Who we are

This site is itrafa.com, a personal blog about infrastructure, networking and security written by Rafael Gómez from Tampa, Florida.

Data controller: Rafael Gómez. You can write to [email protected] about anything concerning your data.

This policy sets out what is collected, who receives it and what for. It is written on the assumption that someone may read it from the European Union, so GDPR standards apply.

What is collected and who receives it

This is the full list of services involved when you visit. If any of them stops being used, this table is updated.

ServiceWhat it receivesWhat for
CloudflareYour IP address, browser and the full request. All traffic passes through their servers before reaching mine.Serving the site, protecting it and speeding it up
Cloudflare TurnstileBrowser signals when you submit a commentTelling people from bots without a CAPTCHA
Cloudflare Web AnalyticsThe page you visit, where you came from and technical browser data. It sets no cookies.Measuring site performance
Google Search Console, through Site KitNothing of yours: it is the data Google already holds from its own searchesSeeing which searches bring visitors
Antispam BeeComment content and metadataFiltering spam
Loginizer and fail2banIP addresses of failed login attemptsBlocking brute-force attacks on the admin panel
Microsoft 365The notification that you commented, which includes your name and emailDelivering that notification to my inbox

There is no advertising, no social media pixels and no sale of data to third parties.

Comments

When you leave a comment, the form data (name, email and website if you add one), your IP address and your browser string are stored. The last one helps detect spam.

The picture shown next to your comment is generated on this site, from the initial of your name. Gravatar is not queried, nor is any other service, so your email address never leaves here.

Legal basis: your consent when submitting the form.

Analytics

This site does not use Google Analytics. It did until 4 August 2026 and it was removed: it left two tracking cookies in every visitor’s browser in exchange for numbers that did not justify that cost.

All that remains is Cloudflare‘s analytics, which counts page views, where visits come from and what device they use. It sets no cookies, creates no identifier and follows nobody across sites. I see how many people read something, not who each of them is.

Google Search Console is still connected, but that works the other way round: it shows me the data Google already holds from its own searches. It collects nothing from your visit.

Cookies

This site sets no tracking cookies at all. The only ones it may set are functional, which is why you will not see a cookie banner here: there is nothing to consent to.

Embedded content from other sites

Some posts include embedded videos or other content. Those elements behave exactly as if you had visited the originating site: they can collect data, use cookies and track your interaction with them.

How long data is kept

Your rights

You can request access to any data held about you, its rectification, its erasure, the restriction of its processing, object to that processing and ask for portability of anything you provided.

Write to [email protected] to exercise them. If you believe they were not handled properly, you can complain to the data protection authority in your country.

Where your data goes

The servers are in the United States, and several of the services in the table operate from there too. If you write from the European Union, your data leaves the European Economic Area.

Cloudflare and Microsoft, both listed in the table, process data in the United States and in any other country where they hold servers.

Changes to this policy

When any of the above changes, this page is updated and its revision date changes with it. Substantive changes will also be announced on the blog.

Last reviewed: 4 August 2026.