Last updated: September 9, 2026

IT & C respects the right to privacy and the protection of personal data.

This Privacy Policy explains what personal data we may collect, why we use it, the legal bases for processing, to whom it may be disclosed, how long it may be retained, and what rights data subjects have.

Personal data are processed in accordance with Regulation (EU) 2016/679 – the General Data Protection Regulation (GDPR) and applicable Romanian legislation.

1. Data Controller

The data controller is:

MultiMedia SRL
Tax Identification Number: RO 14965117
Trade Register No.: J2021004636402
European Unique Identifier: ROONRC.J2021004636402
Lt. Radu Beller 3-5
011701 Bucharest, Sector 1, Romania
Phone: +40 745 526 896
Email: office@multimedia.com.ro

For matters specifically related to IT & C:

contact@internetmobile.ro

MultiMedia SRL is the publisher of IT & C.

2. Scope

This policy applies to personal data processed in connection with:

  • the website www.internetmobile.ro;
  • communications with the Editorial Office;
  • manuscript submission and evaluation;
  • the activities of authors, reviewers, and members of the journal’s structures;
  • the Open Journal Systems (OJS) editorial platform used by the journal;
  • user accounts;
  • newsletters and subscriptions;
  • comments;
  • online-store orders;
  • forms and other services made available by the journal.

The OJS platform of MultiMedia Publishing Academic Journals may also have its own privacy statement applicable to platform-specific functions.

3. Processing Principles

Personal data are processed in accordance with the principles of:

  • lawfulness, fairness, and transparency;
  • purpose limitation;
  • data minimization;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • accountability.

We do not seek to collect personal data that are unnecessary for providing services, conducting the editorial process, or complying with legal obligations.

4. Categories of Personal Data We May Process

Depending on an individual’s relationship with the journal, we may process the following categories of data:

Identification Data

  • first name;
  • surname;
  • professional name;
  • academic or professional title;
  • username.

Contact Data

  • email address;
  • telephone number;
  • postal address where necessary for invoicing or delivery.

Professional and Academic Data

  • institutional affiliation;
  • position;
  • city and country;
  • fields of expertise;
  • professional biography;
  • publications;
  • CV;
  • ORCID iD;
  • institutional profile;
  • Google Scholar;
  • Web of Science Researcher Profile;
  • Scopus Author ID;
  • OpenAlex or other academic identifiers and profiles.

Editorial Data

For authors, co-authors, editors, and reviewers, we may process:

  • manuscripts and associated files;
  • submission history;
  • revised versions;
  • peer-review reports;
  • editorial decisions;
  • editorial comments;
  • declarations of competing interests;
  • funding information;
  • Data Availability Statements;
  • author contribution information;
  • communications related to the editorial process.

Order Data

For purchases, we may process:

  • products ordered;
  • order date and value;
  • billing address;
  • delivery address;
  • information required for invoicing;
  • payment status;
  • order history.

We do not intentionally store complete bank-card details where payment is processed by an external payment-service provider.

Technical Data

Depending on the functions used:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • date and time of access;
  • pages requested;
  • security logs;
  • error and technical-operation data.

Data Provided Voluntarily

We may also process other information voluntarily provided through:

  • email;
  • forms;
  • comments;
  • applications;
  • requests submitted to the Editorial Office;
  • other means of communication.

5. Purposes of Processing

Personal data may be used for the following purposes:

Website Administration

  • website operation;
  • account management;
  • infrastructure security;
  • prevention of fraud and abuse;
  • diagnosis of technical problems;
  • backups.

Editorial Process

  • receiving manuscripts;
  • identifying authors and co-authors;
  • selecting and contacting reviewers;
  • managing peer review;
  • communicating editorial decisions;
  • copyediting and production;
  • publication and archiving;
  • handling corrections, complaints, appeals, and integrity concerns.

Academic Publication and Metadata

For accepted works, professional data necessary to identify authors may be processed and published, including:

  • author name;
  • affiliation;
  • country;
  • ORCID;
  • contribution;
  • bibliographic information associated with the work.

This information may appear in the article, on the article page, and in metadata transmitted to academic services.

Indexing and Persistent Identification

Publication metadata may be provided to services such as:

  • Crossref;
  • ORCID, where the appropriate integration is used;
  • OpenAlex;
  • databases and indexing services;
  • libraries;
  • repositories;
  • aggregators;
  • preservation services;
  • academic search engines;
  • OAI-PMH-compatible services.

Administration of Journal Structures

Professional data of Editorial Board members, Scientific Advisory Board members, and other collaborators may be used for:

  • evaluation of applications;
  • role administration;
  • editorial communication;
  • publication of professional profiles;
  • transparent presentation of journal structures.

Online Store

Data may be processed for:

  • recording and fulfilling orders;
  • payment;
  • invoicing;
  • delivery;
  • handling returns and complaints;
  • compliance with tax and accounting obligations.

Communication

Contact data may be used for:

  • responding to inquiries;
  • communication with authors and reviewers;
  • order notifications;
  • administrative communications;
  • newsletters and promotional communications where an appropriate legal basis exists.

