Plainly stated: what we collect, why we collect it, who else touches it, and how to make us delete it.
Operational ITAM is a registered brand name of EpicB Media LLC, a Michigan limited liability company. EpicB Media LLC is the data controller for information collected through operationalitam.com. In this policy, "we" and "us" mean EpicB Media LLC.
You can reach us by email at contact@operationalitam.com, or by mail at:
Operational ITAM
35339 23 Mile Road
PO Box #112
New Baltimore, MI 48047
United States
Written privacy requests — access, correction, deletion, or opt-out — may be sent to either address and are handled the same way.
We collect what you deliberately type into a form on this site, basic analytics about which pages get visited, and the standard technical logs every web server keeps. We do not sell your personal information. We do not run advertising or remarketing trackers. We do not buy contact lists. If you want your information deleted, email us and we will delete it.
Executive Briefing requests and general enquiries. When you submit the intake form on our contact page we collect your name, work email, phone number if you provide one, organization, job title, organization size, the service and challenge you selected, your renewal timing, any platform details you share, your free-text description, and how you found us. We use this to prepare for and respond to your enquiry.
Executive Brief downloads. To receive the Executive Brief PDF you provide a name, work email, and optionally a company name. We use this to send the document and, if you have not told us otherwise, occasional ITAM insights. Every such email includes an unsubscribe link.
Listener Case Files. When you submit a case file for the Operational ITAM Podcast we collect your first name, city or metro area, email address, and optionally your role and organization size, along with the topic you selected and the situation you describe. We also record your explicit choice about how you wish to be credited, and any optional boxes you tick.
Server logs. Our hosting provider records standard technical information for every request: IP address, browser and operating system, referring page, requested URL, and timestamp. These logs exist for security and troubleshooting. We do not use them to build profiles of individuals.
Website analytics. We use Google Analytics 4 to understand which pages people find useful. It records the pages you visit, roughly how long you stay, the site or search that sent you, your approximate location derived from your IP address, and your device and browser type. It also records a few specific actions: opening the Executive Brief download form, clicking a podcast subscribe button, and expanding an episode transcript.
We have configured it deliberately narrowly. Google Analytics 4 does not log or store IP addresses at all — an address is used momentarily to derive approximate location and is then discarded. Google Signals, the feature that joins analytics data to signed-in Google accounts to produce demographics and cross-device tracking, is switched off both in our page code and at the property level. Ad personalization is off. We run no advertising or remarketing tags of any kind, and we do not send any customer data to Google for audience matching. If your browser sends a Do Not Track signal, the analytics script does not load at all.
Google acts as our data processor for this, under Google's business data privacy terms. You can opt out across every site that uses Google Analytics by installing Google's official opt-out browser add-on.
The Operational ITAM Podcast is hosted by Transistor and distributed through Apple Podcasts, Spotify, Amazon Music, and any app that reads our public RSS feed.
When you play or download an episode, Transistor records the request in the same way any web server does — IP address, user agent, timestamp, and how much of the file was retrieved. Transistor uses this to produce aggregate download counts and approximate geography. We see the aggregate reports. We do not receive, and cannot obtain, a list of who listened to what.
If you subscribe through Apple Podcasts, Spotify, Amazon Music, or another directory, that platform's own privacy policy governs what it collects about you. We have no control over and no visibility into that data beyond the anonymized aggregate figures each platform chooses to show us.
This deserves its own section, because it is the one thing on this site where information you send us may be repeated publicly.
If you submit a case file, your situation may be described and discussed on an episode of the podcast. Before that happens, three things are always true:
One. Your attribution choice is honored exactly as you made it. If you selected first name and city, that is the most that airs. If you selected fully anonymous, nothing identifying airs. If you selected "don't use this on air," it is not used on air at all.
Two. Every case file is sanitized regardless of your choice. We do not name your employer, your vendors, your dollar figures, or any detail that would let a listener identify your organization — even if you included them in your submission.
Three. Your email address is never read on air and is never published. It is used solely to contact you, including to let you know before an episode featuring your situation is released.
Once an episode is published it is distributed to podcast platforms worldwide and cannot be recalled from listeners who have already downloaded it. If you change your mind, tell us before publication and we will pull it. Afterwards we can remove the episode from distribution, but we cannot retrieve copies already downloaded.
