Privacy Policy

Last updated: February 2026

1. Overview

The Pillar Project Corporation ("we," "our," "us") is a registered 501(c)(3) nonprofit organization committed to protecting the privacy and safety of all individuals who use our services. This policy describes how we collect, use, store, and protect personal information.

Given the nature of our work with survivors of domestic violence, human trafficking, and sexual assault, we maintain the highest standards of data privacy and confidentiality.

2. Information We Collect

Survivor/Client Information: Name, contact information, case details, and service records collected during intake and advocacy. This information is encrypted at rest using AES-256 encryption.

Partner/Agency Information: Organization name, contact person, credentials, and referral data submitted through our Partner Portal.

LAP Report Data: Lethality Assessment Program reports containing victim and incident information, submitted by law enforcement and agency partners. All sensitive fields are encrypted at the field level.

Website Visitors: Basic analytics data. We do not use tracking cookies for advertising.

3. How We Use Information

We use collected information solely to:

  • Provide crisis intervention and advocacy services
  • Coordinate emergency resources (shelter, legal aid, medical care)
  • Manage cases and track service delivery
  • Generate anonymized, aggregate reports for grant compliance
  • Communicate with clients about their services

We never sell, share, or disclose personal information to third parties for commercial purposes.

4. Data Security

  • Encryption: Sensitive fields (victim names, contact info, addresses, incident details) are encrypted using AES-256-GCM at the field level before storage
  • Access Control: Role-based access control (RBAC) restricts data access to authorized personnel only
  • Multi-Factor Authentication: Required for all admin and partner accounts accessing sensitive data
  • Audit Logging: Every access, modification, and export of sensitive data is logged with timestamp, user identity, and IP address
  • Session Security: 15-minute idle timeout, single-session enforcement
  • HTTPS: All data in transit is encrypted via TLS

5. Data Retention

We follow a structured data retention policy:

  • Active: Records 0 to 2 years old are actively maintained for ongoing service delivery
  • Archived: Records 2 to 7 years old are archived with restricted access for grant compliance and legal requirements
  • Deleted: Records older than 7 years are permanently and irreversibly deleted

6. Your Rights

You have the right to:

  • Request access to your personal information
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Withdraw consent for non-essential data processing

To exercise these rights, contact director@thepillarprojectbaltimore.org.

7. Mandatory Reporting

As a social services organization, we are required by Maryland law to report suspected child abuse or neglect. We may also be compelled to disclose information pursuant to a valid court order. We will notify affected individuals when legally permitted to do so.

8. Breach Response

In the event of a data breach involving personal information, we will:

  • Notify affected individuals within 72 hours of discovery
  • Report to relevant authorities as required by Maryland law
  • Conduct a full investigation and implement corrective measures
  • Provide a written incident report

9. Legal Framework & Compliance

Our data practices are informed by:

  • Violence Against Women Act (VAWA): We adhere to VAWA confidentiality provisions, which prohibit the disclosure of personally identifying information collected in connection with services to victims of domestic violence, sexual assault, stalking, and trafficking.
  • Maryland Personal Information Protection Act: We comply with Maryland's breach notification requirements and data protection standards.
  • Victims of Crime Act (VOCA): Data collected under VOCA-funded programs follows VOCA confidentiality and reporting requirements.
  • Family Violence Prevention and Services Act (FVPSA): Client information is protected under FVPSA confidentiality mandates.

10. Consent Workflows

We obtain informed consent before collecting any personal information:

  • Referral Consent: Partners submitting referrals and LAP reports confirm they have authority to share client information for the purpose of coordinating services.
  • Intake Consent: Survivors provide informed consent during intake, acknowledging what information is collected, how it will be used, who will have access, and their right to withdraw consent.
  • Service Enrollment: Education and training program enrollments include a data consent statement.
  • Withdrawal: Clients may withdraw consent at any time by contacting director@thepillarprojectbaltimore.org. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.

11. Justification for Storing Full LAP Data

We store complete Lethality Assessment Program data (including victim PII) for the following documented reasons:

  • Immediate Safety: Contact information is required to reach survivors within 24 hours and coordinate emergency resources.
  • Resource Coordination: Incident details enable accurate safety planning.
  • Continuity of Care: Complete records enable effective warm hand-offs to long-term service partners.
  • Grant Compliance: Funders require outcome tracking that links intake data to service delivery.
  • Law Enforcement Collaboration: Receiving organizations need full context for effective intervention.

All stored LAP data is encrypted at the field level (AES-256-GCM), access-controlled, audit-logged, and subject to our data retention lifecycle (active 0 to 2 years, archived 2 to 7 years, permanently deleted after 7 years).

12. Data Deletion Enforcement

Data deletion is enforced through automated and manual controls:

  • Records older than 2 years are automatically flagged for archival with restricted access.
  • Records older than 7 years are permanently deleted upon admin review and confirmation.
  • All deletion actions are irreversible and audit-logged.
  • Individual data deletion requests are processed within 30 days, subject to legal retention obligations.

13. Contact

For privacy-related inquiries:

The Pillar Project Corporation
Baltimore, Maryland
(347) 221-4189
director@thepillarprojectbaltimore.org