Privacy Policy and Statement

Last updated: 19 July 2026

This Privacy Policy explains what personal data we collect through the International Journal of Disaster Risk Management (IJDRM) website, why we collect it, how it is used within the editorial and publishing workflow, with whom it may be shared, how long it is retained, and what choices and rights you have in relation to your personal data.

This Policy is interpreted in accordance with the applicable data-protection legislation of the Republic of Serbia and, where applicable, the General Data Protection Regulation (EU) 2016/679 (GDPR).

1. Journal and Publisher (Data Controller)

Data Controller: Scientific-Professional Society for Disaster Risk Management (SPS-DRM), publisher of the International Journal of Disaster Risk Management (IJDRM)

Journal: International Journal of Disaster Risk Management (IJDRM)

Publisher: Scientific-Professional Society for Disaster Risk Management (SPS-DRM)

Address: Dimitrija Tucovića 121, Belgrade, Serbia

Privacy contact: office@ijdrm.com; editor@ijdrm.com

Editorial contact: Prof. Dr. Vladimir M. Cvetković, Editor-in-Chief

For any questions, requests or concerns regarding personal data processing, please contact us using the email addresses above.

2. What This Policy Covers

This Policy applies to:

  • Visitors who browse the journal website;
  • Users who create accounts, including authors, reviewers, editors and readers;
  • Individuals whose personal data are entered into the system by another person, such as co-authors or suggested reviewers;
  • All stages of manuscript submission, peer review, editorial handling, production, publication, correction, retraction and preservation of the scholarly record;
  • Communications conducted through the journal platform or by email in connection with journal activities.

3. What Personal Data We Collect

Depending on your interaction with the journal, we may process the following categories of personal data.

A. Registration and Profile Information

  • Full name;
  • Email address;
  • Affiliation, department, institution and country;
  • Mailing address, where required;
  • ORCID iD, where provided;
  • Username, password credentials and account preferences;
  • Academic title, areas of expertise, reviewing interests and other professional information voluntarily provided by the user.

Passwords are stored and managed through the journal platform’s security mechanisms and are not accessible to the public.

B. Submission and Peer-Review Information

  • Manuscript files and supplementary materials, including figures, tables, appendices, datasets and related documentation;
  • Article metadata, including title, abstract, keywords, references and author details;
  • Cover letters, declarations, authorship information, funding information and conflict-of-interest statements;
  • Editorial correspondence exchanged through the platform or by email;
  • Review reports, editorial recommendations, decision records, revision history and responses to reviewers;
  • Information relating to corrections, complaints, appeals, suspected misconduct or research-integrity investigations.

Authors should not include unnecessary directly identifiable, confidential or sensitive personal data relating to research participants in manuscripts, supplementary files or datasets. Authors are responsible for ensuring that research data submitted to the journal have been collected, anonymized, shared and processed lawfully and in accordance with applicable ethical standards.

C. Technical and Security-Related Information

  • IP address;
  • Browser type, device type and basic technical information;
  • Date and time of access;
  • Server and system log data;
  • Session information;
  • Cookies necessary for login, authentication, secure navigation and platform functionality;
  • Information required to detect, investigate and prevent security incidents, misuse, fraud or unauthorized access.

D. APC-Related Administrative Data

Where an Article Processing Charge (APC) applies, we may process limited information required for administrative, accounting and payment-confirmation purposes, including:

  • Author or payer name;
  • Affiliation and billing address;
  • Invoice details;
  • Institutional or tax-related information, where required;
  • Payment confirmation, date and status;
  • Correspondence concerning invoicing, discounts or waivers.

IJDRM does not store payment-card details. Payments are processed by banks, PayPal or other third-party payment providers under their own terms and privacy policies.

E. Personal Data Received from Other Sources

A corresponding or submitting author may provide the names, email addresses, affiliations, countries and ORCID iDs of co-authors. Reviewer and editor contact details may also be obtained from institutional websites, public scholarly profiles, bibliographic databases or recommendations provided during the editorial process.

Where personal data are provided by another person, they are used only for legitimate editorial, peer-review, publication and research-integrity purposes. Corresponding authors are expected to inform their co-authors that their personal data have been submitted to the journal and will be processed in accordance with this Privacy Policy.

4. Why We Use Personal Data

We process personal data in order to:

  • Create and manage user accounts;
  • Receive and process manuscript submissions;
  • Verify authorship, affiliations and contributor information;
  • Select and invite qualified reviewers;
  • Organize and conduct peer review;
  • Make, document and communicate editorial decisions;
  • Process manuscript revisions and responses to reviewers;
  • Prepare accepted manuscripts for publication;
  • Register Digital Object Identifiers (DOIs);
  • Disseminate article metadata to scholarly databases and infrastructure services;
  • Maintain the accuracy, integrity and permanence of the published scholarly record;
  • Process corrections, expressions of concern, retractions, complaints and appeals;
  • Investigate suspected plagiarism, duplicate publication, authorship disputes or other forms of research misconduct;
  • Manage APC invoicing, discounts, waivers and payment confirmations, where applicable;
  • Protect the journal website and editorial platform against misuse, unauthorized access, fraud and security threats;
  • Maintain backups and ensure business continuity;
  • Produce aggregated operational statistics to evaluate and improve editorial workflows and journal services;
  • Comply with applicable legal, accounting, regulatory and ethical obligations.

