Contents
- Data Controller and Contact Information
- Scope of this Privacy Policy
- Personal Data Collected
- Editorial and Peer-Review Data
- Purposes and Legal Bases of Processing
- Mandatory and Optional Data
- Recipients and Authorized Persons
- Personal Data Made Public
- Personal Data Relating to Third Parties
- Cookies and Tracking Technologies
- Data Security and Confidentiality
- Processing Location and International Transfers
- Data Retention
- Automated Decision-Making
- Data-Subject Rights
- Right to Lodge a Complaint
- Changes to this Privacy Policy
Journal of Nursing in Infection Prevention and Control (JNIPC), the official publication of the ANIPIO Scientific Society, respects the privacy and personal data of readers, authors, reviewers, Editors, members of the Editorial Board, registered users, and other individuals who interact with the Journal.
This Privacy Policy explains how personal data are collected, used, stored, disclosed, protected, and otherwise processed through the JNIPC website, the iEditore Journals publishing platform, and the Journal’s editorial and peer-review workflows.
Personal data are processed in accordance with the General Data Protection Regulation – Regulation (EU) 2016/679 (GDPR), applicable Italian data-protection legislation, and other applicable legal requirements.
Data Controller and Contact Information
The Data Controller for personal data collected voluntarily or automatically through the JNIPC website and the iEditore Journals publishing platform is:
Infermieristica Editore di Hamilton Dollaku – iEditore
Via Gorizia 1/A
76126 Trani (BT), Italy
VAT number: 08552860721
Email: info@ieditore.com
Data Protection Officer / Responsabile della Protezione dei Dati:
Hamilton Dollaku
Requests concerning personal data and the exercise of data-subject rights may be addressed to: info@ieditore.com .
ANIPIO, the owner of JNIPC, and authorized members of the Journal’s scientific and editorial structure may access and process personal data to the extent necessary to perform their assigned editorial, scientific, organizational, and administrative functions.
Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through:
- the public JNIPC website;
- user registration and account management;
- the online manuscript-submission system;
- editorial screening and manuscript management;
- double-blind peer review;
- revision, acceptance, production, and publication;
- corrections, expressions of concern, retractions, and other post-publication procedures;
- communications with authors, reviewers, Editors, and readers;
- editorial-board and reviewer administration;
- technical assistance and website security;
- metadata registration, indexing, archiving, and digital preservation;
- calls for papers and other Journal communications, where permitted by law.
This Privacy Policy does not govern third-party websites or services that may be accessed through external links. Those services operate under their own privacy policies and terms.
Personal Data Collected
Depending on how an individual interacts with the Journal, the following categories of personal data may be collected.
Registration and Identification Data
- first name and surname;
- username and account identifier;
- password in protected or encrypted form;
- email address;
- telephone number, where voluntarily provided;
- preferred language;
- country and geographical information voluntarily provided by the user;
- ORCID iD or other researcher identifier;
- professional role and areas of expertise.
Professional and Institutional Data
- department and institutional affiliation;
- professional title and qualifications;
- institutional address;
- academic or professional biography;
- research interests and reviewer competencies;
- membership of the Editorial Board or other Journal roles;
- curriculum vitae, where requested or voluntarily provided.
Contact and Communication Data
- messages submitted through contact forms;
- emails and editorial correspondence;
- requests for information or technical assistance;
- responses to Journal invitations;
- complaints, appeals, corrections, and post-publication communications;
- communication preferences.
Technical and Usage Data
- Internet Protocol address;
- browser type and version;
- operating system and device information;
- date and time of access;
- session identifiers;
- pages accessed and actions performed within the platform;
- login, submission, and editorial-workflow logs;
- system-error and security-event information;
- technical cookies necessary for authentication, navigation, and security.
Technical information may be collected automatically when users access or use the website or publishing platform.
Editorial and Peer-Review Data
The Journal processes personal data required to manage manuscript submission, editorial evaluation, peer review, production, publication, and preservation.
These data may include:
- manuscripts and supplementary materials;
- title-page information;
- author names, affiliations, contact details, and ORCID iDs;
- authorship and contributorship declarations;
- funding and conflict-of-interest statements;
- ethical-approval and institutional-authorization documents;
- publication-consent and copyright-permission documents;
- cover letters and responses to reviewers;
- reviewer invitations, acceptance or refusal records, and review reports;
- editorial recommendations and decisions;
- internal editorial notes and correspondence;
- production files, proofs, and publication metadata;
- records relating to complaints, appeals, alleged misconduct, corrections, expressions of concern, or retractions;
- similarity reports and other research-integrity documentation;
- audit trails generated through the editorial-management system.
