Privacy Policy

Last updated: September 7, 2026

1. Data Controller

Name: Roee Bar Barkai
Contact: linkedin.com/in/roee-bar
Website: https://roeebar.com

2. Data We Collect

  • Analytics (Google Analytics 4): Page views, user flow, device information, browser type, IP address (anonymized via GA4 IP anonymization), geographic location (country/city level only)
  • Cookies: Google Analytics cookies (_ga, _gid, _gat) for analytics tracking
  • Server Logs: HTTP request logs on Vercel (IP address, user agent, referer) for security and performance monitoring
  • Feedback Submissions: If you use the feedback widget, we store the message you type (10-500 characters), the feedback type you selected, the site language, whether you had accepted analytics, the time of submission, and an internal status used to triage it. Your browser’s user-agent string is stored only if you had accepted analytics.

3. Legal Basis for Processing

  • Analytics (GDPR Article 6(1)(a)): User consent via cookie consent banner. Analytics cookies are only set after you accept the cookie banner.
  • Server Logs (GDPR Article 6(1)(f)): Legitimate interest for security, fraud prevention, and performance optimization.

4. Data Retention Periods

  • Google Analytics Data: 14 months (Google's default retention policy)
  • Analytics Cookies: 2 years from first visit (GA4 default)
  • Server Logs: 30 days (Vercel default), then automatically deleted
  • Sentry Error Logs: 90 days for error events (PII pre-scrubbed)

5. Third-Party Data Processors & Subprocessors

Google Analytics 4

  • Purpose: Web analytics and user behavior tracking
  • Location: USA (partially processed in EU)
  • Legal Transfer: Standard Contractual Clauses (SCCs)
  • Adequacy decision: EU-U.S. Data Privacy Framework (DPF) — European Commission adequacy decision of 10 July 2023, Commission Implementing Decision (EU) 2023/1795

Vercel

  • Purpose: Web hosting and CDN
  • Location: Multiple datacenters (US, EU)
  • Legal Transfer: Standard Contractual Clauses (SCCs)
  • Data Processed: Request logs, server performance data

Sentry

  • Purpose: Error tracking and performance monitoring
  • Location: USA
  • Legal Transfer: Standard Contractual Clauses (SCCs)
  • Data Protection: PII scrubbing enabled (no email, API keys, or passwords transmitted)

Google Generative AI (Gemini)

  • Purpose: Powers the AI chat assistant on this site — generates the replies to messages you send it
  • Location: USA
  • Legal Transfer: Not confirmed. The transfer mechanism for this integration has not been verified, and none is claimed here.
  • Data Processed: The text of the chat messages you send, together with the site context sent alongside them in the prompt. Please do not enter personal or confidential information into the chat.

6. Your GDPR Rights (Articles 15-22)

Under GDPR, you have the following rights:

  • Right of Access (Article 15): Request a copy of all personal data we hold about you in a structured, commonly used, machine-readable format
  • Right to Rectification (Article 16): Correct or update inaccurate or incomplete personal data
  • Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten"), subject to legal obligations
  • Right to Restrict Processing (Article 18): Request that we limit how we use your data while a dispute is resolved
  • Right to Data Portability (Article 20): Receive your data in a portable, machine-readable format (JSON, CSV)
  • Right to Object (Article 21): Opt-out of analytics, marketing, or processing based on legitimate interest
  • Right to Withdraw Consent (Article 7(3)): Withdraw consent for analytics at any time via cookie settings
  • Right to Lodge a Complaint: File a complaint with your national data protection authority

How to Exercise Your Rights:

Contact via LinkedIn with the subject "GDPR Request" and specify which right you wish to exercise. We will respond within 30 days as required by GDPR.

7. Cookie Policy & Consent Management

Strictly Necessary Cookies (No consent required)

  • Session tokens (authentication)
  • CSRF tokens (security)
  • Preference cookies (dark/light mode, language)

Analytics Cookies (Consent required)

  • _ga: Google Analytics user ID (expires 2 years)
  • _gid: Google Analytics session ID (expires 24 hours)
  • _gat: Google Analytics rate limiting (expires 1 minute)

Cookie Consent:

A cookie consent banner appears on your first visit. Analytics cookies are only set after you click "Accept." You can manage cookies in your browser settings at any time, or click "Cookie settings" in the footer to review or withdraw your choice.

8. External Links & Third-Party Websites

This website contains links to external websites (LinkedIn, GitHub, Twitter, etc.). We are not responsible for the privacy practices of external sites. Please review the privacy policies of any third-party websites before submitting personal data.

9. Security & Data Protection Measures

  • HTTPS/TLS: All traffic encrypted in transit with TLS 1.3
  • Content Security Policy (CSP): Strict CSP headers prevent XSS attacks
  • HTTP Security Headers: X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security configured
  • Data Minimization: We collect only data necessary for stated purposes
  • Subprocessor Audits: Our third-party processors are vetted for security and compliance

Security Disclaimer:

While we implement industry-standard security measures, no transmission over the internet is 100% secure. We cannot guarantee absolute security. You use this site at your own risk. We are not liable for unauthorized access due to factors beyond our control.

10. International Data Transfers (EU/UK Residents)

If you are located in the EU, UK, or other jurisdiction with data protection laws, be aware that your data may be transferred to and processed in the United States, where some of our service providers are located.

Legal Mechanisms for Safe Transfers:

  • Standard Contractual Clauses (SCCs): Standard Contractual Clauses are one of the appropriate safeguards available under Article 46. The mechanism stated for each processor, where one has been confirmed, is listed in the third-party processors section above.
  • EU-U.S. Data Privacy Framework (DPF): Google Analytics and Vercel are certified under the EU-U.S. Data Privacy Framework, the European Commission's adequacy decision of 10 July 2023. Its predecessor, the EU-US Privacy Shield, was invalidated by the Court of Justice on 16 July 2020 in Case C-311/18 (Schrems II) and is no longer a valid transfer route.
  • Adequacy Decisions: Chapter V permits a transfer to a third country either on the basis of an adequacy decision (Article 45) or with appropriate safeguards such as Standard Contractual Clauses (Article 46). Where the route for a processor has not been confirmed, this policy says so rather than assuming one.

11. Children's Privacy

This website is not directed at individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction, e.g., 16 in the UK). We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it immediately.

12. Consent and Legitimate Interest

Analytics relies on your consent (GDPR Article 6(1)(a)), given through the cookie banner, so it is not covered by a legitimate interest assessment. We rely on legitimate interest (GDPR Article 6(1)(f)) for server logs, for security, fraud prevention and performance monitoring.

13. Updates to This Privacy Policy

We may update this privacy policy from time to time as our practices evolve or to comply with legal requirements. We will notify you of any material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date above

Your continued use of this website after changes have been posted constitutes your acceptance of the updated policy.

14. Data Protection Authority Contact Information

If you have concerns about our privacy practices or believe we have violated GDPR, you have the right to lodge a complaint with your national data protection authority:

15. Questions or Concerns?

If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

Contact: LinkedIn — linkedin.com/in/roee-bar

Website: https://roeebar.com

Also see our Terms of Use for information on governing law and dispute resolution.

We aim to respond to all data subject requests and inquiries within 30 days.

This privacy policy is effective as of September 7, 2026 and complies with:

  • GDPR (EU General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)
  • UK Data Protection Act 2018
  • ePrivacy Directive 2002/58/EC (Cookie Law)