Rakafet Baka Moses - Privacy Policy
1. Introduction and Scope
This document sets out the privacy policy of Rakafet Baka Moses (hereinafter: “the Business”, “we” or “us”) regarding the collection, use, sharing, retention, and security of personal information of website visitors, sub-domain course website visitors, customers, subscribers to services and newsletters, and those who contact us through our communication channels. The policy is formulated in accordance with the Privacy Protection Law, 5741-1981 and its regulations (including Amendment 13), the Communications Law (Telecommunications and Broadcasts), 5742-1982, Section 30a (Spam Law), and the GDPR regulations of the European Union, where applicable. Use of the website, services, and communication channels constitutes consent to this policy. If you do not agree to this policy, please refrain from using the services.
2.Business Details and Data Controller
The data controller is: Rakafet Baka Moses
. Contact details: Email: rakefetm5@gmail.com;
Phone: +972508508303.
Main website: https://bareket-live.co.il/.
Courses website: https://courses.bareket-live.co.il/.
For the purpose of European regulations (where applicable), the Business acts as a data controller regarding the personal information collected as part of the services.
3.Target Audience and Minors
The services are intended for adults aged 18 and over and are not directed at minors. We do not knowingly collect information from minors. If we become aware that information about a minor has been collected without the consent of a parent/legal guardian, we will take action to delete it. When providing third-party details (for example, mother’s name or names of relatives for compatibility checking in communication), you must ensure that you have permission to share this information, and you will provide us with details only to the extent required for the service.
4.Types of Information Collected
We may collect the following information: full name; phone number; email address; home/shipping address; payment details (credit/debit card number and clearing details, as provided to the authorized clearing processor); IP address and approximate location data; names of relatives/mother when provided to us for compatibility checking in communication; contact details, correspondence, and content of inquiries by email and WhatsApp; usage and browsing data on the website and sub-domain (such as pages viewed, times, online identifiers, and cookies); transaction and purchase history; marketing preferences. Providing information is voluntary, but some services may not be possible without providing certain information.
5.Sources and Means of Collection
Information is collected from the following sources: forms and modules on the main WordPress site; transfer to the courses website on the sub-domain https://courses.bareket-live.co.il/ for registration and access to content; email inquiries; WhatsApp inquiries and calls; clearing and accounting systems; and automatically through cookies, server logs, and analytics tools. Sometimes information about relatives is provided to us by you for the purpose of providing communication services.
6.Purposes of Processing and Legal Grounds
We process information for the purposes of: providing services, delivering courses and support; contacting customers and responding to inquiries; online purchases and clearing; sending updates, newsletters, and marketing content in accordance with the law; analyzing browsing data and improving user experience; business management, documentation, collection, and compliance with legal requirements; paid advertising and measuring campaign effectiveness. Legal grounds for processing include: performance of a contract or taking steps prior to entering into a contract; our legitimate interest in operating and improving the services, securing them, and protecting our rights, subject to balancing against your rights; consent, where required (including for electronic marketing); and legal obligation, including retaining accounting documents.
7.Direct Marketing
We will send you marketing messages and updates (email, SMS, instant messages) in accordance with applicable law and in cases where your consent is required – only after we have received explicit consent, inter alia by checking a box or clicking an approval button. Every message will include an option to unsubscribe with a click and a clear and simple request. You may request to stop receiving mailings at any time, and the unsubscribe instruction will be carried out within the timeframe stipulated by law. We will clearly identify ourselves, state contact details, and honor opt-out requests in accordance with Section 30a of the Communications Law.
8.Cookies and Similar Technologies
We use cookies, pixels, and similar identifiers for the purpose of operating the website, saving settings, security, analytics, and measuring/adapting paid advertising. Cookies can be managed/blocked in browser settings; full blocking may impair website functionality. In cases requiring consent, we will display a cookie consent message. We may integrate analytical and advertising tools for the purpose of analyzing usage and improving the service; the collected information may include IP address, device ID, visited pages, and actions on the website.
9.Disclosure of Information to Third Parties
We will disclose information to third parties only as required for the provision of services, compliance with the law, enforcement of terms, protection of rights, or based on your consent. Categories of recipients may include: clearing and accounting providers; course platforms and website infrastructure; cloud, backup, and storage providers; customer relationship management, automation, and marketing systems; communication and messaging tools; artificial intelligence providers as integrated into the service; professional advisors and authorities in accordance with legal obligation. A list of example systems and service providers appears in the appendix. Providers act as data processors according to our instructions, subject to appropriate agreements, except in cases where they act as independent controllers according to their laws.