JNIPC applies a double-blind peer-review process. Author identities are not disclosed to reviewers through the anonymized manuscript, and reviewer identities are not disclosed to authors.
Authorized members of the Editorial Office may access identifying information where necessary to manage the editorial process, verify conflicts of interest, resolve technical issues, or investigate ethical concerns.
Purposes and Legal Bases of Processing
Personal data may be processed for the following purposes.
Provision of the Publishing and Editorial Service
Personal data are processed to create and administer user accounts, receive submissions, assign Editors and reviewers, manage peer review, communicate editorial decisions, produce articles, and publish scholarly content.
The legal basis is the performance of a contract or the implementation of pre-contractual measures requested by the user, together with the legitimate interest of the Journal and Publisher in operating a scholarly-publishing service.
Management of the Scholarly Record
Data are processed to register DOIs, generate and distribute metadata, index articles, preserve published content, maintain citation records, and manage corrections, retractions, and other post-publication notices.
The legal basis is the legitimate interest in preserving the accuracy, integrity, permanence, accessibility, and traceability of the scholarly record and, where applicable, compliance with legal obligations.
Research Integrity and Publication Ethics
Personal data may be processed to identify plagiarism, duplicate publication, fabricated information, undisclosed conflicts of interest, manipulated peer review, ethical violations, or other possible misconduct.
The legal basis is the legitimate interest of the Journal, Publisher, authors, readers, and scientific community in maintaining the reliability and integrity of scholarly publication.
Website and Platform Security
Technical and usage data may be processed to authenticate users, maintain system availability, prevent unauthorized access, identify fraudulent or malicious activity, investigate security incidents, and protect the rights and systems of the Journal, Publisher, and users.
The legal basis is the legitimate interest in ensuring the security, stability, and proper functioning of the website and editorial platform.
Compliance with Legal Obligations
Personal data may be processed where necessary to comply with applicable laws, regulations, court orders, legal-deposit obligations, tax or accounting requirements, regulatory requests, or other binding obligations.
The legal basis is compliance with a legal obligation to which the Data Controller is subject.
Responding to Requests and Protecting Legal Rights
Personal data may be processed to respond to enquiries, complaints, appeals, data-subject requests, or legal claims and to establish, exercise, or defend the rights of the Data Controller, Journal, users, or third parties.
The legal basis is compliance with legal obligations and the legitimate interest in protecting and defending legal rights.
Journal Communications
Contact information may be used to send editorial communications, review invitations, publication notifications, calls for papers, or information concerning JNIPC activities.
Communications necessary to manage a submission, review, editorial role, or registered account form part of the requested Journal service.
Promotional or non-essential communications are sent only where permitted by applicable law. Recipients may object to or unsubscribe from such communications at any time.
Consent-Based Processing
Where processing is based on consent, including the use of certain non-essential cookies or optional communications, consent may be withdrawn at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Mandatory and Optional Data
Certain personal data are required to create an account, submit or review a manuscript, perform an editorial role, or communicate with the Journal.
Failure to provide mandatory information may prevent the Journal from:
- creating or maintaining an account;
- receiving or evaluating a submission;
- assigning or completing a peer review;
- publishing an accepted article;
- responding to a request;
- meeting ethical, legal, or publication-integrity requirements.
Data identified as optional may be omitted without preventing use of the essential Journal services, unless the information later becomes necessary for a specific editorial, legal, ethical, or technical purpose.
Recipients and Authorized Persons
Personal data may be accessed only by individuals and organizations that require such access for legitimate editorial, publishing, technical, legal, or administrative purposes.
Recipients may include:
- authorized iEditore staff and system administrators;
- the Editor-in-Chief and authorized JNIPC Editors;
- the Journal Manager and authorized Editorial Office personnel;
- authorized ANIPIO representatives involved in the scientific or organizational management of the Journal;
- peer reviewers, who receive anonymized manuscript materials;
- copyeditors, proofreaders, designers, typesetters, and production personnel;
- hosting, information-technology, cybersecurity, and technical-support providers;
- email and communication-service providers;
- DOI registration agencies, including Crossref or another registration agency used by iEditore;
- indexing, metadata-aggregation, library, archiving, preservation, and scholarly-discovery services;
- legal advisers, auditors, insurers, and professional consultants where necessary;
- ethics committees, research institutions, funders, or regulatory bodies where required to investigate a substantiated ethical or legal concern;
- courts, law-enforcement authorities, supervisory authorities, or public bodies where disclosure is required by law.
