At Discovery Publishers, we believe in the “privacy by design” principle. This policy explains how we handle personal data for our authors, readers, and partners.
1. Data Controller & Compliance (GDPR/CCPA)
For the purposes of the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), Discovery Publishers acts as the Data Controller.
- EU Residents: We process your data based on “Legitimate Interest” (to evaluate and manage publishing contracts) and “Contractual Necessity” (to fulfill our obligations to you as an author or reader).
- California Residents: We do not “sell” your personal information as defined by the CCPA.
2. Information We Collect & How We Get It
We collect minimal data through the following channels:
- Manuscript Submissions: Name, email, and professional history provided by you.
- Book Distribution: If you download a digital copy or ARC (Advance Review Copy) of our books, we receive your email address and name to ensure delivery.
- Direct Communication: Correspondence via email or secure messaging.
3. Mailing Lists & Third-Party Processors
While we do not currently run a high-frequency newsletter, we may use your email (obtained via BookFunnel or direct consent) to send sporadic updates regarding new releases or author news.
- Service Providers: We may use third-party processors like Mailchimp or similar platforms to manage these communications.
- Opt-Out: Every email will include a clear “Unsubscribe” link. We do not engage in automated profiling or “shadow” tracking.
4. Data Security & Storage
We treat your manuscripts and personal data with the highest level of technical caution:
- Encryption: All sensitive files are stored using industry-standard encryption (AES-256).
- Minimal Exposure: We prioritize local processing on secure hardware and minimize the use of third-party cloud “SaaS” tools that harvest telemetry.
- Retention: We keep submission data for the duration of the evaluation process. For signed authors, data is kept for the life of the contract plus any legally required tax/accounting periods.
5. Your Rights
Under GDPR and CCPA, you have the following rights:
- Access & Portability: You can request a copy of the data we hold.
- Erasure: You can request that we delete your personal data (the “Right to be Forgotten”), provided it does not conflict with our legal or contractual obligations.
- Correction: You can ask us to update inaccurate information.