Personal Data Processing Policy

  • Version 1.0
  • Approved on 9 September 2026
  • Art. 18.1(2) of Federal Law No. 152-FZ
This translation is provided for convenience. In case of discrepancy, the Russian version prevails.
Перевод предоставлен для удобства; приоритет имеет русская версия.

This Personal Data Processing Policy (the “Policy”) defines the procedure and conditions for the processing of personal data by the Limited Liability Company “Academic Publishing House” (the “Operator”) and sets out information on the personal data protection requirements that the Operator implements.

The Policy has been adopted pursuant to clause 2 of part 1 of Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (“152-FZ”) and is published in accordance with part 2 of Article 18.1 of 152-FZ — by providing unrestricted access to its text on the website econferences.ru.

Operator: Limited Liability Company “Academic Publishing House” (ООО «Академический издательский дом»).

PSRN (ОГРН): [уточняется] · TIN (ИНН): [уточняется]

Registered address: [уточняется]

E-mail address for requests from data subjects: info@econferences.ru

1. General provisions and definitions

1.1. The Policy applies to all personal data that the Operator receives from data subjects in connection with the operation of the website econferences.ru (the “Website”), the organisation and holding of academic conferences, and the receipt, peer review and publication of academic materials.

1.2. The terms “personal data”, “processing of personal data”, “operator”, “data subject”, “dissemination”, “provision”, “blocking”, “destruction”, “anonymisation” and “cross-border transfer of personal data” are used with the meanings assigned to them by Article 3 of 152-FZ.

1.3. The Operator processes personal data on a lawful and fair basis, limits processing to the achievement of specific, pre-defined and lawful purposes, and does not merge databases containing personal data processed for purposes that are incompatible with one another (Article 5 of 152-FZ).

1.4. The Operator does not process special categories of personal data (Article 10 of 152-FZ) or biometric personal data (Article 11 of 152-FZ). The Operator does not process the personal data of minors under 14 years of age.

1.5. The Operator does not take decisions producing legal effects concerning a data subject or otherwise affecting his or her rights and legitimate interests solely on the basis of automated processing of personal data (Article 16 of 152-FZ).

2. Legal grounds for processing

2.1. The legal grounds for the processing of personal data are:

  • the consent of the data subject to the processing of his or her personal data — clause 1 of part 1 of Article 6 of 152-FZ (for the purposes set out in sub-clauses (i), (iii), (iv) and (v) of clause 3.1 of this Policy);
  • the necessity of processing for the performance of a contract to which the data subject is a party, beneficiary or guarantor, as well as for the conclusion of a contract at the initiative of the data subject — clause 5 of part 1 of Article 6 of 152-FZ (for the purpose set out in sub-clause (ii) of clause 3.1);
  • the consent of the data subject to the processing of personal data permitted by the data subject for dissemination — Article 10.1 of 152-FZ (for the purpose set out in sub-clause (iii) of clause 3.1, as regards making data publicly available);
  • the necessity of performing obligations imposed on the Operator by the legislation of the Russian Federation on accounting and on taxes and levies — clause 2 of part 1 of Article 6 of 152-FZ.

2.2. Further legal grounds for processing are: the Constitution of the Russian Federation; the Civil Code of the Russian Federation; 152-FZ; Federal Law No. 149-FZ of 27 July 2006 “On Information, Information Technologies and Protection of Information”; the charter of the Operator; contracts concluded between the Operator and data subjects; and the consents given by data subjects.