Service providers that process personal data on behalf of the Data Controller are required to process those data according to documented instructions, applicable data-protection law, confidentiality obligations, and appropriate security measures.
An updated list of relevant data processors may be requested from the Data Controller.
Personal Data Made Public
When an article is accepted and published, certain personal and professional information becomes part of the public scholarly record.
Published information may include:
- authors’ names;
- institutional affiliations;
- ORCID iDs;
- corresponding-author contact information;
- authorship and contributorship statements;
- acknowledgements;
- funding disclosures;
- conflict-of-interest declarations;
- ethical-approval information;
- biographical information, where applicable;
- article metadata and bibliographic citations.
Published information may be distributed to Crossref, search engines, indexing databases, repositories, libraries, preservation networks, and other scholarly infrastructures.
Because published metadata form part of the permanent scholarly record, requests for their deletion or alteration may be restricted. Material inaccuracies may be addressed through a formal correction or other appropriate publication notice.
Personal Data Relating to Third Parties
Users who submit personal data concerning co-authors, contributors, patients, research participants, reviewers, institutional contacts, or other third parties must ensure that they are lawfully entitled to provide those data to the Journal.
The submitting user is responsible for informing relevant individuals, where required, about the processing of their personal data.
Authors must not upload directly identifiable patient or participant information unless it is scientifically necessary, legally permissible, appropriately protected, and supported by the required consent or authorization.
Special-category personal data, including health information, genetic information, biometric data, or information concerning racial or ethnic origin, religious beliefs, political opinions, trade-union membership, sex life, or sexual orientation, must not be submitted unless their processing is necessary, lawful, ethically approved, and adequately protected.
Manuscripts and supplementary files should contain anonymized or appropriately de-identified data wherever possible.
Cookies and Tracking Technologies
The JNIPC website and the iEditore Journals platform may use technical cookies and similar technologies that are necessary to provide core website and platform functions.
Technical cookies may be used to:
- maintain authenticated user sessions;
- remember navigation and language preferences;
- protect forms and accounts against unauthorized use;
- support submission and editorial-workflow functions;
- maintain security and system stability;
- prevent fraudulent or malicious activity.
Technical cookies that are strictly necessary for the operation of the service may be used without consent where permitted by applicable law.
Analytics, profiling, advertising, social-media, embedded-content, or other non-essential tracking technologies will be activated only where they have been technically configured and where an appropriate legal basis exists.
Where consent is required, such technologies will not be activated before the user has made a valid choice through the website’s cookie-management system.
Users may withdraw or modify cookie preferences at any time through the cookie settings made available on the website.
Details of the cookies and external services actually active on the JNIPC website, including their providers, purposes, duration, and applicable safeguards, are provided in the separate Cookie Policy accessible through the website footer or cookie banner.
Disabling technical cookies may prevent certain areas of the website or editorial platform from functioning correctly.
Data Security and Confidentiality
The Data Controller adopts appropriate technical and organizational measures designed to protect personal data against:
- unauthorized or unlawful access;
- accidental loss or destruction;
- unauthorized disclosure;
- alteration or corruption;
- misuse or fraudulent processing;
- unavailability of systems or data.
Measures may include:
- role-based access controls;
- password protection and authentication procedures;
- secure communications and encrypted connections;
- logging and monitoring of system activity;
- backup and recovery procedures;
- software maintenance and security updates;
- confidentiality obligations for authorized personnel;
- procedures for responding to security incidents.
Authors, reviewers, and Editors must preserve the confidentiality of unpublished manuscripts, peer-review reports, editorial correspondence, and research data.
No method of electronic transmission or storage can guarantee absolute security. However, reasonable measures are adopted in relation to the nature, context, and risks of the processing.
Processing Location and International Transfers
Personal data are primarily processed within Italy and the European Economic Area through the offices, systems, and service providers involved in operating the Journal and publishing platform.
