Draft pending legal review. This text was prepared as a starting point and must be reviewed by a lawyer and completed with the controller's details before it is published as final. It is not legal advice.
Last updated: October 9, 2026 (draft)
Who we are and what this policy covers
This policy explains how the journal Pediatric Surgery Latam (the “journal”), published by [publisher to be defined] (the “controller”), handles the personal data of people who visit this site, create an account, submit manuscripts, review them or edit them.
Data controller: [publisher to be defined], based in [country to be defined]. Contact for personal-data matters: editor@pediatricsurgerylatam.org.
By creating an account or submitting a manuscript you confirm that you have read this policy and the Terms and conditions.
What data we collect
We only collect what is needed to run the journal:
- Account: name, email, password (stored encrypted by the authentication provider; we cannot see it), preferred language and, if you enter them, ORCID, affiliation and country.
- Roles: whether you are an author, reviewer, editor or other role in the journal.
- Manuscripts: title, abstracts, keywords, authors (name, email, ORCID, affiliation, country), declarations on ethics, consent, conflicts of interest, funding, data availability and use of artificial intelligence, and the files you upload (manuscript, title page, cover letter and supplementary material).
- Peer review: each reviewer's comments, scores and recommendation, and the editorial team's decisions and letters.
- Technical records: an audit log of relevant actions (for example, submission, decision, role change), with the date and the account that performed them; and an anonymous counter of reads and downloads of published articles.
- Emails: the notifications we send you (address, type of notice and date).
We do not collect payment data, we do not use advertising, and we do not install tracking cookies or third-party analytics tools.
Patients and minors
The journal publishes pediatric surgery. Authors must not include in manuscripts or supplementary files data that identifies a patient (name, initials, medical record number, full date of birth, facial images, among others) without written informed consent from the parents or guardians and, where applicable, the child's assent.
The author is responsible for obtaining and keeping those consents. If we receive identifiable data without consent, we may reject the manuscript, request anonymization or delete the data.
What we use the data for and on what basis
- To create and manage your account, and let you submit, follow, review or edit manuscripts (performance of the relationship you request).
- To manage peer review, make editorial decisions and publish accepted articles (legitimate interest of the journal and relationship with the author).
- To send you editorial-process notices: confirmations, review invitations, decisions and reminders (necessary for the service).
- To keep the service secure, prevent abuse and keep an audit log (legitimate interest).
- To meet ethical and legal duties, such as investigating misconduct, publishing corrections or retractions and answering requests from authorities.
We do not sell your data or use it for automated decisions. Artificial intelligence does not make editorial decisions or evaluate manuscripts on behalf of the journal.
Confidentiality and peer review
Unpublished manuscripts are confidential. Only the author and the editorial team can access them. Reviewers only see the anonymized manuscript and supplementary material after accepting the invitation; they do not see the title page, the cover letter or the identity of the authors.
Confidential comments that a reviewer addresses to the editor are not shown to the authors. Comments for the authors are delivered without identifying the reviewer.
Reviewers commit not to share the manuscript, not to use it for their own work and not to upload it to external artificial intelligence tools.
What becomes public
When an article is published, its title, abstract, keywords, text, references, editorial dates, license and the author details you declared for publication (name, affiliation, country and ORCID, if included) become public. Publishing an article is part of the scientific record and is, by nature, permanent and open.
The scientific committee page shows only the data each member authorized (name, affiliation, country, specialty, ORCID and photograph).
Providers that process data on our behalf
To run the journal we use providers that process data on our instructions:
- Supabase: database, authentication and file storage (Americas region; exact location to be confirmed).
- Cloudflare: hosting and delivery of the website.
- Resend: sending of notification emails.
- Google Fonts and jsDelivr: load typefaces and a code library from their servers, so your IP address and browser data reach those providers when you visit the site.
Some of these providers are outside your country, so your data may be transferred to other jurisdictions. We require appropriate security measures and do not authorize providers to use the data for their own purposes.
Cookies and browser storage
We do not use advertising or tracking cookies. When you log in, your browser stores a session item in local storage to keep you signed in; it is removed when you log out. Information necessary for the site to work (for example, editable texts and roles) may also be stored temporarily.
How long we keep data
Proposed periods, subject to approval by the controller and its legal advisor:
- Account: while active; deleted or anonymized at your request, except what must be kept for legal or ethical reasons.
- Unpublished manuscripts, reviews and decisions: [period to be defined, e.g. 5 years] from the final decision.
- Published articles and their metadata: permanently, as part of the scientific record.
- Audit log and sent emails: [period to be defined, e.g. 5 years].
Backups may keep data for a limited additional time.
Your rights
You may request access to your data, its rectification, its deletion, restriction of or objection to certain processing and, where applicable, portability of the data you gave us. You may also withdraw your consent where processing is based on it.
To exercise them write to editor@pediatricsurgerylatam.org from your account email. We will reply within a reasonable time and, at most, within the period set by the applicable law ([country to be defined]).
Limitation: an article that has already been published cannot be erased from the scientific record; we can correct it or, in justified cases, retract it following editorial ethics rules. If you believe your rights are not respected, you may go to the data-protection authority in your country.
Security
We apply reasonable technical and organizational measures: encrypted connections (HTTPS), role-based access control enforced on the server, private storage for unpublished files, an audit log and file size and type limits. No system is completely invulnerable; if an incident affects personal data, we will assess it and notify people and authorities where the law requires.
Changes and contact
We may update this policy; we will publish the new version on this page with its date. If the change is significant, we will tell you by email or on the site.
Questions about this policy: editor@pediatricsurgerylatam.org.