10.Transfers of Information Outside of Israel
Some processing is carried out through providers outside of Israel, including in the European Union/EEA and in countries that do not provide an equivalent level of protection. Where GDPR applies, we will act according to appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) of the EU and complementary protection measures. In Israel, we will act according to the requirements of the applicable law on transferring information abroad and ensure appropriate commitments from the recipients of the information to protect it.
11.Retention and Deletion
We will retain personal information only as required for the purposes for which it was collected and for a reasonable period thereafter for legitimate business needs, compliance with obligations and legal provisions, or until a request for deletion or as required by legitimate business need/legal obligation. Transaction data and accounting documents will be retained as required by law (such as according to bookkeeping laws). Marketing information will be retained until the right to object/unsubscribe is exercised. At the end of the relevant periods, we will take action to delete or anonymize it.
12.Data Subject Rights
Subject to applicable law, you have rights regarding personal information, including: the right to review the information held about you and to correct it if it is incorrect, incomplete, or inaccurate; the right to request deletion in certain cases; the right to object to the use for direct marketing purposes and to unsubscribe from mailings; according to GDPR (where applicable) – also rights to restrict processing, data portability, object to processing based on legitimate interest, and lodge a complaint with a supervisory authority. To exercise your rights, contact rakefetm5@gmail.com or call +972508508303, and we will endeavor to respond within the timeframes stipulated by law. Upon contact, we will perform reasonable identity verification.
13.Information Security and Security Incidents
We implement reasonable and accepted information security measures, including: access controls based on “need to know”; use of HTTPS on all relevant websites; two-step verification for critical service accounts; and periodic backups. In addition, we use encryption in transit and on supported infrastructures, password policies, security updates for systems/plugins, built-in permission management, and hardening and logical control. Despite efforts, there is no absolute security. In the event of a security incident that may create a material risk, we will act in accordance with the law: we will document, manage the incident, and provide appropriate notifications to data subjects and authorities (including the Privacy Protection Authority in Israel, and under GDPR – to a supervisory authority within 72 hours, where required).
14.Use of Artificial Intelligence (AI)
We may use artificial intelligence tools (such as chatbots and drafting/analysis tools) for the purpose of streamlining processes, drafting content, and customer service. As a policy, we will not feed personally identifiable information into these tools unless it is necessary for the service and in accordance with the law; where required, we will act to minimize, mask, or pseudonymize the information. AI providers may act as processors on our behalf or as separate controllers according to their terms. Do not type excessive or sensitive information into these tools without justification. We will maintain access controls and examine the terms of the providers and the protection measures they implement.
15.Controller vs. Processor
In data processing relationships, the Business is a “data controller”/database owner in relation to the information collected as part of the services. External service providers acting on our behalf (clearing, storage, marketing, automation, courses, etc.) generally act as “data processors” and process the information according to our instructions and binding agreements. In cases where a provider acts as an independent controller (for example, operational logs or compliance with its own law), processing will be done in accordance with that provider’s privacy policy.
16.Updates to the Policy
We may update this policy from time to time to reflect changes in law, services, or providers. We will publish an updated version on the website, and it will take effect on the date of publication unless otherwise stated. It is recommended to review the policy from time to time. Last updated: September 25, 2025.
17.Appendix – List of Systems and Service Providers
- Rivhit-iCredit – Clearing and payment processing.
- Hashbonit Online – Invoice and receipt generation.
- Smoove – Mailing list management, automations, and marketing.
- Airtable – Data management and light CRM.
- ManyChat – Chatbots and marketing messages.
- Make (Integromat) – Automations and integrations between systems.
- WhatsApp – Communication and customer service.
- Google Cloud – File storage, backup, and sharing.
- ChatGPT – Content drafting, support, and artificial intelligence.
- NotebookLM – AI-based content summarization and analysis.
- Cloud – Cloud infrastructure/website hosting.
- Bulldog – Marketing tools/landing pages.
- Wammit – WhatsApp automation and marketing.
- WordPress – Website management, forms, and content.
- Courses Website (courses.bareket-live.co.il) – Course delivery, registration, and user management.