سياسة الخصوصية — Publish Lens / Privacy Policy
English version (Arabic text governs in case of conflict)
1. Who we are and our legal role
Publish Lens ("Platform") evaluates scholarly journals using open data. For your data as a direct user (account, preferences, billing) we are the Controller. For data an institutional client submits under its contract, we act as Processor on its behalf under a separate Data Processing Agreement [PDPL_COMPLIANCE.md §1.2].
Controller identity: PublishLens (legal name, confirmed by the owner on 2026-09-07). This page will be updated with the registered address and commercial registration number once registration completes. To reach the controller, use the Contact page.
Governing laws: Saudi PDPL (primary, SDAIA regulator); GDPR for EU residents and UK GDPR for UK residents; CCPA/CPRA for California residents; LGPD for Brazilian residents.
2. What we actually collect (no assumptions)
We follow data minimization; fields below match our database verbatim [DATABASE_SCHEMA.md]:
- Account: email, optional free-text organization, role, created date. No mandatory name, no phone, no national ID.
- Preferences: language, numeral style, notification settings, optional display name (2–100 chars).
- Recommendations: manuscript title excerpt, 200 chars maximum (DB constraint), language, status. Your full manuscript is never stored — it is processed then automatically deleted
[ARCHITECTURE.md §4/K5, FR-14]. - Billing: only Paddle subscription IDs/status. We never store your card data — Paddle is Merchant of Record.
- API keys (institutions): stored as a SHA-256 hash only.
- Audit & alerts: your account events.
- Terms-acceptance record (2026-09-09): document version and digital fingerprint, time of acceptance, masked network address, browser family, language, and acceptance channel (sign-up / re-acceptance / settings). Append-only; retained after account deletion with a hash of the email rather than the email itself, as contractual evidence (basis: performance of contract and defence of claims).
- Sign-in events: time of sign-in, masked network address (never the full address), browser and OS family, a hashed device fingerprint, and an email notice on sign-in from a new device (basis: account security — legitimate interest).
- Editorial-board member data (RoPA-R12): names, roles, textual affiliations, ISO3 country of editorial-board members of journals, drawn from publicly available sources (OpenEditors, publisher websites). Processed on the basis of legitimate interest for the purpose of assessing academic editorial transparency; data subjects have the right to object and to request removal from the public display layer (see §6b/§6d).
- Author and citation-network data (RoPA-R9): author names and affiliations in citation edges from OpenAlex (CC0) and PubMed. Processed on the basis of legitimate interest for bibliometric analysis.
Legitimate Interest Assessment (LIA): A documented balancing test has been performed internally for each of R6 (security audit log), R7 (defence of claims), R9 (citation network), R12 (editorial-board data), following the three-step test (lawful interest — necessity — balancing) per EDPB Guidelines 01/2024. A summary of these assessments is available to compliance auditors on request.
We do not collect: health data, minors' data, biometric/genetic data, or precise location.
Sensitive personal information (CPRA §1798.121): We do not intentionally collect sensitive personal information. To the extent any manuscript title excerpt submitted by a user incidentally contains information that could be characterized as sensitive, such information is processed transiently solely to deliver the requested journal recommendation and is not retained beyond the automated processing cycle, consistent with our data minimization obligations.
3. Why we process and on what legal basis
Contract (account, service, billing), consent (recommendations, optional analytics), legal obligation (financial/tax records under applicable law), and legitimate interest (security audit log; defence of legal claims; bibliometric citation analytics; editorial-board transparency). Full mapping: PDPL_COMPLIANCE.md §3 (RoPA).
4. Recipients and cross-border transfers
Infrastructure is hosted on Hetzner in Germany (EU) in the current release, so your data is transferred outside the Kingdom. Transfers are covered by SCCs on SDAIA-approved templates with each sub-processor, and by the equivalent EU SCCs (Implementing Decision 2021/914) where applicable, supported by documented Transfer Impact Assessments [PDPL_COMPLIANCE.md §4].