3. Purposes of processing

3.1. The Operator processes personal data separately for each of the following purposes:

Table 1. Purposes of processing, categories of data subjects and data processed
No.Purpose of processing Categories of data subjectsList of personal data
(i) Receipt of materials for consideration and organisation of their peer review (including plagiarism screening and academic review) Authors, co-authors Surname, given name, patronymic; e-mail address; telephone number; country; organisation (affiliation); position; academic degree and/or academic title; ORCID identifier; the content of correspondence with the Operator
(ii) Conclusion and performance of the contract on participation in a conference and publication of materials (including invoicing, receipt of the organisational fee and accounting) Authors, co-authors, conference participants, payers Surname, given name, patronymic; e-mail address; telephone number; country; organisation (affiliation); payment details (amount, date, payment purpose, payer details to the extent reflected in the payment document)
(iii) Publication of accepted materials in open access, including the compilation of publication metadata, assignment of a DOI, archiving and transfer of metadata to indexing services Authors, co-authors Surname, given name, patronymic (including in transliteration); organisation (affiliation); country; position, academic degree and/or academic title; ORCID identifier; e-mail address — only where the author has given a separate permission (see section 10)
(iv) Sending informational messages on the status of a submission and the progress of the services (notifications of receipt of a material, review results, an issued invoice, publication, and DOI assignment) Authors, co-authors, conference participants Surname, given name, patronymic; e-mail address; telephone number
(v) Compilation of anonymised Website traffic statistics and maintenance of the technical operability of the Website Website visitors IP address; country and region determined from the IP address; session cookie data (session identifier); browser type and version; operating system; date and time of access; address of the requested page

3.2. The Operator does not use personal data for purposes other than those listed in clause 3.1 and does not process personal data that is excessive in relation to the stated purposes (part 5 of Article 5 of 152-FZ).

3.3. The Operator does not send advertising messages and does not transfer personal data to third parties for marketing purposes.

4. Categories of data subjects

4.1. The Operator processes the personal data of the following categories of data subjects:

  • authors — persons who have submitted materials to the Operator for consideration and publication;
  • co-authors — persons named by an author as co-authors of the submitted materials;
  • conference participants — persons who have applied to take part in academic conferences organised by the Operator;
  • Website visitors — persons accessing the Website, in respect of the data listed in sub-clause (v) of clause 3.1.

4.2. The personal data of co-authors is provided to the Operator by the submitting author. By submitting a material, the author confirms that he or she has obtained the consent of each co-author to the transfer of that co-author’s personal data to the Operator and to its processing for the purposes set out in clause 3.1, and undertakes to bring the content of this Policy to the attention of the co-authors. The Operator may send a co-author a notice of the processing of his or her personal data to the e-mail address indicated by the author.

5. Procedure and methods of processing

5.1. Personal data is processed by automated and mixed means — using computing facilities and without the use of such facilities.

5.2. The Operator performs the following actions with personal data: collection, recording, systematisation, accumulation, storage, updating (renewal, alteration), retrieval, use, transfer (provision, access, dissemination — solely to the extent and on the terms set out in section 10 of this Policy), anonymisation, blocking, deletion and destruction.

5.3. Personal data is collected by the following means:

  • through the registration and submission forms on the Website (Open Journal Systems platform);
  • by electronic mail at the address info@econferences.ru and other addresses in the econferences.ru domain;
  • from the text of the materials submitted by the author (author details set out in the material itself);
  • automatically upon access to the Website — to the extent set out in sub-clause (v) of clause 3.1.

5.4. The Operator does not collect personal data from publicly available sources and does not acquire personal data databases from third parties.

6. Localisation of databases within the Russian Federation

6.1. In accordance with part 5 of Article 18 of 152-FZ, when collecting personal data, including through the information and telecommunications network “Internet”, the Operator ensures the recording, systematisation, accumulation, storage, updating (renewal, alteration) and retrieval of the personal data of citizens of the Russian Federation using databases located within the territory of the Russian Federation.

6.2. The technical facilities for processing and storing the databases are located on the servers of the hosting provider OOO “Beget” (Russian Federation, data centre in St. Petersburg). The Operator does not use any other databases containing the personal data of citizens of the Russian Federation for primary collection.

6.3. The transfer of certain information outside the Russian Federation takes place exclusively after primary collection and recording in databases located within the territory of the Russian Federation, to the extent and on the terms set out in sections 7 and 8 of this Policy.

7. Transfer of personal data to third parties

7.1. The Operator transfers personal data to the following third parties to the extent necessary to achieve the purposes set out in clause 3.1:

