Privacy Policy - PLOS (original) (raw)
PRIVACY POLICY UPDATES
We have recently made some updates to this privacy policy to clarify our existing practices. See here for prior versions.
Updated on March 20th, 2024
INTRODUCTION
Public Library of Science (PLOS) is dedicated to protecting your personal information and will make every reasonable effort to handle collected information appropriately. All information collected will be handled with care in accordance with PLOS’ standards for integrity and objectivity and respect for your privacy. PLOS endeavors to comply with all laws and regulations that apply to the gathering and use of personal information, including US privacy laws, the EU General Data Protection Regulation, and the data protection laws of the People’s Republic of China (China which solely for the purpose of this privacy policy refers to Mainland China only). This privacy policy describes the information we collect, the purposes for which it is used, and your choices regarding its use. As used in this privacy policy, “we” and “us” includes PLOS and our staff, employees, officers, directors, volunteer editors and reviewers, and vendors and independent contractors under contract with us. “PLOS Sites” includes the following: the web pages and content on the PLOS websites, journal sites, and PLOS or third party tools, software, submission systems, web forms, registration system, and any other means through which we interact with you.
- Information We Collect
- How We Use and Disclose Your Information
- How Long We Retain Your Information
- Protection of Personal Information
- Third Party Websites
- Sending you Email Communications
- Changes to this Privacy Policy
- Additional Terms for European Economic Area and UK Residents
- Additional Terms for China Residents
- How to Contact Us Regarding Your Personal Information
INFORMATION WE COLLECT
Personal Information
We request personal information from you while interacting with the PLOS Sites, as follows:
- When you register on a PLOS Site for updates or to receive other types of notifications from us, we will ask for your email address to enable us to send you the information you have requested.
- If you want to submit a manuscript or other research output to PLOS for consideration or for posting on our sites or as a preprint, we will ask for the following information so that we may consider, process, and possibly publish your manuscript, in conformance with accepted publishing standards: your name, title, telephone number, email address, institution, department, address, and credit card or other payment information. You may voluntarily provide us with additional information to help us identify and contact you, such as your middle name, degree, preferred name, secondary phone number, fax number, position, ORCID iD (Open Researcher and Contributor Identifier), state or province, and areas of interest or expertise. Except for credit card or other payment information, we will ask for the same information if you want to be considered as an editor or reviewer. If you are a corresponding author, we require your ORCID iD to help identify you and connect your work to your ORCID record when an article is published. You can learn more about ORCID iD here.
- If you want to submit a public comment on our website, we will ask for the following information: email, first name, and last name. Your display name, which is auto-generated to include your first initial, last name and randomly selected number(s), will be made public along with your comment. If you request that your account be deleted, your comment will remain on our website but your display name will no longer be associated with your comment.
- If you register on a PLOS Site, we will gather and store your username and password to identify you at sign-in and to administer your account.
- If we send you email with links then we will gather and store the information about the links that you click on in order to track the effectiveness of our communications.
Additionally, PLOS may process some basic personal information about you (email address, name and research interest) that is publicly available to register you as a potential reviewer and expert or to contact you about publishing with PLOS on a particular topic. If you do not wish to be contacted as a potential reviewer or for possible publication with PLOS, you can email us at privacy@plos.org. We will keep some of your personal information to recall your request not to be contacted in the future.
Finally, we may collect demographic information about you, such as geographic location, age gender, race and ethnic origin for diversity, equity and inclusion purposes and for analytic purposes. If you provide demographic information to PLOS, you do so voluntarily and PLOS will collect, store and use your demographic information in accordance with this privacy policy.
Technical Information
By corresponding with PLOS, submitting to PLOS journals, or generally visiting or otherwise interacting with the PLOS Sites, we collect, have access to, store and may use data including your computer’s IP address, the URL/domain name of any referring website, the time and date of your visit to the PLOS Sites, metadata and certain information known as “clickstream data” to enable us to understand how people interact with the PLOS Sites, to analyze data for trends and statistics, to help diagnose and solve issues with the PLOS Sites and our technologies, products, and services, to optimize the performance of the PLOS Sites, or to investigate integrity issues. We use click view data to provide statistics on articles such as number of views and downloads. We also use session cookies, as described below. From time to time, we use software tools to play back user sessions for our internal use in assessing our customers’ interactions with our software, and these sessions may be linked to your user account. When we send you an email which contains personalized links then we will gather and store your name, email, and any link you click on, when you click on the links in order to track the effectiveness of our communications.
