In a nutshell
- Publishers, research institutions, funders, integrity bodies, and researchers worldwide trust Proofiger with the integrity and quality of their research. It’s our privilege and duty to protect their data and yours.
- Proofiger develops and operates Octym, a platform that reviews manuscripts, grant applications, and other research documents and surfaces suspected quality and integrity issues. Octym analyses the text, images, references, and author information contained in those documents, so personal data is processed as part of a review.
- Whoever submits a document to Octym — an institution, a publisher, or an individual researcher — decides why it is submitted and what review is performed, and is the Data Controller. We process it on their behalf and according to their instructions.
- We do not use your documents to train or improve AI models, ours or our providers’. We do not use them for benchmarking, research, marketing, or product development.
- Octym is not designed for identifiable health information and must not be used for it.
- We keep documents for a short period. Unless separately agreed, a document and its review results are retained for three months from submission, and you can delete them yourself at any time.
- If you use Octym on behalf of one of our customers, or if your personal data appears in a document reviewed on Octym, please approach the relevant customer (e.g. university, institution, funder, or publisher) regarding any question or request involving your data.
- Like most businesses, we also collect and process personal information of our website visitors, business contacts, customers, and their users.
- We respect your rights regarding your personal information.
- Have a question and can’t find an answer? Contact us, we’re here to help: [email protected] Now in more detail:
1. Introduction and Definitions
1.1 We are Proofiger Ltd. — simply referenced here as “Proofiger”, “we”, or “us”. You can find our contact details below.
1.2 Proofiger’s Software as a Service solution Octym — referred to here as “Octym” or the “Platform” — is intended for use by publishers, research institutions, research funders, research integrity bodies, and individual researchers — our “Customers” — to review scientific manuscripts, grant applications, and other research documents (generally referred to as “Documents” in this policy) and to identify suspected quality and integrity issues in them.
1.3 The party that submits a Document to Octym decides why it is submitting the Document and which review it wants performed, and controls the data processed on its account. That party is therefore the Data Controller in respect of the personal data contained in the Document, and Proofiger is the Data Processor, processing that data on the Controller’s behalf and according to its instructions. This applies whether the submitting party is an institution, a publisher, a funder, or an individual researcher.
1.4 Our Customers nominate the Platform’s “End-Users” on their account (for example authors, editors, reviewers, and research integrity staff), configure what those End-Users may do, including whether and how review results may be shared, and are responsible under our Terms of Service for handling data rights and data requests as Data Controllers.
To make things clear with an example: if you are an editor working for a publisher and you review manuscripts on Octym on the publisher’s behalf, then you are an End-User, the publisher is our Customer and has control over your personal data, and we process your personal data on the publisher’s behalf and according to its instructions. If you are an End-User and have any issue regarding your personal information, please contact the publisher first!
1.5 In addition, we operate our “Website” — octym.proofig.com — and collect personal data of “Visitors”. Some Visitors and other people who communicate with us become our business “Contacts” or Customers. We collect and process various personal information regarding our Visitors, Contacts, and Customers, and we are the Data Controller for such personal data. We are also the Data Controller for the account, authentication, billing, security, and usage data described in Section 3, which we process in order to operate and protect the Platform.
If you are a Visitor, Contact, or Customer of ours and have any issue regarding your personal information that we control, please contact us (details below).
1.6 Octym is a separate product from Proofiger’s Proofig platform. Use of the Proofig platform is governed by the Proofig Privacy Policy, separately. Your use of Octym is also governed by the Octym Terms of Service.
2. How Do We Collect Personal Data?
2.1 Contacts and Customers. There are several ways in which we may receive your personal data:
- When you share it with us directly, through your communication with us on the Website’s contact forms, by email, phone, in conferences, meetings, or via any other communication channel.
- When other Customers, Contacts, business partners, or third parties share your information with us, based on their interaction with you, their purposes, their legal bases, and their privacy policy. In such cases, we take responsibility for controlling only the personal data that we have received.
- We might augment the personal data we have about you with information you provided us directly, information others have provided us about you, and data we have collected about you from your use of our Website. 2.2 End-Users. We have limited personal information about you, received in one of two ways: our Customer provided us with your personal data, including through a single sign-on or authentication provider selected by the Customer; or you provided it to us directly through your use of Octym.
2.3 Individuals whose personal data appears in a Document. If you are an author, co-author, contributor, editor, reviewer, or another individual whose personal data appears in a Document, we receive that data because a Customer or End-User submitted the Document to the Platform. We do not obtain it from you, we do not contact you, and we have no relationship with you. The Customer that submitted the Document is the Data Controller in respect of your data and is responsible for informing you and for handling your requests. Please see Section 14.
