Privacy Policy

Effective Date: 2025-11-01

Last Updated: 2025-11-01

Positive Science SAS attaches great importance to the protection of your personal data and respect for your privacy. This Privacy Policy informs you transparently about how we collect, use, store and protect your personal data when you use our scientific publication platform. This policy complies with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and French Data Protection Act.

1. Data Controller

Company Name: Positive Science SAS (being established)

Legal Form: Simplified Joint Stock Company (SAS)

Registered Office: 91 Route des Romains, 67200 Strasbourg, France

Email: [email protected]

Legal Representative: Valentina TESLENKO

Data Protection Officer (DPO)

DPO Email: [email protected]

DPO Postal Address: DPO - Positive Science SAS, 91 Route des Romains, 67200 Strasbourg, France

2. Information We Collect

Personal Information: Name, email address, affiliation, and other details you provide during registration or submission.
Usage Data: Information about how you access and use our services, including your IP address, browser type, and pages visited.
Cookies: We use cookies to enhance your experience and analyze site traffic.

Detailed Data Collection Table

The following table provides a comprehensive overview of the types of data we collect, their purpose, and retention period:

Data CategoryType of DataPurpose of CollectionRetention Period
Account InformationFirst name, last name, patronymic, username, email, phone number, password (encrypted)Account creation, authentication, communicationDuration of account + 1 year after deletion
Profile InformationDate of birth, address, biography, affiliation, profile photo, research interestsProfile personalization, researcher identification, networkingDuration of account + 1 year after deletion
Scientific ContentArticle title, abstract, keywords, article files, ORCID ID, author affiliationsPublication management, peer review, scientific indexingPermanent (scientific archiving)
Submission DataSubmission title, abstract, files, submission status, editorial decisionsEditorial process management, peer review tracking10 years after final decision
Review DataReviewer comments, decisions, review datesPeer review process, quality control, editorial decisions10 years after publication/rejection
Payment InformationPayment amount, currency, transaction ID (Stripe), payment status, receiptsPayment processing, billing, financial records10 years (legal obligation)
Technical DataIP address, browser type, device information, access logs, cookiesService provision, security, analytics, user experience improvement13 months
Communication DataEmail correspondence, notifications, support ticketsUser communication, customer support, service notifications3 years after last interaction
Document SignaturesSigned contracts, copyright agreements, electronic signature dataLegal compliance, copyright management, contract enforcement10 years (legal obligation)

3. Legal Basis for Processing

In accordance with GDPR Article 6, we process your personal data based on the following legal grounds:

PurposeLegal Basis
Account managementPerformance of contract (Art. 6(1)(b))
Service provisionPerformance of contract (Art. 6(1)(b))
Peer review processPerformance of contract + Legitimate interest (Art. 6(1)(b)(f))
Payment processingPerformance of contract + Legal obligation (Art. 6(1)(b)(c))
CommunicationPerformance of contract + Legitimate interest (Art. 6(1)(b)(f))
Service improvementLegitimate interest (Art. 6(1)(f))
Security and fraud preventionLegitimate interest + Legal obligation (Art. 6(1)(c)(f))
Marketing (newsletters)Consent (Art. 6(1)(a)) - opt-in
Legal complianceLegal obligation (Art. 6(1)(c))

4. How We Use Your Information

To provide and maintain our services.
To manage your account and submissions.
To communicate with you about your submissions, reviews, and other platform-related updates.
To improve our platform and user experience.

5. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following limited circumstances:

With Your Consent: We may share your information with your explicit consent.
For Peer Review: Your submission details will be shared with reviewers and editors as part of the peer review process.
Service Providers: We may share information with third-party vendors who perform services on our behalf (hosting: Hetzner Germany, payment: Stripe, DOI: CrossRef/DataCite).
Legal Requirements: We may disclose your information if required by law or in response to valid requests by public authorities.
Published Content: Published articles include author names, affiliations, emails, and ORCID IDs and are publicly accessible.

6. International Data Transfers

Your data is primarily hosted and processed within the European Union.

Primary hosting: Hetzner Online GmbH (Germany, EU).

For service providers outside the EU, we ensure appropriate safeguards through:

European Commission adequacy decisions, OR
EU Standard Contractual Clauses (SCC), OR
Recognized certifications (e.g., Privacy Shield successors)

7. Your Data Protection Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15): Obtain confirmation of processing, access to your data, and information about the processing.
Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
Right to Erasure (Art. 17): Request deletion of your data (subject to conditions, e.g., scientific archiving, legal obligations).
Right to Restriction (Art. 18): Limit processing in certain cases.
Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
Right to Object (Art. 21): Object to processing (absolute right for marketing purposes).
Right to Withdraw Consent: Withdraw your consent at any time for processing based on consent.
Right to Post-Mortem Directives: Define the fate of your data after your death.

How to Exercise Your Rights

To exercise your rights, please contact us:

Email: [email protected] or [email protected]

Postal Address: DPO - Positive Science SAS, 91 Route des Romains, 67200 Strasbourg, France

Response time: 1 month (extendable by 2 months if complex). Exercise is free of charge unless requests are manifestly unfounded or excessive.

Right to Lodge a Complaint

If you believe your rights are not being respected, you can lodge a complaint with:

CNIL (French Data Protection Authority): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France. Website: https://www.cnil.fr

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

Security Measures

SSL/TLS encryption for all communications
Encrypted password storage (robust hashing)
Firewall and intrusion detection systems
Regular secure backups
Security updates and patches
Two-factor authentication (2FA) available
Access limited to authorized personnel only
Staff GDPR training

Data Breach Notification: In case of a data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours and inform affected individuals if there is a high risk.

9. Minors' Privacy

Our platform is intended for persons aged 18 and over. We do not knowingly collect data from minors.

If you are a parent/guardian and discover that your child has provided personal data to us, please contact us immediately for deletion.

For minors aged 15-18 in an educational context: parental consent is required.

10. Cookies Policy

We use cookies and similar tracking technologies in accordance with GDPR requirements.

Types of Cookies

A. Strictly Necessary Cookies (no consent required): Session, authentication, and security cookies. Duration: Session only.
B. Performance and Analytics Cookies (consent required): Google Analytics or alternatives for anonymized usage statistics. Duration: 13 months maximum.
C. Functional Cookies (consent required): Language preferences, display settings. Duration: 12 months maximum.
D. Advertising Cookies (consent required, if applicable): Targeted advertising. Duration: 13 months maximum.

Managing Your Cookie Preferences

You can manage cookies through: (1) Cookie banner on first visit, (2) 'Manage Cookies' link at bottom of pages, (3) Your account settings, (4) Your browser settings (Chrome, Firefox, Safari, Edge).

11. Automated Decision-Making and Profiling

We may create profiles to personalize content recommendations, suggest relevant articles/journals, and improve search functionality. Legal basis: Legitimate interest (improving user experience). You can object by contacting us.

We do NOT make any decisions producing significant legal effects based solely on automated processing.

All editorial decisions are ALWAYS made by humans.

12. Links to Other Websites

Our service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

13. Changes to This Privacy Policy

We reserve the right to modify this Policy at any time.

Notification of substantial changes: Email to active accounts, notification on the platform, publication of the new version. Changes take effect upon publication. The update date is indicated at the top of the document.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: [email protected] or [email protected]
Address: Strasbourg, France