Cookies and Other Tracking Technologies
We and our third party providers use cookies and other tracking technologies to collect information. For more detailed information about the cookies and other tracking technologies we use, why we use them, the basis for using them, and your choices, see our Cookie Policy.
Children’s Privacy
Use of the PLOS Sites is intended for adults at least eighteen (18) years of age and we do not knowingly collect personally-identifying information from children under the age of thirteen (13).
HOW WE USE AND DISCLOSE YOUR INFORMATION
Use by PLOS
PLOS uses your personal information as described in the “INFORMATION WE COLLECT” section, to customize your experience on the PLOS Sites and facilitate our interactions with you.
If you are an author, we use your personal information for the purpose of processing, reviewing, communicating about, facilitating editorial review and peer review, for publishing, and to facilitate payment of article publishing fees.
If you are an editor or reviewer, we use your personal information to contact you about your potential or actual role as an editor or reviewer, to request and facilitate your review and handling of manuscripts, and to update you on news and developments at PLOS as it may affect your work with us.
If an author chooses to publish their peer review history, we make the manuscript review process available to the public when an article is published, including the contents of emails and other communications between reviewers, editors and authors via a PLOS Site.
If you write a blog for the PLOS blog, your name, photograph and biography (as provided by you) will be made public.
We may also use your personal information to assist with improving the peer review system, editorial process, integrity investigations and scientific communication, as part of PLOS’s ongoing research program on the processes we use in the course of manuscript handling.
If you provide demographic information to PLOS as described in the “INFORMATION WE COLLECT” section above, then we usually collect and use this information on an anonymized basis so that you will not be identified from it unless we tell you otherwise. We will use that information only for internal diversity tracking purposes.
If you simply visit PLOS Sites to read content, we will use information such as your URL and cookies to provide a good experience, as described in the “INFORMATION WE COLLECT” section.
We may also collect your name, email, address and phone number at conferences or events.
Disclosure to Third Parties
If you submit a manuscript or other research content to us for possible publication, we will send the title and abstract of your manuscript, and your name, to one or more potential external/volunteer editors and reviewers to gauge their interest in reviewing your content. If they agree to review your content, we will send them your full manuscript and any revisions and relevant comments you have provided. If your manuscript is accepted for publication, we share information about you, your manuscript, or other research content as reasonably necessary with volunteer curators and channel managers. In addition to volunteer curators and channel managers, we may share the foregoing information with journalists prior to publication for the purpose of promoting your work.
If you choose to publish your manuscript as a preprint, we send your manuscript to our preprint partner(s) for posting of your manuscript.
If a paper is published or posted as a preprint, the following information appears as part of the paper: author’s name, role, email address, affiliation, ORCID iD, any competing interests, editor’s name, and affiliation. The foregoing information will also be included in the article XML and syndicated to third parties. If you are a reviewer that has voluntarily provided an ORCID iD to PLOS and choose to participate in the ORCID reviewer recognition, we will share general information about your review with your ORCID record, such as the year your review was completed and type of review.
If an author chooses to publish their peer review history, then the contents of emails and other communications between reviewers, editors and authors via a PLOS Site will be made public. If you are a reviewer and provide us with your consent, we will disclose your name as part of the peer review history when an article is published and the author has chosen to publish the peer review history. To remove your name from the peer review history after disclosure to the public, you can email privacy@plos.org.
We may also disclose personal information as reasonably necessary for the purposes described in this privacy policy to other third parties, as follows:
- Vendors, independent contractors, and consultants to enable us to provide products and services, such as editorial and production vendors supporting submission checks, peer review, and publication, financial institutions (for facilitating payment of fees owed), web and technical support providers (such as hosting providers and customer service and support providers), and third parties who provide syndication and preprints
- Institutions or consortia, to facilitate payment of publishing fees on the author’s behalf, if applicable
- Third party workflow service intermediaries, to facilitate the performance of contractual obligations between PLOS and institutions or consortia, as applicable
- Other publishers
- Third parties authorized by you to receive such information, such as third parties that facilitate the automatic update of your ORCID record.
