Data Protection Notice
Journal of Applied Cryptanalysis & System Integrity (JACSI)
Effective: March 2026
This notice explains how JACSI processes personal data in compliance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the UK General Data Protection Regulation (UK GDPR), and the German Bundesdatenschutzgesetz (BDSG).
Data Controller
David Tom Foss
Jakobstr. 40, 02826 Görlitz, Deutschland
Email: [email protected]
What Personal Data We Process
| Category | Data Elements | Persons |
|---|---|---|
| Authors | Name, email, institutional affiliation, ORCID, country, manuscript text, correspondence | Submitting and co-authors |
| Reviewers | Name, email, institutional affiliation, ORCID, review reports, correspondence | Peer reviewers |
| Editorial Board | Name, email, institutional affiliation, ORCID, country, publication record | Board members |
| Website visitors | IP address, browser type, pages visited (server logs) | All visitors |
| Correspondents | Name, email, message content | Anyone contacting JACSI |
Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| Manuscript handling (submission, review, publication) | Legitimate interest (Art. 6(1)(f)) — necessary for journal operations |
| Publishing author names and affiliations | Legitimate interest (Art. 6(1)(f)) — standard scholarly practice |
| Publishing reviewer names (open peer review) | Explicit consent (Art. 6(1)(a)) — via Reviewer Consent Form |
| Publishing Editorial Board information | Consent (Art. 6(1)(a)) — via Board Member Agreement |
| Server logs | Legitimate interest (Art. 6(1)(f)) — security and abuse prevention |
| Email correspondence | Legitimate interest (Art. 6(1)(f)) — responding to inquiries |
Data Retention
| Data Type | Retention Period |
|---|---|
| Published articles (author data) | Permanently (scholarly record) |
| Published review reports | Permanently (scholarly record) |
| Rejected manuscript data | 2 years after rejection |
| Reviewer correspondence | 5 years after decision |
| Server logs | 90 days |
| Email correspondence | 3 years |
Data Sharing
JACSI shares personal data with:
- Crossref: Author names, article titles, DOIs (for DOI registration)
- DOAJ: Journal and article metadata (for indexing)
- ORCID: Author identifiers (with author consent)
- PKP PN / LOCKSS: Published article content (for preservation)
- Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany): Server hosting, data processing within the EU. Privacy Policy
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA): CDN, DNS, DDoS protection. US transfer based on EU Standard Contractual Clauses (SCCs) and Cloudflare Data Processing Addendum. Privacy Policy
- Brevo (Sendinblue) SAS (106 boulevard Haussmann, 75008 Paris, France): Transactional email relay. Data processing within the EU. Privacy Policy
JACSI does not:
- Sell personal data
- Share data with advertisers
- Transfer data outside the EU/UK without adequate safeguards
International Transfers
If data is transferred outside the EU/EEA (e.g., to reviewers in non-EU countries), JACSI relies on:
- Standard Contractual Clauses (SCCs) where applicable
- The UK-EU adequacy decision for UK transfers
- The data subject's explicit consent for one-off transfers
Your Rights
Under GDPR/UK GDPR, you have the right to:
| Right | Description | How to Exercise |
|---|---|---|
| Access (Art. 15) | Obtain a copy of your personal data | Email [email protected] |
| Rectification (Art. 16) | Correct inaccurate data | Email [email protected] |
| Erasure (Art. 17) | Request deletion of your data* | Email [email protected] |
| Restriction (Art. 18) | Limit how we process your data | Email [email protected] |
| Portability (Art. 20) | Receive your data in machine-readable format | Email [email protected] |
| Objection (Art. 21) | Object to processing based on legitimate interest | Email [email protected] |
| Withdraw consent (Art. 7(3)) | Withdraw any consent given | Email [email protected] |
*Note: The right to erasure may be limited for published scholarly records, which serve the public interest in maintaining the integrity of the academic record.
Supervisory Authorities
- UK: Information Commissioner's Office (ICO) — https://ico.org.uk/
- Germany: Saechsischer Datenschutzbeauftragter — https://www.saechsdsb.de/
- EU: You may lodge a complaint with any EU supervisory authority
Cookies
The JACSI OJS installation uses:
- Essential cookies: Session management, language preference (no consent required)
- No tracking cookies: JACSI does not use analytics tracking, advertising cookies, or third-party trackers
Changes to This Notice
Changes will be published on this page with an updated effective date. Significant changes will be communicated via the journal website.
Contact
For data protection queries: [email protected]