Privacy Statement

Personal Data and Editorial Confidentiality

Privacy Statement

Multidisciplinary Journals (MJ)  |  e-ISSN 3047-8499

The names, email addresses, affiliations, identifiers, and other personal information entered on this journal site will be used only for legitimate journal-management, scholarly-communication, research-integrity, security, legal, and publication purposes described in this statement. Multidisciplinary Journals (MJ) does not sell personal data and does not disclose it for unrelated commercial purposes.

Data principleMinimum necessary
Editorial processConfidential access
Published recordTransparent metadata
Commercial saleNever

1. Scope and Responsible Organisation

This statement applies to personal data processed through the MJ website and Open Journal Systems (OJS), including data relating to authors, co-authors, reviewers, editors, editorial staff, registered readers, complainants, correspondents, and website users. MJ is published by Universitas Dehasen Bengkulu, which provides institutional oversight for the journal's handling of personal data.

This statement addresses personal data used to operate the journal. Personal or confidential information contained in research data is governed additionally by the journal's Research Data Policy and Ethical Oversight Policy. Copyright ownership and reuse are governed separately by the Copyright and Licensing Policy.

2. Personal Data We May Process

Data Category Examples
Account and identity data Name, username, preferred salutation, password hash, roles, language preference, ORCID iD, and other identifiers voluntarily supplied.
Contact and affiliation data Email address, telephone or WhatsApp number when provided, institutional affiliation, department, country, mailing address, and professional profile.
Submission and authorship data Manuscript files, title-page details, author order, contributor roles, declarations, funding information, conflicts of interest, ethics information, and correspondence.
Editorial and peer-review data Reviewer interests, invitations, acceptance or decline history, review reports, editor assignments, decisions, revision history, and audit logs.
Publication metadata Author names, affiliations, ORCID iDs, corresponding-author details, acknowledgements, funding, article history, DOI, licensing, and other information forming part of the scholarly record.
Technical and security data IP address, date and time of access, browser or device information, authentication events, system logs, cookie identifiers, and actions recorded for security or audit purposes.
Administrative and payment data Invoice references, OJS submission ID, payer name, payment amount, transaction reference, waiver or refund records, and proof of payment. Full card credentials, passwords, and one-time passwords must never be submitted.
Complaint and integrity data Appeals, complaints, allegations, supporting evidence, responses, institutional communications, and resolution records.

3. Purposes of Processing

MJ processes personal data only when reasonably necessary for one or more of the following purposes:

  • creating and administering user accounts and journal roles;
  • receiving manuscripts and managing editorial screening, double-blind peer review, revision, copyediting, production, and publication;
  • verifying authorship, contributor roles, conflicts of interest, ethics approvals, consent, originality, and research integrity;
  • communicating decisions, reminders, production queries, publication notices, and journal-service information requested by the user;
  • publishing and disseminating the scholarly record and depositing metadata with DOI agencies, indexing services, libraries, repositories, and preservation services;
  • administering invoices, APC waivers, refunds, and auditable financial records independently from editorial decisions;
  • preventing spam, fraud, unauthorised access, manipulated peer review, cybersecurity incidents, and misuse of the platform;
  • responding to access requests, complaints, legal claims, research-integrity concerns, and institutional investigations; and
  • maintaining backups, archives, system continuity, and an accurate version of record.

4. Legal and Ethical Basis

Depending on the context, processing may be necessary to provide requested journal services, perform editorial and publication functions, comply with legal obligations, protect legitimate scholarly and security interests, preserve the integrity of the academic record, or act on valid consent where consent is the appropriate basis. Processing is conducted with reference to applicable Indonesian law, including Law of the Republic of Indonesia Number 27 of 2022 on Personal Data Protection.

Withdrawing consent does not invalidate processing already lawfully undertaken and may not require removal of information that must be retained in the published scholarly record, an integrity investigation, a financial record, or another lawful record.

5. Privacy Requirements for Manuscripts and the Article Template

For double-blind review, authors must:
  1. place author names, affiliations, ORCID iDs, contact details, biographies, acknowledgements, and other identifying information on a separate title page;
  2. remove author identity from the blinded manuscript, file properties, tracked changes, comments, filenames, self-identifying acknowledgements, and supplementary files;
  3. replace identifying self-citations only when necessary for anonymity and restore complete citations after review;
  4. avoid including names, photographs, identification numbers, precise addresses, facial images, voice recordings, medical identifiers, or other recognisable participant data unless scientifically necessary, ethically approved, and supported by valid consent;
  5. anonymise or pseudonymise research data and quotations where appropriate and explain any justified limitation;
  6. include an ethics approval statement, informed-consent statement, consent-for-publication statement, and data-availability statement when applicable; and
  7. confirm that sharing a dataset, image, transcript, case description, or supplementary file does not unlawfully disclose personal or confidential information.
Author responsibilityAuthors are responsible for obtaining appropriate ethics approval and consent and for protecting research participants. The journal may request evidence confidentially, but such evidence is not automatically published or shared with reviewers.

6. Editorial Confidentiality and Access Control

  • Access is limited by OJS role and the responsibilities assigned to an editor, reviewer, production worker, administrator, or authorised publisher representative.
  • Reviewers receive only the information needed to assess the manuscript and must not attempt to identify authors or disclose unpublished material.
  • Editors and reviewers must not upload unpublished manuscripts, review reports, or personal data to public generative-AI platforms or unapproved external services.
  • A person with a material conflict of interest must not access or determine the matter beyond what is necessary to disclose and manage that conflict.
  • Privileged editorial information must not be used for personal, competitive, commercial, or research advantage.

