records. The manuscript and its files, the title page with author names, affiliations, and contact details, the submission metadata, your declarations on funding, conflicts of interest, ethics approval, consent, and the use of generative tools, and all correspondence about the submission. This includes personal data about your co-authors that you supply.
  • Review records. Reviewer identity, invitations, acceptances and declines, reports, recommendations, uploaded files, and dates. Review is double-anonymous: authors are not shown reviewer identities, and reviewers are not shown author identities.
  • Editorial records. Decisions, editor notes, and records of ethics or misconduct inquiries under Misconduct Investigations.
  • Published metadata. Author names, affiliations, ORCID iDs, and the article itself. See the separate warning below.
  • Technical data. Server logs recording IP address, date and time, requested address, response status, referring page, and browser identification; error logs; and records of sign-in attempts.
  • Correspondence. Email you send to the journal's addresses, and the delivery records of email the system sends you.

The journal does not ask for special categories of data. Do not put health information, data revealing political or religious views, or similar material into correspondence or profile fields. Personal data inside your research materials is your responsibility as a researcher; see Research Data and Informed Consent.

When you name a co-author or suggest a reviewer, you are giving the journal someone else's personal data. Do so only where you are entitled to, and tell that person you have done it.

Why the journal processes it, and on what legal basis

PurposeLegal basis (GDPR Article 6)
Creating and operating your account; receiving, screening, reviewing, deciding on, and publishing your submission(1)(b) — steps taken at your request and performance of the publishing arrangement between you and the Publisher
Administering peer review, including inviting and corresponding with reviewers(1)(f) — the legitimate interest of the Publisher, authors, and readers in independent quality control of scholarly work
Screening submissions with similarity-detection software. Any such service acts only on the Publisher's instructions.(1)(f) — legitimate interest in the integrity of the published record
Publishing the article and its metadata, and keeping it available permanently(1)(b) and (1)(f) — the integrity and permanence of the scholarly record
Investigating and recording allegations of misconduct, and issuing corrections or retractions(1)(f), and (1)(c) where a legal obligation applies
Keeping the site secure and available; preventing and investigating abuse(1)(f) — legitimate interest in the security of the service
Sending announcements or other optional messages you have asked for(1)(a) — your consent, which you may withdraw at any time
Complying with Romanian and EU law, and responding to lawful requests from authorities(1)(c)

Where processing rests on legitimate interests, you may object under Article 21; see your rights below.

Published author data is public and permanent

This is the part authors most often overlook. When an article is published, the author names, affiliations, and ORCID iDs in its metadata become public, machine-readable, and permanent. They are displayed on the site, exposed through the journal's OAI-PMH interface, and copied by search engines, harvesters, and readers, beyond the journal's control. Publication is by design an act of making information public.

The practical consequences:

  • Author metadata cannot be erased on request. Article 17(3)(d) of the GDPR permits the Publisher to refuse erasure where processing is necessary for archiving in the public interest and for scientific purposes; the scholarly record is such a case.
  • The corresponding author's email address is published only if you agree to it. Tell the editor before acceptance if you would rather it were not shown.
  • Name changes are honored without a public notice. If you change your name, write to [email protected]; the journal will update the name on the article, in the metadata, and in your account, and will not publish a correction notice drawing attention to the change or require you to explain the reason.
  • Factual errors in your published name or affiliation are corrected on request.

Who has access to your data

  • Editors and editorial staff handling your submission.
  • Reviewers, who receive the anonymized manuscript and its files, and not your identity.
  • Copyeditors, typesetters, and proofreaders working on accepted articles.
  • Service providers acting as processors on the Publisher's instructions under Article 28 contracts: the hosting provider, the email provider, and the similarity-detection service.
  • The public, for published articles and their metadata only.
  • Authorities, where the Publisher is legally required to disclose.

The Publisher does not sell personal data, does not rent or share mailing lists, and does not disclose the existence or content of an unpublished submission to anyone outside the editorial process.

Transfers outside the European Economic Area

Scholarship is international: an editor or a reviewer handling your manuscript may be located anywhere in the world, and sending them the manuscript is a transfer. Where a recipient is outside the EEA, the Publisher relies on an Article 46 safeguard where one is available, and otherwise on Article 49(1)(b), the transfer being necessary to handle the submission you made. Processors outside the EEA are engaged only under Standard Contractual Clauses or another Chapter V mechanism.

How long data is kept

DataRetention
Account dataWhile the account exists. You may ask for it to be closed and deleted at any time.
Rejected or withdrawn submissions and their review recordsA limited period after the final decision — long enough to answer an appeal or an allegation about the work — and then deleted.
Published articles and their metadataPermanently, as the scholarly record.
Review and editorial records for published articlesKept for as long as the article is published, so that questions about how it was handled can be answered.
Misconduct investigation filesKept for as long as the Publisher needs them to defend or explain the outcome.
Server and security logsA limited period, normally no longer than twelve months.
BackupsDeleted on the backup rotation schedule; a deletion from the live system reaches the backups when the affected backups expire.

Your rights

Under the GDPR you may ask for access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability of data you provided, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand.

Write to [email protected], or on paper to the registered seat above. You will receive a reply within one month, extendable by two further months for complex requests, in which case you will be told before the first month is out. You may be asked to confirm your identity where the request concerns data not obviously connected to the address you write from.

Two limits apply, and they are stated so that you are not surprised by them. An access request will not disclose the identity of a reviewer, because that is another person's data and disclosing it would breach the confidentiality on which review depends. And erasure does not extend to published articles and their author metadata, or to records the Publisher needs in order to establish or defend a legal claim.

If you are not satisfied, you may complain to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), whose contact details are published on its website, or to the supervisory authority of the EU country where you live or work.

Cookies and tracking

The site uses only technically necessary cookies. These are a session cookie set by the journal system so that you stay signed in and your submission form is not lost between pages, and a preference cookie recording choices such as interface language. Nothing else is stored on your device.

Peer Academics runs no advertising, no advertising network, no third-party analytics, no social-media pixels, and no cross-site trackers. Any usage statistics the journal compiles are produced on its own server from its own logs; no visitor data is passed to an analytics company. Because the cookies used are strictly necessary to provide a service you have requested, no consent banner is displayed, as permitted under Romanian law transposing the ePrivacy Directive (Law no. 506/2004). You may block or delete cookies in your browser; if you block them you can still read everything on the site, but you will not be able to sign in, submit, or review.

Automated decisions, security, and age

No decision about your manuscript is made automatically. Similarity-detection output is read by an editor and never applied mechanically; see Plagiarism and Text Recycling. There is no profiling.

The site is served over HTTPS, passwords are stored hashed, and access to submissions is limited to the people whose role in the process requires it. If a personal data breach occurs, the Publisher will notify ANSPDCP within 72 hours where the GDPR requires it, and will inform affected people where the breach is likely to result in a high risk to them.

Accounts are for people aged 16 or over. The journal does not knowingly process the data of children.

Changes to this notice

When this notice changes, the new version is published on this page. Changes that materially affect how your data is processed will be announced to registered users. Questions about anything above go to [email protected].