Editorial Policy
Privacy Policy
This policy explains what personal data the journal collects, what it does with it, and what rights you have over it. It describes the site as it actually works today, not as it may work later.
Last updated
Who is responsible
Blue Ocean Research Journal for Social Sciences (BORJSS) is published by Blue Ocean Educational Services (Pvt.) Ltd., which is the controller of the personal data described here. Enquiries about this policy go to the editorial office at ceoborjss@gmail.com.
What this site does today
The journal is newly launched and the site is still being built out. It is worth being specific about the present position rather than describing a system that does not yet exist:
- There are no reader accounts. You do not need to register, log in, or give an email address to read anything.
- There is no analytics or tracking. The site runs no analytics service, no advertising network and no third-party tracking scripts.
- There are no tracking cookies. Reading the site sets no cookie of any kind.
- The forms save, but do not yet notify anyone. The contact and reviewer-application forms record what you submit so the editorial office can act on it, but no email is sent — to you or to the office — because the mail provider has not been connected. If you need a prompt reply, use the email addresses on the contact page as well.
- Manuscripts are still sent by email. The portal is built and accounts, submissions and peer review all work inside it, but it is not yet open to authors — email notification is not connected, so nobody would be told what happened to their manuscript. Until it opens, submissions reach the editorial office by email.
The sections below describe both what happens now and what will happen once those systems are in operation. This policy will be updated, with a new date, before any of them begins processing real personal data.
What data is collected
- Reading the site
- Nothing that identifies you. The hosting infrastructure keeps standard server logs, which include IP addresses, for security and reliability.
- Contact form
- Your name, email address, subject and message. Stored for the editorial office to respond to; not forwarded anywhere else, and no email is sent yet.
- Reviewer application
- Your name, email, affiliation, position, areas of expertise and any ORCID iD you supply. Stored as a pending application for an editor to review; not forwarded anywhere else.
- Manuscript submission
- Author names, affiliations, email addresses, ORCID iDs, the manuscript and its files, and declarations.
- Peer review
- Reviewer identity, expertise, review history, availability, and the content of reports.
- Accounts
- Name, email, password (stored hashed, never in readable form), role and activity within the portal.
- Charges (planned)
- Billing name, institution and invoice records. Card details are never seen or held by the journal.
The journal does not ask for, and does not want, special category data — health, religion, political opinion, ethnicity — about the people who use it. Where research participants’ data appear in a manuscript, they are governed by the research ethics policy and the data availability policy, not by this one.
Why it is collected
Each category is collected for a stated purpose and is not reused for anything else:
- To answer you — enquiries and reviewer applications are used to reply and, for reviewers, to match expertise to manuscripts;
- To operate peer review — running submission, review, decisions and production;
- To publish — author names and affiliations appear in the published article, which is the point of publishing it;
- To keep the record — maintaining the integrity of what has been published, including corrections and retractions;
- To meet obligations — invoicing, accounting, and responding to ethical or legal enquiries;
- To keep the site running — server logs used for security and diagnosis.
Your data is never sold, rented or shared for marketing. The journal sends no marketing email. Where a table of contents alert is offered in future it will be opt-in, and unsubscribing will be a single click.
Cookies and analytics
Reading this site sets no cookies. There is no analytics service, no advertising, no social media pixel and no third-party tracking script anywhere on the public site. Nothing you read here is logged against you, and there is no cookie banner because there is nothing to consent to.
Signing in to the portal sets a single strictly necessary cookie that keeps you signed in. It holds a session token only, does not track you across other sites, and cannot be disabled without making sign-in impossible. Signing out clears it. No consent banner is required for a cookie of that kind, and none will be added for tracking, because tracking is not planned.
Should the journal ever add analytics, it will use a privacy-preserving service that does not profile individuals, and this policy will say so before it is switched on.
Who can see your data
Access is limited to those who need it. Manuscripts and their associated data are seen only by the handling editor, the assigned reviewers, the editorial office and, where relevant, the production team.