2.4 Visitors. We might receive some personal data through your device, operating system, and browser, and various hosting, tracking, and analytics technologies used on our Website, such as cookies (see below). Our Website does not currently respond to “Do Not Track” signals sent by your browser or device.
3. What Personal Data Do We Process?
3.1 Contacts and Customers. We may collect and process these types of personal data about you: identification and account information, such as full name, username, and password; contact details, such as country and time zone, work address, phone numbers, and email address; work-related information, such as organization, division, department, role, educational information, and title; social networking information you have shared with us; payment and billing information; any personal data contained in photos, media, and other files sent to us; and any other personal data you provide us on any communication channel, such as email correspondence, customer support, and product feedback.
3.2 End-Users. Our Customers decide what data to share about their End-Users. These are the types of personal data about End-Users that we may process on Customers’ behalf: identification information, such as full name, username, and password; authentication and single sign-on information; contact details, such as email address; work-related information, such as organization, division, department, role, and title; and any other personal data our Customers share with Proofiger.
3.3 Personal data contained in Documents. The principal object submitted to the Platform is a Document. Depending on the review selected, a Document may contain main text, figures and tables, references, supplementary information included in the Document, ethics and funding statements, author and contributor information, and, for grant workflows, assembled application sections such as specific aims, research strategy, biosketches, facilities information, budget and justification, data management plans, and human-subject or animal-related sections. Such material may contain personal data relating to authors, co-authors, contributors, editors, reviewers, and other individuals named, described, or depicted in it. Octym does not control the contents of user-uploaded Documents.
3.4 Author and contributor information analyzed during a review. Where it is relevant to a selected check, Octym analyses information about authors and contributors, which may include names, affiliations, ORCID and other identifiers, authorship and contribution information, conflicts and disclosures, and funding and grant information. This analysis is performed to detect inconsistencies, errors, and potentially falsified information in the Document under review. It is carried out in connection with that Document and its review. Octym does not create a persistent identity profile, risk score, misconduct record, co-authorship map, or other record about any individual that outlasts the review or that is carried across Documents or across Customers.
3.5 Agent interactions. The Human Review Environment includes a conversational interface (the “Agent”). Prompts submitted to the Agent and the responses generated are associated with the review session of the relevant Document and are processed automatically.
3.6 Usage and technical data. We collect and process usage, logs, analytics, and other device and technical data when you use our Website or the Platform, including device information and identifiers, operating system information, IP address, browser and session information, browsing history and referrals, cookies information, language and connectivity information, file metadata, and usage information such as screen views, clicks, and usage time.
3.7 A note on how Octym differs. Octym analyses the text of Documents and information about the individuals named in them, and not only the images they contain. We describe this openly because it is material to understanding what the Platform does with personal data.
4. What About Personal Data of Children?
4.1 Octym is a technology platform for the review of scientific and research content and is not intended for children. We do not knowingly collect or process information about children. Please contact us (contact details below) if you have any concern with respect to children’s personal data on the Platform.
5. What About Health Information?
5.1 Octym is not designed, intended, or validated for the processing of identifiable health information. Our Terms of Service prohibit the submission to the Platform of individually identifiable health information, protected health information, patient records, patient-identifying images, and any other health or medical information relating to an identified or identifiable individual, and require that any human-subject, clinical, or patient-derived information in a Document be de-identified or anonymized before submission.
5.2 We do not represent that the Platform is compliant with HIPAA or with any other law, regulation, or standard governing the processing of health information, and we do not enter into business associate agreements or equivalent arrangements in connection with the Platform unless expressly agreed in writing.
5.3 The Platform does not screen for, detect, or flag prohibited health information. We may, at our discretion and without prior notice, refuse to process, restrict, quarantine, or delete any Document we believe contains it, and may suspend the relevant account. Submission of such information is at the sole risk and responsibility of the party submitting it.
6. What About Cookies?
6.1 A cookie is a small data file that your browser saves on your computer or mobile device. We use cookies to collect information and provide our services. We may use cookies to enable certain features, to understand how you interact with us, to monitor your usage of our Website and the Platform, and to personalize your experience. You can set your browser to prevent the use of cookies. If you do not accept cookies, our Website and the Platform may not function properly.
