Privacy notice

What we collect from readers, subscribers, authors and reviewers, why, who we share it with, and the choices you have. Written to be read, not skimmed.

Section 1 of 11

Who we are & what this covers

GSMS Publications is run by the Green and Sustainable Materials Society (GSMS), a non-profit association (perkumpulan) registered in indonesia. The Society is the data controller for the personal data described here.

This notice covers pubs.greensus.org (the journal website you are reading), the article-usage service behind it, and the personal data we process when you subscribe to e-alerts, contact us, or take part in publishing with one of our journals as an author, reviewer or editor through the submission portal (submit.revise.id) and the production system (production.revise.id). Both systems are operated for the Society by its platform provider, Revise, which processes data only on the Society's instructions (section 6).

The Society's own website, greensus.org, and its membership records are outside this notice. Links from our pages to other organisations' sites are governed by those sites' own notices.

Section 2 of 11

Reading the site

You can read every article without an account, and we do not try to identify individual readers. Three things happen in the background.

Site analytics (Umami, self-hosted)

We run our own instance of the open-source analytics tool Umami at analytics.revise.id. It records the page visited, the referring site, your country (from your IP address), browser, operating system and screen size, and counts unique visitors with a daily-rotating hash so that visits cannot be linked across days. It sets no cookies, stores no IP addresses, and shares nothing with advertising networks.

Article views and downloads

When you open an article or download its PDF, your browser sends a small request to our publishing API recording the article, the event type, a random session identifier kept in your browser's session storage (deleted when the tab closes), your browser's user-agent string and a salted one-way hash of your IP address. The raw address is never stored. The hash is used only to filter duplicates and automated traffic; the totals appear as the views and downloads shown on each article. We honour the browser Do Not Track setting: if it is on, no request is sent.

Server logs and search

Like every website, our servers keep standard access logs (IP address, time, page requested, user-agent) for security and troubleshooting; they are rotated and deleted automatically after about two weeks. Searches typed into the site are sent to our own search service; queries are not linked to any person and are not used to build profiles.

Section 3 of 11

E-alerts & enquiries

E-alerts. If you follow a journal, we store your email address, the name you optionally give, the journal chosen and the date. We use this only to tell you about new articles and issues of that journal and, occasionally, a call for papers from it. We do not sell, rent or share the list, and we do not send third-party marketing. You can stop at any time on the unsubscribe page, which deactivates your address immediately, or by emailing us.

Enquiries. If you email the publisher or an editorial office, we keep the correspondence for as long as needed to deal with it and, where it concerns a manuscript or a published article, as part of that record. Concerns about published work may be shared with the authors and their institution under our publication ethics policy; the identity of a person raising a concern is protected where they ask for it.

Section 4 of 11

Submitting, reviewing & production

Publishing a paper needs a lot more personal data than reading one, because we have to know who wrote it, who assessed it and who decided on it. This is the core of a scholarly record and we process it on the basis of the publishing agreement between authors and the journal and our legitimate interest in running peer review.

WhoWhat we holdWhy
Anyone with a portal account Title, name, email address (verified), institution and department, country, ORCID iD, phone number and areas of expertise if you add them; password (stored hashed); two-factor settings; login times. To identify you, secure your account and match reviewers to manuscripts.
Authors The manuscript, files and cover letter; co-author names, affiliations and emails; funding, conflict-of-interest and data-availability statements; every version, response letter and decision; the correspondence around it. To run peer review and, if accepted, to publish and preserve the article and its provenance.
Co-authors Name, affiliation and email as entered by the submitting author. We email each co-author to confirm they agree to be listed. To prevent people being named as authors without their knowledge.
Reviewers Invitations and responses, your report and confidential comments, ratings and recommendation, deadlines, and the certificate we issue (name, journal, date, verification ID). To assess manuscripts, recognise your work and let you prove it.
Editors and staff Roles, assignments, decisions and an audit trail of actions taken in the system. To make the editorial process accountable.
Accepted articles in production The corresponding author's name and email, the proof and any annotations they make on it, and the date they approve it. To produce the final article and record the author's sign-off.