- To respond to claims asserted against us or comply with legal process (e.g., subpoenas or warrants), or lawful requests from government or law enforcement authorities (as required to meet national security or law enforcement requirements), and to enforce or comply with our agreements, terms of use, and this privacy policy
- Academic research groups and researchers for the purposes of improving or evaluating the peer review system, editorial process, integrity investigations and scientific communication
- Third-party tools, websites, and providers of tools or services engaged by PLOS to support submission checks & processing, peer review, the editorial process, integrity investigations and/or scientific communication
- To comply with applicable law, or as required or permitted by law
- Where it is in our legitimate interests, under relevant law, to run, grow and develop our organization in order to expand the impact of science and medicine
- If we sell any business or assets, we may disclose your personal information to the buyer of such business or assets
- If substantially all of our or any of our affiliates’ assets are acquired by a third party, in which case personal information held by us will be one of the transferred assets
- To protect the safety of any person or to prevent any illegal activity
- To protect the rights, property, or safety of PLOS, our staff, our users or other persons. This may include exchanging personal information with other organizations for the purposes of fraud protection and credit risk reduction
- Institutions, ethics committees, and other third parties, as appropriate, where we have concerns about failure to comply with our publishing standards and guidelines or to uphold research integrity or publication ethics standards, or where their input is otherwise needed in regard to an integrity investigation by PLOS
In some cases, the applications or user interfaces you encounter while on our sites are managed by third parties, who may require that you provide your personal information. We are not responsible for the privacy practices of these third party services or applications. We recommend carefully reviewing the user terms and privacy statement of each third party service, website, and/or application prior to use.
PLOS will never disclose demographic information, described in the “INFORMATION WE COLLECT” section above, to third parties, unless it has been anonymized or otherwise deidentified.
No Sale or Leasing of Your Information
Except as described in the “Disclosure to Third Parties” section of this privacy policy, we will not disclose your personal information to third parties without your consent. We will not sell or lease your personal information to any third party. We may disclose aggregate demographic and statistical information with our business partners; this information is not specific to the identification of you as an individual.
HOW LONG WE RETAIN YOUR INFORMATION
We retain your personal information for as long as necessary to provide services and fulfill the transactions you have requested; for the purposes of preserving PLOS publishing standards and ethical guidelines; for archiving scientific research, peer review details, and correspondence about PLOS content; and for other essential purposes such as complying with our legal obligations. We will retain and use your information as necessary to comply with our legal obligations, to resolve disputes, and to enforce our agreements.
Requests to delete, amend or withdraw consent – non-EEA or UK residents
You may be entitled to request that we delete or amend your personal information. You may also be entitled to withdraw your consent, when consent is the basis for processing your personal information. We apply the same procedures, limitations and exceptions established for European Economic Area (EEA) and UK residents in this privacy policy to all who make such request to delete or amend personal information, or withdraw consent for processing personal information, regardless of geographic location. Please read the “Your Rights” paragraph under the “ADDITIONAL TERMS FOR EUROPEAN ECONOMIC AREA AND UK RESIDENTS” below for details. If you are a resident of the EEA or UK, see below for more specific details on how that applies to you.
PROTECTION OF PERSONAL INFORMATION
We use reasonable and appropriate physical, technical, and administrative safeguards to protect your information from unauthorized use, access, loss, misuse, alteration, or destruction. We endeavor to protect the personal information we receive, gather and store, by such means as password protection, firewalls and other means. We also require that third party service providers acting on our behalf or with whom we share your information also provide appropriate security measures in accordance with industry standards.
Transmissions over the internet are never entirely secure and we cannot guarantee the security of information you submit via a PLOS Site while it is in transit over the internet. Any such transmission of information by you over the internet is at your own risk.
THIRD PARTY WEBSITES
If, in your interactions with the PLOS Sites, you are linked or directed to, or click on, a third party website, we cannot control what information you may provide to that party or on/at that website, and are not responsible for how that party may use or disclose any information you may provide to them. As such, we urge that you exercise caution before providing them with your personal information and to review the third party’s privacy policy for information on its data processing practice.
SENDING YOU EMAIL COMMUNICATIONS
Except in countries or jurisdictions where it is not be permitted by law, we may from time to time send you email communications regarding our business, products or services in response to your use of the PLOS Sites.
For UK and EEA recipients, PLOS’ legal basis for using your information to send email communications is our legitimate interests to run, grow and develop our organization in order to expand the impact of science and medicine and spread knowledge in this field. We describe our legitimate interests in more detail under the “Legal Basis for your information” section below. Email communications will be sent on an opt out basis to any recipient who has registered or signed up for PLOS services and did not opt out.
