PSVa Privacy Policy
Personally Identifiable Information (PII)
Information Security & Data Retention
Data Access
Data Disposal and User Deletion Requests
Third Party Privacy Policy Links
Your Choices & Controls
Personally Identifiable Information (PII)
In order to provide services and outreach, Postpartum Support Virginia (PSVa) collects the following Personally Identifiable Information (PII):
- Direct identifiers – First name, last name, date of birth
- Contact information – Mailing address, billing address, email address, phone number
Demographic information is collected directly from forms provided on the website, email, phone call or text conversation, or through forms linked to QR codes at in-person events. Only staff members who need the information to perform a specific job are granted access to the relevant PII.
PSVa is the sole owner of the information you voluntarily provide from this website. We use your PII to provide requested services, facilitate events, process donations, and develop partnerships. We will never share or sell your PII to anyone outside our organization, although we may share aggregated, non-personal data with third parties.
PII may be automatically shared with one or more software platform partners – Google Analytics, Kindful, MailChimp, ECINS, and Unite Us. No mobile information will be obtained from and/or shared with third parties or affiliates for marketing or promotional purposes. All the PII categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. You can always decline or stop receiving messages by responding “STOP” at any time. Reply “HELP” for more information. Message and data rates may apply. Message frequency varies.
We do not exercise control over third-party websites, which may place their own cookies or other files on your computer, collect data, or solicit personal information from you. External websites have their own security and privacy policies that govern your activity on their website.
PSVa uses the following applications: Microsoft 365, Google Analytics, Meta (Facebook/Instagram), Kindful, MailChimp, ECINS, Nextiva VOIP services, Airtable, Teamwork, QuickBooks and Unite Us. To support advertising and tracking, PSVa may employ the following tools: Remarketing, Impression Reporting, data collection via advertising cookies and anonymous identifiers, DoubleClick Campaign Manager integration, Demographics and Interest Reporting. To implement these tools, PSVa and third-party vendors use first-party cookies and third-party cookies together to inform, optimize, and serve ads based on past visits to PSVa webpages. These cookies collect information about visits to the PSVa website, but do not collect PII.
Information Security & Data Retention
We take precautions to protect your information. The computers/servers in which we store PII are kept in a secure environment.
We retain personal data for only as long as necessary to fulfill the purposes for which it was collected, in accordance with legal, contractual, and operational requirements. The retention periods for different categories of data are as follows: (PII):
- User Account Data – Retained as long as the user maintains an active account. If an account remains inactive for 2 years, it may be deleted or anonymized.
- Transaction and Billing Data – Stored for 7 years to comply with financial regulations and audit requirements.
Data Access
Access to personal data is restricted to authorized personnel and service providers who require it for operational, legal, or security purposes. This includes:
- Internal staff with data protection training
- Trusted third-party service providers, bound by confidentiality and data processing agreements
- Regulatory authorities if required by law
All access is managed with strict access controls and logging mechanisms to prevent unauthorized use.
Data Disposal and User Deletion Requests
Users have the right to request the deletion of their personal data in accordance with GDPR requirements. Upon receiving a valid request for:
- Data Deletion – Personal data linked to internal systems will be erased or anonymized, except for data required to be retained for legal or regulatory compliance.
- Third-Party Processors – If data has been shared with third parties, we will request deletion as per our agreements with them.
For general data disposal, we ensure:
- Digital data is securely deleted using industry-standard methods.
- Physical records (if any) are securely shredded and disposed of.
Users may submit deletion requests via psvadata@data.postpartumva.org, and we will respond within the legally mandated timeframe.
This policy is reviewed and updated periodically to ensure compliance with GDPR and other applicable regulations.
Third Party Privacy Policy Links
Airtable
ECINS
Google Analytics
Kindful
MailChimp
Meta (Facebook/Instagram)
Microsoft
Nextiva VOIP Services
Teamwork
Unite Us
Your Choices & Controls
You may opt out of any future contacts at any time. You can email psvadata@data.postpartumva.org to:
- Learn what data we have about you
- Change any data we have about you
- Delete any data we have about you
- Express any concern you have about our use of your data