🇪🇺 This policy is compliant with the EU General Data Protection Regulation (GDPR)
At Erdos Publish House S.L, protecting your personal data is a fundamental commitment. This Privacy Policy explains what data we collect, why we collect it, and how you can exercise your rights under GDPR and other applicable privacy laws.
1. Data Controller
The data controller responsible for your personal data processed through the Cervantes platform is:
2. Data We Collect
2.1 Account and Identity Data
- Full name, email address, institutional affiliation, country
- ORCID identifier (optional but recommended)
- Profile information such as biography and research interests
- Hashed passwords (we never store plaintext passwords)
2.2 Manuscript and Editorial Data
- Submitted manuscripts, cover letters, and supplementary files
- Revision history, author responses, and editorial correspondence
- Peer review reports and editorial decisions
- Co-author details provided by the submitting author
2.3 Usage and Technical Data
- IP address, browser type, operating system, and device type
- Pages visited, actions performed, and timestamps
- Session tokens and authentication logs
- Error logs and performance metrics
2.4 Financial Data
- Payment transaction records (amount, date, reference)
- Invoice details including billing name and address
- We do not store full card numbers — these are handled by our PCI-compliant payment processor
2.5 Communications Data
- Emails sent through the platform (automated notifications and editorial messages)
- Support ticket contents and correspondence with our team
3. How We Use Your Data
- Platform operation: managing submissions, peer review, editorial decisions, and publishing workflows
- Account management: authentication, role assignment, and user support
- Communications: automated status notifications, editorial correspondence, and platform updates
- Payments: processing APCs, generating invoices, and maintaining financial records
- Security: fraud prevention, abuse detection, and platform integrity
- Compliance: meeting legal obligations under GDPR, tax law, and academic publishing standards
- Analytics: aggregated, anonymized usage data to improve the platform
4. Legal Basis for Processing
We process personal data under the following GDPR legal bases:
- Contract (Art. 6(1)(b)): processing necessary to provide the Cervantes service under our Terms of Service
- Legal Obligation (Art. 6(1)(c)): compliance with tax, accounting, and legal requirements
- Legitimate Interests (Art. 6(1)(f)): platform security, fraud prevention, and service improvement
- Consent (Art. 6(1)(a)): optional analytics cookies and marketing communications (where applicable)
5. Data Sharing and Third Parties
We do not sell your personal data. We may share data with trusted third parties solely to operate the Service:
- Payment processors: for secure APC and fee collection (PCI-DSS compliant)
- Email delivery services: for sending platform notifications and editorial communications
- Cloud hosting providers: for secure data storage and platform infrastructure
- Analytics services: aggregated, anonymized usage data only
- Legal and regulatory authorities: when required by law, court order, or to protect our legal rights
All third-party processors are bound by data processing agreements ensuring GDPR compliance. We do not transfer your data to third parties for advertising or profiling purposes.
Journal operators (editors, managing editors) accessing the platform may view submitted manuscripts and related metadata as required for editorial management. Their access is governed by the journal's own editorial policies.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Active accounts: data retained for the duration of the account and service relationship
- Published manuscripts: bibliographic metadata retained indefinitely for academic record integrity
- Rejected/withdrawn manuscripts: retained for 5 years, then anonymized or deleted
- Financial records: retained for 7 years in compliance with tax and accounting regulations
- Log and security data: retained for 12 months
- Deleted accounts: personal data deleted within 90 days of account closure request
You may request deletion of your personal data at any time, subject to our legal obligations to retain certain records.
7. Security
We implement industry-standard technical and organizational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access controls and principle of least privilege
- Regular security audits and penetration testing
- Bcrypt password hashing — we never store plaintext passwords
- Multi-factor authentication support
- Regular encrypted backups with tested recovery procedures
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, in accordance with GDPR Article 33–34.
8. Cookies and Tracking
8.1 Types of Cookies
- Strictly necessary cookies: required for the platform to function (session management, authentication). Cannot be disabled.
- Functional cookies: remember your preferences such as language selection.
- Analytics cookies: collect anonymized usage data to help us improve the Service. Require your consent.
- Marketing cookies: we do not use marketing or advertising cookies.
8.2 Managing Cookies
You can manage your cookie preferences via the cookie banner shown on your first visit, or at any time through the Cookie Settings link in the footer. You may also configure your browser to block or delete cookies, though this may affect certain platform features.
9. International Transfers
Cervantes is operated from Spain (European Union). Your data may be processed by our infrastructure and service providers within the EU/EEA. Where data is transferred to third countries outside the EEA, we ensure adequate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Binding Corporate Rules where applicable
10. Your Rights
Under the GDPR and other applicable data protection laws, you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data ("right to be forgotten"), subject to legal obligations.
Right to Restriction
Request that we limit how we process your data in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Withdraw Consent
Withdraw consent at any time for processing based on consent.
Lodge a Complaint
Complain to your national data protection supervisory authority.
To exercise any of these rights, contact us at cervantes@erdospublish.org. We will respond within 30 days. For Spanish residents, the supervisory authority is the Agencia Española de Protección de Datos (AEPD) at aepd.es.
11. Children's Privacy
Cervantes is intended for use by professionals and researchers in academic settings. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that a child under 16 has provided personal data without verifiable parental consent, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify registered users by email and display a prominent notice on the platform at least 14 days before the changes take effect.
The date of the most recent update is shown at the top of this page. We encourage you to review this policy periodically.