Confidentiality. Manuscripts under review, reviewer reports and confidential comments are seen only by the editors handling the paper, the reviewers assigned to it and the authors (for comments addressed to them). Reviewer identities are not disclosed to authors. A public tracking page lets the corresponding author follow a manuscript's status with a private link; it shows the stage, not the content.

Your account. You can update your details at any time in the portal's settings and delete your account there. Deleting an account removes your login and profile; records that form part of a manuscript's history (for example that you reviewed or authored it) are kept, because the integrity of the published record depends on them (section 9).

Section 5 of 11

Information we publish

A published article permanently records who wrote it. For every author we publish the name, affiliation and ORCID iD given in the manuscript, and for the corresponding author the email address supplied for that purpose. Funding, conflict-of-interest, data-availability and (where applicable) ethics-approval statements are published with the article. Acknowledgements name the people the authors chose to thank.

This information is embedded in the article's HTML, PDF and JATS XML, deposited with Crossref, and made available to indexing services, so it cannot be recalled once published. Authors should make sure every named person has agreed. Corrections to a name or affiliation are made through a published correction (see Corrections & retractions); we will update the record for a legal change of name on request, following COPE guidance on name changes.

Editorial board members' names, affiliations and, where they have provided one, photographs are published on each journal's Editorial board page with their consent. Reviewer certificates are verifiable at a public address that shows the reviewer's name, the journal and the date, and nothing about the manuscript.

Section 6 of 11

Who we share data with

We never sell personal data. We share it only with the organisations below, for the purposes stated.

  • Revise (revise.id), the Society's platform provider, hosts this website, the publishing API, the submission portal and the production system on servers it operates for us. It processes personal data only to provide those services and on our instructions.
  • Crossref receives the bibliographic metadata of every article (including author names, affiliations and ORCID iDs) to register its DOI, and the metadata of corrections and retractions for Crossmark. Crossref makes this metadata openly available.
  • Indexing and discovery services such as Google Scholar and BASE harvest published article metadata from our pages and our OAI-PMH endpoint. This is how research is found.
  • Citation data providers. To show citation counts we look up each article's DOI at Dimensions, Crossref and OpenAlex from our servers; no reader data is sent. The Dimensions badge on article pages is loaded by your browser directly (section 7).
  • Resend, an email delivery service, transmits the messages sent by the submission portal and production system (invitations, decisions, confirmations). It processes recipient addresses and message content to deliver them.
  • Reviewers and editors see the manuscripts and author information needed to assess a paper, under the confidentiality rules in section 4.
  • Institutions and authorities may be contacted under our publication ethics policy when misconduct is suspected, or where the law requires disclosure.

Some of these organisations are outside Indonesia. Where personal data leaves the country we rely on the recipient's published commitments and, for scholarly metadata, on the fact that the data is intended for open publication.

Section 7 of 11

Third-party services in your browser

A few parts of our pages are fetched by your browser from other organisations' servers. Each of them therefore sees your IP address and basic browser information for that request. We list them all; none is used for advertising.

ServiceWhereWhat it does & what it sees
Google Fonts
Google LLC
Every page The Inter and Newsreader typefaces. Your browser requests the font files from Google, which sees your IP address and browser details. Google states it does not use these requests for tracking or advertising. Their notice ↗
Crossmark widget
Crossref
Article pages Shows whether an article has been corrected or retracted. The script is loaded from Crossref's servers; the status pop-up is fetched only when you click the Crossmark button. Their notice ↗
Dimensions badge
Digital Science
Article pages with a DOI Displays the article's citation count from the Dimensions database. Loading the badge sends the DOI and your IP address to Digital Science. Their notice ↗
MathJax and Chart.js
jsDelivr CDN
Article pages Open-source libraries for rendering mathematics and charts, served from the jsDelivr content-delivery network, which logs the request. Their notice ↗
ORCID icon
ORCID Inc.
Author lists A 16-pixel image loaded from orcid.org next to authors who have an ORCID iD. ORCID sees the image request. Their notice ↗

Share buttons on article pages are plain links: nothing is loaded from, or sent to, a social network until you click one. Our analytics and article-usage requests (section 2) go to servers operated for the Society, not to a third party.