6. Legal Bases for Processing

Depending on the circumstances, processing may rely on one or more of the following legal bases under the GDPR:

Consent

Article 6(1)(a) GDPR, for example for:

  • voluntary newsletter subscriptions;
  • certain non-essential cookies and technologies;
  • certain marketing communications.

Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Performance of a Contract or Pre-Contractual Steps

Article 6(1)(b), for example for:

  • processing orders;
  • supplying products;
  • certain activities necessary for managing an editorial submission.

Legal Obligations

Article 6(1)(c), for example for:

  • accounting;
  • invoicing;
  • tax obligations;
  • responding to requests required by law.

Legitimate Interests

Article 6(1)(f), where necessary for legitimate interests such as:

  • website administration and security;
  • prevention of abuse;
  • protection of information systems;
  • preservation of the integrity of the scholarly record;
  • administration and documentation of editorial processes;
  • protection of the legitimate rights and interests of the journal and publisher.

7. Authors’ Data

Authors provide data necessary for:

  • identification;
  • manuscript administration;
  • editorial communication;
  • evaluation and publication;
  • DOI assignment;
  • generation and transmission of metadata.

For published articles, certain professional data become part of the public scholarly record.

These may include the author’s name, affiliation, ORCID, and other bibliographic elements necessary to identify the author and publication.

A personal email address will not be published automatically merely because it was provided in OJS, unless publication is necessary or the author has agreed to it.

8. Reviewers’ Data

Reviewer data are used for:

  • verification of expertise;
  • invitations to review;
  • administration of the peer-review process;
  • documentation of editorial activity;
  • prevention and management of competing interests.

Under the double-anonymous review process, the reviewer’s identity is not disclosed to the author.

Reviewer data are not published in association with a specific manuscript unless journal policy and the consent of the persons involved expressly permit this.

9. Editorial Team and Scientific Advisory Board Members

For persons who accept a public role in the journal’s structures, the following may be published:

  • name;
  • editorial role;
  • affiliation;
  • country;
  • field of expertise;
  • ORCID;
  • academic or institutional profile.

Publication of this information is necessary for transparency of the journal’s editorial structure and takes place in accordance with the member’s consent and accepted role.

10. Applicants for Editorial and Reviewer Roles

Persons submitting an application may provide:

  • CV;
  • contact details;
  • affiliation;
  • ORCID;
  • publications;
  • fields of expertise;
  • links to academic profiles.

These data are used solely for evaluating the application, verifying the information supplied, and, where the applicant is accepted, administering the collaboration.

An unsuccessful application may be retained for a reasonable period where the applicant has been informed that they may be considered for future collaboration or where another applicable legal basis exists.

11. Newsletters and Marketing Communications

Newsletters and promotional communications are sent only where an appropriate legal basis exists.

Where processing is based on consent, consent may be withdrawn at any time by:

  • using the unsubscribe link included in the message;
  • contacting the journal at contact@internetmobile.ro.

Withdrawal of consent does not affect necessary administrative communications concerning a manuscript, account, or order.

12. Comments

Where users post comments, we may collect:

  • data entered into the comment form;
  • IP address;
  • browser information,

for the purpose of preventing spam, abuse, and security problems.

Approved comments may become public together with the name or pseudonym chosen by the user.

Users should not include personal data relating to other individuals in comments without a legitimate basis.

13. Cookies and Similar Technologies

The website may use cookies and similar technologies for:

  • technical operation;
  • security;
  • storing preferences;
  • measuring website use;
  • other functions.

Strictly necessary cookies may be used to provide the requested service.

Non-essential cookies are used in accordance with the website’s applicable consent mechanism.

Detailed information is available in the Cookie Policy.

14. Analytics

The website may use analytics tools to understand how it is used and to improve its operation.

Depending on the service configuration, information processed may include:

  • pages visited;
  • duration of the visit;
  • device;
  • traffic source;
  • technical connection data.

Where such a service requires consent for cookies or other non-essential technologies, consent will be requested through the website’s consent mechanism.

15. Recipients of Personal Data

Personal data may be accessed or processed, to the extent necessary, by categories such as:

  • authorized MultiMedia personnel and collaborators;
  • editors involved in the editorial process;
  • reviewers, within the limits of the peer-review process;
  • hosting providers;
  • IT service providers;
  • email providers;
  • payment processors;
  • courier companies;
  • accounting service providers;
  • editorial infrastructure providers;
  • public authorities where required by law.

For academic publications, metadata legitimately intended for publication and indexing may be transmitted to databases, registers, libraries, repositories, DOI services, and other scholarly infrastructures.

16. Processors and External Services

Where external providers are used for hosting, email, payments, security, analytics, or other operations, they receive only the data necessary to provide the relevant service.

Depending on the circumstances, providers may act as processors or independent controllers in accordance with applicable law and their own policies.

17. International Data Transfers

Some academic, technical, or commercial services used by the journal may have infrastructure or recipients outside the European Economic Area.

Where personal data are transferred to a third country and the transfer falls within the scope of the GDPR, it must rely on an appropriate legal mechanism, such as:

  • an adequacy decision of the European Commission;
  • Standard Contractual Clauses;
  • other safeguards or derogations provided by the GDPR.