Table 2. Recipients of personal data
RecipientJurisdiction Data transferredPurpose and legal ground
OOO “Beget” (hosting provider)Russian Federation All data held in the Operator’s information system — by virtue of the technical nature of the hosting services Maintaining the operability of the Website; processing on behalf of the Operator (part 3 of Article 6 of 152-FZ) under a contract containing confidentiality and security obligations
Crossref (Publishers International Linking Association, Inc.)USA Publication metadata: author’s surname, given name and patronymic, organisation (affiliation), ORCID identifier, title of the material, publication details Registration and deposit of DOIs; performance of the contract (clause 5 of part 1 of Article 6 of 152-FZ) and consent to dissemination (Article 10.1 of 152-FZ)
Zenodo (European Organization for Nuclear Research, CERN)Switzerland Publication metadata and the full text of the published material Long-term archiving of published materials; performance of the contract and consent to dissemination
OpenAIRE AMKEEuropean Union (Greece) Publication metadata harvested via the OAI-PMH protocol Aggregation of metadata of open-access academic publications; consent to dissemination
Google LLC (Google Scholar)USA Publication metadata made publicly available on the Website and the full text of the published material Indexing of published materials in an academic search engine; consent to dissemination
Acquiring bank / servicing bankRussian Federation Payer’s surname, given name and patronymic, payment purpose and amount — to the extent provided for by the payment documents Settlements under the contract on participation and publication; performance of the contract (clause 5 of part 1 of Article 6 of 152-FZ) and the requirements of the legislation on the national payment system

7.2. Personal data may be provided to state authorities, local self-government bodies and other authorised bodies in the cases and in the manner established by the legislation of the Russian Federation.

7.3. The Operator does not transfer personal data to third parties beyond the scope set out in clause 7.1 and does not sell personal data.

8. Cross-border transfer of personal data

8.1. The Operator carries out cross-border transfers of personal data to the following foreign states:

  • the Swiss Confederation (Zenodo / CERN) — a state party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), which provides adequate protection of the rights of data subjects (part 1 of Article 12 of 152-FZ);
  • the Hellenic Republic and other member states of the European Union (OpenAIRE AMKE) — states party to Convention ETS No. 108;
  • the United States of America (Crossref, Google LLC) — a state that does not provide adequate protection of the rights of data subjects. The transfer is carried out in the manner prescribed by part 4 of Article 12 of 152-FZ.

8.2. Before commencing any cross-border transfer of personal data, the Operator submits to the authorised body for the protection of the rights of data subjects (Roskomnadzor) a notification of its intention to carry out cross-border transfers of personal data (part 4 of Article 12 of 152-FZ).

8.3. Only the metadata of a published material and the full text of a published material — that is, information that by the very nature of the service provided is to be disclosed to an unlimited group of persons — is transferred to states that do not provide adequate protection of the rights of data subjects. Such transfer is carried out for the purpose of performing a contract to which the data subject is a party (clause 3 of part 4 of Article 12 of 152-FZ) and on the basis of the data subject’s consent in written form to the cross-border transfer of his or her personal data (clause 1 of part 4 of Article 12 of 152-FZ), executed in accordance with the Consent to Personal Data Processing.

8.4. Information that is not subject to disclosure (telephone number, payment details, the content of correspondence) is not transferred across borders.

9. Processing and storage periods

9.1. Personal data is processed until the purposes of processing have been achieved or until the need to achieve them has ceased, unless a different period is established by the legislation of the Russian Federation or by contract.

Table 3. Storage periods by category of data
Category of dataStorage period
User account on the Website and related information Until the account is deleted at the request of the data subject or until consent is withdrawn. In the absence of any request from the data subject — for the entire period during which the account exists
Information relating to the conclusion and performance of the contract on participation and publication (invoices, payment documents, primary accounting records) 5 (five) years — in accordance with part 1 of Article 29 of Federal Law No. 402-FZ of 6 December 2011 “On Accounting” and sub-clause 8 of clause 1 of Article 23 of the Tax Code of the Russian Federation, calculated from the year following the year in which settlements were completed
Metadata of published materials and the full text of published materials Indefinitely — as an integral part of the scholarly record. A published material forms part of academic discourse, is subject to permanent retention and citation, and information on authorship cannot be deleted without distorting the scholarly record
Materials rejected following consideration or withdrawn by the author before publication 1 (one) year from the date of the decision — for the purpose of resolving possible disputes, after which they are destroyed
Website access data (server logs, the data listed in sub-clause (v) of clause 3.1) No more than 12 (twelve) months, after which the data is anonymised or destroyed
Requests from data subjects and the related correspondence 3 (three) years from the date of the last request

9.2. Once the purposes of processing have been achieved, or if the need to achieve them has ceased, personal data is destroyed or anonymised within a period not exceeding 30 (thirty) days (part 4 of Article 21 of 152-FZ), unless otherwise provided by contract or by the legislation of the Russian Federation.

