>
Privacy Policy

How we collect, use, and protect the data you share with us.

IBM Licensing Experts is an independent IBM license advisory firm. We collect a small amount of business contact information through forms on this website. We use that information solely to respond to inquiries and deliver requested research. We do not sell, share, or syndicate any contact data with third parties.

Last updatedMay 19, 2026
Effective dateJanuary 1, 2024
Regions coveredGlobal, including GDPR and CCPA aligned regions

1. Overview

This privacy policy describes how IBM Licensing Experts (also referred to in this document as we, us, or our) handles information collected through the website at ibmlicensingexperts.com. We are an independent IBM licensing advisory firm and we are not an IBM Business Partner, reseller, or affiliate. We collect data only as needed to respond to enterprise inquiries and to provide requested research materials.

If you are evaluating whether to share information with our firm, please also read the about page and why independence matters to understand the operating principles that shape our data handling practices.

2. Who we are

IBM Licensing Experts operates as the data controller for personal information submitted through the website. We provide independent IBM license consulting, audit defense, and contract negotiation services to enterprise clients. Our complete services are described on the license consulting, audit defense, and contract negotiation pages.

3. Data we collect

We collect only the data required to respond to inquiries and deliver research. The data we collect through website forms includes the following.

  • Full name
  • Job title
  • Company name
  • Corporate email address (personal email domains are not accepted)
  • How you found our firm
  • A free text description of the IBM licensing topic you would like to discuss

We also collect a small set of standard technical data through ordinary web server logs. This includes browser type, device type, anonymized IP address, referring page, and the time and date of visit. Server log data is retained for a limited period for security monitoring and aggregate site analytics only.

4. How we use data

We use the data you submit through the website for the following purposes only.

  • To respond to your inquiry, typically within 24 hours, with a personal reply from a senior consultant
  • To deliver requested research materials, including white papers and reference guides
  • To maintain a record of correspondence relevant to potential or existing engagements
  • To comply with applicable legal and regulatory obligations

We do not use submitted data to populate marketing automation systems. We do not enroll inquiry contacts in ongoing email sequences. We do not target contacts with advertising on any platform.

6. Sharing and disclosure

We do not sell, rent, lease, or syndicate any personal data collected through this website. We do not share inquiry data with any third party for marketing or sales purposes.

We share data only with the following limited categories of recipients.

  • Service providers who process data on our behalf strictly to operate the website and our internal correspondence systems. This includes our forms vendor (Formspree), our hosting provider, and standard productivity and email services.
  • Professional advisors such as auditors and legal counsel under appropriate confidentiality obligations.
  • Regulatory authorities where required by applicable law or valid legal process.

Every service provider we engage is subject to written data processing terms that limit use of personal data to the purposes we instruct.

7. Data retention

We retain inquiry data for the duration of the active conversation and for a reasonable follow up period thereafter, generally not exceeding three years from the most recent contact. Client engagement records are retained for the duration of the engagement and for the period required by applicable professional, contractual, and tax obligations.

Server log data is retained for a short rolling window, generally between 30 and 90 days, for security monitoring purposes.

8. Security

We apply administrative, technical, and physical safeguards to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission, access controls on internal systems, mandatory authentication for staff accounts, and standard endpoint and account hygiene practices.

No system can be fully secured against every possible threat. If we ever become aware of a security incident affecting your personal data we will notify you and any applicable regulator in accordance with the law of the relevant jurisdiction.

9. Your rights

Depending on your location, you may have the following rights with respect to personal data we hold about you.

  • The right to access the personal data we hold about you
  • The right to request correction of inaccurate or incomplete data
  • The right to request erasure of data, subject to legal and contractual retention obligations
  • The right to object to or restrict certain processing
  • The right to data portability
  • The right to withdraw consent at any time, where processing is based on consent
  • The right to lodge a complaint with a supervisory authority

To exercise any of these rights, please reach out through the contact page. We will respond within 30 days unless an extension is permitted under applicable law.

10. Cookies and similar technologies

The site uses a minimal set of cookies. Strictly necessary cookies enable core site functionality such as remembering a form session. Aggregate analytics cookies, where present, are used in a privacy preserving configuration that does not identify individual visitors. We do not use advertising cookies, cross site trackers, or social media tracking pixels on this site.

11. International data transfers

We operate globally and may transfer personal data across borders to provide services and operate our firm. Where personal data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred outside those regions, we use Standard Contractual Clauses or other lawful transfer mechanisms to provide an appropriate level of protection.

12. Children

The website is directed at enterprise IT, procurement, finance, and legal professionals. We do not knowingly collect personal data from children. If you believe we may have collected data from a child, please reach out through the contact page so we can remove the data.

13. Changes to this policy

We may update this privacy policy from time to time. The version date at the top of the page reflects the most recent change. Material changes will be highlighted with a prominent notice on the page for a reasonable period after publication.

14. How to contact us about privacy

If you have a question about this policy or about how we handle personal data, please reach out through the contact page. Specify the nature of your request in the message field and we will route your inquiry to the appropriate team member.

For inquiries unrelated to privacy, please use the standard contact form or explore our published white papers and insights blog.

Have a question about a specific data request?

Privacy or otherwise, reach out and a senior team member responds within 24 hours.