7. Publication and Disclosure of Metadata

When an article is published, selected information becomes part of the public scholarly record. This normally includes author names, affiliations, ORCID iDs, contributor roles, corresponding-author contact information where stated for publication, funding and conflict declarations, acknowledgements, article history, DOI, references, and licensing information.

Published metadata may be transmitted internationally through Crossref or another DOI registration agency, search engines, indexing and abstracting services, library catalogues, repositories, citation databases, analytics systems, and digital-preservation services. Public scholarly metadata may remain available even after an OJS account is closed.

Account-only data—such as a private telephone number, password hash, unpublished address, reviewer identity under double-blind review, or internal correspondence—is not published merely because an article is accepted.

8. When Personal Data May Be Shared

MJ may share the minimum necessary personal data with:

  • editors, reviewers, copyeditors, layout editors, proofreaders, administrators, and authorised publisher personnel;
  • OJS hosting, email, security, backup, DOI, similarity-screening, payment-administration, indexing, repository, and preservation providers acting for legitimate journal purposes;
  • an author's institution, employer, ethics committee, funder, or competent research-integrity body when a substantiated concern requires referral;
  • law-enforcement, courts, regulators, or other authorities when disclosure is legally required or necessary to protect rights, safety, or the integrity of the journal; and
  • a successor custodian if journal ownership, hosting, or preservation responsibility is lawfully transferred, with appropriate safeguards and notice where required.

External providers must not use journal data for unrelated purposes. MJ does not sell, rent, or exchange user lists with advertisers, data brokers, manuscript solicitors, or unrelated third parties.

9. Cookies, Logs, and Website Analytics

OJS may use strictly necessary cookies to maintain sessions, authentication, language preferences, and security. Server and application logs may record IP addresses, access times, browser information, and system events for security, troubleshooting, abuse prevention, and service reliability.

Any optional analytics or third-party tracking service must be assessed, documented, configured to minimise personal data, and disclosed before activation. The journal must not insert hidden trackers, unauthorised advertising code, SEO-spam scripts, or unrelated external links into the website.

10. Retention and Deletion

Record Retention Approach
Published articles and public metadata Retained as part of the permanent scholarly record, subject to correction, retraction, or exceptional removal procedures.
Submission, review, and decision records Retained for the period reasonably required for editorial audit, dispute resolution, research-integrity review, and journal reporting; access remains restricted.
Financial and payment records Retained according to applicable accounting, audit, taxation, fraud-prevention, and institutional requirements.
User accounts and profile data Retained while the account is active or needed for journal roles and records, then deleted, anonymised, or restricted where appropriate and legally permitted.
Security logs and backups Retained according to the documented security, backup, incident-response, and digital-preservation schedule, then securely rotated or deleted.

Deletion requests are assessed against legal, contractual, integrity, preservation, and scholarly-record obligations. When deletion is not appropriate, access may be restricted or unnecessary fields may be minimised, anonymised, or pseudonymised.

11. Security Measures

  • role-based access and least-privilege administration;
  • HTTPS transmission, secure authentication, password hashing, and account-management controls;
  • OJS, server, plugin, and dependency updates based on supported releases and security risk;
  • separate, access-controlled backups and tested recovery procedures;
  • monitoring, logging, malware or malicious-link checks, and incident response;
  • confidentiality obligations and appropriate training for editorial and administrative personnel; and
  • secure deletion or disposal when records are no longer required.

No internet service can guarantee absolute security. Users should use unique passwords, protect their accounts, verify unusual messages, and promptly report suspected unauthorised access.

12. Individual Rights and Requests

Subject to applicable law and legitimate journal obligations, an individual may request information about their personal data, access to relevant data, correction of inaccurate data, deletion or restriction where appropriate, withdrawal of consent where processing is based on consent, or review of an objection to processing.

A privacy request should include:
  • the requester's name and registered email address;
  • the OJS username, manuscript ID, DOI, or other record reference where relevant;
  • a clear description of the data or action requested; and
  • sufficient information to verify identity without collecting excessive identification data.

The journal may request clarification, refuse disclosure that would reveal another person's confidential information, or retain information necessary for publication integrity, legal obligations, security, fraud prevention, dispute resolution, or the permanent scholarly record. The reason will be explained where appropriate.

13. Personal Data Incident

A suspected loss, unauthorised disclosure, alteration, malicious access, account compromise, or misuse of personal data should be reported promptly. The publisher will assess the incident, contain the risk, preserve relevant evidence, restore secure operation, document corrective action, and notify affected persons or competent authorities when required.

A report should identify the affected account, manuscript, page, email, or transaction; describe what happened and when; and include relevant evidence without redistributing exposed personal data.

14. Policy Review and Contact

This statement may be updated when journal practices, OJS functions, service providers, legal requirements, security risks, or publication workflows change. Material changes will be dated and published on this page. A change will not be used to legitimise unrelated processing of data collected under an earlier statement.

Privacy Request or Incident Report Contact the MJ editorial office through the official journal page. Do not send passwords, one-time passwords, or unrestricted financial credentials. Journal Contact Page OJS Login