Confidentiality and NDA
Unpublished work is the most sensitive thing a client can hand over. This is how it is handled.
1. What we treat as confidential
Everything you send us before publication is confidential:
- manuscripts, figures, data and supplementary files;
- peer review reports and editorial correspondence;
- author and reviewer identities in a blinded review process;
- where you ask for it, the fact that you work with us at all.
We use this material only to do the work you engaged us for. We do not discuss it, show it or quote from it, and we do not use it as a sample or reference without your written permission.
2. The NDA
We sign a mutual non-disclosure agreement on request, at no charge, before you send anything. We can also sign your institution’s own NDA.
Without a signed NDA, this policy applies by default from the moment a file reaches us. That includes enquiries that never become projects.
3. Where files are stored
Files are stored with Railway (railway.com) in private storage, on servers in the European Union (Amsterdam, the Netherlands). They are not reachable from the public internet; they are served only to signed-in users who have access to that project.
We do not keep client files in consumer cloud drives or file-sharing services. Files move between you and us through the enquiry form or the client portal over an encrypted connection, or by email if you choose to send them that way.
4. How long we keep them
- Attachments to enquiries that did not become a project: deleted 12 months after our last exchange.
- Files from a completed project: kept for 24 months after completion, so that corrections, re-deposits and later issues remain possible, then deleted.
- Final deliverables (PDF, XML, metadata): handed over to you on completion, so your own record does not depend on ours.
You can ask for earlier deletion at any time. We act on it within 14 days.
5. Who has access
Access is limited to the people working on that specific manuscript or journal, and to you. Access to the client portal is personal and protected by a password.
When someone stops working on a project, their access to its files ends the same day.
6. Subcontractors
Some projects use outside specialists, for example for translation, specialist typesetting or illustration. Every such person signs confidentiality terms at least as strict as these before receiving anything, and receives only what their part of the work needs.
You can ask at any time who is working on your material, and you can ask us not to use subcontractors at all.
7. Peer review confidentiality
Where we administer peer review for a journal, reviewer identities and reports are seen only by the editors and the people managing the review. In a blinded process, we remove identifying information from files before they go to reviewers or authors, and we check file metadata as well as the visible text.
Blinding is maintained through production: author identities are restored only at the stage the journal’s policy allows.
8. Confidentiality and AI tools
Unpublished client material is never submitted to third-party AI services that retain input or train on it. The full rules are in the AI policy.
9. Deletion and return
To have all your material returned or deleted, write to info@recto.digital. Within 14 days we:
- send you everything we produced, in its original formats (PDF, XML, layout sources, metadata), if you want it back;
- delete the files from our storage, our backups as they rotate, and our correspondence archive;
- confirm in writing that the deletion is done.
We keep only what the law requires us to keep, such as payment records, and we tell you what that is.
10. Breach notification
If confidential material is exposed, or we have reason to believe it may have been, we tell the affected client within 72 hours of finding out. The notification says what was affected, how it happened as far as we know, what we have done about it, and what you may need to do.
Where personal data is involved, we also notify the supervisory authority as described in the Privacy policy.