Where required by law, we may process your personal information for marketing purposes on the basis of your consent.
You can opt out of receiving such communications at any time by using the unsubscribe link(s) in emails we send you or by emailing us at privacy@plos.org.
You can opt out of receiving such communications by using the unsubscribe link(s) in emails we send you or by emailing us at privacy@plos.org.
CHANGES TO THIS PRIVACY POLICY
PLOS may make changes to this privacy policy from time to time. Changes to this privacy policy will be made by updating this page. Please visit this privacy policy regularly to read the current version. If there are material changes to how we use your personal information, we will endeavor to provide you with reasonable notice of such changes, either by prominent notice on www.plos.org or to your email address of record.
Cross Border Transfers
PLOS is headquartered in the United States, with an office in the United Kingdom, subsidiaries in Germany and Singapore, and service providers throughout the world. As such, PLOS and our service providers may transfer your personal information to, or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. PLOS will take measures to protect the cross-border transfer of your information in accordance with applicable law.
If you do not want your personal information transferred to the U.S., please do not submit any information to us or use our services. When PLOS transfers information about individuals based in the EEA or UK outside of those countries, we will take appropriate measures to safeguard the transfer as required by applicable law, including by using of European Commission-approved standard contractual data protection clauses or following an adequacy decision by the EU Commission and equivalent provisions under applicable UK law.
ADDITIONAL TERMS FOR EUROPEAN ECONOMIC AREA AND UK RESIDENTS
If you reside within the European Economic Area or United Kingdom, the following additional terms apply.
Legal Basis for Use of Your Information
The information we require, as identified in the “INFORMATION WE COLLECT” section of this privacy policy, is processed under the following legal basis:
PLOS’s legitimate interests. This includes:
- to enable PLOS to provide our products and services to you
- finding and contacting qualified reviewers to ensure the high level of articles published in a PLOS journal, as applicable
- contacting authors and other academics to ensure they are aware when PLOS is calling for papers for relevant journals
- to ensure compliance with publishing standards and ethical guidelines and to take action necessary to uphold these
- for marketing to individuals at businesses/corporate addresses and to our subscribers, market research and business development
- for analytics, to gather metrics to better understand how users use the PLOS Sites, to evaluate and improve the PLOS Sites, and to provide PLOS’ users with this information, where applicable
- to provide information on PLOS publication fees and other relevant terms with institutions or consortia, where applicable
- to prevent fraud and other illegal activity
- the legitimate interests of others (for example, to ensure the security of our website)
- to comply with legal obligations, as part of our general business operations, and for other internal business administration purposes
- if we collect demographic information from you (such as gender and ethnic origin) in order to carry out diversity monitoring and such information is not collected in an anonymous format, then we rely on our legitimate interest to do so.
Contractual obligations. For the performance of contractual obligations between you and PLOS, including the PLOS Terms of Use.
Consent. Where required by law, we may process your personal information in some cases for marketing purposes on the basis of your consent (which you may withdraw at any time after giving it, as described in this privacy policy). Otherwise, email communication will be sent on an opt out basis to any recipient who has registered or signed up to PLOS services and did not opt out.
Your Rights
Deletion of Personal Information
You may be entitled to request that we delete your personal information in certain specific circumstances. If you wish to exercise this right, please submit your request at privacy@plos.org.
If you are an author and have submitted a manuscript or other research outputs to PLOS, or you are an editor or reviewer that has reviewed manuscripts or other research outputs submitted to PLOS, some of your personal data will be retained as necessary for PLOS to establish, exercise or defend a legal claim; for archiving scientific research; and for exercising the right of freedom of expression and information. We may retain your personal data for the purposes of preserving PLOS publishing standards and ethical guidelines, which authors are made aware of before submission of any manuscript or other research output. Such personal data includes your name, institutional affiliation, title and email address.
If your article has been published or posted as a preprint, the following additional personal data will be retained for purposes of archiving scientific research: author’s role, ORCID iD, and any competing interests.
We will consider all such requests and provide our response within a reasonable period (but no longer than one calendar month from our receipt of your request unless we tell you that we are entitled to a longer period under applicable law). We may require you to verify your identity before we respond to your request. Certain personal information may be exempt from such requests in certain circumstances, including as provided for in this privacy policy.