7. What Are the Purposes for Processing Personal Data?
7.1 On the Platform. The purposes for the processing of personal data on the Platform are determined by the party that submits the Document. A Customer may set End-Users to perform various activities, such as submitting a Document for review, reviewing the results, confirming or rejecting findings, generating a report, sharing review results within the limits the Customer configures, and administering the Customer’s account. Each Customer might use Octym for different purposes, which may include preparing a manuscript or grant application for submission, screening submissions against a journal’s or funder’s requirements, investigating concerns about published work, improving the quality of academic research, and maintaining the reputation of academic publications.
7.2 Our own purposes. Our purpose in processing data on the Platform is to provide our services to our Customers according to our Terms of Service and any agreement with them, and according to applicable law. We also process personal data in order to create, authenticate, and administer accounts; to provide customer support and to investigate and resolve technical problems, including where a Customer asks us to look into a specific Document, subject to the access restrictions described in Section 11; to ensure that the Platform works as intended and to protect the Platform, our company, our staff, and our Customers against misuse, abuse, and security threats; to bill and collect fees; and to comply with any applicable law and to assist law enforcement agencies under any applicable law.
7.3 What we do not do with your Documents. We do not use the content of Documents, or personal data contained in them, for the following purposes: training, fine-tuning, developing, or improving artificial intelligence models, whether ours or those of our providers; quality evaluation of our services, unless a Customer has separately authorised it; statistics or benchmarking; marketing; research; or product improvement and development.
7.4 Operational and statistical data. We may collect, use, and disclose aggregated and statistical information concerning the operation and usage of the Platform — such as volumes, processing times, and performance metrics — provided that it contains no content of any Document and does not enable the identification of any Customer, End-User, Document, or individual. Such information is not personal data, and we may use it for any purpose, including improving our services and marketing.
7.5 Website, Customers, Contacts, and Visitors. If you are a Customer, Contact, or Visitor, we may process your personal data for our own business purposes, including: delivering our products and services, improving them, and developing new features, products, and services; providing information about our company, products, and services; providing customer support, billing, and invoicing; contacting you via any communication channel, including email, phone, and messaging platforms; analyzing and optimizing Website and Platform traffic and usage; protecting our company, staff, Customers, and systems; recruitment, where you apply to work with us; online advertising; and direct marketing, from which you can always opt out by unsubscribing through links in any communication or by contacting us and notifying us accordingly.
8. What Is the Legal Basis for the Processing of Data?
8.1 On the Platform, as Data Processors. We process personal data on the Platform based on the following legal bases: processing is necessary for the performance of our contracts with our Customers or our partners; processing is necessary for compliance with a legal obligation to which we are subject as data processors; processing is necessary for the performance of a task carried out in the public interest, such as maintaining the integrity and quality of academic research; processing is necessary for the purposes of the legitimate interests pursued by us, such as the conduct of our business and the purposes for which we process personal data as detailed in this Privacy Policy; and, where applicable, the data subject has given us consent, for example when logging in to the Platform.
8.2 Our Customers as Data Controllers. As Data Controllers, our Customers usually process personal data on Octym on one or more of the following legal bases: processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary for the performance of a task carried out in the public interest, such as maintaining the integrity and quality of academic research; processing is necessary for the purposes of the legitimate interests pursued by the Customer or by a third party, such as conducting their business as academic institutions, funders, or publishers; or the data subject has given consent to the processing of his or her personal data for specific purposes communicated by the Customer.
8.3 Consent for personal data in Documents. We are generally able to obtain consent only from the person using Octym. Where a Document contains personal data relating to other individuals, we rely on the Customer or End-User submitting it having the legal right and all authorizations and consents required to submit that Document and to have it processed, as they represent to us under our Terms of Service. It is the Customer’s responsibility, and not ours, to inform those individuals and to obtain any consent that applicable law requires.
8.4 Website, Customers, Contacts, and Visitors. As Data Controllers for our Customers’, Contacts’, and Visitors’ personal data, we process personal data based on any or some of the following legal bases: the data subject has given us consent for specific purposes communicated in this policy; processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary in order to protect the vital interests of the data subject or of another natural person, or for the establishment, exercise, or defence of legal claims; processing is necessary for compliance with a legal obligation to which we are subject, for example the need to maintain billing records; and processing is necessary for the purposes of the legitimate interests pursued by us or our Customers, for example the conduct of our business, the development and delivery of our products and services, and their promotion and sale.
9. Who Is Your Information Shared With?
9.1 The Customer. For the delivery of our services, we share End-User and Platform data on the Platform with the Customer who is the Data Controller with respect to such data. Our Customers may select to share information with others, as stated in their respective privacy policies.