5. Legal Grounds for Processing

Where applicable data-protection laws require a legal basis, we rely on one or more of the following grounds.

A. Steps Taken at Your Request and Performance of Publishing Services

We process personal data when necessary to create an account, receive and evaluate a manuscript, conduct peer review, communicate editorial decisions, publish accepted content and provide related editorial and publishing services requested by users.

B. Legitimate Interests

We process personal data where necessary for the legitimate interests of the journal, the publisher, authors, reviewers and the scholarly community.

These legitimate interests include:

  • Administering scholarly peer review;
  • Ensuring publication quality;
  • Selecting suitable reviewers and editors;
  • Protecting editorial independence;
  • Maintaining publication ethics and research integrity;
  • Investigating potential misconduct;
  • Preventing fraud and misuse;
  • Protecting the security of the OJS platform;
  • Maintaining reliable editorial records;
  • Preserving the integrity and permanence of the scholarly record;
  • Improving journal operations and services.

Where processing is based on legitimate interests, we consider the interests, rights and reasonable expectations of the individuals concerned.

C. Consent

We rely on consent where it is required, including for optional communications, newsletters or non-essential cookies and tracking technologies.

Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

D. Legal Obligations

We process personal data where necessary to comply with applicable legal, accounting, tax, regulatory or other binding obligations, including the retention of invoices and financial documentation.

Certain personal data are necessary to create an account, submit or review a manuscript, communicate editorial decisions or publish an accepted article. If the required data are not provided, the journal may be unable to provide the requested editorial or publishing service.

6. Who Can Access Personal Data and When We Share It

IJDRM does not sell, rent or trade personal data.

Personal data may be accessed by:

  • Authorized members of the editorial office;
  • The Editor-in-Chief, editors and editorial assistants responsible for handling the submission;
  • Reviewers, to the extent necessary to conduct peer review;
  • Copyeditors, proofreaders, layout editors and production personnel involved in preparing accepted manuscripts for publication;
  • Authorized technical personnel responsible for hosting, system administration, maintenance, security, backups and email delivery;
  • Payment, accounting or administrative service providers, where applicable.

Depending on the relevant workflow, recipients may include:

  • OJS hosting and technical-support providers;
  • Email, backup and cybersecurity providers;
  • Plagiarism-detection and similarity-checking services;
  • Payment and accounting providers;
  • DOI registration agencies, including Crossref;
  • Digital preservation and archiving services;
  • Indexing and abstracting databases;
  • Libraries, repositories and scholarly discovery services;
  • Competent public authorities where disclosure is required by law.

For accepted and published articles, author names, affiliations, ORCID iDs, correspondence details where designated for publication, and article metadata become part of the public scholarly record. These data may be distributed to Crossref, indexing databases, libraries, repositories, archiving services and other scholarly communication platforms.

IJDRM operates a double-blind peer-review process. Reviewers ordinarily receive anonymized manuscript files and do not receive author identities. Author or reviewer identities may be disclosed only where necessary, authorized by the individuals concerned, permitted by journal policy or required for research-integrity or legal purposes.

Technical and professional service providers are permitted to process personal data only to the extent necessary to provide the relevant service and are expected to apply appropriate confidentiality and security safeguards.

We share only the personal data reasonably necessary for the relevant editorial, technical, administrative or publishing purpose.

7. International Data Transfers

Some service providers and scholarly infrastructure services used by the journal may process personal data outside Serbia or outside the country in which the data subject is located.

Where applicable data-protection law requires safeguards for an international transfer, we rely on appropriate mechanisms such as adequacy decisions, contractual data-protection clauses or other legally recognized safeguards.

Information about the safeguards applicable to a particular transfer may be requested using the contact details provided in this Policy.

8. How Long We Keep Personal Data

We retain personal data only for as long as necessary for editorial, publishing, administrative, security, legal and scholarly-record purposes.

In particular:

  • Published article metadata and information necessary to preserve the version of record may be retained permanently as part of the public scholarly record;
  • Submission, peer-review and editorial decision records may be retained for extended periods to preserve editorial accountability, address complaints or appeals, investigate potential misconduct and protect the integrity of the scholarly record;
  • Account information is retained while the account remains active or while it remains connected to editorial, reviewing or publication records that the journal must preserve;
  • Financial records, invoices and payment confirmations are retained for the period required by applicable accounting and tax laws;
  • Technical and security logs are retained only for as long as reasonably necessary for platform operation, troubleshooting, security monitoring and incident investigation;
  • Records connected with complaints, appeals, corrections, expressions of concern, retractions or misconduct investigations may be retained for as long as necessary to document the journal’s actions and decisions.