Sub-processors:
- Hetzner (hosting, Germany)
- Paddle (payments — Merchant of Record; may process in the US/UK depending on payment route)
- Cloudflare (CDN and WAF — may process metadata and IP addresses; has facilities in the US and EU under DPF and SCCs)
- Email provider (alerts)
- LLM provider for recommendations — as a service provider under Cal. Civ. Code §1798.140(ag), under a no-training, ≤30-day retention contract
[AI_GOVERNANCE.md].
For Brazilian residents: As of January 2026, EU–Brazil mutual adequacy is in force (ANPD Resolution 32/2026; EC Implementing Decision 2026/179); transfers to Germany are conducted under a recognised adequacy framework. For any onward transfer falling outside this adequacy, we rely on ANPD-SCCs (Resolution 19/2024) or other safeguards recognised under LGPD Art. 33.
We never sell or rent your data.
5. Retention
Account/preferences: for the life of your account. We apply commercially reasonable efforts to complete deletion within a reasonable period not normally exceeding thirty (30) days of a deletion request; this period may be extended exceptionally for technical or legal requirements beyond our control, with notice to the data subject. Recommendation history: with your account. Billing records: retained for applicable legal/tax obligations, pseudonymised via crypto-shredding after account deletion, rendering re-identification technically infeasible (GDPR Art. 17(3)(b)). Audit log: append-only for the duration required by security and defence-of-claims obligations under GDPR Art. 17(3)(e); subject to SUNSET_PLAN.md on platform sunset. Snapshots of publicly-available journal and editorial-board data: retained as an academic bibliometric record serving a substantial public interest in scientific transparency under GDPR Art. 17(3)(d); disclosed editorial-board members retain the right to object under Art. 21 and to request removal from the public display layer, subject to preservation of the methodological record.
Terms-acceptance records: ten (10) years after account closure, with an email hash only (contractual evidence; longest limitation period for claims). Sign-in events: deleted with the account and periodically trimmed to the last twelve (12) months.
6. Your rights and how to exercise them (general — covers PDPL)
Technically implemented [API_DESIGN.md §6.8]: access/export (GET /account, POST /account/export), rectification (PATCH /account), deletion (DELETE /account, completed within the period stated in §5), objection to legitimate-interest processing (including editorial-board data) (POST /account/object or privacy@publishlens.com), withdraw consent (footer link, anytime).
We respond within the timeframe required by applicable law, generally no later than fifteen (15) business days, with the right to extend where permitted by law, with prior notice of any extension and its grounds. Non-self-service requests: privacy@publishlens.com.
Indirect notice to editorial-board members: Because we obtain editorial-board data from publicly available sources without direct contact with the individuals concerned, this Policy operates as an indirect processing notice under GDPR Art. 14 and PDPL Arts. 12–13. To object or request removal from the display layer, contact privacy@publishlens.com.
Data Protection Impact Assessment (DPIA): We have conducted a preliminary DPIA and concluded that our current processing activities do not require a full assessment under applicable criteria (PDPL Art. 25 · GDPR Art. 35). We revisit this assessment annually and on material change.
§6b. Rights of EU/UK Residents (GDPR / UK-GDPR)
Applies to data subjects residing in the EU or UK, under GDPR (Regulation 2016/679) and UK GDPR.
