Legal

Privacy
Policy

We are committed to safeguarding the privacy of individuals who entrust us with their information — particularly those sharing sensitive details as part of their journey toward resilience.

Who We Are

Parting Glass Foundation Inc. (the "Foundation," "we," "us," or "our") is a Missouri-based 501(c)(3) nonprofit organization dedicated to providing trauma healing and resiliency support through retreats, events, and workshops for military personnel, veterans, and their families.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website (www.partingglass.org), engage with our services, or interact with us in any way.

As a U.S.-based organization with operations in Europe, we comply with applicable U.S. laws and the EU's General Data Protection Regulation (GDPR) for any processing of personal data of individuals in the EU/EEA. For GDPR purposes, we are the data controller.

Information We Collect

We collect information to support our mission of fortifying warriors for their journey home. The types of information we may collect include:

  • Personal Information — Name, email address, phone number, mailing address, and country of residence.
  • Demographic Information — Age, gender, veteran status, or military affiliation.
  • Payment Information — Donation details, processed securely via third-party providers. We do not store payment card data.
  • Sensitive Personal Information — Health-related data, including mental health history, trauma experiences, PTSD symptoms, or resiliency needs, which may be shared during retreat applications, surveys, or program participation. This is considered "special category" data under GDPR and is collected only with your explicit consent.
  • Automatically Collected Information — Device and usage data such as IP address, browser type, operating system, pages visited, and time spent on our site, collected via cookies and analytics tools.

We collect this information directly from you via forms, applications, or communications, or indirectly from partners such as therapists or veteran organizations, or through website analytics tools.

How We Use Your Information

We use your information solely to advance our charitable purposes. Specific uses include:

  • Processing retreat applications, facilitating workshops, and delivering resiliency resources.
  • Communicating with you about programs, updates, or opportunities that align with your interests.
  • Processing donations and issuing receipts.
  • Analyzing data to enhance program effectiveness, measure outcomes, and report on our impact.
  • Ensuring operational security and compliance, including fraud prevention.

Under GDPR, our legal bases for processing are:

Consent For sensitive health data or marketing communications.
Legitimate Interests Service delivery and program improvement, where not overridden by your rights.
Contractual Necessity Fulfilling a retreat participation agreement.
Legal Obligation Tax reporting for donations and other regulatory requirements.

We do not use your information for automated decision-making or profiling that produces legal effects.

Sharing Your Information

We treat your information with the confidentiality expected in SOF communities — shared only on a need-to-know basis. We may share information with:

  • Service providers such as therapists, facilitators, or payment processors, who are bound by confidentiality agreements.
  • Partners for collaborative program delivery, with your consent where required.
  • Legal authorities if required by law, such as for safety concerns or valid legal process.

We do not sell, rent, or trade your information. For international data transfers we use safeguards such as EU Standard Contractual Clauses to ensure GDPR-equivalent protection.

Sub-processors

To operate this site and our programs, we rely on a small set of vendors who process limited personal information on our behalf. We disclose them here in keeping with GDPR Article 13(1)(e) and equivalent U.S. state-law requirements. Each is bound by a written data-processing agreement and processes data only for the purpose listed below.