The submission form is not a secure channel and a case file is not a privileged or confidential communication. Please do not send audit letters, contracts, license agreements, vendor correspondence, or anything covered by an NDA or your employer's confidentiality policy. If your situation requires document review, book a briefing instead — an NDA is available before any data is shared.
We use a small number of third-party services to run this site. Each receives only what it needs to do its job.
Formspree processes submissions from every form on this site and forwards them to us by email. Your form data passes through and is stored on Formspree's infrastructure.
Google Analytics receives the page-visit data described above and processes it on our behalf.
GoDaddy hosts the website and keeps the server logs described above. GoDaddy also adds its own traffic-measurement script to pages served from its hosting platform. That script is inserted by the host rather than by us, and the data it collects is governed by GoDaddy's privacy policy. We do not receive individual visitor data from it.
Transistor hosts and distributes the podcast audio and produces the aggregate listening statistics described above.
Google Fonts serves the typefaces used on this site. Your browser requests those font files from Google's servers, which means Google receives your IP address as part of that request.
We do not sell, rent, or trade personal information to anyone, for any purpose. We do not share it with advertisers or data brokers. We would disclose information if compelled by valid legal process, and we would tell you unless legally prohibited from doing so.
Analytics cookies. Google Analytics sets first-party
cookies — typically _ga and a second cookie tied to our
measurement ID — to recognize a returning browser and avoid counting the
same visitor twice. They expire automatically, contain a randomly
generated identifier rather than anything about you personally, and are
not read by any advertising system. Blocking or deleting them in your
browser settings has no effect on how this site works.
Everything else. This site sets no other cookies and uses no browser local storage. There are no advertising, remarketing, or social tracking pixels.
The embedded podcast player is served by Transistor inside an iframe. Transistor may set its own cookies within that frame, governed by Transistor's privacy policy rather than ours.
A note on consent banners. We do not show one. Our services are directed at organizations in the United States, where analytics cookies of this kind do not require prior consent, and the Do Not Track check plus the opt-out add-on above give you a working way to refuse. If you are in the EU or UK and would rather we had not collected analytics data about your visit, email us and we will have it deleted.
Enquiry and briefing request data is retained for as long as we are in active conversation with you, and for up to three years afterwards for business record-keeping. Newsletter subscriber data is retained until you unsubscribe. Listener case files are retained for up to two years so that we can reference an answered question and reach you if a follow-up episode revisits it. Server logs are retained according to our hosting provider's standard retention period. Google Analytics data is retained for 14 months, after which Google deletes the underlying user-level records automatically; only aggregate reporting survives beyond that point.
You can shorten any of these by asking us to delete your information.
Whoever and wherever you are, you can ask us to show you what we hold about you, correct anything wrong, delete it, or stop emailing you. Email contact@operationalitam.com and we will act on it within 30 days. We will not charge you and we will not treat you differently for asking.
If you are in California, the CCPA and CPRA give you rights to know, delete, correct, and opt out of sale or sharing of personal information. We do not sell or share personal information as those laws define it, so there is nothing to opt out of — but every other right applies and is exercised through the email address above.
If you are in the EU, UK, or another GDPR jurisdiction, our lawful bases are your consent (newsletter, case file submission) and our legitimate interest in responding to business enquiries and operating a secure website. You have the right to access, rectify, erase, restrict, port, and object, and to lodge a complaint with your supervisory authority. Note that our services are directed at organizations in the United States; we do not target EU or UK residents.
If you are in a US state with a comprehensive privacy law — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others — the same rights apply through the same email address.
This site is served over HTTPS. Form submissions are encrypted in transit. We keep the number of systems touching your data deliberately small.
We will not claim your data is perfectly safe, because nobody can. No internet transmission or storage system is completely secure. That is precisely why the case file form asks you not to send confidential material, and why sensitive client data is handled under an NDA through a controlled channel rather than a web form.
This is a business-to-business site with no content or services directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has submitted information to us, email us and we will delete it.
We link to standards bodies, research reports, vendor documentation, and podcast platforms. Those sites have their own privacy policies and we are not responsible for their practices.
When we change this policy we update the "Last updated" date at the top. If a change materially affects how we handle information you have already given us, we will email you about it rather than relying on you to notice.
Questions, requests, or complaints about privacy go to contact@operationalitam.com. A person reads that address.