I. Legal bases and actual legitimate interests pursued
| Basis | Article | Application | Legitimate interest pursued (where applicable) |
|---|---|---|---|
| Performance of a contract | Art. 6(1)(b) | Account creation, journal recommendations, subscription management | — |
| Consent | Art. 6(1)(a) | Optional analytics (opt-in); corresponding-author acknowledgement | — |
| Legal obligation | Art. 6(1)(c) | Retention of billing records under applicable accounting/tax rules (including German UStG where applicable) | — |
| Legitimate interests | Art. 6(1)(f) | Internal security audit log | Detection of and response to unauthorised access |
| Legitimate interests | Art. 6(1)(f) | Defence of appeals and legal claims | Preservation of evidence and demonstration of compliance |
| Legitimate interests | Art. 6(1)(f) | Citation analytics (R9) | Bibliometric research beneficial to the academic community |
| Legitimate interests | Art. 6(1)(f) | Editorial-board data (R12) | Transparency of academic editorial governance |
II. Your rights under GDPR Arts. 12–22
Exercise these rights at privacy@publishlens.com or from your account dashboard. We respond within the timeframe required by applicable law, generally no later than fifteen (15) business days, and in all cases within the statutory maximum of one month (extendable by up to two further months for complex requests with prior notice), per GDPR Art. 12(3).
| Right | Article | How to exercise |
|---|---|---|
| Access | Art. 15 | GET /account |
| Rectification | Art. 16 | PATCH /account |
| Erasure | Art. 17 | DELETE /account. We will action the request within the timeframe in §5. Certain categories are retained under the following Art. 17(3) exceptions, applied narrowly: (a) billing records retained in pseudonymised form via crypto-shredding — Art. 17(3)(b); (b) security audit-log entries retained in pseudonymised form where necessary for the establishment, exercise or defence of legal claims — Art. 17(3)(e); (c) snapshot records of publicly-disclosed editorial-board membership and journal metadata retained as an academic bibliometric record serving substantial public interest in scientific transparency — Art. 17(3)(d). We will confirm in writing what has been deleted, what has been pseudonymised, and under which exception any residual data is retained. |
| Restriction | Art. 18 | Request via privacy@publishlens.com — we restrict use pending verification |
| Portability | Art. 20 | POST /account/export |
| Object | Art. 21 | POST /account/object or privacy@publishlens.com. Where we process on legitimate-interest grounds, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims. |
| No solely-automated decisions | Art. 22 | We do not make decisions producing legal effects or similarly significantly affecting any natural person based solely on automated processing. Journal-quality scores assess publication titles (organisations), not individuals, and constitute advisory information for the user's own academic decision-making. Where any feature is introduced that could produce an automated output bearing materially on a natural person's interests, we will conduct a prior impact assessment, implement human-review mechanisms as required by Art. 22(3), and update this notice before launch. You may request human review of any decision that affects you directly at privacy@publishlens.com. |
| Withdraw consent | Art. 7(3) | Consent-settings link in the footer — as easy as giving consent, without retroactive effect |
| Lodge a complaint | Art. 77 | With the supervisory authority in your country of residence; given hosting in Germany (Hetzner), the BfDI is a relevant authority, alongside your right to seek judicial remedy |
III. Cross-border transfers (Arts. 44–49)
Where personal data of EU or UK residents is accessed by personnel or systems located outside the EEA (including in the Kingdom of Saudi Arabia), such access constitutes an international transfer under GDPR Chapter V and UK GDPR. We rely on the Standard Contractual Clauses adopted by the European Commission under Implementing Decision 2021/914 (Module 2: Controller to Processor), supplemented by a Transfer Impact Assessment. We have assessed that applicable laws in the destination country do not, in practice, impair the level of protection guaranteed by those clauses, having regard to the low sensitivity of the data transferred, the limited categories involved, and the technical safeguards applied (encryption in transit and at rest, access controls, pseudonymisation). Where an adequacy decision is issued by the European Commission covering any destination country to which we transfer data, we will update our safeguards accordingly. A copy of the applicable SCCs is available on request at privacy@publishlens.com.
IV. EU Representative (Art. 27) [Placeholder — to be finalised before first EU institutional contract.] We are assessing whether our processing volume triggers Art. 27, and are committed to designating and publishing a representative before signing any institutional contract with an EU entity.
V. Data Protection Officer (DPO) [Placeholder — reviewed annually.] The founder currently discharges DPO-level responsibilities. Under Art. 37, we reassess whether formal independent designation is required as scope evolves.