9.3. The destruction of personal data is confirmed by an act on the destruction of personal data and/or by an extract from the event log of the personal data information system, in the manner established by Roskomnadzor Order No. 179 of 28 October 2022.

10. Publication of materials and dissemination of personal data

10.1. The publication of an accepted material in open access entails the dissemination of the personal data of the author and co-authors — surname, given name and patronymic, organisation (affiliation), country and (where provided) the ORCID identifier. Such dissemination is carried out solely on the basis of a separate consent to the processing of personal data permitted by the data subject for dissemination, executed in accordance with Article 10.1 of 152-FZ and Roskomnadzor Order No. 18 of 24 February 2021 (see the page Consent to Dissemination).

10.2. The author is entitled to impose prohibitions on the dissemination of individual categories of personal data, as well as conditions for their dissemination (parts 9 and 10 of Article 10.1 of 152-FZ). The e-mail address and the ORCID identifier are published only where the author has given express permission.

10.3. Under no circumstances may the silence or inaction of a data subject be deemed to constitute consent to the processing of personal data permitted for dissemination (part 8 of Article 10.1 of 152-FZ).

10.4. A data subject is entitled at any time to require the Operator to cease the transfer (dissemination, provision, access) of his or her personal data (part 12 of Article 10.1 of 152-FZ). The procedure for, and the actual limits of, complying with such a requirement — including the limitations arising from dissemination already carried out under an open licence — are set out on the page Consent to Dissemination.

11. Rights of the data subject

11.1. A data subject has the right to obtain the information provided for by part 7 of Article 14 of 152-FZ, namely:

  • confirmation of the fact that personal data is processed by the Operator;
  • the legal grounds and purposes of the processing of personal data;
  • the purposes and methods of processing applied by the Operator;
  • the name and location of the Operator, information on persons (other than the Operator’s employees) who have access to the personal data or to whom the personal data may be disclosed;
  • the personal data processed that relates to the data subject and the source from which it was obtained;
  • the periods of processing of personal data, including the periods of storage;
  • the procedure for the exercise by the data subject of the rights provided for by 152-FZ;
  • information on cross-border transfers of data that have been carried out or are contemplated;
  • the name or the surname, given name and patronymic and the address of the person processing personal data on behalf of the Operator;
  • other information provided for by 152-FZ or other federal laws.

11.2. A data subject is entitled to require the Operator to rectify his or her personal data, to block it or to destroy it where the personal data is incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and to take the measures provided for by law to protect his or her rights (part 1 of Article 14 of 152-FZ).

11.3. A data subject is entitled to appeal against the acts or omissions of the Operator to the authorised body for the protection of the rights of data subjects (Roskomnadzor) or in court, and is entitled to compensation for losses and/or compensation for moral harm in court proceedings (part 2 of Article 17 of 152-FZ).

11.4. Procedure for submitting requests

Enquiries, requests and demands from data subjects are to be sent:

  • to the e-mail address info@econferences.ru — with the subject line “Request from a data subject”;
  • in written form to the Operator’s registered address: [уточняется].

A request must contain: the number of the principal identity document of the data subject or his or her representative, information on the date of issue of that document and the issuing authority; information confirming the data subject’s involvement in relations with the Operator (submission number, title of the material, name of the conference) or information otherwise confirming that the Operator processes the data subject’s personal data; and the signature of the data subject or of his or her representative. A request may be submitted in the form of an electronic document signed with an electronic signature in accordance with the legislation of the Russian Federation (part 3 of Article 14 of 152-FZ).

Response time. The Operator considers a request and provides a response within 10 (ten) business days of the date of its receipt. That period may be extended, by no more than 5 (five) business days, with a reasoned notice of the extension being sent to the data subject.

11.5. Procedure for withdrawing consent

Consent to the processing of personal data may be withdrawn by the data subject at any time (part 2 of Article 9 of 152-FZ). A withdrawal of consent is to be sent in written form to the Operator’s registered address or to the e-mail address info@econferences.ru and must contain the data subject’s surname, given name and patronymic, information enabling the data subject to be identified in the Operator’s information system, and an express statement that consent is being withdrawn.