Retention periods are determined according to the status of the submission, applicable legal and accounting requirements, the need to address disputes or allegations of misconduct, system-security requirements, and the journal’s responsibility to preserve the published scholarly record.

When personal data are no longer necessary for these purposes, they will be securely deleted or anonymized, where technically and legally possible.

9. Cookies and Similar Technologies

The journal website uses cookies primarily to provide essential functionality, including:

  • Maintaining login sessions;
  • Authenticating registered users;
  • Enabling secure navigation;
  • Saving basic preferences;
  • Protecting the website and editorial platform from misuse.

Essential cookies are necessary for the website and OJS platform to function properly. Disabling them in browser settings may prevent users from logging in or using certain website functions.

If IJDRM introduces analytics, embedded third-party content, social-media tracking or other non-essential technologies, the journal will provide appropriate information and, where required by law, request user consent before activating those technologies.

10. Your Rights

Subject to applicable law, you may have the right to:

  • Request confirmation of whether we process your personal data;
  • Request access to your personal data;
  • Request correction of inaccurate or incomplete personal data;
  • Request deletion of personal data in certain circumstances;
  • Request restriction of processing in certain circumstances;
  • Object to processing based on legitimate interests;
  • Withdraw consent where processing is based on consent;
  • Request data portability, where applicable;
  • Lodge a complaint with a competent supervisory authority.

These rights are not absolute and may be limited where continued processing or retention is necessary to:

  • Protect the integrity of the scholarly record;
  • Preserve editorial decisions and peer-review history;
  • Establish, exercise or defend legal claims;
  • Investigate publication misconduct;
  • Comply with legal, accounting or regulatory obligations;
  • Protect the rights and freedoms of other individuals.

Complete deletion may not be possible for records that must be preserved to protect editorial accountability and the scholarly record. Where deletion is not possible, we will consider reasonable data-minimization, anonymization or processing-restriction measures.

We may request additional information necessary to verify the identity of the person submitting a request. We will respond without undue delay and normally within one month, subject to any extension permitted by applicable law.

To exercise your rights, please contact:

office@ijdrm.com
editor@ijdrm.com

You also have the right to lodge a complaint with the competent supervisory authority in Serbia:

Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia
Website: https://www.poverenik.rs/en/

Where the GDPR applies, you may also lodge a complaint with the competent supervisory authority in the European Economic Area country of your habitual residence, place of work or place of the alleged infringement.

11. Automated Decision-Making and Profiling

IJDRM does not make manuscript acceptance or rejection decisions solely through automated processing and does not use profiling to make decisions that produce legal or similarly significant effects concerning users.

Plagiarism-detection, similarity-checking, artificial-intelligence or other automated tools may support administrative, technical or editorial assessment. However, such tools do not replace qualified human judgment, and final editorial decisions are made by the Editor-in-Chief or authorized editors.

12. Data Security and Personal Data Breaches

We apply reasonable technical and organizational safeguards to protect the confidentiality, availability and integrity of personal data.

These safeguards include controlled access to the editorial platform, role-based user permissions, password-protected accounts, regular backups, system maintenance and standard security practices.

Access to confidential manuscript files, review reports, editorial correspondence and decision records is limited to individuals who require such access for legitimate editorial, technical or administrative purposes.

Despite these measures, no online system can guarantee absolute security.

In the event of a suspected personal data breach, the journal will investigate and document the incident, take appropriate measures to contain and mitigate its effects, and notify the competent supervisory authority and affected individuals where required by applicable law.

13. Children

The journal website and its editorial services are intended for academic, research and professional users.

IJDRM does not knowingly collect personal data from children through account registration or ordinary editorial activities. If we become aware that personal data have been collected from a child without an appropriate legal basis or authorization, we will take reasonable steps to delete or restrict those data.

14. Updates to This Policy

We may revise this Privacy Policy to reflect changes in journal practices, technology, service providers, legal requirements or applicable data-protection standards.

The updated version will be published on the journal website with a revised “Last updated” date. Where changes materially affect the way personal data are processed, we may provide additional notice through the journal website, OJS platform or registered user email addresses, where appropriate.

15. Contact

Data Controller

Scientific-Professional Society for Disaster Risk Management (SPS-DRM)
Publisher of the International Journal of Disaster Risk Management (IJDRM)
Dimitrija Tucovića 121
Belgrade, Serbia
Email: office@ijdrm.com; editor@ijdrm.com

Editorial Contact

Prof. Dr. Vladimir M. Cvetković
Editor-in-Chief
International Journal of Disaster Risk Management (IJDRM)
Email: editor@ijdrm.com