Access, Update, Data Portability and Other Rights
You may also be entitled to access your information, update your personal information which is out of date or incorrect, restrict use of your personal information in certain specific circumstances, place a data portability request (applicable only when we use your personal information on the basis of your consent or performance of a contract, and where our use of your information is carried out by automated means), and ask us to consider any valid objections which you have to our use of your personal information where we process it on the basis of our or another person’s legitimate interest. Requests should be directed to privacy@plos.org.
We will consider all such requests and provide our response within a reasonable period (but no longer than one calendar month from our receipt of your request unless we tell you we are entitled to a longer period under applicable law). We may require you to verify your identity before we respond to any of your requests. Certain personal information may be exempt from such requests in certain circumstances, including as provided for in this privacy policy.
Complaints
You also have the right to lodge a complaint before a supervisory data protection authority regarding our data processing.
If you are in Europe, an up to date list of data protection authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. If you are in the UK, the data protection authority is the UK Information Commissioner’s Office available at https://ico.org.uk/.
ADDITIONAL TERMS FOR CHINA RESIDENTS
If you reside in China, the following additional terms apply. The terms “personal information” and “sensitive personal information” referred to in this privacy policy have the same meanings respectively defined under the Personal Information Protection Law of the People’s Republic of China (PIPL). For personal information of residents in China, the data controller (i.e., the personal information processor as defined under the PIPL) is PLOS.
Processing of Sensitive Personal Information
Among the various categories of personal information we collect as described in the “INFORMATION WE COLLECT” section of this privacy policy, the following may be considered as sensitive personal information as defined in the PIPL: credit card or other payment information, race and ethnicity. We will process your sensitive personal information for the specific purposes as described in this privacy policy, and in a way that has the least impact on your personal rights and interests. By using our services, you will be deemed as having consented to our collection and processing of your sensitive personal information in accordance with this privacy policy.
Legal Basis for Use of Your Information in China
We may, where applicable under the Chinese laws, rely on some or all of the following applicable legal bases for the processing of your personal information: (i) your consent, (ii) the necessity to conclude or perform a contract to which you are a party, (iii) the necessity to perform a statutory duty or legal obligation; and (iv) other circumstances as stipulated in China laws. We will process your personal information for the purposes specified in the “HOW WE USE AND DISCLOSE YOUR INFORMATION” section of this privacy policy.
Cross Border Transfers and Disclosure to Third Parties
As China residents, you acknowledge, understand and agree that our processing of your personal information takes place outside of China and your personal information will be stored outside of China. We will take measures to protect your information in accordance with applicable law.
We share your personal information with the recipients as prescribed in the “Disclosure to Third Parties” section of this privacy policy. Where required by applicable law, details of the recipients will be made available to you upon your request. If we provide your personal information to such recipients, we will follow and adopt the applicable process and requirements required by the applicable law. By using our services, you will be deemed as having consented to our sharing of your personal data to the foregoing recipients in accordance with this privacy policy.
Your Rights under PIPL
This section describes the rights of residents in China regarding the personal information under Chinese law and explains how to exercise those rights.
- Right of access and copy: You have the right to access and copy the personal information concerning you.
- Right to rectification: You have the right to request that we rectify inaccurate personal information concerning you or supplement incomplete personal information.
- Right to erasure: You have the right to ask us to erase your personal information in certain circumstances specified under the applicable law. However, your right to erasure will not affect the lawfulness of our processing prior to the erasure request or processing based on the applicable legal bases.
- Right to explanation: You have the right to require that we further explain our rules of processing of personal information to the extent that they are unclear or not addressed in this privacy policy.
- Right to transfer: You have the right to request that we transfer your personal information that we hold about you to another controller to the extent the conditions stipulated by the applicable law are fulfilled.
- Right to withdraw your consent: If you have given your consent regarding certain types of processing activities, you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal or processing based on the applicable legal bases.
- Other rights permitted by the applicable law.
If you wish to exercise the above rights, please submit your request at privacy@plos.org. We will consider all such requests and provide our response within a reasonable period (but no longer than one calendar month from our receipt of your request unless we tell you that we are entitled to a longer period under applicable law). We may require you to verify your identity before we respond to your request. Certain personal information may be exempt from such requests in certain circumstances, including as provided for in this privacy policy.