Processor Data processed Purpose Location
Cloudflare, Inc. All site traffic; encrypted storage of donor, subscriber, and program-operational records; gated staff routes. Hosting, content delivery, access control, durable storage (Workers, R2, D1, Access). United States
Amazon Web Services, Inc. Travel-itinerary documents (passenger name, confirmation code, flight detail) submitted by program participants. Structured-data extraction via Amazon Bedrock under a signed HIPAA Business Associate Agreement. Anthropic, PBC is AWS's downstream sub-processor for the underlying Claude model; Anthropic does not receive data directly from us. United States
Resend (Resend, Inc.) Outbound transactional email (form acknowledgments, broadcasts) and inbound forwarded itinerary attachments. Email delivery and inbound-email webhook routing. United States
monday.com Ltd. Subscriber email + segment label; donor classification (individual / organization). Constituent cultivation pipeline and donor segmentation. United States operations (parent entity in Israel)
Zeffy (Simplyk Inc.) Donor name, contact, donation amount and metadata. Donation acceptance and donor record ingestion. Canada
Intuit Inc. Donor and vendor names, donation and disbursement amounts, journal entries. Bookkeeping and IRS-required nonprofit accounting in QuickBooks Online. United States
Google LLC (Workspace) Staff email and calendar only. Not used to process program-participant records. Internal staff communications. United States
Microsoft Corporation (Azure) Short audio segments transcoded during live Ukrainian-to-English interpretation when staff use the operational translator. Not stored. Real-time speech translation via Azure AI Speech. United States / Germany West Central region

This list reflects sub-processors as of 13 May 2026. Material changes are reflected in the "Last reviewed" date in the sidebar; a complete revision history is available on request to info@partingglass.org.

Data Security

We implement robust security measures to protect your data:

  • Encryption for data in transit and at rest.
  • Access controls limited to authorized personnel.
  • Regular security reviews and staff training.
  • Industry-standard practices for handling sensitive health data.

Despite these measures, no system is impenetrable. In the event of a breach, we will notify affected individuals and relevant authorities as required by law — within 72 hours under GDPR where applicable.

Your Rights

You have rights over your data. These rights empower you to control your own narrative:

Access
Request a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete information.
Erasure
Request deletion of your data under certain conditions, including withdrawal of consent.
Restriction
Limit how we process your data while we verify accuracy or handle an objection.
Objection
Object to processing based on legitimate interests.
Portability
Receive your data in a structured, machine-readable format.
Withdraw Consent
At any time, without affecting the lawfulness of prior processing.
Lodge a Complaint
EU residents may contact their local supervisory authority at any time.

To exercise any of these rights, contact us using the details below. We respond within one month. There is no fee unless requests are manifestly unfounded or excessive. Providing personal data is voluntary but may be necessary to participate in certain programs.

Cookies & Tracking

Our website uses cookies for functionality and analytics:

  • Essential cookies — Required for basic site operation. Cannot be disabled.
  • Analytics cookies — Help us understand how visitors use the site so we can improve it (e.g., Google Analytics via Google Tag Manager).

We do not use advertising or tracking cookies for commercial purposes. You can manage or disable cookies at any time through your browser settings. Note that disabling certain cookies may affect site functionality.

Embedded Content

Pages on this site may include embedded content such as videos, images, or third-party widgets. Embedded content from other websites behaves as if you had visited those websites directly — they may collect data about you, use cookies, embed additional tracking, and monitor your interaction with that content.

We recommend reviewing the privacy policies of any third-party services whose content appears on our site.

Children's Privacy

Our programs and services are intended for adults. We do not knowingly collect personal data from minors under the age of 13 without verifiable parental consent. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe we may have collected information from a minor, please contact us immediately.

Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy:

  • Participant records — Up to 7 years post-participation for outcome tracking and legal compliance.
  • Donation records — As required by IRS regulations, typically 7 years.
  • Communications — Retained as long as necessary to provide services or as required by law.

We delete or anonymize data once retention periods expire.

Changes to This Policy

We review this policy annually or whenever our practices materially change. Continued use of our website after changes are posted constitutes acceptance of the updated policy. For significant changes, we will provide notice via email or a prominent notice on our website.

The date of the most recent review appears in the sidebar. Prior versions are available upon request.

Contact Us

For questions about this policy, to exercise your data rights, or to raise a concern:

Parting Glass Foundation Inc.

Missouri 501(c)(3) · EIN: 39-4336247
Email: info@partingglass.org
Website: www.partingglass.org

EU residents who are unsatisfied with our response may lodge a complaint with their national data protection supervisory authority or the lead authority in their jurisdiction.