Home / Data Processing Agreement
Who is responsible for what data on the platform - the organizer's role, our role, and our duties as processor, in plain words.
Last updated: 23 August 2026
This page states the standard data-processing terms that apply automatically to every venue on AMS. Institutions that need a countersigned copy for their records can request one at info@techfist.org.
When a university, society, or organizing committee ("the Organizer") runs a conference or journal on the Article Management System, the manuscripts, author details, reviews and decisions of that venue are the Organizer's data - not ours. This Data Processing Agreement ("DPA") records, in writing, who is responsible for what. It forms part of the Terms of Service and applies to every venue hosted on AMS by an independent organizer.
The Organizer is the Data Controller for their venue's data: submitted manuscripts and files, author and co-author personal details, reviewer identities and reviews, editorial decisions, and correspondence sent through the venue. The Organizer decides why and how that data is used - Technology Fist does not.
Technology Fist is the Data Processor for that same data: we host it, store it, back it up, deliver the emails the workflow sends, and process it only as needed to operate the platform's documented functions and to follow the Organizer's lawful written instructions.
Technology Fist is itself the Data Controller - not a processor - for: user accounts on the platform, billing and payment records, security and audit logs, venues that Technology Fist itself operates, and the permanent published record in the Technology Fist Digital Library.
Hosting and storage of venue data; automated workflow processing (submission, review assignment, decisions, notifications); scheduled backups; email delivery on the venue's behalf; and payment references where a fee is collected (full card details never touch our servers - they go directly to the payment gateway, which acts as its own controller for them).
We process venue data only for operating the service and on the Organizer's instructions. Our staff access it only where support requires it and under confidentiality. We protect it with the platform's security measures: encrypted storage of credentials and secrets, salted password hashing, optional two-factor authentication, role-based access control, security audit logs, and routine backups. We notify the Organizer without undue delay on becoming aware of a personal-data breach affecting their venue, assist with data-subject requests directed to their venue, and, at termination of a venue's subscription, return or delete the venue's unpublished data on written request - subject only to what the law requires us to keep and to the permanence of anything already published (see the Data Retention Policy).
We use a small set of infrastructure providers to run the service: our hosting provider (servers and backups), our email delivery route, and - only where a venue collects fees - the payment gateway named at checkout. We remain responsible for our sub-processors' handling of venue data. A current list is available on request.
The platform's servers may be located outside the Organizer's country. By using AMS, the Organizer authorizes processing on our hosting infrastructure, protected by the measures in section 4 regardless of location.
This DPA applies for as long as the Organizer's venue is hosted on AMS, and its obligations about retention and deletion survive termination. It is governed by the same law and jurisdiction as the Terms of Service. Questions, instructions, and requests: info@techfist.org.