Certain technical, communication, registration, indexing, archiving, or scholarly services may process data in other countries.
Where personal data are transferred outside the European Economic Area, the transfer will take place only where permitted under applicable data-protection law and on the basis of an appropriate safeguard, which may include:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses approved by the European Commission;
- binding corporate rules, where applicable;
- another legally recognized transfer mechanism;
- an applicable statutory derogation in specific circumstances.
Information concerning relevant international transfers and safeguards may be requested from the Data Controller.
Data Retention
Personal data are retained only for as long as reasonably necessary for the purposes for which they were collected, taking into account legal, contractual, ethical, technical, archival, and research-integrity requirements.
User Accounts
Account information is retained while the account remains active and may be retained afterwards where necessary to document editorial activity, protect system security, resolve disputes, or comply with legal obligations.
Submitted and Rejected Manuscripts
Manuscripts, metadata, editorial decisions, reviews, and correspondence may be retained after rejection or withdrawal for a period necessary to document the editorial process, prevent duplicate submission, address complaints or misconduct, defend legal rights, and maintain the integrity of peer review.
Published Articles and Metadata
Published articles, author information, bibliographic metadata, DOI records, licensing statements, and post-publication notices are preserved on a long-term or permanent basis as part of the scholarly record.
Reviewer and Editorial Records
Reviewer invitations, reports, editorial assignments, decisions, and related records may be retained for as long as necessary to document the peer-review process, provide reviewer recognition, investigate concerns, and comply with publication-ethics requirements.
Technical Logs
Technical, access, and security logs are retained for periods proportionate to their purpose and may be retained longer where they are required to investigate a security incident, fraud, unlawful activity, or legal claim.
Consent Records
Records demonstrating consent or withdrawal may be retained for as long as necessary to demonstrate compliance with applicable legal requirements.
At the end of the relevant retention period, personal data may be deleted, anonymized, restricted, or securely archived, depending on the nature and purpose of the information.
Automated Decision-Making
JNIPC does not make editorial decisions concerning the acceptance or rejection of manuscripts solely through automated processing.
Similarity-detection tools, automated checks, manuscript-management functions, or technical screening systems may support the editorial process, but their outputs are assessed by authorized Editors or Editorial Office personnel.
Users are not subject to decisions based solely on automated processing that produce legal effects or similarly significant effects, unless expressly permitted by applicable law and accompanied by the required safeguards.
Data-Subject Rights
Subject to the conditions, limitations, and exceptions established by the GDPR, individuals may exercise the following rights:
- Right of access: to obtain confirmation as to whether their personal data are processed and to receive access to those data;
- Right to rectification: to request the correction of inaccurate or incomplete personal data;
- Right to erasure: to request deletion of personal data where the applicable legal requirements are met;
- Right to restriction: to request restriction of processing in the circumstances provided by law;
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format where the right applies;
- Right to object: to object to processing based on legitimate interests, including direct-marketing processing;
- Right to withdraw consent: where processing is based on consent;
- Rights concerning automated decision-making: where applicable under Article 22 GDPR;
- Right to lodge a complaint: with the competent supervisory authority.
Certain rights may be limited where processing is necessary to preserve the integrity of the scholarly record, comply with legal obligations, protect confidentiality, establish or defend legal claims, or exercise freedom of expression and information.
In particular, deletion of published author information or editorial records may not be possible where continued retention is necessary to maintain the accuracy, provenance, transparency, and integrity of a published scientific article.
Requests should be sent to: info@ieditore.com .
The Data Controller may request information necessary to verify the identity of the person making the request and to prevent unauthorized disclosure of personal data.
Requests will be handled without undue delay and within the time limits established by applicable data-protection law.
Right to Lodge a Complaint
Individuals who believe that the processing of their personal data infringes applicable data-protection law may lodge a complaint with the competent supervisory authority.
In Italy, the competent authority is:
Garante per la protezione dei dati personali
Website: https://www.garanteprivacy.it/
The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Changes to this Privacy Policy
This Privacy Policy may be updated to reflect changes in applicable law, the Journal’s editorial activities, the configuration of the publishing platform, data-processing practices, or the services used by JNIPC and iEditore.
Updated versions will be published on the Journal website and will indicate the date of the latest revision.
Where a change materially affects the processing of personal data, users may be informed through the website, editorial platform, or another appropriate communication channel.
Last updated: 28 July 2026