9.2 Sharing of review results by End-Users. The Platform allows an End-User to share a review page, its findings, and a report, subject to controls configured by the Customer’s organization administrator. All sharing options are disabled by default, and the Customer determines which, if any, are available to its End-Users. Where sharing is enabled and used, the shared material — which may contain personal data from the Document — becomes accessible to the recipients chosen by the End-User, who may be outside the Customer’s organization. The Customer and its End-Users decide whether, what, and with whom to share, and we are not responsible for a recipient’s use of shared material.
9.3 Our service providers. We use service providers for various processing activities needed for the performance of the Platform, our Website, our other services, our operations, and our business, and share information with them on a need basis. These currently include: cloud hosting, storage, and infrastructure providers; providers of artificial intelligence and language models used to perform checks and to operate the Agent; providers of specialist analysis services used within a review; help centre and customer support technology. We limit the information we share with each provider based on the business need in using it.
9.4 Third-party services selected by the End-User. The Platform may offer an End-User the option to use services provided by third parties as part of a review. Where an End-User elects to use such a service, the Document or parts of it may be transmitted to and processed by that provider, and that processing is subject to the provider’s own terms and privacy policy in addition to this policy.
9.5 Within our organization. We may share data with our staff, subsidiaries, affiliates, and contractors for the provision of our services and our operations, subject to the access restrictions described in Section 11.
9.6 Non-identifiable information. We may share non-personally identifiable and aggregate information for any purpose. Such data is not personal data and its sharing cannot be used to identify you.
9.7 Legal process. We may need to share your information with law enforcement agencies, courts of law, and other governmental organizations, if ordered to do so by competent bodies and according to applicable law.
9.8 Mergers and acquisitions. If we are involved in a merger, asset sale, financing, liquidation, bankruptcy, or the acquisition of all or part of our business by another company, we may share your information with that company and its advisors before and after the transaction date.
10. Do We Use Your Content to Train AI Models?
10.1 No. We do not use Documents, their content, or personal data contained in them to train, fine-tune, develop, or improve our models. Use of Customer content for research and development or model training is prohibited within our organization.
10.2 The Platform uses our own proprietary models and technology together with artificial intelligence models and services provided by selected third parties, and we may add, remove, replace, or change the models, providers, and infrastructure we use. We contract with the third-party providers we use on terms that prohibit the use of content transmitted to them for training or improving their models.
11. How Do We Safeguard Your Personal Data?
11.1 We take information security very seriously. To begin with, we limit personal data collection to the minimum required to provide the optimal value to both Customers and End-Users, and we do not attempt to identify any individual beyond what a selected check requires.
11.2 Automated processing and restricted access. Processing of Documents on the Platform is automated. Our employees cannot browse or access Customer Documents in the ordinary course. Access to a specific Document by a person at Proofiger is exceptional, is limited to a small number of specifically authorized senior personnel, and occurs where a Customer asks us to investigate or assist with a particular Document or problem. This is exceptional support access and not routine review of Customer content.
11.3 We implement appropriate security standards to prevent unauthorized or excessive access, maintain data accuracy, and ensure the correct use of information. We encrypt data in transit and at rest, and we securely back up information to avoid data loss. We also implement appropriate organizational measures to protect your information. We apply our security standards when working with business and technology partners. Unfortunately, although we make every effort to keep your data safe, we cannot fully ensure or warrant the security of your personal information.
12. Do We Transfer Personal Data Internationally?
12.1 Documents and other information on the Platform are stored on cloud infrastructure provided by Amazon Web Services, in [• region(s)]. Our research and development and customer support functions are located in Israel.
12.2 At the same time, our business is international. We serve Customers around the world and we use providers and service providers in various countries, including providers of artificial intelligence models and specialist analysis services. We therefore transfer, store, or otherwise process personal information in other countries. We take appropriate safeguards in the selection of our processing vendors around the world to require that personal information is well protected, and we put in place the transfer mechanisms required under applicable law. Despite our efforts, it may be the case that a country where your personal information is processed has different, or less protective, data protection and privacy regulation than the country you live in.
13. For How Long Do We Keep Personal Data?
13.1 Documents and review results. Octym is not intended to serve as a long-term storage system for Documents. Unless otherwise agreed in writing with a Customer, we retain a submitted Document and the results of its review for three months from the date of its submission, after which we may delete them, and we may choose instead to anonymize them in a way that does not enable the identification of any individual. A Customer or End-User may delete a submitted Document and its results at any time, and may back up data from the Platform on their own systems within the retention period.
