Privacy Policy
Effective Date: November 11, 2025
Contact: [email protected] | (310) 390-6612
Website: https://didihirsch.org
1. Purpose and Scope
Didi Hirsch Mental Health Services (“Didi Hirsch,” “we,” “our,” or “us”) is a California-based 501(c)(3) nonprofit organization providing mental-health, substance-use, and suicide-prevention services.
We are a HIPAA-covered entity for clinical operations and a nonprofit for community education, training, and fundraising activities.
We collect and use information to support our mission of providing equitable, trauma-informed, and culturally responsive care.
This Policy explains how we collect, use, share, and safeguard information obtained through our websites, online forms, email communications, virtual events, and donation platforms (collectively, the “Site”).
When you receive or inquire about clinical or behavioral-health services, your data may constitute Protected Health Information (PHI) and is then governed by our Notice of Privacy Practices (HIPAA).
2 Information We Collect
| Category | Examples | Purpose |
|---|---|---|
| Personal Identifiers | Name, email, phone | Service coordination and communication |
| Transaction Data | Donation or event registration info | Payment processing and receipts |
| Technical Data | IP address, device type, cookies | Website functionality and analytics |
| Sensitive Data | Health or demographic info | Care coordination or equity reporting (with consent) |
A. Information You Provide Directly
Includes information submitted through service, referral, donation, employment, volunteer, media, or training forms—such as contact details, program preferences, payment data, and optional demographics.
B. Information Collected Automatically
IP address, approximate location, browser and device type, pages visited, and analytics identifiers (see § 11).
C. Sensitive or Health-Related Information
If you describe symptoms, crises, or service needs in a form, that information becomes PHI once entered into our clinical systems and is protected under HIPAA and 42 CFR Part 2.
Sensitive data such as race, ethnicity, gender, or disability is collected only when voluntarily provided or required by law.
3 Legal and Operational Bases for Use
We process information to:
- Deliver requested services and respond to inquiries.
- Administer donations and maintain required financial records.
- Operate legitimate nonprofit interests such as education and quality improvement.
- Comply with laws and regulations.
- Protect vital interests, including life-safety and crisis response.
- Act with your consent when required (e.g., using a testimonial or photo).
4 How We Use Information
We use information to: provide services, process donations, communicate updates, analyze Site performance, recruit personnel, and ensure accessibility and equity.
We never sell personal or donor data and never use PHI for marketing without authorization.
5 When and How We Disclose Information
We share information only when necessary and under strict controls:
- Service Providers performing functions such as donation processing, email distribution, cloud hosting, analytics, or security.
- Legal and Safety Obligations to comply with laws or protect individuals from harm.
- Program Transitions if operations merge or reorganize, with confidentiality protections.
- With Consent for donor recognition or stories.
All vendors must meet privacy and security standards equal to HIPAA and CPRA requirements.
6 Third-Party Vendors and Examples
- Blackbaud / JustGiving / Stripe / PayPal – Donation processing (PCI-DSS Level 1)
- Constant Contact / Mailchimp – Email distribution and event invitations
- Google Analytics / Tag Manager – Website analytics and performance
- Microsoft 365 / Salesforce Nonprofit Cloud – Secure document and constituent management
Vendors are periodically reviewed and contracted under written data-protection obligations.
7 Data Security and Incident Response
We maintain administrative, technical, and physical safeguards:
- 256-bit SSL/TLS encryption in transit
- Multifactor authentication and role-based access
- Annual HIPAA and cybersecurity training
- Encrypted backups and disaster recovery
- Continuous intrusion and malware monitoring
If a data incident occurs, we activate our incident-response plan: containment, forensic review, notification to affected individuals, and regulatory reporting per HIPAA and state law.
8 Donations and Financial Information
- All donations are processed via PCI-compliant vendors; we do not store full payment data.
- Recurring donations use tokenized credentials.
- Donor records are retained seven years for IRS and audit purposes.
- Anonymous donations are respected.
- Opt out of future solicitations any time via [email protected].
9 HIPAA and Protected Health Information (PHI)
PHI is used and disclosed only for treatment, payment, and health-care operations. We execute Business Associate Agreements with vendors handling PHI and never use PHI for marketing without authorization.
For details, see our Notice of Privacy Practices (HIPAA) or request a copy at [email protected].
10 Cookies, Analytics, and Tracking Technologies
We use cookies and similar tools to remember preferences, analyze traffic, and enhance security.
| Type | Purpose | Retention |
|---|---|---|
| Essential | Enable core functions | Session |
| Analytics | Aggregate performance data (Google Analytics) | 26 months |
| Performance | Load balancing and speed | 12 months |
You can disable cookies in your browser. We do not respond to “Do Not Track” signals. Opt out of Google Analytics at tools.google.com/dlpage/gaoptout.
See our Cookie & Tracking Notice for additional detail.
11 Automated Tools and AI
We use limited automated technologies, spam filters, form validation, and analytics, to protect and improve our Site. These tools never make decisions about service eligibility or care.
12 Third-Party Links and Social Media
Our Site may link to external sites or embed social content. We do not control those platforms. Pages protected by Google reCAPTCHA are subject to the Google Privacy Policy and Terms of Service.
13 Email and Text Communications
- Marketing emails include unsubscribe links.
- Transactional emails (e.g., receipts or policy updates) may still be sent.
- SMS programs are optional; reply STOP to cancel, HELP for assistance. We do not share contact information for third-party advertising.
| Record Type | Typical Retention | Legal Basis |
|---|---|---|
| Clinical records (PHI) | ≥ 10 years or per law | Health record rules |
| Donor records | 7 years | IRS and audit |
| Website logs / analytics | ≤ 26 months | Security analysis |
| HR applications | 3 years | Employment law |
| General inquiries | 2 years | Operational needs |
We regularly review retention schedules to ensure compliance with evolving laws and grant requirements. Data slated for deletion is securely erased or de-identified under NIST SP 800-88.
15 Children and Youth Privacy
Our public Site is not intended for children under 13. We do not knowingly collect data from children online. Youth accessing crisis or clinical services are protected under federal and state confidentiality laws and our NPP.
16 California Privacy Rights (CPRA)
Although most nonprofits are exempt, we may voluntarily honor CPRA principles.
| Right | Description |
|---|---|
| Access / Portability | Request a summary of personal data we maintain (excluding PHI). |
| Correction | Request correction of inaccurate data. |
| Deletion | Request deletion where permitted by law. |
| Opt-Out | We do not sell or share personal data. |
| Authorized Agent | Designate an agent to submit a request on your behalf. |
| Appeal | If a request is denied, email [email protected] with subject “Privacy Rights Appeal.” |
| Non-Discrimination | We will not deny services for exercising privacy rights. |
We verify identity before fulfilling requests and respond within 45 days.
17 Cross-Border Data Transfers
Our systems are hosted in the United States. International users consent to transfer and processing here. We apply reasonable contractual and technical safeguards, including standard contractual clauses where required.
18 Updates to This Policy
We may revise this Policy periodically. Material changes will be posted on our homepage or communicated by email. We archive previous versions and make them available upon request.
19 Contact Us
Didi Hirsch Mental Health Services
Compliance & Privacy Office
4760 Sepulveda Blvd., Culver City, CA 90230
[email protected]
(310) 390-6612
You may also report accessibility issues or suspected privacy violations to this address.