Saltar para o conteúdo

Journal of Plastic, Breast & Reconstructive Surgery·Revisto por pares · Acesso aberto

JPBRS

Legal

Privacy Policy

Last updated 14 September 2026

Journal of Plastic, Breast & Reconstructive Surgery (JPBRS) (“JPBRS”, “we”, “us”) is committed to protecting your personal data. This policy explains what we collect, why, how we use and protect it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Denmark data protection law.

1. Who we are (data controller)

The data controller is Journal of Plastic, Breast & Reconstructive Surgery (JPBRS). For any privacy question or to exercise your rights, contact us at privacy@jpbrs.com.

2. The data we collect

  • Account & profile data: name, email address, password (stored only as a salted hash), and optionally your title, specialty, institution, country, ORCID and biography.
  • Authentication data: if you sign in with Plast ID or another single sign-on provider, we receive your identifier and basic profile from that provider.
  • Submission & review content: the case reports, comments, reviews and scores you create, and records of your activity in the editorial workflow.
  • Clinical case material: case text and images you upload. This may include clinical/medical content — see our Patient Privacy & Consent policy.
  • Payment data: if you buy peer-review publication tokens, payments are processed by Stripe. We do not store your full card details.
  • Technical data: limited log and security data needed to operate the service. See our Cookie Policy.
  • Usage statistics: anonymous, aggregated page views and product events from our self-hosted analytics (see section 4a).

3. Why we use it and our legal basis

  • To provide the service (accounts, submission, peer review, publication) — performance of a contract.
  • To process payments for peer-review publication tokens — performance of a contract.
  • To communicate about submissions, reviews and account matters — legitimate interests / contract.
  • To keep the platform secure and prevent abuse — legitimate interests.
  • To understand how the platform is used through aggregated, anonymous usage statistics — legitimate interests (GDPR art. 6(1)(f)).
  • To meet legal and publishing-ethics obligations — legal obligation / public interest.

Where we publish your name and affiliation as an author, we rely on the contractual relationship and the legitimate interest of scholarly attribution.

4. Sharing and processors

We never sell your personal data. We share it only with service providers who process it on our behalf under contract:

  • Hosting and database infrastructure (EU-based).
  • Object storage for uploaded media (Hetzner, EU).
  • Email delivery (Resend).
  • Payment processing (Stripe).
  • Usage analytics (Umami, self-hosted by Nordic Surgery Lab ApS on its own server at Hetzner Online GmbH, Germany, EU) — see section 4a.

Published cases (including author names, affiliations and case content) are, by design, publicly available open-access content.

4a. Analytics

We measure how the platform is used with Umami, an open-source analytics tool that runs on Nordic Surgery Lab’s own server in the EU (analytics.nordicsurgerylab.com). It is cookieless: nothing is stored on your device (no cookies, no local storage), there is no cross-site tracking, and your IP address is not stored. A visit is identified only by a daily-rotating hash of IP address, browser and website that cannot be reversed.

We record page views and anonymous product events such as “case published” or “purchase completed”. These events contain no personal data: no name, email, user ID, free text or patient data. The data stays on our server and is not shared with third parties. The legal basis is our legitimate interest in aggregated usage statistics (GDPR art. 6(1)(f)). Because nothing is stored on your device, no cookie consent is required under the Danish cookie rules, but you can object to this processing at any time by emailing privacy@jpbrs.com.

5. International transfers

We aim to keep personal data within the EU/EEA. Where a processor transfers data outside the EEA, that transfer is protected by an adequacy decision or the European Commission’s Standard Contractual Clauses.

6. Retention

We keep account and profile data for as long as your account is active. Published scholarly content forms part of the permanent scientific record and is normally retained indefinitely. Other data is kept only as long as needed for the purposes above or as required by law, then deleted or anonymised.

7. Your rights

Subject to legal limits, you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time.

To exercise any right, email privacy@jpbrs.com. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).

8. Security

We use appropriate technical and organisational measures — including encryption in transit, hashed passwords, access controls and removal of image metadata (EXIF) on upload — to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the authorities of any breach as required by law.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify you.