13.2 Other data. We keep other personal information we collect for different periods, depending on the type of information, for example: the period of our contract with our Customers, including a post-termination period as agreed with them; legal requirements regarding certain types of data, such as billing records; and other factors. Generally speaking, we retain personal information for a period reasonably needed to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. We also retain personal information for as long as necessary to resolve disputes, enforce our rights and agreements, and protect our staff and Customers.
13.3 Deletion. If we no longer need your information for the purposes mentioned in this Privacy Policy, we will delete or anonymize it. On certain occasions we might not be able to fully delete or anonymize personal information for technical or operational reasons, for example deletion from backup storage and archives. In such cases, we take reasonable measures to secure any information still maintained by us according to our standard data security practices.
13.4 After termination. Following the termination of our contract with a Customer, and unless the Customer instructs otherwise in advance, personal data stored on the Customer’s account will be deleted or anonymized in a way that does not enable the identification of a natural person, unless there is a legal reason or legitimate interest for us to retain it. We may keep the personal data of the Customer and its representatives after termination for any legitimate business or legal purpose, including all purposes stated in this Privacy Policy.
13.5 Copies held by Customers. Please be aware that our Customers may also retain, on their own systems and computers, copies of personal data obtained through the Platform, including downloaded reports and shared review results, even after we have completed the provision of our services, ended our contractual relationship, and deleted or anonymized data related to the Customer’s account. Such retention is subject to the Customer’s privacy policy, purposes, legal bases, agreements with data subjects, and any applicable law. We take no responsibility for Customers’ use of personal data outside the Platform.
14. What Are Your Rights With Respect to Your Personal Data?
If you are an End-User using the Platform, or your personal data appears in a Document reviewed on the Platform, please approach the relevant Customer — the publisher, university, institution, or funder that submitted the Document or asked you to use the Platform — to exercise any rights you may have, as they are the Data Controller of your personal information. Otherwise, please contact us (details below).
14.1 According to the data protection and privacy regulation where you live, you may have certain rights with respect to your personal information. Your rights may include, under certain terms and conditions set in the EU General Data Protection Regulation or other applicable law:
- Right of Access to your personal data processed by us;
- Right to Rectification of inaccurate or incomplete personal data;
- Right to Erasure of your personal data (“Right to be Forgotten”);
- Right to Restriction of Processing for a certain period or under certain conditions;
- Right to Data Portability of your personal data to another data controller in a structured format;
- Right to Object to the processing of your personal data. Specifically, you have the right to object to further processing of your personal data for direct marketing purposes;
- Right Not To Be Subject to a Decision Based Solely on Automated Decision-Making. Octym is a decision-support tool. Its findings, assessments, and reports are presented to a person for review, and a person makes any decision. We do not make any decision with legal or similarly significant effect based solely on automated processing, and our Terms of Service require our Customers not to do so either;
- Right to File a Complaint with the applicable data protection authority in your country. 14.2 Where the Customer as Data Controller does not have the ability to address a request, we will provide the Customer with reasonable assistance to facilitate the request to the extent possible and required by applicable law.
14.3 After deletion or anonymization of your personal data following its retention period, the rights to access, erasure, rectification, and data portability cannot be enforced.
14.4 Your personal information is processed based on several legal bases, including your consent. You can withdraw your consent at any time. Other legal bases, including statutory or contractual requirements that apply to you or to our Customer, might remain intact even following the withdrawal of your consent.
15. Do We Ever Change Our Privacy Policy?
15.1 Occasionally, we change this Privacy Policy to accommodate product and service development, industry standards, or new regulation. If we have your contact details, we will let you know personally if such changes are material, and seek consent for the updated Privacy Policy where required and as needed.
15.2 Please read the latest Privacy Policy available here from time to time. Note that we may require your consent to our up-to-date Terms of Service and Privacy Policy whenever you use our Website or the Platform. If you do not agree to these terms and this policy, please do not use our services.
16. Who Can You Contact Regarding Your Personal Data?
If you are an End-User using the Platform, or your personal data appears in a Document reviewed on the Platform, please contact the relevant Proofiger Customer (e.g. publisher, university, institution, or funder) first with any issue, as they are the Data Controller of your personal information.
You can contact us with any question or concern you have at:
Proofiger Ltd.
15 Carmel St., Rehovot, Israel
Email: [email protected]