Privacy Statement

Effective date: 26 Feb 2026
Last updated: 15 Mar 2026

Engineering Informatics and Intelligent Systems (EIIS) and its publishing platform, operated by Informatics Foundry (“we”, “us”, “our”), are committed to protecting your personal data and respecting your privacy.

This Privacy Statement explains how we collect, use, store, disclose, and otherwise process personal data in connection with the operation of this journal website, including user registration, manuscript submission, peer review, editorial administration, publication, and related communications.

1. Data Controller

The data controller responsible for the personal data processed through this journal site is:

Informatics Foundry Ltd.
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
General contact: info@informaticsfoundry.org

If you have any questions about this Privacy Statement or wish to exercise your data protection rights, please contact us using the details above.

2. Scope of this Privacy Statement

This Privacy Statement applies to personal data collected through this journal website and related editorial and publishing processes, including when you:

  • create an account on the journal site;
  • submit a manuscript or act as a co-author;
  • serve as a reviewer, editor, guest editor, or advisory board member;
  • subscribe to publication alerts, newsletters, or journal announcements;
  • contact us through the website or by email;
  • browse the website where technical data such as IP address, browser type, and server logs may be collected for security and site administration purposes.

3. Categories of Personal Data We Collect

Depending on your relationship with the journal, we may collect and process the following categories of personal data:

Account and identity information

  • name;
  • username;
  • title;
  • institutional affiliation;
  • ORCID iD or other scholarly identifiers, where provided;
  • role on the platform (e.g. author, reviewer, editor, reader).

Contact information

  • email address;
  • postal address, where relevant;
  • telephone number, where voluntarily provided.

Professional and publication-related information

  • biography, expertise, research interests, keywords, reviewing interests;
  • manuscript files, supplementary files, cover letters, responses to reviewers, editorial decisions, and correspondence;
  • authorship, affiliation, funding, conflict-of-interest, and acknowledgement information;
  • reviewer recommendations, reports, scores, and editorial comments.

Technical and usage information

  • IP address;
  • device and browser information;
  • log files and timestamps;
  • security-related and authentication records;
  • cookie-related data, where applicable under the site’s cookie settings.

Communications and preferences

  • your preferences for receiving alerts, announcements, or review invitations;
  • correspondence sent to or from the editorial office.

4. Purposes of Processing

We process personal data for the following purposes:

Journal operation and account administration

  • to create and manage user accounts;
  • to authenticate users and maintain platform security;
  • to administer access rights and user roles.

Submission, peer review, and editorial management

  • to receive, process, assess, and manage manuscript submissions;
  • to administer peer review and editorial decision-making;
  • to identify, invite, and communicate with reviewers, editors, and authors;
  • to maintain the integrity, traceability, and auditability of editorial workflows.

Publication and scholarly communication

  • to publish accepted articles and associated metadata;
  • to display author names, affiliations, biographies, acknowledgements, and other publication information where relevant;
  • to index, archive, disseminate, and preserve scholarly content.

Communications

  • to send transactional and service-related communications, such as submission confirmations, editorial decisions, reviewer invitations, password resets, and system notices;
  • where you opt in, to send new publication alerts, journal announcements, and related updates;
  • where you opt in or where otherwise lawful, to contact you regarding opportunities to review submissions.

Compliance, security, and administration

  • to comply with legal, regulatory, ethical, and publishing obligations;
  • to prevent misuse of the platform, fraud, unauthorised access, or other security incidents;
  • to establish, exercise, or defend legal claims.

5. Legal Bases for Processing

Where UK GDPR and/or EU GDPR applies, we rely on one or more of the following legal bases, depending on the context:

Performance of a contract or steps prior to entering into a contract
For example, where processing is necessary to create and maintain your account, administer submissions, manage peer review, or provide publishing services you request.

Legitimate interests
For example, for operating and improving the journal, maintaining editorial records, ensuring the integrity of scholarly publishing, preventing misuse, communicating with authors, reviewers, and editors in connection with journal workflows, and securing the website and systems. Where we rely on legitimate interests, we consider and balance those interests against your rights and freedoms.

Consent
For example, where you choose to receive publication alerts, announcements, or other optional communications, or where local law requires consent for certain communications or technologies.

Legal obligation
Where processing is necessary to comply with applicable law, regulatory requirements, publishing ethics obligations, audit requirements, or lawful requests from public authorities.

