Privacy Policy for callforpaper.org
Effective Date: November 25, 2025
callforpaper.org (“Platform,” “we,” “us,” or “our”), operated by SVSS Labs (including its owners and affiliates), respects your privacy. This Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect personal data when you use our website and custom submission system (the “Services”). We process data in compliance with applicable laws, including the EU General Data Protection Regulation (GDPR) for EU/EEA users, Singapore’s Personal Data Protection Act (PDPA), and equivalent standards.
By using the Services, you consent to this Policy. If you are an EU/EEA resident, you have enhanced rights (see Section 8).
1. Information We Collect
We collect only necessary data (data minimization principle) for conference submissions, registrations, and operations:
Personal Data (from Users/Organizers/Authors/Reviewers):
- Name, email, affiliation, ORCID iD, country (for visa/region stats).
- Co-author details (if applicable).
- Payment info (via secure gateways; we do not store cards).
Usage Data:
- IP address (anonymized for EU users via IP anonymization in Google Analytics), browser/device type, pages visited, time spent (via Google Analytics, hosted by Google Ireland Ltd. with safeguards for EEA data; no Personally Identifiable Information sent).
- Cookies: Strictly necessary (e.g., session management); optional analytics (Google Analytics cookies, e.g., _ga, _gid—require consent for EU/EEA users).
Subscription Data: Email for newsletters (opt-in only).
We do not collect sensitive data (e.g., health, politics) unless required for a specific conference (with explicit consent).
2. How We Collect Data
- Directly: Forms for registration/submission (e.g., paper uploads).
- Automatically: Cookies/logs during use.
- Third Parties: Payment processors (e.g., Stripe) for upgrades; hosting (DigitalOcean in Singapore).
3. How We Use Data
Under lawful bases (consent or legitimate interest):
- Core Services: Process submissions, match reviewers, run conferences (legitimate interest).
- Communications: Send confirmations, newsletters (consent).
- Analytics: Improve Services (anonymized data).
- Security/Fraud: Detect abuse (legitimate interest).
- Legal: Comply with laws.
Retention: Data kept only as needed (e.g., 1 year post-event for proceedings; delete on request).
4. Data Sharing and Transfers
We do not sell data. Sharing is limited to:
- Service providers (e.g., email tools like Resend) under Data Processing Agreements (DPAs) ensuring GDPR/PDPA compliance.
- Co-authors/reviewers (for collaboration).
- Authorities if legally required.
Transfers: All data stored in Singapore (DigitalOcean data center), which provides adequate protections. For EU/EEA data, we use safeguards like Standard Contractual Clauses (SCCs) if needed. No transfers to high-risk countries.
5. Cookies and Tracking
We use:
- Essential cookies (no consent needed).
- Optional cookies (analytics): Managed via consent banner for Google Analytics tracking. EU/EEA users must opt-in before cookies are set; non-consent defaults to denied. We use Google Consent Mode to respect choices. Withdraw anytime via banner or browser settings.
Browser settings can disable cookies, but may limit functionality. For details on Google Analytics cookies, see Google's policy: https://policies.google.com/technologies/types.
6. Security
Data is protected with HTTPS, encryption (e.g., AES-256), access controls, and regular audits. Breaches are reported per law (72 hours for GDPR).
7. Children's Privacy
Services are not for children under 16. We do not knowingly collect their data.
8. Your Rights
You can exercise these rights (free, within 30 days):
- Access/Download: Request your data (JSON/CSV via profile).
- Rectify/Update: Correct inaccuracies.
- Erase/Delete: Remove data (except published proceedings for academic integrity).
- Portability: Export data.
- Withdraw Consent: Anytime (e.g., unsubscribe link).
EU/EEA users: Contact us as Data Controller. Complaints to supervisory authorities (e.g., Singapore PDPC or EU DPA).
Profile tools: “Download My Data” / “Delete Account” available.
9. Third-Party Links
Links to external sites (e.g., ORCID) are not covered. Review their policies.
10. Changes
We may update this Policy; notice via email/posting. Continued use = acceptance.
11. Contact
Data Protection Officer: Kevin [email protected]. For EU: Include “GDPR Request.”
Last Updated: November 25, 2025