Some data is necessarily shared outside the journal, and only these:
- Hosting and infrastructure providers, which process data on the journal’s instructions in order to run the site;
- Crossref, which receives the metadata of published articles — including author names, affiliations and ORCID iDs — so that DOIs resolve;
- Indexing services and preservation archives, which receive published article metadata and content;
- A payment provider, once charges are live, which handles card details directly so that the journal never receives them;
- An author’s institution or a funder, where a misconduct investigation requires it under the publication ethics policy;
- A court or regulator, where the journal is legally obliged to disclose.
Some of these providers operate outside Pakistan, so data may be processed in other countries. The journal uses established providers that apply recognised data protection safeguards.
Privacy in peer review
Review is double-blind, and the confidentiality that protects it is part of this policy as much as it is part of the peer review policy.
- Reviewer identities are never disclosed to authors — not during review, not after a decision, and not after publication;
- Author identities are withheld from reviewers, which is why the main file must be anonymised;
- Reports are confidential and are shared only with the authors, the handling editor and, where a manuscript is transferred, the receiving editor;
- Manuscripts must not be entered into AI services by reviewers or editors — doing so transmits confidential work to a third party, and is prohibited by the AI-assisted writing policy;
- The identity of a person raising a concern under the ethics or complaints policies is not disclosed to the person it concerns, wherever the investigation allows.
What becomes public
Publication is by its nature public and permanent. When an article is published, the following become part of the public record and cannot be withdrawn later: author names, affiliations, ORCID iDs, the corresponding author’s email address, the contribution statement, and the funding, competing interests, ethics and data availability statements.
This is a consequence of publishing under an open licence — the article is copied, indexed and archived elsewhere, beyond the journal’s control. Authors should be sure they are content for the email address they give to remain published indefinitely. A factual error in a name or affiliation can be corrected under the retraction and correction policy; a change of mind about being published cannot undo publication.
How long data is kept
- Published articles and their metadata
- Permanently
- Editorial records for published articles
- 10 years, so that later concerns can be investigated
- Declined manuscripts and their reports
- 5 years
- Reviewer records
- Until you ask to be removed
- Enquiries and correspondence
- 2 years
- Invoices and financial records
- As long as the law requires
- Server logs
- A short operational period, then discarded
Your rights
Whatever jurisdiction you are in, the journal will honour the following requests about your own personal data:
- Access — a copy of the personal data held about you;
- Correction — inaccurate details put right;
- Deletion — removal of your data, subject to the limits below;
- Restriction and objection — asking that processing stop while a dispute is resolved;
- Portability — your data in a machine-readable form;
- Withdrawal of consent — where processing rests on consent, such as remaining in the reviewer database.
Two limits apply, and the journal states them rather than leaving them to be discovered. Published articles cannot be unpublished — the scholarly record depends on stability, and copies exist elsewhere. And editorial records are kept for the periods above even after an account is closed, so that a later question about a published article can still be investigated.
To exercise any of these, write to the editorial office. Requests are answered within 30 days, and there is no charge.
Security
The site is served over HTTPS. When the portal launches, passwords will be stored only as salted hashes and never in readable form, access will be restricted by role, and manuscripts will be accessible only to those assigned to them.
No system is perfectly secure. Where a breach affects personal data and presents a real risk, the journal will notify the people affected and the relevant authority without undue delay, and will say what happened rather than minimising it.
Children
The journal’s services are intended for researchers and are not directed at children. It does not knowingly collect personal data from anyone under 16 through this site. Where research involves children as participants, the safeguards in the research ethics policy apply.
Changes to this policy
This policy will change as the submission portal, accounts and payment processing come into operation. The date at the top records when it was last revised, and any change that materially affects how personal data is handled will be described here before it takes effect — not retrospectively.
Contacting us
Questions, requests and complaints about personal data go to the editorial office at ceoborjss@gmail.com, or by post to Editorial Office, BORJSS, Pakistan.
If you are not satisfied with the response, you may complain under the complaints and appeals policy, and you may also raise the matter with the data protection authority in your own country.
Standards this policy follows
BORJSS editorial policies are modelled on the Committee on Publication Ethics (COPE) Core Practices and the principles of transparency required by the Directory of Open Access Journals. Where this policy is silent on a question, COPE guidance applies.
Publication ethics policy →