6. How We Use Optional Checkboxes and Preferences

Where the registration form allows you to tick boxes such as:

  • receiving notifications of new publications and announcements; and/or
  • being contacted with requests to review submissions,

these options are voluntary. If you opt in, we will use your contact details and relevant professional profile information for those purposes. You may withdraw your consent or update your preferences at any time through your account settings or by contacting us.

Please note that essential service communications relating to your account, submissions, reviews, editorial decisions, security, or platform administration are not marketing communications and may still be sent where necessary for the operation of the journal.

7. Recipients of Personal Data

We may share personal data, strictly on a need-to-know basis, with the following categories of recipients:

  • editorial staff, editors, guest editors, and authorised journal administrators;
  • reviewers, where necessary for peer review workflows;
  • authors and co-authors, where necessary within submission and publication processes;
  • hosting providers, IT service providers, email delivery providers, backup providers, and other processors supporting the journal platform;
  • indexing, abstracting, archiving, DOI registration, plagiarism screening, preservation, and scholarly infrastructure services, where applicable;
  • professional advisers, auditors, insurers, or legal representatives where necessary;
  • regulators, law enforcement agencies, courts, or other public authorities where required by law or where necessary to protect legal rights.

We do not sell your personal data.

8. International Transfers

Your personal data may be processed in the United Kingdom, the European Economic Area, or in other countries where our service providers, journal participants, or scholarly infrastructure partners operate.

Where personal data is transferred outside the UK or EEA, we will take appropriate steps to ensure that such transfers are made in accordance with applicable data protection law, including by relying on adequacy regulations/decisions, standard contractual clauses, or other lawful safeguards where required.

9. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Statement, including to maintain the scholarly record, support editorial transparency, comply with legal and ethical obligations, resolve disputes, and enforce agreements.

In practice:

  • account and editorial workflow records may be retained for as long as the journal account remains active and for a reasonable period thereafter;
  • submission, peer review, and publication records may be retained long term where necessary to maintain the integrity of the academic record and editorial history;
  • optional communication preferences are retained until you unsubscribe or request deletion, subject to any overriding record-keeping requirements;
  • technical logs are typically retained for a limited security and operational period.

Where a precise retention period is not possible, we determine retention by reference to the nature of the data, the purpose of processing, legal obligations, dispute risk, and the need to preserve the scholarly and publishing record.

10. Your Rights

Subject to applicable law, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of your personal data in certain circumstances;
  • request restriction of processing in certain circumstances;
  • object to processing based on legitimate interests;
  • request data portability where applicable;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with a supervisory authority.

These rights are not absolute and may be subject to legal or ethical limitations, including where retention is necessary for the integrity of the scholarly record, compliance with publishing obligations, or the establishment, exercise, or defence of legal claims.

To exercise your rights, please contact: editorial@informaticsfoundry.org

11. Complaints

If you are located in the United Kingdom, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
If you are located in the European Economic Area, you may also lodge a complaint with your local data protection supervisory authority.

We would, however, appreciate the opportunity to address your concerns first.

12. Security

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, password protection, role-based permissions, secure hosting arrangements, logging, and backup procedures.

However, no internet-based system can be guaranteed to be completely secure, and you should also take reasonable steps to protect your account credentials.

13. Cookies and Similar Technologies

This site may use cookies or similar technologies that are necessary for site functionality, login sessions, security, preferences, and analytics.

Where required by law, non-essential cookies will only be used with your consent. Further details should be provided in the site’s Cookie Notice or Cookie Settings page.

14. Third-Party Links and Services

This journal site may contain links to third-party websites or integrate third-party scholarly services. We are not responsible for the privacy practices of third-party sites or services, and you should review their privacy notices separately.

15. Publication of Personal Information in the Scholarly Record

Where a manuscript is accepted for publication, personal data forming part of the scholarly record may be published, including author names, affiliations, correspondence details where designated, funding information, acknowledgements, ORCID iDs where supplied, and other metadata relevant to publication and indexing.

Because the publication record serves academic, citation, and archival purposes, removal or alteration of published information may not always be possible except in accordance with editorial policies, legal requirements, and correction or retraction procedures.

16. Children

This journal site is intended for academic, professional, and scholarly use and is not directed to children. We do not knowingly collect personal data from children through this site.

17. Changes to this Privacy Statement

We may update this Privacy Statement from time to time to reflect legal, technical, or operational changes. Any updated version will be posted on this page with a revised “Last updated” date.