Academic metadata intended for publication are, by their nature, intended for international distribution for the purposes of citation, identification, and discovery of the publication.

18. Retention Period

Personal data are retained only for as long as necessary for the purposes for which they were collected and to comply with legal or legitimate obligations.

Retention periods may vary according to the nature of the data.

Editorial Data

Data necessary to document the editorial process may be retained long term for:

  • integrity of the scholarly record;
  • documentation of decisions;
  • resolution of ethical concerns;
  • corrections and retractions;
  • prevention of conflicts or duplication of editorial processes.

Publication Data

Authors’ names, affiliations, identifiers, and other metadata associated with a published work may be retained permanently, as they form part of the bibliographic and scholarly record of the publication.

Commercial and Financial Data

These data are retained for the periods required under applicable tax and accounting legislation.

Newsletter Data

Data are retained until the individual unsubscribes or until there is no longer a lawful basis for processing.

Technical Data

Logs and security data are retained for limited periods appropriate to security, diagnostic, and abuse-prevention requirements.

19. Data Security

We apply reasonable technical and organizational measures to protect personal data against:

  • unauthorized access;
  • loss;
  • destruction;
  • alteration;
  • unauthorized disclosure;
  • misuse.

Measures may include:

  • secure HTTPS connections;
  • access controls;
  • software updates;
  • backups;
  • server-level security measures;
  • limitation of user privileges;
  • monitoring of security incidents and unauthorized access.

No information system can guarantee absolute security.

20. Data Subject Rights

Subject to the conditions laid down by the GDPR, individuals may have:

  • the right to information;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability, where applicable;
  • the right to object;
  • the right to withdraw consent;
  • rights concerning automated individual decision-making, where such processing takes place;
  • the right to lodge a complaint with the supervisory authority.

These rights are not absolute. For example, a request for erasure cannot automatically result in removal of an author’s name from a published article where the data are necessary to preserve the integrity of the scholarly record, exercise freedom of expression and information, or comply with other legal obligations.

21. Exercising Your Rights

Requests concerning personal data may be sent to:

contact@internetmobile.ro

or:

office@multimedia.com.ro

To protect personal data, verification of the identity of the person making the request may be necessary.

We will respond within the period required by the GDPR, normally within one month of receiving the request. In complex cases, this period may be extended in accordance with the Regulation.

Exercising these rights is, in principle, free of charge.

Only where a request is manifestly unfounded or excessive, particularly because of its repetitive nature, may a reasonable fee be charged or the request be refused with justification in accordance with the GDPR.

22. Right to Erasure and Published Scholarly Literature

The right to erasure of personal data should not be confused with a right to unilaterally withdraw or delete a published academic article.

After publication, the author’s name and bibliographic metadata form part of the scholarly record of the work.

Corrections, retractions, or other changes to the scholarly record are handled under the Editorial Policy, not through simple deletion of bibliographic data.

Where published personal information is inaccurate, excessive, or no longer justified, the situation will be assessed individually.

23. Automated Decision-Making

The journal does not normally use exclusively automated decision-making processes that produce significant legal effects for authors, reviewers, or users.

In particular, acceptance or rejection of a manuscript is not decided automatically by software or artificial intelligence.

Automated tools may be used for technical support, for example for checks, security, or similarity detection, without replacing human editorial decision-making.

24. Children’s Data

The journal’s editorial services are intended primarily for adults and persons active in academic or professional environments.

We do not intentionally seek to collect personal data from children through services directed specifically at them.

Where an activity exceptionally involves data relating to minors, applicable legal requirements will be respected, including rules concerning consent of a legal representative where necessary.

25. Links to Other Websites

The website may contain links to external services.

Once an external website is accessed, the processing of the user’s data is governed by that service’s own privacy policy.

MultiMedia does not control the data-protection practices of external operators.

26. Personal Data Breaches

In the event of a security incident involving personal data, MultiMedia will assess the risk and take the measures required under the GDPR.

Where required by law, the incident will be notified to the supervisory authority and/or affected individuals.

27. Supervisory Authority

If you believe that your personal data are being processed in breach of applicable law, you have the right to lodge a complaint with:

National Supervisory Authority for Personal Data Processing – ANSPDCP
Bd. G-ral Gheorghe Magheru no. 28-30
Sector 1, Bucharest, Romania
Postal Code 010336

ANSPDCP provides procedures and forms for submitting complaints concerning the application of the GDPR.

28. Changes to This Privacy Policy

This policy may be updated to reflect:

  • legislative changes;
  • changes to services;
  • changes to technical infrastructure;
  • introduction or removal of service providers;
  • development of the editorial process;
  • changes in data-security practices.

The current version and date of last update are displayed on this page.

For significant changes, other reasonable means of notification may also be used where appropriate.

29. Contact

For questions or requests concerning personal data protection:

IT & C
Email: contact@internetmobile.ro

Controller:

MultiMedia SRL
Lt. Radu Beller 3-5
011701 Bucharest, Sector 1, Romania
Phone: +40 745 526 896
Email: office@multimedia.com.ro