§6c. Rights of California Residents (CCPA/CPRA)
Applies to users residing in California, under CCPA (Cal. Civ. Code §1798.100 et seq.) as amended by CPRA.
I. Categories of personal information — see §2 for verbatim field-level mapping.
Sensitive personal information (SPI — §1798.121): We do not intentionally collect sensitive personal information as defined in the CPRA. To the extent any manuscript title excerpt submitted by a user incidentally contains information that could be characterized as sensitive, such information is processed transiently solely to deliver the requested journal recommendation and is not retained beyond the automated processing cycle, consistent with our data minimization obligations.
II. We do not sell or share your personal information for cross-context behavioral advertising
We do not sell or share your personal information as defined under Cal. Civ. Code §§1798.140(ad) and (ah). All third-party sub-processors who receive personal information (including the LLM inference provider used to generate journal recommendations) receive such information solely as service providers under written contracts that prohibit retention, use, or disclosure for any purpose other than performing services for PublishLens, consistent with Cal. Civ. Code §1798.140(ag). No data is disclosed for cross-context behavioral advertising.
III. Your CCPA/CPRA rights
| Right | Statute | Wording and mechanism |
|---|---|---|
| Right to Know | §1798.100 | To the extent required by applicable law, and subject to identity verification, you may request that we disclose the categories and specific pieces of personal information we have collected about you in the preceding 12 months. GET /account displays what we hold. |
| Right to Delete | §1798.105 | You may request deletion of personal information we have collected. We will comply to the extent permitted by law, subject to exceptions including but not limited to completion of transactions, security, legal obligations, and legitimate internal uses consistent with reasonable consumer expectations. |
| Right to Correct | §1798.106 | You may request correction of inaccurate personal information. We will use commercially reasonable efforts to correct such information, taking into account the nature of the data and our processing purposes. PATCH /account. |
| Right to Opt-Out of Sale/Sharing | §1798.120 | Because we do not sell or share personal information for behavioral advertising, no opt-out mechanism is presently required. Should our practices change, we will provide a conspicuous "Do Not Sell or Share My Personal Information" link prior to any such activity. |
| Right to Limit Use of SPI | §1798.121 | Not applicable — we do not intentionally collect SPI. |
| Right to Non-Discrimination | §1798.125 | You will receive no lower service level or different pricing for exercising any of these rights. |
Notice of Price or Service Difference (California Residents — §1798.125): PublishLens offers a Free tier and a Pro tier. The difference in features and usage limits between tiers reflects the operational cost of delivering expanded services and does not constitute compensation for the sale of personal information. We do not condition service on a user's exercise of any CCPA/CPRA right. If you believe any price or service difference constitutes a financial incentive as defined under Cal. Civ. Code §1798.125, you may contact privacy@publishlens.com to receive a plain-language explanation of how the difference relates to the value of any personal information involved, if at all.
Annual Privacy Metrics (California): To the extent we are required by applicable California law to compile and disclose annual privacy metrics, we will publish such metrics at [publishlens.com/privacy-metrics] within the timeframe required by law. Where disclosure thresholds have not yet been met, we maintain internal records of all consumer rights requests and responses for a minimum of 24 months as required by Cal. Code Regs. tit. 11, §7102.
Contact: privacy@publishlens.com. We respond within the timeframe required by CCPA (45 days, extendable by a further 45 days) after identity verification.
§6d. Rights of Brazilian Residents (LGPD)
Applies to data subjects residing in Brazil, under LGPD (Law No. 13.709/2018).
