
Security & Data Protection

Our approach
The Growth Syndicate B.V. (TGS) works with B2B companies across marketing, growth, RevOps, analytics, content, design and web development. That work can involve access to client systems, business contact data, campaign information and confidential commercial information.
We use a documented security and data-protection framework designed around least-privilege access, secure devices, strong authentication, controlled use of third-party tools, data minimisation and clear incident-response responsibilities. Where a client has stricter contractual or security requirements, those requirements take precedence for that engagement.
Security practices at a glance
Identity and access management
Access to client information is based on role, assignment and business need. TGS uses individual company identities and client-specific invitations wherever possible. Shared or generic logins are treated as exceptions and are used only where a client or tool setup requires them, with credentials handled through approved password-management controls.
Access is periodically reviewed and is removed when a person leaves TGS, changes role, is removed from a client engagement or otherwise no longer needs the access.
Device and endpoint security
Personnel handling client information use TGS-issued or approved work devices. TGS-issued MacBooks are configured with full-disk encryption, password and/or biometric authentication, automatic screen locking, endpoint protection and operating-system/security updates.
Physical access to work devices is restricted to the authorised user, and company devices are returned as part of offboarding.
Credential protection
TGS uses 1Password for company-managed credential storage and authorised sharing. Credentials should not be intentionally sent through ordinary email, Slack, WhatsApp or unsecured documents, and company or client credentials must not be reused for personal services.
Client data separation and handling
Client data is separated from other client and internal information using dedicated folders, channels, workspaces and/or client-controlled systems. Access is limited to the team members assigned to that client.
We work in client systems directly wherever practical. Exports of CRM data, contact databases or similar Personal Data are limited to cases where they are necessary and authorised. Where a temporary local copy is genuinely required, it must be stored only on an encrypted approved device, deleted as soon as it is no longer needed and, as a TGS baseline, no later than 30 days unless another period has been expressly authorised.
AI and automation
TGS uses AI and automation tools in parts of its work, but their use is subject to data-protection and client-specific restrictions. We aim to remove, anonymise or minimise Personal Data before using AI where reasonably possible.
- Raw CRM exports and contact lists are not uploaded to unapproved general-purpose AI systems.
- Authentication credentials are never submitted to AI or automation tools.
- Production-system data is not submitted unless the use case has been specifically authorised.
- Client-specific restrictions on AI always override TGS's general tool policy.
Personnel, confidentiality and security responsibilities
People who handle client data are subject to confidentiality and data-protection obligations appropriate to their role. They receive TGS security and data-handling requirements at onboarding and are required to acknowledge the applicable rules. Relevant personnel reconfirm key security obligations periodically.
Sub-processors and third-party services
TGS uses third-party cloud, collaboration, marketing, analytics and productivity services to deliver its work. Where a provider or contractor processes client Personal Data on our behalf, TGS applies the contractual and approval requirements applicable to the client engagement.
We do not treat the existence of a TGS account as blanket permission to use a tool for every client. Client-approved tools, system restrictions and data-processing terms are applied where required.
International data transfers
TGS works with an international team. Where access to EEA Personal Data from outside the EEA constitutes a restricted international transfer, TGS uses an appropriate GDPR transfer mechanism. Depending on the circumstances, this may include the European Commission's Standard Contractual Clauses together with supporting transfer assessments and supplementary safeguards.
Client-specific country restrictions or prior-approval requirements are respected and take precedence over the TGS baseline.
Security incidents
TGS maintains a documented incident-escalation process. Personnel must report an actual or suspected security or privacy incident immediately and, in any event, within four hours of becoming aware of it. TGS then assesses, contains and investigates the incident and follows the notification and cooperation requirements in the applicable client agreement and data-protection law.
Offboarding and access removal
When a person leaves TGS or is removed from an engagement, relevant company and client-system access is revoked, company credentials and password-manager access are removed as applicable, the company device is returned, and authorised temporary local client data is deleted or returned in accordance with instructions.
Audit and client assurance
TGS maintains internal documentation to evidence the controls relevant to client Data Processing Agreements and security reviews. Depending on the engagement and the scope of a review, this may include our information-security policy, security self-attestation, data-processing and confidentiality terms, access records, international-transfer documentation and other relevant evidence.
Detailed internal security documents are not published publicly, but appropriate information can be made available to clients during procurement, contracting or a contractual audit, subject to confidentiality and data-minimisation considerations.
Data protection
When TGS processes Personal Data on behalf of a client, we act under the applicable client agreement and Data Processing Agreement. We process client Personal Data only for authorised service purposes and do not reuse it for unrelated purposes or cross-client datasets unless expressly authorised.
For information about how TGS processes Personal Data for its own purposes - for example through our website or business communications - please see our Privacy Policy.
Security and privacy questions
For security, privacy or data-protection enquiries, contact legal@thegrowthsyndicate.com.
The Growth Syndicate B.V.
Jozef Israëlskade 46-1
1072 SB Amsterdam
The Netherlands