Purpose
The policy sets out the principles that guide our handling of data across editorial, research, and platform operations.
Scope
It applies to all data processed by TICH, including reader account information, contributor records, editorial correspondence, and operational logs.
Core principles
- Data minimization: collect only what is needed for a specific purpose.
- Purpose limitation: use data for the purpose it was collected for, and not for unrelated activities.
- Accuracy: maintain reasonable steps to keep records accurate and up to date.
- Storage limitation: retain data only as long as necessary.
- Integrity and confidentiality: apply reasonable safeguards against unauthorized access, loss, or alteration.
- Accountability: assign responsibility for data handling within the editorial and technical teams.
Categories of data
- Reader and subscriber data (contact details, preferences).
- Contributor data (affiliations, ORCID where provided, manuscript records).
- Operational data (server logs, anonymized analytics, error reports).
We do not collect sensitive health information from readers as part of normal site operation. Any research-related data is handled under additional ethics requirements described in the Research Ethics and Compliance policy.
Security practices
We apply standard technical and organizational measures, including access controls, encrypted transport, and routine review of permissions. We do not claim absolute security and do not make guarantees beyond what is reasonable for a platform of our type.
Sharing and processors
We engage a limited set of service providers (for example, hosting, email, and analytics) that act as data processors under contractual obligations. We do not sell personal data or share it for advertising profiling.
Incident handling
If a data incident occurs that materially affects users, we will take reasonable steps to investigate, contain, and communicate the issue in line with applicable obligations.
Responsibility
Day-to-day responsibility for data protection sits with the TICH operations team, with editorial responsibilities clearly separated from administrative ones. Concerns can be raised through the contact page.