I. Legal bases under Art. 7
Processing under Art. 7(IX) LGPD (legitimate interest) is confined to: (a) security audit logging necessary to detect and respond to unauthorized access; (b) defence of legal claims; (c) editorial-board transparency assessment from publicly available sources. A legitimate-interest assessment (LIA) documenting the balancing test is maintained internally and may be provided to the ANPD upon request. Users may object to processing on this ground at any time via privacy@publishlens.com.
| Basis | Article | Application |
|---|---|---|
| Contract | Art. 7(V) | Account operation, journal recommendations, subscription management |
| Consent | Art. 7(I) | Optional analytics; corresponding-author acknowledgement |
| Legal obligation | Art. 7(II) | Retention of billing records under applicable law |
| Legitimate interest | Art. 7(IX) | As above — narrow scope |
II. Your rights under LGPD Art. 18 — as previously detailed in v0.2 tables, unchanged in substance.
III. Automated decisions (Art. 20)
Journal recommendations generated by our platform are informational outputs made available to the user to support their academic decision-making; they do not constitute decisions "made about" the user within the meaning of LGPD Art. 20. To the extent any output produced by automated processing is deemed to affect a data subject's interests under Art. 20, the data subject may at any time request a review of that output by contacting privacy@publishlens.com. We will provide a human-reviewed written response within 15 business days, including an explanation of the criteria and procedures used, to the extent technically feasible and not constituting disclosure of trade secrets.
IV. Data Protection Officer — Brazil (Encarregado — Art. 41)
Pursuant to LGPD Art. 41 and ANPD Resolution No. 18/2024, PublishLens has designated a Data Protection Officer for Brazil [Placeholder — formal appointment instrument to be executed prior to first Brazilian user]. Contact: dpo-brazil@publishlens.com. The DPO may communicate in Portuguese when required. Formal appointment documentation is maintained internally and is available to the ANPD upon request. In the DPO's absence, a designated substitute performs the same functions.
V. International Transfers (Art. 33 — ANPD Resolution No. 19/2024; 2026 mutual adequacy)
Personal data of Brazilian residents is stored on servers in Germany (Hetzner, EU). As of January 2026, the European Union and Brazil have established mutual adequacy recognition (ANPD Resolution No. 32/2026; EC Implementing Decision 2026/179), such that transfers to Germany are conducted under an adequacy framework. To the extent any onward transfer falls outside this adequacy decision, we rely on ANPD-approved Standard Contractual Clauses (Resolution No. 19/2024) or other safeguards recognized under LGPD Art. 33. Our transfer mechanisms are reviewed annually or upon material changes to the applicable regulatory framework.
Supervisory authority: ANPD. Contact: privacy@publishlens.com.
7. Consent, cookies, marketing
Necessary cookies always run; analytics/marketing are opt-in, off by default, with no non-essential script loaded before consent; change your choice anytime [COOKIE_CONSENT_SPEC.md]. Marketing emails require separate, revocable consent; service alerts you created are contract-based.
8. Security
We apply industry-recognised encryption standards in transit and at rest, updated in line with current best security practices; alongside a WAF, secrets management, and API keys stored as hashes only, referenced to OWASP ASVS 5.0 L2 [SECURITY.md]. Specific technical details are available on request to compliance auditors.
Breach notification: We endeavour to notify breaches as soon as possible; our internal operational target is 48 hours as a best-effort goal, and in all cases we comply with the timeframes prescribed by the laws applicable in each jurisdiction — in particular: notification to SDAIA within 72 hours under PDPL Art. 24, notification to the competent supervisory authority within 72 hours under GDPR Art. 33, and notification of affected individuals without undue delay where harm is likely. Internal timeframes are operational targets, not standalone legal warranties.
9. Compliance officer & updates
The founder acts as DPO-level compliance officer [PDPL_COMPLIANCE.md §9.1]. Reviewed annually and on material change; notified 30 days before any material change takes effect. Contact: privacy@publishlens.com.
Mandatory notice / تنبيه إلزامي: This draft has been reviewed by an AI legal committee (PDPL/GDPR/CCPA/LGPD specialists). It has NOT been reviewed by licensed human counsel. Publication requires final review and sign-off by admitted counsel in each affected jurisdiction. Owner accepts residual risk (see ADR-025).