Where consent is withdrawn, the Operator ceases processing the personal data and ensures its destruction within a period not exceeding 30 (thirty) days of receipt of the withdrawal, except where the processing is carried out on another legal ground provided for by 152-FZ, including by reason of the need to perform a contract, to discharge obligations imposed on the Operator by the legislation on accounting and on taxes and levies, and in respect of the metadata of published materials retained as part of the scholarly record (clause 9.1 of this Policy).

12. Cookies and third-party services

12.1. The Website uses a single technically necessary session cookie — OJSSID. This file contains a random session identifier, is required to maintain the user’s authentication state and the correct operation of the Website’s forms, does not contain personal data in an explicit form and is deleted when the browser session ends.

12.2. No third-party web analytics systems are used on the Website. The Operator does not place third-party traffic counters, advertising pixels, social-network trackers or other cross-site user tracking tools on the Website.

12.3. The Website’s typography uses fonts loaded from the servers of the Google Fonts service (Google LLC, USA). When a page is loaded, the user’s browser makes requests to the domains fonts.googleapis.com and fonts.gstatic.com, as a result of which the user’s IP address and technical information about his or her browser are transferred to Google LLC. Google Fonts does not set cookies. A user who wishes to prevent such a transfer may block requests to those domains using browser settings or extensions; the Website retains full functionality in that case and is displayed using system fonts.

12.4. Refusing cookies. A user may at any time prohibit the storage of cookies in his or her browser settings and delete previously stored cookies. The relevant settings are located: in Google Chrome — “Settings” → “Privacy and security” → “Cookies and other site data”; in Mozilla Firefox — “Settings” → “Privacy & Security”; in Safari — “Settings” → “Privacy”; in Microsoft Edge — “Settings” → “Cookies and site permissions”; in Yandex Browser — “Settings” → “Sites” → “Advanced site settings”. If cookies are disabled, the functions of the Website that require authentication (including the submission of materials) become unavailable.

13. Measures to ensure the security of personal data

13.1. The Operator takes the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision or dissemination, as well as against other unlawful acts (Article 19 of 152-FZ).

13.2. The Operator has implemented, in particular, the following measures provided for by part 1 of Article 18.1 of 152-FZ:

  • a person responsible for organising the processing of personal data has been appointed (Article 22.1 of 152-FZ);
  • this Policy has been issued and published, and local acts on the processing of personal data and on the list of measures aimed at ensuring the performance of the Operator’s obligations have been adopted;
  • a list has been drawn up of the persons whose access to personal data is necessary for the performance of their duties; the Operator’s employees have been familiarised with the provisions of the personal data legislation and with the Operator’s local acts;
  • internal control is carried out over the compliance of personal data processing with the requirements of 152-FZ and the regulatory acts adopted thereunder;
  • organisational and technical measures to ensure the security of personal data during processing in information systems are applied in accordance with Resolution of the Government of the Russian Federation No. 1119 of 1 November 2012, including: differentiation of access rights and password protection, encryption of the data transmission channel using the TLS protocol (HTTPS), regular backups, maintenance of event logs, regular software updates and restriction of physical access to equipment;
  • an assessment is made of the harm that may be caused to data subjects and of the relationship between that harm and the measures taken;
  • unrestricted access to this Policy is provided on the Website (part 2 of Article 18.1 of 152-FZ).

13.3. Where it is established that personal data has been unlawfully or accidentally transferred (provided, disseminated or made accessible), resulting in a violation of the rights of data subjects, the Operator notifies the authorised body for the protection of the rights of data subjects in the manner and within the time limits established by part 3.1 of Article 21 of 152-FZ.

14. Final provisions

14.1. The Operator may amend this Policy. A new version of the Policy is approved by order of the Operator’s director and enters into force upon its publication on the Website at econferences.ru/privacy/, unless the new version specifies a different date of entry into force.

14.2. The current version of the Policy is permanently available on the Internet at the address indicated above. Data subjects are advised to review the text of the Policy periodically.

14.3. Matters not regulated by this Policy are governed by the legislation of the Russian Federation.

Approved by Order of the Director of ООО «Академический издательский дом» (Academic Publishing House LLC)

Date of approval: 9 September 2026 · Version 1.0

Date of publication: 9 September 2026