Processing
Data we process and why
Published articles
An accepted article is published with the names and affiliations of its authors and, where an author supplied one, a contact email address, as the scholarly record requires. The same names and affiliations go into the article's metadata and its DOI registration with Crossref. The basis is the publishing agreement, Article 6(1)(b) GDPR, and the journal's legitimate interest in an attributable record, Article 6(1)(f).
Technical access data
When pages are requested, technical logs may contain the requested page, referrer URL, date and time, transferred data volume, and user agent. They do not contain visitor IP addresses; the section on server access logs below sets out exactly what is recorded. Processing serves the efficient and secure delivery of the website and is based on the publisher's legitimate interests under Article 6(1)(f) GDPR.
Contact and correspondence
If you write to the publisher at contact@banachpress.com or to the editorial office at submissions@banachpress.com, the information you provide is used to answer your request and any follow-up questions. Depending on the request, the basis is Article 6(1)(b), Article 6(1)(f), or, where requested, consent under Article 6(1)(a) GDPR.
Hosting
The site is delivered through Amazon Web Services, using Amazon S3 for storage and Amazon CloudFront for distribution, which may process technical connection data on behalf of the site operator. Content is stored in the Frankfurt region (eu-central-1) and served from CloudFront edge locations, so data may be processed outside the country of collection. AWS describes safeguards including the European Commission's Standard Contractual Clauses. Read the AWS privacy notice and GDPR information.
Manuscript submission and peer review
Manuscripts are submitted and reviewed through Open Journal Systems (OJS) at ojs.journalofconvexanalysis.com, a separate system from this website. To submit, an author creates an account there, giving a name, affiliation, country, email address, username and password, and then uploads the manuscript together with the names, affiliations and email addresses of all co-authors and the declarations the journal asks for. Editors and reviewers hold accounts in the same system, and the reviewers' reports, the editorial decisions and the correspondence about each manuscript are kept there.
This information is used to conduct peer review, reach an editorial decision and prepare an accepted article for publication. For the submitting author the basis is Article 6(1)(b) GDPR, since submission is the first step towards a publishing agreement; for co-authors, reviewers and editors it is Article 6(1)(f), the journal's legitimate interest in conducting peer review.
The submission system is hosted for the publisher by the Public Knowledge Project (PKP) of Simon Fraser University, Canada, on servers in Canada. PKP acts on the publisher's instructions under its hosting terms; see the PKP Publishing Services privacy policy. Canada is covered by a European Commission adequacy decision. The system sets a session cookie on every visit, which is needed to sign in and stay signed in, keeps its own technical logs on PKP's servers, and protects its registration form with Google reCAPTCHA, which loads a script from Google and sends Google technical data about the browser. Notifications from the system are sent from PKP's mail server.
An account remains until its holder asks for it to be closed. The record of a submission, including the decision and the reviewers' reports, is kept as the record of the peer-review process.
Article processing charges and payment
When a manuscript is accepted, the publisher collects an article processing charge. Payment is handled by Stripe, a payment provider established in the United States. The editorial office issues an invoice through Stripe, prepared from the name, email address and billing address of the author or of the institution paying on the author's behalf, together with the institution's VAT number and purchase order number where it gives them. The invoice arrives by email with a payment page hosted by Stripe, where the payer enters card or wallet details or receives the bank details for a transfer. Card and wallet details are entered on Stripe's page and go to Stripe, never to the publisher. The publisher sees the payer's name, contact and billing details, the amount, the payment method with the last four digits of a card, and whether the payment has cleared.
Stripe processes the payment on the publisher's instructions. It also uses transaction and device data from its payment page, including the IP address and cookies of its own, to prevent fraud and to meet its own legal obligations, and for those purposes it acts as an independent controller; see the Stripe privacy policy. The basis for the publisher's processing is the publishing agreement, Article 6(1)(b) GDPR. Invoices and payment records are kept for as long as the accounting and tax law that applies to the publisher requires.
Disclosure and retention
Personal data is disclosed to the people and services named on this page and to no one else unless the law permits or requires it: to Amazon Web Services, PKP and Stripe as processors acting on the publisher's instructions; to the journal's editors and reviewers for peer review; and to Crossref, in the form of published article metadata, for DOI registration. Data is deleted when it is no longer required for its purpose. Where a statutory retention duty applies to the publisher, deletion is deferred until that period ends and processing is meanwhile restricted to the required purpose.
Server access logs
The content delivery network records a technical log entry for each request. These entries contain the requested address, the date and time, the response status, the volume of data transferred, the browser's user agent and referring page, the edge location that served the request, and the autonomous system number of the network the request came from. That number identifies a network operator, such as a university or an internet provider, and is recorded so that automated crawling can be told apart from reading. It does not identify a person or a household.
Visitor IP addresses are not recorded. The log format is configured to omit them, along with the client port and any forwarded-for header, so the entries do not identify individual visitors. Logs are stored in encrypted, non-public storage and are deleted automatically after 90 days by a retention rule; they are used only to operate and secure the website and are not combined with any other data.
Cookies and analytics
This website itself sets no cookies, stores nothing in the browser, and loads no scripts, fonts or other resources from third-party servers. It contains no advertising trackers, no analytics and no online contact form; contact is initiated through the visitor's own email application. The submission system and the payment pages run on their own addresses, operated by PKP and Stripe, and set only the cookies they need to keep you signed in and to prevent fraud, as described above. Neither carries advertising trackers.