Section 8 of 11

Cookies & local storage

This website sets no cookies, which is why it shows no cookie banner.

The only thing we store in your browser is the random session identifier described in section 2, held in session storage under the key oj_sid. It contains no personal information and disappears when you close the tab. The third-party services in section 7 may set their own cookies under their own notices; to our knowledge, the font, icon and library requests do not.

The submission portal and production system do use cookies, because you sign in to them: a session cookie that keeps you logged in, a security (CSRF) token, and, if you tick “remember me”, a longer-lived login cookie. These are strictly necessary for the service and are not used for tracking or analytics.

Section 9 of 11

How long we keep data

DataKept for
Server access logsAbout two weeks, then deleted automatically.
Site analytics (Umami)Aggregated statistics indefinitely; the daily visitor hash cannot identify anyone after the day it was made.
Article view and download eventsIndefinitely, as the basis of published usage statistics. They contain a hash, not an address, and are aggregated by month.
E-alert subscriptionsUntil you unsubscribe. Deactivated addresses are kept only to make sure we do not email them again, and are removed on request.
Portal accountsUntil you delete your account or ask us to. Inactive accounts may be removed after a period of notice.
Manuscript records, reviews and decisionsPermanently for published articles, as part of the scholarly record and to answer later questions about integrity. Rejected and withdrawn submissions are kept so that resubmissions, appeals and integrity questions can be handled, and are deleted on the author's request once no such matter is open.
Published article contentPermanently. See Digital preservation.
CorrespondenceAs long as the matter it concerns is open, and afterwards as part of any manuscript record it belongs to.
Section 10 of 11

Legal basis & your rights

The Society is established in Indonesia and processes personal data under Law No. 27 of 2022 on Personal Data Protection (UU PDP). Where the EU or UK General Data Protection Regulation applies to a reader or author, we aim to meet it too. Our grounds are:

  • Consent for e-alerts and for publishing editorial board photographs; you may withdraw it at any time.
  • Performance of an agreement for authors and reviewers using the submission portal and for producing accepted articles.
  • Legitimate interests in running peer review, keeping the scholarly record accurate, securing our systems and understanding how the site is used, none of which we consider outweighed by readers' interests given the minimal data involved.
  • Legal obligation where a law or court requires us to keep or disclose data.

You have the right to:

Access and correct

Ask what we hold about you and have inaccuracies corrected. Portal users can do most of this themselves in their settings.

Delete

Have your data erased where we no longer need it. Information forming part of a published article or its editorial record is exempt, because removing it would falsify the record; we will explain what we can and cannot do.

Object and restrict

Object to processing based on legitimate interests, or ask us to pause it while a dispute is resolved.

Withdraw consent and complain

Stop e-alerts at any time. If you are unhappy with our answer you may complain to the data protection authority in your country, or in Indonesia to the authority designated under the UU PDP.

To exercise any right, email admin@greensus.org from the address we hold, or tell us how to verify that the request is yours. We answer within the time limits set by the applicable law and do not charge for it.

Our services are intended for researchers and are not directed at children. We do not make decisions about individuals by automated means.

Section 11 of 11

Changes & contact

We will update this notice when our systems or the law change, and note the date at the top of the sidebar. A change that affects e-alert subscribers or portal users in a material way is announced by email or in News before it takes effect. This notice was last revised on 14 September 2026.

Privacy enquiries

Green and Sustainable Materials Society
Bandar Lampung, Indonesia
admin@greensus.org

Related pages: Publishing policies · Terms of use · Accessibility statement · Unsubscribe from e-alerts.