Recto.
For journalsFor authorsSamplesPricingAboutLogin / Sign UpBook a call
Back to Recto

Privacy policy

What we collect through this site, why we are allowed to, how long we keep it and how you get it removed.

Last updated: 5 October 2026 · Contact: info@recto.digital

Contents

  1. Who is responsible
  2. What data we collect
  3. Why we process it, and on what basis
  4. How long we keep it
  5. Who has access
  6. International transfers
  7. Your rights
  8. Cookies and analytics
  9. Security
  10. Complaints
  11. Changes to this policy

1. Who is responsible

The controller of personal data collected through this site and in the course of our work is Recto, Banja Luka, Bosnia and Herzegovina (“Recto”, “we”).

For anything about your personal data, write to info@recto.digital. A person, not an automated system, reads that inbox.

We process personal data in line with the Law on Personal Data Protection of Bosnia and Herzegovina and, where it applies to our clients in the European Union, the General Data Protection Regulation (GDPR). We have not appointed a representative in the EU; write to the address above.

2. What data we collect

  • Enquiry forms: your name, email address, optional ORCID iD, the journal or institution, ISSN, details of the manuscript or journal, and your message.
  • Uploaded files: manuscripts and other files you attach, and the personal data inside them, such as author names, affiliations and contact details.
  • Correspondence: emails you send us and our replies.
  • Client portal account: name, email address, a securely hashed password, and the projects and files linked to your account.
  • Payment: when you pay through PayPal, we receive the payer’s name, email address and the transaction details. We never see or store card numbers.
  • Server logs: IP address, browser type, the page requested and the time, recorded automatically by our hosting for security.

We do not buy personal data, and we do not collect more than the forms ask for.

3. Why we process it, and on what basis

  • Answering an enquiry and preparing a quote: your consent, given when you submit a form. You can withdraw it at any time.
  • Carrying out the work you engaged us for, including your portal account and project files: performance of the contract, or steps you asked for before entering into one.
  • Payment and accounting records: our legal obligations under accounting and tax law.
  • Security logs and protection against abuse: our legitimate interest in keeping the site and your files safe.

We do not use your data for advertising, we do not sell it, and we do not make decisions about you by automated means alone.

4. How long we keep it

  • Enquiries that did not become a project, including attachments: 12 months from our last exchange, then deleted.
  • Project files and correspondence: for the duration of the engagement and 24 months after completion, so that corrections and re-deposits remain possible. Earlier deletion on request.
  • Portal accounts: until you ask us to close the account, or 24 months after your last project, whichever is earlier.
  • Payment and accounting records: for the period required by accounting and tax law.
  • Server logs: no longer than 90 days.

Backup copies are overwritten on a rolling basis and follow the same periods.

5. Who has access

Inside Recto, only the people working on your enquiry or project. Outside Recto, only these service providers, each for its own part:

  • Railway (railway.com): hosting of the site, the database, file storage and backups.
  • Our email delivery provider: sending notifications and replies.
  • PayPal: processing payments, as an independent controller under its own privacy statement.
  • Subcontracted editors or typesetters, where a project uses them: only the material they need, under written confidentiality terms equal to ours.

You can ask us at any time who has had access to your material.

6. International transfers

Our servers, database, file storage and backups are located in the European Union (Amsterdam, the Netherlands). Your data is stored within the European Economic Area and is not moved outside it in the ordinary course of our work.

Our hosting provider is based in the United States. Where its staff may need to access stored data from outside the EEA, for example to provide technical support, that access is covered by the standard contractual clauses in its data processing terms. You can ask us for a copy of the relevant safeguards.

7. Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data erased, unless we must keep it by law;
  • restrict or object to processing;
  • receive the data you gave us in a portable format;
  • withdraw consent at any time, without affecting processing done before.

Write to info@recto.digital. We answer within 30 days, and we may ask you to confirm your identity first. Requests are free of charge.

8. Cookies and analytics

This site sets only the cookies it needs to work:

  • auth_token: keeps you signed in to the client portal. It cannot be read by scripts on the page, and it expires after 12 hours or when you sign out.
  • auth_user: holds your display name for the portal interface while you are signed in, for up to 12 hours.

Your light or dark theme choice is saved in your own browser and is never sent to us.

We do not use analytics, advertising or tracking cookies. If that changes, this section will list them and the site will ask for your consent first.

9. Security

All traffic to this site is encrypted (HTTPS). Files and the database sit in private storage that is not publicly reachable; files are served only to signed-in users with access to that project. Passwords are stored only as secure hashes. Access to files is limited to the people working on the project.

If a breach affects your personal data in a way that is likely to put you at risk, we notify the supervisory authority within 72 hours of becoming aware of it, and tell you without undue delay what happened and what you can do.

10. Complaints

You can lodge a complaint with the Personal Data Protection Agency of Bosnia and Herzegovina (Agencija za zaštitu ličnih podataka u BiH, azlp.ba). If you live in the European Union, you can also complain to the data protection authority of your country.

You do not have to contact us first, though we would like the chance to put things right.

11. Changes to this policy

When this policy changes, the new version is published here and the date at the top is updated. If a change affects how we use data you have already given us, we tell active clients by email before it takes effect.

Related:Privacy policyTerms of serviceConfidentiality & NDAAI policy
Recto.

Modern infrastructure for scholarly publishing. From manuscript to indexed publication, in one place.

For journals
ServicesIndexingOngoing maintenancePricing
Company
For authorsSamples & portfolioAboutBook a call
Legal
Privacy policyTerms of serviceConfidentiality & NDAAI policy
Contact
info@recto.digitalBanja Luka, BiH
© 2026 Recto — Scholarly publishing serviceFrom manuscript to indexing